Section: .. / 0612-advisories /
| /// File Name: |
sa23385.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for gdm. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23385/ | | File Size: | 4435 | | Last Modified: | Dec 15 10:27:42 2006 |
| MD5 Checksum: | 2b45062439d6a4f5d3107f6143a6e42b |
|
| /// File Name: |
sa23389.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for links. This fixes a vulnerability, which can be exploited by malicious people to expose sensitive information and manipulate data.
| | Homepage: | http://secunia.com/advisories/23389/ | | File Size: | 2238 | | Last Modified: | Dec 15 10:27:24 2006 |
| MD5 Checksum: | 4a812a1398e2458586b8c387ee83101f |
|
| /// File Name: |
sa23387.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in the gdmchooser application of the GNOME Display Manager, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23387/ | | File Size: | 2594 | | Last Modified: | Dec 15 10:27:24 2006 |
| MD5 Checksum: | 82155f5ea60aa5245c0daca7ac123905 |
|
| /// File Name: |
CORE-2006-1127.txt |
Description:
|
Core Security Technologies Advisory - A locally exploitable stack overflow vulnerability has been found in the mod_ctrls module of ProFTPD server. ProFTPD versions 1.3.0a and 1.3.0 are affected.
| | Author: | Alfredo Ortega | | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 8433 | | Last Modified: | Dec 15 10:27:03 2006 |
| MD5 Checksum: | 6096a9dd5e3ec88cb5749723f3b93f9c |
|
| /// File Name: |
db2dos.txt |
Description:
|
IBM's DB2 suffers from a remote denial of service condition during CONNECT processing.
| | Author: | Vivek Rathod | | Homepage: | http://www.appsecinc.com/ | | File Size: | 2511 | | Related CVE(s): | CVE-2006-4257 | | Last Modified: | Dec 15 10:25:23 2006 |
| MD5 Checksum: | 54076abe7eb3aa992558fb05a44fb143 |
|
| /// File Name: |
coolplayer215.txt |
Description:
|
Coolplayer versions 215 and below suffer from multiple boundary error conditions.
| | Author: | Mehdi Oudad, Kevin Fernandez | | File Size: | 1540 | | Last Modified: | Dec 15 10:20:26 2006 |
| MD5 Checksum: | 3c17a0866c9560a8020efea41428345d |
|
| /// File Name: |
iis51asp.txt |
Description:
|
IIS 5.1 suffers from a flaw where it allows an ASP shell to be spawned via execute rights for IUSR_Machine.
| | Author: | Brett Moore | | File Size: | 3630 | | Last Modified: | Dec 15 10:18:43 2006 |
| MD5 Checksum: | 27c670b23ab54e041855dfd8e033d2a7 |
|
| /// File Name: |
secunia-iescript.txt |
Description:
|
Secunia Research has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error within the exception handling of script errors. This can be exploited to corrupt memory via an HTML document containing specially crafted JavaScript that triggers certain errors simultaneously. Microsoft Internet Explorer 6.0 is affected.
| | Author: | Jakob Balle, Carsten Eiram | | Homepage: | http://secunia.com/ | | File Size: | 3904 | | Related CVE(s): | CVE-2006-5579 | | Last Modified: | Dec 15 10:03:31 2006 |
| MD5 Checksum: | 0d1a5d8fed13912ddba36e83cd8697d5 |
|
| /// File Name: |
12.12.06-2.txt |
Description:
|
iDefense Security Advisory 12.12.06 - Local exploitation of a directory traversal vulnerability in ld.so could potentially allow a non root user to execute arbitrary code as root. iDefense has confirmed that Solaris 10 for both x86 and SPARC is vulnerable. It is speculated that older versions of Solaris are vulnerable as well.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3882 | | Last Modified: | Dec 15 10:01:38 2006 |
| MD5 Checksum: | ca8e1ff30728bf31c6ffdc63bf0606d1 |
|
| /// File Name: |
12.12.06-1.txt |
Description:
|
iDefense Security Advisory 12.12.06 - Local exploitation of a buffer overflow vulnerability in ld.so could potentially allow a non root user to execute arbitrary code as root. iDefense has confirmed that Solaris 10 for both x86 and SPARC is vulnerable. Older versions of Solaris are likely to be vulnerable as well.
| | Author: | Sean Larsson | | Homepage: | http://www.idefense.com/ | | File Size: | 5388 | | Last Modified: | Dec 15 09:59:41 2006 |
| MD5 Checksum: | ac1761d2572b44e616c2ffe2f2101f37 |
|
| /// File Name: |
ZDI-06-046.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sophos Anti-Virus. The specific flaw exists in the parsing of SIT archives. When a long non-null terminated filename is processed by veex.dll, a heap overflow occurs due to the miscalculation of the string's actual size. Exploitation is possible leading to remote code execution running under the SYSTEM context.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2557 | | Related CVE(s): | CVE-2006-6335 | | Last Modified: | Dec 15 09:51:18 2006 |
| MD5 Checksum: | 574724912b52b37ed18d1d664973f1bd |
|
| /// File Name: |
openLDAPslapd.txt |
Description:
|
There is a remotely exploitable buffer overflow in the Kerberos KBIND authentication code in the OpenLDAP slapd server for versions 2.4.3 and below. Note that the vulnerable code only exists in versions compiled with the --enabled-kbind option.
| | Author: | Solar Eclipse | | Homepage: | http://www.phreedom.org/solar/ | | Related Exploit: | openldap-kbind-p00f.c | | File Size: | 1586 | | Last Modified: | Dec 15 09:45:54 2006 |
| MD5 Checksum: | 556f08e3c45be942cff3c7201c4a3991 |
|
| /// File Name: |
sitekiosk-xss.txt |
Description:
|
SiteKiosk versions below 6.5.150 suffer from a validation input flaw that allows for cross site scripting and arbitrary filesystem access.
| | Author: | Brett Moore | | Homepage: | http://security-assessment.com/ | | File Size: | 3691 | | Last Modified: | Dec 15 09:34:44 2006 |
| MD5 Checksum: | 85430b6f7d57504b6e04310ee5630ecb |
|
| /// File Name: |
USN-380-2.txt |
Description:
|
Ubuntu Security Notice 380-2 - avahi regression: USN-380-1 fixed a vulnerability in Avahi. However, if used with Network manager, that version occasionally failed to resolve .local DNS names until Avahi got restarted. This update fixes the problem.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 37264 | | Last Modified: | Dec 14 23:55:24 2006 |
| MD5 Checksum: | bb3faaed1d51b32fd4b265762aae8307 |
|
| /// File Name: |
USN-395-1.txt |
Description:
|
Ubuntu Security Notice 395-1 - Multiple vulnerabilities in the Linux Kernel.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 138230 | | Last Modified: | Dec 14 23:54:38 2006 |
| MD5 Checksum: | b9937e102aa738fbc55866c983272d69 |
|
| /// File Name: |
ZDI-06-045.txt |
Description:
|
ZDI-06-045: Sophos Anti-Virus CPIO Archive Parsing Buffer Overflow Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2707 | | Last Modified: | Dec 14 23:53:20 2006 |
| MD5 Checksum: | 3a51060f8f0625ce78e55b39aa04fc5c |
|
| /// File Name: |
ZDI-06-047.txt |
Description:
|
ZDI-06-047: Microsoft Visual Studio WmiScriptUtils.dll Cross-Zone Scripting Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3080 | | Last Modified: | Dec 14 23:52:46 2006 |
| MD5 Checksum: | d7e0aed6dc9e552cfa10329e3273cf33 |
|
| /// File Name: |
ZDI-06-048.txt |
Description:
|
ZDI-06-048: Microsoft Internet Explorer normalize() Function Memory Corruption Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2773 | | Last Modified: | Dec 14 23:52:19 2006 |
| MD5 Checksum: | 74f6b3b67cb6b9f7846eac9700a2f314 |
|
| /// File Name: |
ZDI-06-049.txt |
Description:
|
ZDI-06-049: Symantec Veritas NetBackup Long Request Buffer Overflow Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2875 | | Last Modified: | Dec 14 23:51:48 2006 |
| MD5 Checksum: | 6b41b66ed4d64aa7d2d6b9b3e71555ea |
|
| /// File Name: |
ZDI-06-050.txt |
Description:
|
ZDI-06-050: Symantec Veritas NetBackup CONNECT_OPTIONS Buffer Overflow Vulnerability
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2900 | | Last Modified: | Dec 14 23:49:24 2006 |
| MD5 Checksum: | 6fba51c6d288e6d86e0b1eb762cdad16 |
|
| /// File Name: |
rPSA-2006-0230-1.txt |
Description:
|
rPath Security Advisory: 2006-0230-1 Previous versions of the evince package contain a vulnerability that enables attackers to provide intentionally malformed postscript files which will cause evince to execute arbitrary attacker-provided code. (This vulnerability was originally discovered in the gv program.)
| | Homepage: | http://www.rpath.com | | File Size: | 889 | | Last Modified: | Dec 14 23:47:53 2006 |
| MD5 Checksum: | dca61a40323a399718db778de1f7a52c |
|
| /// File Name: |
rPSA-2006-0231-1.txt |
Description:
|
rPath Security Advisory: 2006-0231-1 Previous versions of the squirrelmail package are vulnerable to multiple cross-site scripting (XSS) attacks that allow the attacker to subvert web browsers being used with squirrelmail.
| | Homepage: | http://www.rpath.com | | File Size: | 787 | | Last Modified: | Dec 14 23:47:28 2006 |
| MD5 Checksum: | 91ff1abb24d337258261bc08366ce33c |
|
| /// File Name: |
rPSA-2006-0232-1.txt |
Description:
|
rPath Security Advisory: 2006-0232-1 - Previous versions of the libgsf package contain a flaw in parsing OLE documents that could allow an attacker to crash applications that use libgsf, and possibly to cause them to execute arbitrary code, by presenting a user with an intentionally malformed OLE document.
| | Homepage: | http://www.rpath.com | | File Size: | 883 | | Last Modified: | Dec 14 23:46:51 2006 |
| MD5 Checksum: | d3120dc2436e3d5725c6447be6268b73 |
|
| /// File Name: |
DSA-1234-1.txt |
Description:
|
Debian Security Advisory 1234-1: A denial of service vulnerability has been discovered in the CGI library included with Ruby, the interpreted scripting language for quick and easy object-oriented programming.
| | Homepage: | http://www.debian.org/security | | File Size: | 28943 | | Last Modified: | Dec 14 22:43:45 2006 |
| MD5 Checksum: | b9b3642a2d1b73563eb353d2fb1eb3cd |
|
| /// File Name: |
DSA-1235-1.txt |
Description:
|
Debian Security Advisory 1235-1: A denial of service vulnerability has been discovered in the CGI library included with Ruby, the interpreted scripting language for quick and easy object-oriented programming.
| | Homepage: | http://www.debian.org/security | | File Size: | 21332 | | Last Modified: | Dec 14 22:43:01 2006 |
| MD5 Checksum: | fee77b125724711e784faa7f76507aa1 |
|
|
|
|
|