.:[ packet storm ]:.
                             
security in numbers
security in numbers

 Section:  .. / Last 20 Advisory Files /

 ///  File Name:lateral-sql-followup.txt
Description:
Follow up information regarding a whitepaper about lateral SQL injection and how ALTER SESSION privileges are not needed.
Author:David Litchfield
Homepage:http://www.ngssoftware.com/
Related File:lateral-sql-injection.pdf
File Size:3146
Last Modified:Jul 18 17:19:21 2008
MD5 Checksum:18e62d117823ca0a5a0b55a02c6b4c8f

 ///  File Name:MDVSA-2008-148.txt
Description:
Mandriva Linux Security Advisory - Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.16. This update provides the latest Firefox to correct these issues.
Homepage:http://www.mandriva.com/security/
File Size:60625
Related CVE(s):CVE-2008-2785, CVE-2008-2933
Last Modified:Jul 18 04:33:13 2008
MD5 Checksum:ab9dcc763cd53eb00f2102db6b1ca667

 ///  File Name:vim-filecreation.txt
Description:
Vim version 5.0 through the current version suffer from an arbitrary code execution vulnerability via an insecure temporary file creation flaw.
Author:Jan Minar
File Size:3242
Last Modified:Jul 18 04:32:36 2008
MD5 Checksum:e0aafe45a3a0e558f53b941ce10d137f

 ///  File Name:ZDI-08-044.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the browser's handling reference counters to the nsCSSValue:Array class. Creating more then 65,535 references will overflow a 16-bit reference counter and therefore result in an erroneous free() while the object still exists. Properly manipulated this can result in arbitrary code execution under the context of the current user.
Homepage:http://www.zerodayinitiative.com/
File Size:3515
Related CVE(s):CVE-2008-2785
Last Modified:Jul 17 16:12:30 2008
MD5 Checksum:58c97cd821304abdbc467ae1ad85e405

 ///  File Name:ZDI-08-043.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the GetVMArgsOption() function used while parsing the java-vm-args attribute of the j2se tag in xml based JNLP files. When a user downloads a malicious JNLP file, the vulnerable attribute is read into a static buffer. If an overly long value is defined by the java-vm-args attribute, a stack based buffer overflow occurs, resulting in an exploitable condition.
Homepage:http://www.zerodayinitiative.com/
File Size:3501
Last Modified:Jul 17 16:11:49 2008
MD5 Checksum:cf0518925fb29057bec90deed667e775

 ///  File Name:ZDI-08-042.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the writeManifest() method of the CacheEntry class. A directory traversal flaw in this method allows the creation of arbitrary files on the target system. After the file has been created, a call to Runtime.getRuntime.exec() can be used to execute the file.
Author:Peter Csepely
Homepage:http://www.zerodayinitiative.com/
File Size:3411
Last Modified:Jul 17 16:11:03 2008
MD5 Checksum:40bc93865482ae2445c34853dcd2207d

 ///  File Name:USN-623-1.txt
Description:
Ubuntu Security Notice 623-1 - A flaw was discovered in the browser engine. A variable could be made to overflow causing the browser to crash. If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Billy Rios discovered that Firefox did not properly perform URI splitting with pipe symbols when passed a command-line URI. If Firefox were passed a malicious URL, an attacker may be able to execute local content with chrome privileges.
Homepage:http://security.ubuntu.com/
File Size:22719
Related CVE(s):CVE-2008-2785, CVE-2008-2933
Last Modified:Jul 17 15:29:57 2008
MD5 Checksum:134f5257fe6d05be8b868a8de33caf4f

 ///  File Name:SSRT080097-2.txt
Description:
HP Security Bulletin - Potential security vulnerabilities have been identified with HP Select Identity Active Directory Bidirectional LDAP Connector . The vulnerabilities could be exploited to allow remote unauthorized access.
Homepage:http://www.hp.com/
File Size:6233
Related CVE(s):CVE-2008-1665
Last Modified:Jul 17 15:28:56 2008
MD5 Checksum:16bcd9b00ec4628549a66a8a61cc3f8c

 ///  File Name:SSRT080058.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running BIND. The vulnerability could be exploited remotely to cause DNS cache poisoning.
Homepage:http://www.hp.com/
File Size:6949
Related CVE(s):CVE-2008-1447
Last Modified:Jul 17 15:16:48 2008
MD5 Checksum:81ca5324ef291a1e31b9850373d3dca6

 ///  File Name:dsa-1611-1.txt
Description:
Debian Security Advisory 1611-1 - Anders Kaseorg discovered that afuse, an automounting file system in user-space, did not properly escape meta characters in paths. This allowed a local attacker with read access to the filesystem to execute commands as the owner of the filesystem.
Homepage:http://www.debian.org/security
File Size:5021
Related CVE(s):CVE-2008-2232
Last Modified:Jul 16 20:04:36 2008
MD5 Checksum:667d150cda2558de83b99a4350f259eb

 ///  File Name:n.runs-SA-2008.003.txt
Description:
Apple QuickTime versions prior to 7.5 suffer from a heap overflow vulnerability when handling PICT images.
Author:Sergio Alvarez
Homepage:http://www.nruns.com/
File Size:9491
Last Modified:Jul 16 15:49:48 2008
MD5 Checksum:86cef345102da7283cb680756f7c7847

 ///  File Name:n.runs-SA-2008.002.txt
Description:
The F-Prot Anti-Virus engine versions below 4.4.4 suffer form an out-of-bounds memory access denial of service vulnerability.
Author:Sergio Alvarez
Homepage:http://www.nruns.com/
File Size:5248
Last Modified:Jul 16 15:48:37 2008
MD5 Checksum:f9e5ad9d51dc0e30c8a0d4478a729c61

 ///  File Name:dsa-1544-2.txt
Description:
Debian Security Advisory 1544-2 - Thomas Biege discovered that the upstream fix for the weak random number randomization did still not use difficult-to-predict random numbers. This is corrected in this security update.
Homepage:http://www.debian.org/security
File Size:5057
Related CVE(s):CVE-2008-1637
Last Modified:Jul 16 15:45:43 2008
MD5 Checksum:82e55904d542f28198d9499d43db9a50

 ///  File Name:SSRT080097.txt
Description:
HP Security Bulletin - Potential security vulnerabilities have been identified with HP Select Identity Active Directory Bidirectional LDAP Connector . The vulnerabilities could be exploited to allow remote unauthorized access.
Homepage:http://www.hp.com/
File Size:6092
Related CVE(s):CVE-2008-1665
Last Modified:Jul 16 15:43:55 2008
MD5 Checksum:a11f1f733768ff70d0e990e3269f40d2

 ///  File Name:netrw-exec.txt
Description:
Lack of sanitization throughout Netrw can lead to arbitrary code execution upon opening a directory with a crafted name.
Author:Jan Minar
File Size:5137
Last Modified:Jul 16 15:43:19 2008
MD5 Checksum:0a45093ff0e3eb716b14884b0b054a39

 ///  File Name:vim72b-exec.txt
Description:
Vim versions greater than and equal to 7.2.a.013 suffer from an arbitrary code execution vulnerability using the shellescape() function.
Author:Jan Minar
File Size:3450
Last Modified:Jul 16 15:42:12 2008
MD5 Checksum:9315516bf2b023bbb2f7e8cdfb678067

 ///  File Name:MDVSA-2008-147.txt
Description:
Mandriva Linux Security Advisory - Tavis Ormandy of the Google Security Team discovered a heap-based buffer overflow when compiling certain regular expression patterns. This could be used by a malicious attacker by sending a specially crafted regular expression to an application using the PCRE library, resulting in the possible execution of arbitrary code or a denial of service. The updated packages have been patched to correct this issue.
Homepage:http://www.mandriva.com/security/
File Size:4319
Related CVE(s):CVE-2008-2371
Last Modified:Jul 16 14:50:23 2008
MD5 Checksum:b8e63c1a7fd5d361e566c9cacb751161

 ///  File Name:USN-625-1.txt
Description:
Ubuntu Security Notice 625-1 - A massive slew of Linux kernel related vulnerabilities have been addressed for the linux-source-2.6.15/20/22 packages.
Homepage:http://security.ubuntu.com/
File Size:192927
Related CVE(s):CVE-2007-6282, CVE-2007-6712, CVE-2008-0598, CVE-2008-1615, CVE-2008-1673, CVE-2008-2136, CVE-2008-2137, CVE-2008-2148, CVE-2008-2358, CVE-2008-2365, CVE-2008-2729, CVE-2008-2750, CVE-2008-2826
Last Modified:Jul 16 14:50:16 2008
MD5 Checksum:5e9e19eec557961a1d40d8762fd5cff3

 ///  File Name:MDVSA-2008-146.txt
Description:
Mandriva Linux Security Advisory - A memory management issue was found in libpoppler by Felipe Andres Manzano that could allow for the execution of arbitrary code with the privileges of the user running a poppler-based application, if they opened a specially crafted PDF file. The updated packages have been patched to correct this issue.
Homepage:http://www.mandriva.com/security/
File Size:6044
Related CVE(s):CVE-2008-2950
Last Modified:Jul 15 21:09:57 2008
MD5 Checksum:37e194777605bac78445c2e820e31d67

 ///  File Name:07.15.08-3.txt
Description:
iDefense Security Advisory 07.15.08 - Local exploitation of an untrusted library path vulnerability in Oracle Corp.'s Oracle Database product allows attackers to gain elevated privileges. This vulnerability specifically exists in a set-uid root program distributed with Oracle Database for Linux and Unix platforms. By replacing a module owned by the oracle user, which is loaded by this program, an attacker can execute arbitrary code as root. iDefense confirmed the existence of this vulnerability in Oracle 11g R1 version 11.1.0.6.0 on 32-bit Linux platform. Previous versions may also be affected.
Author:Joxean Koret
Homepage:http://www.idefense.com/
File Size:3311
Related CVE(s):CVE-2008-2613
Last Modified:Jul 15 20:23:19 2008
MD5 Checksum:e8ee1e493dada84f07feb39294a4a5f6