<rss version="2.0"><channel><title>Bugtraq (bugtraq) Mailing List</title>
<link>http://seclists.org/#bugtraq</link>
<description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
<language>en-us</language><ttl>60</ttl>
<item><title>[Full-disclosure] [tool] SDT Cleaner 1.0</title><description>Posted by Nahuel C. Riva on Jul 23&lt;p&gt;


&lt;p&gt;
Hello!
&lt;br /&gt;
&lt;p&gt;You can find it here:
&lt;br /&gt;
http://oss.coresecurity.com/projects/sdtcleaner.html
&lt;br /&gt;
&lt;p&gt;Package:
&lt;br /&gt;
http://oss.coresecurity.com/repo/SDTCleaner-v1.0.zip
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;What is the SDT Cleaner?
&lt;br /&gt;
&lt;p&gt;SDT Cleaner is a tool that intends to clean the SSDT (system service
&lt;br /&gt;
descriptor table) from hooks.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0222.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0222.html</guid>
<pubDate>Wed, 23 Jul 2008 19:49:33 -0300</pubDate></item>
<item><title>[ MDVSA-2008:154 ] - Updated xemacs packages fix vulnerability</title><description>Posted by security_at_mandriva.com on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;&amp;nbsp;_______________________________________________________________________
&lt;br /&gt;
&amp;nbsp;
&lt;br /&gt;
&amp;nbsp;Mandriva Linux Security Advisory                         MDVSA-2008:154
&lt;br /&gt;
&amp;nbsp;http://www.mandriva.com/security/
&lt;br /&gt;
&amp;nbsp;_______________________________________________________________________
&lt;br /&gt;
&amp;nbsp;
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0221.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0221.html</guid>
<pubDate>Wed, 23 Jul 2008 17:29:00 -0600</pubDate></item>
<item><title>[SECURITY] [DSA 1616-1] new clamav packages fix denial of service</title><description>Posted by Devin Carraway on Jul 24&lt;p&gt;


&lt;p&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1616-1                  security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                           Devin Carraway
&lt;br /&gt;
July 24, 2008                         ...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0220.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0220.html</guid>
<pubDate>Thu, 24 Jul 2008 07:36:24 +0000</pubDate></item>
<item><title>CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning Flaw Exploit</title><description>Posted by Iruid on Jul 23&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;____      ____     __    __
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/    \...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0219.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0219.html</guid>
<pubDate>Wed, 23 Jul 2008 18:34:26 -0500</pubDate></item>
<item><title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title><description>Posted by security_at_mandriva.com on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;&amp;nbsp;_______________________________________________________________________
&lt;br /&gt;
&amp;nbsp;
&lt;br /&gt;
&amp;nbsp;Mandriva Linux Security Advisory                         MDVSA-2008:153
&lt;br /&gt;
&amp;nbsp;http://www.mandriva.com/security/
&lt;br /&gt;
&amp;nbsp;_______________________________________________________________________
&lt;br /&gt;
&amp;nbsp;
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0218.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0218.html</guid>
<pubDate>Wed, 23 Jul 2008 15:56:00 -0600</pubDate></item>
<item><title>Re: Wordpress Malicious File Execution Vulnerability</title><description>Posted by otto_at_ottodestruct.com on Jul 23&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Regarding this report of May 2008:
&lt;br /&gt;
http://www.securityfocus.com/bid/29276
&lt;br /&gt;
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2392
&lt;br /&gt;
&lt;p&gt;The report is invalid. This is not a vulnerability or a security flaw. Quite frankly, I think it&#39;s a joke.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0217.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0217.html</guid>
<pubDate>23 Jul 2008 19:44:51 -0000</pubDate></item>
<item><title>[SECURITY] [DSA 1615-1] New xulrunner packages fix several vulnerabilities</title><description>Posted by Moritz Muehlenhoff on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1615-1                  security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                       Moritz Muehlenhoff
&lt;br /&gt;
July 23, 2008                         ...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0216.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0216.html</guid>
<pubDate>Wed, 23 Jul 2008 22:33:58 +0200</pubDate></item>
<item><title>[SECURITY] [DSA 1614-1] New iceweasel packages fix several vulnerabilities</title><description>Posted by Moritz Muehlenhoff on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1614-1                  security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                       Moritz Muehlenhoff
&lt;br /&gt;
July 23, 2008                         ...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0215.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0215.html</guid>
<pubDate>Wed, 23 Jul 2008 22:07:11 +0200</pubDate></item>
<item><title>[USN-628-1] PHP vulnerabilities</title><description>Posted by Jamie Strandboge on Jul 23&lt;p&gt;


&lt;p&gt;
=========================================================== 
&lt;br /&gt;
Ubuntu Security Notice USN-628-1              July 23, 2008
&lt;br /&gt;
php5 vulnerabilities
&lt;br /&gt;
CVE-2007-4782, CVE-2007-4850, CVE-2007-5898, CVE-2007-5899,
&lt;br /&gt;
CVE-2008-0599, CVE-2008-1384, CVE-2008-2050, CVE-2008-2051,
&lt;br /&gt;
CVE-2008-2107, CVE-2008-2108,...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0214.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0214.html</guid>
<pubDate>Wed, 23 Jul 2008 15:39:07 -0400</pubDate></item>
<item><title>Vim: Flawed Fix of Arbitrary Code Execution Vulnerability in filetype.vim</title><description>Posted by Jan Min on Jul 23&lt;p&gt;


&lt;p&gt;
1. SUMMARY
&lt;br /&gt;
&lt;p&gt;Product  : Vim -- Vi IMproved
&lt;br /&gt;
Version  : Tested with Vim 7.2b.10, filetype.vim 2008-07-17
&lt;br /&gt;
Impact   : Arbitrary code execution
&lt;br /&gt;
Wherefrom: Local and remote
&lt;br /&gt;
CVE      : CVE-2008-2712
&lt;br /&gt;
Original : http://www.rdancer.org/vulnerablevim-filetype.vim.updated.html
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0213.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0213.html</guid>
<pubDate>Wed, 23 Jul 2008 19:29:01 +0100</pubDate></item>
<item><title>[SECURITY] [DSA 1540-3] New lighttpd packages fix regression</title><description>Posted by Thijs Kinkhorst on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1540-3                  security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                          Thijs Kinkhorst
&lt;br /&gt;
July 23, 2008                         ...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0212.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0212.html</guid>
<pubDate>Wed, 23 Jul 2008 20:59:43 +0200 (CEST)</pubDate></item>
<item><title>RE: Windows Vista Power Management amp Local Security Policy</title><description>Posted by Good Securitypractice on Jul 23&lt;p&gt;


&lt;p&gt;
People in this discussion have been focusing on the technical aspects
&lt;br /&gt;
rather than the people aspect.
&lt;br /&gt;
&lt;p&gt;The current power management system is MUCH more secure because people
&lt;br /&gt;
do not have to be given an account on the machine for them to shut it
&lt;br /&gt;
down.
&lt;br /&gt;
&lt;p&gt;This is helpful when an admin can not get to...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0211.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0211.html</guid>
<pubDate>Wed, 23 Jul 2008 13:16:06 -0400</pubDate></item>
<item><title>RE: Windows Vista Power Management amp Local Security Policy</title><description>Posted by Abe Getchell on Jul 22&lt;p&gt;


&lt;p&gt;
Correct. Power management in Windows Vista is apparently given a pass to
&lt;br /&gt;
bypass local security policy, which is a bad thing, and sets a bad
&lt;br /&gt;
precedence. I will leave it to others to exploit this security issue, given
&lt;br /&gt;
that I know little about the programmatic aspect of power management in
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0210.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0210.html</guid>
<pubDate>Tue, 22 Jul 2008 18:37:07 -0400</pubDate></item>
<item><title>AST-2008-011: Traffic amplification in IAX2 firmware provisioning system</title><description>Posted by Asterisk Security Team on Jul 22&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Asterisk Project Security Advisory - AST-2008-011
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;+------------------------------------------------------------------------+
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;|      Product       | Asterisk...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0209.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0209.html</guid>
<pubDate>Tue, 22 Jul 2008 18:16:07 -0500</pubDate></item>
<item><title>AST-2008-010: Asterisk IAX POKE resource exhaustion</title><description>Posted by Asterisk Security Team on Jul 22&lt;p&gt;


&lt;p&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Asterisk Project Security Advisory - AST-2008-010
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;+------------------------------------------------------------------------+
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;|       Product        | Asterisk...</description>
<link>http://seclists.org/bugtraq/2008/Jul/0208.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Jul/0208.html</guid>
<pubDate>Tue, 22 Jul 2008 18:15:49 -0500</pubDate></item>
</channel></rss>