New User, Welcome!     Login

Ryan Smith

=?UTF-8?B?Q09SRS0yMDA3LTA5Mjg6IFN0YWNrLWJhc2VkIGJ1ZmZlciBvdmVyZmw=?= =?UTF-8?B?b3cgdnVsbmVyYWJpbGl0eSBpbiBPcGVuQlNE4oCZcyBESENQIHNlcnZlcg==?=

This vulnerability was discovered by Nahuel Riva and Gerardo Richarte from
the CORE IMPACT Exploit Writers Team (EWT).

The VMware vulnerabilities that originally triggered research and
subsequent discovery of the buffer overflow vulnerability in OpenBSD’s
dhcpd were found by Neel Mehta and Ryan Smith from IBM X-Force [3].

Since the advisory from IBM X-Force lists 3 apparently distinct bugs
(using 3 different CVE names) but provides no technical details to
uniquely identify each one of them we’ve decided to roll a dice and picked
CVE-2007-0063 as the one to identify the bug reported in this advisory.

[ GLSA 200907-06 ] Adobe Reader: User-assisted execution of arbitrary code

* An anonymous researcher reported a stack-based buffer overflow
  related to U3D model files with a crafted extension block
  (CVE-2009-1855).

* Jun Mao and Ryan Smith of iDefense Labs reported an integer
  overflow related to the FlateDecode filter, which triggers a
  heap-based buffer overflow (CVE-2009-1856).

* Haifei Li of Fortinet's FortiGuard Global Security Research Team
  reported a memory corruption vulnerability related to TrueType fonts

iDefense Security Advisory 06.11.09: Adobe Reader and Acrobat FlateDecode Integer Overflow Vulnerability

06/05/2009  - Tentative disclosure date of 06/09/2009 set
06/09/2009  - Coordinated public disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao and Ryan Smith, iDefense
Labs

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php


VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player

     This release fixes several vulnerabilities in the DHCP server
     that could enable a specially crafted packets to gain system-level
     privileges. (CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)

     Thanks to Neel Mehta and Ryan Smith of the IBM Internet Security
     Systems X-Force for discovering and researching these
     vulnerabilities.

     Hosted products
     ---------------

iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Information Disclosure Vulnerability

07/28/2009  Public disclosure via MS09-035 out-of-band bulletin
07/29/2009  Material presented at BlackHat USA

IX. CREDIT

This vulnerability was discovered by Ryan Smith of iDefense Labs.

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php

Free tools, research and upcoming events

iDefense Security Advisory 08.11.09: Multiple Vendor Microsoft ATL/MFC ActiveX Type Confusion Vulnerability

07/29/2009  Material presented at BlackHat USA
08/11/2009  Public disclosure via MS09-037

IX. CREDIT

This vulnerability was discovered by Ryan Smith of iDefense Labs.

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php

Free tools, research and upcoming events

[USN-543-1] VMWare vulnerabilities

After a standard system upgrade you need to reboot your computer to
effect the necessary changes.

Details follow:

Neel Mehta and Ryan Smith discovered that the VMWare Player DHCP server
did not correctly handle certain packet structures.  Remote attackers
could send specially crafted packets and gain root privileges.
(CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)

Rafal Wojtczvk discovered multiple memory corruption issues in VMWare

iDefense Security Advisory 07.28.09: Multiple Vendor Microsoft ATL/MFC ActiveX Security Bypass Vulnerability

07/29/2009  Material presented at BlackHat USA
08/11/2009  Microsoft publishes MS09-037

IX. CREDIT

This vulnerability was discovered by Ryan Smith of iDefense Labs.

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php

Free tools, research and upcoming events

[ GLSA 200711-23 ] VMware Workstation and Player: Multiple vulnerabilities

Description
===========

Multiple vulnerabilities have been discovered in several VMware
products. Neel Mehta and Ryan Smith (IBM ISS X-Force) discovered that
the DHCP server contains an integer overflow vulnerability
(CVE-2007-0062), an integer underflow vulnerability (CVE-2007-0063) and
another error when handling malformed packets (CVE-2007-0061), leading
to stack-based buffer overflows or stack corruption. Rafal Wojtczvk
(McAfee) discovered two unspecified errors that allow authenticated



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!