[Full-disclosure] IRM025: TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS

2007-11-29 Thread IRM Research
IRM Security Advisory 025 TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS Vulnerability Type / Importance: Remote DoS / High Problem Discovered: 16 April 2007 Vendor Contacted: 16 April 2007 Advisory Published: 29 November 2007

Re: [Full-disclosure] Microsoft FTP Client Multiple Bufferoverflow Vulnerability

2007-11-29 Thread KJK::Hyperion
Tonnerre Lombard ha scritto: Isn't the FTP client compiled with stack overflow protection? If so, how is that supposed to help? By terminating the program before the payload is executed May I suggest that this protection is not perfect? I was hoping that people on this mailing list consider

[Full-disclosure] [SECURITY] [DSA 1409-3] New samba packages fix several vulnerabilities

2007-11-29 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1409-3 [EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp November 29, 2007

Re: [Full-disclosure] n3td3v denounces the actions of www.derangedsecurity.com

2007-11-29 Thread Byron Sonne
fellow scots stick up for each other, so remember that the next time you talk to a scotsman, because we're tough and bold and we'll kick you in the teeth you swedish fuck. You know why Scots wear kilts, right? Sheep can hear zippers. ___

Re: [Full-disclosure] Microsoft FTP Client Multiple

2007-11-29 Thread Valdis . Kletnieks
On Wed, 28 Nov 2007 21:44:40 PST, Daniel H. Renner said: From what I've noticed, users of MS' FTP client aren't the usual Windows GUI user. So that would be one good social engineering trick... I wouldn't be surprised if a large percentage of those FTP client users aren't suffering from the

Re: [Full-disclosure] Security Contact @ Avast!

2007-11-29 Thread Thierry Zoller
S Could anyone send me the security contact of avast! ? S [EMAIL PROTECTED] does not response. security@ vlk@ -- http://secdev.zoller.lu Thierry Zoller Fingerprint : 5D84 BFDC CD36 A951 2C45 2E57 28B3 75DD 0AC6 F1C7 ___ Full-Disclosure - We believe

Re: [Full-disclosure] Microsoft FTP Client Multiple

2007-11-29 Thread Dude VanWinkle
On Nov 29, 2007 12:11 PM, [EMAIL PROTECTED] wrote: On Wed, 28 Nov 2007 21:44:40 PST, Daniel H. Renner said: From what I've noticed, users of MS' FTP client aren't the usual Windows GUI user. So that would be one good social engineering trick... I wouldn't be surprised if a large

[Full-disclosure] ERRATA: [ GLSA 200711-20 ] Pioneers: Multiple Denials of Service

2007-11-29 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [ERRATA UPDATE]GLSA 200711-20:04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Re: [Full-disclosure] Microsoft FTP Client Multiple

2007-11-29 Thread Daniel H. Renner
Dude VanWinkle wrote: On Nov 29, 2007 12:11 PM, [EMAIL PROTECTED] wrote: On Wed, 28 Nov 2007 21:44:40 PST, Daniel H. Renner said: From what I've noticed, users of MS' FTP client aren't the usual Windows GUI user. So that would be one good social engineering trick... I wouldn't be surprised

[Full-disclosure] AST-2007-025 - SQL Injection issue in res_config_pgsql

2007-11-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-025 ++ | Product| Asterisk|

[Full-disclosure] AST-2007-026 - SQL Injection issue in cdr_pgsql

2007-11-29 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2007-026 ++ | Product| Asterisk|

Re: [Full-disclosure] Microsoft FTP Client Multiple

2007-11-29 Thread Peter Besenbruch
On Thursday 29 November 2007 07:11:58 [EMAIL PROTECTED] wrote: I wouldn't be surprised if a large percentage of those FTP client users aren't suffering from the same smug I'm too klewed to fall for it attitude that many Mac users have One would hope they would be klewed enough to use a