company solutions service design
» chop solutions » security news

news aus der it-welt

news von SecurityTrackerexterner Link

»Symantec Data Loss Prevention KeyView Filter Memory Corruption Errors Let Remote Users Deny Service
NULL

»Symantec Mail Security KeyView Filter Memory Corruption Errors Let Remote Users Execute Arbitrary Code
NULL

»IBM Lotus Notes Memory Corruption Errors in Various File Readers Let Remote Users Execute Arbitrary Code
NULL

»LVM2 Missing Authentication in Cluster Local Volume Manager Lets Local Users Manage Volumes in the Cluster
NULL

»Apple Safari Memory Corruption Errors Let Remote Users Execute Arbitrary Code
NULL

»Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
NULL

»w3m NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certificates
NULL

»JBoss Seam Input Validation Flaw in Processing JBoss Expression Language Expressions Lets Remote Users Execute Arbitrary Code
NULL

»Nessus Web Server Input Validation Flaw Permits Cross-Site Scripting Attacks
NULL

»Symantec Antivirus Corporate Edition Alert Management Service Lets Remote Users Execute Arbitrary Code
NULL

»Mac OS X WebDAV Memory Allocation Error Lets Local Users Deny Service
NULL

»Citi Mobile Local File Storage May Disclose Potentially Sensitive Information to Local Users
NULL

»GnuPG GPGSM Tool Certificate Import Memory Error May Let Remote Users Execute Arbitrary Code
NULL

»Mozilla Firefox Regression Error in Plugin Parameter Array Fix Lets Remote Users Execute Arbitrary Code
NULL

»Apple Safari AutoFill Discloses Potentially Sensitive Information to Remote Users
NULL

»Linux Kernel CIFS Filesystem DNS Lookup Caching Bug Lets Local Users Poison the Cache
NULL

»Qt Memory Corruption Error in QTextEngine::LayoutData::reallocate() May Let Remote Users Execute Arbitrary Code
NULL

»RSA Federated Identity Manager URL Redirection Flaw Lets Remote Users Bypass Security Controls
NULL

»HP OpenView Network Node Manager Buffer Overflow in 'ov.dll' Lets Remote Users Execute Arbitrary Code
NULL

»Cisco Content Delivery System Internet Streamer Directory Traversal Flaw Discloses Files to Remote Users
NULL

»Mozilla Thunderbird Bugs Let Remote Users Execute Arbitrary Code, Bypass Same-Domain Controls, and Spoof URLs
NULL

»Mozilla Firefox Bugs Let Remote Users Bypass Same-Domain Controls and Spoof URLs
NULL

»Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code
NULL

»HP OpenView Network Node Manager Unspecified Bug Lets Remote Users Execute Arbitary Code
NULL

»OpenLDAP Bugs in slap_mods_free() and IA5StringNormalize() Let Remote Users Execute Arbitrary Code
NULL

»Apple iTunes Buffer Overflow in Processing 'itpc:' URLs Lets Remote Users Execute Arbitrary Code
NULL

»BIND 'RRSIG' Query Processing Error Lets Remote Users Deny Service
NULL

»Microsoft Windows Shell LNK Shortcut Processing Flaw Lets Users Execute Arbitrary Code
NULL

»SAP J2EE Engine Input Validation Flaw in Web Services Navigator Permits Cross-Site Scripting Attacks
NULL

»IPSwitch IMail Server Stack Overflow in Processing 'Reply-To' Headers Lets Remote Users Execute Arbitrary Code
NULL

»SAP GUI Heap Overflow in 'wadmxhtml.dll' Tags Property Lets Remote Users Execute Arbitrary Code
NULL

»Juniper Secure Access (IVE) Input Validation Flaw in 'welcome.cgi' Permits Cross-Site Scripting Attacks
NULL

»F5 FirePass Input Validation Flaw in Pre-Logon Sequence Permits Cross-Site Scripting Attacks
NULL

»Solaris OpenSSO Enterprise Unspecified Flaw Lets Remote Users Modify Data
NULL

»IBM solidDB Lets Remote Users Execute Arbitrary Code via a Long Username Field Value
NULL

»ToolTalk Database Server Heap Overflow in Processing '.rec' Files Lets Remote Users Execute Arbitrary Code
NULL

»Winamp Buffer Overflow in Processing FLV Content Lets Remote Users Execute Arbitrary Code
NULL

»Oracle Fusion Middleware Flaws Let Remote Users Access and Modify Data and Deny Service
NULL

»Oracle WebLogic Plugin Encoding Error Lets Remote Users Inject HTTP Headers
NULL

»Oracle PeopleSoft and JDEdwards Flaws Let Remote and Local Users Access and Modify Data and Local Users Deny Service
NULL

»Oracle Supply Chain Products Suite Lets Local Users Gain Elevated Privileges
NULL

»Oracle E-Business Suite Bugs Let Remote Users Access and Modify Data and Deny Service
NULL

»Oracle TimesTen Data Server Lets Remote Users Gain Full Control of the Target System
NULL

»Solaris Multiple Flaws Let Remote Users Gain Full Control and Let Local Users Deny Service and Gain Elevated Privileges
NULL

»Oracle Enterprise Manager Grid Control Console Flaw Lets Remote Users Modify Data
NULL

»Oracle Secure Backup Lets Remote Users Gain Full Control of the Target System
NULL

»HP Client Automation Enterprise Infrastructure (Radia) Discloses Potentially Sensitive Information to Remote Users
NULL

»Oracle Database Bugs Let Remote Users Modify Data and Deny Service and Remote Authenticated Users Access Data
NULL

»OpenVMS Auditing Lets Local Users Gain Elevated Privileges
NULL

»Microsoft Office Outlook Validation Error in Processing Attachments Lets Remote Users Execute Arbitrary Code
NULL

aktuelles von Debian Securityexterner Link

»DSA-2076 gnupg2 - use-after-free
It was discovered that GnuPG 2 uses a freed pointer when verifying a signature or importing a certificate with many Subject Alternate Names, potentially leading to arbitrary code execution.

»DSA-2075 xulrunner - several vulnerabilities
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems:

»DSA-2074 ncompress - integer underflow
Aki Helin discovered an integer underflow in ncompress, the original Lempel-Ziv compress/uncompress programs. This could lead to the execution of arbitrary code when trying to decompress a crafted LZW compressed gzip archive.

»DSA-2073 mlmmj - insufficient input sanitising
Florian Streibelt reported a directory traversal flaw in the way the Mailing List Managing Made Joyful mailing list manager processed users' requests originating from the administrator web interface without enough input validation. A remote, authenticated attacker could use these flaws to write and/or delete arbitrary files.

»DSA-2072 libpng - several vulnerabilities
Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems:

»DSA-2071 libmikmod - buffer overflows
Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files.

»DSA-2070 freetype - several vulnerabilities
Robert Swiecki discovered several vulnerabilities in the FreeType font library, which could lead to the execution of arbitrary code if a malformed font file is processed.

»DSA-2069 znc - denial of service
It was discovered that znc, an IRC bouncer, is vulnerable to denial of service attacks via a NULL pointer dereference when traffic statistics are requested while there is an unauthenticated connection.

»DSA-2068 python-cjson - buffer overflow
Matt Giuca discovered a buffer overflow in python-cjson, a fast JSON encoder/decoder for Python. This allows a remote attacker to cause a denial of service (application crash) through a specially-crafted Python script.

»DSA-2066 wireshark - several vulnerabilities
Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer. It was discovered that null pointer dereferences, buffer overflows and infinite loops in the SMB, SMB PIPE, ASN1.1 and SigComp dissectors could lead to denial of service or the execution of arbitrary code.

»DSA-2064 xulrunner - several vulnerabilities
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems:

»DSA-2065 kvirc - several vulnerabilities
Two security issues have been discovered in the DCC protocol support code of kvirc, a KDE-based next generation IRC client, which allow the overwriting of local files through directory traversal and the execution of arbitrary code through a format string attack.

»DSA-2063 pmount - insecure temporary file
Dan Rosenberg discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. A local attacker could overwrite arbitrary files utilising a symlink attack.

»DSA-2062 sudo - missing input sanitization
Anders Kaseorg and Evan Broder discovered a vulnerability in sudo, a program designed to allow a sysadmin to give limited root privileges to users, that allows a user with sudo permissions on certain programs to use those programs with an untrusted value of PATH. This could possibly lead to certain intended restrictions being bypassed, such as the secure_path setting.

»DSA-2061 samba - memory corruption
Jun Mao discovered that Samba, an implementation of the SMB/CIFS protocol for Unix systems, is not properly handling certain offset values when processing chained SMB1 packets. This enables an unauthenticated attacker to write to an arbitrary memory location resulting in the possibility to execute arbitrary code with root privileges or to perform denial of service attacks by crashing the samba daemon.

»DSA-2060 cacti - insufficient input sanitization
Stefan Esser discovered that cacti, a front-end to rrdtool for monitoring systems and services, is not properly validating input passed to the rra_id parameter of the graph.php script. Due to checking the input of $_REQUEST but using $_GET input in a query an unauthenticated attacker is able to perform SQL injections via a crafted rra_id $_GET value and an additional valid rra_id $_POST or $_COOKIE value.

»DSA-2059 pcsc-lite - buffer overflow
It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root.

»DSA-2058 glibc, eglibc - multiple vulnerabilities
Several vulnerabilities have been discovered in the GNU C Library (aka glibc) and its derivatives. The Common Vulnerabilities and Exposures project identifies the following problems:

»DSA-2057 mysql-dfsg-5.0 - several vulnerabilities
Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems:

»DSA-2056 zonecheck - missing input sanitizing
It was discovered that in zonecheck, a tool to check DNS configurations, the CGI does not perform sufficient sanitation of user input; an attacker can take advantage of this and pass script code in order to perform cross-site scripting attacks.

 
stand: 29.07.2010 @ 07:09
stand: 28.07.2010 @ 14:09
english