Section: .. / 0606-advisories /
| /// File Name: |
glsa-200606-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-03 - KaDaL-X discovered a format string error within the handling of filenames. Hans de Goede also discovered several other format string errors in the processing of dia files. Versions less than 0.95.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2626 | | Last Modified: | Jun 11 04:23:49 2006 |
| MD5 Checksum: | 8b6a97f8db8f7f6f21638ec4a3ae0fc0 |
|
| /// File Name: |
glsa-200606-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-02 - When the mailbox is created in useradd, the open() function does not receive the three arguments it expects while O_CREAT is present, which leads to random permissions on the created file, before fchmod() is executed. Versions less than 4.0.15-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2637 | | Last Modified: | Jun 11 04:23:45 2006 |
| MD5 Checksum: | 9288ee1a0cee72ef9353b0caca9b7443 |
|
| /// File Name: |
glsa-200606-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-01 - SEC Consult has discovered a buffer overflow in the code processing style sheet attributes. It is caused by an integer signedness error in a length check followed by a call to a string function. It seems to be hard to exploit this buffer overflow to execute arbitrary code because of the very large amount memory that has to be copied. Versions less than 8.54 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2735 | | Last Modified: | Jun 11 04:23:39 2006 |
| MD5 Checksum: | cbc6653e675e3450c02b4728d4f281cf |
|
| /// File Name: |
glsa-200606-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-08 - rgod discovered that WordPress insufficiently checks the format of cached username data. Versions less than 2.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2579 | | Last Modified: | Jun 11 04:23:31 2006 |
| MD5 Checksum: | e78bc0bd1e3b3d044b7c101dc2e66530 |
|
| /// File Name: |
glsa-200606-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-07 - Roman Veretelnikov discovered that Vixie Cron fails to properly check whether it can drop privileges accordingly if setuid() in do_command.c fails due to a user exceeding assigned resource limits. Versions less than 4.1-r9 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2589 | | Last Modified: | Jun 11 04:23:25 2006 |
| MD5 Checksum: | 90634a07feebd4612158dfe42936f1ba |
|
| /// File Name: |
MDKSA-2006-098.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-098: PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications via invalid encodings of multibyte characters, aka one variant of "Encoding-Based SQL Injection."
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 12595 | | Last Modified: | Jun 11 04:21:41 2006 |
| MD5 Checksum: | 4261e1ee878f9868b455c043769cc88a |
|
| /// File Name: |
MDKSA-2006-097.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-097: SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5498 | | Last Modified: | Jun 11 04:21:33 2006 |
| MD5 Checksum: | 4368baf386bf27035f0639fbb6323897 |
|
| /// File Name: |
MDKSA-2006-096.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-096: A stack-based buffer overflow in st.c in slurpd for OpenLDAP might allow attackers to execute arbitrary code via a long hostname.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 8489 | | Last Modified: | Jun 11 04:21:26 2006 |
| MD5 Checksum: | 62c2d2fac61e071395f05b5ce43b7701 |
|
| /// File Name: |
MDKSA-2006-095.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-095: A stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5788 | | Last Modified: | Jun 11 04:21:16 2006 |
| MD5 Checksum: | 295b5101a7d564b8c1c74cc0c8c85c2b |
|
| /// File Name: |
dsa-1090-1.txt |
Description:
|
Debian Security Advisory 1090-1: A vulnerability has been discovered in SpamAssassin, a Perl-based spam filter using text analysis, that can allow remote attackers to execute arbitrary commands.
| | Homepage: | http://www.debian.org/security | | File Size: | 5568 | | Last Modified: | Jun 11 04:18:12 2006 |
| MD5 Checksum: | 7104c4714e63c36f2d0e19bbfa6eacb8 |
|
| /// File Name: |
dsa-1095-1.txt |
Description:
|
Debian Security Advisory 1095-1: Several problems have been discovered in the FreeType 2 font engine.
| | Homepage: | http://www.debian.org/security | | File Size: | 16056 | | Last Modified: | Jun 11 04:18:04 2006 |
| MD5 Checksum: | 494845561c6b8fb29dfa26debccefece |
|
| /// File Name: |
dsa-1094-1.txt |
Description:
|
Debian Security Advisory 1094-1: Joxean Koret discovered several cross-site scripting vulnerabilities in Gforge, an online collaboration suite for software development, which allow injection of web script code.
| | Homepage: | http://www.debian.org/security | | File Size: | 5209 | | Last Modified: | Jun 11 04:17:57 2006 |
| MD5 Checksum: | de1732dd0c480a9a3e736a4938963d75 |
|
| /// File Name: |
dsa-1093-1.txt |
Description:
|
Debian Security Advisory 1093-1: Several format string vulnerabilities have been discovered in xine-ui, the user interface of the xine video player, which may cause a denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 4941 | | Last Modified: | Jun 11 04:17:50 2006 |
| MD5 Checksum: | a5e6d1690242748786265df2c0dff0a6 |
|
| /// File Name: |
dsa-1092-1.txt |
Description:
|
Debian Security Advisory 1092-1: Josh Berkus and Tom Lane discovered that MySQL 4.1, a popular SQL database, incorrectly parses strings escaped with mysql_real_escape() which could lead to SQL injection. This problem does only exist in versions 4.1 and 5.0.
| | Homepage: | http://www.debian.org/security | | File Size: | 11968 | | Last Modified: | Jun 11 04:17:44 2006 |
| MD5 Checksum: | 4da430dcb9ea283da945b874bd545f8a |
|
| /// File Name: |
dsa-1091-1.txt |
Description:
|
Debian Security Advisory 1091-1: Several problems have been discovered in the TIFF library.
| | Homepage: | http://www.debian.org/security | | File Size: | 18748 | | Last Modified: | Jun 11 04:17:37 2006 |
| MD5 Checksum: | 742f82e0c7aa1bad6f685faf531ae3cc |
|
| /// File Name: |
sa20554.txt |
Description:
|
Secunia Security Advisory - r0t has reported some vulnerabilities in My Photo Scrapbook, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/20554/ | | File Size: | 2577 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 9e9c5947316764037f1f618413b2dcd9 |
|
| /// File Name: |
sa20552.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/20552/ | | File Size: | 2904 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 3ba5510a8855f7afa626e8c61e814191 |
|
| /// File Name: |
sa20551.txt |
Description:
|
Secunia Security Advisory - Federico Fazzi has discovered a vulnerability in 0verkill, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/20551/ | | File Size: | 2216 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 3c7e5104a15c139197633180288ae74c |
|
| /// File Name: |
sa20550.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for binutils. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20550/ | | File Size: | 7168 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | ca3dbedb76ab61b7bc8847ab25b5a83e |
|
| /// File Name: |
sa20549.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for xine-lib. This fixes a weakness, which can be exploited by malicious people to crash certain applications on a user's system.
| | Homepage: | http://secunia.com/advisories/20549/ | | File Size: | 4878 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | e30491739bf345bb178cbead169d9db8 |
|
| /// File Name: |
sa20548.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for courier-mta. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/20548/ | | File Size: | 19428 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 7e50e408dfa4e388ce4527dfc225e0d5 |
|
| /// File Name: |
sa20547.txt |
Description:
|
Secunia Security Advisory - David 'Aesthetico' Vieira-Kurz has discovered some vulnerabilities in i.List, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.
| | Homepage: | http://secunia.com/advisories/20547/ | | File Size: | 2688 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 0aec1284a6e1e03e39cb66a9f9ae14aa |
|
| /// File Name: |
sa20545.txt |
Description:
|
Secunia Security Advisory - r0t has reported two vulnerabilities in OfficeFlow, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/20545/ | | File Size: | 2542 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | d57fcde547fce1f83b80b1c84e3b83f6 |
|
| /// File Name: |
sa20544.txt |
Description:
|
Secunia Security Advisory - r0t has reported a vulnerability in VanillaSoft Helpdesk, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/20544/ | | File Size: | 2314 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | d8d83e000cadc32799241ca10346ee9e |
|
| /// File Name: |
sa20543.txt |
Description:
|
Secunia Security Advisory - Claus Berghamer has discovered a vulnerability in FilZip, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/20543/ | | File Size: | 2311 | | Last Modified: | Jun 10 07:36:59 2006 |
| MD5 Checksum: | 112cf9ec2d861428277ba165057977a7 |
|
|
|
|
|