|
Colapse all |
Post message
[ESA-20030806-020] 'stunnel' signal handler race denial-of-service. 2003-08-06 EnGarde Secure Linux (security guardiandigital com) RE: Notepad popups in Internet Explorer and Outlook 2003-08-05 Thor Larholm (thor pivx com) The problem at hand is not one of Notepad or the view-source protocol, but of the behavior inherant to Internet Explorer on how to handle certain mimetypes and protocols. Your advisory (good as it is) highlights an example of the problem, but disregards the larger picture. Whether or not a specific [ more ] [ reply ] Halflife exploit that provides a shell in fbsd 2003-08-04 Spoilt JeSuS (spoilt_jesus uhagr org) hk-vig of UHAGr and wsxz of Priv8security published a high risk remote root exploit (if running by root) against Halflife <= 1.1.1.0 (including all mods like CS, DoD) and dedicated server 3.1.1.1c1/4.1.1.1a. Exploitation successfully tested on FreeBSD.This code is based upon the recent hal [ more ] [ reply ] [sec-labs] Zone Alarm Device Driver vulnerability 2003-08-04 sec-labs team (noreply sec-labs hack pl) Notepad popups in Internet Explorer and Outlook 2003-08-04 Richard M. Smith (rms computerbytesman com) Hi, Do Notepad popups represent a security risk or are they simply another way for spammers and marketers to annoy us? Because of a design flaw in Internet Explorer, Notepad popup windows can be displayed from an HTML email message or Web page regardless of browser security settings. In addition, N [ more ] [ reply ] [SECURITY] [DSA-358-2] New kernel packages fix potential "oops" 2003-08-05 Matt Zimmerman (mdz debian org) Re: question about oracle advisory 2003-08-05 McCartney, Daymon (US - Deerfield) (dmccartney deloitte com) (1 replies) David: Do you have any plans to release proof of concept code for the Oracle exploit? The reason I ask is that "due to architectural constraints," Oracle is not planning on releasing a patch for 8i releases. We contacted them about this, but they're sticking to their guns about the exploit requir [ more ] [ reply ] Re: Invision Board spoof and defacement 2003-08-05 matt ibforums com In-Reply-To: <20030804002946.4431.qmail (at) www.securityfocus (dot) com [email concealed]> You've got to be kidding me? >The vendor hasn't been notified because of their >handling of previous vulnerabilties I found in Invision >Board I am extremely responsible with regards to security and in most cases I've had a fi [ more ] [ reply ] ZH2003-14SA (security advisory): aspBoard XSS Vulnerability 2003-08-05 G00db0y (G00db0y zone-h org) ZH2003-14SA (security advisory): aspBoard XSS Vulnerability Published: 5 august 2003 Released: 5 august 2003 Name: aspBoard Affected Systems: 1.2 Issue: Remote attackers can inject XSS script Author: G00db0y (at) zone-h (dot) org [email concealed] Vendor: http://www.freezingcold.com Description ** [ more ] [ reply ] Slight privilege elevation from bin to root in IBM DB2 7.1 - 8.1 all binaries 2003-08-05 pask cmlc upv es [CLA-2003:717] Conectiva Security Announcement - postfix 2003-08-04 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : postfix SUMMARY : Remote denial of service vu [ more ] [ reply ] [CLA-2003:716] Conectiva Security Announcement - wget 2003-08-04 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : wget SUMMARY : Buffer overflow vulnerability [ more ] [ reply ] NetBSD Security Advisory 2003-010: remote panic in OSI networking code 2003-08-04 NetBSD Security Officer (security-officer netbsd org) [ESA-20030804-019] 'postfix' Remote denial-of-service. 2003-08-04 EnGarde Secure Linux (security guardiandigital com) Off-by-one Buffer Overflow Vulnerability in BSD libc realpath(3) 2003-08-04 Dave Ahmad (da securityfocus com) Originally reported as affecting only WU-FTPD. It seems that the bug is in code borrowed from the BSD C library. NetBSD, FreeBSD and OpenBSD announcements attached. David Mirza Ahmad Symantec PGP: 0x26005712 8D 9A B1 33 82 3D B3 D0 40 EB AB F0 1E 67 C6 1A 26 00 57 12 -- The battle for the past [ more ] [ reply ] NetBSD Security Advisory 2003-011: off-by-one error in realpath(3) 2003-08-04 NetBSD Security Officer (security-officer NetBSD org) Macromedia DW MX PHP Authentication Suit Vulnerabilities 2003-08-04 Lorenzo Hernandez Garcia-Hierro (novappc novappc com) ------------------- Product: PHP Authentication Suit for DreamWeaver Vendor: Macromedia Versions: VULNERABLE - DreamWeaver MX 6.0 - All the PHP Auth systems created with this - Variables : ALL LIKE accessdenied NOT VULNERABLE - ? --------------------- Description: The PHP User Authentication [ more ] [ reply ] Unix command line RPC/DCOM Vulnerability Scanner 2003-08-02 the farpointer (farp myrealbox com) brought to you by: -------------------------- kid : ironkid (at) buildtheb0x (dot) com [email concealed] and farp : farp (at) buildtheb0x (dot) com [email concealed] #gcc -o dcom_scanz dcom_scanz.c # ./dcom_scanz usage: dcom-isvuln <target-ip> [--debug] # ./dcom_scanz 10.1.1.25 [+] Connecting to 10.1.1.25 [+] Sending DCERPC, Bind: call_id: 9 UUID: R [ more ] [ reply ] ZH2003-5SA (security advisory): Windows beta webserver for pocket pc: full remote access. 2003-08-02 G00db0y (G00db0y zone-h org) Invision Board spoof and defacement 2003-08-04 Daniel Boland (DCBoland blueyonder co uk) -INTRO- All versions of Invisions Board have a flaw in their input filtering that allows an attacker to completely mess up Invision's display and in one case I managed to change the URL of some of the forums links, which could be used to refer users to fake login sites to collect passwords e [ more ] [ reply ] [SECURITY] [DSA-361-1] New kdelibs packages fix several vulnerabilities 2003-08-01 Matt Zimmerman (mdz debian org) wu-ftpd-2.6.2 off-by-one remote exploit. 2003-08-04 dong-h0un U (xploit hackermail com) I succeeded in RedHat Linux (x86) wu-2.6.2(1), 2.6.2(2), 2.6.1, 2.6.0. (Most version). This is never fake. Excellent Advisory was already announced (2003/07/31): http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt This information was very useful to me. I'm thankful to them. This works well in [ more ] [ reply ] SuSE Security Announcement: postfix (SuSE-SA:2003:033) 2003-08-04 krahmer suse de (Sebastian Krahmer) leak of information in counterpane/Bruce Schneier's (now open source) Password Safe program 2003-08-03 vali iname com Program description: --- Password Safe is a tool that allows you to have a different password for all the different programs and websites that you deal with, without actually having to remember all those usernames and passwords. Originally created by Bruce Schneier's Counterpane Labs, Password Saf [ more ] [ reply ] |
|
Privacy Statement |
Hash: SHA1
+-----------------------------------------------------------------------
-+
| Guardian Digital Security Advisory August 06, 2003 |
| http://www.guardiandigital.com ESA-20030806-020 |
|
[ more ] [ reply ]