SecuriTeam.comBeyond Security will help you expose your security holes and will show you what the bad guys already know about your hosts and network. Use our Automated Scanning service to perform a full security audit of your site, and find the latest security news and tools on Beyond Security's SecuriTeam web site.Vulnerabilities in Pragmatic General Multicast (PGM) Allows Denial of Service (MS08-036)- June 15, 2008 This security update resolves two privately reported vulnerabilities in the Pragmatic General Multicast (PGM) protocol that could allow a denial of service if malformed PGM packets are received by an affected system. An attacker who successfully exploited this vulnerability could cause a user s system to become non-responsive and to require a restart to restore functionality. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user...http://www.securiteam.com/windowsntfocus/5FP0G1FOKA.html Vulnerability in Active Directory Allows Denial of Service (MS08-035)- June 15, 2008 This security update resolves a privately reported vulnerability in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008; Active Directory Application Mode (ADAM) when installed on Windows XP Professional and Windows Server 2003; and Active Directory Lightweight Directory Service (AD LDS) when installed on Windows Server 2008. The vulnerability could be exploited to allow an attacker to cause a denial of service condition. On Windows.http://www.securiteam.com/windowsntfocus/5EP0F1FOKI.html Collection of Vulnerabilities in Fully Patched Vim- June 15, 2008 "Vim is an almost compatible version of the UNIX editor Vi. Many new features have been added: multi-level undo, syntax highlighting, command line history, on-line help, spell checking, filename completion, block operations, etc.'' Improper quoting in some parts of Vim written in the Vim Script can lead to arbitrary code execution upon opening a crafted file.http://www.securiteam.com/unixfocus/5AP0B1FOKO.html Multiple Vulnerabilities in QuickTime (PICT, AAC and URLs)- June 11, 2008 Apple's QuickTime product has been found to contain numerous vulnerabilities that would allow an attacker to cause the program to execute arbitrary code by sending it a malformed PICT, ACC encoded file or a malicious URL.http://www.securiteam.com/securitynews/5XP0E0AOKU.html freeSSHD Post Authentication Buffer Overflow (Exploit)- June 9, 2008 "freeSSHd, like it's name says, is a free implementation of an SSH server." A vulnerability in freeSSHD allows remote attackers to cause the server to overflow an internal buffer by sending it an arbitrary long change directory requesthttp://www.securiteam.com/exploits/5TP052KOKI.html VMware Multiple Products vmware-authd Untrusted Library Loading Vulnerability- June 9, 2008 VMware Inc. markets "several virtualization products which allow multiple virtual computers to run on a single system". Local exploitation of an untrusted library path vulnerability in multiple products distributed by VMware Inc. could allow an attacker to execute arbitrary code with root privileges.http://www.securiteam.com/unixfocus/5PP012KOKS.html NASA BigView Stack Buffer Overflow- June 6, 2008 NASA BigView 1 allows for interactive panning and zooming of images of arbitrary size on desktop PCs running Linux. Using this software, one can explore (on relatively modest machines) images such as the Mars Orbiter Camera mosaic 92160x33280 pixels.http://www.securiteam.com/unixfocus/5WP041POKQ.html Tomcat Host-Manager XSS Vulnerability- June 4, 2008 The Tomcat Host Manager web application does not escape user provided data before including it in the output.http://www.securiteam.com/unixfocus/5TP0215OKS.html Lynis - Security and System Auditing Tool- June 1, 2008http://www.securiteam.com/tools/5FP030AOKY.html |