Packet Storm Security Last 100100 Most Recent Packet Storm File Additionsglsa-200807-04.txt- (Found July 15, 2008 ) Gentoo Linux Security Advisory GLSA 200807-04 - Felipe Andres Manzano reported a memory management issue in the Page class constructordestructor. Versions less than 0.6.3-r1 are affected.http://packetstormsecurity.org/0807-advisories/glsa-200807-04.txt vbulletin-adminxss.txt- (Found July 15, 2008 ) vBulletin versions 3.7.2 and below and 3.6.10 PL2 and below suffer from a persistent cross site scripting flaw in the administrator logs.http://packetstormsecurity.org/0807-exploits/vbulletin-adminxss.txt cisco-sa-20080708-dns.txt- (Found July 15, 2008 ) Cisco Security Advisory - Multiple Cisco products are vulnerable to DNS cache poisoning attacks due to their use of insufficiently randomized DNS transaction IDs and UDP source ports in the DNS queries that they produce, which may allow an attacker to more easily forge DNS answers that can poison DNS caches. To exploit this vulnerability an attacker must be able to cause a vulnerable DNS server to perform recursive DNS queries. Therefore, DNS servers that are only authoritative, or servers...http://packetstormsecurity.org/0807-advisories/cisco-sa-20080708-dns.txt dsa-1605-1.txt- (Found July 15, 2008 ) Debian Security Advisory 1605-1 - Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS spoofing and cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.http://packetstormsecurity.org/0807-advisories/dsa-1605-1.txt dsa-1604-1.txt- (Found July 15, 2008 ) Debian Security Advisory 1604-1 - Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.http://packetstormsecurity.org/0807-advisories/dsa-1604-1.txt joomlacontent-sql.txt- (Found July 15, 2008 ) The Joomla Content component version 1.0.0 suffers from a SQL injection vulnerability.http://packetstormsecurity.org/0807-exploits/joomlacontent-sql.txt auracms-addeditdelete.txt- (Found July 15, 2008 ) AuraCMS versions 2.2.2 and below arbitrary editadddelete exploit that makes use of pages_data.php.http://packetstormsecurity.org/0807-exploits/auracms-addeditdelete.txt 07.08.08-1.txt- (Found July 15, 2008 ) iDefense Security Advisory 07.08.08 - Remote exploitation of an integer underflow vulnerability within Microsoft Corp.'s SQL Server could allow a remote attacker to execute arbitrary code with the privileges of the SQL Server. The vulnerability exists within the code responsible for parsing a stored backup file. A 32-bit integer value, representing the size of a record, is taken from the file and used to calculate the number of bytes to read into a heap buffer. This calculation can underflow,...http://packetstormsecurity.org/0807-advisories/07.08.08-1.txt USN-622-1.txt- (Found July 15, 2008 ) Ubuntu Security Notice 622-1 - Dan Kaminsky discovered weaknesses in the DNS protocol as implemented by Bind. A remote attacker could exploit this to spoof DNS entries and poison DNS caches. Among other things, this could lead to misdirected email and web traffic.http://packetstormsecurity.org/0807-advisories/USN-622-1.txt ollydbg-overflow.txt- (Found July 15, 2008 ) OllyDBG version 1.10 and ImpREC version 1.7f proof of concept exploit that demonstrates a buffer overflow vulnerability.http://packetstormsecurity.org/0807-exploits/ollydbg-overflow.txt |