New User, Welcome!     Login

Next Page >>

File type

VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

http://downloads.vmware.com/d/info/datacenter_downloads/vmware_vsphere_4/4_0
   Release Notes:
   http://downloads.vmware.com/support/pubs/vs_pages/vsp_pubs_esx41_vc41.html

   File type: .iso
   md5sum: 729cf247aa5d33ceec431c86377eee1a
   sha1sum: c1e10a5fcbc1ae9d13348d43541d574c563d66f0

   File type: .zip
   md5sum: fd1441bef48a153f2807f6823790e2f0

VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.

 
http://downloads.vmware.com/support/vsphere4/doc/vsp_esxi41_u1_rel_notes.ht
ml
   http://kb.vmware.com/kb/1027919

   File type: .iso
   MD5SUM: d68d6c2e040a87cd04cd18c04c22c998
   SHA1SUM: bbaacc0d34503822c14f6ccfefb6a5b62d18ae64

   ESXi 4.1 Update 1 (upgrade ZIP from ESXi 4.1)
   File type: .zip

RainbowCrack 1.4 is released - The Time-Memory Tradeoff Hash Cracker

RainbowCrack is a general propose implementation of Philippe Oechslin's faster time-memory trade-off technique. It cracks hashes with rainbow tables.

Version 1.4 of the RainbowCrack software is now available for download.

New features:
- New compact rainbow table file format (.rtc) reduce rainbow table size by 50% to 56.25% 
- New rt2rtc utility convert rainbow table from raw file format (.rt) to compact file format (.rtc) 
- New rtc2rt utility convert rainbow table from compact file format (.rtc) to raw file format (.rt) 
- The rcrack/rcrack_cuda program support both .rt and .rtc rainbow table file format 
- Conversion from non-perfect to perfect rainbow table is supported by rt2rtc utility


VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

   Type          Product Binaries
   http://downloads.vmware.com/download/download.do?downloadGroup=VC40U1

   VMware vCenter Server 4 and modules
   File size: 1.8 GB
   File type: .iso
   MD5SUM: 057d55b32eb27fe5f3e01bc8d3df3bc5
   SHA1SUM: c90134418c2e4d3d6637d8bee44261300ad95ec1

   VMware vCenter Server 4 and modules
   File size: 1.5 GB

VMSA-2011-0008 VMware vCenter Server and vSphere Client security vulnerabilities

http://downloads.vmware.com/d/info/datacenter_downloads/vmware_vsphere_4/4_
0
   Release Notes:
   http://www.vmware.com/support/vsphere4/doc/vsp_vc40_u3_rel_notes.html
 
   File type: .iso
   md5sum: b04780df75f70621d0c8794e8773a983
   sha1sum: a9f1398306158572ea1c3d202ed8c6ad922e0764

   File type: .zip
   md5sum: bc8179a639dcc6563d7dbf968095edc7

VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues

   Type         Product Binaries
   http://downloads.vmware.com/download/download.do?downloadGroup=VC40U1

   VMware vCenter Server 4 and modules
   File size: 1.8 GB
   File type: .iso
   MD5SUM: 057d55b32eb27fe5f3e01bc8d3df3bc5
   SHA1SUM: c90134418c2e4d3d6637d8bee44261300ad95ec1

   VMware vCenter Server 4 and modules
   File size: 1.5 GB

CORE-2011-0204: Adobe Audition vulnerability processing malformed session file

Adobe Audition is a digital audio workstation software for Windows that
was originally developed by Syntrillium as Cool Edit Pro, and acquired
by Adobe in 2003. The software allows user to do multitrack audio mixing
and editing and supports storing of multitrack audio using a session
file format (.ses).

Adobe audition is vulnerable to numerous buffer overflows while parsing
several fields inside the TRKM chunk on session (.ses) files. Then, a
memory corruption can be leveraged to execute arbitrary code on
vulnerable systems by enticing users to open specially crafted session

CORE-2007-0821: Lotus Notes buffer overflow in the Lotus WorkSheet file processor

and business collaboration application developed by IBM to work as a
desktop client in conjunction with IBM’s Lotus Domino server application.

The email functionality of Lotus Notes supports previewing and processing
file attachments in various formats. To preview and process files in the
Lotus Worksheet File format (WKS) used by Lotus 1-2-3 the email client
uses a library from a third-party software vendor (Autonomy’s Verity
KeyView SDK). Several buffer overflow vulnerabilities were found in the
third-party library used by Lotus Notes to process Lotus 1-2-3 file
attachments.


WordPress 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution

if (! @ is_uploaded_file( $file['tmp_name'] ) )
        return $upload_error_handler( $file, __( 'Specified file failed upload test.' ));

// A correct MIME type will pass this test. Override $mimes or use the upload_mimes filter.
if ( $test_type ) {
        $wp_filetype = wp_check_filetype( $file['name'], $mimes );

        extract( $wp_filetype );

        if ( ( !$type || !$ext ) && !current_user_can( 'unfiltered_upload' ) )
                return $upload_error_handler( $file, 

CORE-2008-0124: Multiple vulnerabilities in Google's Android SDK

handbook about security holes that also describes current
state-of-the-start exploitation techniques for different hardware
platforms and operating systems [6].

 The vulnerabilities discovered are summarized below grouped by the type
of image file format that is parsed by the vulnerable component.

 #1 - GIF image parsing heap overflow

The Graphics Interchange Format (GIF) is image format dating at least
from 1989 [7]. It was popularized because GIF images can be compressed

VMSA-2010-0005 VMware products address vulnerabilities in WebAccess

   Type          Product Binaries
   http://downloads.vmware.com/download/download.do?downloadGroup=VC250U6

   VirtualCenter DVD image - English only version
   File size: 854 MB
   File type: .iso
   md5sum: d83b09ac0533a418d5b7f5493dbd3ed3
   sha1sum: 1b969b397a937402b5e9463efc767eff7a980ad0

   VirtualCenter as a Zip file - English only version
   File size: 625 MB

VMSA-2012-0003 VMware VirtualCenter Update and ESX 3.5 patch update JRE

   Type          Product Binaries

   http://www.vmware.com/download/download.do?downloadGroup=VC250U6B

   vCenter Server DVD image - English only version
   File type: iso
   MD5SUM: 085f7bddd2adf2c4ba5bd066271e2b06
   SHA1SUM: 019ff0a67d150d0a3dbdac53bfde0b0eb69f9bfd

   vCenter Server as a Zip file - English only version
   File type: zip

VMSA-2010-0002 VMware vCenter update release addresses multiple security issues in Java JRE

   Type          Product Binaries
   http://downloads.vmware.com/download/download.do?downloadGroup=VC250U6

   VirtualCenter DVD image - English only version
   File size: 854 MB
   File type: .iso
   md5sum: d83b09ac0533a418d5b7f5493dbd3ed3
   sha1sum: 1b969b397a937402b5e9463efc767eff7a980ad0

   VirtualCenter as a Zip file - English only version
   File size: 625 MB

EEYE: Multiple Vulnerabilities In .FLAC File Format and Various Media Applications

Multiple Vulnerabilities In .FLAC File Format and Various Media
Applications

Release Date:
November 15, 2007

Date Reported:
September 28, 2007 (Vendor Reporting Coordination Began With US-CERT)

Severity:

4f: The File Format Fuzzing Framework

Krakow Labs Development

4f: The File Format Fuzzing Framework

4f is a file format fuzzing framework. 4f uses modules which are
specifications of the targeted binary or text file format that tell it
how to fuzz the target application.

If 4f detects a crash, it will log crucial information important for
allowing the 4f user to reproduce the problem and also debugging

iDefense Security Advisory 09.09.08: Apple QuickTime PICT Integer Overflow Vulnerability

Sep 09, 2008

I. BACKGROUND

Quicktime is Apple's media player product, and is used to render video
and other media. The PICT file format was developed by Apple Inc. in
1984. PICT files can contain both object oriented images and bitmaps.
For more information visit the vendor's web site at the following URL.

http://www.apple.com/quicktime/


iDefense Security Advisory 12.07.10: Apple QuickTime PICT Memory Corruption Vulnerability

Dec 07, 2010

I. BACKGROUND

QuickTime is Apple's media player product used to render video and other
media. The PICT file format was developed by Apple Inc. in 1984. PICT
files can contain both object-oriented images and bitmaps. For more
information visit http://www.apple.com/quicktime/

II. DESCRIPTION


[SECURITY] [DSA 1632-1] New tiff packages fix arbitrary code execution

Problem type   : local (remote)
Debian-specific: no
CVE Id(s)      : CVE-2008-2327

Drew Yao discovered that libTIFF, a library for handling the Tagged Image
File Format, is vulnerable to a programming error allowing malformed
tiff files to lead to a crash or execution of arbitrary code.

For the stable distribution (etch), this problem has been fixed in
version 3.8.2-7+etch1.


[waraxe-2012-SA#084] - Multiple Vulnerabilities in OpenCart 1.5.2.1

waraxe.jpg.620d348d4551ea2870e4cb602881a1d8

2. upload script allows through only files with specific extensions - images 
and text files. If we try to upload file "test.php", then server responds as:

{"error":"Invalid file type!"}


Source code snippet from  script "product.php":
-----------------[ source code start ]---------------------------------
public function upload() {

[ MDVSA-2011:010 ] xfig

 
 Stack-based buffer overflow in the read_1_3_textobject function in
 f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject
 function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier,
 allows remote attackers to execute arbitrary code via a long string
 in a malformed .fig file that uses the 1.3 file format.  NOTE:
 some of these details are obtained from third party information
 (CVE-2009-4227).
 
 Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier
 allows remote attackers to cause a denial of service (application

iDefense Security Advisory 10.11.07: Multiple Vendor FLAC Library Multiple Integer Overflow Vulnerabilities

http://labs.idefense.com/intelligence/vulnerabilities/
Oct 11, 2007

I. BACKGROUND

Free Lossless Audio Codec (FLAC) is a popular file format for audio data
compression. AOL Corp.'s Winamp media player has support for the FLAC
format. More information about FLAC and Winamp is available at the
following URLs.

http://flac.sourceforge.net/

iDefense Security Advisory 09.17.07: Multiple Vendor OpenOffice TIFF File Parsing Multiple Integer Overflow Vulnerabilities

Sep 17, 2007

I. BACKGROUND

OpenOffice is an open-source desktop office suite for many of today's
popular operating systems. Tagged Image File Format (TIFF) is a widely
supported image file format. More information about these technologies
are available from the following URLs.

http://www.openoffice.org/


PrivaWall Antivirus Office XML Format Evasion/Bypass Vulnerability

PrivaWall Antivirus Office XML Format Evasion/Bypass Vulnerability

DESCRIPTION

Office XML formats are a Microsoft proprietary file format regarding office
documents, spreadsheets etc., otherwise known as Microsoft's Open Document
XML (not to be confused with Office Open XML).

This format, which can be viewed as a hybrid between .doc and .docx formats,
is essentially a .xml file that is identified with the magic number

Vtiger CRM 5.0.4 Multiple Vulnerabilities

It's known that in some circostances (for example when the PHP handler
is configured using AddType/Action/AddHandler globally, eg. not inside
an Apache's Files/FilesMatch directive) blacklisting is not enough as
files in the form of "filename.php.foo" will be mapped back to PHP
anyway (since foo is not explicitly defined in the MIME map and Apache
will try to guess the filetype by its own).

Beside this known issue we want to point out a less known exploitation
methodology that works on Windows hosts.

First the attacker has to find the name of the file that was uploaded

CVE-2007-4600 - Mathcad Protect Worksheet Vulnerability

Mathcad Security Vulnerability Briefing - CVE-2007-4600


Synopsis of Vulnerability
==========================
The ‘Protect Worksheet’ functionality, used to protect sections Mathcad sheets from alterations, in versions 12 through 14 is easily bypassed allowing access to the protected data due to the implementation of the file format used to save the files. 


Background on Mathcad
======================
Mathcad (http://www.ptc.com/appserver/mkt/products/home.jsp?k=3901) is used to perform, document and share calculation and design work. The unique Mathcad visual format and scratchpad interface integrate standard mathematical notation, text and graphs in a single worksheet - making Mathcad ideal for knowledge capture, calculation reuse, and engineering collaboration.

[DSECRG-08-025] Local File Include in OneCMS 2.5

****
#################################################

 $mod = $_GET['load'];
 $filexp = explode(".", $mod);
 $filetype = $filexp[1];
 $file = $filexp[0];
 $file2 = "mods/$mod";

 if (!is_numeric($mod)) { // makes sure that the user isnt entering a #
 if ($filetype == "php") {

Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities

Products Confirmed Not Vulnerable
- ---------------------------------

The Cisco WebEx Player for the WebEx Advanced Recording Format (ARF)
file format is not affected by these vulnerabilities.

No other Cisco products are currently known to be affected by these
vulnerabilities.

Details

Family Connections 1.8.2 Arbitrary File Upload

                                if ($docs->uploadDocument($_FILES['doc']['type'],
$_FILES['doc']['name'], $_FILES['doc']['tmp_name'])) {
                                        
...

function uploadDocument ($filetype, $filename, $filetmpname) {
                global $LANG;
                $known_photo_types = array('application/msword' => 'doc',
'text/plain' => 'txt', 'application/excel' => 'xsl',
'application/vnd.ms-excel' => 'xsl', 'application/x-msexcel' => 'xsl',
                        'application/x-compressed' => 'zip', 'application/x-zip-compressed'

Cisco Security Advisory: Buffer Overflow Vulnerabilities in the Cisco WebEx Player

Products Confirmed Not Vulnerable
+--------------------------------

The Cisco WebEx Player for the WebEx Advanced Recording Format (ARF)
file format is not affected by the vulnerabilities described in this
document.

No other Cisco products are currently known to be affected by these
vulnerabilities.


[waraxe-2009-SA#070] - Multiple Vulnerabilities in MKPortal <= 1.2.1

                global $mkportals, $DB, $mklib, $Skin, $_FILES;

..
                $file =  $_FILES['FILE_UPLOAD']['tmp_name'];
                $file_name =  $_FILES['FILE_UPLOAD']['name'];
                //$file_type =  $_FILES['FILE_UPLOAD']['type'];
                $peso =  $_FILES['FILE_UPLOAD']['size'];                
                
                if (!$file) {
                        $message = "{$mklib->lang['b_compfile']}";
                        $mklib->error_page($message);

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!