<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bugtraq (bugtraq) Mailing List</title>
<link>http://seclists.org/#bugtraq</link>
<atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
<description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
<language>en-us</language><ttl>60</ttl>
<item><title>[ GLSA 200812-07 ] Mantis: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-07
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0021.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0021.html</guid>
<pubDate>Tue, 2 Dec 2008 18:55:03 +0100</pubDate></item>
<item><title>[ GLSA 200812-02 ] enscript: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-02
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0020.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0020.html</guid>
<pubDate>Tue, 2 Dec 2008 18:28:07 +0100</pubDate></item>
<item><title>[ GLSA 200812-04 ] lighttpd: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-04
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0019.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0019.html</guid>
<pubDate>Tue, 2 Dec 2008 18:33:06 +0100</pubDate></item>
<item><title>[ GLSA 200812-05 ] libsamplerate: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-05
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0018.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0018.html</guid>
<pubDate>Tue, 2 Dec 2008 18:40:19 +0100</pubDate></item>
<item><title>[ GLSA 200812-06 ] libxml2: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-06
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0017.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0017.html</guid>
<pubDate>Tue, 2 Dec 2008 18:42:03 +0100</pubDate></item>
<item><title>[ GLSA 200812-03 ] IPsec-Tools: racoon Denial of Service</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-03
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0016.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0016.html</guid>
<pubDate>Tue, 2 Dec 2008 18:30:56 +0100</pubDate></item>
<item><title>[ GLSA 200812-01 ] OptiPNG: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-01
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0015.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0015.html</guid>
<pubDate>Tue, 2 Dec 2008 18:25:54 +0100</pubDate></item>
<item><title>[USN-683-1] Imlib2 vulnerability</title><description>Posted by Marc Deslauriers on Dec 02&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-683-1          December 02, 2008
&lt;br /&gt;
imlib2 vulnerability
&lt;br /&gt;
CVE-2008-5187
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu releases:
&lt;br /&gt;
&lt;p&gt;Ubuntu 6.06 LTS
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0014.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0014.html</guid>
<pubDate>Tue, 02 Dec 2008 11:24:02 -0500</pubDate></item>
<item><title>Cpanel fantastico Privilege Escalation quotModSec and PHP restriction Bypassquot</title><description>Posted by l1un_at_hotmail.com on Dec 1&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Script : Cpanel 11.x
&lt;br /&gt;
bug : language.php [edite file]
&lt;br /&gt;
exploit=Cpanel fantastico Privilege Escalation &amp;quot;ModSec and PHP restriction Bypass&amp;quot;
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;safemode off , mod_security off  Disable functions :  All NONE ,access root folder 
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0013.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0013.html</guid>
<pubDate>Mon, 1 Dec 2008 18:07:03 -0700</pubDate></item>
<item><title>Re: binlogin gives root to group utmp</title><description>Posted by 0xjbrown41_at_gmail.com on Dec 1&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
I&#39;m glad you finally seemed to make the &#39;bug&#39; fixing team of Debian aware of security issues. I&#39;m just glad I personally haven&#39;t seem this much scrutiny from the security team or my faith in Debian maintainers in all areas would significantly...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0012.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0012.html</guid>
<pubDate>1 Dec 2008 17:35:20 -0000</pubDate></item>
<item><title>Dates for SyScan09</title><description>Posted by organiser_at_syscan.org on Dec 02&lt;p&gt;


&lt;p&gt;
dear all
&lt;br /&gt;
&lt;p&gt;There will be 4 SyScan&#39;09 conferences next year in 4 different exciting 
&lt;br /&gt;
countries in Asia. They are as follows:
&lt;br /&gt;
&lt;p&gt;SyScan&#39;09 Shanghai: 14th and 15th May 2009
&lt;br /&gt;
SyScan&#39;09 Hong Kong: 19th and 20th May 2009
&lt;br /&gt;
SyScan&#39;09 Singapore: 2nd and 3rd July July 2009
&lt;br /&gt;
SyScan&#39;09 Taiwan: 7th and 8th July...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0011.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0011.html</guid>
<pubDate>Tue, 02 Dec 2008 20:16:44 +0800</pubDate></item>
<item><title>[SECURITY] [DSA 1676-1] New flamethrower packages fix denial of service</title><description>Posted by dann frazier on Dec 1&lt;p&gt;


&lt;p&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1676-1                security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                           dann frazier
&lt;br /&gt;
December 01, 2008                   http://www.debian.org/security/faq
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0010.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0010.html</guid>
<pubDate>Mon, 1 Dec 2008 15:49:35 -0700</pubDate></item>
<item><title>[USN-682-1] libvorbis vulnerabilities</title><description>Posted by Marc Deslauriers on Dec 01&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-682-1          December 01, 2008
&lt;br /&gt;
libvorbis vulnerabilities
&lt;br /&gt;
CVE-2008-1419, CVE-2008-1420, CVE-2008-1423
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0009.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0009.html</guid>
<pubDate>Mon, 01 Dec 2008 12:11:59 -0500</pubDate></item>
<item><title>[USN-681-1] ImageMagick vulnerability</title><description>Posted by Marc Deslauriers on Dec 01&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-681-1          December 01, 2008
&lt;br /&gt;
imagemagick vulnerability
&lt;br /&gt;
CVE-2008-1096
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu releases:
&lt;br /&gt;
&lt;p&gt;Ubuntu 6.06 LTS...</description>
<link>http://seclists.org/bugtraq/2008/Dec/0008.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0008.html</guid>
<pubDate>Mon, 01 Dec 2008 12:11:08 -0500</pubDate></item>
<item><title>[BMSA 2008-09] Two buffer overflow vulnerabilities in Rumpus v6.0</title><description>Posted by Nam Nguyen on Dec 1&lt;p&gt;


&lt;p&gt;
BLUE MOON SECURITY ADVISORY 2008-09
&lt;br /&gt;
===================================
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;:Title: Two buffer overflows in Maxum Rumpus
&lt;br /&gt;
:Severity: Critical
&lt;br /&gt;
:Reporter: Blue Moon Consulting
&lt;br /&gt;
:Products: Maxum Rumpus v6.0
&lt;br /&gt;
:Fixed in: 6.0.1
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;Description
&lt;br /&gt;
-----------
&lt;br /&gt;
&lt;p&gt;Rumpus turns any Mac into a file transfer server....</description>
<link>http://seclists.org/bugtraq/2008/Dec/0007.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2008/Dec/0007.html</guid>
<pubDate>Mon, 1 Dec 2008 23:56:19 +0700</pubDate></item>
</channel></rss>