oss-security November 2011 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: By Date

oss-security By Date

SubjectAuthorDate
Re: [oss-security] XSSer v1.6 -beta- aka "Grey Swarm!" released.Henri Salo
Re: [oss-security] XSSer v1.6 -beta- aka "Grey Swarm!" released.Kurt Seifried
Re: [oss-security] XSSer v1.6 -beta- aka "Grey Swarm!" released.Solar Designer
[oss-security] XSSer v1.6 -beta- aka "Grey Swarm!" released.psy
Re: [oss-security] CVE id request: ffmpegKurt Seifried
Re: [oss-security] CVE id request: ffmpegKurt Seifried
Re: [oss-security] CVE request: Proc::ProcessTable perl moduleKurt Seifried
[oss-security] CVE request: Proc::ProcessTable perl moduleMoritz Muehlenhoff
[oss-security] CVE id request: ffmpegNico Golde
Re: [oss-security] CVE Request: lighttpd/mod_auth out-of-bounds read due to signedness errorKurt Seifried
Re: [oss-security] CVE request: mediawiki before 1.17.1Kurt Seifried
Re: [oss-security] Fwd: Bug script install slackwareSolar Designer
[oss-security] Re: Fwd: Bug script install slackwareRaphael Bastos
Re: [oss-security] Fwd: Bug script install slackwareRaphael Bastos
[oss-security] CVE Request: lighttpd/mod_auth out-of-bounds read due to signedness errorStefan Bühler
[oss-security] Re: Fwd: Bug script install slackwarePatrick J. Volkerding
[oss-security] CVE request: mediawiki before 1.17.1Hanno Böck
Re: [oss-security] Fwd: Bug script install slackwareSolar Designer
Re: [oss-security] Fwd: Bug script install slackwareKurt Seifried
[oss-security] Fwd: Bug script install slackwareRaphael Bastos
Re: [oss-security] CVE request: includeViewParameters re-evaluates param/model values as EL expressions on Mojarra/MyFacesKurt Seifried
[oss-security] CVE request: includeViewParameters re-evaluates param/model values as EL expressions on Mojarra/MyFacesDavid Jorm
[oss-security] CVE assigned for gdb: arbitrary code execution via .debug_gdb_scriptsKurt Seifried
Re: [oss-security] linux-distros Slackware membershipSolar Designer
Re: [oss-security] CVE Request -- ClearSilver (neo_cgi) -- Format string flaw by processing CGI error messages in Python moduleKurt Seifried
Re: [oss-security] CVE Request -- python-celery / Celery v2.4 -- Privilege escalation due improper sanitization of --uid and --gid arguments in certain tools (CELERYSA-0001Kurt Seifried
[oss-security] linux-distros Slackware membershipPatrick J. Volkerding
Re: [oss-security] non-Linux advance notification listAlex Legler
Re: [oss-security] non-Linux advance notification listMichael Harrison
[oss-security] CVE Request -- python-celery / Celery v2.4 -- Privilege escalation due improper sanitization of --uid and --gid arguments in certain tools (CELERYSA-0001Jan Lieskovsky
Re: [oss-security] non-Linux advance notification listSolar Designer
Re: [oss-security] non-Linux advance notification listSolar Designer
Re: [oss-security] non-Linux advance notification listMichael Harrison
[oss-security] Re: CVE Request -- ClearSilver (neo_cgi) -- Format string flaw by processing CGI error messages in Python moduleColin Watson
[oss-security] CVE Request -- ClearSilver (neo_cgi) -- Format string flaw by processing CGI error messages in Python moduleJan Lieskovsky
Re: [oss-security] non-Linux advance notification listSolar Designer
Re: [oss-security] non-Linux advance notification listJoost Hoogendoorn
Re: [oss-security] non-Linux advance notification listSolar Designer
Re: [oss-security] CVE request: ffmpeg before 0.7.8 and 0.8.7 2 buffer overflows and out-of-bounds readKurt Seifried
Re: [oss-security] CVE Request -- yaws -- Directory traversal flawKurt Seifried
[oss-security] Re: CVE Request -- yaws -- Directory traversal flawRob Keith
[oss-security] CVE Request -- yaws -- Directory traversal flawJan Lieskovsky
Re: [oss-security] CVE Request: colord sql injectionsKurt Seifried
Re: [oss-security] CVE Request: colord sql injectionsLudwig Nussel
Re: [oss-security] CVE Request: colord sql injectionsJan Lieskovsky
[oss-security] CVE Request: colord sql injectionsLudwig Nussel
Re: [oss-security] CVE request -- kernel: kvm: device assignment DoSKurt Seifried
[oss-security] CVE request -- kernel: kvm: device assignment DoSPetr Matousek
Re: [oss-security] Re: Please REJECT CVE-2011-4112Petr Matousek
[oss-security] Re: Please REJECT CVE-2011-4112Tavis Ormandy
[oss-security] Please REJECT CVE-2011-4112Petr Matousek
Re: [oss-security] CVE request: ffmpeg before 0.7.8 and 0.8.7 2 buffer overflows and out-of-bounds readHanno Böck
[oss-security] CVE-2011-4324 kernel: nfsv4: mknod(2) DoSEugene Teo
Re: [oss-security] CVE Request -- 1) Namazu v2.0.21: XSS flaw by processing HTTP cookies 2) Namazu v2.0.20: Stack-based buffer overflow by replacing blank "uri" field valueKurt Seifried
Re: [oss-security] CVE request: ffmpeg before 0.7.8 and 0.8.7 2 buffer overflows and out-of-bounds readKurt Seifried
Re: [oss-security] CVE request: jenkinsKurt Seifried
[oss-security] CVE request: jenkinsJamie Strandboge
[oss-security] CVE request: ffmpeg before 0.7.8 and 0.8.7 2 buffer overflows and out-of-bounds readHanno Böck
[oss-security] Typo in description of CVE-2011-2708 and CVE-2011-4331? [was: Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3 - CVE-2011-2710 / CVE-2011-2708 issue]Jan Lieskovsky
[oss-security] CVE Request -- 1) Namazu v2.0.21: XSS flaw by processing HTTP cookies 2) Namazu v2.0.20: Stack-based buffer overflow by replacing blank "uri" field valueJan Lieskovsky
Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3 - CVE-2011-2710 / CVE-2011-2708 issueSteven M. Christey
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedGuido Berhoerster
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedMarc Deslauriers
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedYves-Alexis Perez
Re: [oss-security] Fwd: Wordpress plugin BackWPup Remote and Local Code Execution Vulnerability - SOS-11-003Kurt Seifried
Re: [oss-security] CVE-request: Symphony CMS Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (NS-11-008)Kurt Seifried
[oss-security] CVE-request: Symphony CMS Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (NS-11-008)Henri Salo
[oss-security] Fwd: Wordpress plugin BackWPup Remote and Local Code Execution Vulnerability - SOS-11-003Henri Salo
Re: [oss-security] CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key typeKurt Seifried
Re: [oss-security] CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key typeEugene Teo
Re: [oss-security] Did this ArchLinux/shaman thing ever get a CVE?Kurt Seifried
Re: [oss-security] CVE-request: XSS in Tiki Wiki CMS Groupware (HTB23027)Kurt Seifried
Re: [oss-security] CVE-request: Contao 2.10.1 Cross-site scripting vulnerabilityKurt Seifried
[oss-security] CVE-request: Contao 2.10.1 Cross-site scripting vulnerabilityHenri Salo
Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3Kurt Seifried
Re: [oss-security] CVE-request: LabWiki <= 1.1 Multiple VulnerabilitiesKurt Seifried
Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3 - CVE-2011-2710 / CVE-2011-2708 issueKurt Seifried
Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3Henri Salo
Re: [oss-security] CVE-request: LabWiki <= 1.1 Multiple VulnerabilitiesHenri Salo
[oss-security] CVE-request: XSS in Tiki Wiki CMS Groupware (HTB23027)Henri Salo
Re: [oss-security] CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key typeKurt Seifried
Re: [oss-security] CVE-request: LabWiki <= 1.1 Multiple VulnerabilitiesKurt Seifried
Re: [oss-security] Fwd: XSS vulnerability in Joomla 1.6.3Kurt Seifried
Re: [oss-security] CVE request: drupal before 7.5 access bypassKurt Seifried
[oss-security] CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key typePetr Matousek
[oss-security] Fwd: XSS vulnerability in Joomla 1.6.3Henri Salo
Re: [oss-security] CVE request: drupal before 7.5 access bypassMoritz Muehlenhoff
[oss-security] CVE-request: LabWiki <= 1.1 Multiple VulnerabilitiesHenri Salo
Re: [oss-security] kernel: hfs: add sanity check for file name lengthKurt Seifried
Fwd: [oss-security] Fwd: Multiple Cross-Site-Scripting vulnerabilities in Dolibarr 3.1.0Kurt Seifried
Re: [oss-security] CVE Request (minor) -- gnash -- Unsafe management of HTTP cookiesKurt Seifried
Re: [oss-security] CVE Request: openssh 5.8p2Kurt Seifried
Re: [oss-security] CVE Request -- kernel: wrong headroom check in udp6_ufo_fragment()Kurt Seifried
[oss-security] CVE Request -- kernel: wrong headroom check in udp6_ufo_fragment()Petr Matousek
[oss-security] CVE Request: openssh 5.8p2Marcus Meissner
[oss-security] CVE Request (minor) -- gnash -- Unsafe management of HTTP cookiesJan Lieskovsky
[oss-security] Fwd: Multiple Cross-Site-Scripting vulnerabilities in Dolibarr 3.1.0Henri Salo
[oss-security] kernel: hfs: add sanity check for file name lengthEugene Teo
[oss-security] CVE-2011-4112 kernel: null ptr deref at dev_queue_xmit+0x35/0x4d0Eugene Teo
Re: [oss-security] CVE request: drupal before 7.5 access bypassKurt Seifried
Re: [oss-security] CVE request: websitebaker 2.8.1 and earlier: authentication error in backup moduleKurt Seifried
Re: [oss-security] CVE request: joomla 1.5 before 1.5.25 password change vulnerabilityKurt Seifried
[oss-security] CVE request: drupal before 7.5 access bypassHanno Böck
[oss-security] CVE request: websitebaker 2.8.1 and earlier: authentication error in backup moduleHanno Böck
[oss-security] CVE request: joomla 1.5 before 1.5.25 password change vulnerabilityHanno Böck
Re: [oss-security] closed-list membership transitionSolar Designer
Re: [oss-security] CVE request: ejabberd before 2.1.9Kurt Seifried
[oss-security] CVE request: ejabberd before 2.1.9Hanno Böck
Re: [oss-security] CVE Request -- Ruby on Rails / rubygem-actionpack -- XSS in the 'translate' helper methodKurt Seifried
Re: [oss-security] CVE Request -- Dovecot -- Validate certificate's CN against requested remote server hostname when proxyingKurt Seifried
[oss-security] CVE Request -- Ruby on Rails / rubygem-actionpack -- XSS in the 'translate' helper methodJan Lieskovsky
[oss-security] Re: CVE Request -- Dovecot -- Validate certificate's CN against requested remote server hostname when proxyingTimo Sirainen
[oss-security] CVE Request -- Dovecot -- Validate certificate's CN against requested remote server hostname when proxyingJan Lieskovsky
Re: [oss-security] non-Linux advance notification listTim Zingelman
[oss-security] non-Linux advance notification listSolar Designer
[oss-security] linux-distros list setup updateSolar Designer
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cSolar Designer
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cSolar Designer
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cVincent Danen
Re: [oss-security] CVE Request: nginx resolver heap overflowKurt Seifried
Re: [oss-security] CVE Request: nginx resolver heap overflowKurt Seifried
[oss-security] CVE Request: nginx resolver heap overflowBen Hawkes
Re: [oss-security] glibc crypt(3), crypt_r(3), PHP crypt() may use alloca()Henri Salo
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cThe Fungi
Re: [oss-security] glibc crypt(3), crypt_r(3), PHP crypt() may use alloca()Steve Grubb
Re: [oss-security] glibc crypt(3), crypt_r(3), PHP crypt() may use alloca()Solar Designer
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cSolar Designer
Re: [oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cSolar Designer
Re: [oss-security] CVE Request: openid4java not properly verifying the signature of Attribute Exchange (AX) informationKurt Seifried
[oss-security] CVE-2011-4313: BIND 9 Resolver crashes after logging an error in query.cSolar Designer
[oss-security] CVE Request: openid4java not properly verifying the signature of Attribute Exchange (AX) informationDavid Jorm
Re: [oss-security] CVE-2011-3368 suggested patch incomplete for apache2 < 2.2.18Kurt Seifried
Re: [oss-security] CVE-2011-3368 suggested patch incomplete for apache2 < 2.2.18Vincent Danen
Re: [oss-security] weird crypt-sha* in DragonFly BSDSolar Designer
Re: [oss-security] CVE Request -- ReviewBoard v1.5.7 && v1.6.3 -- XSS in the commenting system (diff viewer and screenshot pages components)Kurt Seifried
[oss-security] CVE Request -- ReviewBoard v1.5.7 && v1.6.3 -- XSS in the commenting system (diff viewer and screenshot pages components)Jan Lieskovsky
Re: [oss-security] OpenBSD bcrypt error returnSolar Designer
Re: [oss-security] *BSD's DES-based crypt(3) treats all invalid salt chars as '.'Solar Designer
[oss-security] *BSD's DES-based crypt(3) treats all invalid salt chars as '.'Solar Designer
Re: [oss-security] glibc crypt(3), crypt_r(3), PHP crypt() may use alloca()Solar Designer
[oss-security] OpenBSD bcrypt error returnSolar Designer
[oss-security] weird crypt-sha* in DragonFly BSDSolar Designer
[oss-security] glibc crypt(3), crypt_r(3), PHP crypt() may use alloca()Solar Designer
Re: [oss-security] CVE Request -- Squid v3.1.16 -- Invalid free by processing CNAME DNS record pointing to another CNAME record pointing to an empty A-recordSteven M. Christey
[oss-security] Arch Linux Shaman issueKurt Seifried
[oss-security] Did this ArchLinux/shaman thing ever get a CVE?Kurt Seifried
Re: [oss-security] CVE request: ResourceSpace before 4.2.2833 insufficient access checkKurt Seifried
Re: [oss-security] CVE request: cmsmadesimple before 1.9.4.3 - remote database corruptionKurt Seifried
Re: [oss-security] Fwd: DSA 2338-1 moodle security updateKurt Seifried
Re: [oss-security] CVE Request -- kernel: jbd/jbd2: invalid value of first log block leads to oopsKurt Seifried
Re: [oss-security] CVE Request -- kernel: nfs4_getfacl decoding kernel oopsKurt Seifried
[oss-security] CVE request: ResourceSpace before 4.2.2833 insufficient access checkHanno Böck
[oss-security] CVE request: cmsmadesimple before 1.9.4.3 - remote database corruptionHanno Böck
Re: [oss-security] CVE Request -- kernel: nfs4_getfacl decoding kernel oopsKurt Seifried
Re: [oss-security] CVE Request -- kernel: nfs4_getfacl decoding kernel oopsKurt Seifried
[oss-security] CVE Request -- kernel: jbd/jbd2: invalid value of first log block leads to oopsPetr Matousek
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedMarc Deslauriers
[oss-security] CVE Request -- kernel: nfs4_getfacl decoding kernel oopsPetr Matousek
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedJohn Haxby
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedGuido Berhoerster
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedRobert Ancell
Re: [oss-security] CVE Request -- ProFTPD -- Response pool use-after-free flaw (ZDI-CAN-1420)Kurt Seifried
[oss-security] CVE Request -- ProFTPD -- Response pool use-after-free flaw (ZDI-CAN-1420)Jan Lieskovsky
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedGuido Berhoerster
Re: [oss-security] Re: CVE request: Android: vold stack buffer overflowNick Kralevich
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedMarc Deslauriers
Re: [oss-security] CVE Request -- libsocialweb -- Untrusted connection opened to Twitter social service without user's approval upon service start via dbusKurt Seifried
Re: [oss-security] CVE request: gnutls possible DoS (GNUTLS-SA-2011-2)Kurt Seifried
[oss-security] CVE Request -- libsocialweb -- Untrusted connection opened to Twitter social service without user's approval upon service start via dbusJan Lieskovsky
[oss-security] CVE request: gnutls possible DoS (GNUTLS-SA-2011-2)Vincent Danen
Re: [oss-security] CVE request: kernel: multiple flaws allowing to sniff keystrokes timingsEugene Teo
Re: [oss-security] Re: CVE request for CalibreKurt Seifried
Re: [oss-security] Re: CVE request: Android: vold stack buffer overflowKurt Seifried
Re: [oss-security] potential OpenPAM vulnerabilityKurt Seifried
[oss-security] potential OpenPAM vulnerabilitySebastian Krahmer
Re: [oss-security] /proc/interrupts PoC: spy-interruptsDavid Hicks
Re: [oss-security] Duplicate CVE assigned: CVE-2011-2708 CVE-2011-2710Henri Salo
Re: [oss-security] CVE request: kernel: multiple flaws allowing to sniff keystrokes timingsEugene Teo
[oss-security] Re: CVE request: Android: vold stack buffer overflowDan Rosenberg
[oss-security] CVE request: Android: vold stack buffer overflowDan Rosenberg
Re: [oss-security] caml-light insecure temporary filesDavid Holland
[oss-security] CVE request: kernel: multiple flaws allowing to sniff keystrokes timingsVasiliy Kulikov
Re: [oss-security] Fwd: DSA 2338-1 moodle security updatejmm_at_nospam
[oss-security] Fwd: DSA 2338-1 moodle security updateHenri Salo
[oss-security] /proc/interrupts PoC: spy-interruptsVasiliy Kulikov
Re: [oss-security] CVE Request -- Ruby (OpenSSL extension) -- Insecure way of creation exponent value by private RSA key generationKurt Seifried
[oss-security] CVE Request -- Ruby (OpenSSL extension) -- Insecure way of creation exponent value by private RSA key generationJan Lieskovsky
Re: [oss-security] CVE Request -- pam_yubico -- Authentication bypass via NULL passwordKurt Seifried
[oss-security] CVE Request -- pam_yubico -- Authentication bypass via NULL passwordJan Lieskovsky
Re: [oss-security] caml-light insecure temporary filesEitan Adler
Re: [oss-security] Re: CVE request for CalibreJason A. Donenfeld
Re: [oss-security] caml-light insecure temporary filesKurt Seifried
Re: [oss-security] Re: CVE request for CalibreKurt Seifried
Re: [oss-security] caml-light insecure temporary filesFlorian Weimer
Re: [oss-security] Duplicate CVE assigned: CVE-2011-2708 CVE-2011-2710Marcus Meissner
[oss-security] caml-light insecure temporary filesDavid Holland
Re: [oss-security] Request for CVE Identifier: bzexe insecure temporary filevladz
Re: [oss-security] Duplicate CVE assigned: CVE-2011-2708 CVE-2011-2710Henri Salo
[oss-security] /proc/$PID/sched PoC: spy-gksuVasiliy Kulikov
Re: [oss-security] CVE request: unsafe use of /tmp in multiple CPAN modulesSolar Designer
Re: [oss-security] CVE request: unsafe use of /tmp in multiple CPAN modulesSolar Designer
Re: [oss-security] Re: CVE request for CalibreJason A. Donenfeld
Re: [oss-security] Re: CVE request for CalibreSteven M. Christey
Re: [oss-security] Re: CVE request for CalibreJason A. Donenfeld
Re: [oss-security] Re: CVE request for CalibreJason A. Donenfeld
Re: [oss-security] CVE request: MaharaKurt Seifried
[oss-security] CVE request: MaharaMoritz Muehlenhoff
Re: [oss-security] CVE Request -- kernel: sysctl: restrict write access to dmesg_restrictSolar Designer
Re: [oss-security] CVE request: unsafe use of /tmp in multiple CPAN modulesSolar Designer
Re: [oss-security] CVE request: unsafe use of /tmp in multiple CPAN modulesKurt Seifried
Re: [oss-security] CVE Request -- Drupal (v6.x based) Views module - SQL injection due improper escaping of database parameters for certain filters / arguments (SA-CONTRIB-2011-052)Kurt Seifried
[oss-security] CVE Request -- Drupal (v6.x based) Views module - SQL injection due improper escaping of database parameters for certain filters / arguments (SA-CONTRIB-2011-052)Jan Lieskovsky
Re: [oss-security] Re: CVE request for CalibreKurt Seifried
Re: [oss-security] CVE Request -- phpMyAdmin -- Arbitrary local file read flaw by loading XML strings / importing XML filesKurt Seifried
Re: [oss-security] CVE request: wordpress plugin timthumb before 2.0 remote code executionKurt Seifried
[oss-security] CVE Request -- phpMyAdmin -- Arbitrary local file read flaw by loading XML strings / importing XML filesJan Lieskovsky
[oss-security] CVE request: wordpress plugin timthumb before 2.0 remote code executionHanno Böck
Re: [oss-security] Re: CVE request for CalibreDan Rosenberg
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedGuido Berhoerster
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedKurt Seifried
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedYves-Alexis Perez
Re: [oss-security] Re: [LightDM] Version 1.0.6 releasedKurt Seifried
Re: [oss-security] Re: CVE request for Django-piston and TastypieKurt Seifried
[oss-security] Re: [LightDM] Version 1.0.6 releasedYves-Alexis Perez
Re: [oss-security] kiwi shell meta char injectionThomas Biege
[oss-security] kiwi shell meta char injectionThomas Biege
[oss-security] Re: CVE request for CalibreJason A. Donenfeld
[oss-security] CVE request for CalibreJason A. Donenfeld
[oss-security] Re: CVE request for Django-piston and TastypieDavid Black
Re: [oss-security] CVE request for Django-piston and TastypieKurt Seifried
Re: [oss-security] CVE request for wireshark flawsKurt Seifried
Re: [oss-security] CVE request for Django-piston and TastypieVincent Danen
[oss-security] CVE request for wireshark flawsVincent Danen
Re: [oss-security] CVE request for Django-piston and TastypieKurt Seifried
[oss-security] CVE request for Django-piston and TastypieDavid Black
[oss-security] libcap/capsh: does not chdir after chrootHuzaifa Sidhpurwala