[ISN] Secunia Weekly Summary

From: InfoSec News (isnat_private)
Date: Thu Jun 26 2003 - 23:37:01 PDT

  • Next message: InfoSec News: "[ISN] Ottawa aiming to thwart cyber-terrorists"

    ===========================================================================
    
                        The Secunia Weekly Advisory Summary
                              2003-06-19 - 2003-06-26
    
                             This week : 45 advisories
    
    ===========================================================================
    
    Are you confident that your environment is secure?
    
    Really Secure?
    
    or have you missed one patch!
    
    Spend 2 minutes and get your security level documented via The Secunia
    Vulnerability Scanner.
    
    https://testzone.secunia.com/online_vulnerability_scanner/
    
    ===========================================================================
    
    ============
     2003-06-26
    ============
    
    BRS WebWeaver Error Page Cross-Site Scripting Vulnerability
    Less critical
    http://www.secunia.com/advisories/9123/
    
     -- 
    
    Conectiva update for ethereal
    Moderately critical
    http://www.secunia.com/advisories/9122/
    
     -- 
    
    Gentoo update for ethereal
    Moderately critical
    http://www.secunia.com/advisories/9121/
    
     -- 
    
    Gentoo update for xpdf
    Moderately critical
    http://www.secunia.com/advisories/9119/
    
     -- 
    
    Gentoo update for acroread
    Moderately critical
    http://www.secunia.com/advisories/9118/
    
     -- 
    
    Red Hat update for ypserv
    Less critical
    http://www.secunia.com/advisories/9117/
    
     -- 
    
    Red Hat update for XFree
    Moderately critical
    http://www.secunia.com/advisories/9116/
    
    
    ============
     2003-06-25
    ============
    
    Microsoft Windows Media Services Remote System Access
    Highly critical
    http://www.secunia.com/advisories/9115/
    
     -- 
    
    Microsoft Windows Media Player ActiveX Media Library Manipulation
    Less critical
    http://www.secunia.com/advisories/9114/
    
     -- 
    
    Internet Explorer Horizontal Rule Buffer Overflow Vulnerability
    Highly critical
    http://www.secunia.com/advisories/9113/
    
     -- 
    
    ypserv Denial of Service Vulnerability
    Less critical
    http://www.secunia.com/advisories/9112/
    
     -- 
    
    PerlEdit Denial of Service Vulnerability
    Less critical
    http://www.secunia.com/advisories/9111/
    
     -- 
    
    InterForum Multiple Vulnerabilities
    Moderately critical
    http://www.secunia.com/advisories/9110/
    
     -- 
    
    GKrellM Buffer Overflow Vulnerability
    Moderately critical
    http://www.secunia.com/advisories/9109/
    
     -- 
    
    WebJeff-Filemanager Directory Traversal
    Moderately critical
    http://www.secunia.com/advisories/9108/
    
     -- 
    
    zenTrack Directory Traversal
    Moderately critical
    http://www.secunia.com/advisories/9107/
    
     -- 
    
    GuestBookHost Cross-Site Scripting Vulnerability
    Less critical
    http://www.secunia.com/advisories/9106/
    
     -- 
    
    WebAdmin USER Parameter Buffer Overflow Vulnerability
    Highly critical
    http://www.secunia.com/advisories/9105/
    
     -- 
    
    SGI IRIX inetd Denial of Service Vulnerability
    Less critical
    http://www.secunia.com/advisories/9104/
    
    
    ============
     2003-06-24
    ============
    
    Sun Cobalt update for PPTP
    Highly critical
    http://www.secunia.com/advisories/9102/
    
     -- 
    
    iWeb Mini Web Server URL Encoding Directory Traversal
    Moderately critical
    http://www.secunia.com/advisories/9101/
    
     -- 
    
    elm Privilege Escalation
    Not critical
    http://www.secunia.com/advisories/9100/
    
     -- 
    
    Sun Linux update for kernel
    Moderately critical
    http://www.secunia.com/advisories/9099/
    
     -- 
    
    Mandrake update for Ethereal
    Moderately critical
    http://www.secunia.com/advisories/9098/
    
    
    ============
     2003-06-23
    ============
    
    NGC Active MailServer 2002 Denial of Service
    Moderately critical
    http://www.secunia.com/advisories/9097/
    
     -- 
    
    GNATS Privilege Escalation
    Less critical
    http://www.secunia.com/advisories/9096/
    
     -- 
    
    IBM OS/390 Multiple Vulnerabilities
    Highly critical
    http://www.secunia.com/advisories/9095/
    
     -- 
    
    Red Hat update for Netscape
    Moderately critical
    http://www.secunia.com/advisories/9094/
    
     -- 
    
    osh Privilege Escalation
    Less critical
    http://www.secunia.com/advisories/9093/
    
     -- 
    
    sdfingerd Privilege Escalation
    Less critical
    http://www.secunia.com/advisories/9092/
    
     -- 
    
    Symantec Security Check ActiveX Remotely Exploitable Buffer Overflow
    Moderately critical
    http://www.secunia.com/advisories/9091/
    
     -- 
    
    phpBB SQL Injection
    Moderately critical
    http://www.secunia.com/advisories/9090/
    
     -- 
    
    pMachine Cross Site Scripting
    Less critical
    http://www.secunia.com/advisories/9087/
    
    
    ============
     2003-06-20
    ============
    
    ARMIDA Long HTTP Request Denial of Service Vulnerability
    Less critical
    http://www.secunia.com/advisories/9089/
    
     -- 
    
    Sun Solaris Database Function Privilege Escalation Vulnerabilities
    Less critical
    http://www.secunia.com/advisories/9088/
    
     -- 
    
    Eldav Insecure Temporary File Creation Vulnerability
    Less critical
    http://www.secunia.com/advisories/9086/
    
     -- 
    
    Orville Write Environment Variable Privilege Escalation Vulnerability
    Less critical
    http://www.secunia.com/advisories/9085/
    
     -- 
    
    Red Hat update for kernel
    Moderately critical
    http://www.secunia.com/advisories/9084/
    
     -- 
    
    Power Server Multiple Vulnerabilities
    Moderately critical
    http://www.secunia.com/advisories/9083/
    
     -- 
    
    XBlockOut Multiple Privilege Escalation Vulnerabilities
    Not critical
    http://www.secunia.com/advisories/9082/
    
     -- 
    
    HP-UX tftpd Denial of Service
    Less critical
    http://www.secunia.com/advisories/9081/
    
     -- 
    
    webfs Request-URI Buffer Overflow Vulnerability
    Highly critical
    http://www.secunia.com/advisories/9080/
    
     -- 
    
    SurfControl Web Filter for Microsoft ISA Directory Traversal
    Less critical
    http://www.secunia.com/advisories/9079/
    
    
    ============
     2003-06-19
    ============
    
    ProFTPD mod_sql SQL Injection
    Moderately critical
    http://www.secunia.com/advisories/9078/
    
     -- 
    
    Kerio MailServer Buffer Overflows and Cross Site Scripting
    Highly critical
    http://www.secunia.com/advisories/9077/
    
    
    ===========================================================================
    
    Secunia recommends that you verify all advisories you receive, by clicking
    the link.
    Secunia NEVER sends attached files with advisories.
    Secunia does not advise people to install third party patches, only use
    those supplied by the vendor.
    
    Contact details:
    Web	: http://www.secunia.com/
    E-mail	: supportat_private
    Tel	: +44 (0) 20 7016 2693
    Fax	: +44 (0) 20 7637 0419
    
    ===========================================================================
    
    
    
    -
    ISN is currently hosted by Attrition.org
    
    To unsubscribe email majordomoat_private with 'unsubscribe isn'
    in the BODY of the mail.
    



    This archive was generated by hypermail 2b30 : Fri Jun 27 2003 - 01:38:01 PDT