<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>08 Nov  2009 20:27:28 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[ MDVSA-2009:295 ] apache</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>08 Nov  2009 13:20:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70747</link>
</item><item>
<title>[SECURITY] [DSA 1932-1] New pidgin packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 11:47:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70746</link>
</item><item>
<title>[SECURITY] [DSA 1931-1] New NSPR packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 02:07:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70744</link>
</item><item>
<title>Linux 2.6.x fs/pipe.c local root exploit (CVE-2009-3547)</title>
<description>For those who were not yet aware, there is at least 3 public exploits since 11/05/2009 for CVE-2009-3547 targeting *all* linux kernels from 2.6.0 to 2</description>
<pubDate>07 Nov  2009 11:37:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70740</link>
</item><item>
<title>[SECURITY] [DSA 1930-1] New drupal6 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>06 Nov  2009 16:46:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70741</link>
</item><item>
<title>How to receive SPAM mail</title>
<description>Hi Full-disclosure I have a SPAM filter and virus firewall testing. So, I want to get the real SPAM is sent to a specific email address. What better</description>
<pubDate>06 Nov  2009 11:11:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70728</link>
</item><item>
<title>[ GLSA 200911-01 ] Horde: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-01 - - -</description>
<pubDate>06 Nov  2009 05:36:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70720</link>
</item><item>
<title>MySQL trick for SQL injection</title>
<description>Good day! I recently encountered a problem with the implementation of SQL injection.  I wanted to write a file with the code interpreter to execute</description>
<pubDate>06 Nov  2009 04:55:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70719</link>
</item><item>
<title>[ MDVSA-2009:294 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>05 Nov  2009 16:52:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70698</link>
</item><item>
<title>[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 16:51:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70716</link>
</item><item>
<title>Using Blended Browser Threats involving Chrome to steal files on your computer</title>
<description>For complete post with images, please visit http://securethoughts.com/2009/11/using-blended-browser-threats-involving-ch rome-to-steal-files-on-your-c</description>
<pubDate>05 Nov  2009 16:47:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70699</link>
</item><item>
<title>[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 14:03:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70715</link>
</item><item>
<title>SSL/TLS MiTM PoC</title>
<description>It might not work with up-to-date OpenSSL. Fixing that is left as an exercise for the reader. -- Pavel Kankovsky aka Peak             /</description>
<pubDate>05 Nov  2009 13:54:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70697</link>
</item><item>
<title>[USN-855-1] libhtml-parser-perl vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-855-1     November 05, 2009 libhtml-parser-perl vulnerabil</description>
<pubDate>05 Nov  2009 12:28:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70696</link>
</item><item>
<title>[USN-854-1] GD library vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-854-1     November 05, 2009 libgd2 vulnerabilities CVE-200</description>
<pubDate>05 Nov  2009 11:30:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70695</link>
</item><item>
<title>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability</title>
<description>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-08</description>
<pubDate>05 Nov  2009 10:08:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70712</link>
</item><item>
<title>CORE-2009-0912: Blender .blend Project Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>05 Nov  2009 09:12:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70694</link>
</item><item>
<title>[SECURITY] [DSA 1927-1] New Linux 2.6.26 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 08:21:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70714</link>
</item><item>
<title>[Bkis-12-2009] eoCMS SQL injection vulnerability - Bkis Report</title>
<description>eoCMS SQL injection vulnerability 1. General information eoCMS is an open source code software which is used to develop Internet forum (http://eocm</description>
<pubDate>04 Nov  2009 21:22:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70692</link>
</item><item>
<title>Exp1oit for Serv-U 9.0.0.5 new bug</title>
<description>hi,  I have written a piece of code to demonstrate the new serv-u bug.  Attached please find the source code for Win2k3 SP2 + DEP. Perhaps you shoul</description>
<pubDate>04 Nov  2009 19:41:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70691</link>
</item><item>
<title>CONFidence 2.0, schedule online, last time to register.</title>
<description>Dear Madame/Sir, CONFidence is the one of the most technical conference in Eastern Europe. You can find videos from the latest edition here: http://2</description>
<pubDate>04 Nov  2009 17:13:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70713</link>
</item><item>
<title>Argentinean Arnet isp webmail</title>
<description>Moderate vulnerability in argentinean ARNET isp webmail. well, there is some kind of weakened authentication on the webmail of Arnet (webmail.arnet.</description>
<pubDate>04 Nov  2009 15:00:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70718</link>
</item><item>
<title>AST-2009-009: Cross-site AJAX request vulnerability</title>
<description>Asterisk Project Security Advisory - AST-2009-009   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70673</link>
</item><item>
<title>AST-2009-008: SIP responses expose valid usernames</title>
<description>Asterisk Project Security Advisory - AST-2009-008   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70672</link>
</item><item>
<title>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability</title>
<description>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-080 November 4</description>
<pubDate>04 Nov  2009 11:50:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70711</link>
</item><item>
<title>ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability</title>
<description>ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-079 November 4, 2009 --</description>
<pubDate>04 Nov  2009 11:50:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70710</link>
</item><item>
<title>ZDI-09-078: Sun Java Runtime AWT setDifflCM Stack Overflow Vulnerability</title>
<description>ZDI-09-078: Sun Java Runtime AWT setDifflCM Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-078 November 4, 2009 -- A</description>
<pubDate>04 Nov  2009 11:50:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70709</link>
</item><item>
<title>ZDI-09-077: Sun Java Web Start Arbitrary Command Execution Vulnerability</title>
<description>ZDI-09-077: Sun Java Web Start Arbitrary Command Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-077 November 4, 2009 -- A</description>
<pubDate>04 Nov  2009 11:50:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70708</link>
</item><item>
<title>ZDI-09-076: Sun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability</title>
<description>ZDI-09-076: Sun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-076 November 4, 200</description>
<pubDate>04 Nov  2009 11:50:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70707</link>
</item><item>
<title>[SECURITY] [DSA 1926-1] New TYPO3 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>04 Nov  2009 11:33:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70675</link>
</item><item>
<title>Context IS Advisory - Autocomplete Data Theft in Mozilla Firefox</title>
<description>===============================ADVISORY=============================== Name:        Autocomplete Data Theft in Mozilla Firefox Systems Affecte</description>
<pubDate>04 Nov  2009 10:35:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70674</link>
</item><item>
<title>Interactive HTTP GET and POST Shell -- R.I.P str0ke</title>
<description>Nothing new here, but thought this might be useful to some people...Tries to maintain current working directory when you use &amp;#039;cd&amp;#039;. http://codepad.o</description>
<pubDate>04 Nov  2009 05:41:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70662</link>
</item><item>
<title>Apple ptrace panic PoC - R.I.P str0ke</title>
<description>We are mourning a good friend today. I first begun talking to str0ke when I started publishing exploit codes onto this mailing list, he would always b</description>
<pubDate>04 Nov  2009 05:19:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70660</link>
</item><item>
<title>Secunia Research: IBM Tivoli Storage Manager CAD Service Buffer Overflow</title>
<description>======================================================================            Secunia Research 04/11/2009    - IBM Tivoli Storage</description>
<pubDate>04 Nov  2009 04:35:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70663</link>
</item><item>
<title>How Prosecutors Wiretap Wall Street</title>
<description>The answer is both more mundane and more alarming. Prosecutors are using the FBI&amp;#039;s massive surveillance system, DCSNet, which stands for Digital Colle</description>
<pubDate>03 Nov  2009 17:55:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70654</link>
</item><item>
<title>Bractus SunTrack Multiple XSS</title>
<description>Vendor: Bractus (http://bract.us) Product: SunTrack (http://bract.us/demo/login.jsp) Multiple stored XSS vulnerabilities exist in the Bractus SunTrac</description>
<pubDate>03 Nov  2009 16:21:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70652</link>
</item><item>
<title>e-Courier Tracking Site Multiple Script UserGUID Parameter XSS</title>
<description>Vendor: e-Courier (http://www.ecouriersoftware.com/) Product: CMS Tracking Site Issue: Cross-Site Scripting. Description: Nearly all pages include the</description>
<pubDate>03 Nov  2009 16:20:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70653</link>
</item><item>
<title>[ MDVSA-2009:293 ] squidGuard</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>03 Nov  2009 10:31:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70650</link>
</item><item>
<title>[ MDVSA-2009:292 ] wireshark</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>03 Nov  2009 08:16:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70647</link>
</item><item>
<title>ZDI-09-075: Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability</title>
<description>ZDI-09-075: Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-075 November 2, 200</description>
<pubDate>02 Nov  2009 15:32:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70648</link>
</item><item>
<title>QuahogCon Call for Papers</title>
<description>About QuahogCon QuahogCon is a new regional conference for the hacker culture in all forms. Hardware, Software, Security, Social, Eco Hacking, Zero</description>
<pubDate>02 Nov  2009 15:24:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70649</link>
</item><item>
<title>[USN-850-3] poppler vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-850-3     November 02, 2009 poppler vulnerabilities CVE-20</description>
<pubDate>02 Nov  2009 13:46:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70646</link>
</item><item>
<title>NSOADV-2009-001: Symantec ConsoleUtilities ActiveX Control buffer overflow</title>
<description>_________________________________________ Security Advisory NSOADV-2009-001 _________________________________________ ________________________________</description>
<pubDate>02 Nov  2009 12:14:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70645</link>
</item><item>
<title>Reminder for DeepSec 2009 Conference</title>
<description>== DeepSec In-Depth Security Conference 2009 &amp;quot;TripleSec&amp;quot; == This is a reminder for the third DeepSec conference, taking place between 17th and 20th N</description>
<pubDate>01 Nov  2009 15:42:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70642</link>
</item><item>
<title>KCSEC-00000001-ServUWebClient</title>
<description>Hello list, the vulnerability named &amp;quot;RhinoSoft.com Serv-U 9.0.0.5 WebClient Remote Buffer Overflow&amp;quot; can be found at http://www.rangos.de/ServU-ADV.tx</description>
<pubDate>01 Nov  2009 14:18:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70641</link>
</item><item>
<title>[SECURITY] [DSA 1925-1] New proftpd-dfsg packages fix SSL certificate verification weakness</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>01 Nov  2009 03:08:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70637</link>
</item><item>
<title>[SECURITY] [DSA 1924-1] New mahara packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>01 Nov  2009 03:08:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70636</link>
</item><item>
<title>KC Security Services .</title>
<description>KC Security is born. ___________________ View the announcement PDF here: http://rangos.de/KC%20Security.pdf - http://www.rangos.de Everything securi</description>
<pubDate>31 Oct  2009 17:08:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70638</link>
</item><item>
<title>Dark side of bookmarks</title>
<description>Hello participants of Full-Disclosure! After my articles about different attacks via redirectors - Redirectors: the phantom menace (http://websecuri</description>
<pubDate>31 Oct  2009 13:24:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70635</link>
</item><item>
<title>[USN-853-1] Firefox and Xulrunner vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-853-1      October 31, 2009 firefox-3.0, firefox-3.5, xulr</description>
<pubDate>30 Oct  2009 20:23:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70634</link>
</item><item>
<title>CubeCart 4 Session Management Bypass</title>
<description>CubeCart 4 Session Management Bypass Release Date: 2009/10/29 Author: Bogdan Calin (bogdan [at] acunetix [dot] com) Severity: Critical Vendor Status:</description>
<pubDate>30 Oct  2009 06:07:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70632</link>
</item><item>
<title>SecurityReason: Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities ] Author: Maksymilian Arciemowic</description>
<pubDate>30 Oct  2009 05:36:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70633</link>
</item><item>
<title>CVE-2009-1979 (Oracle RDBMS)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi. This vulnerability was ranked 10.0 (for Windows) in CPUoct2009 and related to improper AUTH_SESSKE</description>
<pubDate>30 Oct  2009 03:32:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70629</link>
</item><item>
<title>SafeNet SoftRemote Local Buffer Overflow - Security Advisory - SOS-09-008</title>
<description>SafeNet SoftRemote Local Buffer Overflow - Security Advisory - SOS-09-008  Release Date.         30-Oct-2009 Vendor Notification Date.</description>
<pubDate>29 Oct  2009 23:17:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70628</link>
</item><item>
<title>[SECURITY] [DSA 1923-1] New libhtml-parser-perl packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory D</description>
<pubDate>29 Oct  2009 18:04:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70631</link>
</item><item>
<title>problems with - [USN-850-1] poppler vulnerabilities</title>
<description>Mr full-disclosure, I cannot find: http://security.ubuntu.com/ubuntu/pool/main/p/poppler/libpoppler4_0.10.5-1ubuntu2.4_i386.deb I get the following:</description>
<pubDate>29 Oct  2009 13:52:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70630</link>
</item><item>
<title>Mura CMS</title>
<description>[ONSEC-09-020] Mura CMS root folder disclosure Objective: Mura CMS &amp;lt;= 5.1 Type: Disclosure of ways Threat: Medium Date Discovered: 22.09.2009 Dat</description>
<pubDate>29 Oct  2009 13:38:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70627</link>
</item><item>
<title>[ MDVSA-2009:291 ] jetty5</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>29 Oct  2009 13:03:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70626</link>
</item><item>
<title>2wire Remote Denial of Service</title>
<description>========================================        2WIRE REMOTE DENIAL OF SERVICE     ========================================</description>
<pubDate>29 Oct  2009 10:18:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70624</link>
</item><item>
<title>[ MDVSA-2009:290 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>29 Oct  2009 08:57:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70623</link>
</item><item>
<title>[SECURITY] [DSA 1922-1] New xulrunner packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>28 Oct  2009 14:13:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70615</link>
</item><item>
<title>ZDI-09-074: Multiple Vendor Hummingbird STR Service Stack Overflow Vulnerability</title>
<description>ZDI-09-074: Multiple Vendor Hummingbird STR Service Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-074 October 28, 20</description>
<pubDate>28 Oct  2009 14:08:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70619</link>
</item><item>
<title>Mariposa Botnet C&amp;amp;C decryption plugin for wireshark</title>
<description>Hi all, we&amp;#039;ve developed a Wireshark plugin that will allow you to view obfuscated pcaps of traffic from a Mariposa infected client and actually decry</description>
<pubDate>28 Oct  2009 13:14:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70618</link>
</item><item>
<title>iDefense Security Advisory 10.28.09: Mozilla Firefox GIF Color Map Parsing Buffer Overflow Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 iDefense Security Advisory 10.28.09 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 28, 2009</description>
<pubDate>28 Oct  2009 12:42:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70614</link>
</item><item>
<title>Hijacking Opera&amp;#039;s Native Page using malicious RSS payloads</title>
<description>Hijacking Opera&amp;#039;s Native Page using malicious RSS payloads ---------------------------------------------------------------------------- --------- For</description>
<pubDate>28 Oct  2009 06:55:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70613</link>
</item><item>
<title>FRHACK 01 Epic fail keynote</title>
<description>&amp;quot;&amp;quot;&amp;quot;  &amp;gt; FRHACK: By Hackers, For Hackers! http://www.frhack.org ########################################################## FRHACK is the First Internat</description>
<pubDate>28 Oct  2009 06:30:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70622</link>
</item><item>
<title>[SECURITY] [DSA 1921-1] New expat packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>28 Oct  2009 02:39:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70620</link>
</item><item>
<title>Secunia Research: Mozilla Firefox Floating Point Memory Allocation Vulnerability</title>
<description>======================================================================            Secunia Research 28/10/2009  - Mozilla Firefox Floatin</description>
<pubDate>28 Oct  2009 01:58:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70621</link>
</item><item>
<title>[G-SEC 49-2009] McAfee generic PDF detection bypass</title>
<description>________________________________________________________________________      McAfee multiple products - Generic PDF detection bypass __________</description>
<pubDate>27 Oct  2009 15:26:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70611</link>
</item><item>
<title>[G-SEC 48-2009] F-SECURE - Generic PDF detection bypass</title>
<description>________________________________________________________________________      F-SECURE multiple products - Generic PDF detection bypass ________</description>
<pubDate>27 Oct  2009 15:23:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70610</link>
</item><item>
<title>[G-SEC 47-2009] Symantec generic PDF detection bypass</title>
<description>________________________________________________________________________        Symantec multiple products - Generic PDF bypass _______________</description>
<pubDate>27 Oct  2009 15:19:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70609</link>
</item><item>
<title>[ MDVSA-2009:289 ] kernel</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>27 Oct  2009 13:21:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70608</link>
</item><item>
<title>VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------          VMware Se</description>
<pubDate>27 Oct  2009 12:39:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70607</link>
</item><item>
<title>Invalid #PF Exception Code in VMware can result in Guest Privilege Escalation</title>
<description>Invalid #PF Exception Code in VMware can result in Guest Privilege Escalation ------------------------------------------------------------------------</description>
<pubDate>27 Oct  2009 12:15:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70606</link>
</item><item>
<title>Strange repeating probes to port 80</title>
<description>Dear list readers, for unknown reason I decided to create very lame honeypot. I took WXP, enabled IIS and forwarded ports 80 and 135 (both TCP and UDP</description>
<pubDate>27 Oct  2009 01:12:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70605</link>
</item><item>
<title>iAWACS PWN2RM Challenge Results</title>
<description>How to disable McAfee/NOD32/GDATA/Norton/AVG/Kaspersky/DrWeb ? !!!!! http://www.esiea-recherche.eu/data/pwn2rm.pdf&amp;quot;]http://www.esiea-recherche.eu/dat</description>
<pubDate>27 Oct  2009 01:08:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70600</link>
</item><item>
<title>Hash</title>
<description>For the record : /usr/bin/shasum advisory.txt 9fefeeb9d3ebf7c6822961e59ae94cfb655bcd53 advisory.txt Regards,</description>
<pubDate>26 Oct  2009 19:08:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70599</link>
</item><item>
<title>AST-2009-007: ACL not respected on SIP INVITE</title>
<description>Asterisk Project Security Advisory - AST-2009-007   +------------------------------------------------------------------------+  |   Product</description>
<pubDate>26 Oct  2009 13:26:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70598</link>
</item><item>
<title>[SECURITY] [DSA-1920-1] New nginx packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>26 Oct  2009 12:37:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70603</link>
</item><item>
<title>squidGuard 1.3 &amp;amp; 1.4 : buffer overflow</title>
<description>Advisory -------- Date      2009-10-26 Program     squidGuard URL       http://squidguard.org/ Found by    Matthieu BOUTHORS App</description>
<pubDate>26 Oct  2009 11:09:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70597</link>
</item><item>
<title>Cherokee Web Server 0.5.4 Denial Of Service</title>
<description>Disclaimer: [.This code is for Educational Purposes , I would Not be responsible for any misuse of this code] [*] Download Page : http://www.cherokee</description>
<pubDate>26 Oct  2009 06:03:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70604</link>
</item><item>
<title>[ GLSA 200910-03 ] Adobe Reader: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200910-03 - - -</description>
<pubDate>25 Oct  2009 11:56:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70596</link>
</item><item>
<title>[SECURITY] [DSA 1919-1] New smarty packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>25 Oct  2009 09:24:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70602</link>
</item><item>
<title>[SECURITY] [DSA 1918-1] New phpmyadmin packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>25 Oct  2009 05:00:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70601</link>
</item><item>
<title>Jetty 6.x and 7.x Multiple Vulnerabilities</title>
<description>Jetty 6.x and 7.x Multiple Vulnerabilities  Name       Multiple Vulnerabilities in Jetty Systems Affected Jetty 7.0.0 and earlier versions</description>
<pubDate>24 Oct  2009 15:30:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70595</link>
</item><item>
<title>[US-1984-1] JTTF (Joint Terrorism Task Force) and Fusion Center. Common Sense.</title>
<description>Ladies and gentlemen, The PATRIOT act is a bill that has been rushed through congress. Our impulse reactions to a single attack caused up to jump an</description>
<pubDate>24 Oct  2009 10:23:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70594</link>
</item><item>
<title>[SECURITY] [DSA 1917-1] New mimetex packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Oct  2009 17:19:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70593</link>
</item><item>
<title>[SECURITY] [DSA 1916-1] New kdelibs packages fix SSL certificate verification weakness</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Oct  2009 17:12:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70592</link>
</item><item>
<title>[SECURITY] [DSA 1912-2] New advi packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Oct  2009 16:50:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70591</link>
</item><item>
<title>[ MDVSA-2009:288 ] proftpd</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>23 Oct  2009 16:31:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70590</link>
</item><item>
<title>[SECURITY] [DSA 1915-1] New Linux 2.6.26 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>23 Oct  2009 08:58:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70589</link>
</item><item>
<title>H D Moore sells Metasploit: Open source project in commercial hands</title>
<description>http://risky.biz/metasploit_sold</description>
<pubDate>22 Oct  2009 16:14:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70576</link>
</item><item>
<title>Snort &amp;lt;= 2.8.5 IPV6 Remote DoS</title>
<description>============================================= - Date: October 22th, 2009 - Discovered by: Laurent Gaffié - Severity: Low =============================</description>
<pubDate>22 Oct  2009 14:56:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70575</link>
</item><item>
<title>[USN-850-2] poppler regression</title>
<description>=========================================================== Ubuntu Security Notice USN-850-2      October 22, 2009 poppler regression https://lau</description>
<pubDate>22 Oct  2009 12:38:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70573</link>
</item><item>
<title>[ GLSA 200910-02 ] Pidgin: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200910-02 - - -</description>
<pubDate>22 Oct  2009 12:09:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70572</link>
</item><item>
<title>[SECURITY] [DSA 1914-1] New mapserver packages fix serveral vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory D</description>
<pubDate>22 Oct  2009 11:33:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70580</link>
</item><item>
<title>[ MDVSA-2009:287 ] xpdf</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>22 Oct  2009 10:04:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70571</link>
</item><item>
<title>nginx null pointer dereference</title>
<description>debian:~# uname -a Linux debian 2.6.18-6-686 #1 SMP Thu Aug 20 21:56:59 UTC 2009 i686 GNU/Linux debian:~# cat /etc/issue Debian GNU/Linux 4.0 \n \l d</description>
<pubDate>22 Oct  2009 09:35:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70582</link>
</item><item>
<title>Israelis, take note</title>
<description>Hi all, this message is for the Israeli community. :o) ×&#039;×&amp;#149;××&amp;#149; ×œ×©×ª×&amp;#149;×ª ×&#039;×™×¨×&#039; ×¢× ×ž× ×›&amp;quot;×œ SANS. ×ª×©×œ×-×&amp;#149; ×œ×™ ××™×ž×™×™×œ ×× ××ª× ×¨×</description>
<pubDate>22 Oct  2009 05:45:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70581</link>
</item><item>
<title>Everfocus EDR1600 remote authentication bypass</title>
<description>************************************************************** Product: Everfocus EDR1600 Version affected: all Website: http://www.everfocus.com/ Dis</description>
<pubDate>22 Oct  2009 02:48:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70569</link>
</item>
</channel>
</rss>
