[Full-disclosure] Dirtiest Web Sites of Summer 2009

2009-08-19 Thread Ivan .
http://safeweb.norton.com/dirtysites ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] iDefense Security Advisory 08.11.09: Multiple Vendor Microsoft ATL/MFC ActiveX Type Confusion Vulnerability

2009-08-19 Thread iDefense Labs
iDefense Security Advisory 08.11.09 http://labs.idefense.com/intelligence/vulnerabilities/ Aug 11, 2009 I. BACKGROUND Microsoft's Component Object Model (COM) was designed to allow interoperability between disjointed software components. It is a standardized interface solution to the programming

[Full-disclosure] [Bkis-11-2009] ProShow Gold Buffer Overflow Vulnerabilities

2009-08-19 Thread Bkis
[Bkis-11-2009] ProShow Gold Buffer Overflow Vulnerabilities 1. General Information ProShow Gold is a software allowing you easily create photo and video slide shows on DVD, PC and Web. Recently, Bkis has just detected vulnerabilities in the software related to the processing of ProShow Slidesh

[Full-disclosure] iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Information Disclosure Vulnerability

2009-08-19 Thread iDefense Labs
iDefense Security Advisory 07.28.09 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 28, 2009 I. BACKGROUND Microsoft's Component Object Model (COM) was designed to allow interoperability between disjointed software components. It is a standardized interface solution to the programming

[Full-disclosure] iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Security Bypass Vulnerability

2009-08-19 Thread iDefense Labs
iDefense Security Advisory 07.28.09 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 28, 2009 I. BACKGROUND Microsoft's Component Object Model (COM) was designed to allow interoperability between disjointed software components. It is a standardized interface solution to the programming

Re: [Full-disclosure] [SECURITY] [DSA 1870-1] New pidgin packages fix arbitrary code execution

2009-08-19 Thread Nico Golde
Hi, * Nico Golde [2009-08-20 03:28]: > -- > Debian Security Advisory DSA-1870-1secur...@debian.org > http://www.debian.org/security/ Nico Golde > August 19th, 2009

[Full-disclosure] [SECURITY] [DSA 1870-1] New pidgin packages fix arbitrary code execution

2009-08-19 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1870-1secur...@debian.org http://www.debian.org/security/ Nico Golde August 19th, 2009

[Full-disclosure] [SECURITY] [DSA 1869-1] New curl packages fix SSL certificate verification weakness

2009-08-19 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1869-1secur...@debian.org http://www.debian.org/security/ Nico Golde August 19th, 2009

[Full-disclosure] [USN-809-1] GnuTLS vulnerabilities

2009-08-19 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-809-1August 19, 2009 gnutls12, gnutls13, gnutls26 vulnerabilities CVE-2009-2409, CVE-2009-2730, https://launchpad.net/bugs/305264 === A securit

[Full-disclosure] [ MDVSA-2009:207 ] perl-Compress-Raw-Bzip2

2009-08-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:207 http://www.mandriva.com/security/

[Full-disclosure] iDefense Security Advisory 08.11.09: Microsoft Office Web Components 2000 Buffer Overflow Vulnerability

2009-08-19 Thread iDefense Labs
iDefense Security Advisory 08.11.09 http://labs.idefense.com/intelligence/vulnerabilities/ Aug 11, 2009 I. BACKGROUND Office Web Components is a group of ActiveX controls that can be used to view and edit Microsoft Office files such as spreadsheets and charts. It is commonly used to allow a user

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-19 Thread D-vice
stop feeding the fucking troll!! On 8/19/09, Exibar wrote: > That's ashame if he has bad bones perhaps if he drank more milk that > would help. MY mom always said "Drink milk, it builds strong bones". > > This statement just confused me, what are you trying to say here? > > " let it

[Full-disclosure] Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability

2009-08-19 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability Advisory ID: cisco-sa-20090819-fwsm http://www.cisco.com/warp/public/707/cisco-sa-20090819-fwsm.shtml Revision 1.0 For Public Release 2009 August 19 1600 UTC (GMT

Re: [Full-disclosure] False statements made about security researcher n3td3v

2009-08-19 Thread Exibar
That's ashame if he has bad bones perhaps if he drank more milk that would help. MY mom always said "Drink milk, it builds strong bones". This statement just confused me, what are you trying to say here? " let it be now don't pretend of him as a black hat for your entertainment"

[Full-disclosure] [IVIZ-09-005] CA HIPS Remote Kernel Vulnerability

2009-08-19 Thread iViZ Security Advisory
--- [ iViZ Security Advisory 09-00519/08/2009 ] --- iViZ Techno Solutions

[Full-disclosure] [USN-802-2] Apache regression

2009-08-19 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-802-2August 19, 2009 apache2 regression https://launchpad.net/bugs/409987 === A security issue affects the following Ubuntu releases: Ubuntu 6

[Full-disclosure] [SECURITY] [DSA 1868-1] New kde4libs packages fix several vulnerabilities

2009-08-19 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1868-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris August 19, 2009

[Full-disclosure] [SECURITY] [DSA 1867-1] New kdelibs packages fix several vulnerabilities

2009-08-19 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1867-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris August 19, 2009

[Full-disclosure] Kaspersky AV/IS 2010 (avp.exe) Denial-of-Service

2009-08-19 Thread Maksymilian Arciemowicz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [ Kaspersky AV/IS 2010 (avp.exe) Denial-of-Service ] Author: Maksymilian Arciemowicz http://SecurityReason.com Date: - - Dis.: 10.07.2009 - - Pub.: 19.08.2009 Risk: Medium Affected Software (tested): - - Kaspersky Internet Security 2010 9.0.0.459 (

[Full-disclosure] ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities

2009-08-19 Thread ZDI Disclosures
ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-09-059 -- CVE ID: CVE-2009-1978 -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Details: This vulnerability a

[Full-disclosure] ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vulnerability

2009-08-19 Thread ZDI Disclosures
ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-058 -- CVE ID: CVE-2009-1977 -- Affected Vendors: Oracle -- Affected Products: Oracle Secure Backup -- Vulnerability Details: This vulnerability allows r

[Full-disclosure] rPSA-2009-0121-1 kernel open-vm-tools

2009-08-19 Thread rPath Update Announcements
rPath Security Advisory: 2009-0121-1 Published: 2009-08-18 Products: rPath Appliance Platform Linux Service 1 rPath Appliance Platform Linux Service 2 rPath Linux 2 Rating: Minor Exposure Level Classification: Local Root Deterministic Unauthorized Access Updated Versions: kerne

[Full-disclosure] rPSA-2009-0119-1 apr apr-util

2009-08-19 Thread rPath Update Announcements
rPath Security Advisory: 2009-0119-1 Published: 2009-08-18 Products: rPath Appliance Platform Linux Service 1 rPath Appliance Platform Linux Service 2 rPath Linux 1 rPath Linux 2 Rating: Severe Exposure Level Classification: Remote Deterministic Denial of Service Updated Versio

[Full-disclosure] rPSA-2009-0118-1 mod_dav_svn subversion

2009-08-19 Thread rPath Update Announcements
rPath Security Advisory: 2009-0118-1 Published: 2009-08-18 Products: rPath Linux 2 Rating: Major Exposure Level Classification: Remote System User Deterministic Denial of Service Updated Versions: mod_dav_svn=conary.rpath@rpl:2/1.4.6-2.2-1 subversion=conary.rpath@rpl:2/1.4.