[Full-disclosure] [USN-521-1] libmodplug vulnerability

2007-09-27 Thread Kees Cook
=== Ubuntu Security Notice USN-521-1 September 27, 2007 libmodplug vulnerability CVE-2006-4192 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubunt

[Full-disclosure] [ MDKSA-2007:190 ] - Updated kdebase packages fix KDM vulnerability

2007-09-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:190 http://www.mandriva.com/security/ ___

[Full-disclosure] CAT6500 accessible via 127.0.0.x loopback addresses

2007-09-27 Thread lee . e . rian
Lee E Rian/TCO/HQ/BOC wrote on 08/29/2006 01:49:40 PM: > > I found something interesting w/ the cat6000s - telnet 127.0.0.11 > gets you into the switch & telnet 127.0.0.12 gets you into the router > > % snmpget 127.0.0.11 sysDescr.0 > RFC1213-MIB::sysDescr.0 = STRING: "Cisco Systems WS-C6509.Cisco

[Full-disclosure] [ GLSA 200709-17 ] teTeX: Multiple buffer overflows

2007-09-27 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200709-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ MDKSA-2007:189 ] - Updated t1lib packages fix vulnerability

2007-09-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:189 http://www.mandriva.com/security/ ___

Re: [Full-disclosure] New term "RDV" is born

2007-09-27 Thread T Biehn
Genius! On 9/27/07, worried security <[EMAIL PROTECTED]> wrote: > > > RDV = recently disclosed vulnerability. > > A recently disclosed vulnerability (or RDV for short) is an unpatched > vulnerablity which has been recently disclosed. > > "RDV" will be used by the whitehat industry to describe what

[Full-disclosure] [ GLSA 200709-16 ] Lighttpd: Buffer overflow

2007-09-27 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200709-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-disclosure] New term "RDV" is born

2007-09-27 Thread worried security
RDV = recently disclosed vulnerability. A recently disclosed vulnerability (or RDV for short) is an unpatched vulnerablity which has been recently disclosed. "RDV" will be used by the whitehat industry to describe what the underground and blackhats call "0-day". If you agree with RDV, start usin

[Full-disclosure] Owning Big Brother: How to Crack into Axis IP cameras

2007-09-27 Thread Adrian P.
We found multiple vulnerabilities on Axis 2100 IP cameras affecting both old firmware versions and the latest firmware (2.43). The research is made of two components: a purple paper and a video. The research doesn't just cover boring PoCs, but actual Hollywood-style exploits :-). Yes, this incl

[Full-disclosure] iDefense Security Advisory 09.27.07: Computer Associates BrightStor HSM r11.5 Multiple Vulnerabilities

2007-09-27 Thread iDefense Labs
Computer Associates BrightStor HSM r11.5 Multiple Vulnerabilities iDefense Security Advisory 09.27.07 http://labs.idefense.com/intelligence/vulnerabilities/ Sep 27, 2007 I. BACKGROUND Computer Associates BrightStor Hierarchical Storage Manager (HSM) is an application used to create a tiered stor

Re: [Full-disclosure] New RFID Mail list and project

2007-09-27 Thread full-disclosure
hey jack, The only thing that ever made attrition.org interesting is that it let us know what ytcracker and MostHated were up to, and your corporate sponsorship of their actions. That is an era passed however and we are now on to new things. Quite frankly we don't care what the ytcracker an

Re: [Full-disclosure] New RFID Mail list and project

2007-09-27 Thread full-disclosure
Wow you dudes haven't been relevant since you proved you couldn't sustain ddos attacks as retaliation towards your support of criminal activities. Is this new list of yours going to be moderated by pink rabbits? Either way I bet it sucks more than this list. SHOUTOUTS: [EMAIL PROTECTED] - THE

Re: [Full-disclosure] defining 0day

2007-09-27 Thread Zow
> As a professional, I would be happy to see terms like '0day' banished > from the lexicon entirely. It's an essentially meaningless -- all > third-party exploits are zero-day to _somebody_ -- term of boast co- > opted from the warez scene, and we can do perfectly well without it. I'd accept

Re: [Full-disclosure] CAT6500 accessible via 127.0.0.x loopback addresses

2007-09-27 Thread Ilker Temir
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Response: Catalyst 6500 and Cisco 7600 Series Devices Accessible via Loopback Address http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtml Revision 1.0 For Public Release 2007 September 26 2200 UTC (GMT) Cisco Response ===

[Full-disclosure] [SECURITY] [DSA 1343-2] New file packages fix arbitrary code execution

2007-09-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1343-2[EMAIL PROTECTED] http://www.debian.org/security/ Florian Weimer September 25th, 2007