RedTram News Search Engine
Русский  English Українська  Français  Polski  Deutsch  Italiano  Español  中文   
9 July 2008 year (time zone GMT 00:00)  Number of sources in English: 4473
Navigating the themes
Navigating the regions
All Themes Technologies Hard & Soft Information Security World
Information Security (World) RSS 2.0

Debian: DNS vulnerability impact on the libc stub resolver

09.07.2008 14:04    linuxsecurity.com
LinuxSecurity.com: Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS spoofing and cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.


Gentoo: Poppler User-assisted execution of arbitrary

09.07.2008 14:04    linuxsecurity.com
LinuxSecurity.com: =3D=3D=3D=3D=3D=3D=3D=3D Poppler is affected by a memory management issue, which could lead to the execution of arbitrary code.

Ubuntu: Bind vulnerability

09.07.2008 14:03    linuxsecurity.com
LinuxSecurity.com: Dan Kaminsky discovered weaknesses in the DNS protocol as implemented by Bind. A remote attacker could exploit this to spoof DNS entries and poison DNS caches. Among other things, this could lead to misdirected email and web traffic.

Mandriva: Updated OpenOffice.org packages fix vulnerability

09.07.2008 14:03    linuxsecurity.com
LinuxSecurity.com: Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow. The updated packages have been patched to fix

Mandriva: Updated Firefox packages fix vulnerabilities

09.07.2008 14:03    linuxsecurity.com
LinuxSecurity.com: Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.15. This update provides the latest Firefox to correct these issues.

RedHat: Important: bind security update

09.07.2008 14:03    linuxsecurity.com
LinuxSecurity.com: Updated bind packages that help mitigate DNS spoofing attacks are now available. This update has been rated as having important security impact by the Red Hat Security Response Team.

Major fix to DNS Vulnerability Impacts Debian

09.07.2008 14:03    linuxsecurity.com
LinuxSecurity.com: A very serious flaw in the Internet's DNS servers may have been ripe for a significant exploit, though a familiar security researcher might have sounded the alarm just in time. Now, Microsoft and Linux vendors are responding urgently. In

Sun Solaris 10 DNS Cache Poisoning Vulnerability

09.07.2008 13:36    secunia.com
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache. The vulnerability is caused due to the products not sufficiently randomising the DNS transaction ID and the source port number,

rPath update for vsftpd

09.07.2008 13:36    secunia.com
rPath has issued an update for vsftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a memory leak when using PAM and can be

Debian bind DNS Cache Poisoning Vulnerability

09.07.2008 13:36    secunia.com
Debian has acknowledged a vulnerability in bind, which can be exploited by malicious people to poison the DNS cache.

Juniper Networks Products DNS Cache Poisoning Vulnerability

09.07.2008 13:35    secunia.com
A vulnerability has been reported in various Juniper Network products, which can be exploited by malicious people to poison the DNS cache. The vulnerability is caused due to the products not sufficiently randomising the DNS transaction ID and the source

Sun Solaris DNS Cache Poisoning Vulnerability

09.07.2008 13:35    secunia.com
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache. The vulnerability is caused due to the products not sufficiently randomising the DNS transaction ID and the source port number,

Fedora update for seamonkey

09.07.2008 13:35    secunia.com
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.

Nominum CNS and Vantio DNS Cache Poisoning Vulnerability

09.07.2008 13:35    secunia.com
Nominum has acknowledged a vulnerability in Nominum CNS and Vantio, which can be exploited by malicious people to poison the DNS cache. The vulnerability is caused due to the DNS servers not sufficiently randomising the DNS query port number, which

Fedora update for WebKit

09.07.2008 13:35    secunia.com
Fedora has issued an update for WebKit. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Sun Java JDK / JRE Multiple Vulnerabilities

09.07.2008 13:34    secunia.com
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system. 1) An

Red Hat update for pidgin

09.07.2008 13:34    secunia.com
Red Hat has issued an update for pidgin. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Pidgin MSN SLP Message Integer Overflow Vulnerabilities

09.07.2008 13:34    secunia.com
Some vulnerabilities have been reported in Pidgin, which potentially can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to integer overflow errors in the "msn_slplink_process_msg" function in libpurple/protocols/msnp9/slplink.c and libpurple/protocols/msn/slplink.c, and can potentially

FFmpeg libavformat "str_read_packet()" Buffer Overflow

09.07.2008 13:34    secunia.com
A vulnerability has been reported in FFmpeg, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the "str_read_packet()" function in libavformat/psxstr.c. This can be exploited to

F5 FirePass 1200 SSL VPN SNMP Denial of Service

09.07.2008 13:33    secunia.com
nnposter has reported a vulnerability in F5 FirePass 1200 SSL VPN, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error when traversing certain OID branches (e.g. hrSWInstalled

1 | 2 | 3 | 4 »