Re: [Full-disclosure] Skype Network Remote DoS Exploit

2007-08-18 Thread Draichis
Kindly post the poc on the mailing list, as opposed to a link On Aug 17, 2007, at 8:13 AM, Valery Marchuk wrote: Hi all! On SecurityLab.ru forum an exploit code was published by an anonymous user. Reportedly it must have caused Skype massive disconnections today. The PoC uses standar

[Full-disclosure] [ GLSA 200708-13 ] BIND: Weak random number generation

2007-08-18 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200708-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] new default password database available

2007-08-18 Thread admin
Hi to everyone, there is a new default password database available. You can find it here: http://www.redoracle.com/index.php?option=com_password&task=rlist In this database there are 423 vendors and 1957 passwords. This database is updated every week as you can see with your eyes. Regards Redo

[Full-disclosure] Unexploitable buffer-overflow in the logging function of the Unreal engine

2007-08-18 Thread Luigi Auriemma
### Luigi Auriemma Application: Unreal engine http://www.unrealtechnology.com http://www.epicgames.com Versions: this engine is used in many games like Unreal Tournam

[Full-disclosure] Multiple vulnerabilities in rFactor 1.250

2007-08-18 Thread Luigi Auriemma
### Luigi Auriemma Application: rFactor http://www.rfactor.net Versions: <= 1.250 Platforms:Windows Bugs: A] buffer-overflow B] "Connection lost" crash

[Full-disclosure] Multiple vulnerabilities in Toribash 2.71

2007-08-18 Thread Luigi Auriemma
### Luigi Auriemma Application: Toribash http://www.toribash.com Versions: <= 2.71 Platforms:Windows, Mac and Linux Bugs: A] dedicated server format string

[Full-disclosure] OSNews

2007-08-18 Thread I. D.
http://distrowatch.com/weekly.php?issue=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd%00 Someone forget their chroot soup this morning. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-discl

[Full-disclosure] [ MDKSA-2007:167 ] - Updated libvorbis packages fix vulnerabilities

2007-08-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:167 http://www.mandriva.com/security/ ___

[Full-disclosure] [ MDKSA-2007:166 ] - Updated rsync packages fix off-by-one buffer overflow

2007-08-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:166 http://www.mandriva.com/security/ ___