[SECURITY] [DSA 1799-1] New qemu packages fix several vulnerabilities

2009-05-11 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1799-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff May 11, 2009

[security bulletin] HPSBMA02348 SSRT080033 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Denial of Service (DoS)

2009-05-11 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01495949 Version: 2 HPSBMA02348 SSRT080033 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code, Denial of Service (DoS) NOTICE: The information in this Securi

[security bulletin] HPSBMA02349 SSRT080043 rev.3 - HP OpenView Network Node Manager (OV NNM), Remote Unauthorized Access to Data

2009-05-11 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01496048 Version: 3 HPSBMA02349 SSRT080043 rev.3 - HP OpenView Network Node Manager (OV NNM), Remote Unauthorized Access to Data NOTICE: The information in this Security Bulletin should be act

Re: Five days left to find the oldest data loss incident

2009-05-11 Thread Dragos Ruiu
On 11-May-09, at 7:29 AM, Juha-Matti Laurio wrote: The oldest documented vulnerability in computer security world is password file disclosure vulnerability from 1965, found by Mr. Ryan Russell. Open Security Foundation launched a competition in April to find the oldest documented data lo

[oCERT-2009-004] AjaxTerm session id collision

2009-05-11 Thread Andrea Barisani
#2009-004 AjaxTerm session id collision Description: AjaxTerm, an open source web based terminal, uses a form of random session id generation which can lead to remote session hijacking. The ajaxterm.js script allocates session ids on the client side using the following method: var sid=""+Math

[USN-774-1] MoinMoin vulnerability

2009-05-11 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-774-1 May 11, 2009 moin vulnerability CVE-2009-1482 === A security issue affects the following Ubuntu releases: Ubuntu 8.10 Ubuntu 9.04 Thi

Re: TinyWebGallery <= 1.7.6 LFI / Remote Code Execution Exploit

2009-05-11 Thread michael
Wrong title - because the exploit only is for local file include - no Remote Code execution. - Mike

Five days left to find the oldest data loss incident

2009-05-11 Thread Juha-Matti Laurio
The oldest documented vulnerability in computer security world is password file disclosure vulnerability from 1965, found by Mr. Ryan Russell. Open Security Foundation launched a competition in April to find the oldest documented data loss incident. They have announced that the last day to mak

Advisory - Gmail/Google Doc PDF Repurposing Integrated Attacks - Cookie Hijacking / Stealing

2009-05-11 Thread Aditya K Sood
Hi Google docs network was vulnerable to PDF repurposing attacks. The vulnerability was disclosed to Google with a discretion. This was done to mitigate the risk . Google had worked over it and patched it with in a period of 5 days. The Google doc has been refined now and the integrated support f

RE: Insufficient Authentication vulnerability in Acer notebooks

2009-05-11 Thread David Sánchez Martín
hi folk, Is not that a simple design decission? (truly brain-dead, but a conscious decission). > -Mensaje original- > De: MustLive [mailto:mustl...@websecurity.com.ua] > Enviado el: domingo, 10 de mayo de 2009 15:23 > Para: bugtraq@securityfocus.com > Asunto: Insufficient Authenti

[Bkis-08-2009] Microchip MPLAB IDE Buffer Overflow Vulnerability

2009-05-11 Thread Bkis
Microchip MPLAB IDE Buffer Overflow Vulnerability 1. General Information MPLAB IDE is a famous Integrated Development Environment (IDE) of Microchip (www.microchip.com) that provides a single integrated environment to develop applications for Microchip microcontrollers and digital signal cont

[ MDVSA-2009:109 ] quagga

2009-05-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:109 http://www.mandriva.com/security/

Insufficient Authentication vulnerability in Acer notebooks

2009-05-11 Thread MustLive
Hello SecurityFocus! I want to warn you about vulnerability in Acer notebooks. It's Insufficient Authentication vulnerability. Which I found 28.04.2009 in two my notebooks. At these notebooks Windows XP Home Rus is using, in case of other OS the vulnerability can be also present. In Windows XP

[SECURITY] [DSA 1798-1] New pango1.0 packages fix arbitrary code execution

2009-05-11 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1798-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris May 10, 2009

TinyWebGallery <= 1.7.6 LFI / Remote Code Execution Exploit

2009-05-11 Thread travesti
http://www.travesti.in details..: this vulnerability drift from QuiXplorer (http://quixplorer.sourceforge.net/) exp link.: http://www.travesti.in/ex.txt This PoC was written for educational purpose. Use it at your own risk. Author will be not responsible for any dama