[Full-disclosure] [ GLSA 200507-04 ] RealPlayer: Heap overflow vulnerability

2005-07-06 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Unpatched phpBB XSS [in 2.0.16]

2005-07-06 Thread Dominik Birk
PoC is included with the description. I would advise administrators to disable the rendering of BBCode for the time being, this mitigates the issue. According to this Exploit there is still no official answer from PHPBB. Because of that, I just want to post my personal little version of

[Full-disclosure] [USN-148-1] zlib vulnerability

2005-07-06 Thread Martin Pitt
=== Ubuntu Security Notice USN-148-1 July 06, 2005 zlib vulnerability CAN-2005-2096 === A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog)

[Full-disclosure] [SECURITY] [DSA 739-1] New trac package fixes upload/download vulnerability

2005-07-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 739-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze July 6th, 2005

[Full-disclosure] [ GLSA 200507-05 ] zlib: Buffer overflow

2005-07-06 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] McAfee Intrushield IPS Abuse

2005-07-06 Thread c0ntex
/* * $ An open security advisory #8 - McAfee Intrushield IPS Management Console Abuse

[Full-disclosure] GNATS - gen-index

2005-07-06 Thread Adam Zabrocki
Name: GNATS - gen-index Vendor URL: http://www.gnu.org/software/gnats Author: Adam Zabrocki [EMAIL PROTECTED] Date: June 16, 2005 Issue: GNATS - the GNU problem report management system allows attacker to

[Full-disclosure] SUSE Security Announcement: zlib denial of service attack (SUSE-SA:2005:039)

2005-07-06 Thread Marcus Meissner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 __ SUSE Security Announcement Package:zlib Announcement ID:SUSE-SA:2005:039 Date:

[Full-disclosure] [SECURITY] [DSA 740-1] New zlib packages fix denial of service

2005-07-06 Thread Michael Stone
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA 740-1 [EMAIL PROTECTED] http://www.debian.org/security/Michael Stone July 06, 2005

Re: [Full-disclosure] [ GLSA 200507-05 ] zlib: Buffer overflow

2005-07-06 Thread H D Moore
Does anyone have an idea on how to trigger this? Debian and SuSE say this is a denial of service. Gentoo says code execution, but they are the ones who found the bug. Most zlib bugs can be exploited prior to authentication in OpenSSH. The patch being is being distributed by the vendors and is

Re: [Full-disclosure] alert: the 111111 bug

2005-07-06 Thread Ron DuFresne
On Sun, 3 Jul 2005, Paul Schmehl wrote: --On July 4, 2005 12:03:02 AM +0100 lsi [EMAIL PROTECTED] wrote: For this customer 11/11/11 in the date field means, don't process this record, which will obviously cause problems with legitimate transactions on that date. I suspect using a new

Re: [Full-disclosure] Re: alert: the 111111 bug

2005-07-06 Thread Ron DuFresne
On Mon, 4 Jul 2005, Thomas Binder wrote: Hi! On Sun, Jul 03, 2005 at 10:18:02PM -0500, Paul Schmehl wrote: Not to worry. The 11th of November, 2011 is a Saturday. No one will be working that day. :-) Mhmm, it's a Friday according to my calendar - is mine or yours in error? cal

Re: [Full-disclosure] alert: the 111111 bug

2005-07-06 Thread Paul Schmehl
--On Wednesday, July 06, 2005 14:31:17 -0500 Ron DuFresne [EMAIL PROTECTED] wrote: On Sun, 3 Jul 2005, Paul Schmehl wrote: --On July 4, 2005 12:03:02 AM +0100 lsi [EMAIL PROTECTED] wrote: For this customer 11/11/11 in the date field means, don't process this record, which will obviously

Re: [Full-disclosure] alert: the 111111 bug

2005-07-06 Thread Steve Friedl
On Wed, Jul 06, 2005 at 03:11:58PM -0500, Paul Schmehl wrote: Not to worry. The 11th of November, 2011 is a Saturday. No one will be working that day. :-) It was a joke. A *joke*. Did anyone *seriously* think I actually looked it *up*? When it's so easy, why not? $ cal 11

[Full-disclosure] [ GLSA 200507-06 ] TikiWiki: Arbitrary command execution through XML-RPC

2005-07-06 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] Researching IMISERV (wupdt.exe)

2005-07-06 Thread rlh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello everyone, I am in the process of developing network security labs for some community college students. Very recently I assisted a neighbor with removing the IMISERV virus from a friend's laptop. It's not possible to get the laptop back, but I

[Full-disclosure] Wireless Strengths Test

2005-07-06 Thread GOH HO YEE JOHN
Hi Im conducting a lab-test with a couple of industrial wireless equipments to test its strengths. Was wondering do you have any suggestions on what I can carry out with? - Wireless Client - Wireless AP (FakeAP) o Is it possible for Orinoco Cards packed with HostAP Drivers? I need to

[Full-disclosure] MDKSA-2005:112 - Updated zlib packages fix vulnerability

2005-07-06 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Update Advisory ___ Package name: zlib Advisory ID: