Section: .. / 0807-advisories /
| /// File Name: |
sa31120.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Firefox 2, which can be exploited by malicious people to bypass certain security restrictions and disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/31120/ | | File Size: | 2622 | | Last Modified: | Jul 16 15:45:24 2008 |
| MD5 Checksum: | 7b1140a0c9a9676cd41386de213169ab |
|
| /// File Name: |
sa31122.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for seamonkey. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31122/ | | File Size: | 2555 | | Last Modified: | Jul 16 15:45:24 2008 |
| MD5 Checksum: | 3bcc53004de21a2223583a41b8d3c88c |
|
| /// File Name: |
SSRT080097.txt |
Description:
|
HP Security Bulletin - Potential security vulnerabilities have been identified with HP Select Identity Active Directory Bidirectional LDAP Connector . The vulnerabilities could be exploited to allow remote unauthorized access.
| | Homepage: | http://www.hp.com/ | | File Size: | 6092 | | Related CVE(s): | CVE-2008-1665 | | Last Modified: | Jul 16 15:43:55 2008 |
| MD5 Checksum: | a11f1f733768ff70d0e990e3269f40d2 |
|
| /// File Name: |
netrw-exec.txt |
Description:
|
Lack of sanitization throughout Netrw can lead to arbitrary code execution upon opening a directory with a crafted name.
| | Author: | Jan Minar | | File Size: | 5137 | | Last Modified: | Jul 16 15:43:19 2008 |
| MD5 Checksum: | 0a45093ff0e3eb716b14884b0b054a39 |
|
| /// File Name: |
vim72b-exec.txt |
Description:
|
Vim versions greater than and equal to 7.2.a.013 suffer from an arbitrary code execution vulnerability using the shellescape() function.
| | Author: | Jan Minar | | File Size: | 3450 | | Last Modified: | Jul 16 15:42:12 2008 |
| MD5 Checksum: | 9315516bf2b023bbb2f7e8cdfb678067 |
|
| /// File Name: |
MDVSA-2008-147.txt |
Description:
|
Mandriva Linux Security Advisory - Tavis Ormandy of the Google Security Team discovered a heap-based buffer overflow when compiling certain regular expression patterns. This could be used by a malicious attacker by sending a specially crafted regular expression to an application using the PCRE library, resulting in the possible execution of arbitrary code or a denial of service. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 4319 | | Related CVE(s): | CVE-2008-2371 | | Last Modified: | Jul 16 14:50:23 2008 |
| MD5 Checksum: | b8e63c1a7fd5d361e566c9cacb751161 |
|
| /// File Name: |
USN-625-1.txt |
Description:
|
Ubuntu Security Notice 625-1 - A massive slew of Linux kernel related vulnerabilities have been addressed for the linux-source-2.6.15/20/22 packages.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 192927 | | Related CVE(s): | CVE-2007-6282, CVE-2007-6712, CVE-2008-0598, CVE-2008-1615, CVE-2008-1673, CVE-2008-2136, CVE-2008-2137, CVE-2008-2148, CVE-2008-2358, CVE-2008-2365, CVE-2008-2729, CVE-2008-2750, CVE-2008-2826 | | Last Modified: | Jul 16 14:50:16 2008 |
| MD5 Checksum: | 5e9e19eec557961a1d40d8762fd5cff3 |
|
| /// File Name: |
MDVSA-2008-146.txt |
Description:
|
Mandriva Linux Security Advisory - A memory management issue was found in libpoppler by Felipe Andres Manzano that could allow for the execution of arbitrary code with the privileges of the user running a poppler-based application, if they opened a specially crafted PDF file. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 6044 | | Related CVE(s): | CVE-2008-2950 | | Last Modified: | Jul 15 21:09:57 2008 |
| MD5 Checksum: | 37e194777605bac78445c2e820e31d67 |
|
| /// File Name: |
sa31057.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for bluez-libs and bluez-utils. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/31057/ | | File Size: | 2439 | | Last Modified: | Jul 15 20:23:26 2008 |
| MD5 Checksum: | bc2502081e7dbd78a4aee303f9f09c15 |
|
| /// File Name: |
sa31067.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for java-1.4.2-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31067/ | | File Size: | 2296 | | Last Modified: | Jul 15 20:23:26 2008 |
| MD5 Checksum: | ac326930a9178ca15b6d4aa2184ef3c9 |
|
| /// File Name: |
07.15.08-3.txt |
Description:
|
iDefense Security Advisory 07.15.08 - Local exploitation of an untrusted library path vulnerability in Oracle Corp.'s Oracle Database product allows attackers to gain elevated privileges. This vulnerability specifically exists in a set-uid root program distributed with Oracle Database for Linux and Unix platforms. By replacing a module owned by the oracle user, which is loaded by this program, an attacker can execute arbitrary code as root. iDefense confirmed the existence of this vulnerability in Oracle 11g R1 version 11.1.0.6.0 on 32-bit Linux platform. Previous versions may also be affected.
| | Author: | Joxean Koret | | Homepage: | http://www.idefense.com/ | | File Size: | 3311 | | Related CVE(s): | CVE-2008-2613 | | Last Modified: | Jul 15 20:23:19 2008 |
| MD5 Checksum: | e8ee1e493dada84f07feb39294a4a5f6 |
|
| /// File Name: |
07.15.08-2.txt |
Description:
|
iDefense Security Advisory 07.15.08 - Remote exploitation of a buffer overflow vulnerability in the DBMS_AQELM package in Oracle Corp.'s Oracle Database product allows attackers to execute arbitrary code with the privileges of the database user. This vulnerability exists due to improper input validation when handling a parameter passed to a procedure within the DBMS_AQELM package. Since the parameter is not properly validated, providing a long string can cause a buffer overflow to occur. This results in corruption of the database and could allow for the execution of arbitrary code as the database user. iDefense confirmed the existence of this vulnerability in Oracle Database version 10.2.0.3 and 11.1.0.6 with the October 2007 CPU applied. Previous versions may also be affected.
| | Author: | Joxean Koret | | Homepage: | http://www.idefense.com/ | | File Size: | 3635 | | Related CVE(s): | CVE-2008-2607 | | Last Modified: | Jul 15 20:22:23 2008 |
| MD5 Checksum: | ce82ad21bbe158ccfb4fd2c80da488bc |
|
| /// File Name: |
07.15.08-1.txt |
Description:
|
iDefense Security Advisory 07.15.08 - Remote exploitation of a pre-authentication input validation vulnerability in Oracle Corp.'s Oracle Internet Directory allows an attacker to conduct a denial of service attack on a vulnerable host. Internet Directory consists of two processes. One process acts as a listener. It handles incoming connections and passes them off to the second process. The second process, which handles requests, contains the vulnerability. When processing a malformed LDAP request, it is possible to cause the handler to dereference a NULL pointer. This results in the process crashing. Future connection requests will be accepted by the listener process, and then immediately closed when it finds that there is no handler process running. iDefense confirmed the existence of this vulnerability in Oracle Internet Directory for Windows version 10.1.4.0.1 with the April 2007 CPU installed. Previous versions may also be affected.
| | Author: | Joxean Koret | | Homepage: | http://www.idefense.com/ | | File Size: | 3843 | | Related CVE(s): | CVE-2008-2595 | | Last Modified: | Jul 15 20:20:55 2008 |
| MD5 Checksum: | e8fd9c9196beac5c66e3d1a2dbceb960 |
|
| /// File Name: |
NISR15072008.txt |
Description:
|
NGSSoftware Insight Security Research Advisory - Oracle Application Server installs a number of PLSQL packages in the backend database server. One of these is the WWV_RENDER_REPORT package and it is vulnerable to PLSQL injection. This package uses definer rights execution and therefore executes with the privileges of the owner, in this case the highly privileged PORTAL user.
| | Author: | David Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 3709 | | Related CVE(s): | CVE-2008-2589 | | Last Modified: | Jul 15 20:18:26 2008 |
| MD5 Checksum: | c6bc69f8abb9b4ec0ab0dfecf8149c3d |
|
| /// File Name: |
glsa-200807-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200807-09 - Jakub Wilk discovered a directory traversal vulnerability in the applydiff() function in the mercurial/patch.py file. Versions less than 1.0.1-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2480 | | Related CVE(s): | CVE-2008-2942 | | Last Modified: | Jul 15 20:02:55 2008 |
| MD5 Checksum: | 50462d81464b1af2654e6f46ece39373 |
|
| /// File Name: |
dsa-1569-3.txt |
Description:
|
Debian Security Advisory 1569-3 - Since the previous security update, the cacti package could no longer be rebuilt from the source package. This update corrects that problem. Note that this problem does not affect regular use of the provided binary packages (.deb).
| | Homepage: | http://www.debian.org/security | | File Size: | 3425 | | Related CVE(s): | CVE-2008-0783, CVE-2008-0785 | | Last Modified: | Jul 15 20:02:17 2008 |
| MD5 Checksum: | 17dce37d3f17988c79c9c5f1d1a8a226 |
|
| /// File Name: |
sa30943.txt |
Description:
|
Secunia Security Advisory - S.W.A.T. has reported a vulnerability in Maian Weblog, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/30943/ | | File Size: | 2244 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | e1584408f27e5c8863e514c5bc78c22a |
|
| /// File Name: |
sa30990.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for pcre3. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/30990/ | | File Size: | 16363 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | c17d01786da6677df806f4c1275c3ed6 |
|
| /// File Name: |
sa31003.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in Firebird, which can be exploited by malicious users to disclose system information.
| | Homepage: | http://secunia.com/advisories/31003/ | | File Size: | 2096 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | 182ad098be0f5a47eb960490bc07ac8e |
|
| /// File Name: |
sa31033.txt |
Description:
|
Secunia Security Advisory - FreeBSD has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
| | Homepage: | http://secunia.com/advisories/31033/ | | File Size: | 2410 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | c6a16928af3a333f5fa2a0fc3aed0322 |
|
| /// File Name: |
sa31045.txt |
Description:
|
Secunia Security Advisory - S.W.A.T. has reported a vulnerability in Maian Uploader, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/31045/ | | File Size: | 2254 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | b57ac016f30bec36ca9d6181e624beba |
|
| /// File Name: |
sa31053.txt |
Description:
|
Secunia Security Advisory - cOndemned has discovered a vulnerability in CodeDB, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/31053/ | | File Size: | 2263 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | a37957a7a1382e7fbc79965009d71605 |
|
| /// File Name: |
sa31055.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for java-1.5.0-sun. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31055/ | | File Size: | 2359 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | e5c3e6120b0cb68b22d76a1cb0cae6c8 |
|
| /// File Name: |
sa31062.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/31062/ | | File Size: | 2446 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | cb2b365226f397f193382ddb1b6b077a |
|
| /// File Name: |
sa31064.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities and a weakness have been reported in Firebird, which can be exploited by malicious users to cause a DoS (Denial of Service) and disclose system information, and by malicious, local users to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/31064/ | | File Size: | 3301 | | Last Modified: | Jul 15 20:01:58 2008 |
| MD5 Checksum: | 8b7aaa65be6de82a6cf501b7031fdf03 |
|
|
|
|
|