New User, Welcome!     Login

Next Page >>

editing

Addendum :[TZO-09-2009] Avast bypass / evasion (Limited details)

You are encouraged to read the time line and draw your own conclusions.

Desktop Protection

    * avast! 4 Professional (impact low, reason real-time protection)
    * avast! 4 Home Edition (impact low, reason real-time protection)
    * avast! Pro Family pack (impact low, reason real-time protection)
    * avast! WHS Edition (impact low, reason real-time protection)
    * avast! Mac Edition (impact unknown)
    * avast! Linux Home Edition (impact unknown)
    * avast! U3 Edition (impact unknown)

Re: Enomaly ECP: Multiple vulnerabilities in VMcasting protocol & implementation.

The reported issue DOES NOT AFFECT ANY CURRENT ENOMALY PRODUCT.  Our current products are Enomaly ECP Service Provider Edition and Enomaly ECP High Assurance Edition, and neither utilizes the "vmfeed" module.

Specifically, the "vmfeed" module has not been utilized in any version of our products released since the initial release of Enomaly ECP Service Provider Edition in June 2009.  The "vmfeed" module was utilized only in our previous-generation "Community Edition" product, which has been deprecated and withdrawn from distribution.  Enomaly ECP Service Provider Edition is a completely different product from the old Community Edition.

As a result, since the Community Edition product is deprecated and has been withdrawn, Enomaly has not investigated this reported issue.

Further information on the differences between the deprecated Community Edition technology and our current Service Provider Edition technology can be found at http://src.enomaly.com.

Lars-Erik Forsberg, VP Delivery
Enomaly Inc.

Collection of Vulnerabilities in Fully Patched Vim 7.1

arbitrary code execution upon opening a crafted file.


2. Overview

``Vim is an almost compatible version of the UNIX editor Vi.  Many new features
have been added: multi-level undo, syntax highlighting, command line history,
on-line help, spell checking, filename completion, block operations, etc.''
        -- VIM 7.1 README.txt

Parts of Vim are written in the Vim script language.  A feature of this

[security bulletin] HPSBMA02615 SSRT100228 rev.1 - HP Insight Diagnostics Online Edition Running on Linux and Windows, Remote Cross Site Scripting (XSS)

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02652463
Version: 1

HPSBMA02615 SSRT100228 rev.1 - HP Insight Diagnostics Online Edition Running on Linux and Windows, Remote Cross Site Scripting (XSS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-12-14
Last Updated: 2010-12-14

[Bkis-04-2010] Multiple Vulnerabilities in OpenBlog

Besides, Bkis also found some XSS and CSRF vulnerabilities on the following
OpenBlog's functions: 

XSS holes are found on the following modules: 
-       Create a new post 
-       Edit a post
-       Create a new page

Because these modules' input variables are not adequately checked and
filtered, hacker might insert his code into the path's links. If a user
logins to his Blog and clicks the link, hacker's malicious code (JavaScript)

[security bulletin] HPSBMA02571 SSRT100034 rev.1 - HP Insight Diagnostics Online Edition, Remote Cross Site Scripting (XSS)

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02492472
Version: 1

HPSBMA02571 SSRT100034 rev.1 - HP Insight Diagnostics Online Edition, Remote Cross Site Scripting (XSS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-08-30
Last Updated: 2010-08-30

[waraxe-2009-SA#070] - Multiple Vulnerabilities in MKPortal <= 1.2.1

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Security risk: critical
Preconditions:
 1. attacker must be registered user
 2. attacker must have blog editing privileges

Registered users with blog keeping privileges can access personal gallery
functionality, example URL:

http://localhost/mkportal.1.2.1/index.php?ind=blog&op=p_gal

Multiple vulnerabilities in LineWeb 1.0.5

- Quick statistics function (server status, game server status, online players)
- Statistics (login server status, game server status, players online, total accounts, total characters, total gm characters, total clans)

Administrator Features:
- (NEW) New administrator skin
- (NEW) New server settings (Edit server settings, server rates, specs etc)
- (NEW) New website settings (Title, Note from the management, Contact Email, Rankings Limit)
- (NEW) Ads Management (Add, Edit & Delete)
- News management (add, edit & delete)
- Download management (add, edit & delete)
- Login

[security bulletin] HPSBMA02417 SSRT090031 rev.2 - HP Data Protector Express and HP Data Protector Express Single Server

Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01697543
Version: 2


CAU-2008-0002: Microsoft Windows SharePoint Services Picture Source XSS

Overview
========

A stored XSS vulnerability exists in Microsoft Windows SharePoint
Services 2.0 where a malicious user can bypass sanitization and inject 
javascript into a web page they are editing. Under normal circumstances,
SharePoint does not permit users to include javascript in any submitted
content.


Impact

Avast! Multiple Vulnerabilities

Avast! Multiple Vulnerabilities

BACKGROUND

Avast! antivirus software represents complete virus protection, offering full desktop security including a resident shield. Daily automatic updates ensure continuous data protection against all types of malware and spyware. Avast! antivirus is certified by both ICSA Labs and West Coast Labs Checkmark.
Avast! Professional Edition 4.8 is a collection of award winning, high-end technologies that work in perfect synergy, having one common goal: to protect your system and valuable data against computer viruses, spyware and rootkits. It represents a best-in-class antivirus solution for any Windows-based workstation.

Source: http://www.avast.com

VULNERABLE PRODUCTS


AST-2009-005: Remote Crash Vulnerability in SIP channel driver

   |----------------------------+------------+------------------------------|
   |      Asterisk Addons       |  1.6.0.x   | Not affected                 |
   |----------------------------+------------+------------------------------|
   |      Asterisk Addons       |  1.6.1.x   | Not affected                 |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |   A.x.x    | All versions                 |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |   B.x.x    | All versions prior to        |
   |                            |            | B.2.5.9                      |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |   C.2.x    | All versions prior to        |

[TZO-20-2009] AVG ZIP evasion / bypass

Ref         : [TZO-20-2009] - AVG generic ZIP bypass / evasion
WWW         : http://blog.zoller.lu/2009/04/avg-zip-evasion-bypass.html
Vendor      : http://www.AVG.com
Status      : Patched (with engine build 8.5 323)
CVE         : none provided
Credit      : t.b.a
OSVDB vendor entry: none [1]
Security notification reaction rating : good
Notification to patch window : +-28 days 

Comment:

AST-2009-003: SIP responses expose valid usernames

   |----------------------------+------------+------------------------------|
   |      Asterisk Addons       |   1.4.x    | Not affected                 |
   |----------------------------+------------+------------------------------|
   |      Asterisk Addons       |   1.6.x    | Not affected                 |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |   A.x.x    | All versions                 |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |   B.x.x    | All versions prior to        |
   |                            |            | B.2.5.8                      |
   |----------------------------+------------+------------------------------|
   | Asterisk Business Edition  |  C.1.x.x   | All versions prior to        |

AST-2009-001: Information leak in IAX2 authentication

   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.4.x  | Not affected                    |
   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.6.x  | Not affected                    |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  A.x.x  | All versions                    |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  B.x.x  | All versions prior to B.2.5.7   |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  | C.1.x.x | All versions prior to C.1.10.4  |
   |----------------------------+---------+---------------------------------|

Call for Papers H2HC Cancun/Mexico and H2HC Sao Paulo/Brazil

 CALL FOR PAPERS - Hackers 2 Hackers Conference 7th edition

The call for papers for H2HC 7th edition is now open.  H2HC is a hacker
conference taking place in Sao Paulo, Brazil, from 27 to 28 November
2010 and this year for the first time also in Cancun, on 3 of December 2010.

[ - Introduction - ]

For the seventh consecutive year and past success we have been having,
the annual Hackers 2 Hackers Conference will be held again in Sao Paulo,

[security bulletin] HPSBMA02417 SSRT090031 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01697543
Version: 1

HPSBMA02417 SSRT090031 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2009-05-13
Last Updated: 2009-05-12

[security bulletin] HPSBMA02516 SSRT090232 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02067559
Version: 1

HPSBMA02516 SSRT090232 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local

Denial of Service (DoS), Execution of Arbitrary Code

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.


[security bulletin] HPSBMA02576 SSRT090231 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02498535
Version: 1

HPSBMA02576 SSRT090231 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2010-09-08
Last Updated: 2010-09-08

Windows SMB NTLM Authentication Weak Nonce Vulnerability

1.Vulnerablity information
2.Vulnerablity description
3.Vulnerable systems
4.Vendor Information, solutions and workarounds
5.Credits
6.Technical description
6.1.NTLMv1 authentication protocol
6.2.The Flaws
6.3.Detecting if the SMB service generates duplicate 8-byte challenges
6.4.Exploiting duplicate challenges

AST-2009-009: Cross-site AJAX request vulnerability

   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.4.x  | Unaffected                      |
   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.6.x  | Unaffected                      |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  A.x.x  | Unaffected                      |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  B.x.x  | All versions prior to B.2.5.12  |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  C.x.x  | All versions prior to C.2.4.5   |
   |                            |         | and C.3.2.2                     |

AST-2009-008: SIP responses expose valid usernames

   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.4.x  | Unaffected                      |
   |----------------------------+---------+---------------------------------|
   |      Asterisk Addons       |  1.6.x  | Unaffected                      |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  A.x.x  | All versions                    |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  B.x.x  | All versions prior to B.2.5.12  |
   |----------------------------+---------+---------------------------------|
   | Asterisk Business Edition  |  C.x.x  | All versions prior to C.2.4.5   |
   |                            |         | and C.3.2.2                     |

AST-2008-011: Traffic amplification in IAX2 firmware provisioning system

   |----------------------------------+-------------+-----------------------|
   |         Asterisk Addons          |    1.2.x    | Not affected          |
   |----------------------------------+-------------+-----------------------|
   |         Asterisk Addons          |    1.4.x    | Not affected          |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |    A.x.x    | All versions          |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |    B.x.x    | All versions prior to |
   |                                  |             | B.2.5.4               |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |    C.x.x    | All versions prior to |

AST-2008-010: Asterisk IAX 'POKE' resource exhaustion

   |----------------------------------+-------------+-----------------------|
   |         Asterisk Addons          |    1.2.x    | Not affected          |
   |----------------------------------+-------------+-----------------------|
   |         Asterisk Addons          |    1.4.x    | Not affected          |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |    A.x.x    | All versions          |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |   B.x.x.x   | All versions prior to |
   |                                  |             | B.2.5.4               |
   |----------------------------------+-------------+-----------------------|
   |    Asterisk Business Edition     |   C.x.x.x   | All versions prior to |

ZSA-2007-029: syslog-ng Denial of Service

--------   Z o r p  S e c u r i t y  A d v i s o r y   ( Z S A ) ------------
PACKAGE             : syslog-ng, syslog-ng-premium-edition
AFFECTED VERSION    : <= 2.0.6, 2.1.8
FIXED               : 2.0.6, 2.1.8
SUMMARY             : Denial of Service
TYPE                : remote
AFFECTED            : all platforms
ZSA-ID              : ZSA-2007-029
DATE                : Dec 14, 2007

Command Execution in Hannon Hill Cascade Server

language, Xalan-Java supports the creation and use of extension
elements and extension functions... Extensions written in Java are
directly supported by Xalan-Java."

Because Cascade Server does not restrict the kind of XSLT code users
are able to enter, any user with access to edit XSLT stylesheets can
cause Cascade Server to execute arbitrary Java code. Using the
java.lang.Runtime class, Java can run shell commands.

While the privilege level of the Cascade Server process may prevent
an attacker from gaining complete control of the host system, that

QuickerSite Multiple Vulnerabilities

2. Vulnerabilities:
####################
        2.1. Insecure Direct Object Reference [in "bs_login.asp"]. Everyone can change admin password.
                2.1.1. Exploit:
                                Check the exploit section.
        2.2. Insecure Direct Object Reference [in "bs_login.asp"]. Everyone can edit all the site info., such as admin email address.
                2.2.1. Exploit:
                                Check the exploit section.
        2.3. Insecure Direct Object Reference [in "bs_login.asp"]. Everyone can edit all the site design. (Also, all the site settings can be changed by other parameters)
                2.3.1. Exploit:
                                Check the exploit section.

Insufficient Anti-automation and Denial of Service vulnerabilities in multiple systems

those systems, which changed filename of CaptchaSecurityImages.php.

So I made additional research on vulnerable systems previously reported by
me, and found many projects which are also affected. Here is a list of them
as an addition to my two previous advisories. I already combined information
about vulnerabilities in GunCMS and PhoenixCMS PHP Edition into one
advisory, and in this advisory I'm using the same approach. Where I combine
multiple vulnerable systems into one advisory not by just using of the same
script, but when they use codes of other systems.

Concerning vulnerabilities in MiniManager for Project MANGOS

AST-2009-010: RTP Remote Crash Vulnerability

   |----------------------------------+----------------+--------------------|
   |       Asterisk Open Source       |     1.4.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |       Asterisk Open Source       |     1.6.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    Asterisk Business Edition     |     B.x.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    Asterisk Business Edition     |     C.x.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    s800i (Asterisk Appliance)    |     1.3.x      | All versions       |
   +------------------------------------------------------------------------+

AST-2009-006: IAX2 Call Number Resource Exhaustion

   |----------------------------------+----------------+--------------------|
   |       Asterisk Open Source       |     1.4.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |       Asterisk Open Source       |     1.6.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    Asterisk Business Edition     |     B.x.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    Asterisk Business Edition     |     C.x.x      | All versions       |
   |----------------------------------+----------------+--------------------|
   |    s800i (Asterisk Appliance)    |     1.3.x      | All versions       |
   +------------------------------------------------------------------------+

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!