[Full-disclosure] [SECURITY] [DSA 2663-1] tinc security update

2013-04-22 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2663-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez April 22, 2013

[Full-disclosure] Vulnerabilities in multiple plugins for WordPress with jPlayer

2013-04-22 Thread MustLive
Hello list! I want to inform you about multiple vulnerabilities in multiple plugins for WordPress with jPlayer. These are Cross-Site Scripting and Content Spoofing and vulnerabilities. I've wrote about vulnerabilities in jPlayer earlier (http://seclists.org/fulldisclosure/2013/Apr/192). jPlayer

Re: [Full-disclosure] How do I contact Vodafone Security?

2013-04-22 Thread Jeffrey Walton
On Mon, Apr 22, 2013 at 9:10 AM, Jann Horn wrote: > does anyone know how I can contact Vodafone Security (preferably a > Germany-specific group because I have no idea whether the issue > affects people in other countries, too)? > > I sent a mail to secur...@vodafone.de and it didn't bounce (in cas

[Full-disclosure] [ MDVSA-2013:150 ] mysql

2013-04-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:150 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] [ MDVSA-2013:149 ] roundcubemail

2013-04-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:149 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] [ MDVSA-2013:148 ] roundcubemail

2013-04-22 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:148 http://www.mandriva.com/en/support/security/ __

Re: [Full-disclosure] 0day Vulnerability in VLC (this is my first release of the vuln anywhere)

2013-04-22 Thread kaveh ghaemmaghami
That was my mistake (publicly disclosure issues before notifying to the vendor ) hope you don't wanna experience my mistake you can also report to v...@secunia.com for your discovery and coordination on your behalf Regards Kaveh On Mon, Apr 22, 2013 at 7:18 PM, Henri Salo wrote: > On Mon, Apr 2

Re: [Full-disclosure] 0day Vulnerability in VLC (this is my first release of the vuln anywhere)

2013-04-22 Thread Henri Salo
On Mon, Apr 22, 2013 at 07:31:07AM -0400, jay van wrote: > if VLC media player is launched in QT mode and the user is on windows NT > (any version of windows so far as tested) connected to the internet there > is a vulnerability in the handling of unicast packets. The Proof of concept > code is in

[Full-disclosure] 0day Vulnerability in VLC (this is my first release of the vuln anywhere)

2013-04-22 Thread jay van
if VLC media player is launched in QT mode and the user is on windows NT (any version of windows so far as tested) connected to the internet there is a vulnerability in the handling of unicast packets. The Proof of concept code is in development and should be ready for publishing within the next 2

[Full-disclosure] How do I contact Vodafone Security?

2013-04-22 Thread Jann Horn
Hello, does anyone know how I can contact Vodafone Security (preferably a Germany-specific group because I have no idea whether the issue affects people in other countries, too)? I sent a mail to secur...@vodafone.de and it didn't bounce (in case someone from Vodafone is reading this: it was sent

[Full-disclosure] NoSuchCon 2013, Paris (France), May 15th-17 th

2013-04-22 Thread NoSuchCon
Hello list, It is a real pleasure to announce the final & exceptional lineup for NoSuchCon 2013, which will happen in Paris next month. Thank you to all of you who submitted this year – we had a hard time selecting top notch content only, as we have been overwhelmed with quality research p

[Full-disclosure] Coliseum101 - Security Conferences Calendar

2013-04-22 Thread Nahuel Grisolia
Hi all! I would like to introduce you to `Coliseum101 - Security Conferences Calendar´. The URL is: http://coliseum101.com You'll find the best -well known- security conferences around the globe, with some additional info about them, etc. There's a place for sponsors too, so just shoot me an

[Full-disclosure] 44Café Tuesday 23rd April, Earls Court London - What to expect

2013-04-22 Thread Steve
44Café: The vendor-free event returns tomorrow! 44Café is the free vendor-free one-day event taking place upstairs at O'Neill's, 326 Earl's Court Road, London on the 23rd of April. We'll have talks, beer and free bacon butties to give away. If you're tired of vendors at the main exhibitio

Re: [Full-disclosure] VUPEN Security Research - Adobe Flash Player RTMP Data Processing Object Confusion (CVE-2013-2555)

2013-04-22 Thread Benji
It was a perfect example of a largely deployed application which utilises security engineers, and has pushed patches/code which was ineffective. My point was that bugs like that are a lot easier to sort in a design or development stage than after the fact when remediation time is tight, and that

[Full-disclosure] [SE-2012-01] Yet another Reflection API flaw affecting Oracle's Java SE

2013-04-22 Thread Security Explorations
Hello All, Today, a vulnerability report with an accompanying Proof of Concept code was sent to Oracle notifying the company of a new security weakness affecting Java SE 7 software. The new flaw was verified to affect all versions of Java SE 7 (including the recently released 1.7.0_21-b11). It