Small Business System

- there is no shame for cleverness -

Archive for October 3rd, 2008

[USN-649-1] OpenSSH vulnerabilities

without comments

If you're new here, you may want to opt-in Or click this link: Small Business System of this week

Small Business System of last week

Thanks for visiting!

Name:
Email:
Computer Security Mashup

Posted by Kees Cook on Oct 1. =========================================================== Ubuntu Security Notice USN-649-1 October 01, 2008 openssh vulnerabilities CVE-2008-1657, CVE-2008-4109

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in blogs

[USN-649-1] OpenSSH vulnerabilities

without comments

Posted by Kees Cook on Oct 1

===========================================================

Ubuntu Security Notice USN-649-1 October 01, 2008

openssh vulnerabilities

CVE-2008-1657, CVE-2008-4109

===========================================================

A security issue affects the following Ubuntu releases:

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in security

FreeBSD Security Advisory FreeBSD-SA-08:10.nd6

without comments

Posted by FreeBSD Security Advisories on Oct 2. ============================================================================= FreeBSD-SA-08:10.nd6 Security Advisory … ShareThis.

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in blogs

FreeBSD Security Advisory FreeBSD-SA-08:10.nd6

without comments

Posted by FreeBSD Security Advisories on Oct 2

=============================================================================

FreeBSD-SA-08:10.nd6 Security Advisory

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in security

Adobe Flash Player plug-in null pointer dereference and browser crash

without comments

Posted by Matthew Dempsky on Oct 1. If a Flash 9 SWF loads two SWF files with different SWF version numbers from two distinct HTTP requests to the exact same URL (including query string arguments), then Adobe’s Flash Player plug-in

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in blogs

Adobe Flash Player plug-in null pointer dereference and browser crash

without comments

Posted by Matthew Dempsky on Oct 1

If a Flash 9 SWF loads two SWF files with different SWF version

numbers from two distinct HTTP requests to the exact same URL

(including query string arguments), then Adobe’s Flash Player plug-in

will try to dereference a null pointer. This issue affects at least

versions 9.0.45.0,…

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in security

XSS vulnerability in phpMyID

without comments

Posted by Raphael Geissert on Oct 1. Subject: XSS vulnerability in phpMyID Credits: Raphael Geissert Release date: 2008-10-27 Affects: v0.9 [23-Jul-2008]. Resources: * Homepage: http://siege.org/projects/phpMyID/

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in blogs

XSS vulnerability in phpMyID

without comments

Posted by Raphael Geissert on Oct 1

Subject: XSS vulnerability in phpMyID

Credits: Raphael Geissert <atomo64_at_gmail.com>

Release date: 2008-10-27

Affects: v0.9 [23-Jul-2008]

Resources:

    * Homepage: http://siege.org/projects/phpMyID/

    * Demo: http://phpmyid.com

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in security

Layered Defense Research Advisory: Juniper Netscreen Firewall

without comments

Posted by dh_at_layereddefense.com on Oct 2. (’binary’ encoding is not supported, stored as-is) ================================================== Layered Defense Research Advisory 1 October 2008

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in blogs

Layered Defense Research Advisory: Juniper Netscreen Firewall Cross-Site-Scripting (XSS) event log injection

without comments

Posted by dh_at_layereddefense.com on Oct 2

(’binary’ encoding is not supported, stored as-is)
==================================================
Layered Defense Research Advisory 1 October 2008
==================================================
1) Affected Product
Juniper Netscreen Firewall
ScreenOS version 5.4.0r9.0

Written by blogo

October 3rd, 2008 at 11:40 pm

Posted in security