PacketStorm Security

20 Most Recent Packet Storm File Additions



glsa-200804-27.txt

April 25, 2008, 8:52 pm   [ link da copiare ]
Gentoo Linux Security Advisory GLSA 200804-27 - Nathan G. Grennan reported a boundary error in SILC Toolkit within the silc_fingerprint() function in the file lib/silcutil/silcutil.c when passing overly long data, resulting in a stack-based buffer overflow. Versions less than 1.1.7 are affected.

DDIVRT-2008-11.txt

April 25, 2008, 8:52 pm   [ link da copiare ]
BadBlue is a web server used for peer-to-peer file sharing. By default, several executable files are stored in the web root: badblue.exe, uninst.exe, and dyndns.exe. Executable files stored in the web root of BadBlue can be launched remotely by any user. This can be leveraged to create a DoS condition by repeatedly invoking the uninst.exe executable. Due to the fact that BadBlue has not released a patch for the previously documented directory traversal vulnerability, an attacker may utilize these two flaws in conjunction to place a malicious executable in the web root and compromise a vulnerable server.

T208-CFP.txt

April 25, 2008, 8:52 pm   [ link da copiare ]
T2'08 Call For Papers - Announcing the annual T2'08 conference, which will take place in Helsinki, Finland, from October 16 to 17, 2008. They are looking for original technical presentations in the fields of information security. Presentations should last a minimum of 60 minutes and a maximum of two hours and be presented in English.

joomlajpad-sql.txt

April 25, 2008, 8:52 pm   [ link da copiare ]
The Joomla Jpad component version 1.0 suffers from a SQL injection vulnerability.

wordpress-cookie-integrity.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
An attacker, who is able to register a specially crafted username on a Wordpress 2.5 installation, is able to generate authentication cookies for other chosen accounts. This is not good.

MDVSA-2008-091.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
Mandriva Linux Security Advisory - A few vulnerabilities were found in Wireshark, that could cause it to crash or hang under certain conditions.

ruby-nmap-parser-0.3.tgz

April 25, 2008, 8:22 pm   [ link da copiare ]
This library provides a Ruby interface to Nmap's scan data. It can run Nmap and parse its XML output directly from the scan, parse a file containing the XML data from a separate scan, parse a String of XML data from a scan, or parse XML data from an object via its read() method. This information is presented in an easy-to-use and intuitive fashion for storing and manipulating.

minibb-xsssql.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
miniBB version 2.2 suffers from cross site scripting and SQL injection vulnerabilities.

postnukeschedule-sql.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
The Postnuke PostSchedule module suffers from a SQL injection vulnerability.

dsa-1558-1.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
Debian Security Advisory 1558-1 - It was discovered that crashes in the Javascript engine of xulrunner, the Gecko engine library, could potentially lead to the execution of arbitrary code.

sipwitch-0.1.1.tar.gz

April 25, 2008, 8:22 pm   [ link da copiare ]
GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP specific capabilities such as presence and messaging. It supports secure telephone extensions for making calls over the Internet, and intercept/decrypt-free peer-to-peer audio and video extensions. It is not a SIP proxy, a multi-protocol telephone server, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.

SSRT080031.txt

April 25, 2008, 8:22 pm   [ link da copiare ]
HP Security Bulletin - A potential vulnerability has been identified with the HPeDiag ActiveX control which is a component of HP Software Update running under windows. The vulnerability could be exploited to allow remote disclosure of information and execution of arbitrary code.

[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15]