<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>08 Nov  2009 17:46:10 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[ MDVSA-2009:295 ] apache</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>08 Nov  2009 13:20:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70747</link>
</item><item>
<title>[SECURITY] [DSA 1932-1] New pidgin packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 11:47:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70746</link>
</item><item>
<title>[SECURITY] [DSA 1931-1] New NSPR packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 02:07:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70744</link>
</item><item>
<title>Linux 2.6.x fs/pipe.c local root exploit (CVE-2009-3547)</title>
<description>For those who were not yet aware, there is at least 3 public exploits since 11/05/2009 for CVE-2009-3547 targeting *all* linux kernels from 2.6.0 to 2</description>
<pubDate>07 Nov  2009 11:37:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70740</link>
</item><item>
<title>[SECURITY] [DSA 1930-1] New drupal6 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>06 Nov  2009 16:46:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70741</link>
</item><item>
<title>How to receive SPAM mail</title>
<description>Hi Full-disclosure I have a SPAM filter and virus firewall testing. So, I want to get the real SPAM is sent to a specific email address. What better</description>
<pubDate>06 Nov  2009 11:11:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70728</link>
</item><item>
<title>[ GLSA 200911-01 ] Horde: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-01 - - -</description>
<pubDate>06 Nov  2009 05:36:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70720</link>
</item><item>
<title>MySQL trick for SQL injection</title>
<description>Good day! I recently encountered a problem with the implementation of SQL injection.  I wanted to write a file with the code interpreter to execute</description>
<pubDate>06 Nov  2009 04:55:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70719</link>
</item><item>
<title>[ MDVSA-2009:294 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>05 Nov  2009 16:52:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70698</link>
</item><item>
<title>[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 16:51:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70716</link>
</item><item>
<title>Using Blended Browser Threats involving Chrome to steal files on your computer</title>
<description>For complete post with images, please visit http://securethoughts.com/2009/11/using-blended-browser-threats-involving-ch rome-to-steal-files-on-your-c</description>
<pubDate>05 Nov  2009 16:47:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70699</link>
</item><item>
<title>[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 14:03:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70715</link>
</item><item>
<title>SSL/TLS MiTM PoC</title>
<description>It might not work with up-to-date OpenSSL. Fixing that is left as an exercise for the reader. -- Pavel Kankovsky aka Peak             /</description>
<pubDate>05 Nov  2009 13:54:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70697</link>
</item><item>
<title>[USN-855-1] libhtml-parser-perl vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-855-1     November 05, 2009 libhtml-parser-perl vulnerabil</description>
<pubDate>05 Nov  2009 12:28:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70696</link>
</item><item>
<title>[USN-854-1] GD library vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-854-1     November 05, 2009 libgd2 vulnerabilities CVE-200</description>
<pubDate>05 Nov  2009 11:30:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70695</link>
</item><item>
<title>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability</title>
<description>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-08</description>
<pubDate>05 Nov  2009 10:08:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70712</link>
</item><item>
<title>CORE-2009-0912: Blender .blend Project Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>05 Nov  2009 09:12:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70694</link>
</item><item>
<title>[SECURITY] [DSA 1927-1] New Linux 2.6.26 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 08:21:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70714</link>
</item><item>
<title>[Bkis-12-2009] eoCMS SQL injection vulnerability - Bkis Report</title>
<description>eoCMS SQL injection vulnerability 1. General information eoCMS is an open source code software which is used to develop Internet forum (http://eocm</description>
<pubDate>04 Nov  2009 21:22:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70692</link>
</item><item>
<title>Exp1oit for Serv-U 9.0.0.5 new bug</title>
<description>hi,  I have written a piece of code to demonstrate the new serv-u bug.  Attached please find the source code for Win2k3 SP2 + DEP. Perhaps you shoul</description>
<pubDate>04 Nov  2009 19:41:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70691</link>
</item><item>
<title>CONFidence 2.0, schedule online, last time to register.</title>
<description>Dear Madame/Sir, CONFidence is the one of the most technical conference in Eastern Europe. You can find videos from the latest edition here: http://2</description>
<pubDate>04 Nov  2009 17:13:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70713</link>
</item><item>
<title>Argentinean Arnet isp webmail</title>
<description>Moderate vulnerability in argentinean ARNET isp webmail. well, there is some kind of weakened authentication on the webmail of Arnet (webmail.arnet.</description>
<pubDate>04 Nov  2009 15:00:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70718</link>
</item><item>
<title>AST-2009-009: Cross-site AJAX request vulnerability</title>
<description>Asterisk Project Security Advisory - AST-2009-009   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70673</link>
</item><item>
<title>AST-2009-008: SIP responses expose valid usernames</title>
<description>Asterisk Project Security Advisory - AST-2009-008   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70672</link>
</item><item>
<title>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability</title>
<description>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-080 November 4</description>
<pubDate>04 Nov  2009 11:50:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70711</link>
</item>
</channel>
</rss>
