|
Colapse all |
Post message
[CLA-2003:778] Conectiva Security Announcement - net-snmp 2003-11-07 Conectiva Updates (secure conectiva com br) SRT2003-11-06-0710 - IBM DB2 Multiple local security issues 2003-11-08 KF (dotslash snosoft com) Full details on this issue are available on our website. There will be no forced pdf files, and we have removed the java applet that so many of you complained about. Registration is still necessary for indepth detail on this issue. I have also attempted to stop the cross posting to the mailing l [ more ] [ reply ] [Full-Disclosure] [SECURITY] [DSA 397-1] New PostgreSQL packages fix buffer overflow 2003-11-07 debian-security-announce lists debian org PowerPortal v1.1b Cross-Site Scripting Vulnerability 2003-11-07 David Ferreira (iamroot systemsecure org) [CLA-2003:779] Conectiva Security Announcement - cups 2003-11-07 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : cups SUMMARY : Denial of service vulnerabilit [ more ] [ reply ] UPDATE: PSK Cracking using IKE Aggressive Mode 2003-11-06 Michael Thumann (mlthumann ids-guide de) Hi, we just release a Vulnerability scanner for the PSK Attack we've described in april in our paper 'PSK Cracking using IKE Aggressive Mode'. The scanner is freely available from our website: www.ernw.de/download/ikeprobe.zip The paper itself is available from our website too. Take a look at w [ more ] [ reply ] [CLA-2003:777] Conectiva Security Announcement - thttpd 2003-11-06 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : thttpd SUMMARY : Fixes for several vulnerabil [ more ] [ reply ] DoS for Ganglia 2003-11-06 Jim Prewett (download hpc unm edu) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The Center for High Performance Computing at UNM / Dopesquad Security Advisory Wed Nov 5 13:10:35 MST 2003 Discovery made by: James E. Prewett (download (at) hpc.unm (dot) edu [email concealed]) Product: Ganglia Versions: 2.5.3 tested There is an error [ more ] [ reply ] Re: Six Step IE Remote Compromise Cache Attack 2003-11-06 http-equiv (at) excite (dot) com [email concealed] (1 malware com) I can confirm the below on a brand spanking new, 3 week old, top-of- the-line machine with Windows XP Home edition, customised, with every conceivable patch, security pack, gadget enabled updating twaddle it comes with and installed to date. I demand a refund from the vendor ! This is a disgrac [ more ] [ reply ] MDKSA-2003:104 - Updated CUPS packages fix denial of service vulnerability 2003-11-06 Mandrake Linux Security Team (security linux-mandrake com) Re: RE: Six Step IE Remote Compromise Cache Attack 2003-11-06 Steven M. Christey (coley mitre org) (1 replies) Thor Larholm said: >This post raises an interesting question. Is our goal to find new >vulnerabilities and attack vectors to help secure users and critical >infrastructures, or is our goal to ease exploitation of existing >vulnerabilities? > >There are no new vulnerabilities or techniques highligh [ more ] [ reply ] RE: Six Step IE Remote Compromise Cache Attack 2003-11-06 Drew Copley (dcopley eeye com) > -----Original Message----- > From: Benjamin Franz [mailto:snowhare (at) nihongo (dot) org [email concealed]] > Sent: Wednesday, November 05, 2003 2:50 PM > To: Thor Larholm > Cc: Liu Die Yu; bugtraq (at) securityfocus (dot) com [email concealed] > Subject: RE: Six Step IE Remote Compromise Cache Attack > > > On Wed, 5 Nov 2003, Thor Larholm wrote: > [ more ] [ reply ] RE: Six Step IE Remote Compromise Cache Attack 2003-11-05 psz maths usyd edu au (Paul Szabo) Thor Larholm <thor (at) pivx (dot) com [email concealed]> wrote: > Is our goal to find new vulnerabilities and attack vectors to help secure > users and critical infrastructures, or is our goal to ease exploitation > of existing vulnerabilities? The former is part of our goal, the latter is certainly not. We actively look fo [ more ] [ reply ] RE: Six Step IE Remote Compromise Cache Attack 2003-11-05 Thor Larholm (thor pivx com) > From: white colin john [mailto:cjwhite1 (at) ehlnx13.ews.uiuc (dot) edu [email concealed]] > If there's no proof-of-concept that shows current > bugs can be combined into an exploit, is there > any pressure on microsoft to patch the bugs? There has already been several proof-of-concepts for each and every vulnerability th [ more ] [ reply ] RE: Six Step IE Remote Compromise Cache Attack 2003-11-05 Thor Larholm (thor pivx com) (6 replies) This post raises an interesting question. Is our goal to find new vulnerabilities and attack vectors to help secure users and critical infrastructures, or is our goal to ease exploitation of existing vulnerabilities? There are no new vulnerabilities or techniques highlighted in this attack (which i [ more ] [ reply ] RE: Six Step IE Remote Compromise Cache Attack 2003-11-05 white colin john (cjwhite1 ehlnx13 ews uiuc edu) (1 replies) RE: Six Step IE Remote Compromise Cache Attack 2003-11-06 Tyler Larson (noreply tlarson com) (1 replies) [CLA-2003:775] Conectiva Security Announcement - apache 2003-11-05 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : apache SUMMARY : Fix for some vulnerabilities [ more ] [ reply ] RE: double slash moves cache from INTERNET zone to MYCOMPUTER zone 2003-11-05 Thor Larholm (thor pivx com) I can only reproduce this from the My Computer zone, which already allows arbitrary command execution through the codeBase vulnerability - I don't see anything new in this, but feel free to correct me. Regards Thor Larholm Senior Security Researcher PivX Solutions, LLC Get our research, join our [ more ] [ reply ] |
|
Privacy Statement |
Hash: SHA1
- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--
PACKAGE : net-snmp
SUMMARY : Fix for the net-snmp packa
[ more ] [ reply ]