exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 9 of 9 RSS Feed

Files Date: 2009-01-25

Mandriva Linux Security Advisory 2009-029
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-029 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, remote, overflow, arbitrary, local, vulnerability
systems | linux, mandriva
advisories | CVE-2008-5286, CVE-2009-0032
SHA-256 | 5bd12d58fe984f20eaf9ce8cdca247ed7d8e7d8f56db06e9e6d14c5d9cc5ef19
Mandriva Linux Security Advisory 2009-028
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-028 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS before 1.3.8 allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, remote, web, denial of service, overflow, arbitrary, local, cgi, vulnerability
systems | linux, mandriva
advisories | CVE-2008-5183, CVE-2008-5184, CVE-2008-5286, CVE-2009-0032
SHA-256 | 1e8a4108fdf9c2d57d8db1cf6e760cbbcb404476f8da36f8cd8b11ddda80fdbe
Mandriva Linux Security Advisory 2009-027
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-027 - A vulnerability has been discovered in CUPS shipped with Mandriva Linux which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, arbitrary, local
systems | linux, mandriva
advisories | CVE-2009-0032
SHA-256 | 1c87943c9e741986daa1f1e9fb9d367afebe78c319ee66ce82cba925bda98601
Enano 1.0.5 Persistent Cross Site Scripting
Posted Jan 25, 2009
Authored by fuzion

Enenano CMS version 1.0.5 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 39100a5902f6ef9df37d19aa3b0387f1b03d573ce9c77ff3abcd55db4d16c781
Whitepaper - Win Vista DLL Injection (32bit)
Posted Jan 25, 2009
Authored by George Nicolaou | Site astalavista.com

Whitepaper discussing DLL injection on Windows Vista (32bit). Includes an executable for injecting a DLL in a process of your choice and the original source code is in the pdf.

tags | paper
systems | windows
SHA-256 | f0dd535766ba29b245a3335c2feb08cece3689d2a38a0437a4a282fb4e6429ad
MediaMonkey 3.0.6 Buffer Overflow
Posted Jan 25, 2009
Authored by AlpHaNiX

MediaMonkey version 3.0.6 local buffer overflow proof of concept exploit that creates a malicious .m3u file.

tags | exploit, overflow, local, proof of concept
SHA-256 | 6763975490ae3e021335cc169237a2601f2d5c31ee120cd505bf9a646113abe2
Merak Media Player 3.2 Buffer Overflow
Posted Jan 25, 2009
Authored by H-T Team | Site no-hack.fr

Merak Media Player version 3.2 .m3u file local buffer overflow proof of concept exploit.

tags | exploit, overflow, local, proof of concept
SHA-256 | 8332f00fbcce76d698eaaeeecc871a70f8812c7638885101912197a2d74bd680
EleCard MPEG Player Stack Overflow
Posted Jan 25, 2009
Authored by AlpHaNiX

EleCard MPEG Player local stack overflow exploit that creates a malicious .m3u file that binds a shell to port 4444.

tags | exploit, overflow, shell, local
SHA-256 | d06cb01494daf799139e1db84863c8d027881dfdb735cc41fc7209a21920a643
PostgreSQL UDF For Command Execution
Posted Jan 25, 2009
Authored by Bernardo Damele | Site bernardodamele.blogspot.com

Patched source code for lib_postgresqludf_sys that allows for command execution on postgres with user defined functions.

tags | library
SHA-256 | 7e2243d51f00284725bd535fed895dcbb3fd66596981f866c66e9deabc5992ae
Page 1 of 1
Back1Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close