[Full-disclosure] [USN-851-1] Elinks vulnerabilities

2009-10-21 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-851-1 October 21, 2009 elinks vulnerabilities CVE-2006-5925, CVE-2008-7224 === A security issue affects the following Ubuntu releases: Ubuntu 6.

[Full-disclosure] [USN-850-1] poppler vulnerabilities

2009-10-21 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-850-1 October 21, 2009 poppler vulnerabilities CVE-2009-0755, CVE-2009-3603, CVE-2009-3604, CVE-2009-3605, CVE-2009-3607, CVE-2009-3608, CVE-2009-3609 ===

[Full-disclosure] [ MDVSA-2009:286 ] ocaml-camlimages

2009-10-21 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:286 http://www.mandriva.com/security/

Re: [Full-disclosure] McKesson Horizon Clinical Infrastructure (HCI) version 7.6/7.8/10.0/10.1 hardcoded passwords

2009-10-21 Thread Shawn Merdinger
Hi Michael, On Wed, Oct 21, 2009 at 9:36 AM, Michael Krymson wrote: > Oh shit, account...@mckesson.com bounced, too! That must mean they don't > even have any accounting! Hehe...who knows? Maybe you needed to do @internal.mckesson.com ;-P Bringing this back to the issue at hand, a security POC

Re: [Full-disclosure] McKesson Horizon Clinical Infrastructure (HCI) version 7.6/7.8/10.0/10.1 hardcoded passwords

2009-10-21 Thread Michael Krymson
Oh shit, account...@mckesson.com bounced, too! That must mean they don't even have any accounting! Your discovery made a healthcare IT 'news' site. Maybe if you ask nicely, this 'mover and shaker' with the too-busy blog will grace us with his technical debunking of this issue! http://histalk2.com

[Full-disclosure] Adobe Acrobat Reader up to 9.1.1 ONLY Linux integer overflow to heap overflow.

2009-10-21 Thread Adam Zabrocki
Vulnerability like in topic (connected with vulns in xpdf). More details available here: http://blog.pi3.com.pl/?p=19 Best regards, Adam Zabrocki ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Ho

[Full-disclosure] turbodiff v1.01 beta released

2009-10-21 Thread Nicolas A. Economou
Turbodiff is a high-performance IDA plugin designed to detect differences between executable binaries. It works on architectures supported by IDA 4.9 FREE, IDA 5.0 through 5.5. Turbodiff was developed by Nicolas A. Economou, from the Exploit Writers Team of Core Security Technologies. The tool's

Re: [Full-disclosure] milw0rm

2009-10-21 Thread VeNoMouS
We are aware there is a major backlog/delay and we are attempting to do something about that at the moment... - VeNoMouS -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of xsr Sent: Tuesday, 20 October 2009 9: