Section: .. / 0807-advisories /
| /// File Name: |
sa30987.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Dokeos, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/30987/ | | File Size: | 2359 | | Last Modified: | Jul 10 02:29:42 2008 |
| MD5 Checksum: | e1ab1b359843d3bb36ea84ccedc9fbcf |
|
| /// File Name: |
sa30995.txt |
Description:
|
Secunia Security Advisory - RoMaNcYxHaCkEr has reported some vulnerabilities in SafeHTML, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/30995/ | | File Size: | 2286 | | Last Modified: | Jul 10 02:29:42 2008 |
| MD5 Checksum: | e766836b6975546b56fea555709d1161 |
|
| /// File Name: |
sa31001.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Adobe RoboHelp Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/31001/ | | File Size: | 2434 | | Last Modified: | Jul 10 02:29:42 2008 |
| MD5 Checksum: | 8b695bcb1fa68176279a459434c13f88 |
|
| /// File Name: |
sa31002.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for poppler. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/31002/ | | File Size: | 1966 | | Last Modified: | Jul 10 02:29:42 2008 |
| MD5 Checksum: | 26e11085d7fb87a8073ce74ece535838 |
|
| /// File Name: |
sa31004.txt |
Description:
|
Secunia Security Advisory - t0pP8uZz has reported a vulnerability in Lastminute Script, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/31004/ | | File Size: | 2175 | | Last Modified: | Jul 10 02:29:42 2008 |
| MD5 Checksum: | 22446df865ba4fcc5fbf8b5dc53b52c3 |
|
| /// File Name: |
glsa-200807-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200807-04 - Felipe Andres Manzano reported a memory management issue in the Page class constructor/destructor. Versions less than 0.6.3-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2624 | | Related CVE(s): | CVE-2008-2950 | | Last Modified: | Jul 10 02:28:59 2008 |
| MD5 Checksum: | 36459cd37a9f322aee01f5cc30c1f97b |
|
| /// File Name: |
cisco-sa-20080708-dns.txt |
Description:
|
Cisco Security Advisory - Multiple Cisco products are vulnerable to DNS cache poisoning attacks due to their use of insufficiently randomized DNS transaction IDs and UDP source ports in the DNS queries that they produce, which may allow an attacker to more easily forge DNS answers that can poison DNS caches. To exploit this vulnerability an attacker must be able to cause a vulnerable DNS server to perform recursive DNS queries. Therefore, DNS servers that are only authoritative, or servers where recursion is not allowed, are not affected.
| | Homepage: | http://www.cisco.com/ | | File Size: | 70464 | | Related CVE(s): | CVE-2008-1447 | | Last Modified: | Jul 10 02:26:35 2008 |
| MD5 Checksum: | cb637e8f1582226fc0c36ad581d49c46 |
|
| /// File Name: |
dsa-1605-1.txt |
Description:
|
Debian Security Advisory 1605-1 - Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS spoofing and cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.
| | Homepage: | http://www.debian.org/security | | File Size: | 2359 | | Related CVE(s): | CVE-2008-1447 | | Last Modified: | Jul 10 02:24:58 2008 |
| MD5 Checksum: | 21c2647a22a7ca9c73899fa03d092b39 |
|
| /// File Name: |
dsa-1604-1.txt |
Description:
|
Debian Security Advisory 1604-1 - Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.
| | Homepage: | http://www.debian.org/security | | File Size: | 2554 | | Related CVE(s): | CVE-2008-1447 | | Last Modified: | Jul 10 02:23:57 2008 |
| MD5 Checksum: | 45361bf0c543432f0fd3cc3fbcd57d68 |
|
| /// File Name: |
dsa-1603-1.txt |
Description:
|
Debian Security Advisory 1603-1 - Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.
| | Homepage: | http://www.debian.org/security | | File Size: | 25029 | | Related CVE(s): | CVE-2008-1447 | | Last Modified: | Jul 10 02:16:23 2008 |
| MD5 Checksum: | 97eb7a844baa184fbb006f4c445c6ac4 |
|
| /// File Name: |
SSRT080043.txt |
Description:
|
HP Security Bulletin - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to gain unauthorized access to data.
| | Homepage: | http://www.hp.com/ | | File Size: | 6511 | | Related CVE(s): | CVE-2008-0068 | | Last Modified: | Jul 10 02:12:35 2008 |
| MD5 Checksum: | 2ec058ec41940ed48dcd61827c675e85 |
|
| /// File Name: |
SSRT080033.txt |
Description:
|
HP Security Bulletin - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code or to create a Denial of Service (DoS).
| | Homepage: | http://www.hp.com/ | | File Size: | 9805 | | Related CVE(s): | CVE-2008-1697 | | Last Modified: | Jul 10 02:11:41 2008 |
| MD5 Checksum: | 47826c3eb94d19180445d32c7c9064ad |
|
| /// File Name: |
TA08-189A.txt |
Description:
|
Technical Cyber Security Alert TA08-189A - Microsoft has released Security Advisory (955179) to describe attacks on a vulnerability in the Microsoft Office Snapshot Viewer ActiveX control. Because no fix is currently available for this vulnerability, please see the Security Advisory and US-CERT Vulnerability Note VU#837785 for workarounds.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 3342 | | Last Modified: | Jul 10 01:56:11 2008 |
| MD5 Checksum: | c46336f81d5b3c7717995864c6618fdf |
|
| /// File Name: |
oCERT-2008-007.txt |
Description:
|
The Poppler PDF rendering library versions 0.8.4 and below suffers from a memory management bug which can allows for arbitrary code execution.
| | Author: | Andrea Barisani | | Homepage: | http://www.ocert.org/ | | File Size: | 1921 | | Related CVE(s): | CVE-2008-2950 | | Last Modified: | Jul 10 01:55:10 2008 |
| MD5 Checksum: | 8492209d4f5194751f5e439b831e5867 |
|
| /// File Name: |
glsa-200807-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200807-03 - Tavis Ormandy of the Google Security team reported a heap-based buffer overflow when compiling regular expression patterns containing Internal Option Settings such as (?i). Versions less than 7.7-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3159 | | Related CVE(s): | CVE-2008-2371 | | Last Modified: | Jul 10 01:49:16 2008 |
| MD5 Checksum: | 373947e2ea08cbf7ad1a54367e649fb8 |
|
| /// File Name: |
dsa-1602-1.txt |
Description:
|
Debian Security Advisory 1602-1 - Tavis Ormandy discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution.
| | Homepage: | http://www.debian.org/security | | File Size: | 9947 | | Related CVE(s): | CVE-2008-2371 | | Last Modified: | Jul 10 00:52:30 2008 |
| MD5 Checksum: | 2910b17782ff11e4d41b819e101b0c08 |
|
| /// File Name: |
Advisory-DWR.pdf |
Description:
|
Direct Web Rendering (DWR) version 2.0.1 suffers from a cross site scripting vulnerability.
| | Author: | Peter Osterberg | | Homepage: | http://www.fortconsult.net/ | | File Size: | 194548 | | Related CVE(s): | CVE-2008-2740 | | Last Modified: | Jul 10 00:24:48 2008 |
| MD5 Checksum: | 377d17490f5fdf8a4323108cbce18fa9 |
|
| /// File Name: |
wefi-local.txt |
Description:
|
The wireless client, WeFi version 3.2.1.4.1, is susceptible to local vulnerabilities due to improper coding.
| | Author: | Xia Shing Zee | | File Size: | 2040 | | Last Modified: | Jul 10 00:18:47 2008 |
| MD5 Checksum: | 9e018650561ebf7a0b390aa09e01bb54 |
|
| /// File Name: |
MDVSA-2008-135.txt |
Description:
|
Mandriva Linux Security Advisory - A vulnerability was found in gnome-screensaver 2.20.0 that could possibly allow a local user to read the clipboard contents and X selection data for a locked session by using CTRL-V. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2412 | | Related CVE(s): | CVE-2007-6389 | | Last Modified: | Jul 9 23:55:59 2008 |
| MD5 Checksum: | 4d5afeb57c855ddb56de13656bbddaa5 |
|
| /// File Name: |
MDVSA-2008-134.txt |
Description:
|
Mandriva Linux Security Advisory - An incorrect fix for CVE-2007-6239 resulted in Squid not performing proper bounds checking when processing cache update replies. Because of this, a remote authenticated user might have been able to trigger an assertion error and cause a denial of service. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 4596 | | Related CVE(s): | CVE-2008-1612 | | Last Modified: | Jul 9 23:55:30 2008 |
| MD5 Checksum: | e8bff7f4908b0e102f2c90c36b1a09ba |
|
| /// File Name: |
MDVSA-2008-133.txt |
Description:
|
Mandriva Linux Security Advisory - A denial of service condition was discovered in Sympa versions prior to 5.4 that allowed remote attackers to crash the Sympa daemon via a malformed email message. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2355 | | Related CVE(s): | CVE-2008-1648 | | Last Modified: | Jul 9 23:55:13 2008 |
| MD5 Checksum: | dc691b2dcda63b70672d8e016f9ecd97 |
|
| /// File Name: |
MDVSA-2008-132.txt |
Description:
|
Mandriva Linux Security Advisory - A vulnerability was found in gnome-screensaver prior to 2.22.1 when a remote authentication server was enabled. During a network outage, gnome-screensaver would crash upon an unlock attempt, allowing physically local users to gain access to locked sessions. The updated packages have been patched to correct this issue.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2490 | | Related CVE(s): | CVE-2008-0887 | | Last Modified: | Jul 9 23:54:52 2008 |
| MD5 Checksum: | 9feb3b40d7df8089a181f8bbcb1f4f69 |
|
| /// File Name: |
MDVSA-2008-131.txt |
Description:
|
Mandriva Linux Security Advisory - A few vulnerabilities and security-related issues have been fixed in phpMyAdmin since the 2.11.2.2 release. This update provides version 2.11.7 which is the latest stable release of phpMyAdmin and fixes CVE-2008-1149, CVE-2008-1567, CVE-2008-1924, and CVE-2008-2960. No configuration changes should be required since the previous update (version 2.11.2.2). If upgrading from older versions, it may be necessary to reconfigure phpMyAdmin. The configuration file is located in /etc/phpMyAdmin/. In most cases, it should be sufficient so simply replace config.default.php with config.default.php.rpmnew and make whatever modifications are necessary.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2985 | | Related CVE(s): | CVE-2008-1149, CVE-2008-1567, CVE-2008-1924, CVE-2008-2960 | | Last Modified: | Jul 9 23:54:22 2008 |
| MD5 Checksum: | e6951f2517d53eeba1c9512f5b916242 |
|
| /// File Name: |
MDVSA-2008-130.txt |
Description:
|
Mandriva Linux Security Advisory - An integer overflow in the zip_read_entry() function in PHP prior to 4.4.5 allowed remote attackers to execute arbitrary code via a ZIP archive containing a certain type of entry that triggered a heap overflow. Weaknesses in the GENERATE_SEED macro in PHP prior to 4.4.8 and 5.2.5 were discovered that could produce a zero seed in rare circumstances on 32bit systems and generations a portion of zero bits during conversion due to insufficient precision on 64bit systems. The updated packages have been patched to correct these issues.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3796 | | Related CVE(s): | CVE-2007-1777, CVE-2008-2107, CVE-2008-2108 | | Last Modified: | Jul 9 23:45:53 2008 |
| MD5 Checksum: | cdafdd1023afe885ab7639c39e669bd2 |
|
| /// File Name: |
MDVSA-2008-129.txt |
Description:
|
Mandriva Linux Security Advisory - Weaknesses in the GENERATE_SEED macro in PHP prior to 4.4.8 and 5.2.5 were discovered that could produce a zero seed in rare circumstances on 32bit systems and generations a portion of zero bits during conversion due to insufficient precision on 64bit systems. The updated packages have been patched to correct these issues.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3492 | | Related CVE(s): | CVE-2008-2107, CVE-2008-2108 | | Last Modified: | Jul 9 23:45:25 2008 |
| MD5 Checksum: | 9ebaf905d1f62d7dc8139ec7a9e0d6bf |
|
|
|
|
|