|
Colapse all |
Post message
[SECURITY] [DSA 906-1] New sylpheed packages fix arbitrary code execution 2005-11-22 joey infodrom org (Martin Schulze) Gadu-Gadu several vulnerabilities (version <= 7.20) 2005-11-21 Jaroslaw Sajko (sloik man poznan pl) 21/11/05 Gadu-Gadu instant messenger several vulnerabilities I. INTRODUCTION During the preparation of the materials about instant messengers security for the security conference we have checked current state of the Gadu-Gadu (http://www.gadu-gadu.pl) security. There was discovered a several new [ more ] [ reply ] Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability 2005-11-21 securityadvisory computerterrorism com [SECURITY] [DSA 904-1] New netpbm packages fix arbitrary code execution 2005-11-21 joey infodrom org (Martin Schulze) [SECURITY] [DSA 903-1] New unzip packages fix unauthorised permissions modification 2005-11-21 joey infodrom org (Martin Schulze) [SECURITY] [DSA 900-2] New fetchmail packages fix potential information leak 2005-11-21 joey infodrom org (Martin Schulze) Google Search Appliance proxystylesheet Flaws 2005-11-21 H D Moore (sflist digitaloffense net) This document can be found online at: - http://metasploit.com/research/vulns/google_proxystylesheet/ Title: Google Search Appliance proxystylesheet Flaws Release Date: November 21, 2005 Patch Date: August 16, 2005 Reported Date: June 10, 2005 Vendor: Systems Affected: Google Mini Searc [ more ] [ reply ] Re: Work in Progress: FileZilla Server Terminal V0.9.4d Buffer Overflow 2005-11-21 inge henriksen booleansoft com /* FileZillaDoS.cpp FileZilla Server Terminal 0.9.4d DoS PoC by Inge Henriksen. Read the disclaimer at http://ingehenriksen.blogspot.com before using. Made to work with Microsoft(R) Visual C++(R), to use link "WS2_32.lib". */ #include "stdafx.h" #include <iostream> #include "Winsock2.h" #define BU [ more ] [ reply ] [SECURITY] [DSA 811-2] New common-lisp-controller packages fix arbitrary code injection 2005-11-21 joey infodrom org (Martin Schulze) [SECURITY] [DSA 902-1] New xmail packages fix arbitrary code execution 2005-11-21 joey infodrom org (Martin Schulze) cracking safes with thermal imaging 2005-11-21 Michal Zalewski (lcamtuf dione ids pl) Somewhat on the silly side of life, but some subscribers might find it amusing... and a subset of that subset may even find it relevant to their jobs (hopefully in risk management, but possibly in safe cracking): http://lcamtuf.coredump.cx/tsafe/ Cheers, /mz (pluggity plug) http://lcamtuf.core [ more ] [ reply ] Security Advisory: Struts Error Message Cross Site Scripting 2005-11-21 Irene Abezgauz (irene Hacktics com) Background ========== Struts is an open source framework for building web applications. The core of the Struts framework is a flexible control layer based on standard technologies such as Java Servlets, JavaBeans, resource bundles, and the Extensible Markup Language (XML). Struts can be used with di [ more ] [ reply ] Metro Olografix Crypto Meeting 2006 CFP 2005-11-20 Angelo Dell'Aera (buffer olografix org) Metro Olografix, an Italian no-profit association which has been working for spreading the knowledge of information technology and networking since 1994, is looking for high-quality speech submissions for the 2006 edition of the Metro Olografix CryptoMeeting (MOCM). The deadline is set on December [ more ] [ reply ] [TKADV2005-11-004] Multiple Cross Site Scripting vulnerabilities in phpMyFAQ 2005-11-19 tk trapkit de [security - exponentcms] 2005-11-19 Hans Wolters (hans wolters xs4all nl) A number of security issues have been discovered in ExponentCMS ------------------------------------------------------------------------ --------------------- Exponent is a fully-featured, modern CMS written in PHP, that enables non-technical people to manage and update their websites with minima [ more ] [ reply ] [ GLSA 200511-15 ] Smb4k: Local unauthorized file access 2005-11-18 Sune Kloppenborg Jeppesen (jaervosz gentoo org) MDKSA-2005:214 - Updated gdk-pixbuf/gtk+2.0 packages fix vulnerability 2005-11-18 Mandriva Security Team (security mandriva com) Mambo 0day Exploit out in the wild - mambo/skype hacked 2005-11-18 rebarz99 gmail com Mambo 0day Exploit out in the wild http://www.fnse.org/news.php http://share.skype.com/cache/main.htm http://mamboserver.com/modules/main.htm mambo server hacked by a philippine/filipino hacker - the great rebarz99 Hacked By Rebarz99 rebarz99 (at) gmail (dot) com [email concealed] Mabuhay ang Masang Pilipino! T [ more ] [ reply ] [SECURITY] [DSA 901-1] New gnump3d packages fix several vulnerabilities 2005-11-19 joey infodrom org (Martin Schulze) Google Base 2005-11-18 Petko Petkov (ppetkov gnucitizen org) OK, I need to start this subject since nobody else has discussed anything yet on the mailing list. Do you guys know about Google Base?: Google our big hacker friend that helps us to find malicious scripts and open proxies just like that. Well, Google has a new service: Google Base. And there are man [ more ] [ reply ] PHP-Fusion <= 6.00.206 Multiple Vulnerabilities 2005-11-18 r verton gmail com PHP-Fusion <= 6.00.206 Multiple Vulnerabilities =============================================== Software: PHP-Fusion <= 6.00.206 Severity: SQL Injection(s), Path disclosure Risk: High Author: Robin Verton <r.verton (at) gmail (dot) com [email concealed]> Date: Nov. 16 2005 Vendor: http://sourceforge.net/proj [ more ] [ reply ] Snagging Security Tokens to Elevate Privileges 2005-11-18 David Litchfield (davidl ngssoftware com) I've just put up a Database Security Brief; the first of many to come. http://www.databasesecurity.com/dbsec-briefs.htm It's called a brief because there's enough meat to make it interesting but not enough to make it a paper ;) This brief, Snagging Security Tokens to Elevate Privileges, details h [ more ] [ reply ] Secunia Research: Winmail Server Multiple Vulnerabilities 2005-11-18 Secunia Research (vuln secunia com) Secunia Research: MailEnable Buffer Overflow and DirectoryTraversal Vulnerabilities 2005-11-18 Secunia Research (vuln secunia com) [SECURITY] [DSA 900-1] New fetchmail packages fix potential information leak 2005-11-18 joey infodrom org (Martin Schulze) |
|
Privacy Statement |
Hash: SHA1
- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 906-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
November 22nd, 2005
[ more ] [ reply ]