An Analysis of the (In)Security State of the GameHouse Game Installation Mechanism

2013-09-19 Thread RBS Research
January 2013, we encountered the latest version of RealArcade installer provided by GameHouse (a division of RealNetworks) on a system during an audit. Considering its historical vulnerabilities and recent reports about vulnerabilities in game clients/installers, we decided to take a closer look

[PT-2013-41] Arbitrary Code Execution in Ajax File and Image Manager

2013-09-19 Thread noreply
--- (PT-2013-41) Positive Technologies Security Advisory Arbitrary Code Execution in Ajax File and Image Manager --- ---[ Vulnerable software ] Ajax File and Image Manager Version:

[ MDVSA-2013:238 ] wireshark

2013-09-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:238 http://www.mandriva.com/en/support/security/

Re: %windir%\temp\sso\ssoexec.dll (or: howtrustworthy is Microsoft's build process)

2013-09-19 Thread Stefan Kanthak
This is a followup to http://seclists.org/fulldisclosure/2012/Mar/17 and http://seclists.org/fulldisclosure/2013/Aug/225: On Sunday, March 04, 2012 9:06 PM I wrote: Hi @ll, the system image \Setup\WIM\setup.wim on the POSReady 2009 eval CD, available from the Microsoft Download Center under

[ MDVSA-2013:239 ] wordpress

2013-09-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:239 http://www.mandriva.com/en/support/security/

[security bulletin] HPSBGN02923 rev.1 - HP ArcSight Enterprise Security Manager Management Web Interface, Remote Cross Site Scripting (XSS)

2013-09-19 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03901176 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03901176 Version: 1 HPSBGN02923

[SECURITY] [DSA 2761-1] puppet security update

2013-09-19 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2761-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert September 19, 2013

[security bulletin] HPSBGN02925 rev.1 - HP IceWall SSO, IceWall File Manager and IceWall Federation Agent, Multiple Remote Unauthorized Access Vulnerabilities

2013-09-19 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03918632 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03918632 Version: 1 HPSBGN02925

Paypal Inc Bug Bounty #99 - Filter Bypass Persistent Web Vulnerability

2013-09-19 Thread Vulnerability Lab
Title: == Paypal Inc Bug Bounty #99 - Filter Bypass Persistent Web Vulnerability Date: = 2013-09-20 References: === http://www.vulnerability-lab.com/get_content.php?id=984 PayPal Security UID: nj1071UU VL-ID: = 984 Common Vulnerability Scoring System: