New User, Welcome!     Login

object/oriented programming language

[ GLSA 200907-16 ] Python: Integer overflows

Multiple integer overflows in Python have an unspecified impact.

Background
==========

Python is an interpreted, interactive, object-oriented programming
language.

Affected packages
=================


[ GLSA 200802-10 ] Python: PCRE Integer overflow

execution of arbitrary code.

Background
==========

Python is an interpreted, interactive, object-oriented programming
language.

Affected packages
=================


[ GLSA 200812-17 ] Ruby: Multiple vulnerabilities

attacks including arbitrary code execution and Denial of Service.

Background
==========

Ruby is an interpreted object-oriented programming language. The
elaborate standard library includes an HTTP server ("WEBRick") and a
class for XML parsing ("REXML").

Affected packages
=================

[ GLSA 200807-16 ] Python: Multiple vulnerabilities

arbitrary code.

Background
==========

Python is an interpreted, interactive, object-oriented programming
language.

Affected packages
=================


[ GLSA 200807-01 ] Python: Multiple integer overflows

Multiple integer overflows may allow for Denial of Service.

Background
==========

Python is an interpreted, interactive, object-oriented programming
language.

Affected packages
=================


[ GLSA 201001-09 ] Ruby: Terminal Control Character Injection

Background
==========

Ruby is an interpreted scripting language for quick and easy
object-oriented programming. It comes bundled with a HTTP server
("WEBrick").

Affected packages
=================


[ GLSA 200711-07 ] Python: User-assisted execution of arbitrary code

Denial of Service.

Background
==========

Python is an interpreted, interactive, object-oriented programming
language.

Affected packages
=================


[ GLSA 200906-02 ] Ruby: Denial of Service

cause a Denial of Service attack.

Background
==========

Ruby is an interpreted object-oriented programming language. The
elaborate standard library includes the "BigDecimal" class.

Affected packages
=================


Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection

-------------------------
Invision Power Board (IPB) is a professional forum system that has  
been built
from the ground up with speed and security in mind, taking advantage  
of object
oriented code, highly-optimized SQL queries, and the fast PHP engine. A
comprehensive administration control panel is included to help you  
keep your
board running smoothly. Moderators will also enjoy the full range of  
options
available to them via built-in tools and moderators control panel.  

[ GLSA 200801-11 ] CherryPy: Directory traversal vulnerability

attackers to read and write arbitrary files.

Background
==========

CherryPy is a Python-based, object-oriented web development framework.

Affected packages
=================

    -------------------------------------------------------------------

[SECURITY] [DSA 1412-1] New ruby1.9 packages fix insecure SSL certificate validation

Vulnerability  : programming error
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2007-5162 CVE-2007-5770

Several vulnerabilities have been discovered in Ruby, an object-oriented
scripting language. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2007-5162


[SECURITY] [DSA 1411-1] New libopenssl-ruby packages fix insecure SSL certificate validation

Vulnerability  : programming error
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2007-5162 CVE-2007-5770

Several vulnerabilities have been discovered in Ruby, an object-oriented
scripting language. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2007-5162


iDefense Security Advisory 09.09.08: Apple QuickTime PICT Integer Overflow Vulnerability

I. BACKGROUND

Quicktime is Apple's media player product, and is used to render video
and other media. The PICT file format was developed by Apple Inc. in
1984. PICT files can contain both object oriented images and bitmaps.
For more information visit the vendor's web site at the following URL.

http://www.apple.com/quicktime/

II. DESCRIPTION

CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability

CVE Name: N/A


3. *Vulnerability Description*

eFront [1] is an easy-to-use, open source and object-oriented
multilingual eLearning platform that can be used to build learning
communities, educate and retain the end-users.

eFront is vulnerable to local file inclusion vulnerability, which
allows an external remote attacker to upload an arbitrary file and

Python winappdbg module v1.0 is out!

The winappdbg python module allows developers to quickly code
instrumentation scripts in Python under a Windows environment.

It uses ctypes to wrap many Win32 API calls related to debugging, and
provides an object-oriented abstraction layer to manipulate threads,
libraries and processes, attach your script as a debugger, trace
execution, hook API calls, handle events in your debugee and set
breakpoints of different kinds (code, hardware and memory).
Additionally it has no native code at all, making it easier to
maintain or modify than other debuggers on Windows.

[SECURITY] [DSA 1481-1] New python-cherrypy packages fix denial of service

Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2008-0252

It was discovered that a directory traversal vulnerability in CherryPy,
a pythonic, object-oriented web development framework may lead to denial 
of service by deleting files through malicious session IDs in cookies.

For the stable distribution (etch), this problem has been fixed in
version 2.2.1-3etch1.


Metrica Service Assurance Multiple Cross Site Scripting

***********************************************************************

Summary

Metrica Service Assurance Framework implements a distributed,
object-oriented, J2EE-based architecture. It work with a Web-based
user interfaces, from end-user report generation to detailed system
administration and configuration.

***********************************************************************


XSS Vulnerability in JpGraph 3.0.6

Discovered by Martin Barbella <barbella@sas.upenn.edu>

Description of Vulnerability:
-----------------------------
JpGraph is an object oriented library for PHP that can be used to create
various types of graphs which also contains support for client side
image maps.

The GetURLArguments function for the JpGraph's Graph class does not
properly sanitize the names of get and post variables, leading to a

WinAppDbg 1.3 is out!

It uses ctypes to wrap many Win32 API calls related to debugging, and provides

an object-oriented abstraction layer to manipulate threads, libraries and

processes, attach your script as a debugger, trace execution, hook API calls,

handle events in your debugee and set breakpoints of different kinds (code,


WinAppDbg version 1.2 is out!

The WinAppDbg python module allows developers to quickly code instrumentation
scripts in Python under a Windows environment.

It uses ctypes to wrap many Win32 API calls related to debugging, and provides
an object-oriented abstraction layer to manipulate threads, libraries and
processes, attach your script as a debugger, trace execution, hook API calls,
handle events in your debugee and set breakpoints of different kinds (code,
hardware and memory). Additionally it has no native code at all, making it
easier to maintain or modify than other debuggers on Windows.


Re: [Full-disclosure] WinAppDbg version 1.2 is out!

Jared


> 
> It uses ctypes to wrap many Win32 API calls related to debugging, and provides
> an object-oriented abstraction layer to manipulate threads, libraries and
> processes, attach your script as a debugger, trace execution, hook API calls,
> handle events in your debugee and set breakpoints of different kinds (code,
> hardware and memory). Additionally it has no native code at all, making it
> easier to maintain or modify than other debuggers on Windows.
> 

FreeBSD Security Advisory FreeBSD-SA-08:13.protosw

I.   Background

The FreeBSD kernel provides support for a variety of different types of
communications sockets, including IPv4, IPv6, ISDN, ATM, routing protocol,
link-layer, netgraph(4), and bluetooth sockets.  As an early form of
object-oriented design, much of the functionality specific to different
types of sockets is abstracted via function pointers.

II.  Problem Description

Some function pointers for netgraph and bluetooth sockets are not

[SECURITY] [DSA 1410-1] New ruby1.8 packages fix insecure SSL certificate validation

Vulnerability  : programming error
Problem type   : local/remote
Debian-specific: no
CVE Id(s)      : CVE-2007-5162 CVE-2007-5770

Several vulnerabilities have been discovered in Ruby, an object-oriented
scripting language. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2007-5162


WinAppDbg module v1.1 is out!

The WinAppDbg python module allows developers to quickly code instrumentation
scripts in Python under a Windows environment.

It uses ctypes to wrap many Win32 API calls related to debugging, and provides
an object-oriented abstraction layer to manipulate threads, libraries and
processes, attach your script as a debugger, trace execution, hook API calls,
handle events in your debugee and set breakpoints of different kinds (code,
hardware and memory). Additionally it has no native code at all, making it
easier to maintain or modify than other debuggers on Windows.




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!