Section: .. / 0801-advisories /
| /// File Name: |
sa28541.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for e2fsprogs. This fixes a some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28541/ | | File Size: | 4881 | | Last Modified: | Jan 22 10:11:41 2008 |
| MD5 Checksum: | c270f8e7e8727aff14ea682eaf2c4ab1 |
|
| /// File Name: |
sa28555.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/28555/ | | File Size: | 2810 | | Last Modified: | Jan 22 10:11:41 2008 |
| MD5 Checksum: | 214a1f8cc9a60e855adac4cd8cef958e |
|
| /// File Name: |
sa28563.txt |
Description:
|
Secunia Security Advisory - shinnai has discovered two vulnerabilities in Microsoft Visual Basic, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28563/ | | File Size: | 2521 | | Last Modified: | Jan 22 10:11:41 2008 |
| MD5 Checksum: | a32a69c3fa5abc023ae8cd550af31e07 |
|
| /// File Name: |
sa28569.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for libcdio. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28569/ | | File Size: | 2018 | | Last Modified: | Jan 22 10:11:41 2008 |
| MD5 Checksum: | 7db4ae9b8dd9a1d034b40d0bc829da88 |
|
| /// File Name: |
sa28570.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for netscape-flash. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28570/ | | File Size: | 2456 | | Last Modified: | Jan 22 10:11:41 2008 |
| MD5 Checksum: | 528aab035444954f718dc112127489c9 |
|
| /// File Name: |
MDVSA-2008-018.txt |
Description:
|
Mandriva Linux Security Advisory - Kalle Olavi Niemitalo found two boundary errors in the fsplib library, a copy of which is included in gFTP source. A remote attacker could trigger these vulnerabilities by enticing a user to download a file with a specially crafted directory or file name, possibly resulting in the execution of arbitrary code or a denial of service.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2786 | | Related CVE(s): | CVE-2007-3961, CVE-2007-3962 | | Last Modified: | Jan 21 21:54:32 2008 |
| MD5 Checksum: | b5a866774fba020ce271f221d962e4be |
|
| /// File Name: |
dsa-1473-1.txt |
Description:
|
Debian Security Advisory 1473-1 - Joachim Breitner discovered that Subversion support in scponly is inherently insecure, allowing execution of arbitrary commands. Further investigation showed that rsync and Unison support suffer from similar issues. In addition, it was discovered that it was possible to invoke with scp with certain options that may lead to execution of arbitrary commands.
| | Homepage: | http://www.debian.org/security | | File Size: | 8365 | | Related CVE(s): | CVE-2007-6350, CVE-2007-6415 | | Last Modified: | Jan 21 21:53:18 2008 |
| MD5 Checksum: | ae621c9d27cd2c653fdf2d7e090d9c5c |
|
| /// File Name: |
dsa-1466-3.txt |
Description:
|
Debian Security Advisory 1466-3 - The X.org fix for CVE-2007-6429 introduced a regression in the MIT-SHM extension, which prevented the start of a few applications. This update provides updated packages for the xfree86 version included in Debian old stable (Sarge) in addition to the fixed packages for Debian stable (Etch), which were provided in DSA 1466-2.
| | Homepage: | http://www.debian.org/security | | File Size: | 155974 | | Related CVE(s): | CVE-2007-5760, CVE-2007-5958, CVE-2007-6427, CVE-2007-6428, CVE-2007-6429, CVE-2008-0006 | | Last Modified: | Jan 21 21:51:45 2008 |
| MD5 Checksum: | 4faf3d5bad176683b1d3e066158db73d |
|
| /// File Name: |
dsa-1472-1.txt |
Description:
|
Debian Security Advisory 1472-1 - Luigi Auriemma discovered that the Xine media player library performed insufficient input sanitising during the handling of RTSP streams, which could lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 12944 | | Related CVE(s): | CVE-2008-0225 | | Last Modified: | Jan 21 21:50:48 2008 |
| MD5 Checksum: | 5fe521d4c0751ac6a64e78352522b815 |
|
| /// File Name: |
dsa-1471-1.txt |
Description:
|
Debian Security Advisory 1471-1 - Several vulnerabilities were found in the the Vorbis General Audio Compression Codec, which may lead to denial of service or the execution of arbitrary code, if a user is tricked into opening to a malformed Ogg Audio file with an application linked against libvorbis.
| | Homepage: | http://www.debian.org/security | | File Size: | 19281 | | Related CVE(s): | CVE-2007-3106, CVE-2007-4029, CVE-2007-4066 | | Last Modified: | Jan 21 21:49:40 2008 |
| MD5 Checksum: | 18ce3d5a0178d5487d15fbac16479678 |
|
| /// File Name: |
sa28572.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in MyBB, which can be exploited by malicious users to conduct SQL injection or cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/28572/ | | File Size: | 2552 | | Last Modified: | Jan 21 21:39:58 2008 |
| MD5 Checksum: | 059636f2eb10ca8b959d32475c9a328c |
|
| /// File Name: |
sa28568.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Small Axe Weblog, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28568/ | | File Size: | 2487 | | Last Modified: | Jan 21 21:39:48 2008 |
| MD5 Checksum: | e78739f096709a0e5f85819f0f98dbeb |
|
| /// File Name: |
sa28577.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Mantis, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/28577/ | | File Size: | 2345 | | Last Modified: | Jan 21 21:39:48 2008 |
| MD5 Checksum: | dba847affba6c58fa811c300a2006d08 |
|
| /// File Name: |
sa28546.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.
| | Homepage: | http://secunia.com/advisories/28546/ | | File Size: | 2742 | | Last Modified: | Jan 21 20:54:08 2008 |
| MD5 Checksum: | 0b105cf30c05767b62defd671d9e6a9c |
|
| /// File Name: |
sa28548.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28548/ | | File Size: | 35361 | | Last Modified: | Jan 21 20:53:54 2008 |
| MD5 Checksum: | d6ac05bf2e2b87215ad8306ebdcfa77b |
|
| /// File Name: |
sa28549.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for tomcat5.5. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks, and a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
| | Homepage: | http://secunia.com/advisories/28549/ | | File Size: | 3533 | | Last Modified: | Jan 21 20:53:54 2008 |
| MD5 Checksum: | 1b8eb8c77a4a99c0ab84a8e2703a5fe1 |
|
| /// File Name: |
sa28578.txt |
Description:
|
Secunia Security Advisory - Oliver Karow has discovered a vulnerability in BitDefender Update Server, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/28578/ | | File Size: | 2469 | | Last Modified: | Jan 21 20:53:54 2008 |
| MD5 Checksum: | 4b10df4c2709e1c993b8602252e65ddb |
|
| /// File Name: |
dsa-1470-1.txt |
Description:
|
Debian Security Advisory 1470-1 - Ulf Harnhammer discovered that the HTML filter of the Horde web application framework performed insufficient input sanitising, which may lead to the deletion of emails if a user is tricked into viewing a malformed email inside the Imp client.
| | Homepage: | http://www.debian.org/security | | File Size: | 3087 | | Related CVE(s): | CVE-2007-6018 | | Last Modified: | Jan 21 20:53:39 2008 |
| MD5 Checksum: | 6c0a1a0119fd0fe26bfcd524c5cfe419 |
|
| /// File Name: |
dsa-1469-1.txt |
Description:
|
Debian Security Advisory 1469-1 - Sean de Regge and Greg Linares discovered multiple heap and stack based buffer overflows in FLAC, the Free Lossless Audio Codec, which could lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 37730 | | Related CVE(s): | CVE-2007-4619, CVE-2007-6277 | | Last Modified: | Jan 21 20:32:35 2008 |
| MD5 Checksum: | 3bc08633ce6fa121390c3072edcff0c3 |
|
| /// File Name: |
MDVSA-2008-017.txt |
Description:
|
Mandriva Linux Security Advisory - MySQL 5.0.x did not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement. The federated engine in MySQL 5.0.x, when performing a certain SHOW TABLE STATUS query, did not properly handle a response with a small number of columns, which could allow a remote MySQL server to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 4903 | | Related CVE(s): | CVE-2007-6303, CVE-2007-6304 | | Last Modified: | Jan 21 20:24:53 2008 |
| MD5 Checksum: | 5460eb92252d60ca72b592bbd519f179 |
|
| /// File Name: |
glsa-200801-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200801-08 - Devon Miller reported a boundary error in the print_iso9660_recurse() function in files cd-info.c and iso-info.c when processing long filenames within Joliet images. Versions less than 0.78.2-r4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2652 | | Related CVE(s): | CVE-2007-6613 | | Last Modified: | Jan 21 20:23:31 2008 |
| MD5 Checksum: | 7717b9ae6e5440312af976f78e6752d2 |
|
|
|
|
|