Mailing Lists

[ MDVSA-2008:183 ] opensc

BugTraq - Tue, 2008-09-02 13:14
Posted by security_at_mandriva.com on Sep 02

 _______________________________________________________________________

 Mandriva Linux Security Advisory MDVSA-2008:183
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package :...

Categories: Mailing Lists

[USN-639-1] tiff vulnerability

BugTraq - Tue, 2008-09-02 12:25
Posted by Kees Cook on Sep 2

===========================================================
Ubuntu Security Notice USN-639-1 September 02, 2008
tiff vulnerability
CVE-2008-2327
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
...

Categories: Mailing Lists

CS-Cart lt 1.3.5 SQL Injection

BugTraq - Tue, 2008-09-02 11:09
Posted by GulfTech Security Research on Sep 02

##########################################################
# GulfTech Security Research September 02, 2008
##########################################################
# Vendor : CS-Cart.com
# URL : http://www.cs-cart.com/
# Version : CS-Cart <= 1.3.5
# Risk : SQL Injection
...

Categories: Mailing Lists

[ MDVSA-2008:182 ] wordnet

BugTraq - Tue, 2008-09-02 11:08
Posted by security_at_mandriva.com on Sep 02

 _______________________________________________________________________

 Mandriva Linux Security Advisory MDVSA-2008:182
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package :...

Categories: Mailing Lists

[AJECT] Softalk IMAP Server 8.5.1 DoS vulnerability

BugTraq - Tue, 2008-09-02 07:07
Posted by Joo Antunes on Sep 2

----------------------------------------
Synopsis
----------------------------------------
Softalk IMAP Server 8.5.1 is vulnerable to denial-of-service (DoS)
attacks.
The IMAP server crashes when processing an APPEND command with a
strange parameter (see details bellow). Other commands...

Categories: Mailing Lists

[security bulletin] HPSBMA02362 SSRT080044, SSRT080045 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)

BugTraq - Tue, 2008-09-02 07:07
Posted by security-alert_at_hp.com on Sep 02

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01537275
Version: 1

HPSBMA02362 SSRT080044, SSRT080045 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release...

Categories: Mailing Lists

Postfix Linux-only local denial of service

BugTraq - Tue, 2008-09-02 04:53
Posted by Wietse Venema on Sep 2

An on-line version of this announcement is available at
http://www.postfix.org/announcements/20080902.html

Summary:
========
Postfix 2.4 and later, on Linux kernel 2.6, is vulnerable to a
denial of service attack by a local user. There is no breach of
data confidentiality or data integrity....

Categories: Mailing Lists

HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)

BugTraq - Tue, 2008-09-02 04:14
Posted by security-alert_at_hp.com on Sep 02

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01532861
Version: 1

HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted...

Categories: Mailing Lists

In search of examples of malicious source code

BugTraq - Tue, 2008-09-02 02:06
Posted by Steve.Coleman_at_jhuapl.edu on Sep 2

('binary' encoding is not supported, stored as-is) I am currently working on a research project and designing an application specifically aimed at locating malicious logic embedded in source code (C/C++ for now, other languages will be addressed later). As a test of the future implementation I...

Categories: Mailing Lists

ToorCon X Lineup amp Training Seminars Posted amp Pre-Registration Ending

BugTraq - Mon, 2008-09-01 17:09
Posted by h1kari_at_toorcon.org on Sep 1

('binary' encoding is not supported, stored as-is) [*] TOORCON X LINEUP & TRAINING SEMINARS POSTED & PRE-REGISTRATION ENDING

We're very proud to announce our lineup for this year and wanted to remind everyone that ToorCon is happening in less than a month! We also have a couple different...

Categories: Mailing Lists

[SECURITY] [DSA 1634-1] New wordnet packages fix arbitrary code execution

BugTraq - Mon, 2008-09-01 11:17
Posted by Thijs Kinkhorst on Sep 1

------------------------------------------------------------------------
Debian Security Advisory DSA-1634-1 security_at_debian.org
http://www.debian.org/security/ Thijs Kinkhorst
September 01, 2008 ...

Categories: Mailing Lists

[SECURITY] [DSA 1633-1] New slash packages fix multiple vulnerabilities

BugTraq - Mon, 2008-09-01 10:45
Posted by Florian Weimer on Sep 01

------------------------------------------------------------------------
Debian Security Advisory DSA-1633-1 security_at_debian.org
http://www.debian.org/security/ Florian Weimer
September 01, 2008 ...

Categories: Mailing Lists

[Tool] sqlmap 0.6 released

BugTraq - Mon, 2008-09-01 05:35
Posted by Bernardo Damele A. G. on Sep 01

Hi,

I am glad to release sqlmap version 0.6.

Introduction
============

sqlmap is an automatic SQL injection tool developed in Python. Its goal
is to detect and take advantage of SQL injection vulnerabilities on web
applications. Once it detects one or more SQL injections on the target
...

Categories: Mailing Lists

[Suspected Spam]New IETF I-D-: Security Assessment of the Internet Protocol version 4

BugTraq - Sun, 2008-08-31 22:51
Posted by Fernando Gont on Sep 01

Hello, folks,

We have published an IETF Internet-Draft entitled "Security Assessment of
the Internet Protocol version 4", which is heavily based on the "Security
Assessment of the Internet Protocol" that was recently released by the UK
CPNI (...

Categories: Mailing Lists

T208 Challenge - Free Tickets Available

BugTraq - Sun, 2008-08-31 02:32
Posted by Tomi Tuominen on Aug 31

Hi Everyone,

Quite many people have emailed us lately asking if there will be T2'08
Challenge - the answer is yes :)

The purpose of the Challenge is to have an opportunity to win a free
tickets to T2'08 infosec conference:
http://www.t2.fi/

The rules are simple: T2 publishes the Challenge...

Categories: Mailing Lists

Re: OpenVMS fingerd remote stack overflow

BugTraq - Thu, 2008-08-07 12:51
Posted by mlbugtraq_at_noci.xs4all.nl on Aug 7

On Thursday 07 August 2008, Shaun Colley wrote:
> echo `perl -e 'print "a"x1000'` | nc -v dahmer.vistech.net 79

well,

that might yield you a process runing under UIC [80,80], with the username
BLACKLA...? As that is the owner the process runs under.
Probably not an authorized...

Categories: Mailing Lists

[ MDVSA-2008:161 ] rxvt

BugTraq - Thu, 2008-08-07 12:51
Posted by security_at_mandriva.com on Aug 07

 _______________________________________________________________________

 Mandriva Linux Security Advisory MDVSA-2008:161
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package :...

Categories: Mailing Lists

Re: Bluetooth testing...

PenTest - Thu, 2008-08-07 12:37
Posted by Joshua Wright on Aug 07

Serg B wrote:
| Thanks for all replies so far, just a quick update with more detail...
| I am planning to be using a Linux based laptop with a USB bluetooth
| dongle...
|
| Not sure if the equipment is right or not, so any feedback on that
| front is also appreciated.

The tools mentioned...

Categories: Mailing Lists

e107 lt 0.7.11 Arbitrary Variable Overwriting

BugTraq - Thu, 2008-08-07 11:13
Posted by GulfTech Security Research on Aug 07

##########################################################
# GulfTech Security Research August 07, 2008
##########################################################
# Vendor : Steve Dunstan
# URL : http://www.e107.org/
# Version : e107 <= 0.7.11
# Risk : Arbitrary Variable...

Categories: Mailing Lists

Re: [SE-2008-01] J2ME Security Vulnerabilities 2008

BugTraq - Thu, 2008-08-07 10:55
Posted by 0xjbrown41_at_gmail.com on Aug 7

('binary' encoding is not supported, stored as-is) * establishing of arbitrary phone calls

>From RFC 3966 (http://www.faqs.org/rfcs/rfc3966.html):

11. Security Considerations

   The security considerations parallel those for the mailto URL
   [RFC2368].

...

Categories: Mailing Lists
Syndicate content