Section: .. / 0702-advisories /
| /// File Name: |
CVE-2007-0454.tgz |
Description:
|
The name of a file on the server's share is used as the format string when setting an NT security descriptor through the afsacl.so VFS plugin. This affects Samba versions 3.0.6 through 3.0.23d. Patch included.
| | Homepage: | http://www.samba.org/ | | File Size: | 1689 | | Related CVE(s): | CVE-2007-0454 | | Last Modified: | Feb 6 00:38:08 2007 |
| MD5 Checksum: | eccb0d5eb64aff39de90329ce4125dc9 |
|
| /// File Name: |
CVE-2007-0452.tgz |
Description:
|
A logic error in the deferred open code can lead to an infinite loop in smbd. This affect Samba versions 3.0.6 through 3.0.23d. Patch included.
| | Homepage: | http://www.samba.org/ | | File Size: | 2930 | | Related CVE(s): | CVE-2007-0452 | | Last Modified: | Feb 6 00:35:24 2007 |
| MD5 Checksum: | f0ba91b5de2d60182956874ec84f0bc6 |
|
| /// File Name: |
CVE-2007-0453.tgz |
Description:
|
Samba versions 3.0.21 through 3.0.23d suffer from a potential overrun in the gethostbyname() and getipnodebyname() in the nss_winbind.so.1 library on Solaris that can potentially allow for code execution. Patch included.
| | Author: | Olivier Gay | | Homepage: | http://www.samba.org/ | | File Size: | 1777 | | Related CVE(s): | CVE-2007-0453 | | Last Modified: | Feb 6 00:33:25 2007 |
| MD5 Checksum: | 9d2e2d59f2d09444848d5da2e098f6be |
|
| /// File Name: |
firefox-popup.txt |
Description:
|
There is an interesting vulnerability in the default behavior of Firefox builtin popup blocker. This vulnerability, coupled with an additional trick, allows the attacker to read arbitrary user-accessible files on the system, and thus steal some fairly sensitive information. This was tested on 1.5.0.9.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 4615 | | Last Modified: | Feb 6 00:07:25 2007 |
| MD5 Checksum: | 539edaff52bc57444bea4293420707f2 |
|
| /// File Name: |
vmware-weak.txt |
Description:
|
VMware Workstation version 5.5.3 build 34685 suffers from isolation failure and information leakage conditions.
| | Author: | Eitan Caspi | | File Size: | 8753 | | Last Modified: | Feb 6 00:03:59 2007 |
| MD5 Checksum: | 8a34145628a89038d96e44fb844d2ad9 |
|
| /// File Name: |
xmlhttprequest.txt |
Description:
|
A newline-and-tab technology along with the Msxml2.XMLHTTP ActiveX object in Microsoft Internet Explorer allows an attacker to bypass restrictions thus allowing XMLHttpRequest to interact with other sites.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 3458 | | Last Modified: | Feb 6 00:02:03 2007 |
| MD5 Checksum: | b29e0a763eb91c6def25f80552a014bd |
|
| /// File Name: |
ublog-inject.txt |
Description:
|
Ublog Reload version 1.0.5 suffers from multiple html injection vulnerabilities.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1406 | | Last Modified: | Feb 5 23:58:23 2007 |
| MD5 Checksum: | ea4329422981a57a2c37faeda06c9630 |
|
| /// File Name: |
bugzilla-multiple.txt |
Description:
|
Bugzilla Security Advisory - Bugzilla versions 2.20.1 and above suffer from a cross site scripting vulnerability. Version 2.23.3 suffers from a database password disclosure flaw.
| | Author: | Frederic Buclin, Dave Miller, Olav Vitters, Max Kanat-Alexander | | Homepage: | http://www.bugzilla.org/ | | File Size: | 3732 | | Last Modified: | Feb 5 23:24:19 2007 |
| MD5 Checksum: | 69ffd8fbfbab9aae67c189f99ee9d20b |
|
| /// File Name: |
MDKSA-2007-032.txt |
Description:
|
Mandriva Linux Security Advisory - The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3124 | | Related CVE(s): | CVE-2007-0578 | | Last Modified: | Feb 5 23:21:54 2007 |
| MD5 Checksum: | f7025f13a7d027995e4910ea0d7b896c |
|
| /// File Name: |
MDKSA-2007-031.txt |
Description:
|
Mandriva Linux Security Advisory - FIXME Konqueror 3.5.5 does not properly parse HTML comments in title tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment, a related issue to CVE-2007-0478.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 5097 | | Related CVE(s): | CVE-2007-0478, CVE-2007-0537 | | Last Modified: | Feb 5 23:21:11 2007 |
| MD5 Checksum: | cc717265631106caba755eb8dd9e09de |
|
| /// File Name: |
USN-415-1.txt |
Description:
|
Ubuntu Security Notice 415-1 - A flaw was discovered in the error handling of GTK's image loading library. Applications opening certain corrupted images could be made to crash, causing a denial of service.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 15706 | | Related CVE(s): | CVE-2007-0010 | | Last Modified: | Feb 5 23:18:03 2007 |
| MD5 Checksum: | 64f24ebe7615fac59d16b1844dabbe74 |
|
| /// File Name: |
ipswitch504-exec.txt |
Description:
|
Ipswitch WS_FTP Server version 5.04 suffers from multiple arbitrary code execution vulnerabilities.
| | Author: | sapheal | | File Size: | 1256 | | Last Modified: | Feb 5 23:12:11 2007 |
| MD5 Checksum: | 41c3dc01b6ba7b5d157817bca31c3260 |
|
| /// File Name: |
BTP00000P005CF.txt |
Description:
|
Comodo Firewall Pro (former Comodo Personal Firewall) hooks many functions in SSDT and in at least seven cases it fails to validate arguments that come from the user mode. Affected versions include Comodo Firewall Pro 2.4.16.174 and Comodo Personal Firewall 2.3.6.81.
| | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00000P005CF.zip | | File Size: | 1169 | | Last Modified: | Feb 5 23:05:13 2007 |
| MD5 Checksum: | 70dbf1a4a2904f73f4f89fba108d3b43 |
|
| /// File Name: |
sa24013.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for kdelibs. This fixes a weakness, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/24013/ | | File Size: | 3111 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 3c7afb03a7bd6e507cc0f774bcf790a9 |
|
| /// File Name: |
sa24019.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been discovered in Coppermine Photo Gallery, which can be exploited by malicious users to disclose sensitive information and to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/24019/ | | File Size: | 2945 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | c8991a75db3abe21cc94a918b6eacd88 |
|
| /// File Name: |
sa24025.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for wireshark and tshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24025/ | | File Size: | 2250 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 7ac09c44af2891e04ad262c745665ba2 |
|
| /// File Name: |
sa24029.txt |
Description:
|
Secunia Security Advisory - ajann has discovered a vulnerability in Photo Galerie Script, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/24029/ | | File Size: | 2413 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 85ce99ee37594d1667794932dd34520d |
|
| /// File Name: |
sa24031.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Bugzilla, which can be exploited by malicious users to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/24031/ | | File Size: | 2391 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 988e4323cd69ca634521f7ae4d7b9266 |
|
| /// File Name: |
sa24033.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in PostgreSQL, which can be exploited by malicious users to gain knowledge of potentially sensitive information and cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24033/ | | File Size: | 2738 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 17f54a59035b7c28c80cab246e10a4b9 |
|
| /// File Name: |
sa24034.txt |
Description:
|
Secunia Security Advisory - xoron has reported a vulnerability in phpBB++, which can be exploited by malicious people to compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/24034/ | | File Size: | 2433 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 46de034010e75c4b15550461fae69c3c |
|
| /// File Name: |
sa24037.txt |
Description:
|
Secunia Security Advisory - ThE dE@Th has discovered a vulnerability in DreamStats, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24037/ | | File Size: | 2392 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | bb89f45bf416c68275f91960b96994b4 |
|
|
|
|
|