<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Fri, 12 Mar 2010 02:15:08 GMT</pubDate>
    <lastBuildDate>Fri, 12 Mar 2010 02:15:08 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>[USN-911-1] MoinMoin vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/217</link>
    <description>&lt;p&gt;Posted by Jamie Strandboge on Mar 11&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-911-1             March 11, 2010&lt;br&gt;
moin vulnerabilities&lt;br&gt;
CVE-2010-0668, CVE-2010-0669, CVE-2010-0717&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This advisory also applies to the corresponding versions of&lt;br&gt;
Kubuntu, Edubuntu,...&lt;br&gt;</description>
    <pubDate>Fri, 12 Mar 2010 02:01:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/217</guid>
  </item>
  <item>
    <title>iDefense Security Advisory 03.11.10: Multiple Vendor WebKit HTML Element Use After Free Vulnerability</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/216</link>
    <description>&lt;p&gt;Posted by iDefense Labs on Mar 11&lt;/p&gt;iDefense Security Advisory 03.11.10&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://labs.idefense.com/intelligence/vulnerabilities/&quot;&gt;http://labs.idefense.com/intelligence/vulnerabilities/&lt;/a&gt;&lt;br&gt;
Mar 11, 2010&lt;br&gt;
&lt;br&gt;
I. BACKGROUND&lt;br&gt;
&lt;br&gt;
WebKit is an open source web browser engine. It is currently used by&lt;br&gt;
Apple Inc.'s Safari browser, as well as by Google's Chrome browser. For&lt;br&gt;
more information, see the vendor's site at the following link.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://webkit.org/&quot;&gt;http://webkit.org/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
II. DESCRIPTION&lt;br&gt;
&lt;br&gt;
Remote exploitation of a memory corruption vulnerability in WebKit, as&lt;br&gt;
included with...&lt;br&gt;</description>
    <pubDate>Fri, 12 Mar 2010 00:22:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/216</guid>
  </item>


  <item>
    <title>Last day to download WinScanX Basic or WinScanX	Pro... forever.</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/215</link>
    <description>&lt;p&gt;Posted by Reed Arvin on Mar 11&lt;/p&gt;I have received a cease and desist letter regarding certain tools on&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://windowsaudit.com&quot;&gt;http://windowsaudit.com&lt;/a&gt;. Regardless of the validity of the&lt;br&gt;
accusations, I do not have the financial means to support legal&lt;br&gt;
defense.&lt;br&gt;
&lt;br&gt;
With that said, please take this opportunity to download WinScanX&lt;br&gt;
Basic or purchase WinScanX Pro before they are gone forever. After&lt;br&gt;
today, all that remains is a slim chance to find the product(s) via&lt;br&gt;
some other means.&lt;br&gt;
&lt;br&gt;
The &lt;a  rel=&quot;nofollow&quot; href=&quot;http://windowsaudit.com&quot;&gt;http://windowsaudit.com&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 23:42:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/215</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA 2013-1] New egroupware packages	fix several vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/214</link>
    <description>&lt;p&gt;Posted by Moritz Muehlenhoff on Mar 11&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-2013-1                  security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                       Moritz Muehlenhoff&lt;br&gt;
March 11, 2010                        &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : egroupware&lt;br&gt;
Vulnerability  : several&lt;br&gt;
Problem type   : remote...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 22:30:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/214</guid>
  </item>
  <item>
    <title>[ MDVSA-2010:061 ] ncpfs</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/213</link>
    <description>&lt;p&gt;Posted by security on Mar 11&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2010:061&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : ncpfs&lt;br&gt;
 Date    : March 11, 2010&lt;br&gt;
 Affected: 2008.0, 2009.0, 2009.1, 2010.0, Corporate 4.0,&lt;br&gt;
           Enterprise Server 5.0, Multi Network Firewall 2.0...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 20:05:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/213</guid>
  </item>
  <item>
    <title>Re: New Internet Explorer code-execution</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/212</link>
    <description>&lt;p&gt;Posted by Georgi Guninski on Mar 11&lt;/p&gt;haha, they updated their ``advisory'' to 1.1 from 1.0 at&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/981374.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/981374.mspx&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
they changed ``targeted'' to ``public'' and the rest seems the same.&lt;br&gt;
&lt;br&gt;
are targeted customers less important than public customers?&lt;br&gt;
&lt;br&gt;
extra points for spelling eCHO as Echo:&lt;br&gt;
&lt;br&gt;
Echo y| cacls %WINDIR%\SYSWOW64\iepeers.DLL /E /P everyone:N&lt;br&gt;
Impact of workaround. Extended MSHTML functionality such as printing and&lt;br&gt;
Web folders may be...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 19:50:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/212</guid>
  </item>
  <item>
    <title>Re: Multiple vulnerabilities in SUPERAntiSpyware	and Super Ad Blocker</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/211</link>
    <description>&lt;p&gt;Posted by netinfinity on Mar 11&lt;/p&gt;*I am really sorry and appologize for using lame file uploading sites,&lt;br&gt;
but I don't own a domain:( I tried to attach ZIP archive, but it seems&lt;br&gt;
it's being filtered*&lt;br&gt;
&lt;br&gt;
Use tar.gz not zip. Or .rar could also work.&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 19:02:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/211</guid>
  </item>
  <item>
    <title>ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnerability</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/210</link>
    <description>&lt;p&gt;Posted by ZDI Disclosures on Mar 11&lt;/p&gt;ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnerability&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-10-027&quot;&gt;http://www.zerodayinitiative.com/advisories/ZDI-10-027&lt;/a&gt;&lt;br&gt;
March 11, 2010&lt;br&gt;
&lt;br&gt;
-- Affected Vendors:&lt;br&gt;
Skype&lt;br&gt;
&lt;br&gt;
-- Affected Products:&lt;br&gt;
Skype&lt;br&gt;
&lt;br&gt;
-- TippingPoint(TM) IPS Customer Protection:&lt;br&gt;
TippingPoint IPS customers have been protected against this&lt;br&gt;
vulnerability by Digital Vaccine protection filter ID 8328. &lt;br&gt;
For further product information on the TippingPoint IPS,...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 18:09:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/210</guid>
  </item>
  <item>
    <title>ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/209</link>
    <description>&lt;p&gt;Posted by ZDI Disclosures on Mar 11&lt;/p&gt;ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-10-028&quot;&gt;http://www.zerodayinitiative.com/advisories/ZDI-10-028&lt;/a&gt;&lt;br&gt;
March 11, 2010&lt;br&gt;
&lt;br&gt;
-- Affected Vendors:&lt;br&gt;
Skype&lt;br&gt;
&lt;br&gt;
-- Affected Products:&lt;br&gt;
Skype&lt;br&gt;
&lt;br&gt;
-- TippingPoint(TM) IPS Customer Protection:&lt;br&gt;
TippingPoint IPS customers have been protected against this&lt;br&gt;
vulnerability by Digital Vaccine protection filter ID 8329. &lt;br&gt;
For further product information on the TippingPoint IPS, visit:...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 18:08:27 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/209</guid>
  </item>
  <item>
    <title>Vulnerabilities in Abton</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/208</link>
    <description>&lt;p&gt;Posted by MustLive on Mar 11&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
&lt;br&gt;
I want to warn you about vulnerabilities in Abton. It's commercial Ukrainian&lt;br&gt;
CMS.&lt;br&gt;
&lt;br&gt;
-----------------------------&lt;br&gt;
Advisory: Vulnerabilities in Abton&lt;br&gt;
-----------------------------&lt;br&gt;
URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://websecurity.com.ua/2886/&quot;&gt;http://websecurity.com.ua/2886/&lt;/a&gt;&lt;br&gt;
-----------------------------&lt;br&gt;
Timeline:&lt;br&gt;
&lt;br&gt;
31.03.2008 - found the vulnerabilities.&lt;br&gt;
16.02.2009 - announced at my site.&lt;br&gt;
17.02.2009 - informed developers.&lt;br&gt;
24.11.2009 - disclosed at my site....&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 15:19:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/208</guid>
  </item>
  <item>
    <title>Skype URI Handler Input Validation</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/207</link>
    <description>&lt;p&gt;Posted by Paul Craig on Mar 11&lt;/p&gt;     (    , )     (,&lt;br&gt;
  .   `.' ) ('.    ',&lt;br&gt;
   ). , ('.   ( ) (&lt;br&gt;
  (_,) .`), ) _ _,&lt;br&gt;
 /  _____/  / _  \    ____  ____   _____  &lt;br&gt;
 \____  \==/ /_\  \ _/ ___\/  _ \ /     \&lt;br&gt;
 /       \/   |    \\  \__(  &amp;lt;_&amp;gt; )  Y Y  \&lt;br&gt;
/______  /\___|__  / \___  &amp;gt;____/|__|_|  /&lt;br&gt;
        \/         \/.-.    \/         \/:wq&lt;br&gt;
                    (x.0)&lt;br&gt;
                  '=.|w|.='&lt;br&gt;
                  _='`&amp;quot;``=.&lt;br&gt;
&lt;br&gt;
        presents..&lt;br&gt;
&lt;br&gt;
Skype URI Handler Input Validation...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 15:17:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/207</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA 2011-1] New dpkg packages fix	path traversal</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/206</link>
    <description>&lt;p&gt;Posted by Nico Golde on Mar 11&lt;/p&gt;--------------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-2011-1                    security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                                 Nico Golde&lt;br&gt;
March 10th, 2010                        &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
--------------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : dpkg&lt;br&gt;
Vulnerability  : path traversal&lt;br&gt;
Problem type   :...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 15:15:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/206</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA-2010-1] New kvm packages fix	several vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/205</link>
    <description>&lt;p&gt;Posted by dann frazier on Mar 11&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-2010                  security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                         Dann Frazier&lt;br&gt;
March 10, 2010                   &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : kvm&lt;br&gt;
Vulnerability  : privilege escalation/denial of service&lt;br&gt;
Problem type...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 15:13:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/205</guid>
  </item>
  <item>
    <title>Secunia Research: XnView DICOM Parsing Integer	Overflow Vulnerability</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/204</link>
    <description>&lt;p&gt;Posted by Secunia Research on Mar 11&lt;/p&gt;====================================================================== &lt;br&gt;
&lt;br&gt;
                     Secunia Research 10/03/2010&lt;br&gt;
&lt;br&gt;
       - XnView DICOM Parsing Integer Overflow Vulnerability -&lt;br&gt;
&lt;br&gt;
====================================================================== &lt;br&gt;
Table of Contents&lt;br&gt;
&lt;br&gt;
Affected Software....................................................1&lt;br&gt;
Severity.............................................................2&lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 15:12:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/204</guid>
  </item>
  <item>
    <title>Re: credit union phishing scam</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/203</link>
    <description>&lt;p&gt;Posted by Benji on Mar 11&lt;/p&gt;Maybe we can get a definition of the Internet so I can fully grasp  &lt;br&gt;
what this fishing game is?&lt;br&gt;</description>
    <pubDate>Thu, 11 Mar 2010 12:20:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/203</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
