<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
<channel>
     <title>bugtraq at insecure.org</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/date.html</link>
     <description>Latest posts to bugtraq with detailed descriptions</description>
     <managingEditor>fyodor@NOSPAMinsecure.org (fyodor)</managingEditor>
     <webMaster>djeaux@NOSPAMdjeaux.com (djeaux)</webMaster>
     <generator>Scythe 2.10</generator>
     <lastBuildDate>Sat, 17 May 2008 01:50:05 PDT</lastBuildDate>
     <image>
          <url>http://www.djeaux.com/images/scraped_88x31.png</url>
          <title>bugtraq at insecure.org</title>
          <link>http://www.seclists.org/lists/bugtraq/2008/May</link>
          <description>bugtraq scraped from insecure.org</description>
     </image>
     <language>en-us</language>

<item>
     <title>[ MDVSA-2008:101 ] - Updated rdesktop packages fix vulnerabilities</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0182.html</link>
     <author>security@NOSPAMmandriva.com (security_at_mandriva.com)</author>
     <pubDate>Fri, 16 May 2008 14:33:00 -0600</pubDate>
     <description>Mandriva Linux Security Advisory MDVSA-2008:101 Package : rdesktop Date : May 16, 2008 Affected: 2007.1, 2008.0, 2008.1, Corporate 4.0 Problem Description: Several vulnerabilities were discovered in rdesktop, a Remote Desktop Protocol client. An integer underflow vulnerability allowed attackers to cause a ...</description>
</item>
 
<item>
     <title>[ MDVSA-2008:102 ] - Updated libvorbis packages fix vulnerabilities</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0181.html</link>
     <author>security@NOSPAMmandriva.com (security_at_mandriva.com)</author>
     <pubDate>Fri, 16 May 2008 14:50:00 -0600</pubDate>
     <description>Mandriva Linux Security Advisory MDVSA-2008:102 Package : libvorbis Date : May 16, 2008 Affected: 2007.1, 2008.0, 2008.1, Corporate 3.0, Corporate 4.0, Multi Network Firewall 2.0 Problem Description: Will Drewry of the Google Security Team reported several ...</description>
</item>
 
<item>
     <title>[SECURITY] [DSA 1576-2] New openssh packages fix predictable randomness</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0180.html</link>
     <author>noahm@NOSPAMdebian.org (Noah Meyerhans)</author>
     <pubDate>Fri, 16 May 2008 18:14:27 +0200</pubDate>
     <description>- Debian Security Advisory DSA-1576-2 securityatdebian&#46;org Noah Meyerhans May 16, 2008 - Package : openssh Vulnerability : predictable random number generator Problem type : remote Debian-specific: yes CVE Id(s) : CVE-2008-0166 Matt Zimmerman discovered that entries in &#47;.ssh&#47;authorizedkeys with ...</description>
</item>
 
<item>
     <title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0179.html</link>
     <author>jon+bugtraq2@NOSPAMunequivocal.co.uk (Jon Ribbens)</author>
     <pubDate>Fri, 16 May 2008 10:44:15 +0100</pubDate>
     <description>On Wed, May 14, 2008 at 05:20:52PM -0000, Tom.Donovanatacm&#46;org wrote: &gt; It appears there is little that web servers can do to thwart this, &gt; short of changing all '' characters to %2B. That seems excessive. To be fair, this is what Microsoft has recommended, explicitly for the ...</description>
</item>
 
<item>
     <title>Hack.lu 2008 CfP</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0178.html</link>
     <author>info@NOSPAMhack.lu (info)</author>
     <pubDate>Fri, 16 May 2008 08:52:48 +0200</pubDate>
     <description>Call for Papers Hack.lu 2008 The purpose of the hack.lu convention is to give an open and free playground where people can discuss the implication of new technologies in society. hack.lu is a balanced mix convention where technical and non-technical ...</description>
</item>
 
<item>
     <title>ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0177.html</link>
     <author>zdi-disclosures@NOSPAM3com.com (zdi-disclosures_at_3com.com)</author>
     <pubDate>Thu, 15 May 2008 15:25:11 -0500</pubDate>
     <description>ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability May 15, 2008 -- Affected Vendors: Symantec -- Affected Products: Symantec Altiris Deployment Solution -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against this vulnerability by Digital Vaccine protection filter ID 5936. ...</description>
</item>
 
<item>
     <title>ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0176.html</link>
     <author>zdi-disclosures@NOSPAM3com.com (zdi-disclosures_at_3com.com)</author>
     <pubDate>Thu, 15 May 2008 15:23:24 -0500</pubDate>
     <description>ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability May 15, 2008 -- Affected Vendors: Symantec -- Affected Products: Symantec Altiris Deployment Solution -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against this vulnerability by Digital Vaccine protection filter ID 5935. ...</description>
</item>
 
<item>
     <title>SunShop Version 3.5.1 Remote Blind Sql Injection</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0175.html</link>
     <author>irvian.info@NOSPAMgmail.com (irvian.info_at_gmail.com)</author>
     <pubDate>15 May 2008 16:13:52 -0000</pubDate>
     <description>#!&#47;usr&#47;bin&#47;perl -w use LWP::UserAgent; # scripts : SunShop Version 3.5.1 Remote Blind Sql Injection # scripts site : # Discovered # By : irvian # site : # email : irvian.infoatgmail&#46;com print &quot;\r\n[][]\r\n&quot;; print &quot;[]Blind SQL injection []\r\n&quot;; print &quot;[]SunShop Version 3.5.1 []\r\n&quot;; print &quot;[]code by irvian []\r\n&quot;; ...</description>
</item>
 
<item>
     <title>RE: Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities (UNCLASSIFIED)</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0174.html</link>
     <author>theresa.walker@NOSPAMdisa.mil (Walker, Theresa A CIV DISA CSD)</author>
     <pubDate>Wed, 14 May 2008 17:30:24 -0400</pubDate>
     <description>Classification: UNCLASSIFIED Caveats: NONE Please advise Theresa Original Message From: nobodyatcisco&#46;com] On Behalf Of Cisco Systems Product Security Incident Response Team Sent: Wednesday, May 14, 2008 12:15 PM To: bugtraqatsecurityfocus&#46;com Cc: psirtatcisco&#46;com Subject: Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities ...</description>
</item>
 
<item>
     <title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0173.html</link>
     <author>Tom.Donovan@NOSPAMacm.org (Tom.Donovan_at_acm.org)</author>
     <pubDate>14 May 2008 17:20:52 -0000</pubDate>
     <description>Setting the HTTP response header: Content-Type: text&#47;html; charset=iso-8859-1 or adding the tag: &lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text&#47;html; charset=iso-8859-1&quot;&gt; or even both - still does not deter IE from scanning the contents and interpreting them as UTF-7 when Encoding=Auto-Select. ...</description>
</item>
 
<item>
     <title>Aruba Mobility Controller TACACS User Authentication and Cross Site Scripting Vulnerabilities (Aruba Advisory ID: AID-051408)</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0172.html</link>
     <author>invalid@NOSPAMemail.add (Robbie Rupinder) Gill)</author>
     <pubDate>Wed, 14 May 2008 17:07:56 -0700</pubDate>
     <description>Aruba Networks Security Advisory Title: Aruba Mobility Controller TACACS User Authentication and Cross Site Scripting Vulnerabilities Aruba Advisory ID: AID-051408 Revision: 1.0 For Public Release on 05&#47;14&#47;2008 1.) TITLE: Mobility Controller TACACS User Authentication Vulnerability SUMMARY ...</description>
</item>
 
<item>
     <title>Debian generated SSH-Keys working exploit</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0171.html</link>
     <author>mm@NOSPAMdeadbeef.de (mm_at_deadbeef.de)</author>
     <pubDate>15 May 2008 05:54:29 -0000</pubDate>
     <description>Hi Securityfocus, the debian openssl issue leads that there are only 65.536 possible ssh keys generated, cause the only entropy is the pid of the process generating the key. ...</description>
</item>
 
<item>
     <title>Kostenloses Linkmanagementscript SQL Injection Vulnerabilities</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0170.html</link>
     <author>hadihadi_zedehal_2006@NOSPAMyahoo.com (hadihadi_zedehal_2006_at_yahoo.com)</author>
     <pubDate>15 May 2008 03:21:20 -0000</pubDate>
     <description># # # ...::::Kostenloses Linkmanagementscript SQL Injection Vulnerabilities ::::... # Virangar Security Team www.virangar.net Discoverd By :virangar security team(hadihadi) special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra &amp; all virangar members &amp; all hackerz greetz:to my best friend in the world hadiaryaie2004 &amp; my lovely friend arash(imm02tal) ...</description>
</item>
 
<item>
     <title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0169.html</link>
     <author>lament.hero@NOSPAMgmail.com (lament hero)</author>
     <pubDate>Thu, 15 May 2008 00:10:36 +0200</pubDate>
     <description>Hello, Please try to understand what we did here. You might be right in here: &quot;As all ISO, UTF-8 and related charsets were 7-bit clean, it's clear that Microsoft err'ed on the side of accepting UTF-7 charset for automatic detection in violation of RFC 2616.&quot; ...</description>
</item>
 
<item>
     <title>[USN-612-6] OpenVPN regression</title>
     <link>http://www.seclists.org/lists/bugtraq/2008/May/0168.html</link>
     <author>jamie@NOSPAMcanonical.com (Jamie Strandboge)</author>
     <pubDate>Wed, 14 May 2008 16:20:25 -0400</pubDate>
     <description>Ubuntu Security Notice USN-612-6 May 14, 2008 openvpn regression A security issue affects the following Ubuntu releases: Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. ...</description>
</item>
 
</channel>
</rss>
