Buqtraq Archiv September 2002
- The ScrollKeeper Root Trap
- XSS in Null HTTPd
- [RHSA-2002:186-07] Updated scrollkeeper packages fix tempfile vulnerability
- One step easier password guessing on Windows
- SECNAP Security Alert: Radmin Default install options vulnerability
- Re: Trillian XML parser buffer overflow
- Happy Labor Day from Snosoft
- Outlook S/MIME Vulnerability
- Windows .NET Server (RC1) and MSDE (#NISR03092002B)
- From: NGSSoftware Insight Security Research
- Microsoft SQL Server Stored procedures [sp_MSSetServerPropertiesn and sp_MSsetalertinfo] (#NISR03092002A)
- From: NGSSoftware Insight Security Research
- New Paper: Threat profiling Microsoft SQL Server
- From: NGSSoftware Insight Security Research
- SWS Web Server v0.1.0 Exploit
- [SECURITY] [DSA 160-1] New scrollkeeper packages fix insecure temporary file creation
- Compaq mount patch broken
- Re: Outlook S/MIME Vulnerability
- Re: CacheFlow CacheOS Cross-site Scripting Vulnerability
- SecuRemote usernames can be guessed or sniffed using IKE exchange
- Cisco Security Advisory: Cisco VPN 3000 Concentrator Multiple Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- MSIEv6 % encoding causes a problem again
- Re: SUMMARY: Disabling Port 445 (SMB) Entirely
- Re: One step easier password guessing on Windows
- Re: Security side-effects of Word fields
- [security bulletin] SSRT2310a HP Tru64 UNIX & HP OpenVMS Potential OpenSSL Security Vulnerability (fwd)
- Re: Compaq mount patch broken
- [CLA-2002:522] Conectiva Linux Security Announcement - mailman
- Re: **maillist:: Outlook S/MIME Vulnerability
- Cross-Site Scripting in Aestiva's HTML/OS
- GLSA: scrollkeeper
- Cacti security issues
- From: Knights of the Routing Table
- Re: MSIEv6 % encoding causes a problem again
- AFD 1.2.14 multiple local root compromises
- Re: **maillist:: Outlook S/MIME Vulnerability
- [SECURITY] [DSA 161-1] New Mantis package fixes privilege escalation
- TRU64 formal disclosure from Snosoft.
- SPIKE 2.6 Released...
- Bypassing the Finjan SurfinGate URL filter
- Re: **maillist:: Outlook S/MIME Vulnerability
- Re: MSIEv6 % encoding causes a problem again
- Re: MSIEv6 % encoding causes a problem again
- Re: Compaq mount patch broken
- SuSE Security Announcement: glibc (SuSE-SA:2002:031)
- GLSA: amavis
- Cisco Security Advisory: Cisco VPN Client Multiple Vulnerabilities - Second Set
- From: Cisco Systems Product Security Incident Response Team
- RE: SecuRemote usernames can be guessed or sniffed using IKE exchange
- From: Scott Walker Register
- RE: Bypassing the Finjan SurfinGate URL filter
- advisory
- RE: (Fwd) MSIEv6 % encoding causes a problem again
- Re: SWS Web Server v0.1.0 Exploit
- MSIEv6 % encoding - Konqueror 3.0.3 also vulnerable
- zero-width gif: exploit PoC for NS6.2.3 (fixed in 7.0) [Was: GIFs Good, Flash Executable Bad]
- Foundstone Labs Advisory - Remotely Exploitable Buffer Overflow in PGP
- Rapid 7 Advisory R7-0005: ZMerge Insecure Default ACLs
- From: Rapid 7 Security Advisories
- Veritas Backup Exec opens networks for NetBIOS based attacks?
- Re: Security side-effects of Word fields
- [SECURITY] [DSA 162-1] New ethereal packages fix buffer overflow
- RE: Veritas Backup Exec opens networks for NetBIOS based attacks?
- UPDATE: (Was Veritas Backup Exec opens networks for NetBIOS based attacks?)
- Next-hop scanning for open firewall ports
- KSTAT (and maybe others) bypass
- Re: MSIEv6 % encoding - Konqueror 3.0.3 also vulnerable
- MDKSA-2002:054-1 - gaim update
- From: Mandrake Linux Security Team
- All versions of windows infected?
- Re: All versions of windows infected?
- NetGear FM114P URL filter bypassing vulnerability
- Re: Next-hop scanning for open firewall ports
- Re: All versions of windows infected?
- Re: Next-hop scanning for open firewall ports
- PHP header() CRLF Injection
- Vulnerabilities in Microsoft's Java implementation
- Who framed Internet Explorer (GM#010-IE)
- Guardent Client Advisory: Multiple wordtrans-web Vulnerabilities
- GLSA: glibc
- [SECURITY] [DSA 159-2] New Python packages fix problem introduced by security fix
- phpGB: cross site scripting bug
- [RHSA-2002:188-08] New wordtrans packages fix remote vulnerabilities
- phpGB: mysql injection bug
- phpGB: DoS and executing_arbitrary_commands
- sql injection vulnerability in WBB 2.0 RC1 and below
- Trillian weakly encrypts saved passwords
- Unmask 1.0 Release Party at My House!
- [SECURITY] [DSA 163-1] New mhonarc packages fix cross site scripting problems
- Re: Trillian weakly encrypts saved passwords
- RE: Trillian weakly encrypts saved passwords
- Small bug crashes OE
- Small correction...
- RE: PHP header() CRLF Injection
- PHP fopen() CRLF Injection
- Strange Attractors and TCP/IP Sequence Number Analysis - One Year Later
- MDKSA-2002:058 - kdelibs update
- From: Mandrake Linux Security Team
- [SECURITY] [DSA 164-1] New cacti package fixes arbitrary code execution
- IE6 SP1 Notes
- MDKSA-2002:057 - krb5 update
- From: Mandrake Linux Security Team
- Re: Trillian weakly encrypts saved passwords
- [RHSA-2002:189-08] Updated gaim client fixes URL vulnerability
- Re: Small bug crashes OE
- RE: Who framed Internet Explorer and IE6 SP1
- Password Security Policy Question
- Re: Password Security Policy Question
- Re: Password Security Policy Question
- Apple QuickTime ActiveX v5.0.2 Buffer Overrun (a091002-1)
- Foundstone Labs Advisory - Buffer Overflow in Savant Web Server
- [security bulletin] SSRT-547 HP Tru64 UNIX Potential Security Vulnerabilities TPC/IP, FTPD, ARP (fwd)
- Buffer over/underflows in ssldump prior to 0.9b3
- KDE Security Advisory: Secure Cookie Vulnerability
- KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability
- MDKSA-2002:059 - php update
- From: Mandrake Linux Security Team
- Re: Vulnerabilities in Microsoft's Java implementation
- Re: Foundstone Labs Advisory - Buffer Overflow in Savant Web Server
- RE: SecuRemote usernames can be guessed or sniffed using IKE exchange
- Final Speakers for HiverCon 2002 Announced
- Re: Small bug crashes OE
- Norton AntiVirus 2001 POP3 Proxy local DoS
- Re: Vulnerabilities in Microsoft's Java implementation
- slashdot / slashcode disclosing passwords
- Privacy leak in mozilla
- Some unpatched vulnerabilities fixed
- Re: Vulnerabilities in Microsoft's Java implementation
- Re: slashdot / slashcode disclosing passwords
- Re: slashdot / slashcode disclosing passwords
- Re: Password Security Policy Question
- efstool slackware 7.1 local root exploit exploit included
- Re: slashdot / slashcode disclosing passwords
- Re: slashdot / slashcode disclosing passwords
- Bypassing SMTP Content Protection with a Flick of a Button
- ht://Check XSS
- the attachement
- LEVERAGING CROSS-PROTOCOL SCRIPTING IN MSIE
- [SECURITY] [DSA 165-1] New PostgreSQL packages fix several vulnerabilities
- MIMEDefang update (was Re: Bypassing SMTP Content Protection )
- Re: efstool slackware 7.1 local root exploit exploit included
- Bypassing TrendMicro InterScan VirusWall
- xbreaky symlink vulnerability
- Re: PHP fopen() CRLF Injection
- Re: Small bug crashes OE
- FW: Bypassing SMTP Content Protection with a Flick of a Button
- Roaring Penguin fixes for "Bypassing SMTP Content Protection with a Flick of a Button"
- Re: xbreaky symlink vulnerability
- [CLA-2002:523] Conectiva Linux Security Announcement - util-linux
- Re: PHP fopen() CRLF Injection
- Re: xbreaky symlink vulnerability
- Re: Bypassing SMTP Content Protection with a Flick of a Button
- [SECURITY] [DSA 166-1] New purity packages fix potential buffer overflows
- Scan against Enterasys SSR8000 crash the system
- [securitydigest.org]: Changes in August/September 2002
- From: Curator at Security Digest Archives
- Re: Password Security Policy Question
- Re: Password Security Policy Question
- RE: Apache worm in the wild
- bugtraq.c httpd apache ssl attack
- Re: Multiple vulnerabilities in Avaya Argent Office
- Race condition in BRU Workstation 17.0
- OpenSSL worm in the wild
- Security Issue with Mac OS X
- Cobalt 6.0 Local Root
- Savant 3.1 multiple vulnerabilities
- Re: OpenSSL worm in the wild
- Re: bugtraq.c httpd apache ssl attack
- Re: Race condition in BRU Workstation 17.0
- Re: bugtraq.c httpd apache ssl attack
- RE: bugtraq.c httpd apache ssl attack
- [RHSA-2002:036-26] Updated ethereal packages available
- Re: OpenSSL worm in the wild
- Re: OpenSSL worm in the wild
- Re: bugtraq.c httpd apache ssl attack
- Re: Race condition in BRU Workstation 17.0
- nidump on OS X
- RE: bugtraq.c httpd apache ssl attack
- NSSI-2002-sygatepfw5: Sygate Personal Firewall IP Spoofing Vulnerability
- OpenSSH 3.4p1 Privsep
- iDEFENSE Security Advisory 09.16.2002: FreeBSD Ports libkvm Security Vulnerabilities
- [SECURITY] [DSA-136-2] Multiple OpenSSL problems (update)
- Re: Linux Slapper Worm code
- [SECURITY] [DSA 167-1] New kdelibs fix cross site scripting bug
- NetBSD Security Advisory 2002-011: Sun RPC XDR decoder contains buffer overflow
- From: NetBSD Security Officer
- NetBSD Security Advisory 2002-009:
- From: NetBSD Security Officer
- NetBSD Security Advisory 2002-017: shutdown(s, SHUT_RD) on TCP socket does not work as intended
- From: NetBSD Security Officer
- Re: bugtraq.c httpd apache ssl attack
- Microsoft Windows XP Remote Desktop denial of service vulnerability
- Re: Bug in Opera and Konqueror
- Microsoft Windows Remote Desktop Protocol checksum and keystroke vulnerabilities
- Re: Password Security Policy Question
- NetBSD Security Advisory 2002-007: Repeated TIOCSCTTY ioctl can corrupt session hold counts
- From: NetBSD Security Officer
- [SECURITY] [DSA-136-3] Multiple OpenSSL problems (update)
- Lycos HTMLGear Guestbook Script Injection Vulnerability
- NetBSD Security Advisory 2002-006: buffer overrun in libc/libresolv DNS resolver
- From: NetBSD Security Officer
- NetBSD Security Advisory 2002-012: buffer overrun in setlocale
- From: NetBSD Security Officer
- joe editor backup problem
- Re: Bypassing SMTP Content Protection with a Flick of a Button
- NetBSD Security Advisory 2002-013: Bug in NFS server code allows remote denial of service
- From: NetBSD Security Officer
- Advisory: File disclosure in DB4Web
- Bug in Opera and Konqueror
- Remote detection of vulnerable OpenSSL versions
- NetBSD Security Advisory 2002-010: symlink race in pppd
- From: NetBSD Security Officer
- Planet Web Software Buffer Overflow
- Multiple NetBSD Security Advisories Released/Updated
- From: NetBSD Security Officer
- FreeBSD Security Advisory FreeBSD-SA-02:39.libkvm
- From: FreeBSD Security Advisories
- Analysis of Modap worm
- NetBSD Security Advisory 2002-018: Multiple security isses with kfd daemon
- From: NetBSD Security Officer
- Re: bugtraq.c httpd apache ssl attack
- Re: Remote detection of vulnerable OpenSSL versions
- [SECURITY] [DSA 168-1] New PHP packages fix several vulnerabilities
- Microsoft Windows Terminal Services vulnerabilities
- Re: OpenSSH 3.4p1 Privsep
- Re: nidump on OS X
- Advisory: TCP-Connection risk in DB4Web
- Re: nidump on OS X
- Re: nidump on OS X
- Re: Password Security Policy Question
- Cisco VPN 5000 client buffer overflow vulnerabilities.
- Trillian .74 and below, ident flaw.
- IRIX default root umask and coredumps
- From: SGI Security Coordinator
- Cisco Security Advisory: Cisco VPN 5000 Client Multiple Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Microsoft Windows SMB Denial of Service Vulnerabilities in Cisco Products - MS02-045
- From: Cisco Systems Product Security Incident Response Team
- SuSE Security Announcement: xf86 (SuSE-SA:2002:032)
- NetBSD Security Advisory 2002-014: fd_set overrun in mbone tools and pppd
- From: NetBSD Security Officer
- Execution Rights Not Checked Correctly For 16-bit Applications
- Fw: [ut2003bugs] remote denial of service in ut2003 demo
- From: Arne Schwerdtfegger
- Re: OpenSSH 3.4p1 Privsep
- Re: OpenSSH 3.4p1 Privsep
- Web browser certificate Validation flaw: Netscape, Mozilla, MSIE vulnerable - still?
- Re: Trillian .74 and below, ident flaw.
- Re: slashdot / slashcode disclosing passwords
- Re: OpenSSH 3.4p1 Privsep
- Firewall-1 –HTTP Security Server - Proxy vulnerability
- iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3.
- Re: nidump on OS X
- RE: Execution Rights Not Checked Correctly For 16-bit Application s
- Foundstone Research Labs Advisory - Remotely Exploitable Buffer Overflow in ISS Scanner
- Re: Bug in Opera and Konqueror
- trillian DoS: trillian 1.0 pro also vulnerable
- Re: Linux Slapper Worm
- Mozilla vulnerabilities, an update
- The Art of Unspoofing
- NetMeeting 3.01 Local RDS Session Hijacking
- Re: Bug in Opera and Konqueror
- Re: Execution Rights Not Checked Correctly For 16-bit Applications
- KPMG-2002035: IBM Websphere Large Header DoS
- The Trivial Cisco IP Phones Compromise
- Re: Web browser certificate Validation flaw: Netscape, Mozilla, MSIE vulnerable - still?
- Trillian .73 & .74 "PRIVMSG" Overflow.
- Re: The Art of Unspoofing
- Re: The Art of Unspoofing
- Re: Linux Slapper Worm
- http://online.securityfocus.com/archive/1/291358/2002-09-08/2002-09-14/0, Subj: Norton AintiVirus 2001 POPROXY DoS
- [CLA-2002:524] Conectiva Linux Security Announcement - postgresql
- Re: nidump on OS X
- Re: [Full-Disclosure] iDEFENSE Security Advisory 09.18.2002: Security Vulnerabilities in OSF1/Tru64 3.
- Re: Linux Slapper Worm
- Squirrel Mail 1.2.7 XSS Exploit
- Re: Squirrel Mail 1.2.7 XSS Exploit
- iDEFENSE OSF1/Tru64 3.x vuln clarification
- More vulnerabilities (Re: Security side-effects of Word fields)
- CanSecWest/core03
- Re: The Trivial Cisco IP Phones Compromise
- [CLA-2002:525] Conectiva Linux Security Announcement - kdelibs
- ANNOUNCE: Egads 0.9.5
- ANNOUNCE: RATS 2.0
- Re: Trillian .74 and below, ident flaw.
- Re: Microsoft Windows Terminal Services vulnerabilities
- Yet Another. Trillian 'JOIN' Overflow.
- Re: NetMeeting 3.01 Local RDS Session Hijacking
- ShadowCon 2002
- Re: The Trivial Cisco IP Phones Compromise
- SuSE Security Announcement: Slapper worm (SuSE-SA:2002:033)
- Re: The Art of Unspoofing
- RE: The Trivial Cisco IP Phones Compromise
- Re: [UPDATED] Advisory: Multiple 602Pro LAN SUITE 2002 Denial of Service Attacks
- And Again. Trillian 'raw 221' Overflow.
- Sendmail logging and short string precision allows anonymous commands/relay
- *sigh* Trillian multiple DoS's flaws.
- remote exploitable heap overflow in Null HTTPd 0.5.0
- JAWmail XSS
- ToorCon 2002 This Weekend
- NetBSD Security Advisory 2002-009: Multiple vulnerabilities in OpenSSL code (updated 2002/9/22)
- From: NetBSD Security Officer
- RE: NetMeeting 3.01 Local RDS Session Hijacking
- Technical information about the vulnerabilities fixed by MS-02-52
- IE6 SSL Certificate Chain Verification
- PHP source injection in phpWebSite
- [security bulletin] SSRT2362 WEBES Service Tools (HP Tru64 UNIX, HP OpenVMS, Windows) Potential File Access Vulnerability (fwd)
- iDEFENSE Security Advisory 09.23.2002: Directory Traversal in Dino's Webserver
- [CLA-2002:526] Conectiva Linux Security Announcement - xchat
- Wireless Networking Frailty
- Now Online: OWASP Guide to Building Secure Web Applications v1.1
- Trillian Remote DoS Attack - AIM
- Kondara MNU/Linux
- HP Procurve 4000M Stacked Switch HTTP Reset Vulnerability
- Slapper worm redux;
- JSP source code exposure in Tomcat 4.x
- Xoops RC3 script injection vulnerability
- Re: JSP source code exposure in Tomcat 4.x
- Apache 2.0.(39|40) DOS (PHP!)
- RE: Trillian Remote DoS Attack - AIM
- Re: IE6 SSL Certificate Chain Verification
- Re: PHP source injection in phpWebSite
- PHPNUKE 6 XSS Vulnerabilities
- Re: JSP source code exposure in Tomcat 4.x
- RE: Trillian Remote DoS Attack - AIM
- Information Disclosure with Invision Board installation (fwd)
- [RHSA-2002:060-17] Updated Zope packages are available
- RE: JSP source code exposure in Tomcat 4.x
- Shana Informed 3.05 information disclosure
- IIL Advisory: Format String bug in Null Webmail (0.6.3)
- IIL Advisory: Vulnerabilities in acWEB HTTP server
- Re: Information Disclosure with Invision Board installation (fwd)
- OpenVMS POP server local vulnerability
- GLSA: tomcat
- ECHU Alert #2: IMG Attack in the news : 6 CMS vulnerables
- IIL Advisory: Reverse traversal vulnerability in Monkey (0.1.4) HTTP server
- PHP-Nuke x.x SQL Injection
- Not a bug: IIL Advisory: Format String bug in Null Webmail (0.6.3)
- Fwd: QuickTime for Windows ActiveX security advisory
- Re: Information Disclosure with Invision Board installation (fwd)
- Borland Interbase local root exploit
- iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv
- Re: Xoops RC3 script injection vulnerability fixed
- Errata: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv
- Microsoft PPTP Server and Client remote vulnerability
- Re: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv
- [SECURITY] [DSA 149-2] New glibc packages fix
- RE: iDEFENSE Security Advisory 09.26.2002: Exploitable Buffer Overflow in gv
- Postnuke XSS issues
- PHP-Nuke x.x AND PostNuke SQL Injection
- Postnuke XSS issues [correction]
- remote SYSTEM compromise in WASD OpenVMS http server
- Re: IIL Advisory: Reverse traversal vulnerability in Monkey (0.1.4) HTTP server
- Watchguard firewall appliances security issues
- GLSA: dietlibc
- Yet another XSS vulnerability in PHP NUKE
- GLSA: glibc (update)
- Allot Netenforcer problems, GNU TAR flaw
- Re: Hacking Citrix Faq (fwd)
- Another possible RFC 2046 vulnerability.
- From: Jose Marcio Martins da Cruz
- Re: Information Disclosure with Invision Board installation (fwd)
- Re: Xoops RC3 script injection vulnerability
- Software Update Available for Legacy RapidStream Appliances and W atchGuard Firebox Vclass appliances
- Re: Yet another XSS vulnerability in PHP NUKE
- From: Muhammad Faisal Rauf Danka
- Jetty jsp/servlet engine xss / uname disclosure vuln
- SafeTP coughs up internal server IP addresses
- Re: Xoops RC3 script injection vulnerability
- iDEFENSE Security Advisory 09.30.2002: Buffer Overflow in WN Server
- Advisory 03/2002: Fetchmail remote vulnerabilities
- [RHSA-2002:096-24] Updated unzip and tar packages fix vulnerabilities
- [LoWNOISE] "Get Knowledge" SunONE Starter Kit - Sun Microsystems/Astaware
- XSS bug in Monkey (0.5.0) HTTP server
- QT Assistant leaves port unfiltered
- Re: Another possible RFC 2046 vulnerability.
- SuSE Security Announcement: heimdal (SuSE-SA:2002:034)
- MyNewsGroups :) XSS patch
- IIL Advisory: Winamp 3 (1.0.0.488) XML parser buffer overflow vulnerability
- local exploitable overflow in rogue/FreeBSD
- NETGEAR FVS318 Information Disclosure
- Re: Another possible RFC 2046 vulnerability.
- Re: Postnuke XSS issues [correction]
- GNU tar (Re: Allot Netenforcer problems, GNU TAR flaw)
- XSS bug in MyMarket 1.71
Mail converted by MHonArc