Re: [Full-disclosure] Oops! About xscreensaver 5.01

2009-07-08 Thread Kingcope
Hello again, The described xscreensaver vulnerability affects Opensolaris (11 for sure, maybe 10 also) xscreensaver 5.01 builds ONLY. I could not reproduce the vuln on FreeBSD or Linux. (This is getting boring I know, have a nice day) Thanks and Best Regards, Nikolaos Rangos 2009/7/6 Kingcope

Re: [Full-disclosure] [Rumor] SSH 0-day

2009-07-08 Thread Ben Rosenberg
See here: http://lwn.net/Articles/340483/ On Wed, Jul 8, 2009 at 1:00 PM, Martin Spinassi martins.li...@gmail.comwrote: Hi list, I've been reading around (openssh mailing list, some forums, etc.) a rumor about a 0-day exploit in openssh. Does anybody knows if there is *really* something

[Full-disclosure] CORE-2009-0519 - Awingsoft Awakening Winds3D Viewer remote command execution vulnerability

2009-07-08 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ~ Core Security Technologies - CoreLabs Advisory ~ http://www.coresecurity.com/corelabs/ Awingsoft Awakening Winds3D Viewer remote command execution vulnerability 1. *Advisory Information* Title: Awingsoft Awakening Winds3D Viewer

[Full-disclosure] CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information

2009-07-08 Thread Core Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ WordPress Privileges Unchecked in admin.php and Multiple Information Disclosures 1. *Advisory Information* Title: WordPress Privileges Unchecked

[Full-disclosure] MySQL = 5.0.45 post auth format string vulnerability

2009-07-08 Thread Kingcope
MySQL (tested: Version 5.0.45 on CentOS (Linux)) Format String Vulnerability MySQL General Available (GA) Release is vulnerable. Latest MySQL Version is not vulnerable since the bug if ifdef'ed off. from mysql-5.0.75 source (mysql-5.0.75.tar.gz) in the file libmysqld/sql_parse.cc this source code

Re: [Full-disclosure] [Rumor] SSH 0-day

2009-07-08 Thread frank^2
On Wed, Jul 8, 2009 at 1:58 PM, Anderson Kaiseralpkai...@gmail.com wrote: 2009/7/8 Martin Spinassi martins.li...@gmail.com: Hi list, I've been reading around (openssh mailing list, some forums, etc.) a rumor about a 0-day exploit in openssh. Does anybody knows if there is *really* something