<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>http://groups.google.pl/group/mailing.unix.bugtraq</id>
  <title type="text">mailing.unix.bugtraq Google Group</title>
  <subtitle type="text">
  </subtitle>
  <link href="/group/mailing.unix.bugtraq/feed/atom_v1_0_msgs.xml" rel="self" title="mailing.unix.bugtraq feed"/>
  <updated>2010-03-17T16:54:30Z</updated>
  <generator uri="http://groups.google.pl" version="1.99">Google Groups</generator>
  <entry>
  <author>
  <name>Christopher</name>
  <email>voodu...@gmail.com</email>
  </author>
  <updated>2010-03-17T16:54:30Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/354200475462890f/c1bbf3a45fe92b1a?show_docid=c1bbf3a45fe92b1a</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/354200475462890f/c1bbf3a45fe92b1a?show_docid=c1bbf3a45fe92b1a"/>
  <title type="text">Sahana 0.6.2.2 Authentication Bypass</title>
  <summary type="html" xml:space="preserve">
  Ability to completely disable authentication via stream.php and commented &lt;br&gt; out module authentication code within it. &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://victim/&quot;&gt;[link]&lt;/a&gt;&amp;lt;sahana_path&amp;gt;/index.php?mod=ad min&amp;amp;act=acl_enable_acl &lt;br&gt; Authenticates correctly. &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://victim/&quot;&gt;[link]&lt;/a&gt;&amp;lt;sahana_path&amp;gt;/stream.php?mod=a dmin&amp;amp;act=acl_enable_acl &lt;br&gt; Does not.
  </summary>
  </entry>
  <entry>
  <author>
  <name>Secunia Research</name>
  <email>remove-v...@secunia.com</email>
  </author>
  <updated>2010-03-17T15:33:39Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/0b639ce1eeb04e80/abca8a5e6bf7c576?show_docid=abca8a5e6bf7c576</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/0b639ce1eeb04e80/abca8a5e6bf7c576?show_docid=abca8a5e6bf7c576"/>
  <title type="text">Secunia Research: Quicksilver Forums &quot;mysqldump&quot; Password Disclosure</title>
  <summary type="html" xml:space="preserve">
  ============================== ============================== ========== &lt;br&gt; Secunia Research 17/03/2010 &lt;br&gt; - Quicksilver Forums &amp;quot;mysqldump&amp;quot; Password Disclosure - &lt;br&gt; ============================== ============================== ========== &lt;br&gt; Table of Contents &lt;br&gt; Affected Software...................... .............................. 1
  </summary>
  </entry>
  <entry>
  <author>
  <name>Secunia Research</name>
  <email>remove-v...@secunia.com</email>
  </author>
  <updated>2010-03-17T15:33:56Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/80c9fabb51fe04b5/9c6a5f249ecb5f39?show_docid=9c6a5f249ecb5f39</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/80c9fabb51fe04b5/9c6a5f249ecb5f39?show_docid=9c6a5f249ecb5f39"/>
  <title type="text">Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability</title>
  <summary type="html" xml:space="preserve">
  ============================== ============================== ========== &lt;br&gt; Secunia Research 17/03/2010 &lt;br&gt; - Quicksilver Forums Cross-Site Request Forgery Vulnerability - &lt;br&gt; ============================== ============================== ========== &lt;br&gt; Table of Contents &lt;br&gt; Affected Software...................... .............................. 1
  </summary>
  </entry>
  <entry>
  <author>
  <name>Secunia Research</name>
  <email>remove-v...@secunia.com</email>
  </author>
  <updated>2010-03-17T15:33:47Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/ce680ec80b8146a3/e827ef75273de674?show_docid=e827ef75273de674</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/ce680ec80b8146a3/e827ef75273de674?show_docid=e827ef75273de674"/>
  <title type="text">Secunia Research: Quicksilver Forums Backup Information Disclosure</title>
  <summary type="html" xml:space="preserve">
  ============================== ============================== ========== &lt;br&gt; Secunia Research 17/03/2010 &lt;br&gt; - Quicksilver Forums Backup Information Disclosure - &lt;br&gt; ============================== ============================== ========== &lt;br&gt; Table of Contents &lt;br&gt; Affected Software...................... .............................. 1
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jan Schejbal</name>
  <email>jan.mailinglis...@googlemail.com</email>
  </author>
  <updated>2010-03-17T00:31:29Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/74f904d4b5e2f85a/ee88d8aa848cbebf?show_docid=ee88d8aa848cbebf</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/74f904d4b5e2f85a/ee88d8aa848cbebf?show_docid=ee88d8aa848cbebf"/>
  <title type="text">Miranda IM silent TLS failure</title>
  <summary type="html" xml:space="preserve">
  Summary: &lt;br&gt; Under certain conditions, Miranda ignores the &amp;quot;Use TLS&amp;quot; setting in &lt;br&gt; Jabber accounts and uses an unencrypted connection. &lt;br&gt; Affected: Miranda IM (instant messenger), at least versions 0.8.16, &lt;br&gt; 0.9.0 alpha build #6 Unicode and SVN rev. 11383 &lt;br&gt; Description: &lt;br&gt; If the following conditions are met: &lt;br&gt; - &amp;quot;Use TLS&amp;quot; is enabled in the jabber account settings (Network -
  </summary>
  </entry>
  <entry>
  <author>
  <name>&quot;MustLive&quot;</name>
  <email>mustl...@websecurity.com.ua</email>
  </author>
  <updated>2010-03-16T21:40:35Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/2d86651ceefbfabb/9146f33cb4923fe0?show_docid=9146f33cb4923fe0</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/2d86651ceefbfabb/9146f33cb4923fe0?show_docid=9146f33cb4923fe0"/>
  <title type="text">Vulnerabilities in VXDate for Joomla</title>
  <summary type="html" xml:space="preserve">
  Hello Bugtraq! &lt;br&gt; I want to warn you about vulnerabilities in component VXDate for Joomla. &lt;br&gt; ----------------------------- &lt;br&gt; Advisory: Vulnerabilities in VXDate for Joomla &lt;br&gt; ----------------------------- &lt;br&gt; URL: &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://websecurity.com.ua/3849/&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; ----------------------------- &lt;br&gt; Timeline: &lt;br&gt; 10.05.2009 - found the vulnerabilities.
  </summary>
  </entry>
  <entry>
  <author>
  <email>security-al...@hp.com</email>
  </author>
  <updated>2010-03-16T20:56:56Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/1218df0aed516e44/d5690bf1c64e1d9f?show_docid=d5690bf1c64e1d9f</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/1218df0aed516e44/d5690bf1c64e1d9f?show_docid=d5690bf1c64e1d9f"/>
  <title type="text">[security bulletin] HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code</title>
  <summary type="html" xml:space="preserve">
  -----BEGIN PGP SIGNED MESSAGE----- &lt;br&gt; Hash: SHA1 &lt;br&gt; SUPPORT COMMUNICATION - SECURITY BULLETIN &lt;br&gt; Document ID: c02048471 &lt;br&gt; Version: 2 &lt;br&gt; HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code &lt;br&gt; NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
  </summary>
  </entry>
  <entry>
  <author>
  <name>CORE Security Technologies Advisories</name>
  <email>advisor...@coresecurity.com</email>
  </author>
  <updated>2010-03-16T20:48:04Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/5f3d329c4e09e4f2/5119fc88154f99ac?show_docid=5119fc88154f99ac</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/5f3d329c4e09e4f2/5119fc88154f99ac?show_docid=5119fc88154f99ac"/>
  <title type="text">CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability</title>
  <summary type="html" xml:space="preserve">
  -----BEGIN PGP SIGNED MESSAGE----- &lt;br&gt; Hash: SHA1 &lt;br&gt; &lt;p&gt; Core Security Technologies - CoreLabs Advisory &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.coresecurity.com/corelabs/&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; eFront-learning PHP file inclusion vulnerability &lt;br&gt; 1. *Advisory Information* &lt;br&gt; Title: eFront-learning PHP file inclusion vulnerability &lt;br&gt; Advisory Id: CORE-2010-0311
  </summary>
  </entry>
  <entry>
  <author>
  <name>CORE Security Technologies Advisories</name>
  <email>advisor...@coresecurity.com</email>
  </author>
  <updated>2010-03-16T20:11:40Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/ff553df0d3f6fb96/5d1d47b4dbc2af17?show_docid=5d1d47b4dbc2af17</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/ff553df0d3f6fb96/5d1d47b4dbc2af17?show_docid=5d1d47b4dbc2af17"/>
  <title type="text">CORE-2009-0803: Virtual PC Hypervisor Memory Protection Vulnerability</title>
  <summary type="html" xml:space="preserve">
  -----BEGIN PGP SIGNED MESSAGE----- &lt;br&gt; Hash: SHA1 &lt;br&gt; Core Security Technologies - CoreLabs Advisory &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.coresecurity.com/corelabs/&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; Virtual PC Hypervisor Memory Protection Vulnerability &lt;br&gt; 1. *Advisory Information* &lt;br&gt; Title: Virtual PC Hypervisor Memory Protection Vulnerability &lt;br&gt; Advisory Id: CORE-2009-0803
  </summary>
  </entry>
  <entry>
  <author>
  <name>Andrzej Targosz</name>
  <email>andrzej.targ...@proidea.org.pl</email>
  </author>
  <updated>2010-03-16T01:15:28Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/1ca35b3d1e4ff128/1e93e52a7d1a380d?show_docid=1e93e52a7d1a380d</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/1ca35b3d1e4ff128/1e93e52a7d1a380d?show_docid=1e93e52a7d1a380d"/>
  <title type="text">Last Call for Papers, CONFidence 2010, 25-26May, Last Call for Papers</title>
  <summary type="html" xml:space="preserve">
  CONFidence 2010 Last Call for Papers &lt;br&gt; Calling all practitioners in the field of IT security! The 7th edition &lt;br&gt; of CONFidence 2010, is taking place in Krakow on May 25/26, 2010. &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://2010.confidence.org.pl&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; We invite all to send the proposed topic and abstracts of presentation &lt;br&gt; till the 25th of March. Please, remember that CONFidence is an open,
  </summary>
  </entry>
  <entry>
  <author>
  <name>Marc Deslauriers</name>
  <email>marc.deslauri...@canonical.com</email>
  </author>
  <updated>2010-03-16T17:34:50Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/cc38434aef8e6ea9/a98c1273f73d9ee1?show_docid=a98c1273f73d9ee1</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/cc38434aef8e6ea9/a98c1273f73d9ee1?show_docid=a98c1273f73d9ee1"/>
  <title type="text">[USN-913-1] libpng vulnerabilities</title>
  <summary type="html" xml:space="preserve">
  ============================== ============================= &lt;br&gt; Ubuntu Security Notice USN-913-1 March 16, 2010 &lt;br&gt; libpng vulnerabilities &lt;br&gt; CVE-2009-2042, CVE-2010-0205 &lt;br&gt; ============================== ============================= &lt;br&gt; A security issue affects the following Ubuntu releases: &lt;br&gt; Ubuntu 6.06 LTS
  </summary>
  </entry>
  <entry>
  <author>
  <name>ZDI Disclosures</name>
  <email>zdi-disclosu...@tippingpoint.com</email>
  </author>
  <updated>2010-03-16T16:20:09Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/3dc22ddbffe2cbda/1cb38b155080cd1c?show_docid=1cb38b155080cd1c</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/3dc22ddbffe2cbda/1cb38b155080cd1c?show_docid=1cb38b155080cd1c"/>
  <title type="text">ZDI-10-030: Apple WebKit CSS run-in Attribute Rendering Remote Code Execution Vulnerability</title>
  <summary type="html" xml:space="preserve">
  ZDI-10-030: Apple WebKit CSS run-in Attribute Rendering Remote Code Execution Vulnerability &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-10-030&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; March 16, 2010 &lt;br&gt; -- Affected Vendors: &lt;br&gt; Apple &lt;br&gt; Google &lt;br&gt; -- Affected Products: &lt;br&gt; Apple WebKit &lt;br&gt; Apple Safari &lt;br&gt; Google Chrome &lt;br&gt; -- TippingPoint(TM) IPS Customer Protection:
  </summary>
  </entry>
  <entry>
  <author>
  <name>Jeromie Jackson</name>
  <email>jero...@comsecinc.com</email>
  </author>
  <updated>2010-03-16T15:07:25Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/6c390df912aca97a/d8f60dea3c5ad5ea?show_docid=d8f60dea3c5ad5ea</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/6c390df912aca97a/d8f60dea3c5ad5ea?show_docid=d8f60dea3c5ad5ea"/>
  <title type="text">SugarCRM Stored XSS vulnerability</title>
  <summary type="html" xml:space="preserve">
  Class: Stored Cross Site Scripting (XSS) &lt;br&gt; CVE: CVE-2010-0465 &lt;br&gt; Remote: Yes &lt;br&gt; Local: Yes &lt;br&gt; Published: Jan 1, 2010 12:01AM &lt;br&gt; Timeline: Submission to Mitre: January 29, 2010 &lt;br&gt; Vendor Contact: February 18, 2010 &lt;br&gt; Vendor Response: February 19, 2010 &lt;br&gt; Patch Available: March 10, 2010 &lt;br&gt; Credit: Jeromie Jackson CISSP, CISM
  </summary>
  </entry>
  <entry>
  <author>
  <name>rPath Update Announcements</name>
  <email>announce-nore...@rpath.com</email>
  </author>
  <updated>2010-03-16T01:21:11Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/cc3205a644780faf/2184633c1a92c4ff?show_docid=2184633c1a92c4ff</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/cc3205a644780faf/2184633c1a92c4ff?show_docid=2184633c1a92c4ff"/>
  <title type="text">rPSA-2010-0018-1 bind bind-utils caching-nameserver</title>
  <summary type="html" xml:space="preserve">
  rPath Security Advisory: 2010-0018-1 &lt;br&gt; Published: 2010-03-15 &lt;br&gt; Products: &lt;br&gt; rPath Appliance Platform Linux Service 1 &lt;br&gt; rPath Appliance Platform Linux Service 2 &lt;br&gt; rPath Linux 1 &lt;br&gt; rPath Linux 2 &lt;br&gt; Rating: Severe &lt;br&gt; Exposure Level Classification: &lt;br&gt; Remote User Deterministic Vulnerability &lt;br&gt; Updated Versions:
  </summary>
  </entry>
  <entry>
  <author>
  <name>Giuseppe Iuculano</name>
  <email>iucul...@debian.org</email>
  </author>
  <updated>2010-03-15T20:14:44Z</updated>
  <id>http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/9557b862c895861a/88b77c933a65e288?show_docid=88b77c933a65e288</id>
  <link href="http://groups.google.pl/group/mailing.unix.bugtraq/browse_thread/thread/9557b862c895861a/88b77c933a65e288?show_docid=88b77c933a65e288"/>
  <title type="text">[SECURITY] [DSA 2017-1] New pulseaudio packages fix insecure temporary directory</title>
  <summary type="html" xml:space="preserve">
  -----BEGIN PGP SIGNED MESSAGE----- &lt;br&gt; Hash: SHA1 &lt;br&gt; - ------------------------------ ------------------------------ ------------ &lt;br&gt; Debian Security Advisory DSA-2017-1 secur...@debian.org &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.debian.org/security/&quot;&gt;[link]&lt;/a&gt; Giuseppe Iuculano &lt;br&gt; March 15, 2010 &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.debian.org/security/faq&quot;&gt;[link]&lt;/a&gt;
  </summary>
  </entry>
</feed>
