BugTraq Mode:
(Page 822 of 1748)  < Prev  817 818 819 820 821 822 823 824 825 826 827  Next >
AW: MS Office 2007: Digital Signature does not protect Meta-Data 2007-12-13
Naujoks, Hans-Dietmar (Hans-Dietmar Naujoks tuev-sued de)
Dear Mr. Poehls,

I think Microsoft does not consider metadata attached to a document as part of the document and so they decided not to include it in the content protected by the certificate.

This fits the way we use attaching metadata during the process of categorization to enable retrieval of a

[ more ]  [ reply ]
SQL MKPortal M1.1 Rc1 2007-12-12
Sw33t h4cK3r hotmail com
: Discovery by: Sw33t h4cK3r

: POWERED BY: MKPortal M1.1

-----------

Exploit :

http://Example.com/index.php?ind=gallery&op=foto_show&ida=(sql)

[ more ]  [ reply ]
OpenOffice: Duplicated, Unprotected Certificate Information shown in Signed ODF Documents 2007-12-13
poehls informatik uni-hamburg de
Affects: OpenOffice 2.3.0 and 2.2.0 and possibly older versions

I. Background

OpenOffice is a opensource suite containing several programs to

handle Office documents like text documents or spreadsheets.

The latest version uses an XML based document format (ODF).

OpenOffice allows docum

[ more ]  [ reply ]
Fwd: Websense 6.3.1 Filtering Bypass 2007-12-12
The Security Community (thesecuritycommunity gmail com)
Mr. HinkyDink would like to share the following with the Security Community...

---------- Forwarded message ----------
From: <dink (at) mrhinkydink (dot) com [email concealed]>
Date: Dec 12, 2007 6:05 PM
Subject: Websense 6.3.1 Filtering Bypass
To: thesecuritycommunity (at) gmail (dot) com [email concealed]

Please share this with your little friends..

[ more ]  [ reply ]
RE: [Full-disclosure] Fwd: Websense 6.3.1 Filtering Bypass 2007-12-13
Hubbard, Dan (dhubbard websense com)
An added note on this...

Customers do not need to download nor install any new patch for this
fix. It was automatically updated and installed with our nightly
protocol signature updates.

-----Original Message-----
From: full-disclosure-bounces (at) lists.grok.org (dot) uk [email concealed]
[mailto:full-disclosure-bounce

[ more ]  [ reply ]
MS Office 2007: Target of Hyperlinks not covered by Digital Signatures 2007-12-13
poehls informatik uni-hamburg de
Affects: Microsoft Office 2007 (12.0.6015.5000)

MSO (12.0.6017.5000)

possibly older versions

I. Background

Microsoft Office is a suite containing several programs to

handle Office documents like text documents or spreadsheets.

The latest version uses an XML based doc

[ more ]  [ reply ]
[security bulletin] HPSBUX02296 SSRT071504 rev.1 - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code 2007-12-13
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01299773
Version: 1

HPSBUX02296 SSRT071504 rev.1 - HP-UX Running OpenSSL, Remote Execution of Arbitrary Code

NOTICE: The information in this Security Bulletin should be acted upon as soon as pos

[ more ]  [ reply ]
[security bulletin] HPSBUX02294 SSRT071451 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS) 2007-12-13
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01294212
Version: 1

HPSBUX02294 SSRT071451 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

[ more ]  [ reply ]
Hosting Controller - Multiple Security Bugs (Extremely Critical) 2007-12-13
admin bugreport ir
Title: Multiple Security Bugs In Hosting Controller

Critical: Extremely critical

Impact: Full system administrator access

Vendor: Hosting Controller

Version: 6.1 Hot fix <= 3.3

Vendor URL: www.hostingcontroller.com

Solution: N/A From company - There is temporary solution in this report

Exploi

[ more ]  [ reply ]
[USN-550-3] Cairo regression 2007-12-13
Kees Cook (kees ubuntu com)
===========================================================
Ubuntu Security Notice USN-550-3 December 13, 2007
libcairo regression
https://launchpad.net/bugs/175573
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu

[ more ]  [ reply ]
QK SMTP Server 3 - Denial of service 2007-12-12
jplopezy gmail com
Apparently this SMTP server crashes when creating a mail poorly trained causing a denial of service.

Proof-of-concept

HELO ../A/ * 950

MAIL FROM: ../A/ * 950

RCPT TO: ../A/ * 950

data

../A/ * 950

.

Juan Pablo Lopez Yacubian

http://fuzzertina.blogspot.com/

[ more ]  [ reply ]
iDefense Security Advisory 12.11.07: Microsoft DirectX 7 and 8 DirectShow Stack Buffer Overflow Vulnerability 2007-12-12
iDefense Labs (labs-no-reply idefense com)
iDefense Security Advisory 12.11.07
http://labs.idefense.com/intelligence/vulnerabilities/
Dec 11, 2007

I. BACKGROUND

Microsoft DirectShow, part of Microsoft DirectX, is used for the capture
and playback of multimedia streams on Microsoft Windows systems.
Synchronized Accessible Media Interchange

[ more ]  [ reply ]
rPSA-2007-0264-1 mod_dav_svn subversion 2007-12-12
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2007-0264-1
Published: 2007-12-12
Products:
rPath Linux 1

Rating: Minor
Exposure Level Classification:
Remote User Deterministic Information Exposure
Updated Versions:
mod_dav_svn=conary.rpath.com@rpl:1/1.2.3-8.1-1
subversion=conary.rpath.com@rpl:1/1.2.3-8.1

[ more ]  [ reply ]
Re: Re: Cpanel Vulnerability? 2007-12-12
gdfuego gmail com
I would guess someone is trying to hide a phishing page in a frontpage looking folder rather than it actually being a frontpage issue.

[ more ]  [ reply ]
iDefense Security Advisory 12.11.07: Microsoft Internet Explorer JavaScript setExpression Heap Corruption Vulnerability 2007-12-12
iDefense Labs (labs-no-reply idefense com)
iDefense Security Advisory 12.11.07
http://labs.idefense.com/intelligence/vulnerabilities/
Dec 11, 2007

I. BACKGROUND

Internet Explorer is a graphical web browser developed by Microsoft
Corp. and included as part of Microsoft Windows since 1995. The
setExpression method is commonly used to assign

[ more ]  [ reply ]
Re: Media Player Classic 6.4.9 MP4 Stack Overflow 0-day 2007-12-12
Matthew Leeds (mleeds theleeds net)
Just to rehash this for my own clarity, and perhaps that of others, this is not a defect in Media Player Classic so much as a defect in the 3ivx codec. If one were to use a different codec to decode MP4 content this defect would not exist.

This is similar to a defect in Adobe Acrobat Reader browser

[ more ]  [ reply ]
Re: Cpanel Vulnerability? 2007-12-12
Charles Hardin (fonestorm gmail com)
Trying this again since the lists apparently do not like me.

This would sound more like an issue in frontpage extensions than cpanel itself.

On Dec 12, 2007 8:16 AM, Francisco Pecorella <pecorelf (at) gmail (dot) com [email concealed]> wrote:
> Folks,
>
> I have been seen some phishings installed in servers with
> cPanel11/We

[ more ]  [ reply ]
Re: TCP Port randomization paper 2007-12-11
Fernando Gont (fernando gont gmail com)
Hello, Amit,

> However, it seems that your proposal only attempts to address one consequence of
> predictable TCP source ports, namely blind TCP attacks (in all fairness, it appears that the
> object of your proposal is to solve the blind TCP attacks, rather than the issue of predictable
> TCP sour

[ more ]  [ reply ]
MS Office 2007: Digital Signature does not protect Meta-Data 2007-12-12
poehls informatik uni-hamburg de


Affects: Microsoft Office 2007 (12.0.6015.5000)

MSO (12.0.6017.5000)

possibly older versions

I. Background

Microsoft Office is a suite containing several programs to

handle Office documents like text documents or spreadsheets.

The latest version uses an XML based d

[ more ]  [ reply ]
[SECURITY] [DSA 1428-2] New Linux 2.6.18 packages fix several vulnerabilities 2007-12-12
dann frazier (dannf debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 1428-2 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ dann frazier
December 11th, 2007

[ more ]  [ reply ]
Cpanel Vulnerability? 2007-12-12
Francisco Pecorella (pecorelf gmail com)
Folks,

I have been seen some phishings installed in servers with
cPanel11/WebHostManager but installed on folders like _vti_cnf,
_private, etc.

Do you know about a new exploit for cPanel 11/WHM or a new
vulnerability to gain control over those servers?

--
Regards,
FP

[ more ]  [ reply ]
[ MDKSA-2007:244 ] - Updated samba packages fix vulnerability 2007-12-12
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2007:244
http://www.mandriva.com/security/
____________________________________________________________________

[ more ]  [ reply ]
[SECURITY] [DSA 1430-1] New libnss-ldap packages fix denial of service 2007-12-11
Steve Kemp (skx debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-1430-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Steve Kemp
December 11, 2007

[ more ]  [ reply ]
[SECURITY] [DSA 1431-1] New ruby-gnome2 packages fix execution of arbitrary code 2007-12-11
Steve Kemp (skx debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-1431-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Steve Kemp
December 11, 2007

[ more ]  [ reply ]
ZDI-07-076: Microsoft Windows Message Queuing Service Stack Overflow Vulnerability 2007-12-11
zdi-disclosures 3com com
ZDI-07-076: Microsoft Windows Message Queuing Service Stack Overflow

Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-07-076.html

December 11, 2007

-- CVE ID:

CVE-2007-3039

-- Affected Vendor:

Microsoft

-- Affected Products:

Windows 2000 SP4

Windows XP SP2

-- Tipping

[ more ]  [ reply ]
ZDI-07-075: Microsoft Internet Explorer Element Tags Vulnerability 2007-12-11
zdi-disclosures 3com com
ZDI-07-075: Microsoft Internet Explorer Element Tags Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-07-075.html

December 11, 2007

-- CVE ID:

CVE-2007-5344

-- Affected Vendor:

Microsoft

-- Affected Products:

Internet Explorer 6

Internet Explorer 7

-- TippingPoint(TM)

[ more ]  [ reply ]
[SECURITY] [DSA 1429-1] New htdig packages fix cross site scripting 2007-12-11
Steve Kemp (skx debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-1429-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Steve Kemp
December 11, 2007

[ more ]  [ reply ]
ZDI-07-074: Microsoft Internet Explorer Node Manipulation Memory Corruption 2007-12-11
zdi-disclosures 3com com
ZDI-07-074: Microsoft Internet Explorer Node Manipulation Memory

Corruption Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-07-074.html

December 11, 2007

-- CVE ID:

CVE-2007-3903

-- Affected Vendor:

Microsoft

-- Affected Products:

Internet Explorer 6

Internet Explorer

[ more ]  [ reply ]
ZDI-07-073: Microsoft Internet Explorer setExpression Vulnerability 2007-12-11
zdi-disclosures 3com com
ZDI-07-073: Microsoft Internet Explorer setExpression Code Execution

Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-07-073.html

December 11, 2007

-- CVE ID:

CVE-2007-3902

-- Affected Vendor:

Microsoft

-- Affected Products:

Internet Explorer 5.01 SP4

Internet Explorer

[ more ]  [ reply ]
Meridian Prolog Manager Username and Plain Text Password Disclosure 2007-12-11
Prolog Error (prolog disclosure gmail com)
+Note: This is being released without Meridian or CERT approval.
Meridian has been dragging their feet and has shown no good intent
since I first tried to contact them. My guess is that they will be
following all of my releases claiming I was uncooperative. The only
information Meridian ever soug

[ more ]  [ reply ]
(Page 822 of 1748)  < Prev  817 818 819 820 821 822 823 824 825 826 827  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus