«
Expand/Collapse
2758 items tagged "linux"
Related tags:
application [+],
multiple [+],
libavcodec [+],
flaw [+],
ffmpeg [+],
cifs [+],
application crash [+],
null pointer [+],
local security [+],
local [+],
heap memory [+],
based buffer overflow [+],
linux security [+],
system [+],
red hat security [+],
kernel packages [+],
buffer overflow [+],
bin [+],
arbitrary web [+],
linux kernel [+],
wolfgang draxinger [+],
tmp [+],
steve grubb [+],
service [+],
regsets [+],
mathematica [+],
kvm [+],
journal [+],
hfs [+],
foss desktop [+],
foss [+],
course authors [+],
clone [+],
chaos communication congress [+],
cause denial [+],
bsd [+],
abstract time [+],
kernel [+],
denial of service [+],
uri [+],
transparent proxying [+],
tls protocol [+],
tiff library [+],
tiff image [+],
tiff [+],
testtrack [+],
shellcode [+],
scott bell [+],
rpc code [+],
ropeadope [+],
rdf files [+],
race [+],
png image [+],
php scripts [+],
packet [+],
overflow condition [+],
ocsp [+],
null pointer dereference [+],
network address translation [+],
mozilla firefox [+],
mozilla developers [+],
memory safety [+],
memory buffer [+],
log [+],
local host [+],
libvorbis [+],
kettunen [+],
iptables firewall [+],
iptables [+],
invalid pointer [+],
information leak [+],
heap corruption [+],
hash table [+],
file [+],
external entities [+],
execve [+],
directory traversal vulnerability [+],
denial of service attacks [+],
denial of service attack [+],
dalili [+],
cyrus imap server [+],
cyrus imap [+],
code execution [+],
blair [+],
attackers [+],
array length [+],
application crashes [+],
anne van kesteren [+],
addendum [+],
account takeover [+],
security advisory [+],
gentoo linux security [+],
gentoo [+],
service vulnerability [+],
zed attack [+],
x86 linux [+],
video [+],
update [+],
testing tool [+],
temporary file [+],
systemd [+],
sqlalchemy [+],
sql injection [+],
split [+],
small linux [+],
session [+],
server hostname [+],
security vulnerabilities [+],
security experience [+],
remote [+],
red [+],
read [+],
proxy [+],
pkcs7 [+],
ocsinventory [+],
nfs [+],
mint [+],
lvve [+],
linux x86 [+],
linux machine [+],
iproute [+],
hat linux [+],
hat [+],
exploits [+],
exploit [+],
dsa [+],
dash [+],
arbitrary system [+],
android [+],
adobe flash player [+],
Release [+],
code versions [+],
westwood studios [+],
wanting [+],
vtech [+],
vinod [+],
v synch [+],
unauthorized access [+],
unauthorized [+],
umount [+],
ubuntu linux [+],
type displays [+],
toy [+],
tor browser [+],
thomas polasek [+],
teaching [+],
tablet computer [+],
syma [+],
string parameters [+],
sticky hands [+],
sony atrac3 [+],
shutter [+],
security checks [+],
root shell [+],
root privileges [+],
root [+],
raspberry [+],
radio [+],
query string [+],
proof of concept [+],
project [+],
preconceived notion [+],
port [+],
polasek [+],
parallel ports [+],
paper [+],
package [+],
nsv files [+],
nook [+],
nobel peace prize [+],
nieces and nephews [+],
mike kohn [+],
mick [+],
memcg [+],
mail message [+],
login [+],
local buffer overflow [+],
linux systems [+],
linux pc [+],
linux package [+],
linux game [+],
linux enterprise [+],
linux distro [+],
linux box [+],
linus torvalds [+],
lidd [+],
lcd modules [+],
kilobytes [+],
john tsiombikas [+],
ipv [+],
innotab [+],
hugepages [+],
ht editor [+],
holy crap [+],
helicopter [+],
hardware portion [+],
ghash [+],
game pad [+],
full disclosure [+],
flavors of linux [+],
ext [+],
exec [+],
evil [+],
espeak [+],
dongle [+],
dmitry [+],
dissector [+],
debian [+],
course [+],
controller [+],
color [+],
cifsfindnext [+],
chris [+],
chdir [+],
card [+],
bundle [+],
buffer overflow vulnerability [+],
bonus [+],
beaglebone [+],
audio [+],
aslr [+],
apple mjpeg b [+],
3d shutter glasses [+],
vulnerability [+],
memory corruption [+],
security [+],
hacks [+],
mandriva linux [+],
mandriva [+],
zvi,
ziv welch,
zip name,
zip,
zero,
youtube,
xterm,
xpath expressions,
xpath expression,
xor,
xfs file system,
xfs,
xen hypervisor,
xdr,
xcode,
xbee,
xattr,
xampp,
x86,
x.org,
x server,
world andy,
working,
workbench,
workaround,
wlan,
wireless network adapter,
wireless adapter,
windows,
wind speed sensor,
wind,
will,
wii remote,
wii,
whoami,
whitepaper,
whirlygig,
which,
wgetsc,
wft,
week,
webdav server,
webapps,
web interface,
web,
weaknet,
warrant,
wallie,
vulnerable systems,
vulnerable,
vulnerabilities,
vpn,
volume,
vmware,
vmsplice,
vlock,
vlan,
visual cue,
visit,
virus data,
virus,
virtual memory,
virtual consoles,
vidiocsmicrocode,
video streams,
vga signals,
vga,
vfs,
version 6,
verify,
vendors,
vasiliy kulikov,
variable values,
var,
validation,
validate,
uverbs,
utility,
usr bin,
usr,
usn,
using linux,
using a router,
usgs website,
user,
usb network adapter,
usb interface,
usb hub,
usb enclosure,
usb device,
usb,
usa,
urgently,
unwanted sound,
unsafe behavior,
unmount,
unlink,
unix sockets,
unix socket,
unix,
uninitialized pointer,
unicode,
underflow,
unavailable web,
umask,
uid,
udp port 68,
udp,
ubuntu,
txt,
tutti,
tutorial,
tunnels,
truetype,
true randomness,
trucki,
trojan horse,
transplant,
transparent,
tpm,
touchscreen interface,
touch interface,
touch,
tor,
toner,
tls extension,
tipc,
tiocgicount,
timothy b. terriberry,
timer function,
time,
tiff file,
thunder,
thomas pollet,
thin client,
text parameter,
text,
texas instruments,
texas,
tetex,
testing,
tempo,
temperature,
telnet daemon,
telnet,
tcp sockets,
tcp,
tavis ormandy,
tatu ylonen,
task,
target urls,
target system,
tar,
talpa,
tablet,
table,
systemtap,
system temperature,
system kernel,
system beep,
syscall,
sys,
sync shellcode,
sync,
symlinks,
symlink attack,
suspected,
superh sh,
superh,
sun java runtime environment,
sun java runtime,
suid root,
suid,
sudo,
suceed,
subsystem,
struct,
strom carlson,
strom,
string buffer,
stop,
stm,
stk,
start,
stack space,
stack pointer,
stack overflows,
stack overflow,
stack buffer,
stack,
sta,
ssl servers,
ssl,
ssid,
ssh,
srose,
sql query,
sql database,
sql commands,
sql,
spoonwep,
spoofing,
specific software,
spam,
space text,
sourceforge,
source,
sortof,
sophos,
sophisticated attacker,
sony,
sono,
software maintenance,
snowbot,
sniffjoke,
sniffer,
sndrv,
smp systems,
smbfs,
small,
sluggy,
slot,
sloc dos,
slides,
slave server,
sku,
sites,
site,
single board computer,
singapore,
signature verification,
signal code,
signal,
sigkill,
siemens a60,
shutdown linux,
shutdown,
shell scripts,
shell script,
shell metacharacters,
shell code,
shell arm,
shell,
shawn,
shaun clowes,
share photos,
shadow,
sh4,
several attacks,
setup,
setuid,
setreuid,
setreud,
setid,
sethostname,
seth hardy,
setgid,
setdomainname,
session identifier,
server,
serial number field,
serial,
sensor,
seneca college,
sendpage,
sendmsg,
sem,
selinux,
segmentation fault,
security weakness,
security tasks,
security response team,
security protections,
security linux,
security hole,
security flaw,
security enhancements,
security checklist,
security bugs,
security breach,
security advisories,
secure,
sebastian krahmer,
search script,
search,
sdf,
sda,
sd card slot,
sctp,
scsi target,
scsi,
script source code,
script element,
script,
screen space,
screen,
scope,
sbin,
sanity checks,
san antonio,
samsung printer,
samsung,
salve,
safer use,
ryan oneill,
ryan o neill,
running processes,
rules,
rue,
ruby,
rto,
rtl,
rpm,
router,
roundup,
rotor system,
rosewill,
rose protocol,
ros,
rop,
rootkit,
rooting,
root user,
root root,
root privilege,
root exploits,
root exploit,
root ca,
root bin,
robot platform,
robot,
roberto paleari,
rmdir,
retired,
response capability,
reset,
request,
remote security,
remote buffer overflow vulnerability,
remote buffer overflow,
reliable,
release numbers,
reiserfs,
regression,
redhat,
red hat enterprise,
record,
reboot,
readlink,
rds,
rc8,
rc3,
rants,
randomness,
randomize,
random number generator,
ramon de carvalho,
query,
quagga,
quadcopter,
python,
pwrite,
pwned,
purged,
pure ftpd,
pte,
psn network,
psn,
pseudorandom,
ps3,
protocol packets,
protocol index,
protocol implementation,
protections,
protection mechanism,
protection,
prompt text,
programming interface,
programmer,
program security,
program,
proftpd,
process dumper,
process,
proc,
privileged user,
privileged operations,
privileged guest,
privilege escalation vulnerability,
privilege,
priviledges,
printing system,
printing,
printer,
print,
pre,
pppol,
ppd file,
powerpc,
power,
potential security vulnerability,
postgresql server,
post,
port 8080,
port 520,
polymorphic,
poll,
polkitd,
political scandal,
pointer arithmetic,
pointer,
point exception,
point,
poc,
pmc,
pluggable authentication modules,
playstation 3,
playstation,
platform,
pkt,
pkexec,
pidmap,
pid,
picture,
pics,
pic microcontrollers,
phuck,
phpmyadmin,
phpdocumentor,
php functions,
php files,
php,
phar,
personality,
perl code,
perl 5,
peripherals,
perf,
per,
pentiums,
penetration,
pear,
pdf parser,
pdf,
pci,
patch,
password,
passwd,
partition tables,
partition,
part,
parse,
parrot,
paris,
parallel port,
pango,
pam,
page,
pad field,
pacman,
packs,
packetix,
pack,
ownership options,
owners,
overwrite,
override,
overflows,
overflow vulnerability,
overflow,
otheros,
osf,
os linux,
original place,
origin issues,
org,
openwrt,
openttd,
openssl library,
openssl,
openssh,
openoffice,
openldap,
openbsd,
open source software packages,
open source software,
open source project,
open source program,
open,
oops,
oom,
old laptop,
off,
ocfs,
object names,
o warrior,
number generation,
number,
null,
ntp,
notification,
noob,
node,
nix,
niu,
ngs,
nexus,
next,
news,
newline characters,
new,
networkmanager,
network traffic,
network proxy,
network protocol,
network packet,
network interface card,
network analyzer,
network,
netio,
netgear,
netfilter,
netcat shellcode,
netcat,
netbook,
nelson elhage,
neil,
neat piece,
ndman,
ndiswrapper,
nc shellcode,
nbsp,
nav,
native,
nathan,
namespace,
nameidata,
name,
music,
murder trial,
multiport,
multiple users,
multiple buffer overflow,
multicast,
mtab,
msn code,
msata,
mremap,
mpt,
mozilla thunderbird,
move,
mouse,
mount nfs,
mount local,
motion,
mother,
most linux distributions,
monkey island,
money,
module,
modsecurity,
modifying,
mode,
mobile broadband,
mmap,
mkdir tmp,
mkdir,
mixer,
mitigation,
mit kerberos,
missing something,
miro,
mips,
mini usb port,
mikael pettersson,
microcontrollers,
metasploit,
meta,
mempodipper,
memory space,
memory segment,
memory regions,
memory ranges,
memory leak,
memory heap,
memory expansion,
memory exhaustion,
memory consumption,
memory accesses,
memory,
media disk,
measuring cups,
mdvsa,
mdnsresponder,
max lee,
matt richardson,
matt evans,
mathias krause,
mathematic,
market share,
manipulations,
manipulation,
manipulatio,
mandatory access control,
mandalla,
manager,
management errors,
malware,
mail message header,
madvise,
mac osx,
mac os x,
mac os,
mac linux,
mac but,
mac,
lynx,
lwp file,
low frequency,
low,
lot,
logical volume manager,
logic analyzer,
logic,
local privilege escalation,
local memory,
local information,
loader,
load,
lnx,
liquid cooling,
linux wireless,
linux windows,
linux vendors,
linux tools,
linux system,
linux support,
linux sites,
linux servers,
linux os,
linux operating systems,
linux on a 386,
linux network,
linux modules,
linux mips,
linux machines,
linux kernels,
linux kernel versions,
linux kernel tree,
linux kernel drivers,
linux index,
linux images,
linux host,
linux event,
linux driver,
linux distributions,
linux distribution,
linux device driver,
linux device,
linux development,
linux desktop,
linux board,
linux based,
linux 7,
linksys nslu2,
linker,
line,
lighttpd,
light controller,
libxml2,
libxml,
libreoffice,
libpurple,
libcurl,
lempel ziv,
led lamp,
led,
leaps and bounds,
leapfrog,
leak,
ldm,
ld library,
lcd,
las herramientas,
laptops,
laptop,
lamp,
kulikov,
ksm,
kprobe,
knfsd,
kismet wireless,
kismet,
killall,
kill,
kget,
keyring,
keyctl,
keyboard shortcuts,
kexec tools,
kevin dady,
kernels,
kernel versions,
kernel version,
kernel tree,
kernel stack,
kernel setup,
kernel release,
kernel regression,
kernel proc,
kernel patch,
kernel panic,
kernel memory,
kernel internals,
kernel drivers,
kernel code,
kernel 2,
kerberos version,
kerberos 5,
kdump,
kdc,
justin,
jumbo frame,
jumbo,
jtag,
jre,
jpc,
joojoo,
jon oberheide,
john,
joey bernard,
java runtime environment,
java,
janne jansson,
isc dhcp server,
irda,
irc server,
irc,
ipt,
ippersonality,
ipmievd,
iplog,
iphone,
iph,
ipc,
ip multicast,
iommu,
ioctl,
invalid string,
invalid,
internet storage,
internet group management protocol,
internet group management,
internal storage,
interface,
interesting things,
intel 64,
integer overflow vulnerability,
integer overflow,
integer,
installing linux,
installation,
install,
insight,
input validation,
input peripherals,
input devices,
input,
injectso,
inj,
initialize,
initial character,
init function,
init,
information gathering,
information disclosure vulnerability,
information disclosure,
information,
infocast,
inexpensive robot,
inexpensive components,
inexpensive,
inet,
index names,
index,
incrementing,
implementation,
imaging,
image,
igmp,
igb,
ifconfig,
ids,
icmp,
huzaifa sidhpurwala,
https certificates,
httpd server,
http,
hp power,
hp linux,
how to,
hotkey,
hostos,
host os,
host,
hooking,
home,
hmid,
hijacking,
high risk,
high frequency,
hey,
help,
hebrew character,
heap,
headroom,
header names,
hdsp,
hci,
hashcat,
hash values,
hash collision,
hash,
hardware platform,
hardware peripherals,
hard disk space,
hans reiser,
handshake message,
handhelds,
handheld linux,
hal,
hacking,
hackers,
hack,
h. gunderson,
gzip,
gutterman,
guru,
guide,
guest os,
gss api,
grub,
gross understatement,
great forum,
gre,
gopher servers,
gopher,
good starting point,
gnu tar,
gnu mailman,
gnu linux,
gnu c library,
gnome desktop,
glsa,
glpi,
gitbrew,
gfs,
getuid,
get,
geohot,
generic,
gem,
gdb,
gb card,
game emulation,
fwlogwatch,
futex,
fuse,
functionality,
functional copy,
function,
ftrace,
fsgeometry,
frequency,
freetype,
free version,
free open source software,
frame,
fpl,
forward voltage,
forward message,
forkbome,
forkbombe,
forkbomb,
fork,
forgery,
forensics,
forensic analysis,
force,
fontfile,
fonera based,
folders,
folder,
florian echtler,
fix,
firmware update,
firewire,
filter image,
filter function,
filter,
filesystem,
files search,
file sizes,
file security,
file pcx,
file deletion,
fgx,
fernando,
fbioget,
faulty release,
fasync,
fan,
face icon,
express,
expoits,
exploiting,
exploitation,
exit shellcode,
exit,
exif,
execution stack,
exec system,
exe files,
exe,
excl,
example,
evince,
evasion techniques,
evasion,
evalbot,
ethtool,
ethernet bridge,
ethernet,
etcshadow shellcode,
etcpasswd,
etc passwd,
espresso machine,
escalation issues,
escalation,
error light,
error function,
eraser,
epoll,
epic time,
entropy,
enigma,
engineering,
encryption option,
elsa lancom,
elliptic curve cryptography,
ejection,
ehi,
egghunting,
egghunt,
efi,
educational toy,
edisi,
econet,
eclipse ide,
ec2,
ebtables,
earthquake data,
earthquake alert system,
earthquake,
e go,
dvb,
dumper,
dslr,
dsl,
drop,
droid,
drm,
drivers video sis,
driver,
download,
down,
dos vulnerability,
dos badger game,
donor,
don,
dns,
dll,
django,
diy tools,
distro,
displaylink,
display software,
disk,
discovery,
disclosure,
disableaslrarm shellcode,
disable,
directory traversal,
dir,
digital signature algorithm,
digital picture frame,
didj,
dhcpd,
dhcp,
device driver,
device,
development platform,
development,
developing linux applications,
dev,
desktop,
dereference,
dependency issues,
denies,
denial of service exploit,
denial of service dos,
denial,
demo,
demands,
dell wireless,
dell studio,
dell,
delall shellcode,
dei,
default package,
default,
debreaker,
debian linux,
debian gnu,
de carvalho,
dccp,
day,
david mandalla,
david koblas,
datagram sockets,
datagram congestion control protocol,
database,
daniel paluska,
dan rosenberg,
dan jacobson,
dallas,
dady,
cyrus sasl,
cve,
custom kernel,
culture event,
cuda,
cs4,
creation vulnerability,
crash course,
crash,
cpu utilization,
cpu cycles,
cpu consumption,
cpu clock,
cpu,
course management system,
cortex,
core control,
core c,
copter,
controller area network,
control,
consumption issues,
connector,
connectback,
connect,
conky,
condition,
computer,
compression algorithm,
compilation,
compat,
commands,
command,
comedi,
code encryption,
code,
cname record,
clock event,
clock,
client credentials,
client authentication,
client,
clear,
classic,
class action lawsuit,
clam antivirus,
cisco pix,
cisco ios,
cisco aironet,
chumby,
chuck willis tags,
chuck willis,
christian,
christens,
chris evans,
chown root,
chown,
chmod 777,
chmod,
chips,
chip,
chelsio,
checklist,
check security,
change mode,
change,
cgi perl module,
certificate authorities,
cellphones,
cellphone,
cdrom,
cdr,
cdda,
cat,
capability,
cap,
cant lock,
canonical,
can haz modharden,
camera,
caiaq,
cache manager,
c ping,
c linux,
c library,
c exploit,
c code,
c bridge,
bytes,
bytebinsh shellcode,
byte,
bunny,
bunnie,
building,
bugtraq,
buffer overflows,
buffer overflow vulnerabilities,
buffer overflow tutorial,
buffer overflow bug,
buffer,
buenas,
btrfs,
bt4,
bsd derived,
brute,
broadband,
brief,
bridge,
brace expansion,
boston,
booty,
bootloader,
boot,
bomb,
board,
bluetooth,
blowfish encryption,
block,
blk,
blind,
blackhole,
black hat,
bit,
bindshell,
bindport,
bind 9,
bind,
binary,
binaries,
bilal chishti,
bigdecimal class,
bigdecimal,
bfa,
best buy,
ben nanonote,
ben hawkes,
beep,
beefs,
beagleboard,
bcm,
bash,
badger,
backshell tcp,
backshell,
backdoor,
backconnect,
backbox,
back,
azx,
avr programmer,
auto,
authors,
augen,
auerswald,
attribute,
attacks,
attacker,
attack,
ati,
atheros,
astaro security linux,
astaro,
assertion failure,
aspire,
ascii,
array index,
armor protection,
armor,
armbinsh shellcode,
arm linux,
aristide fattori,
arduino,
arch,
arbitrary html,
arbitrary files,
arbitrary code execution,
arbitrary code,
arabic x,
april first,
april 1,
application protocols,
appletalk,
apple,
apparmor,
apartment in singapore,
apache http server,
apache,
anyone,
antonio,
anti virus,
anti,
andy green,
andrew peng,
andrew griffiths,
andrew,
and,
analyzer,
alsa,
alpha specific,
alert,
alasdair kergon,
agpioc,
advisory updates,
advisory,
adobe reader,
administrator privileges,
acpi,
acl,
acer,
access control list,
access,
abftw,
aaaa,
Weekly,
Support,
Soporte,
Software,
Programming,
Pentesting,
Newbie,
Howto,
Hardware,
Final,
BackTrack,
Area,
Angolo,
ARM,
802 11b
Skip to page:
1
2
3
...
12
-
-
8:20
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-081 - Security issues were identified and fixed in mozilla firefox. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Security research firm iDefense reported that researcher wushi of team509 discovered a memory corruption on Windows Vista and Windows 7 systems with hardware acceleration disabled or using incompatible video drivers. Various other issues have also been addressed.
-
8:20
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-081 - Security issues were identified and fixed in mozilla firefox. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Security research firm iDefense reported that researcher wushi of team509 discovered a memory corruption on Windows Vista and Windows 7 systems with hardware acceleration disabled or using incompatible video drivers. Various other issues have also been addressed.
-
8:20
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-081 - Security issues were identified and fixed in mozilla firefox. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Security research firm iDefense reported that researcher wushi of team509 discovered a memory corruption on Windows Vista and Windows 7 systems with hardware acceleration disabled or using incompatible video drivers. Various other issues have also been addressed.
-
5:01
»
Hack a Day
The Vtech InnoTab is a child-sized tablet computer built for kids. Apart from being the ideal solution to keeping the grubby, sticky hands of nieces and nephews away from proper ‘adult sized’ tablets, it can also serve as a Linux tablet perfect for a few homebrew apps. [Mick] picked up an InnoTab for his son, but after [...]
-
-
20:54
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-079 - A flaw exists in the IP network matching code in sudo versions 1.6.9p3 through 1.8.4p4 that may result in the local host being matched even though it is not actually part of the network described by the IP address and associated netmask listed in the sudoers file or in LDAP. As a result, users authorized to run commands on certain IP networks may be able to run commands on hosts that belong to other networks not explicitly listed in sudoers. The updated packages have been patched to correct this issue.
-
20:54
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-079 - A flaw exists in the IP network matching code in sudo versions 1.6.9p3 through 1.8.4p4 that may result in the local host being matched even though it is not actually part of the network described by the IP address and associated netmask listed in the sudoers file or in LDAP. As a result, users authorized to run commands on certain IP networks may be able to run commands on hosts that belong to other networks not explicitly listed in sudoers. The updated packages have been patched to correct this issue.
-
20:54
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-079 - A flaw exists in the IP network matching code in sudo versions 1.6.9p3 through 1.8.4p4 that may result in the local host being matched even though it is not actually part of the network described by the IP address and associated netmask listed in the sudoers file or in LDAP. As a result, users authorized to run commands on certain IP networks may be able to run commands on hosts that belong to other networks not explicitly listed in sudoers. The updated packages have been patched to correct this issue.
-
17:19
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201205-3 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 19.0.1084.46 are affected.
-
17:19
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201205-3 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 19.0.1084.46 are affected.
-
17:19
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201205-3 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 19.0.1084.46 are affected.
-
-
13:01
»
Hack a Day
[Chris] hasn’t managed to get his hands on a Raspberry Pi yet, so he ordered a BeagleBone and got down to business. He was surprised to find that there isn’t much info out there about using LIDD type displays with the hardware. This protocol is used in many of the 320×240 smart LCD modules on [...]
-
7:08
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1445-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed.
-
7:08
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1445-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed.
-
7:07
»
Packet Storm Security Advisories
Ubuntu Security Notice 1445-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed.
-
7:07
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1445-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed.
-
-
16:25
»
Packet Storm Security Advisories
PRE-CERT Security Advisory - The Linux kernel contains a vulnerability in the driver for HFS plus file systems that may be exploited for code execution or privilege escalation. A specially-crafted HFS plus filesystem can cause a buffer overflow via the memcpy() call of hfs_bnode_read() (in fs/hfsplus/bnode.c).
-
16:25
»
Packet Storm Security Recent Files
PRE-CERT Security Advisory - The Linux kernel contains a vulnerability in the driver for HFS plus file systems that may be exploited for code execution or privilege escalation. A specially-crafted HFS plus filesystem can cause a buffer overflow via the memcpy() call of hfs_bnode_read() (in fs/hfsplus/bnode.c).
-
16:25
»
Packet Storm Security Misc. Files
PRE-CERT Security Advisory - The Linux kernel contains a vulnerability in the driver for HFS plus file systems that may be exploited for code execution or privilege escalation. A specially-crafted HFS plus filesystem can cause a buffer overflow via the memcpy() call of hfs_bnode_read() (in fs/hfsplus/bnode.c).
-
15:02
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201205-2 - Multiple vulnerabilities have been found in ConnMan, allowing attackers to execute arbitrary code or cause Denial of Service. Versions less than 1.0-r1 are affected.
-
15:02
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201205-2 - Multiple vulnerabilities have been found in ConnMan, allowing attackers to execute arbitrary code or cause Denial of Service. Versions less than 1.0-r1 are affected.
-
-
15:31
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-076 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues have also been addressed.
-
15:31
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-076 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues have also been addressed.
-
15:11
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-075 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues were also addressed.
-
15:11
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-075 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues were also addressed.
-
14:57
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0571-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. A flaw was found in the way the Linux kernel's journal_unmap_buffer() function handled buffer head states. On systems that have an ext4 file system with a journal mounted, a local, unprivileged user could use this flaw to cause a denial of service. A flaw was found in the way the KVM_CREATE_IRQCHIP ioctl was handled. Calling this ioctl when at least one virtual CPU already existed could lead to a NULL pointer dereference later when the VCPU is scheduled to run. A local, unprivileged user on a KVM host could use this flaw to crash the host.
-
14:57
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0571-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. A flaw was found in the way the Linux kernel's journal_unmap_buffer() function handled buffer head states. On systems that have an ext4 file system with a journal mounted, a local, unprivileged user could use this flaw to cause a denial of service. A flaw was found in the way the KVM_CREATE_IRQCHIP ioctl was handled. Calling this ioctl when at least one virtual CPU already existed could lead to a NULL pointer dereference later when the VCPU is scheduled to run. A local, unprivileged user on a KVM host could use this flaw to crash the host.
-
14:56
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201205-1 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.168 are affected.
-
14:56
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201205-1 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.168 are affected.
-
14:56
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201205-1 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.168 are affected.
-
-
20:16
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-074 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues have also been addressed.
-
20:16
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-074 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues have also been addressed.
-
20:16
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-074 - Multiple vulnerabilities has been found and corrected in ffmpeg. The Matroska format decoder in FFmpeg does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file. cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362. Various other issues have also been addressed.
-
-
22:25
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2471-1 - Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.
-
13:00
»
Hack a Day
[Vinod] sent in a very cool build he says is somewhat of a ‘mad project’: he mounted an MMC and SD card under Linux using the parallel port on his computer. Even though parallel ports are getting rarer these days, we absolutely love [Vinod]‘s dedication and willingness to dig around the Linux kernel. The hardware portion of the [...]
-
-
8:38
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-073 - A flaw in the OpenSSL handling of CBC mode ciphersuites in DTLS can be exploited in a denial of service attack on both clients and servers. The updated packages have been patched to correct this issue.
-
8:38
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-073 - A flaw in the OpenSSL handling of CBC mode ciphersuites in DTLS can be exploited in a denial of service attack on both clients and servers. The updated packages have been patched to correct this issue.
-
8:38
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-073 - A flaw in the OpenSSL handling of CBC mode ciphersuites in DTLS can be exploited in a denial of service attack on both clients and servers. The updated packages have been patched to correct this issue.
-
-
8:29
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-072 - The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a login CSRF issue. Various other issues have also been addressed.
-
8:28
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-071 - This is a bugfix and security advisory that upgrades php to the latest 5.3.13 version for Mandriva Linux Enterprise 5.2 which resolves numerous upstream bugs in php.
-
8:26
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-068 - PHP-CGI-based setups contain a vulnerability when parsing query string parameters from php files. A remote unauthenticated attacker could obtain sensitive information, cause a denial of service condition or may be able to execute arbitrary code with the privileges of the web server. It was discovered that the previous fix for the CVE-2012-1823 vulnerability was incomplete. The updated packages provides the latest version which provides a solution to this flaw.
-
-
17:17
»
Packet Storm Security Advisories
Ubuntu Security Notice 1432-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was discovered in the Linux kernel's cifs file system. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. A flaw was found in the Linux kernel's ext4 file system when mounting a corrupt filesystem. A user-assisted remote attacker could exploit this flaw to cause a denial of service. Various other issues were also addressed.
-
-
19:25
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-070 - A file existence disclosure flaw was found in the way mount.cifs tool of the Samba SMB/CIFS tools suite performed mount of a Linux CIFS filesystem. A local user, able to mount a remote CIFS share / target to a local directory could use this flaw to confirm existence of a file system object (file, directory or process descriptor) via error messages generated during the mount.cifs tool run. The updated packages have been patched to correct this issue.
-
18:52
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-069 - A file existence dislosure flaw was found in the way mount.cifs tool of the Samba SMB/CIFS tools suite performed mount of a Linux CIFS filesystem. A local user, able to mount a remote CIFS share / target to a local directory could use this flaw to confirm existence of a file system object (file, directory or process descriptor) via error messages generated during the mount.cifs tool run. The updated packages have been patched to correct this issue.
-
-
19:13
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-067 - A vulnerability has been found and corrected in Samba. Security checks were incorrectly applied to the Local Security Authority CreateAccount, OpenAccount, AddAccountRights and RemoveAccountRights allowing any authenticated user to modify the privileges database. The updated packages have been patched to correct this issue.
-
-
13:44
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-066 - Security issues were identified and fixed in Mozilla Firefox and Thunderbird. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found a heap corruption in gfxImageSurface which allows for invalid frees and possible remote code execution. Anne van Kesteren of Opera Software found a multi-octet encoding issue where certain octets will destroy the following octets in the processing of some multibyte character sets. Various other issues were also addressed.
-
13:44
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-066 - Security issues were identified and fixed in Mozilla Firefox and Thunderbird. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found a heap corruption in gfxImageSurface which allows for invalid frees and possible remote code execution. Anne van Kesteren of Opera Software found a multi-octet encoding issue where certain octets will destroy the following octets in the processing of some multibyte character sets. Various other issues were also addressed.
-
13:44
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-066 - Security issues were identified and fixed in Mozilla Firefox and Thunderbird. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found a heap corruption in gfxImageSurface which allows for invalid frees and possible remote code execution. Anne van Kesteren of Opera Software found a multi-octet encoding issue where certain octets will destroy the following octets in the processing of some multibyte character sets. Various other issues were also addressed.
-
-
21:10
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-064 - It was discovered that the fix for was not sufficient to correct the issue for OpenSSL 0.9.8. The updated packages have been upgraded to the 0.9.8w version which is not vulnerable to this issue.
-
21:10
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-064 - It was discovered that the fix for was not sufficient to correct the issue for OpenSSL 0.9.8. The updated packages have been upgraded to the 0.9.8w version which is not vulnerable to this issue.
-
21:10
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-064 - It was discovered that the fix for was not sufficient to correct the issue for OpenSSL 0.9.8. The updated packages have been upgraded to the 0.9.8w version which is not vulnerable to this issue.
-
19:08
»
Packet Storm Security Advisories
Red Hat Security Advisory 2012-0517-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issue: A flaw was found in the Linux kernel in the way splitting two extents in ext4_ext_convert_to_initialized() worked. A local, unprivileged user with the ability to mount and unmount ext4 file systems could use this flaw to cause a denial of service.
-
19:08
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2012-0517-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issue: A flaw was found in the Linux kernel in the way splitting two extents in ext4_ext_convert_to_initialized() worked. A local, unprivileged user with the ability to mount and unmount ext4 file systems could use this flaw to cause a denial of service.
-
19:08
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2012-0517-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issue: A flaw was found in the Linux kernel in the way splitting two extents in ext4_ext_convert_to_initialized() worked. A local, unprivileged user with the ability to mount and unmount ext4 file systems could use this flaw to cause a denial of service.
-
-
18:08
»
Packet Storm Security Recent Files
iptables is built on top of netfilter, the packet alteration framework for Linux 2.4.x and 2.6.x. It is a major rewrite of its predecessor ipchains, and is used to control packet filtering, Network Address Translation (masquerading, portforwarding, transparent proxying), and special effects such as packet mangling.
-
18:08
»
Packet Storm Security Tools
iptables is built on top of netfilter, the packet alteration framework for Linux 2.4.x and 2.6.x. It is a major rewrite of its predecessor ipchains, and is used to control packet filtering, Network Address Translation (masquerading, portforwarding, transparent proxying), and special effects such as packet mangling.
-
18:08
»
Packet Storm Security Misc. Files
iptables is built on top of netfilter, the packet alteration framework for Linux 2.4.x and 2.6.x. It is a major rewrite of its predecessor ipchains, and is used to control packet filtering, Network Address Translation (masquerading, portforwarding, transparent proxying), and special effects such as packet mangling.
-
18:06
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-063 - An XML External Entity expansion flaw was found in the way Raptor processed RDF files. If an application linked against Raptor were to open a specially-crafted RDF file, it could possibly allow a remote attacker to obtain a copy of an arbitrary local file that the user running the application had access to. A bug in the way Raptor handled external entities could cause that application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. libreoffice for Mandriva Linux 2011 has been upgraded to the 3.4.6 version which is not vulnerable to this issue.
-
18:06
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-063 - An XML External Entity expansion flaw was found in the way Raptor processed RDF files. If an application linked against Raptor were to open a specially-crafted RDF file, it could possibly allow a remote attacker to obtain a copy of an arbitrary local file that the user running the application had access to. A bug in the way Raptor handled external entities could cause that application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. libreoffice for Mandriva Linux 2011 has been upgraded to the 3.4.6 version which is not vulnerable to this issue.
-
18:06
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-063 - An XML External Entity expansion flaw was found in the way Raptor processed RDF files. If an application linked against Raptor were to open a specially-crafted RDF file, it could possibly allow a remote attacker to obtain a copy of an arbitrary local file that the user running the application had access to. A bug in the way Raptor handled external entities could cause that application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. libreoffice for Mandriva Linux 2011 has been upgraded to the 3.4.6 version which is not vulnerable to this issue.
-
-
15:01
»
Hack a Day
[Linus Torvalds] pumped out Linux roughly 20 years ago and has now won some pretty major recognition for his contributions. We’ve seen different flavors of Linux installed on virtually everything you can think of, even on a dead badger. This prize is being compared to the Nobel Peace Prize, since there isn’t a Nobel prize [...]
-
-
22:50
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-060 - A potentially exploitable vulnerability has been discovered in the OpenSSL function asn1_d2i_read_bio that affects S/MIME or CMS applications using the built in MIME parser SMIME_read_PKCS7 or SMIME_read_CMS. The updated packages have been patched to correct this issue.
-
22:50
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-060 - A potentially exploitable vulnerability has been discovered in the OpenSSL function asn1_d2i_read_bio that affects S/MIME or CMS applications using the built in MIME parser SMIME_read_PKCS7 or SMIME_read_CMS. The updated packages have been patched to correct this issue.
-
-
0:25
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-4 - Multiple vulnerabilities have been found in FreeType, allowing remote attackers to possibly execute arbitrary code or cause Denial of Service. Versions less than 2.4.9 are affected.
-
0:25
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-4 - Multiple vulnerabilities have been found in FreeType, allowing remote attackers to possibly execute arbitrary code or cause Denial of Service. Versions less than 2.4.9 are affected.
-
0:25
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-8 - Two format string vulnerabilities have been found in the Perl DBD-Pg module, allowing a remote PostgreSQL servers to execute arbitrary code. Versions less than 2.19.0 are affected.
-
0:25
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-8 - Two format string vulnerabilities have been found in the Perl DBD-Pg module, allowing a remote PostgreSQL servers to execute arbitrary code. Versions less than 2.19.0 are affected.
-
0:24
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-7 - Multiple vulnerabilities in Adobe Flash Player, the worst of which might allow remote attackers to execute arbitrary code. Versions less than 11.2.202.228 are affected.
-
0:24
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201204-7 - Multiple vulnerabilities in Adobe Flash Player, the worst of which might allow remote attackers to execute arbitrary code. Versions less than 11.2.202.228 are affected.
-
0:24
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-6 - Multiple vulnerabilities have been found in PolicyKit, the worst of which may allow a local attacker to gain root privileges. Versions less than 0.104-r1 are affected.
-
10:01
»
Hack a Day
We should have included a footnote in the title. You can say that [Thomas Polasek] installed a full version of Arch Linux on his Nook Color, but there’s one caveat. It’s running on top of the Android kernel and his proof-of-concept uses a second computer to get it up and running. But there’s potential for [...]
-
-
21:41
»
SecDocs
Authors:
Wolfgang Draxinger Tags:
Linux Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Time to take a look back and under the hood of the current state of FOSS based desktops: The Good, The Bad and The Ugly – Bloat, strange APIs, too much complexity. The first decade of the 21st century brought huge progress in the development of FOSS Desktop systems. Users can now choose from a broad range of environments, which all adhere to a coherent set of standards. Not to forget that FOSS did even pioneer some GUI technologies which were later adopted by other (read: non free) systems.
-
21:41
»
SecDocs
Authors:
Wolfgang Draxinger Tags:
Linux Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Time to take a look back and under the hood of the current state of FOSS based desktops: The Good, The Bad and The Ugly – Bloat, strange APIs, too much complexity. The first decade of the 21st century brought huge progress in the development of FOSS Desktop systems. Users can now choose from a broad range of environments, which all adhere to a coherent set of standards. Not to forget that FOSS did even pioneer some GUI technologies which were later adopted by other (read: non free) systems.
-
21:41
»
SecDocs
Authors:
Wolfgang Draxinger Tags:
Linux Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Time to take a look back and under the hood of the current state of FOSS based desktops: The Good, The Bad and The Ugly – Bloat, strange APIs, too much complexity. The first decade of the 21st century brought huge progress in the development of FOSS Desktop systems. Users can now choose from a broad range of environments, which all adhere to a coherent set of standards. Not to forget that FOSS did even pioneer some GUI technologies which were later adopted by other (read: non free) systems.
-
21:41
»
SecDocs
Authors:
Wolfgang Draxinger Tags:
Linux Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Time to take a look back and under the hood of the current state of FOSS based desktops: The Good, The Bad and The Ugly – Bloat, strange APIs, too much complexity. The first decade of the 21st century brought huge progress in the development of FOSS Desktop systems. Users can now choose from a broad range of environments, which all adhere to a coherent set of standards. Not to forget that FOSS did even pioneer some GUI technologies which were later adopted by other (read: non free) systems.
-
17:15
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-059 - It was discovered that SQLAlchemy did not sanitize values for the limit and offset keywords for SQL select statements. If an application using SQLAlchemy accepted values for these keywords, and did not filter or sanitize them before passing them to SQLAlchemy, it could allow an attacker to perform an SQL injection attack against the application. The updated packages have been patched to correct this issue.
-
17:15
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-059 - It was discovered that SQLAlchemy did not sanitize values for the limit and offset keywords for SQL select statements. If an application using SQLAlchemy accepted values for these keywords, and did not filter or sanitize them before passing them to SQLAlchemy, it could allow an attacker to perform an SQL injection attack against the application. The updated packages have been patched to correct this issue.
-
11:13
»
Packet Storm Security Exploits
Mathematica on Linux uses the /tmp/MathLink directory in insecure ways that can allow for account takeover. The problem was made worse by later versions as the addendum states.
-
11:13
»
Packet Storm Security Recent Files
Mathematica on Linux uses the /tmp/MathLink directory in insecure ways that can allow for account takeover. The problem was made worse by later versions as the addendum states.
-
11:13
»
Packet Storm Security Misc. Files
Mathematica on Linux uses the /tmp/MathLink directory in insecure ways that can allow for account takeover. The problem was made worse by later versions as the addendum states.
-
-
10:01
»
Hack a Day
[Mike Kohn’s] Syma S107 helicopter wasn’t flying as well as it used to due to a broken gear, he figured he might as well find some use for the toy’s controller, since it was currently sitting around collecting dust. Having done a bunch of work with Syma IR protocols earlier this year, he decided it [...]
-
-
15:09
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-058 - curl is vulnerable to a SSL CBC IV vulnerability when built to use OpenSSL for the SSL/TLS layer. A work-around has been added to mitigate the problem. curl is vulnerable to a data injection attack for certain protocols through control characters embedded or percent-encoded in URLs. The updated packages have been patched to correct these issues.
-
15:09
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-058 - curl is vulnerable to a SSL CBC IV vulnerability when built to use OpenSSL for the SSL/TLS layer. A work-around has been added to mitigate the problem. curl is vulnerable to a data injection attack for certain protocols through control characters embedded or percent-encoded in URLs. The updated packages have been patched to correct these issues.
-
15:09
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-058 - curl is vulnerable to a SSL CBC IV vulnerability when built to use OpenSSL for the SSL/TLS layer. A work-around has been added to mitigate the problem. curl is vulnerable to a data injection attack for certain protocols through control characters embedded or percent-encoded in URLs. The updated packages have been patched to correct these issues.
-
-
8:38
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-057 - Multiple flaws were found in FreeType. Specially crafted files could cause application crashes or potentially execute arbitrary code. The updated packages have been patched to correct this issue.
-
8:38
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-057 - Multiple flaws were found in FreeType. Specially crafted files could cause application crashes or potentially execute arbitrary code. The updated packages have been patched to correct this issue.
-
8:38
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-057 - Multiple flaws were found in FreeType. Specially crafted files could cause application crashes or potentially execute arbitrary code. The updated packages have been patched to correct this issue.
-
-
8:12
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-055 - The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. The updated packages have been patched to correct this issue.
-
8:12
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-055 - The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. The updated packages have been patched to correct this issue.
-
8:12
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-055 - The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call. The updated packages have been patched to correct this issue.
-
7:22
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-2 - A heap-based buffer overflow in InspIRCd may allow execution of arbitrary code. Versions less than 2.0.5-r1 are affected.
-
7:22
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-2 - A heap-based buffer overflow in InspIRCd may allow execution of arbitrary code. Versions less than 2.0.5-r1 are affected.
-
7:22
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201204-2 - A heap-based buffer overflow in InspIRCd may allow execution of arbitrary code. Versions less than 2.0.5-r1 are affected.
-
7:21
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-3 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.151 are affected.
-
7:21
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-3 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.151 are affected.
-
7:21
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201204-3 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.151 are affected.
-
-
13:01
»
Hack a Day
So a man walks into a Radio Shack and the clerk says “Why the long face?”. No, that’s not it. [Ms3fgx] walks into a Radio Shack and says “holy crap, that PS3 IR dongle is only two bucks”. He’s been looking for an IR remote receiver to use with a Linux machine and decided to [...]
-
-
20:28
»
Packet Storm Security Recent Files
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Linux release.
-
20:28
»
Packet Storm Security Misc. Files
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Linux release.
-
18:28
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201204-1 - Multiple vulnerabilities were found in VirtualBox, allowing local attackers to gain escalated privileges. Versions prior to 4.1.8 are affected.
-
18:28
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201204-1 - Multiple vulnerabilities were found in VirtualBox, allowing local attackers to gain escalated privileges. Versions prior to 4.1.8 are affected.
-
18:28
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201204-1 - Multiple vulnerabilities were found in VirtualBox, allowing local attackers to gain escalated privileges. Versions prior to 4.1.8 are affected.
-
-
18:52
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-054 - An integer overflow was discovered in the libtiff/tiff_getimage.c file in the tiff library which could cause execution of arbitrary code using a specially crafted TIFF image file. The updated packages have been patched to correct this issue.
-
18:52
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-054 - An integer overflow was discovered in the libtiff/tiff_getimage.c file in the tiff library which could cause execution of arbitrary code using a specially crafted TIFF image file. The updated packages have been patched to correct this issue.
-
18:52
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-054 - An integer overflow was discovered in the libtiff/tiff_getimage.c file in the tiff library which could cause execution of arbitrary code using a specially crafted TIFF image file. The updated packages have been patched to correct this issue.
-
-
18:23
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-053 - Cross-site scripting vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. The updated packages have been patched to correct this issue.
-
18:23
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-053 - Cross-site scripting vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. The updated packages have been patched to correct this issue.
-
-
19:10
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-052 - If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct this issue.
-
19:10
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-052 - If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct this issue.
-
19:01
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-051 - A specially-crafted Ogg Vorbis media format file could cause an application using libvorbis to crash or, possibly, execute arbitrary code when opened. If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct these issues.
-
19:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-051 - A specially-crafted Ogg Vorbis media format file could cause an application using libvorbis to crash or, possibly, execute arbitrary code when opened. If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct these issues.
-
19:01
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-051 - A specially-crafted Ogg Vorbis media format file could cause an application using libvorbis to crash or, possibly, execute arbitrary code when opened. If a specially-crafted Ogg Vorbis media file was opened by an application using libvorbis, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct these issues.
-
18:45
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-050 - Multiple vulnerabilities have been found and corrected in phpmyadmin. It was possible to conduct XSS using a crafted database name. The show_config_errors.php scripts did not validate the presence of the configuration file, so an error message shows the full path of this file, leading to possible further attacks. This upgrade provides the latest phpmyadmin version to address these vulnerabilities.
-
18:45
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-050 - Multiple vulnerabilities have been found and corrected in phpmyadmin. It was possible to conduct XSS using a crafted database name. The show_config_errors.php scripts did not validate the presence of the configuration file, so an error message shows the full path of this file, leading to possible further attacks. This upgrade provides the latest phpmyadmin version to address these vulnerabilities.
-
18:45
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-050 - Multiple vulnerabilities have been found and corrected in phpmyadmin. It was possible to conduct XSS using a crafted database name. The show_config_errors.php scripts did not validate the presence of the configuration file, so an error message shows the full path of this file, leading to possible further attacks. This upgrade provides the latest phpmyadmin version to address these vulnerabilities.
-
-
19:27
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-049 - Cross-site scripting vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter. The updated packages have been patched to correct this issue.
-
19:27
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-049 - Cross-site scripting vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter. The updated packages have been patched to correct this issue.
-
19:27
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-049 - Cross-site scripting vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter. The updated packages have been patched to correct this issue.
-
19:27
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-048 - Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766. The updated packages have been patched to correct this issue.
-
19:27
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-048 - Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766. The updated packages have been patched to correct this issue.
-
10:22
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-047 - The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate. The updated packages have been patched to correct this issue.
-
10:22
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-047 - The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate. The updated packages have been patched to correct this issue.
-
10:22
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-047 - The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate. The updated packages have been patched to correct this issue.
-
8:22
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-046 - A potential memory corruption has been found and corrected in libpng. The updated packages have been patched to correct this issue.
-
8:22
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-046 - A potential memory corruption has been found and corrected in libpng. The updated packages have been patched to correct this issue.
-
8:22
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-046 - A potential memory corruption has been found and corrected in libpng. The updated packages have been patched to correct this issue.
-
-
10:52
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-24 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.142 are affected.
-
10:52
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201203-24 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.142 are affected.
-
10:52
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201203-24 - Multiple vulnerabilities have been reported in Chromium and V8, some of which may allow execution of arbitrary code. Versions less than 18.0.1025.142 are affected.
-
-
16:58
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-045 - Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service via a large SessionTicket. The updated packages have been patched to correct this issue.
-
16:58
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-045 - Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service via a large SessionTicket. The updated packages have been patched to correct this issue.
-
-
17:15
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-043 - A vulnerability has been found and corrected in nginx. A specially crafted backend response could result in sensitive information leak. The updated packages have been patched to correct this issue.
-
17:15
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-043 - A vulnerability has been found and corrected in nginx. A specially crafted backend response could result in sensitive information leak. The updated packages have been patched to correct this issue.
-
17:15
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-043 - A vulnerability has been found and corrected in nginx. A specially crafted backend response could result in sensitive information leak. The updated packages have been patched to correct this issue.
-
16:51
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-23 - Multiple vulnerabilities have been found in libzip, the worst of which might allow execution of arbitrary code. Versions less than 0.10.1 are affected.
-
16:51
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201203-23 - Multiple vulnerabilities have been found in libzip, the worst of which might allow execution of arbitrary code. Versions less than 0.10.1 are affected.
-
16:51
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201203-23 - Multiple vulnerabilities have been found in libzip, the worst of which might allow execution of arbitrary code. Versions less than 0.10.1 are affected.
-
-
19:43
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-042 - Multiple vulnerabilities was found and corrected in Wireshark. The ANSI A dissector could dereference a NULL pointer and crash. The IEEE 802.11 dissector could go into an infinite loop. The pcap and pcap-ng file parsers could crash trying to read ERF data. The MP2T dissector could try to allocate too much memory and crash. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
-
19:37
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-22 - Multiple vulnerabilities have been found in nginx, the worst of which may allow execution of arbitrary code. Versions less than 1.0.14 are affected.
-
19:37
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-21 - Multiple vulnerabilities have been found in Asterisk, the worst of which may allow execution of arbitrary code. Versions less than 1.8.10.1 are affected.
-
19:36
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-20 - A vulnerability in Logwatch might allow remote attackers to execute arbitrary code. Versions less than 7.4.0 are affected.
-
15:01
»
Hack a Day
This circuit is how [John Tsiombikas] makes his cheap 3D shutter glasses work with a Linux machine. It’s not that they were incompatible with Linux. The issue is that only certain video cards have the stereo port necessary to drive the head-mounted hardware. Shutter glasses block light from one eye at a time, so that [...]
-
6:01
»
Hack a Day
Linux is generally considered the go-to OS for under powered computers. Wanting to challenge the preconceived notion that Linux requires ‘a computer made in the last 20 years,’ [Dmitry] built the worst Linux PC ever around a simple 8-bit microcontroller. The ATMega1284p [Dmitry] used doesn’t have a lot to offer as far as RAM and storage goes; just 16 kilobytes [...]
-
-
20:00
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-041 - A memory leak and a hash table collision flaw in expat could cause denial of service attacks. The updated packages have been patched to correct this issue.
-
20:00
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-041 - A memory leak and a hash table collision flaw in expat could cause denial of service attacks. The updated packages have been patched to correct this issue.
-
20:00
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-041 - A memory leak and a hash table collision flaw in expat could cause denial of service attacks. The updated packages have been patched to correct this issue.
-
19:56
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-040 - gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure. The updated packages have been patched to correct this issue. The GnuTLS packages for Mandriva Linux 2011 has been upgraded to the 2.12.8 version due to problems with the test suite while building it, additionally a new dependency was added on p11-kit for the PKCS #11 support.
-
19:56
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-040 - gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure. The updated packages have been patched to correct this issue. The GnuTLS packages for Mandriva Linux 2011 has been upgraded to the 2.12.8 version due to problems with the test suite while building it, additionally a new dependency was added on p11-kit for the PKCS #11 support.
-
19:56
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-040 - gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure. The updated packages have been patched to correct this issue. The GnuTLS packages for Mandriva Linux 2011 has been upgraded to the 2.12.8 version due to problems with the test suite while building it, additionally a new dependency was added on p11-kit for the PKCS #11 support.
-
19:41
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-039 - The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure. The updated packages have been patched to correct this issue.
-
19:41
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-039 - The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure. The updated packages have been patched to correct this issue.
-
19:41
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-039 - The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure. The updated packages have been patched to correct this issue.
-
-
17:22
»
Packet Storm Security Advisories
Gentoo Linux Security Advisory 201203-19 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 17.0.963.83 are affected.
-
17:22
»
Packet Storm Security Recent Files
Gentoo Linux Security Advisory 201203-19 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 17.0.963.83 are affected.
-
17:22
»
Packet Storm Security Misc. Files
Gentoo Linux Security Advisory 201203-19 - Multiple vulnerabilities have been reported in Chromium, some of which may allow execution of arbitrary code. Versions less than 17.0.963.83 are affected.
-
-
16:59
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-037 - The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message. The updated packages have been patched to correct this issue.
-
16:59
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-037 - The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message. The updated packages have been patched to correct this issue.
-
16:59
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-037 - The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message. The updated packages have been patched to correct this issue.
-
16:53
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-036 - Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a \%2e\%2e in a URI. The updated packages have been patched to correct this issue.
-
16:53
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-036 - Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a \%2e\%2e in a URI. The updated packages have been patched to correct this issue.
-
16:53
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-036 - Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a \%2e\%2e in a URI. The updated packages have been patched to correct this issue.
-
16:53
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-035 - Multiple out-of heap-based buffer read flaws and invalid pointer dereference flaws were found in the way file, utility for determining of file types processed header section for certain Composite Document Format files. A remote attacker could provide a specially-crafted CDF file, which once inspected by the file utility of the victim would lead to file executable crash. The updated packages for Mandriva Linux 2011 have been upgraded to the 5.11 version and the packages for Mandriva Linux 2010.2 has been patched to correct these issues.
-
16:53
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-035 - Multiple out-of heap-based buffer read flaws and invalid pointer dereference flaws were found in the way file, utility for determining of file types processed header section for certain Composite Document Format files. A remote attacker could provide a specially-crafted CDF file, which once inspected by the file utility of the victim would lead to file executable crash. The updated packages for Mandriva Linux 2011 have been upgraded to the 5.11 version and the packages for Mandriva Linux 2010.2 has been patched to correct these issues.
-
16:53
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-035 - Multiple out-of heap-based buffer read flaws and invalid pointer dereference flaws were found in the way file, utility for determining of file types processed header section for certain Composite Document Format files. A remote attacker could provide a specially-crafted CDF file, which once inspected by the file utility of the victim would lead to file executable crash. The updated packages for Mandriva Linux 2011 have been upgraded to the 5.11 version and the packages for Mandriva Linux 2010.2 has been patched to correct these issues.
-
16:47
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-034 - libzip uses an incorrect loop construct, which can result in a heap overflow on corrupted zip files. libzip has a numeric overflow condition, which, for example, results in improper restrictions of operations within the bounds of a memory buffer. The updated packages have been upgraded to the 0.10.1 version to correct these issues.
-
16:47
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-034 - libzip uses an incorrect loop construct, which can result in a heap overflow on corrupted zip files. libzip has a numeric overflow condition, which, for example, results in improper restrictions of operations within the bounds of a memory buffer. The updated packages have been upgraded to the 0.10.1 version to correct these issues.
-
16:47
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-034 - libzip uses an incorrect loop construct, which can result in a heap overflow on corrupted zip files. libzip has a numeric overflow condition, which, for example, results in improper restrictions of operations within the bounds of a memory buffer. The updated packages have been upgraded to the 0.10.1 version to correct these issues.
-
-
21:01
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-033 - A heap-based buffer overflow flaw was found in the way libpng processed compressed chunks in PNG image files. An attacker could create a specially-crafted PNG image file that, when opened, could cause an application using libpng to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct this issue.
-
21:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-033 - A heap-based buffer overflow flaw was found in the way libpng processed compressed chunks in PNG image files. An attacker could create a specially-crafted PNG image file that, when opened, could cause an application using libpng to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct this issue.
-
21:01
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-033 - A heap-based buffer overflow flaw was found in the way libpng processed compressed chunks in PNG image files. An attacker could create a specially-crafted PNG image file that, when opened, could cause an application using libpng to crash or, possibly, execute arbitrary code with the privileges of the user running the application. The updated packages have been patched to correct this issue.
-
-
18:19
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-032 - Security issues were identified and fixed in mozilla firefox and thunderbird. Security researchers Blair Strang and Scott Bell of Security Assessment found that when a parent window spawns and closes a child window that uses the file open dialog, a crash can be induced in shlwapi.dll on 32-bit Windows 7 systems. Security researcher Soroush Dalili reported a way to bypass this protection. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
18:19
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-032 - Security issues were identified and fixed in mozilla firefox and thunderbird. Security researchers Blair Strang and Scott Bell of Security Assessment found that when a parent window spawns and closes a child window that uses the file open dialog, a crash can be induced in shlwapi.dll on 32-bit Windows 7 systems. Security researcher Soroush Dalili reported a way to bypass this protection. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
18:19
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-032 - Security issues were identified and fixed in mozilla firefox and thunderbird. Security researchers Blair Strang and Scott Bell of Security Assessment found that when a parent window spawns and closes a child window that uses the file open dialog, a crash can be induced in shlwapi.dll on 32-bit Windows 7 systems. Security researcher Soroush Dalili reported a way to bypass this protection. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
-
16:31
»
Hack a Day
The latest version of the Linux kernel was just released on Sunday, and there’s a little bonus which we think is worth considering. It seems that many changes from Android made their way into version 3.3 of the Linux kernel. This may not sound like much, but it’s a great example of the power of [...]
-
-
9:22
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-031 - Security issues were identified and fixed in mozilla firefox. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
9:22
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-031 - Security issues were identified and fixed in mozilla firefox. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
9:22
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-031 - Security issues were identified and fixed in mozilla firefox. Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. Various other issues were also addressed.
-
-
19:07
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-030 - A TOCTOU race condition was found in the way the systemd-logind login manager of the systemd, a system and service manager for Linux, performed removal of particular records related with user session upon user logout. A local attacker could use this flaw to conduct symbolic link attacks, potentially leading to removal of arbitrary system file. The updated packages have been patched to correct this issue.
-
19:07
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-030 - A TOCTOU race condition was found in the way the systemd-logind login manager of the systemd, a system and service manager for Linux, performed removal of particular records related with user session upon user logout. A local attacker could use this flaw to conduct symbolic link attacks, potentially leading to removal of arbitrary system file. The updated packages have been patched to correct this issue.
Skip to page:
1
2
3
...
12