[Full-disclosure] [SECURITY] [DSA 1801-1] New ntp packages fix several vulnerabilities

2009-05-20 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1801-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst May 19, 2009

[Full-disclosure] [SECURITY] [DSA 1802-1] New squirrelmail packages fix several vulnerabilities

2009-05-20 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - Debian Security Advisory DSA-1802-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst May 19, 2009

[Full-disclosure] rPSA-2009-0086-1 postgresql postgresql-contrib postgresql-server

2009-05-20 Thread rPath Update Announcements
rPath Security Advisory: 2009-0086-1 Published: 2009-05-19 Products: rPath Linux 2 Rating: Minor Exposure Level Classification: Local System User Deterministic Denial of Service Updated Versions: postgresql=conary.rpath@rpl:2/8.3.7-0.1-1

[Full-disclosure] ZDI-09-022: Apple Safari Malformed SVGList Parsing Code Execution Vulnerability

2009-05-20 Thread ZDI Disclosures
ZDI-09-022: Apple Safari Malformed SVGList Parsing Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-022 May 13, 2009 -- CVE ID: CVE-2009-0945 -- Affected Vendors: Apple -- Affected Products: Apple Safari -- TippingPoint(TM) IPS Customer Protection: TippingPoint

[Full-disclosure] ZDI-09-023: Apple OS X ATSServer Compact Font Format Parsing Memory Corruption Vulnerability

2009-05-20 Thread ZDI Disclosures
ZDI-09-023: Apple OS X Unspecified ATSServer Font Parsing Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-023 May 13, 2009 -- CVE ID: CVE-2009-0154 -- Affected Vendors: Apple -- Affected Products: Apple OS X -- Vulnerability Details: This vulnerability allows

[Full-disclosure] Cisco Security Advisory: CiscoWorks TFTP Directory Traversal Vulnerability

2009-05-20 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: CiscoWorks TFTP Directory Traversal Vulnerability Advisory ID: cisco-sa-20090520-cw http://www.cisco.com/warp/public/707/cisco-sa-20090520-cw.shtml Revision 1.0 For Public Release 2009 May 20 1600 UTC (GMT) Summary

[Full-disclosure] [SECURITY] [DSA 1803-1] New nsd packages fix denial of service

2009-05-20 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1803-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst May 20, 2009

[Full-disclosure] iDefense Security Advisory 05.20.09: IBM AIX libc MALLOCDEBUG File Overwrite Vulnerability

2009-05-20 Thread iDefense Labs
iDefense Security Advisory 05.19.09 http://labs.idefense.com/intelligence/vulnerabilities/ May 19, 2009 I. BACKGROUND IBM's AIX is a Unix operating system based on System V, which runs on the PowerPC (PPC) architecture. For more information, visit the product web site at the following URL.

[Full-disclosure] [SECURITY] [DSA 1804-1] New ipsec-tools packages fix denial of service

2009-05-20 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1804-1secur...@debian.org http://www.debian.org/security/ Nico Golde May 20th, 2009

[Full-disclosure] CORE-2009-0109 - Multiple XSS in Sun Communications Express

2009-05-20 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Multiple XSS in Sun Communications Express 1. *Advisory Information* Title: Multiple XSS in Sun Communications Express Advisory ID: