Mandriva Linux Security Advisory 2009-029 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.
5bd12d58fe984f20eaf9ce8cdca247ed7d8e7d8f56db06e9e6d14c5d9cc5ef19
Mandriva Linux Security Advisory 2009-028 - Security vulnerabilities have been discovered and corrected in CUPS. CUPS before 1.3.8 allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions. CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow. CUPS shipped with Mandriva Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.
1e8a4108fdf9c2d57d8db1cf6e760cbbcb404476f8da36f8cd8b11ddda80fdbe
Mandriva Linux Security Advisory 2009-027 - A vulnerability has been discovered in CUPS shipped with Mandriva Linux which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. The updated packages have been patched to prevent this.
1c87943c9e741986daa1f1e9fb9d367afebe78c319ee66ce82cba925bda98601
Enenano CMS version 1.0.5 suffers from a persistent cross site scripting vulnerability.
39100a5902f6ef9df37d19aa3b0387f1b03d573ce9c77ff3abcd55db4d16c781
Whitepaper discussing DLL injection on Windows Vista (32bit). Includes an executable for injecting a DLL in a process of your choice and the original source code is in the pdf.
f0dd535766ba29b245a3335c2feb08cece3689d2a38a0437a4a282fb4e6429ad
MediaMonkey version 3.0.6 local buffer overflow proof of concept exploit that creates a malicious .m3u file.
6763975490ae3e021335cc169237a2601f2d5c31ee120cd505bf9a646113abe2
Merak Media Player version 3.2 .m3u file local buffer overflow proof of concept exploit.
8332f00fbcce76d698eaaeeecc871a70f8812c7638885101912197a2d74bd680
EleCard MPEG Player local stack overflow exploit that creates a malicious .m3u file that binds a shell to port 4444.
d06cb01494daf799139e1db84863c8d027881dfdb735cc41fc7209a21920a643
Patched source code for lib_postgresqludf_sys that allows for command execution on postgres with user defined functions.
7e2243d51f00284725bd535fed895dcbb3fd66596981f866c66e9deabc5992ae