<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
    <pubDate>Fri, 20 Nov 2009 21:30:08 GMT</pubDate>
    <lastBuildDate>Fri, 20 Nov 2009 21:30:08 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</title>
    <link>http://seclists.org/bugtraq/2009/Nov/149</link>
    <description>&lt;p&gt;Posted by VMware Security Team on Nov 20&lt;/p&gt;-----------------------------------------------------------------------&lt;br&gt;
                   VMware Security Advisory&lt;br&gt;
&lt;br&gt;
Advisory ID:       VMSA-2009-0016&lt;br&gt;
Synopsis:          VMware vCenter and ESX update release and vMA patch&lt;br&gt;
                   release address multiple security issue in third&lt;br&gt;
                   party components&lt;br&gt;
Issue date:        2009-11-20&lt;br&gt;
Updated on:        2009-11-20 (initial release of advisory)&lt;br&gt;
CVE numbers:       --- JRE ---...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 21:16:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/149</guid>
  </item>
  <item>
    <title>IE7</title>
    <link>http://seclists.org/bugtraq/2009/Nov/148</link>
    <description>&lt;p&gt;Posted by info on Nov 20&lt;/p&gt;&amp;lt;!--&lt;br&gt;
securitylab.ir&lt;br&gt;
K4mr4n_st () yahoo com&lt;br&gt;
--&amp;gt;&lt;br&gt;
&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&amp;quot; &lt;br&gt;
&amp;quot;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot&quot;&gt;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&amp;quot&lt;/a&gt;;&amp;gt;&lt;br&gt;
&amp;lt;HTML xmlns=&amp;quot;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.w3.org/1999/xhtml&amp;quot&quot;&gt;http://www.w3.org/1999/xhtml&amp;quot&lt;/a&gt;;&amp;gt; &lt;br&gt;
    &amp;lt;HEAD&amp;gt;&lt;br&gt;
&amp;lt;script&amp;gt;   &lt;br&gt;
            function load(){&lt;br&gt;
                var e;&lt;br&gt;
                e=document.getElementsByTagName(&amp;quot;STYLE&amp;quot;)[0];...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 19:47:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/148</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBMA02478 SSRT090251 rev.1 - HP Operations Manager for Windows, Remote Unauthorized Access</title>
    <link>http://seclists.org/bugtraq/2009/Nov/147</link>
    <description>&lt;p&gt;Posted by security-alert on Nov 20&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c01931960&lt;br&gt;
Version: 1&lt;br&gt;
&lt;br&gt;
HPSBMA02478 SSRT090251 rev.1 - HP Operations Manager for Windows, Remote Unauthorized Access&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2009-11-18&lt;br&gt;
Last Updated: 2009-11-18&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote unauthorized access&lt;br&gt;
&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response Team...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 16:22:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/147</guid>
  </item>
  <item>
    <title>PHP &quot;multipart/form-data&quot; denial of service</title>
    <link>http://seclists.org/bugtraq/2009/Nov/146</link>
    <description>&lt;p&gt;Posted by Bogdan Calin on Nov 20&lt;/p&gt;Description&lt;br&gt;
------------&lt;br&gt;
PHP version 5.3.1 was just released. This release contains a patch for a&lt;br&gt;
denial of service condition we've reported on 27 October 2009. The&lt;br&gt;
problem is related with PHP's handling of RFC 1867 (Form-based File&lt;br&gt;
Upload in HTML).&lt;br&gt;
&lt;br&gt;
When you send a POST request to a PHP script with the content-type of&lt;br&gt;
&amp;quot;multipart/form-data&amp;quot; and include a list of files in that request, PHP&lt;br&gt;
will create a temporary file for each file from...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 16:08:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/146</guid>
  </item>
  <item>
    <title>Firefox 3.5.3 Remote Array Overrun (UPDATE)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/145</link>
    <description>&lt;p&gt;Posted by cxib on Nov 20&lt;/p&gt;Please update CVE-2009-1563 BID:36851 and BID:36843&lt;br&gt;
&lt;br&gt;
Mozilla has changed credit. &lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mozilla.org/security/announce/2009/mfsa2009-59.html&quot;&gt;http://www.mozilla.org/security/announce/2009/mfsa2009-59.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
and add correct CVE: CVE-2009-0689.&lt;br&gt;
&lt;br&gt;
CVE-2009-1563 shouldn't never exists. It is duplicate.&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 16:01:58 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/145</guid>
  </item>
  <item>
    <title>KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/144</link>
    <description>&lt;p&gt;Posted by cxib on Nov 20&lt;/p&gt;[ KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- KDELibs 4.3.3&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/74&quot;&gt;http://securityreason.com/achievement_securityalert/74&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
KDELibs is a collection of libraries built on top of...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 15:57:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/144</guid>
  </item>
  <item>
    <title>K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/143</link>
    <description>&lt;p&gt;Posted by cxib on Nov 20&lt;/p&gt;[ K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- K-Meleon 1.5.3&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/72&quot;&gt;http://securityreason.com/achievement_securityalert/72&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
K-Meleon is an extremely fast, customizable,...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 15:57:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/143</guid>
  </item>
  <item>
    <title>SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/142</link>
    <description>&lt;p&gt;Posted by cxib on Nov 20&lt;/p&gt;[ SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- SeaMonkey 1.1.18&lt;br&gt;
&lt;br&gt;
Fixed in:&lt;br&gt;
- SeaMonkey 2.0&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/71&quot;&gt;http://securityreason.com/achievement_securityalert/71&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
The SeaMonkey project is...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 15:47:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/142</guid>
  </item>
  <item>
    <title>Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/141</link>
    <description>&lt;p&gt;Posted by cxib on Nov 20&lt;/p&gt;[ Opera 10.01 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- Opera 10.01&lt;br&gt;
- Opera 10.10 Beta&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/73&quot;&gt;http://securityreason.com/achievement_securityalert/73&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
Opera is a Web browser and Internet suite...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 15:45:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/141</guid>
  </item>


  <item>
    <title>NSA Iraqi Computer Attacks And U.S. Defense</title>
    <link>http://seclists.org/bugtraq/2009/Nov/140</link>
    <description>&lt;p&gt;Posted by Gadi Evron on Nov 19&lt;/p&gt;In a recent article in the National Journal Magazine, the NSA&lt;br&gt;
supposedly admits to using computer attacks in Iraq, attacking&lt;br&gt;
cellular systems. Aside to the hacking part, which is obviously&lt;br&gt;
&amp;quot;cool&amp;quot;, the impact on the US cyber defense stance as well as&lt;br&gt;
international relations is staggering.&lt;br&gt;
&lt;br&gt;
I spent some time trying to figure out what facts were given in the&lt;br&gt;
story, and analyze it.&lt;br&gt;
&lt;br&gt;
Original story:...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:45:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/140</guid>
  </item>
  <item>
    <title>AssetsSoSimple supplier_admin.php Supplier Field XSS</title>
    <link>http://seclists.org/bugtraq/2009/Nov/139</link>
    <description>&lt;p&gt;Posted by Bugs NotHugs on Nov 19&lt;/p&gt;product: AssetsSoSimple&lt;br&gt;
version tested: 0.33&lt;br&gt;
vendor URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://assetssosimple.sourceforge.net/&quot;&gt;http://assetssosimple.sourceforge.net/&lt;/a&gt;&lt;br&gt;
script: supplier_admin.php&lt;br&gt;
field: Supplier&lt;br&gt;
&lt;br&gt;
ooo&lt;br&gt;
&lt;br&gt;
BugsNotHugs&lt;br&gt;
Shared Vulnerability Disclosure Account&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:36:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/139</guid>
  </item>
  <item>
    <title>Auto Manager admin.cgi Multiple Field XSS</title>
    <link>http://seclists.org/bugtraq/2009/Nov/138</link>
    <description>&lt;p&gt;Posted by Bugs NotHugs on Nov 19&lt;/p&gt;vendor: interactivetools.com, inc.,&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.interactivetools.com/products/automanager/&quot;&gt;http://www.interactivetools.com/products/automanager/&lt;/a&gt;&lt;br&gt;
product: Auto Manager&lt;br&gt;
version: 2.52&lt;br&gt;
script: admin.cgi&lt;br&gt;
fields: Vehicle, Year, Price, Drive Train, Transmission, Body, Engine,&lt;br&gt;
Description, Color, Miles&lt;br&gt;
&lt;br&gt;
***&lt;br&gt;
&lt;br&gt;
BugsNotHugs&lt;br&gt;
Shared Vulnerability Disclosure Account&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:27:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/138</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBMA02477 SSRT090177 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)</title>
    <link>http://seclists.org/bugtraq/2009/Nov/137</link>
    <description>&lt;p&gt;Posted by security-alert on Nov 19&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c01926980&lt;br&gt;
Version: 2&lt;br&gt;
&lt;br&gt;
HPSBMA02477 SSRT090177 rev.2 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2009-11-17&lt;br&gt;
Last Updated: 2009-11-18&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote Denial of Service (DoS)&lt;br&gt;
&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:18:44 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/137</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBPI02472 SSRT090196 rev.1 - Certain HP Color LaserJet Printers, Remote Unauthorized Access to Data, Denial of Service</title>
    <link>http://seclists.org/bugtraq/2009/Nov/136</link>
    <description>&lt;p&gt;Posted by security-alert on Nov 19&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c01886100&lt;br&gt;
Version: 1&lt;br&gt;
&lt;br&gt;
HPSBPI02472 SSRT090196 rev.1 - Certain HP Color LaserJet Printers, Remote Unauthorized Access to Data, Denial of Service&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2009-11-18&lt;br&gt;
Last Updated: 2009-11-18&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote unauthorized access to data, Denial of Service (DoS)&lt;br&gt;
&lt;br&gt;
Source:...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:08:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/136</guid>
  </item>
  <item>
    <title>[USN-860-1] Apache vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2009/Nov/135</link>
    <description>&lt;p&gt;Posted by Jamie Strandboge on Nov 19&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-860-1          November 19, 2009&lt;br&gt;
apache2 vulnerabilities&lt;br&gt;
CVE-2009-3094, CVE-2009-3095, CVE-2009-3555&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This advisory also applies to the corresponding versions of&lt;br&gt;
Kubuntu,...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 16:01:14 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2009/Nov/135</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
