SKIDATA RFID Freemotion.Gate Unauthenticated Web Service Aribtrary Remote Command Execution

2013-11-19 Thread Dennis Kelly
Title: SKIDATA RFID Freemotion.Gate Unauthenticated Web Service Aribtrary Remote Command Execution Product: Freemotion.Gate Vendor: SKIDATA, http://www.skidata.com/en/ RTP|One, http://http://www.rtp.com/ Vulnerable Versions: 4.1.3.5 and likely all prior versions. Tested Version: 4.1.3.5

FreeBSD Security Advisory FreeBSD-SA-13:14.openssh

2013-11-19 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-13:14.opensshSecurity Advisory The FreeBSD Project Topic:

16TH AVAR INTERNATIONAL SECURITY CONFERENCE 2013 - (4th-7th Dec'13, Chennai. India)

2013-11-19 Thread Gregory Panakkal
We are pleased to announce that for the first time ever, one of the largest international Security Conferences - AVAR 2013 - is set to be held in Chennai, India. AVAR (Association of Antivirus Asia Researchers) is an independent and not-for-profit organization oriented in the Asia-Pacific

[ MDVSA-2013:266 ] java-1.6.0-openjdk

2013-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:266 http://www.mandriva.com/en/support/security/

[ MDVSA-2013:267 ] java-1.7.0-openjdk

2013-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:267 http://www.mandriva.com/en/support/security/

ESA-2013-078: EMC Document Sciences xPression Multiple Vulnerabilities

2013-11-19 Thread Security Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ESA-2013-078: EMC Document Sciences xPression Multiple Vulnerabilities EMC Identifier: ESA-2013-078 CVE Identifier: CVE-2013-6173, CVE-2013-6174, CVE-2013-6175, CVE-2013-6176, CVE-2013-6177 Severity Rating: CVSS v2 Base Score: See below for

pineapp mailsecure remote no authenticated privilege escalation remote execution code

2013-11-19 Thread rubengarrote
Hi, related this: http://seclists.org/fulldisclosure/2013/Nov/136 In February 2013 I send Pineapp the following information: - It is possible execute any command bash as qmailq unprivilege user, sending only the following https

XADV-2013003 Linux Kernel fbdev Driver arcfb_write() Overflow

2013-11-19 Thread geinblues
++ | XADV-2013003 Linux Kernel fbdev Driver arcfb_write() Overflow | ++ Vulnerable versions: - linux kernel 3.12 = - linux kernel 2.6.x Testbed: linux kernel

XADV-2013008 Linux Kernel 3.11.7 = sk_attach_filter Kernel Heap Corruption

2013-11-19 Thread geinblues
+---+ | XADV-2013008 Linux Kernel 3.11.7 = sk_attach_filter Kernel Heap Corruption | +---+ Vulnerable versions: - linux kernel 3.11.7 =

XADV-2013007 Linux Kernel bt8xx Video Driver IOCTL Heap Overflow

2013-11-19 Thread geinblues
++ | XADV-2013007 Linux Kernel bt8xx Video Driver IOCTL Heap Overflow | ++ Vulnerable versions: - linux kernel 2.6.18 = Testbed: ubuntu Type: Local Impact: