|
Prev week |
Colapse all |
Post message
AW: MS Office 2007: Digital Signature does not protect Meta-Data 2007-12-13 Naujoks, Hans-Dietmar (Hans-Dietmar Naujoks tuev-sued de) OpenOffice: Duplicated, Unprotected Certificate Information shown in Signed ODF Documents 2007-12-13 poehls informatik uni-hamburg de Affects: OpenOffice 2.3.0 and 2.2.0 and possibly older versions I. Background OpenOffice is a opensource suite containing several programs to handle Office documents like text documents or spreadsheets. The latest version uses an XML based document format (ODF). OpenOffice allows docum [ more ] [ reply ] Fwd: Websense 6.3.1 Filtering Bypass 2007-12-12 The Security Community (thesecuritycommunity gmail com) Mr. HinkyDink would like to share the following with the Security Community... ---------- Forwarded message ---------- From: <dink (at) mrhinkydink (dot) com [email concealed]> Date: Dec 12, 2007 6:05 PM Subject: Websense 6.3.1 Filtering Bypass To: thesecuritycommunity (at) gmail (dot) com [email concealed] Please share this with your little friends.. [ more ] [ reply ] RE: [Full-disclosure] Fwd: Websense 6.3.1 Filtering Bypass 2007-12-13 Hubbard, Dan (dhubbard websense com) An added note on this... Customers do not need to download nor install any new patch for this fix. It was automatically updated and installed with our nightly protocol signature updates. -----Original Message----- From: full-disclosure-bounces (at) lists.grok.org (dot) uk [email concealed] [mailto:full-disclosure-bounce [ more ] [ reply ] MS Office 2007: Target of Hyperlinks not covered by Digital Signatures 2007-12-13 poehls informatik uni-hamburg de [security bulletin] HPSBUX02296 SSRT071504 rev.1 - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code 2007-12-13 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01299773 Version: 1 HPSBUX02296 SSRT071504 rev.1 - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code NOTICE: The information in this Security Bulletin should be acted upon as soon as pos [ more ] [ reply ] [security bulletin] HPSBUX02294 SSRT071451 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS) 2007-12-13 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01294212 Version: 1 HPSBUX02294 SSRT071451 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. [ more ] [ reply ] Hosting Controller - Multiple Security Bugs (Extremely Critical) 2007-12-13 admin bugreport ir Title: Multiple Security Bugs In Hosting Controller Critical: Extremely critical Impact: Full system administrator access Vendor: Hosting Controller Version: 6.1 Hot fix <= 3.3 Vendor URL: www.hostingcontroller.com Solution: N/A From company - There is temporary solution in this report Exploi [ more ] [ reply ] [USN-550-3] Cairo regression 2007-12-13 Kees Cook (kees ubuntu com) =========================================================== Ubuntu Security Notice USN-550-3 December 13, 2007 libcairo regression https://launchpad.net/bugs/175573 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu [ more ] [ reply ] iDefense Security Advisory 12.11.07: Microsoft DirectX 7 and 8 DirectShow Stack Buffer Overflow Vulnerability 2007-12-12 iDefense Labs (labs-no-reply idefense com) iDefense Security Advisory 12.11.07 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 11, 2007 I. BACKGROUND Microsoft DirectShow, part of Microsoft DirectX, is used for the capture and playback of multimedia streams on Microsoft Windows systems. Synchronized Accessible Media Interchange [ more ] [ reply ] rPSA-2007-0264-1 mod_dav_svn subversion 2007-12-12 rPath Update Announcements (announce-noreply rpath com) rPath Security Advisory: 2007-0264-1 Published: 2007-12-12 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Remote User Deterministic Information Exposure Updated Versions: mod_dav_svn=conary.rpath.com@rpl:1/1.2.3-8.1-1 subversion=conary.rpath.com@rpl:1/1.2.3-8.1 [ more ] [ reply ] iDefense Security Advisory 12.11.07: Microsoft Internet Explorer JavaScript setExpression Heap Corruption Vulnerability 2007-12-12 iDefense Labs (labs-no-reply idefense com) iDefense Security Advisory 12.11.07 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 11, 2007 I. BACKGROUND Internet Explorer is a graphical web browser developed by Microsoft Corp. and included as part of Microsoft Windows since 1995. The setExpression method is commonly used to assign [ more ] [ reply ] Re: Media Player Classic 6.4.9 MP4 Stack Overflow 0-day 2007-12-12 Matthew Leeds (mleeds theleeds net) Just to rehash this for my own clarity, and perhaps that of others, this is not a defect in Media Player Classic so much as a defect in the 3ivx codec. If one were to use a different codec to decode MP4 content this defect would not exist. This is similar to a defect in Adobe Acrobat Reader browser [ more ] [ reply ] Re: Cpanel Vulnerability? 2007-12-12 Charles Hardin (fonestorm gmail com) Trying this again since the lists apparently do not like me. This would sound more like an issue in frontpage extensions than cpanel itself. On Dec 12, 2007 8:16 AM, Francisco Pecorella <pecorelf (at) gmail (dot) com [email concealed]> wrote: > Folks, > > I have been seen some phishings installed in servers with > cPanel11/We [ more ] [ reply ] Re: TCP Port randomization paper 2007-12-11 Fernando Gont (fernando gont gmail com) Hello, Amit, > However, it seems that your proposal only attempts to address one consequence of > predictable TCP source ports, namely blind TCP attacks (in all fairness, it appears that the > object of your proposal is to solve the blind TCP attacks, rather than the issue of predictable > TCP sour [ more ] [ reply ] MS Office 2007: Digital Signature does not protect Meta-Data 2007-12-12 poehls informatik uni-hamburg de [SECURITY] [DSA 1428-2] New Linux 2.6.18 packages fix several vulnerabilities 2007-12-12 dann frazier (dannf debian org) [SECURITY] [DSA 1430-1] New libnss-ldap packages fix denial of service 2007-12-11 Steve Kemp (skx debian org) [SECURITY] [DSA 1431-1] New ruby-gnome2 packages fix execution of arbitrary code 2007-12-11 Steve Kemp (skx debian org) ZDI-07-076: Microsoft Windows Message Queuing Service Stack Overflow Vulnerability 2007-12-11 zdi-disclosures 3com com ZDI-07-075: Microsoft Internet Explorer Element Tags Vulnerability 2007-12-11 zdi-disclosures 3com com [SECURITY] [DSA 1429-1] New htdig packages fix cross site scripting 2007-12-11 Steve Kemp (skx debian org) ZDI-07-074: Microsoft Internet Explorer Node Manipulation Memory Corruption 2007-12-11 zdi-disclosures 3com com ZDI-07-074: Microsoft Internet Explorer Node Manipulation Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-07-074.html December 11, 2007 -- CVE ID: CVE-2007-3903 -- Affected Vendor: Microsoft -- Affected Products: Internet Explorer 6 Internet Explorer [ more ] [ reply ] ZDI-07-073: Microsoft Internet Explorer setExpression Vulnerability 2007-12-11 zdi-disclosures 3com com ZDI-07-073: Microsoft Internet Explorer setExpression Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-07-073.html December 11, 2007 -- CVE ID: CVE-2007-3902 -- Affected Vendor: Microsoft -- Affected Products: Internet Explorer 5.01 SP4 Internet Explorer [ more ] [ reply ] Meridian Prolog Manager Username and Plain Text Password Disclosure 2007-12-11 Prolog Error (prolog disclosure gmail com) +Note: This is being released without Meridian or CERT approval. Meridian has been dragging their feet and has shown no good intent since I first tried to contact them. My guess is that they will be following all of my releases claiming I was uncooperative. The only information Meridian ever soug [ more ] [ reply ] |
|
Privacy Statement |
I think Microsoft does not consider metadata attached to a document as part of the document and so they decided not to include it in the content protected by the certificate.
This fits the way we use attaching metadata during the process of categorization to enable retrieval of a
[ more ] [ reply ]