|
Colapse all |
Post message
[FLSA-2006:164512] Updated fetchmail packages fix security issues 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) SQL-Injection in e107 allows attacker to become a site admininstrator 2006-05-13 socsam linuxmail org Gphotos Directory Traversal and Cross Site Scripting 2006-05-13 doz bsdmail com Details The first vulnerability issue is due to an input validation error in "index.php" "diapo.php" and "affich.php" scripts that do not validate "rep","image" variables, which may be exploited to cross site scripting attacks. http://traget/index.php?rep=[xss] http://traget/diapo.php?rep=[ [ more ] [ reply ] [FLSA-2006:152923] Updated xloadimage package fixes security issues 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) RE: How secure is software X? 2006-05-12 Ferguson, Justin (IARC) (FergusonJ nv doe gov) (1 replies) David, One thing you have to keep in mind is that a lot of things are incredibly variable when dealing with this subject. For instance, suppose you want to ensure that the URI in a web server is not overflowable. So you test with something like GET /[AAAAAAAAA x 4096] HTTP/1.1 Host: foobar.com Con [ more ] [ reply ] [FLSA-2006:185355] Updated gnupg package fixes security issues 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) Buffer-overflow and NULL pointer crash in Genecys 0.2 2006-05-12 Luigi Auriemma (aluigi autistici org) [FLSA-2006:152898] Updated emacs packages fix a security issue 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) [FLSA-2006:152904] Updated ncpfs package fixes security issues 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) [FLSA-2006:152868] Updated tetex packages fix security issues 2006-05-13 Marc Deslauriers (marcdeslauriers videotron ca) Dovecot IMAP: Mailbox names list disclosure with mboxes 2006-05-12 Timo Sirainen (tss iki fi) Giving "1 LIST .. *" IMAP command allows the user to see all files and directories under the mbox root's parent directory, so potentially you could see other users' mailbox names. Nothing can be done with them though, so it's not possible to read or modify them. There are also some other less than [ more ] [ reply ] SEC Consult SA-20060512-0 :: Symantec Enterprise Firewall NAT/HTTP Proxy Private IP Exposure 2006-05-12 Bernhard Mueller (research sec-consult com) PHPBB 2.0.20 persistent issues with avatars 2006-05-12 rgod autistici org PHPBB 2.0.20 multiple issues with avatars some problems persistently lie in the way it handles remote and uploaded avatars: a remote user can: (1) saturate the server with unuseful files, 'cause phpbb do not delete the previous one when you upload a new avatar (2) use PhpBB installatio [ more ] [ reply ] |
|
Privacy Statement |
Fedora Legacy Update Advisory
Synopsis: Updated fetchmail packages fix security issues
Advisory ID: FLSA:164512
Issue date: 2006-05-12
Product: Red Hat Linux, Fedora Core
Keywords:
[ more ] [ reply ]