Search   Feed   Browse   Add
Feed items 71 - 80 of 781 for June 2008

Edgeos - New Vulnerabilities

Edgeos - Private-Labeled Vulnerability Assessment Services

SuSE Security Update: samba: security update (cifs-mount-5294) - (Found June 29, 2008 )

Critical Risk -- Samba has been updated to fix a security problem:CVE-2008-1105: Secunia research discovered vulnerabilityin Samba, which can be exploited by malicious people tocompromise a vulnerable system.The vulnerability is caused due to a boundary error withinthe 'receive_smb_raw()' function in libutil_sock.c whenparsing SMB packets. This can be exploited to cause aheap-based buffer overflow via an overly large SMB packetreceived in a client context.
http://www.edgeos.com/threats/33100

SuSE Security Update: Security update for Samba (cifs-mount-5292) - (Found June 29, 2008 )

Critical Risk -- Samba has been updated to fix a security problem:CVE-2008-1105: Secunia research discovered vulnerabilityin Samba, which can be exploited by malicious people tocompromise a vulnerable system.The vulnerability is caused due to a boundary error withinthe 'receive_smb_raw()' function in libutil_sock.c whenparsing SMB packets. This can be exploited to cause aheap-based buffer overflow via an overly large SMB packetreceived in a client context.
http://www.edgeos.com/threats/33099

SuSE Security Update: vorbis-tools security update (vorbis-tools-5192) - (Found June 29, 2008 )

Critical Risk -- Specially crafted files or streams could potentially beabused to trick applications that support speex intoexecuting arbitrary code (CVE-2008-1686).
http://www.edgeos.com/threats/33091

SuSE Security Update: Security update for vorbis-tools (vorbis-tools-5193) - (Found June 29, 2008 )

Critical Risk -- Specially crafted files or streams could potentially beabused to trick applications that support speex intoexecuting arbitrary code (CVE-2008-1686).
http://www.edgeos.com/threats/33092

USN614-1 : Linux kernel vulnerabilities - (Found June 29, 2008 )

Critical Risk -- It was discovered that PowerPC kernels did not correctly handle reportingcertain system details. By requesting a specific set of information,a local attacker could cause a system crash resulting in a denialof service. (CVE-2007-6694)A race condition was discovered between dnotify fcntl() and close() inthe kernel. If a local attacker performed malicious dnotify requests,they could cause memory consumption leading to a denial of service,or possibly send arbitrary signals to any.
http://www.edgeos.com/threats/33093

Kaspersky kl1.sys Driver Buffer Overflow Vulnerability - (Found June 29, 2008 )

Critical Risk -- The version of the Kaspersky product installed on the remote hostcontains a stack-based overflow in its 'kl1.sys' kernel driverinvolving its handling of IOCTL 0x800520e8. A local attacker may beable to leverage this issue to gain complete control of the affectedsystem.
http://www.edgeos.com/threats/33094

HP Instant Support HPISDataManager.dll ActiveX Control < 1.0.0.24 Vulnerabilities - (Found June 29, 2008 )

Critical Risk -- The remote host contains several ActiveX controls in HP InstantSupport HPISDataManager.dll, a web-based diagnostic tool fromHewlett-Packard. The version of the controls installed on the remote host reportedlyare affected by several issues. If an attacker can trick a user onthe affected host into viewing a specially-crafted HTML document, hemay be able to use this method to execute arbitrary code by means ofbuffer overflows or to execute delete, download, and write toarbitrary..
http://www.edgeos.com/threats/33095

RHSA-2008-0498: cups - (Found June 29, 2008 )

Critical Risk -- Updated cups packages that fix a security issue are now available for Red Hat Enterprise Linux 3, Red Hat Enterprise Linux 4, and Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The Common UNIX Printing System (CUPS) provides a portable printing layer for UNIX operating systems. An integer overflow flaw leading to a heap buffer overflow was discovered in the Portable Network Graphics (PNG)..
http://www.edgeos.com/threats/33096

RHSA-2008-0515: evolution - (Found June 29, 2008 )

Critical Risk -- Updated evolution28 packages that address two buffer overflow vulnerabilities are now available for Red Hat Enterprise Linux 4. This update has been rated as having important security impact by the Red Hat Security Response Team. Evolution is the integrated collection of e-mail, calendaring, contact management, communications and personal information management (PIM) tools for the GNOME desktop environment. A flaw was found in the way Evolution parsed iCalendar timezone..
http://www.edgeos.com/threats/33097

RHSA-2008-0516: evolution - (Found June 29, 2008 )

Critical Risk -- Updated evolution packages that address a buffer overflow vulnerability are now available for Red Hat Enterprise Linux 3 and Red Hat Enterprise Linux 4. This update has been rated as having critical security impact by the Red Hat Security Response Team. Evolution is the integrated collection of e-mail, calendaring, contact management, communications and personal information management (PIM) tools for the GNOME desktop environment. A flaw was found in the way Evolution...
http://www.edgeos.com/threats/33098
Available Archives
- June (781 items)
Sponsored Links
© 2008 FeedCapsule.com  |  Contact