|
Colapse all |
Post message
TFTPD32 Buffer Overflow Vulnerability (Long filename) 2002-11-18 Aviram Jenik (aviram beyondsecurity com) MailEnable POP3 Server remote shutdown !:/ -newest ~ (and previous) bufferoverflow- 2002-11-17 Ketil Braun Larsen (htx01i12 it-college dk) (My first post, please bare with me.) -/\-About.-/\- I found this problem auditing a webserver, it?s a standard bufferoverflow i guess, but i am not sure how to find all the technical information but if anyone knows what to do i would like to know, if some one have the time to send a brief [ more ] [ reply ] [CLA-2002:549] Conectiva Linux Security Announcement - dhcpcd 2002-11-18 secure conectiva com br -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : dhcpcd SUMMARY : Characters expansion vulnera [ more ] [ reply ] Paketto Keiretsu 1.0 2002-11-18 Dan Kaminsky (dan doxpara com) DoxPara Research is proud to announce the release of the Paketto Keiretsu, Version 1.0, for general use. Paketto presently implements many of the techniques described during recent "Black Ops of TCP/IP" presentations. Feedback is intensely sought, and we are working to maximize portability across al [ more ] [ reply ] Re: LOM: Multiple vulnerabilities in Macromedia Flash ActiveX 2002-11-18 Troy Evans (tevans macromedia com) In-Reply-To: <118-2136623052.20021118134327 (at) SECURITY.NNOV (dot) RU [email concealed]> Status on the below posting regarding: 1. zlib 1.1.3 double free() bug 2. Buffer overflow in SWRemote parameter for flash object. 1. zlib 1.1.4 double free() bug ===================== Flash Player 6 was released with the fix for [ more ] [ reply ] PlanetWeb Web Server Buffer Overflow in processing GET requests 2002-11-18 PlanetDNS Support (support planetdns net) For existing users of PlanetWeb version 1.14, a one-click downloadable patch is available from one of the following download sites. This patch corrects the buffer overflow vulnerability and also includes additional features including integrated support for virtual domain hosting. Please [ more ] [ reply ] RE: bind 8 info update regarding ISS 2002-11-18 Russ (Russ Cooper rc on ca) Note: The Bugtraq Moderator has informed me that this topic has been closed, but they have graciously allowed me an opportunity to respond to statements made directly at me by mark_sala (at) yahoo (dot) com. [email concealed] Mark said; "In the end, I'd rather have a security company find the vulnerabilities and work with the [ more ] [ reply ] [CLA-2002:548] Conectiva Linux Security Announcement - windowmaker 2002-11-18 secure conectiva com br -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : windowmaker SUMMARY : Integer buffer overflow [ more ] [ reply ] LOM: Multiple vulnerabilities in Macromedia Flash ActiveX 2002-11-18 3APA3A (3APA3A SECURITY NNOV RU) [SECURITY] [DSA 198-1] New nullmailer packages fix local denial of service 2002-11-18 joey infodrom org (Martin Schulze) Security Update: [CSSA-2002-046.0] Linux: buffer overflows and other security issues in squid 2002-11-15 security caldera com To: bugtraq (at) securityfocus (dot) com [email concealed] announce (at) lists.caldera (dot) com [email concealed] security-alerts (at) linuxsecurity (dot) com [email concealed] full-disclosure (at) lists.netsys (dot) com [email concealed] ________________________________________________________________________ ______ SCO Security Advisory Subject: Linux: buffer overflows and other security issues in squid [ more ] [ reply ] GNU GCC: Optimizer Removes Code Necessary for Security 2002-11-16 Joseph Wagner (wagnerjd prodigy net) (1 replies) When optimizing code for "dead store removal" the optimizing compiler may remove code necessary for security. A programmer could erroneously think that his code is secure, even though the securing code is removed from the compiled code. For a full report, including a complete description [ more ] [ reply ] Re: GNU GCC: Optimizer Removes Code Necessary for Security 2002-11-17 Florian Weimer (Weimer CERT Uni-Stuttgart DE) [tcpdump-announce] initial comments on trojan attack (fwd) 2002-11-16 Jonas Eriksson (je sekure net) ---------- Forwarded message ---------- Date: Fri, 15 Nov 2002 19:40:47 -0500 From: Michael Richardson <mcr (at) sandelman.ottawa.on (dot) ca [email concealed]> Reply-To: tcpdump-workers (at) sandelman.ottawa.on (dot) ca [email concealed] To: tcpdump-announce (at) tcpdump (dot) org [email concealed] Subject: [tcpdump-announce] initial comments on trojan attack -----BEGIN PGP SIGNED [ more ] [ reply ] patch for named buffer overflow now available (fwd) 2002-11-15 Jonas Eriksson (je sekure net) ---------- Forwarded message ---------- Date: Thu, 14 Nov 2002 19:12:41 -0700 From: Todd C. Miller <Todd.Miller (at) courtesan (dot) com [email concealed]> To: security-announce (at) openbsd (dot) org [email concealed] Subject: patch for named buffer overflow now available A patch for the named buffer overflow is now available. The bug could allow an at [ more ] [ reply ] [SECURITY] [DSA 197-1] New sqwebmail packages fix local information exposure 2002-11-15 joey infodrom org (Martin Schulze) bind 8 info update regarding ISS 2002-11-16 mark_sala yahoo com Upfront, Like to recognize that ISS has been doing a great job at finding very critical but obscure vulnerabilities in popular services. I'm guessing that there has been alot of other security experts that have audited the source code of Bind, SSH, etc and overlooked the discrepencies that ISS pick [ more ] [ reply ] NBActiveX Sure ActiveX Big Vulnerability 2002-11-16 Webmaster, Lorenzo Hernandez Garcia-Hierro (webmaster lorenzohgh com) ******************************* Lorenzo Hernandez garcia-hierro Webmaster of LORENZOHGH.COM LHGHPRODS PROGRAMACIÓN TIENDA ONLINE. ******************************* NBActiveX Sure ActiveX New Vulnerability Dear firends, INTODUCTION This vulnerability is an important failure because the malicious code [ more ] [ reply ] |
|
Privacy Statement |
Advisory available at:
http://www.securiteam.com/windowsntfocus/6C00C2061A.html
TFTPD32 Buffer Overflow Vulnerability (Long filename)
-------------------------------------------------------
SUMMARY
<http://tftpd32.jounin.net> TFTPD32 is a Freeware TFTP server for
Windows 9x/NT/XP. It provides
[ more ] [ reply ]