oss-sec: by date

376 messages starting Apr 01 10 and ending Jun 30 10
Date index | Thread index | Author index


Thursday, 01 April

CVE Request: moodle 1.9.8, 1.8.2 Ludwig Nussel
CVE Request -- Zabbix v1.8.2 and v.1.6.9 Jan Lieskovsky
CVE Request -- libnids v1.24 -- Null pointer dereference Jan Lieskovsky
Re: CVE Request -- aMSN -- improper SSL certificate validation (MITM) Josh Bressers
Re: CVE Request -- Dovecot v1.2.11 -- DoS (excessive CPU use) by processing email with huge header Josh Bressers
Re: CVE Request: DeviceKit privilege escalation via pluggable storage device labels Josh Bressers
CVE Request: policykit (minor) Kees Cook
Re: CVE request: kernel: connector security bypass Josh Bressers
Re: CVE Request -- Transmission v1.92 Josh Bressers
Re: CVE Request: policykit (minor) Josh Bressers
Re: CVE Request -- libnids v1.24 -- Null pointer dereference Josh Bressers
Re: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Josh Bressers
Re: CVE Request: moodle 1.9.8, 1.8.2 Josh Bressers

Friday, 02 April

RE: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Nicolas GREGOIRE
Re: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Moritz Muehlenhoff

Saturday, 03 April

CVE Request -- OpenDCHub v0.8.1 -- Stack overflow by handling a specially-crafted MyINFO message Jan Lieskovsky
Re: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Tomas Hoger
CVE-2010-0463 incomplete horde fixes Nico Golde

Sunday, 04 April

Re: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Nicob

Monday, 05 April

CVE request: kernel: cifs: cifs_create() NULL pointer dereference Eugene Teo
Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference Eugene Teo
Debian Moin Question Josh Bressers
Re: Debian Moin Question Michael Gilbert
Re: Debian Moin Question Giuseppe Iuculano
Re: CVE Request -- OpenDCHub v0.8.1 -- Stack overflow by handling a specially-crafted MyINFO message Josh Bressers
Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference Josh Bressers

Tuesday, 06 April

Re: CVE Request -- Zabbix v1.8.2 and v.1.6.9 Steven M. Christey
ClamAV small issues Jamie Strandboge
CVE Request -- udisks v1.0.0 -- (serious) information disclosure Jan Lieskovsky
CVE Request: MediaWiki 1.15.3 -- Login CSRF Reed Loden

Wednesday, 07 April

Re: ClamAV small issues Josh Bressers
Re: CVE Request -- udisks v1.0.0 -- (serious) information disclosure Josh Bressers
Re: ClamAV small issues Kurt Seifried
Re: CVE Request: MediaWiki 1.15.3 -- Login CSRF Josh Bressers

Thursday, 08 April

CVE Request -- Abcm2ps v5.9.12 -- multiple unspecified vulnerabilities Jan Lieskovsky
Re: CVE Request -- Abcm2ps v5.9.12 -- multiple unspecified vulnerabilities Jan Lieskovsky
Re: CVE Request -- Abcm2ps v5.9.12 -- multiple unspecified vulnerabilities Tim Starling
CVE request -- memcached Jamie Strandboge
CVE Request -- perl v5.8.* -- stack overflow by processing certain regex (Gentoo BTS#313565 / RH BZ#580605) Jan Lieskovsky
Re: CVE request -- memcached Jamie Strandboge
[HITB-Announce] FINAL CALL - CFP for HITBSecConf2010 Amsterdam Hafez Kamal
Re: CVE request -- memcached Josh Bressers
CVE-2010-1146 kernel: reiserfs priv escalation Eugene Teo

Friday, 09 April

Re: CVE-2010-1146 kernel: reiserfs priv escalation Eugene Teo
Re: ClamAV small issues Ludwig Nussel
Re: ClamAV small issues Eren Türkay
Re: ClamAV small issues Eren Türkay
Re: ClamAV small issues Ludwig Nussel

Saturday, 10 April

CVE request: typo3 remote command execution Hanno Böck
CVE request: Java webstart remote code execution Hanno Böck

Sunday, 11 April

CVE request: irssi 0.8.15 Tobias Heinlein

Monday, 12 April

Re: CVE request: typo3 remote command execution Josh Bressers
Re: CVE request: Java webstart remote code execution Josh Bressers
Re: CVE request: irssi 0.8.15 Josh Bressers
Re: CVE request: irssi 0.8.15 Steven M. Christey

Tuesday, 13 April

Re: CVE request: irssi 0.8.15 Josh Bressers
Re: CVE request: irssi 0.8.15 Tomas Hoger
Re: CVE request: irssi 0.8.15 Wouter Coekaerts
Couple of kernel issues Eugene Teo

Wednesday, 14 April

CVE request: aircrack-ng EAPOL buffer overflow Florian Weimer
Re: CVE Request -- perl v5.8.* -- stack overflow by processing certain regex (Gentoo BTS#313565 / RH BZ#580605) Josh Bressers
CVE request: GNU nano (minor) Dan Rosenberg
Re: CVE request: aircrack-ng EAPOL buffer overflow Josh Bressers
Re: CVE request: GNU nano (minor) Josh Bressers
Re: Couple of kernel issues Michael Gilbert
CVE request: kernel: tty: release_one_tty() forgets to put pids Eugene Teo
Re: CVE request: kernel: tty: release_one_tty() forgets to put pids Eugene Teo

Thursday, 15 April

CVE request - sudo Tomas Hoger
Re: CVE request: Java webstart remote code execution Steven M. Christey
Re: CVE request: kernel: tty: release_one_tty() forgets to put pids Josh Bressers
Re: CVE request - sudo Josh Bressers

Friday, 16 April

CVE Request: JIRA Issues Eren Türkay
Re: CVE Request: JIRA Issues Josh Bressers

Saturday, 17 April

Re: Re: CVE request: irssi 0.8.15 Jamie Strandboge
Re: kernel: hvc_console: Fix race between hvc_close and hvc_remove Michael Gilbert
Re: kernel: hvc_console: Fix race between hvc_close and hvc_remove Michael Gilbert

Sunday, 18 April

CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input Matthias Andree
Re: kernel: hvc_console: Fix race between hvc_close and hvc_remove Eugene Teo
Re: kernel: hvc_console: Fix race between hvc_close and hvc_remove Eugene Teo

Monday, 19 April

Re: CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input Florian Weimer
Re: CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input Josh Bressers

Tuesday, 20 April

Re: CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input Matthias Andree

Wednesday, 21 April

Re: CVE-2010-0727 kernel: gfs/gfs2 locking code DoS flaw dann frazier

Thursday, 22 April

Check your WPA2 Enterprise setup Ludwig Nussel
CVE request: VLC <1.0.6 Multiple issues Alex Legler
[HITB-Announce] HITBSecConf2010 - Dubai - Presentation Materials Hafez Kamal
[HITB-Announce] HITB eZine Issue 002 out now! Hafez Kamal

Friday, 23 April

Re: CVE Request: moodle 1.9.8, 1.8.2 Ludwig Nussel
CVE Request: cacti SQL injection in template_export Thijs Kinkhorst

Monday, 26 April

CVE request: joomla <= 1.5.15 code upload, information leak, session fixation, unauthorized access (was Fwd: Joomla! Security News) Hanno Böck
WordNet wn format string issue Tomas Hoger
Searching for vuln apps for testing free code review tools Taras
Re: Searching for vuln apps for testing free code review tools Henri Salo
Re: CVE Request: cacti SQL injection in template_export Josh Bressers
Re: Re: CVE request: irssi 0.8.15 Wouter Coekaerts
Re: CVE request: joomla <= 1.5.15 code upload, information leak, session fixation, unauthorized access (was Fwd: Joomla! Security News) Josh Bressers
CVE request - gfs2 kernel issue Eugene Teo
CVE request - kernel: find_keyring_by_name() can gain the freed keyring Eugene Teo
Re: CVE request: kernel: tty: release_one_tty() forgets to put pids Eren Türkay

Tuesday, 27 April

Re: CVE request: kernel: tty: release_one_tty() forgets to put pids Eugene Teo
Re: Re: CVE request: irssi 0.8.15 Steve Langasek
wafp insecure temporary directory Henri Salo
CVS request - Moodle Dan Poltawski
Re: CVE request - gfs2 kernel issue Josh Bressers
Re: CVE request - kernel: find_keyring_by_name() can gain the freed keyring Josh Bressers
Re: wafp insecure temporary directory Josh Bressers

Wednesday, 28 April

Re: CVE request: VLC <1.0.6 Multiple issues Josh Bressers
CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors Eugene Teo
Re: CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors Hui Zhu
CVE request - Linux Kernel KGDB/ppc issue Hui Zhu
Re: CVE request - Linux Kernel KGDB/ppc issue Eugene Teo
Re: CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors Hui Zhu
Re: CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors Eugene Teo

Thursday, 29 April

Re: [security-linux] Re: [oss-security] CVE request - Linux Kernel KGDB/ppc issue Mark Hatle
Re: CVS request - Moodle Josh Bressers
Re: CVE request - Linux Kernel KGDB/ppc issue Josh Bressers
Re: CVE Request: moodle 1.9.8, 1.8.2 Steven M. Christey
Re: CVE request - Linux Kernel KGDB/ppc issue Eugene Teo

Saturday, 01 May

Multiple vulnerabilities in OpenTTD Matthijs Kooijman

Sunday, 02 May

CVE request: lxr Raphael Geissert

Monday, 03 May

Re: CVE request: lxr Dan Rosenberg
Re: CVE request: lxr Henri Salo
Re: CVE request: lxr Josh Bressers
Re: CVE request: lxr Henri Salo
Re: CVE request: lxr Josh Bressers
Re: CVE request: lxr Dan Rosenberg

Tuesday, 04 May

CVE Request [was Re: [oss-security] kernel: execution possible in non-executable mappings in recent 2.6 kernels (SPARC only)] dann frazier

Wednesday, 05 May

Re: CVE Request [was Re: [oss-security] kernel: execution possible in non-executable mappings in recent 2.6 kernels (SPARC only)] Josh Bressers
CVE Request - Piwik 0.5.5 - XSS vulnerability Anthon Pang
Re: CVE Request - Piwik 0.5.5 - XSS vulnerability Josh Bressers

Thursday, 06 May

Re: CVE request: lxr Steven M. Christey
Re: CVE request: lxr Dan Rosenberg
CVE-2010-0730 xen: emulator instruction decoding inconsistency Eugene Teo

Friday, 07 May

A mysql flaw. Oden Eriksson
MOPS and CVEs? Hanno Böck
Re: MOPS and CVEs? Josh Bressers
CVE Assignment (wireshark) Josh Bressers
CVE Assignment (gnustep) Josh Bressers
Re: CVE Assignment (wireshark) Josh Bressers
Re: CVE Assignment (gnustep) Dan Rosenberg
Re: CVE Assignment (gnustep) Josh Bressers
Re: A mysql flaw. Josh Bressers

Monday, 10 May

Re: A mysql flaw. Oden Eriksson
Re: A mysql flaw. Tomas Hoger

Tuesday, 11 May

Month of PHP Security 2010 Issues Eren Türkay
Re: Month of PHP Security 2010 Issues Moritz Muehlenhoff
CVE assignment: ghostscript stack-based overflow Steven M. Christey
Re: Month of PHP Security 2010 Issues Steven M. Christey
Re: CVE assignment: ghostscript stack-based overflow Dan Rosenberg

Thursday, 13 May

KDENetwork vulnerabilities Jamie Strandboge

Friday, 14 May

Re: CVE request: lxr Josh Bressers
Re: CVE request: lxr Dan Rosenberg
Re: CVE request: lxr Josh Bressers

Sunday, 16 May

CVE request: phpbb 3.0.7 and before 3.0.5 Hanno Böck
CVE request: phorum < 5.2.15 backend XSS Hanno Böck

Monday, 17 May

[oCERT-2010-001] multiple http client unexpected download filename vulnerability Daniele Bianco
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Florian Weimer

Tuesday, 18 May

Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Ludwig Nussel
kernel: btrfs: check for read permission on src file in the clone ioctl Eugene Teo
Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference Greg KH
Re: A mysql flaw. Josh Bressers
Re: CVE request: phorum < 5.2.15 backend XSS Josh Bressers
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Josh Bressers
Re: CVE assignment: ghostscript stack-based overflow Josh Bressers
Re: CVE request: phorum < 5.2.15 backend XSS Steven M. Christey
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Steven M. Christey
Re: kernel: btrfs: check for read permission on src file in the clone ioctl Dan Rosenberg
Re: CVE request: phorum < 5.2.15 backend XSS Josh Bressers
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Josh Bressers
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Solar Designer
Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference Eugene Teo

Wednesday, 19 May

Re: CVE request: phpbb 3.0.7 and before 3.0.5 Hanno Böck
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Ludwig Nussel
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Josh Bressers
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Thijs Kinkhorst
Re: CVE request: phpbb 3.0.7 and before 3.0.5 Steven M. Christey
[HITB-Announce] HITBSecConf2010 - Malaysia Call for Papers Hafez Kamal
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Solar Designer

Thursday, 20 May

Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege
CVE Request for Horde and Squirrelmail Max Olsterd
CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request Jan Lieskovsky
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Solar Designer
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Solar Designer
Re: [core] CVE Request for Horde and Squirrelmail Marcus I. Ryan

Friday, 21 May

Re: CVE Request for Horde and Squirrelmail Thijs Kinkhorst
clamav null pointer dereference Thomas Biege
CVE Request: clamav crash via malformed PDF Jamie Strandboge
Re: clamav null pointer dereference Jamie Strandboge
CVE Request: off by one DoS in pe_icons.c Jamie Strandboge

Saturday, 22 May

Re: CVE Request for Horde and Squirrelmail Max Olsterd

Sunday, 23 May

Re: CVE Request for Horde and Squirrelmail Thijs Kinkhorst

Monday, 24 May

CVE Request -- Cacti v0.8.7 -- three security fixes Jan Lieskovsky
Re: CVE Request for Horde and Squirrelmail Nicob
CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership Eugene Teo
Re: [core] CVE Request for Horde and Squirrelmail Michael M Slusarz

Tuesday, 25 May

Re: [SquirrelMail-Security] [oss-security] CVE Request for Horde and Squirrelmail Paul Lesniewski
Who visits the Linux Security Summit 2010 Thomas Biege
Python rgbimg and audioop issues Tomas Hoger
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Josh Bressers
Re: kernel: btrfs: check for read permission on src file in the clone ioctl Josh Bressers
Re: CVE Request for Horde and Squirrelmail Josh Bressers
Re: CVE Request: clamav crash via malformed PDF Josh Bressers
Re: CVE Request: off by one DoS in pe_icons.c Josh Bressers
Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership Josh Bressers
Re: CVE Request for Horde and Squirrelmail Steven M. Christey
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Josh Bressers
Re: CVE Request: clamav crash via malformed PDF Steven M. Christey
Re: CVE Request: off by one DoS in pe_icons.c Steven M. Christey
Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership Eugene Teo
CVE request - kernel: nfsd: fix vm overcommit crash Eugene Teo

Wednesday, 26 May

Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Tomas Hoger
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities Thomas Biege
Re: CVE request - kernel: nfsd: fix vm overcommit crash Josh Bressers
Re: CVE Request -- Cacti v0.8.7 -- three security fixes Josh Bressers
Re: CVE request - kernel: nfsd: fix vm overcommit crash Eugene Teo

Thursday, 27 May

Re: CVE Request -- Cacti v0.8.7 -- three security fixes Steven M. Christey
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Eren Türkay

Friday, 28 May

Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Tomas Hoger
CVE request: Mediawiki below 1.15.4 / 1.16.0beta3 Hanno Böck
CVE request: ghostscript and gv Ludwig Nussel
Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Eren Türkay
CVE-2009-4824 is a duplicate of CVE-2009-3236 Giuseppe Iuculano

Saturday, 29 May

CVE request: joomla before 1.5.18 Hanno Böck
Re: CVE request: ghostscript and gv Bernhard R. Link
CVE request: zonecheck Sebastien Delafond
Fwd: emesene preditable temporary filename Emilio Pozuelo Monfort
Re: Fwd: emesene preditable temporary filename Marcus Meissner

Sunday, 30 May

Re: CVE request: ghostscript and gv Florian Weimer
Re: CVE request: ghostscript and gv Bernhard R. Link

Monday, 31 May

Re: Fwd: [Full-disclosure] stratsec Security Advisory SS-2010-005: Samba Multiple DoS Vulnerabilities (3.3.x) Tomas Hoger
SFCB vulnerabilities Nicolas Grégoire
CVE request: DM Database Server Shennan.Wang

Tuesday, 01 June

Re: CVE Request -- Cacti v0.8.7 -- three security fixes Jan Lieskovsky
Re: CVE request: Mediawiki below 1.15.4 / 1.16.0beta3 Josh Bressers
Re: CVE request: joomla before 1.5.18 Josh Bressers
Re: CVE request: zonecheck Josh Bressers
Re: Fwd: emesene preditable temporary filename Josh Bressers
Re: SFCB vulnerabilities Josh Bressers
Re: CVE request: DM Database Server Josh Bressers
Re: CVE request: ghostscript and gv Josh Bressers
Re: CVE request: ghostscript and gv Michael Gilbert
Re: CVE request: ghostscript and gv Josh Bressers
Re: SFCB vulnerabilities Nicolas Grégoire
prewikka permission bug Stefan Behte
Re: SFCB vulnerabilities Sebastian Krahmer

Wednesday, 02 June

CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Jan Lieskovsky
Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Jan Lieskovsky
CVE Request -- Beanstalkd (prior v1.4.6) -- Improper sanitization of job body (job payload data) Jan Lieskovsky
Re: SFCB vulnerabilities Nicolas Grégoire

Thursday, 03 June

Re: prewikka permission bug Josh Bressers
Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Josh Bressers
Re: CVE Request -- Beanstalkd (prior v1.4.6) -- Improper sanitization of job body (job payload data) Josh Bressers
CVE Request -- rpcbind -- Insecure (predictable) temporary file use Jan Lieskovsky
Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Steven M. Christey
CVE requests for mplayer/vlc and abcm2ps Moritz Muehlenhoff
Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775) Panu Matilainen

Friday, 04 June

Re: CVE Request -- rpcbind -- Insecure (predictable) temporary file use Josh Bressers
Virii in the wild Henri Salo
Re: CVE requests for mplayer/vlc and abcm2ps Josh Bressers
Re: CVE requests for mplayer/vlc and abcm2ps Tomas Hoger

Sunday, 06 June

CVE request - kernel: ext4: Make sure the MOVE_EXT ioctl can't overwrite append-only files Eugene Teo

Monday, 07 June

Re: CVE Request -- Cacti v0.8.7 -- three security fixes Steven M. Christey
Re: CVE Request -- rpcbind -- Insecure (predictable) temporary file use Steven M. Christey
Re: CVE request: zonecheck Steven M. Christey
Re: CVE Request -- Cacti v0.8.7 -- three security fixes Larry Adams
Re: CVE Request -- Cacti v0.8.7 -- three security fixes Tony Roman
Re: CVE Request -- rpcbind -- Insecure (predictable) temporary file use Josh Bressers
Re: CVE Request -- rpcbind -- Insecure (predictable) temporary file use Steven M. Christey

Tuesday, 08 June

ArpON (Arp handler inspectiON) 2.0 released! Andrea Di Pasquale
jar, fastjar directory traversal vulnerabilities Vincent Danen
Re: CVE Request -- rpcbind -- Insecure (predictable) temporary file use Josh Bressers
Re: jar, fastjar directory traversal vulnerabilities Steven M. Christey
Re: jar, fastjar directory traversal vulnerabilities Vincent Danen

Wednesday, 09 June

Re: CVE request - kernel: ext4: Make sure the MOVE_EXT ioctl can't overwrite append-only files Josh Bressers
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Marcus Meissner
Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Steven M. Christey
CVE requests: maradns, freeciv, rbot, gitolite, gource, shib, kvirc Moritz Muehlenhoff

Thursday, 10 June

Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability Vincent Danen
CVE-2010-2070 kernel-xen: ia64-xen: unset be from the task psr Eugene Teo
CVE request for new wireshark vulnerabilities Vincent Danen

Friday, 11 June

Re: CVE requests: maradns, freeciv, rbot, gitolite, gource, shib, kvirc Josh Bressers
CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own Dan Rosenberg

Saturday, 12 June

CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Alex Legler

Sunday, 13 June

CVE request - pyftpd insecure usage of temporary directory Henri Salo
CVE request - pyftpd default username and password vulnerability Henri Salo
Re: CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own Eugene Teo
Re: CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own Eugene Teo

Monday, 14 June

CVE request: punbb before 1.3.4 xss Hanno Böck
CVE Request: w3m does not check null bytes CN/subjAltName Ludwig Nussel
Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Alex Legler
Re: CVE request: punbb before 1.3.4 xss Josh Bressers
Re: CVE request for new wireshark vulnerabilities Josh Bressers
Re: CVE request - pyftpd insecure usage of temporary directory Josh Bressers
Re: CVE request - pyftpd default username and password vulnerability Josh Bressers
Re: CVE Request: w3m does not check null bytes CN/subjAltName Josh Bressers
Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Josh Bressers
Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Josh Bressers
Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Steven M. Christey
Re: CVE request: punbb before 1.3.4 xss Steven M. Christey
Re: CVE request for new wireshark vulnerabilities Steven M. Christey
Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution Eugene Teo
CVE Request - kernel: put_tty_queue NULL pointer deref dann frazier
Re: CVE Request - kernel: put_tty_queue NULL pointer deref Eugene Teo

Tuesday, 15 June

Re: CVE Request - kernel: put_tty_queue NULL pointer deref Josh Bressers
Re: CVE Request - kernel: put_tty_queue NULL pointer deref Steven M. Christey

Thursday, 17 June

CVE request - kernel: xfs swapext ioctl issue Eugene Teo
VLC 1.0 series End of Life Rémi Denis-Courmont

Friday, 18 June

Stefan Esser's 0day PHP SysCan flaw Josh Bressers
Re: CVE request - kernel: xfs swapext ioctl issue Josh Bressers
CVE request: moodle 1.9.9/1.8.13 multiple vulnerabilities Vincent Danen

Monday, 21 June

Re: [SquirrelMail-Security] [oss-security] CVE Request for Horde and Squirrelmail Paul Lesniewski
Re: CVE request: moodle 1.9.9/1.8.13 multiple vulnerabilities Josh Bressers
CVE Request -- Plone -- arbitrary HTML code injection in safe_html Jan Lieskovsky

Tuesday, 22 June

Re: CVE Request -- Plone -- arbitrary HTML code injection in safe_html Matthew Wilkes
Re: Re: CVE Request -- Plone -- arbitrary HTML code injection in safe_html Steven M. Christey
CVE request: kernel: timekeeping: Prevent oops when GENERIC_TIME=n Eugene Teo
kernel: thinkpad-acpi: lock down video output state access Eugene Teo
kernel: l2tp: Fix oops in pppol2tp_xmit Eugene Teo

Wednesday, 23 June

CVE Request: avahi DoS Ludwig Nussel
CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface Jan Lieskovsky
Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface Florian Streibelt
CVE requests: LibTIFF Dan Rosenberg

Thursday, 24 June

Re: CVE requests: LibTIFF Tomas Hoger
Re: CVE requests: LibTIFF Dan Rosenberg
Re: CVE requests: LibTIFF Tomas Hoger
Re: CVE requests: maradns, freeciv, rbot, gitolite, gource, shib, kvirc Marcus Meissner
Re: CVE requests: maradns, freeciv, rbot, gitolite, gource, shib, kvirc Steven M. Christey

Friday, 25 June

Re: CVE request: kernel: timekeeping: Prevent oops when GENERIC_TIME=n Josh Bressers
Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface Josh Bressers
Re: CVE Request: avahi DoS Josh Bressers
CVE request: feh Daniel Friesel

Saturday, 26 June

Re: CVE Request -- mlmmj -- Directory traversal flaw by editing and saving list entries via php-admin web interface Morten Shearman Kirkegaard

Sunday, 27 June

Re: Stefan Esser's 0day PHP SysCan flaw Raphael Geissert
CVE request: makepasswd, Default settings generate insecure passwords Henri Salo

Monday, 28 June

CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server Eugene Teo
CVE Request -- libpng v1.4.3 and v1.2.44 -- memory leak while processing PNG image with malformed sCAL chunks Jan Lieskovsky
Re: CVE Request -- Drupal v6.16 / v5.22 SA-CORE-2010-001 Henri Salo
Re: CVE request: feh Josh Bressers
Re: CVE request: makepasswd, Default settings generate insecure passwords Josh Bressers
Re: CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server Josh Bressers
Re: CVE Request -- libpng v1.4.3 and v1.2.44 -- memory leak while processing PNG image with malformed sCAL chunks Josh Bressers
Re: CVE Request -- Drupal v6.16 / v5.22 SA-CORE-2010-001 Josh Bressers
kernel: ethtool: kernel buffer overflow in ETHTOOL_GRXCLSRLALL Eugene Teo

Tuesday, 29 June

Re: CVE requests: LibTIFF Dan Rosenberg
Re: kernel: ethtool: kernel buffer overflow in ETHTOOL_GRXCLSRLALL akuster
Re: CVE requests: LibTIFF Tomas Hoger
CVE id request: syscp Nico Golde
Re: CVE requests: LibTIFF Dan Rosenberg
Re: CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server akuster
CVE request: XSS in python paste Raphael Geissert
Re: CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server Eugene Teo
CVE Request: kernel: ethtool: kernel buffer overflow in ETHTOOL_GRXCLSRLALL Eugene Teo

Wednesday, 30 June

CVE request: HTML Purifier Raphael Geissert
Re: CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server akuster
Re: CVE request - kernel: cifs: Fix a kernel BUG with remote OS/2 server Eugene Teo
CVE Request -- PHP strrchr() Interruption Information Leak Vulnerability Péter Veres
Re: CVE Request -- libpng v1.4.3 and v1.2.44 -- memory leak while processing PNG image with malformed sCAL chunks Marcus Meissner
Re: Stefan Esser's 0day PHP SysCan flaw Raphael Geissert
CVE Request -- Python-Mako (prior v0.3.4): Improper escaping of single quotes in escape.cgi (XSS) Jan Lieskovsky
CVE request: PHP MOPS-2010-56..60 Raphael Geissert
Re: Re: Stefan Esser's 0day PHP SysCan flaw Pierre Joye
Re: CVE requests: LibTIFF Josh Bressers
Re: CVE request: PHP MOPS-2010-56..60 Josh Bressers
Re: CVE requests: LibTIFF Dan Rosenberg
Re: CVE id request: syscp Josh Bressers
Re: CVE request: XSS in python paste Josh Bressers
Re: CVE Request: kernel: ethtool: kernel buffer overflow in ETHTOOL_GRXCLSRLALL Josh Bressers
Re: CVE request: HTML Purifier Josh Bressers
Re: CVE Request -- PHP strrchr() Interruption Information Leak Vulnerability Josh Bressers
Re: CVE Request -- Python-Mako (prior v0.3.4): Improper escaping of single quotes in escape.cgi (XSS) Josh Bressers
Re: CVE Request -- PHP strrchr() Interruption Information Leak Vulnerability Pierre Joye
Re: CVE requests: LibTIFF Josh Bressers
Re: CVE request: simplemachinesforum Henri Salo
Re: kernel: hvc_console: Fix race between hvc_close and hvc_remove dann frazier