Re: [Full-disclosure] Zabbix 1.6.2 Frontend Multiple Vulnerabilities

2009-03-09 Thread Eygene Ryabinkin
Good day. Small addition to the advisory. Tue, Mar 03, 2009 at 03:30:26PM +, ascii wrote: Zabbix 1.6.2 Frontend Multiple Vulnerabilities [...] C) Local File Inclusion If the user is authenticated, a Local File Inclusion vulnerability exists in file locales.php. The following URL

[Full-disclosure] [ GLSA 200903-12 ] OptiPNG: User-assisted execution of arbitrary code

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-11 ] PyCrypto: Execution of arbitrary code

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-14 ] BIND: Incorrect signature verification

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-15 ] git: Multiple vulnerabilties

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-16 ] Epiphany: Untrusted search path

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-17 ] Real VNC: User-assisted execution of arbitrary code

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-18 ] Openswan: Insecure temporary file creation

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-19 ] Xerces-C++: Denial of Service

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-20 ] WebSVN: Multiple vulnerabilities

2009-03-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability

2009-03-09 Thread DDI_Vulnerability_Alert
Title - DDIVRT-2009-22 SMART Board Whiteboard Directory Traversal Vulnerability Severity High Date Discovered --- January 19th, 2009 Discovered By - Digital Defense, Inc. Vulnerability Research Team Credit: David Marshall and r...@b13$

[Full-disclosure] DDIVRT-2009-21 vBook Login Application Cross-site Scripting Vulnerability

2009-03-09 Thread DDI_Vulnerability_Alert
Title - DDIVRT-2009-21 vBook Login Application Cross-site Scripting Vulnerability Severity Low Date Discovered --- January 19th, 2009 Discovered By - Digital Defense, Inc. Vulnerability Research Team Credit: David Marshall and r...@b13$

[Full-disclosure] [ GLSA 200903-21 ] cURL: Arbitrary file access

2009-03-09 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] Foxit Reader Multiple Vulnerabilities (CORE-2009-0218)

2009-03-09 Thread Core Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Foxit Reader Multiple Vulnerabilities 1. *Advisory Information* Title: Foxit Reader Multiple Vulnerabilities Advisory ID: CORE-2009-0218

Re: [Full-disclosure] [ GLSA 200903-18 ] Openswan: Insecure temporary file creation

2009-03-09 Thread Paul Wouters
On Mon, 9 Mar 2009, Robert Buchholz wrote: Subject: [ GLSA 200903-18 ] Openswan: Insecure temporary file creation Once again, thanks to everyone for not contacting the Openswan Project in this matter just like they did not do this 6 months ago when this vulnerability came out originally.

[Full-disclosure] List Charter

2009-03-09 Thread John Cartwright
[Full-Disclosure] Mailing List Charter John Cartwright jo...@grok.org.uk - Introduction Purpose - This document serves as a charter for the [Full-Disclosure] mailing list hosted at lists.grok.org.uk. The list was created on 9th July 2002 by Len Rose, and is primarily concerned with