[Full-disclosure] Medium severity flaw in QNX Neutrino RTOS

2011-03-11 Thread Tim Brown
I was recently taking a look at the state of play regarding the security of POSIX runtime linkers and was pointed at the QNX Neutrino RTOS to take a look. In doing so I noticed a problem relating to the way that it handles LD_DEBUG_OUTPUT which allows for the creation or overwriting of an

[Full-disclosure] DC4420 - London DEFCON - March meet - Tuesday 22nd March 2011

2011-03-11 Thread Major Malfunction
Another 22nd! How spooky is that? If I were a gambling man, I'd be betting on horse number 22 coming in 2nd in the 2nd race... or something and while we're on the subject of unlikely things, who says there's no such thing as free beer? Yes, this month we've found not one but two

[Full-disclosure] [USN-1087-1] libvpx vulnerability

2011-03-11 Thread Micah Gersten
=== Ubuntu Security Notice USN-1087-1March 11, 2011 libvpx vulnerability CVE-2010-4489 === A security issue affects the following Ubuntu releases: Ubuntu 10.10 This