Section: .. / Last 20 Advisory Files /
| /// File Name: | MDVSA-2008-210-1.txt | Description:
| Mandriva Linux Security Advisory - CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. The updated packages have been patched to fix the issue. This update was too late for inclusion in Mandriva Linux 2009, so it is being released now for that version. | | Homepage: | http://www.mandriva.com/security/ | | File Size: | 5953 | | Related CVE(s): | CVE-2008-3906 | | Last Modified: | Oct 11 15:02:13 2008 | | MD5 Checksum: | 06dd87708ce37a3441979abe0dfdb2c1 |
|
| /// File Name: | MDVSA-2008-211.txt | Description:
| Mandriva Linux Security Advisory - A buffer overflow in the SGI image format decoding routines used by the CUPS image converting filter imagetops was discovered. An attacker could create malicious SGI image files that could possibly execute arbitrary code if the file was printed. An integer overflow flaw leading to a heap buffer overflow was found in the Text-to-PostScript texttops filter. An attacker could create a malicious text file that could possibly execute arbitrary code if the file was printed. Finally, an insufficient buffer bounds checking flaw was found in the HP-GL/2-to-PostScript hpgltops filter. An attacker could create a malicious HP-GL/2 file that could possibly execute arbitrary code if the file was printed. The updated packages have been patched to prevent this issue; for Mandriva Linux 2009.0 the latest CUPS version (1.3.9) is provided that corrects these issues and also provides other bug fixes. | | Homepage: | http://www.mandriva.com/security/ | | File Size: | 10694 | | Related CVE(s): | CVE-2008-3639, CVE-2008-3640, CVE-2008-3641 | | Last Modified: | Oct 11 15:00:49 2008 | | MD5 Checksum: | 869230af219e9221f53868047fa06838 |
|
| /// File Name: | dsa-1646-2.txt | Description:
| Debian Security Advisory 1646-2 - In DSA 1646-1, an update was announced for a denial of service vulnerability in squid, a caching proxy server. Due to an error in packaging and in testing, the updated packages did not correct the weakness. An updated release is available which corrects the error. A weakness has been discovered in squid, a caching proxy server. The flaw was introduced upstream in response to CVE-2007-6239, and announced by Debian in DSA-1482-1. The flaw involves an over-aggressive bounds check on an array resize, and could be exploited by an authorized client to induce a denial of service condition against squid. | | Homepage: | http://www.debian.org/security | | File Size: | 8925 | | Related CVE(s): | CVE-2008-1612 | | Last Modified: | Oct 11 15:00:34 2008 | | MD5 Checksum: | db72af7c11346b839c9aaceb342e2df5 |
|
| /// File Name: | ZDI-08-067.txt | Description:
| A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple CUPS. Authentication is not required to exploit this vulnerability. The specific flaw exists in the Hewlett-Packard Graphics Language filter. Inadequate bounds checking on the pen width and pen color opcodes result in an arbitrary memory overwrite allowing for the execution of arbitrary code as the "hgltops" process uid. | | Author: | regenrecht | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3091 | | Related CVE(s): | CVE-2008-3641 | | Last Modified: | Oct 11 14:39:14 2008 | | MD5 Checksum: | 9926adae42bd4b463869d0112262dd6b |
|
| /// File Name: | FSC20081009-11.txt | Description:
| A vulnerability has been discovered in the Tape Engine component of CA ARCserve Backup. Insufficient input validation when processing remote procedure call (RPC) requests is the cause of this vulnerability. | | Homepage: | http://www.assurent.com/ | | File Size: | 2161 | | Related CVE(s): | CVE-2008-4398 | | Last Modified: | Oct 10 21:32:38 2008 | | MD5 Checksum: | 628af77713856e077db65ab767d82779 |
|
| /// File Name: | FSC20081009-12.txt | Description:
| A vulnerability has been discovered in the DB Engine component of CA ARCserve Backup. Insufficient input validation when processing remote procedure call (RPC) requests is the cause of this vulnerability. | | Homepage: | http://www.assurent.com/ | | File Size: | 2128 | | Related CVE(s): | CVE-2008-4399 | | Last Modified: | Oct 10 21:31:29 2008 | | MD5 Checksum: | 244cf771a1069b5574ae72a7a89d427e |
|
| /// File Name: | caarcserve-dos.txt | Description:
| CA ARCserve Backup contains multiple vulnerabilities that can allow a remote attacker to cause a denial of service or possibly execute arbitrary code. CA has issued patches to address the vulnerabilities. The first vulnerability occurs due to insufficient validation of certain RPC call parameters by the message engine service. An attacker can exploit a directory traversal vulnerability to execute arbitrary commands. The second vulnerability occurs due to insufficient validation by the tape engine service. An attacker can make a request that will crash the service. The third vulnerability occurs due to insufficient validation by the database engine service. An attacker can make a request that will crash the service. The fourth vulnerability occurs due to insufficient validation of authentication credentials. An attacker can make a request that will crash multiple services. Note that these issues only affect the base product. | | Author: | Ken Williams | | Homepage: | http://www3.ca.com/ | | File Size: | 6325 | | Related CVE(s): | CVE-2008-4397, CVE-2008-4398, CVE-2008-4399, CVE-2008-4400 | | Last Modified: | Oct 9 18:54:03 2008 | | MD5 Checksum: | 3d3a5ef9e28febb30c8e338d187c076a |
|
| /// File Name: | glsa-200810-02.txt | Description:
| Gentoo Linux Security Advisory GLSA 200810-02 - A search path vulnerability in Portage allows local attackers to execute commands with root privileges if emerge is called from untrusted directories. The Gentoo Security Team discovered that several ebuilds, such as sys-apps/portage, net-mail/fetchmail or app-editors/leo execute Python code using python -c, which includes the current working directory in Python's module search path. For several ebuild functions, Portage did not change the working directory from emerge's working directory. Versions less than 2.1.4.5 are affected. | | Homepage: | http://security.gentoo.org | | File Size: | 3143 | | Related CVE(s): | CVE-2008-4394 | | Last Modified: | Oct 9 18:50:17 2008 | | MD5 Checksum: | 8b3fc0142e706b0bc424bf0de635b50a |
|
| /// File Name: | SSRT080099.txt | Description:
| HP Security Bulletin - A potential security vulnerability has been identified with HP System Management Homepage (SMH) for Linux and Windows. This vulnerability could by exploited remotely to allow cross site scripting (XSS). | | Homepage: | http://www.hp.com/ | | File Size: | 6336 | | Related CVE(s): | CVE-2008-4411 | | Last Modified: | Oct 9 18:27:04 2008 | | MD5 Checksum: | e41a3e41c12ed4aacb9e65ddbc1a2496 |
|
| /// File Name: | SSRT080046.txt | Description:
| HP Security Bulletin - A potential security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to create a Denial of Service (DoS). | | Homepage: | http://www.hp.com/ | | File Size: | 9501 | | Related CVE(s): | CVE-2008-3545 | | Last Modified: | Oct 9 18:26:34 2008 | | MD5 Checksum: | 2c42be5796f5be939d3a7312bce7f855 |
|
| /// File Name: | ZDI-08-066.txt | Description:
| A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within dhost.exe, the service responsible for directory replication which is bound by default to TCP port 524. Improper parsing within opcode 0x24 via the Netware Core Protocol can result in an arithmetic calculation based on supplied user-input resulting in an under-allocated heap buffer. This fault can be leveraged to result in arbitrary code execution. | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3426 | | Related CVE(s): | CVE-2008-4480 | | Last Modified: | Oct 9 02:11:57 2008 | | MD5 Checksum: | 790b589691739a22d568d3f8cff2837c |
|
| /// File Name: | ZDI-08-065.txt | Description:
| A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within dhost.exe, the service responsible for directory replication which is bound by default to TCP port 524. Improper parsing within opcode 0x0F via the Netware Core Protocol can result in an arithmetic calculation based on supplied user-input resulting in an integer overflow that will be used to copy into a heap buffer. This fault can be leveraged to result in arbitrary code execution. | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3460 | | Related CVE(s): | CVE-2008-4478 | | Last Modified: | Oct 9 02:10:51 2008 | | MD5 Checksum: | 1022b2e1574faf9e1fb4e47cd4adc33a |
|
| /// File Name: | ZDI-08-064.txt | Description:
| A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The specific flaw resides in the web console running on TCP ports 8028 and 8030. The server exposes a web interface and accepts SOAP connections. The service copies the contents of the Accept-Language header within a SOAP request into a fixed-length buffer without any bounds checking. If an attacker sends a specially crafted request it will trigger an overflow during a memory copy operation leading to arbitrary code execution under the context of the SYSTEM user. | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3472 | | Related CVE(s): | CVE-2008-4479 | | Last Modified: | Oct 9 02:10:02 2008 | | MD5 Checksum: | 424cbdd3ba7f5b2e1149ba96e69d5355 |
|
| /// File Name: | ZDI-08-063.txt | Description:
| A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. The specific flaw resides in the web console running on TCP ports 8028 and 8030. The server exposes a web interface and accepts SOAP connections. While parsing the Content-Length header within a SOAP request an integer overflow can occur. This integer overflow triggers a subsequent overflow during a memory copy operation leading to arbitrary code execution under the context of the SYSTEM user. | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3400 | | Related CVE(s): | CVE-2008-4478 | | Last Modified: | Oct 9 02:08:58 2008 | | MD5 Checksum: | b5bd70f449849cc7f79a158d7d2476ba |
|
| /// File Name: | dsa-1649-1.txt | Description:
| Debian Security Advisory 1649-1 - Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. | | Homepage: | http://www.debian.org/security | | File Size: | 11583 | | Related CVE(s): | CVE-2008-0016, CVE-2008-3835, CVE-2008-3836, CVE-2008-3837, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4065, CVE-2008-4066, CVE-2008-4067, CVE-2008-4068, CVE-2008-4069 | | Last Modified: | Oct 9 02:07:30 2008 | | MD5 Checksum: | de994baacd30c719fd3c122572aac0ba |
|
| /// File Name: | dsa-1648-1.txt | Description:
| Debian Security Advisory 1648-1 - Dmitry E. Oboukhov discovered that the test.alert script used in one of the alert functions in mon, a system to monitor hosts or services and alert about problems, creates temporary files insecurely, which may lead to a local denial of service through symlink attacks. | | Homepage: | http://www.debian.org/security | | File Size: | 5010 | | Related CVE(s): | CVE-2008-4477 | | Last Modified: | Oct 9 02:05:54 2008 | | MD5 Checksum: | eff079919b84da8bf8550b76282317c2 |
|
| /// File Name: | graphviz-overflow.txt | Description:
| A vulnerability exists in Graphviz's parsing engine which makes it possible to overflow a globally allocated array and corrupt memory by doing so. Version 2.20.2 is affected. | | Author: | Roee Hay | | File Size: | 2084 | | Last Modified: | Oct 9 02:05:33 2008 | | MD5 Checksum: | f0a4b70321287389f5f51e6a368aeb51 |
|
|
|
|
|