[security bulletin] HPSBST02897 rev.1 - HP StoreOnce D2D Backup System, Remote Denial of Service (DoS)

2013-08-22 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03828580 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03828580 Version: 1 HPSBST02897 r

Joomla! VirtueMart component <= 2.0.22a - SQL Injection

2013-08-22 Thread Matias Fontanini
Joomla! VirtueMart component <= 2.0.22a - SQL Injection == Description == - Software link: http://www.virtuemart.net/ - Affected versions: All versions between 2.0.8 and 2.0.2

CVE-2013-4152 XML External Entity (XXE) injection in Spring Framework

2013-08-22 Thread Pivotal Security Team
Severity: Important Vendor: Spring by Pivotal Versions Affected: - 3.0.0 to 3.2.3 (Spring OXM & Spring MVC) - 4.0.0.M1 (Spring OXM) - 4.0.0.M1-4.0.0.M2 (Spring MVC) - Earlier unsupported versions may also be affected Description: The Spring OXM wrapper did not expose any property for disabling e

[ MDVSA-2013:215 ] cacti

2013-08-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:215 http://www.mandriva.com/en/support/security/ __

FreeBSD Security Advisory FreeBSD-SA-13:09.ip_multicast

2013-08-22 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 FreeBSD-SA-13:09.ip_multicast Security Advisory The FreeBSD Project Topic: integer overflow in IP_MSFILTER Category: core Module: kernel An

[slackware-security] xpdf (SSA:2013-233-02)

2013-08-22 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] xpdf (SSA:2013-233-02) New xpdf packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, 14.0, and -current to fix a security issue. Here are the details from the Slackware 14.0 ChangeLog: +-

[slackware-security] hplip (SSA:2013-233-01)

2013-08-22 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] hplip (SSA:2013-233-01) New hplip packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, 14.0, and -current to fix a security issue. Here are the details from the Slackware 14.0 ChangeLog: +---

[slackware-security] poppler (SSA:2013-233-03)

2013-08-22 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] poppler (SSA:2013-233-03) New poppler packages are available for Slackware 14.0, and -current to fix a security issue. Here are the details from the Slackware 14.0 ChangeLog: +--+ patches/packages/poppl

FreeBSD Security Advisory FreeBSD-SA-13:10.sctp

2013-08-22 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-13:10.sctp Security Advisory The FreeBSD Project Topic: K