<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>24 Nov  2009 11:05:59 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Remote DoS condition in harbour.pl</title>
<description>Versions of harbour.pl (up to and including build 1941) are vulnerable to a remote Denial of Service attack. Spamming &amp;quot;zeroes&amp;quot; (null packets) to port</description>
<pubDate>24 Nov  2009 06:58:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70896</link>
</item><item>
<title>[USN-861-1] libvorbis vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-861-1     November 24, 2009 libvorbis vulnerabilities CVE-</description>
<pubDate>24 Nov  2009 06:31:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70892</link>
</item><item>
<title>Re: New Paper: MitM Attacks against the chipTAN comfort Online Banking System</title>
<description>Hi, Thank you for the information. MITM is used rather vaguely in this paper. Are the proposed techniques working in an MITM situation - w</description>
<pubDate>24 Nov  2009 04:57:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70890</link>
</item><item>
<title>New Paper: MitM Attacks against the chipTAN comfort Online Banking	System</title>
<description>Abstract ======== ChipTAN comfort is a new system which is supposed to securely authorise online banking transactions by means of a trusted device. It</description>
<pubDate>24 Nov  2009 03:50:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70889</link>
</item><item>
<title>Executing arbitrary PHP code on OpenX &amp;lt;= 2.8.1</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, OpenX adserver version 2.8.1 and lower is vulnerable to remote code execution. To be exploited,</description>
<pubDate>24 Nov  2009 03:02:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70888</link>
</item><item>
<title>Quick.Cart and Quick.CMS CSRF Vulnerabilities</title>
<description>Systems Affected: Quick.Cart 3.4 (other versions untested), Quick.CMS 2.4 (other versions untested) Severity: Medium Vendor: http://opensolution.org/</description>
<pubDate>23 Nov  2009 15:23:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70894</link>
</item><item>
<title>CORE-2009-0910: Autodesk Maya Script Nodes Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:43:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70887</link>
</item><item>
<title>CORE-2009-0909: Autodesk 3DS Max Application Callbacks Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:42:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70886</link>
</item><item>
<title>CORE-2009-0908: Autodesk SoftImage Scene TOC Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:41:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70885</link>
</item><item>
<title>[SECURITY] [DSA 1938-1] New php-mail packages fix insufficient input sanitising</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>22 Nov  2009 23:40:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70884</link>
</item><item>
<title>Fwd: ICMPv4/IP fuzzer prototype.</title>
<description>Hell no random.randrang -&amp;gt; randrange(_) rtfm. and yeah u&amp;#039;r welcome.  2009/11/23 Andrew Farmer &amp;lt;andfarm@gmail.com&amp;gt; On 22 Nov 2009, at 19:48, lauren</description>
<pubDate>22 Nov  2009 22:09:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70882</link>
</item><item>
<title>[Bkis-13-2009] e107 Multiple Vulnerabilities</title>
<description>[Bkis-13-2009] e107 Multiple Vulnerabilities 1. General Information e107 is a free content management system (CMS) written in PHP language and is av</description>
<pubDate>22 Nov  2009 21:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70880</link>
</item><item>
<title>ICMPv4/IP fuzzer prototype.</title>
<description>Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html Enjoy.</description>
<pubDate>22 Nov  2009 19:48:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70879</link>
</item><item>
<title>Climategate: how the MSM reported the greatest scandal in modern science - Telegraph Blogs</title>
<description>hackers providing a public service...... http://blogs.telegraph.co.uk/news/jamesdelingpole/100017451/climategate-how-the-msm-reported-the-greatest-sc</description>
<pubDate>22 Nov  2009 14:44:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70878</link>
</item><item>
<title>Millions of PDF invisibly embedded with your internal disk paths</title>
<description>Millions of PDF invisibly embedded with your internal disk paths ---------------------------------------------------------------- I found an interest</description>
<pubDate>22 Nov  2009 12:14:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70876</link>
</item><item>
<title>HITB Security Conference 2010 Dubai Call for Papers</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The Call for Papers for HITB Security Conference 2010 Dubai is now open! Talks that are more technical</description>
<pubDate>22 Nov  2009 06:13:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70875</link>
</item><item>
<title>Vulnerabilities in plugins for WordPress</title>
<description>Hello Full-Disclosure! I want to tell you about different vulnerabilities in plugins for WordPress. About some of them there were posts to Bugtraq li</description>
<pubDate>21 Nov  2009 13:25:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70874</link>
</item><item>
<title>[ MDVSA-2009:302 ] php</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>21 Nov  2009 08:08:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70872</link>
</item><item>
<title>[SECURITY] [DSA 1937-1] New gforge packages fix cross-site scripting</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>20 Nov  2009 21:30:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70873</link>
</item><item>
<title>[ MDVSA-2009:301 ] kernel</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>20 Nov  2009 16:29:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70870</link>
</item><item>
<title>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability</title>
<description>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09</description>
<pubDate>20 Nov  2009 15:15:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70869</link>
</item><item>
<title>VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -----------------------------------------------------------------------          VMware Sec</description>
<pubDate>20 Nov  2009 12:56:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70867</link>
</item><item>
<title>Pussy and the right to free speech.</title>
<description>This whole thing is ridiculous. Kurt Greenbaum is an idiot. What kind of question is that in the first place? Only and idiot would post â€œwhatâ€</description>
<pubDate>20 Nov  2009 11:10:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70866</link>
</item><item>
<title>PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>Description ------------ PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we&amp;#039;ve reported on 27 Oct</description>
<pubDate>20 Nov  2009 04:03:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70864</link>
</item><item>
<title>n3td3v / Andrew Wallace&amp;#039;s psychological profile</title>
<description>Earlier this year, a very well educated FD member posted the psychological profile of Mr. Wallace. (Found here: http://seclists.org/fulldisclosure/200</description>
<pubDate>19 Nov  2009 19:40:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70863</link>
</item><item>
<title>SecurityReason: KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz</description>
<pubDate>19 Nov  2009 16:26:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70860</link>
</item><item>
<title>SecurityReason: Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ Opera 10.01 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and sp</description>
<pubDate>19 Nov  2009 16:25:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70859</link>
</item><item>
<title>SecurityReason: K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and</description>
<pubDate>19 Nov  2009 16:23:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70858</link>
</item><item>
<title>SecurityReason: SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz an</description>
<pubDate>19 Nov  2009 16:17:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70857</link>
</item><item>
<title>Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>I smell a lawsuit coming on for our friend Greenbaum. &amp;quot;ReadWriteWeb has an article up today discussing an incident in which a school employee lost hi</description>
<pubDate>19 Nov  2009 12:38:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70852</link>
</item><item>
<title>Auto Manager admin.cgi Multiple Field XSS</title>
<description>vendor: interactivetools.com, inc., http://www.interactivetools.com/products/automanager/ product: Auto Manager version: 2.52 script: admin.cgi fields</description>
<pubDate>19 Nov  2009 00:03:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70845</link>
</item><item>
<title>AssetsSoSimple supplier_admin.php Supplier Field XSS</title>
<description>product: AssetsSoSimple version tested: 0.33 vendor URL: http://assetssosimple.sourceforge.net/ script: supplier_admin.php field: Supplier ooo BugsN</description>
<pubDate>19 Nov  2009 00:01:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70844</link>
</item><item>
<title>Foxit Reader vulnerability has been fixed</title>
<description>Hello There, This is Grace Wu from Foxit Corporation. We had noticed the Foxit Reader vulnerability posted at http://seclists.org/fulldisclosure/2009</description>
<pubDate>18 Nov  2009 23:36:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70847</link>
</item><item>
<title>[USN-860-1] Apache vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-860-1     November 19, 2009 apache2 vulnerabilities CVE-20</description>
<pubDate>18 Nov  2009 22:40:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70843</link>
</item><item>
<title>Impersonation is a against the law.</title>
<description>List, It has come to my attention that my client is being impersonated. Securityfocus slandered n3td3v in 2006 causing him to drop out of universit</description>
<pubDate>18 Nov  2009 16:20:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70842</link>
</item><item>
<title>CORE-2009-1027: IBM SolidDB invalid error code vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1    Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>18 Nov  2009 10:23:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70841</link>
</item><item>
<title>Secunia Research: RhinoSoft Serv-U TEA Decoding Buffer Overflow</title>
<description>======================================================================            Secunia Research 18/11/2009      - RhinoSoft Serv-U</description>
<pubDate>18 Nov  2009 07:49:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70840</link>
</item><item>
<title>TLS / SSLv3 vulnerability explained (DRAFT)</title>
<description>Dear List, This paper explains the vulnerability for a broader audience and summarizes the information that is currently available. The document is p</description>
<pubDate>18 Nov  2009 06:42:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70839</link>
</item><item>
<title>DEFCON London - DC4420 - NO MEETING this Thursday! 19th November 2009</title>
<description>what it says on the tin... i regret to inform you that there will be no meeting this month due to repeated let-downs with the current venue... inst</description>
<pubDate>18 Nov  2009 06:24:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70838</link>
</item><item>
<title>SUSE Security Announcement: openssl (SUSE-SA:2009:057)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________</description>
<pubDate>18 Nov  2009 00:56:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70837</link>
</item><item>
<title>[ GLSA 200911-02 ] Sun JDK/JRE: Multiple vulnerabilites</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-02 - - -</description>
<pubDate>17 Nov  2009 14:59:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70836</link>
</item><item>
<title>CORE-2009-0814: HP Openview NNM 7.53 Invalid DB Error Code vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1    Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>17 Nov  2009 14:13:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70835</link>
</item><item>
<title>[SECURITY] [DSA 1936-1] New libgd2 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>17 Nov  2009 12:52:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70833</link>
</item><item>
<title>FDSpam. EFFector 22.33: International Activists Launch New Website to Gather and Share Copyright Knowledge</title>
<description>I realised that though security isn&amp;#039;t mentioned at all -there&amp;#039;s plenty here that gets shouted about on Full Disc on off-topic threads. (Paul, Valdis,</description>
<pubDate>17 Nov  2009 11:51:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70832</link>
</item><item>
<title>The cyber security intelligence community will never be the same</title>
<description>n3td3v prepares to leave the internet after having completed work on n3td3v-0pen0wn.sh  n3td3v has had it with the games done by you jackasses in th</description>
<pubDate>17 Nov  2009 11:48:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70829</link>
</item><item>
<title>Secunia Research: Gimp PSD Image Parsing Integer Overflow Vulnerability</title>
<description>======================================================================            Secunia Research 17/11/2009    - Gimp PSD Image Parsi</description>
<pubDate>17 Nov  2009 06:05:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70828</link>
</item><item>
<title>Metasploit Framework 3.3 Released</title>
<description>We are excited to announce the immediate availability of version 3.3 of the Metasploit Framework. This release includes 446 exploits, 216 auxiliary mo</description>
<pubDate>17 Nov  2009 05:57:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70827</link>
</item><item>
<title>[SECURITY] [DSA 1935-1] New gnutls23/gnutls26 packages fix SSL certificate	verification weakness</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory D</description>
<pubDate>17 Nov  2009 05:46:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70831</link>
</item><item>
<title>iAWACS 2010 CFP</title>
<description>Second International Alternative Workshop on          Aggressive Computing and Security          iAWACS 2010: the Revelation Editi</description>
<pubDate>17 Nov  2009 01:40:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70824</link>
</item><item>
<title>Microsoft confirms first Windows 7 zero-day bug</title>
<description>http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D</description>
<pubDate>16 Nov  2009 22:00:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70822</link>
</item><item>
<title>Re: George Bush&amp;#039;s immature self-styled approach at counterterrorism is an intelligence nightmare</title>
<description>full-disclosure-request@lists.grok.org.uk wrote: &amp;gt; Send Full-Disclosure mailing list submissions to &amp;gt;  3. George Bush&amp;#039;s immature, self-styled appro</description>
<pubDate>16 Nov  2009 16:19:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70821</link>
</item><item>
<title>[ MDVSA-2009:158-2 ] pango</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>16 Nov  2009 14:34:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70820</link>
</item><item>
<title>[SECURITY] [DSA-1934-1] New apache2 packages fix several issues</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>16 Nov  2009 11:30:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70826</link>
</item><item>
<title>[ MDVSA-2009:158-1 ] pango</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>16 Nov  2009 06:33:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70819</link>
</item><item>
<title>Troopers 2010 security conference, CfP</title>
<description>Once more, it will be Troopers time.  This year, again, _everybody_ involved in the event (speakers and attendees) enjoyed themselves and could sign</description>
<pubDate>16 Nov  2009 03:43:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70818</link>
</item><item>
<title>George Bush&amp;#039;s immature, self-styled approach at counterterrorism is an intelligence nightmare</title>
<description>Greetings, This is an intelligence nightmare. Op-Ed by Andrew Wallace (antisec/bbc)  The US constitution is a well thought-out document that is me</description>
<pubDate>15 Nov  2009 11:19:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70816</link>
</item><item>
<title>[ MDVSA-2009:300 ] apache-conf</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>15 Nov  2009 10:26:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70815</link>
</item><item>
<title>Twitter &amp;quot;swine flu&amp;quot; worm</title>
<description>Hi, up to some days ago Twitter was affected by a vulnerability that allowed the propagation of a worm what we like to call &amp;quot;twitter swine flu&amp;quot;. The v</description>
<pubDate>13 Nov  2009 16:41:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70814</link>
</item><item>
<title>[ MDVSA-2009:299 ] xine-lib</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>13 Nov  2009 16:31:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70811</link>
</item><item>
<title>[ MDVSA-2009:297 ] ffmpeg</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>13 Nov  2009 16:27:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70810</link>
</item><item>
<title>1/14</title>
<description>-----BEGIN KREMLIN TEXT 3.0 MESSAGE----- /&amp;quot;&amp;quot;!!1H!@M11?G6Z=WEQ&amp;amp;X0=%#O**`OIK7P5P`IS4ACPJA@4%ID*&amp;quot;]QL6=Z6%%&amp;gt;]!%+2 J&amp;quot; ]7940N1&amp;amp;KD*)V$K!$- .2&amp;gt;B.%9EU0+]2S$$SN</description>
<pubDate>13 Nov  2009 16:17:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70834</link>
</item><item>
<title>[ MDVSA-2009:298 ] xine-lib</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>13 Nov  2009 16:05:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70808</link>
</item><item>
<title>[USN-859-1] OpenJDK vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-859-1     November 13, 2009 openjdk-6 vulnerabilities CVE-</description>
<pubDate>13 Nov  2009 10:38:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70806</link>
</item><item>
<title>OS Commerce authentication bypass</title>
<description>OS Commerce authentication bypass Description: Accessing administration pages should give a login screen to unauthenticated users, however instead,</description>
<pubDate>13 Nov  2009 08:57:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70804</link>
</item><item>
<title>[ MDVSA-2009:296 ] gimp</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>13 Nov  2009 08:16:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70803</link>
</item><item>
<title>Re: Full-Disclosure Digest, Vol 57, Issue 17</title>
<description>&amp;gt; &amp;gt; &amp;gt; ------------------------------ &amp;gt; &amp;gt; Message: 5 &amp;gt; Date: Thu, 12 Nov 2009 14:09:12 +0000 &amp;gt; From: Leandro Malaquias &amp;lt;lm.net.security@gmail.com&amp;gt; &amp;gt; Su</description>
<pubDate>13 Nov  2009 06:56:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70802</link>
</item><item>
<title>MS09-053</title>
<description>Hello, my name is Tomoki Sanaki. I remade based http://www.milw0rm.com/exploits/9559. ---------------------------------------------------------------</description>
<pubDate>13 Nov  2009 06:15:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70801</link>
</item><item>
<title>PHP 5.2.11/5.3.0 Multiple Vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ PHP 5.2.11/5.3.0 Multiple Vulnerabilities ] Author: Maksymilian Arciemowicz http://SecurityReason.co</description>
<pubDate>13 Nov  2009 04:50:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70800</link>
</item><item>
<title>JTTF/FBI informant &amp;quot;snitching&amp;quot; on security professionals in Bay Area</title>
<description>Greetings Full Disclosure, For the past few weeks I&amp;#039;ve been facing a professional dilemma. Should I out someone who at one time fellated me? Should</description>
<pubDate>12 Nov  2009 18:53:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70791</link>
</item><item>
<title>rPSA-2009-0142-2 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0142-2 Published: 2009-11-12 Updated:   2009-11-12 updated to reference CVE-2009-1891 Products:   rPath Appliance Pl</description>
<pubDate>12 Nov  2009 17:02:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70796</link>
</item><item>
<title>rPSA-2009-0145-1 samba samba-client samba-server samba-swat</title>
<description>rPath Security Advisory: 2009-0145-1 Published: 2009-11-12 Products:   rPath Appliance Platform Linux Service 1   rPath Appliance Platform Linux S</description>
<pubDate>12 Nov  2009 14:55:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70795</link>
</item><item>
<title>rPSA-2009-0144-1 apr-util</title>
<description>rPath Security Advisory: 2009-0144-1 Published: 2009-11-12 Products:   rPath Appliance Platform Linux Service 1   rPath Appliance Platform Linux S</description>
<pubDate>12 Nov  2009 14:54:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70794</link>
</item><item>
<title>rPSA-2009-0143-1 util-linux util-linux-extras</title>
<description>rPath Security Advisory: 2009-0143-1 Published: 2009-11-12 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 2 Rating: Informati</description>
<pubDate>12 Nov  2009 14:51:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70793</link>
</item><item>
<title>rPSA-2009-0142-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0142-1 Published: 2009-11-12 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 2 Rating: Major Exp</description>
<pubDate>12 Nov  2009 14:49:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70792</link>
</item><item>
<title>Cryptome posts Microsoft COFEE forensic toolkit</title>
<description>Note: This is a toolkit by Microsoft meant to be used on a thumb drive. There are many open source tools already available, this is just an all-in-</description>
<pubDate>12 Nov  2009 10:07:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70789</link>
</item><item>
<title>[USN-858-1] OpenLDAP vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-858-1     November 12, 2009 openldap2.2 vulnerability CVE-</description>
<pubDate>12 Nov  2009 06:29:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70781</link>
</item><item>
<title>Re: WordPress</title>
<description>Did not work on: Apache/2.2.8 (Ubuntu) DAV/2 PHP/5.2.4-2ubuntu5.7 with Suhosin-Patch Server -------- Original Message -------- Subject: [Full-disclos</description>
<pubDate>12 Nov  2009 06:15:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70779</link>
</item><item>
<title>Microsoft Patents the &amp;quot;sudo&amp;quot; command</title>
<description>Website: http://gizmodo.com/5402796/microsoft-patents-the-sudo-command Patent: http://patft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&amp;amp;Sect2=HITOFF&amp;amp;d=P</description>
<pubDate>12 Nov  2009 06:09:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70780</link>
</item><item>
<title>Secunia Research: Gimp BMP Image Parsing Integer Overflow Vulnerability</title>
<description>======================================================================            Secunia Research 12/11/2009    - Gimp BMP Image Pars</description>
<pubDate>12 Nov  2009 05:18:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70785</link>
</item><item>
<title>HP curiosity and vulnerability</title>
<description>Before the vulnerability.. HP buys 3Com in mega $2.7 billion deal http://www.scmagazineus.com/HP-buys-3Com-in-mega-27-billion-deal/article/157601/ H</description>
<pubDate>11 Nov  2009 15:40:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70775</link>
</item><item>
<title>[USN-853-2] Firefox and Xulrunner regression</title>
<description>=========================================================== Ubuntu Security Notice USN-853-2     November 11, 2009 firefox-3.5, xulrunner-1.9.1 r</description>
<pubDate>11 Nov  2009 09:00:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70773</link>
</item><item>
<title>WordPress &amp;lt;= 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution</title>
<description>============================================= - Release date: November 11th, 2009 - Discovered by: Dawid Golunski - Severity: Moderately High ========</description>
<pubDate>11 Nov  2009 08:47:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70776</link>
</item><item>
<title>List Charter</title>
<description>[Full-Disclosure] Mailing List Charter John Cartwright &amp;lt;johnc@grok.org.uk&amp;gt;  - Introduction &amp;amp; Purpose - This document serves as a charter for the [F</description>
<pubDate>11 Nov  2009 06:14:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70772</link>
</item><item>
<title>Windows 7 , Server 2008R2 Remote Kernel Crash</title>
<description>============================================= - Release date: November 11th, 2009 - Discovered by: Laurent Gaffié - Severity: Medium/High ============</description>
<pubDate>11 Nov  2009 02:58:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70769</link>
</item><item>
<title>UK surveillance plan to go ahead</title>
<description>The Home Office says it will push ahead with plans to ask communications firms to monitor all internet use. http://news.bbc.co.uk/2/hi/uk_news/politi</description>
<pubDate>10 Nov  2009 21:46:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70768</link>
</item><item>
<title>Why the FBI, JTTF (Joint Terrorism Task Force) and DOJ policies are destined to backfire</title>
<description>Berlin Wall: Why we aren&amp;#039;t the Stasi intelligence friendly country the FBI thinks, and why they are doomed to falter. The folly of making FBI into a</description>
<pubDate>10 Nov  2009 20:20:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70767</link>
</item><item>
<title>Spying on Americans: Obama Endorses Bush Era Warrantless Wiretapping</title>
<description>In a Court filing late Friday night, the Obama Administration attempted to dress up in new clothes its embrace of one of the worst Bush Administration</description>
<pubDate>10 Nov  2009 20:00:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70766</link>
</item><item>
<title>iDefense Security Advisory 11.10.09: Microsoft Excel FEATHEADER Record Memory Corruption Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 iDefense Security Advisory 11.10.09 http://labs.idefense.com/intelligence/vulnerabilities/ Nov 10, 2009</description>
<pubDate>10 Nov  2009 13:01:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70765</link>
</item><item>
<title>iDefense Security Advisory 11.10.09: Microsoft Word FIB Processing Stack Buffer Overflow Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 iDefense Security Advisory 11.10.09 http://labs.idefense.com/intelligence/vulnerabilities/ Nov 10, 2009</description>
<pubDate>10 Nov  2009 12:19:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70764</link>
</item><item>
<title>ZDI-09-083: Microsoft Excel Shared Feature Header Pointer Offset Memory Corruption Vulnerability</title>
<description>ZDI-09-083: Microsoft Excel Shared Feature Header Pointer Offset Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-08</description>
<pubDate>10 Nov  2009 12:16:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70763</link>
</item><item>
<title>ZDI-09-082: Microsoft Office Excel PivotTable Cache Record Parsing Memory Corruption Vulnerability</title>
<description>ZDI-09-082: Microsoft Office Excel PivotTable Cache Record Parsing Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-</description>
<pubDate>10 Nov  2009 12:16:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70762</link>
</item><item>
<title>TPTI-09-07: Microsoft Windows License Logging Service Heap Corruption Vulnerability</title>
<description>TPTI-09-07: Microsoft Windows License Logging Service Heap Corruption Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-09-07 November 10, 20</description>
<pubDate>10 Nov  2009 11:59:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70770</link>
</item><item>
<title>[USN-857-1] Qt vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-857-1     November 10, 2009 qt4-x11 vulnerabilities CVE-20</description>
<pubDate>10 Nov  2009 07:53:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70761</link>
</item><item>
<title>[USN-856-1] CUPS vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-856-1     November 10, 2009 cups, cupsys vulnerability CVE</description>
<pubDate>10 Nov  2009 07:52:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70760</link>
</item><item>
<title>[SECURITY] [DSA 1933-1] New cups packages fix cross-site scripting</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>09 Nov  2009 18:41:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70757</link>
</item><item>
<title>Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability Advisory ID: cisco-sa-20</description>
<pubDate>09 Nov  2009 09:30:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70753</link>
</item><item>
<title>[ MDVSA-2009:295 ] apache</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>08 Nov  2009 13:20:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70747</link>
</item><item>
<title>[SECURITY] [DSA 1932-1] New pidgin packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 11:47:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70746</link>
</item><item>
<title>Dark home</title>
<description>Hello participants of Full-Disclosure! After the article Dark side of bookmarks (http://websecurity.com.ua/3643/), I&#039;ll draw you attention to another</description>
<pubDate>08 Nov  2009 09:54:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70752</link>
</item><item>
<title>DoS vulnerability in Internet Explorer</title>
<description>Hello participants of Full-Disclosure! I want to warn you about Denial of Service vulnerability in Internet Explorer. Yesterday I already informed Mi</description>
<pubDate>08 Nov  2009 05:54:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70751</link>
</item>
</channel>
</rss>
