New User, Welcome!     Login

Next Page >>

GPL license

Re: Back door trojan in acajoom-3.2.6 for joomla

The vendor has issued an update, but the explanation falsely minimises
the problem.  (They also did not credit qadr1@ya.ru, nor anyone else.)

http://www.ijoobi.com/blog/latest/acajoom-free-version-3.2.7-available.html
states: "Acajoom GPL 3.2.7 is available for immediate download.  We
recommend all user who use the GPL verison to upgrade immediately due
to security issue.
" ... "A backdoor has been placed in the package by a hacker. This is
concerning only user who downloaded the GPL version ( Acajoom GPL
3.2.7 ) between Thursday 25th of June and Sunday 28th of June."

KwsPHP (Upload) Remote Code Execution Exploit

/*
 * 
 * Copyright (C) darkfig
 * 
 * This program is free software; you can redistribute it and/or 
 * modify it under the terms of the GNU General Public License 
 * as published by the Free Software Foundation; either version 2 
 * of the License, or (at your option) any later version. 
 * 
 * This program is distributed in the hope that it will be useful, 
 * but WITHOUT ANY WARRANTY; without even the implied warranty of 

Telecom Italia Alice Pirelli routers backdoor discoverd to activate telnet/ftp/tftp from internal LAN/WLAN.

 *  RFC 1321 compliant MD5 implementation
 *
 *  Copyright (C) 2001-2003  Christophe Devine
 *
 *  This program is free software; you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation; either version 2 of the License, or
 *  (at your option) any later version.
 *
 *  This program is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of

New open source Security Framework

has a module editor to make the task of
developing new exploits easier, Instant Search and XML-based modules.

This open source project comes to fill a need, a high quality framework 
for exploits and security researchers
with a GPL license and Python as engine for its modules.

GPL license to ensure the code will always be free
Instant search built-in for modules easy access
Module editor that allows the user to create custom exploits
Modules use XML DOM, really easy to modify

Secunia Research: Free Download Manager metalink "name" Directory Traversal

====================================================================== 
3) Vendor's Description of Software 

"What is Free Download Manager? It is a powerful, easy-to-use and
absolutely free download accelerator and manager. Moreover, FDM is
100% safe, open-source software distributed under GPL license.".

Product Link:
http://www.freedownloadmanager.org/

====================================================================== 

Secunia Research: Free Download Manager Torrent Parsing Buffer Overflows

====================================================================== 
3) Vendor's Description of Software 

"What is Free Download Manager? It is a powerful, easy-to-use and
absolutely free download accelerator and manager. Moreover, FDM is 
100% safe, open-source software distributed under GPL license.".

Product Link:
http://www.freedownloadmanager.org/

====================================================================== 

Mariposa Botnet C&C decryption plugin for wireshark

Hi all,

  We've developed a Wireshark plugin that will allow you to view obfuscated pcaps of traffic from a Mariposa infected client and actually decrypt them within Wireshark. The software is available to all as open source software under the GNU GPL license. We hope that it helps in doing further investigation and research into the Mariposa botnet.
  Special thanks to Defence Intelligence for their analysis on Mariposa.

  You can get more information for this tools on our blog at

http://www.paloaltonetworks.com/researchcenter/2009/10/mariposa-tool/

  You can also get the source code and a Windows DLL from the google code at

[ MDVSA-2009:327 ] clamav

 to cause a denial of service (application crash) and possibly execute
 arbitrary code via a crafted URL (CVE-2009-1372).
 
 Important notice about this upgrade: clamav-0.95+ bundles support
 for RAR v3 in libclamav which is a license violation as the RAR v3
 license and the GPL license is not compatible. As a consequence to
 this Mandriva has been forced to remove the RAR v3 code.
 
 Packages for 2008.0 are being provided due to extended support for
 Corporate products.
 

Nessus plugins for recent MS Bulletins

We have released Nessus plugins for the recently published Microsoft
bulletins. The same can be downloaded at,
http://www.secpod.org/nessus-plugins/. These have
been tested with Nessus 2.2.4 and released under GPL. We'll continue to
release these plugins under GPL for the upcoming threats.

Thanks,
Chandra.



[ MDVSA-2009:097 ] clamav

 to cause a denial of service (application crash) and possibly execute
 arbitrary code via a crafted URL (CVE-2009-1372).
 
 Important notice about this upgrade: clamav-0.95+ bundles support
 for RAR v3 in libclamav which is a license violation as the RAR v3
 license and the GPL license is not compatible. As a consequence to
 this Mandriva has been forced to remove the RAR v3 code.
 
 This update provides clamav 0.95.1, which is not vulnerable to
 these issues.
 _______________________________________________________________________

Secunia Research: Free Download Manager Remote Control Server Buffer Overflow

====================================================================== 
3) Vendor's Description of Software 

"What is Free Download Manager? It is a powerful, easy-to-use and
absolutely free download accelerator and manager. Moreover, FDM is 
100% safe, open-source software distributed under GPL license.".

Product Link:
http://www.freedownloadmanager.org/

====================================================================== 

Secunia Research: Free Download Manager Four Buffer Overflow Vulnerabilities

====================================================================== 
3) Vendor's Description of Software 

"What is Free Download Manager? It is a powerful, easy-to-use and
absolutely free download accelerator and manager. Moreover, FDM is
100% safe, open-source software distributed under GPL license.".

Product Link:
http://www.freedownloadmanager.org/

====================================================================== 

[ MDVSA-2009:097 ] clamav

 to cause a denial of service (application crash) and possibly execute
 arbitrary code via a crafted URL (CVE-2009-1372).
 
 Important notice about this upgrade: clamav-0.95+ bundles support
 for RAR v3 in libclamav which is a license violation as the RAR v3
 license and the GPL license is not compatible. As a consequence to
 this Mandriva has been forced to remove the RAR v3 code.
 
 This update provides clamav 0.95.1, which is not vulnerable to
 these issues.
 _______________________________________________________________________

[ GLSA 200903-37 ] Ghostscript: User-assisted execution of arbitrary code

=================

    -------------------------------------------------------------------
     Package                   /   Vulnerable   /           Unaffected
    -------------------------------------------------------------------
  1  app-text/ghostscript-gpl       < 8.64-r2               >= 8.64-r2
  2  app-text/ghostscript-gnu       < 8.62.0                 >= 8.62.0
  3  app-text/ghostscript-esp     <= 8.15.4-r1             Vulnerable!
    -------------------------------------------------------------------
     NOTE: Certain packages are still vulnerable. Users should migrate
           to another package if one is available or wait for the

[TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC

The new version of the "T50 Sukhoi PAK FA Mixed Packet Injector" (v5.2-NG)
will be unleashed on "WEB Security Forum" (http://websecforum.com.br/evento/
/ April 9th-10th 2011 / So Paulo, Brazil).

The next release will include:
1. New License: It is still not licensed under GPL or any other common
Open-source license, but the source code will be available and the use of
any piece of source code for any free or commercial software is denied.

2. CIDR Support: Classless Inter-Domain Routing support for destination IP
address, using a really tiny C algorithm. This would allow the "T50 Sukhoi

Joomla 1.0.13 CSRF

Background
==========

*Joomla!* is a free <http://en.wikipedia.org/wiki/Free_software>, open source <http://en.wikipedia.org/wiki/Open_source_software> content management system <http://en.wikipedia.org/wiki/Content_management_system> for publishing content
on the world wide web <http://en.wikipedia.org/wiki/World_wide_web> and intranets <http://en.wikipedia.org/wiki/Intranet>.
Joomla! is licensed under the GPL <http://en.wikipedia.org/wiki/GNU_General_Public_License>, and is the result of a fork <http://en.wikipedia.org/wiki/Fork_%28software_development%29> of Mambo <http://en.wikipedia.org/wiki/Mambo_%28CMS%29>.


Severity
========
Mild. It requires an administrator to be logged in and to be tricked into a specially

Re: Vim: Netrw: FTP User Name and Password Disclosure

>
> Copying welcome, under the Creative Commons ``Attribution-Share Alike''
> License http://creativecommons.org/licenses/by-sa/2.0/uk/
>
> Code included herein, and accompanying this advisory, may be copied
> according to the GNU General Public License version 2, or the Vim
> license.  See the subdirectory ``licenses''.
>
> Various portions of the accompanying code may have been written by
> various parties.  Those parties may hold copyright, and those portions
> may be copied according to their respective licenses.

Vim: Arbitrary Code Execution in Commands: K, Control-], g]

Copying welcome, under the Creative Commons ``Attribution-Share Alike''
License http://creativecommons.org/licenses/by-sa/2.0/uk/

Code included herein, and accompanying this advisory, may be copied
according to the GNU General Public License version 2, or the Vim
license.  See the subdirectory ``licenses''.

Various portions of the accompanying code may have been written by
various parties.  Those parties may hold copyright, and those portions
may be copied according to their respective licenses.

Vim 7.2c.002 Fixes Arbitrary Command Execution when Handling Tar Archives

Copying welcome, under the Creative Commons ``Attribution-Share Alike''
License http://creativecommons.org/licenses/by-sa/2.0/uk/

Code included herein, and accompanying this advisory, may be copied
according to the GNU General Public License version 2, or the Vim
license.  See the subdirectory ``licenses''.

Various portions of the accompanying code were written by various
parties.  Those parties may hold copyright, and those portions may be
copied according to their respective licenses.

Tool release: extract Windows credentials from registry hives

     * LM and NT hashes (SYSKEY protected)
     * Cached domain passwords
     * LSA secrets

It has no dependencies on any part of Windows, and operates directly  
on registry hive files. It is licensed under the GPL and intended to  
be easy to read, so you can find out how various Windows obfuscation  
algorithms work by reading the code. (I will also be posting a series  
of articles explaining the algorithms in detail on my blog in the  
coming weeks).


ELFdump crash when analyzing crafted ELF file.

ei_abis[osabi]);

[Dreg@ ~/vuln]# gdb --core elfdump.core
GNU gdb 6.1.1 [FreeBSD]
Copyright 2004 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-marcel-freebsd".
Core was generated by `elfdump'.

Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

      it in order to reduce attack surface. Historically, disabling unused
      protocol handlers has always proven to be a wise investment in security. 

In the unlikely event that you heavily rely on the use of hcp://, I have
created an unofficial (temporary) hotfix. You may use it under the terms of
the GNU General Public License, version 2 or later. Of course, you should only
use it as a last resort, carefully test the patch and make sure you understand
what it does (full source code is included). It may be necessary to modify it
to fit your needs.

The package is availble for x86 here:

OverLook Cross-site Scripting Vulnerability

+ Credit: Anatolia Security 



### VULNERABLE PRODUCT ###
+ Description: "Overlook is a modern system of communication licensed of GPL (GNU Public License), which puts at disposal by the user the webmail and webcalendar functionalities.Since the release of the version in November 2006, downloads have exceeded the threshold of 2.000, transforming Overlook on one of the most popular groupware applications."
+ Homepage: http://www.openit.it
+ Download: http://www.openit.it/index.php?option=com_jdownloads&Itemid=87&task=viewcategory&catid=3&lang=en




iDefense Security Advisory 02.12.08: ClamAV libclamav PE File Integer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Feb 12, 2008

I. BACKGROUND

Clam AntiVirus is a multi-platform GPL anti-virus toolkit. ClamAV is
often integrated into e-mail gateways and used to scan e-mail traffic
for viruses. It supports virus scanning for a wide variety of packed
Portable Executable (PE) binaries. For more information visit the
vendor's web site at the following URL.


Secunia Research: Samba "send_mailslot()" Buffer Overflow Vulnerability

3) Vendor's Description of Software 

"Samba is an Open Source/Free Software suite that has, since 1992,
provided file and print services to all manner of SMB/CIFS clients,
including the numerous versions of Microsoft Windows operating systems.
Samba is freely available under the GNU General Public License."

Product Link:
http://www.samba.org/

====================================================================== 

Step-by-step instructions for debugging Cisco IOS using gdb

gdb will connect to the router via the serial cable and display the following:

GNU gdb 6.0
Copyright 2003 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "--host=i686-pc-linux-gnu --target=powerpc-elf".
warning: Relocation packet received with no symbol file.  Packet Dropped

Two security issues fixed in ioQuake3 engine

Hello,

Quake 3 is a popular online first person shooter developed by IDsoftware [1] 
that has been released in 1999 and is still widely played.
After the release of the source code under the GPL, the ioQuake3 project [2]
was started that is dedicated to maintaining the existing codebase.

Several game projects are using a modified version of the ioQuake3 engine.
Some of these projects are:


Original Photo Gallery Remote Command Execution

Copyright (c) 2007 Francesco `ascii` Ongaro

Note: this exploit is DUAL LICENSED,
1. if you'll use it for personal and non-profit purposes you can
   apply GPL v2 and above.

2. In the case you plain to:
   a. use our code in any commercial context
   b. implement this code in your non-GPL application
   c. use this code during a Penetration Test

FAQMasterFlexPlus multiple vulnerabilities

It has language support and features according documentation are:
"Allow to create unlimited categories and unlimited
Questions/Answers and has web-based category and FAQ administration
with Add, Edit, Delete Capability.",

It's free software, released under the GNU General Public Lisence (GPL).
Works with php & mysql and comes bundled in some versions of
Fantastico (Cpanel X).




Secunia Research: TomatoCMS "q" SQL Injection Vulnerability

====================================================================== 
3) Vendor's Description of Software 

"TomatoCMS is an impressive, powerful Content Management System. It's
free and open source licensed under GNU GPL."

Product Link:
http://tomatocms.com/

====================================================================== 

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!