<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
    <pubDate>Fri, 06 Nov 2009 16:15:10 GMT</pubDate>
    <lastBuildDate>Fri, 06 Nov 2009 16:15:10 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>[ GLSA 200911-01 ] Horde: Multiple vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/56</link>
    <description>&lt;p&gt;Posted by Alex Legler on Nov 06&lt;/p&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
Gentoo Linux Security Advisory                           GLSA 200911-01&lt;br&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
                                            &lt;a  rel=&quot;nofollow&quot; href=&quot;http://security.gentoo.org/&quot;&gt;http://security.gentoo.org/&lt;/a&gt;&lt;br&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
&lt;br&gt;
  Severity: Normal&lt;br&gt;
     Title: Horde: Multiple vulnerabilities&lt;br&gt;
      Date: November 06,...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 16:05:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/56</guid>
  </item>
  <item>
    <title>Php 5.3.0 pdflib extension open_basedir bypass</title>
    <link>http://seclists.org/bugtraq/2009/Nov/55</link>
    <description>&lt;p&gt;Posted by r3d . w0rm on Nov 06&lt;/p&gt;Description:&lt;br&gt;
------------&lt;br&gt;
Via this bug , attacker can save a file in path that not allowed in&lt;br&gt;
open_basedir .&lt;br&gt;
&lt;br&gt;
Reproduce code:&lt;br&gt;
---------------&lt;br&gt;
&amp;lt;?php&lt;br&gt;
// Author : Sina Yazdanmehr (R3d.W0rm) ; Our Site : &lt;a  rel=&quot;nofollow&quot; href=&quot;http://IrCrash.com&quot;&gt;http://IrCrash.com&lt;/a&gt;&lt;br&gt;
if(!extension_loaded('pdf')){&lt;br&gt;
   die('pdf extension required .');   &lt;br&gt;
}else{&lt;br&gt;
    $__PATH = $_GET['p']; /*The path that u want save file in .ex:&lt;br&gt;
/etc/file.php*/&lt;br&gt;
    $__VALUE = $_GET['v']; /*The text that u want save in file .ex:...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 15:53:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/55</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/54</link>
    <description>&lt;p&gt;Posted by dann frazier on Nov 06&lt;/p&gt;----------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-1929-1                security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                           Dann Frazier&lt;br&gt;
November 5, 2009                    &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
----------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : linux-2.6&lt;br&gt;
Vulnerability  : privilege escalation/denial of...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 15:43:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/54</guid>
  </item>
  <item>
    <title>[ MDVSA-2009:294 ] firefox</title>
    <link>http://seclists.org/bugtraq/2009/Nov/53</link>
    <description>&lt;p&gt;Posted by security on Nov 06&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2009:294&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : firefox&lt;br&gt;
 Date    : November 5, 2009&lt;br&gt;
 Affected: 2010.0&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Problem Description:&lt;br&gt;
&lt;br&gt;
 Security issues were identified...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 15:34:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/53</guid>
  </item>
  <item>
    <title>Using Blended Browser Threats involving Chrome to steal files on your computer</title>
    <link>http://seclists.org/bugtraq/2009/Nov/52</link>
    <description>&lt;p&gt;Posted by Inferno on Nov 06&lt;/p&gt;For complete post with images, please visit&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securethoughts.com/2009/11/using-blended-browser-threats-involving-ch&quot;&gt;http://securethoughts.com/2009/11/using-blended-browser-threats-involving-ch&lt;/a&gt;&lt;br&gt;
rome-to-steal-files-on-your-computer/&lt;br&gt;
&lt;br&gt;
SECURETHOUGHTS.COM ADVISORY&lt;br&gt;
=============================================&lt;br&gt;
- CVE-ID                : CVE-2009-XXXX (Chrome) {Pending}&lt;br&gt;
- Release Date  : November 05, 2009&lt;br&gt;
- Severity              : Medium&lt;br&gt;
- Discovered by : Inferno&lt;br&gt;
=============================================&lt;br&gt;
&lt;br&gt;
I. TITLE...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 15:25:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/52</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/51</link>
    <description>&lt;p&gt;Posted by dann frazier on Nov 06&lt;/p&gt;----------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-1928-1                security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                           Dann Frazier&lt;br&gt;
November 5, 2009                    &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
----------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : linux-2.6.24&lt;br&gt;
Vulnerability  : privilege escalation/denial of...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 15:18:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/51</guid>
  </item>


  <item>
    <title>[SECURITY] [DSA 1927-1] New Linux 2.6.26 packages fix several vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/50</link>
    <description>&lt;p&gt;Posted by dann frazier on Nov 05&lt;/p&gt;----------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-1927-1                security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                           dann frazier&lt;br&gt;
November 5, 2009                    &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
----------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : linux-2.6&lt;br&gt;
Vulnerability  : privilege escalation/denial of...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 21:04:17 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/50</guid>
  </item>
  <item>
    <title>[USN-854-1] GD library vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/49</link>
    <description>&lt;p&gt;Posted by Marc Deslauriers on Nov 05&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-854-1          November 05, 2009&lt;br&gt;
libgd2 vulnerabilities&lt;br&gt;
CVE-2007-3475, CVE-2007-3476, CVE-2007-3477, CVE-2009-3293,&lt;br&gt;
CVE-2009-3546&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This advisory also applies to the...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 20:58:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/49</guid>
  </item>
  <item>
    <title>[USN-855-1] libhtml-parser-perl vulnerability</title>
    <link>http://seclists.org/bugtraq/2009/Nov/48</link>
    <description>&lt;p&gt;Posted by Marc Deslauriers on Nov 05&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-855-1          November 05, 2009&lt;br&gt;
libhtml-parser-perl vulnerability&lt;br&gt;
CVE-2009-3627&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This advisory also applies to the corresponding versions of&lt;br&gt;
Kubuntu, Edubuntu, and Xubuntu....&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 20:51:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/48</guid>
  </item>
  <item>
    <title>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability</title>
    <link>http://seclists.org/bugtraq/2009/Nov/47</link>
    <description>&lt;p&gt;Posted by ZDI Disclosures on Nov 05&lt;/p&gt;ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-09-081&quot;&gt;http://www.zerodayinitiative.com/advisories/ZDI-09-081&lt;/a&gt;&lt;br&gt;
November 5, 2009&lt;br&gt;
&lt;br&gt;
-- CVE ID:&lt;br&gt;
CVE-2009-2685&lt;br&gt;
&lt;br&gt;
-- Affected Vendors:&lt;br&gt;
Hewlett-Packard&lt;br&gt;
&lt;br&gt;
-- Affected Products:&lt;br&gt;
Hewlett-Packard Power Manager&lt;br&gt;
&lt;br&gt;
-- TippingPoint(TM) IPS Customer Protection:&lt;br&gt;
TippingPoint IPS customers have been protected against this&lt;br&gt;
vulnerability by Digital Vaccine protection filter ID...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 20:43:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/47</guid>
  </item>
  <item>
    <title>CORE-2009-0912: Blender .blend Project Arbitrary Command Execution</title>
    <link>http://seclists.org/bugtraq/2009/Nov/46</link>
    <description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Nov 05&lt;/p&gt;Blender .blend Project Arbitrary Command Execution&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: Blender .blend Project Arbitrary Command Execution&lt;br&gt;
Advisory Id: CORE-2009-0912&lt;br&gt;
Advisory URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/content/blender-scripting-injection&quot;&gt;http://www.coresecurity.com/content/blender-scripting-injection&lt;/a&gt;&lt;br&gt;
Date published: 2009-11-05&lt;br&gt;
Date of last update: 2009-11-04&lt;br&gt;
Vendors contacted: Blender Foundation&lt;br&gt;
Release mode: User release&lt;br&gt;
&lt;br&gt;
2. *Vulnerability Information*&lt;br&gt;
&lt;br&gt;
Class: Failure to Sanitize Data into a Different...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 20:39:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/46</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBMA02474 SSRT090107 rev.1 - HP Power Manager, Remote Execution of Arbitrary Code</title>
    <link>http://seclists.org/bugtraq/2009/Nov/45</link>
    <description>&lt;p&gt;Posted by security-alert on Nov 05&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c01905743&lt;br&gt;
Version: 1&lt;br&gt;
&lt;br&gt;
HPSBMA02474 SSRT090107 rev.1 - HP Power Manager, Remote Execution of Arbitrary Code&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2009-11-04&lt;br&gt;
Last Updated: 2009-11-04&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote execution of arbitrary code&lt;br&gt;
&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response Team...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 16:52:17 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/45</guid>
  </item>
  <item>
    <title>[Bkis-12-2009] eoCMS SQL injection vulnerability - Bkis Report</title>
    <link>http://seclists.org/bugtraq/2009/Nov/44</link>
    <description>&lt;p&gt;Posted by Bkis on Nov 05&lt;/p&gt;eoCMS SQL injection vulnerability&lt;br&gt;
&lt;br&gt;
1. General information&lt;br&gt;
&lt;br&gt;
eoCMS is an open source code software which is used to develop Internet &lt;br&gt;
forum (&lt;a  rel=&quot;nofollow&quot; href=&quot;http://eocms.com/&quot;&gt;http://eocms.com/&lt;/a&gt;). On October 15, 2009, Bkis Security detected a &lt;br&gt;
SQL injection vulnerability in some functions of eoCMS.&lt;br&gt;
&lt;br&gt;
This is a critical vulnerability which allows hacker to access the data &lt;br&gt;
in the database and execute unauthorized tasks. Bkis has informed the &lt;br&gt;
software developer team, and they have...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 16:40:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/44</guid>
  </item>
  <item>
    <title>CONFidence 2.0 schedule online - last time to register</title>
    <link>http://seclists.org/bugtraq/2009/Nov/43</link>
    <description>&lt;p&gt;Posted by Andrzej Targosz on Nov 05&lt;/p&gt;Dear Madame/Sir,&lt;br&gt;
&lt;br&gt;
CONFidence is the one of the most technical conference in Eastern&lt;br&gt;
Europe. You can find videos from the latest edition here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://200902.confidence.org.pl/materialy-maj-2009&quot;&gt;http://200902.confidence.org.pl/materialy-maj-2009&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
You can find all informations here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://200902.confidence.org.pl&quot;&gt;http://200902.confidence.org.pl&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Speakers list (alfabetical order):&lt;br&gt;
    * Chema Alonso&lt;br&gt;
    * Jacob Appelbaum – keynote&lt;br&gt;
    * Jesse Burns&lt;br&gt;
    * Frank Breedijk&lt;br&gt;
    * Łukasz Bromirski&lt;br&gt;
    * Raoul Chiesa&lt;br&gt;
    * Gynvael...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 16:30:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/43</guid>
  </item>
  <item>
    <title>Re: /proc filesystem allows bypassing directory permissions on</title>
    <link>http://seclists.org/bugtraq/2009/Nov/42</link>
    <description>&lt;p&gt;Posted by Pavel Kankovsky on Nov 05&lt;/p&gt;It is required to do nothing:&lt;br&gt;
&lt;br&gt;
F_SETFL&lt;br&gt;
    Set the file status flags, defined in &amp;lt;fcntl.h&amp;gt;, for the file &lt;br&gt;
description associated with fildes from the corresponding bits in the &lt;br&gt;
third argument, arg, taken as type int. Bits corresponding to the file &lt;br&gt;
access mode and the file creation flags, as defined in &amp;lt;fcntl.h&amp;gt;, that are &lt;br&gt;
set in arg shall be ignored. If any bits in arg other than those mentioned &lt;br&gt;
here are changed by the application,...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 16:21:36 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/42</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
