exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 9 of 9 RSS Feed

Files Date: 2009-01-25

Mandriva Linux Security Advisory 2009-029
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-029 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, remote, overflow, arbitrary, local, vulnerability
systems | linux, mandriva
advisories | CVE-2008-5286, CVE-2009-0032
SHA-256 | 5bd12d58fe984f20eaf9ce8cdca247ed7d8e7d8f56db06e9e6d14c5d9cc5ef19
Mandriva Linux Security Advisory 2009-028
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-028 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS before 1.3.8 allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, remote, web, denial of service, overflow, arbitrary, local, cgi, vulnerability
systems | linux, mandriva
advisories | CVE-2008-5183, CVE-2008-5184, CVE-2008-5286, CVE-2009-0032
SHA-256 | 1e8a4108fdf9c2d57d8db1cf6e760cbbcb404476f8da36f8cd8b11ddda80fdbe
Mandriva Linux Security Advisory 2009-027
Posted Jan 25, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-027 - A vulnerability has been discovered in CUPS shipped with Mandriva Linux which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.

tags | advisory, arbitrary, local
systems | linux, mandriva
advisories | CVE-2009-0032
SHA-256 | 1c87943c9e741986daa1f1e9fb9d367afebe78c319ee66ce82cba925bda98601
Enano 1.0.5 Persistent Cross Site Scripting
Posted Jan 25, 2009
Authored by fuzion

Enenano CMS version 1.0.5 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 39100a5902f6ef9df37d19aa3b0387f1b03d573ce9c77ff3abcd55db4d16c781
Whitepaper - Win Vista DLL Injection (32bit)
Posted Jan 25, 2009
Authored by George Nicolaou | Site astalavista.com

Whitepaper discussing DLL injection on Windows Vista (32bit). Includes an executable for injecting a DLL in a process of your choice and the original source code is in the pdf.

tags | paper
systems | windows
SHA-256 | f0dd535766ba29b245a3335c2feb08cece3689d2a38a0437a4a282fb4e6429ad
MediaMonkey 3.0.6 Buffer Overflow
Posted Jan 25, 2009
Authored by AlpHaNiX

MediaMonkey version 3.0.6 local buffer overflow proof of concept exploit that creates a malicious .m3u file.

tags | exploit, overflow, local, proof of concept
SHA-256 | 6763975490ae3e021335cc169237a2601f2d5c31ee120cd505bf9a646113abe2
Merak Media Player 3.2 Buffer Overflow
Posted Jan 25, 2009
Authored by H-T Team | Site no-hack.fr

Merak Media Player version 3.2 .m3u file local buffer overflow proof of concept exploit.

tags | exploit, overflow, local, proof of concept
SHA-256 | 8332f00fbcce76d698eaaeeecc871a70f8812c7638885101912197a2d74bd680
EleCard MPEG Player Stack Overflow
Posted Jan 25, 2009
Authored by AlpHaNiX

EleCard MPEG Player local stack overflow exploit that creates a malicious .m3u file that binds a shell to port 4444.

tags | exploit, overflow, shell, local
SHA-256 | d06cb01494daf799139e1db84863c8d027881dfdb735cc41fc7209a21920a643
PostgreSQL UDF For Command Execution
Posted Jan 25, 2009
Authored by Bernardo Damele | Site bernardodamele.blogspot.com

Patched source code for lib_postgresqludf_sys that allows for command execution on postgres with user defined functions.

tags | library
SHA-256 | 7e2243d51f00284725bd535fed895dcbb3fd66596981f866c66e9deabc5992ae
Page 1 of 1
Back1Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close