Bugtraq: by date

269 messages starting Sep 01 01 and ending Sep 29 01
Date index | Thread index | Author index


Saturday, 01 September

Vulnerability in credit union's E-statement feature BlueJAMC
INCORRECT PATCH REVISIONS: Re: Sun Security Bulletin #00207 David Foster

Sunday, 02 September

verizon wireless website gaping privacy holes Marc Slemko
Re: Vulnerability in credit union's E-statement feature Scott Dier
Re: Vulnerability in credit union's E-statement feature Hugo van der Kooij
Re: verizon wireless website gaping privacy holes Gareth Owen
POP3Lite 0.2.3b minor client side DoS and message injection Daniel Roethlisberger
Possible Issue with Netinfo and Mac OS X Benjamin Gardiner
RE: Programmer claims MS eBook Reader Cracked Рягин Михаил Юрьевич
[SNS Advisory No.41] iPlanet Messaging Server 5.1(evaluation copy) Buffer Overflow Vulnerability snsadv () lac co jp
Re: Vulnerability in credit union's E-statement feature Crispin Cowan
S/Key keyinit(1) authentication (lack thereof) + sudo(1) Frank Tobin

Monday, 03 September

RE: verizon wireless website gaping privacy holes Jeff Carnahan
Re: Possible Issue with Netinfo and Mac OS X Ethan Benson
SuSE Security Announcement: nkitb/nkitserv/telnetd Sebastian Krahmer
Re: verizon wireless website gaping privacy holes Steve Shockley
FW: HP-UX series 800 10.X patch digest Boyce, Nick
fucking basilix bug Karol Wiesek
Re: Possible Issue with Netinfo and Mac OS X Marukka
Re: verizon wireless website gaping privacy holes Russell Handorf
Re: Fw: easy remote detection of a running tripwire for webpages syst em Matthew Wakeling
KaZaa/Morpheus non-exploits Walter Hop
hpux warez auto300526
Re: Lotus Domino DoS solution Michel Arboi
Re: S/Key keyinit(1) authentication (lack thereof) + sudo(1) Derek Martin
Re: Possible Issue with Netinfo and Mac OS X Matthew Seaman
RE: Possible Issue with Netinfo and Mac OS X Dixie Flatline
Re: Possible Issue with Netinfo and Mac OS X kang
Re: Possible Issue with Netinfo and Mac OS X Marc Liyanage
Re: verizon wireless website gaping privacy holes Mark Parry
Re: Possible Issue with Netinfo and Mac OS X Stuart Moore

Tuesday, 04 September

Re: INCORRECT PATCH REVISIONS: Re: Sun Security Bulletin #00207 Casper Dik
PGPsdk Key Validity Vulnerability Patrick Oonk
[ Hackerslab bug_paper ] Informix-SQL application vulnerability s96192
RE: hpux warez Stefaan A Eeckels
Re: AOLserver 3.0 vulnerability Kriston Rehberg
Re: [ Hackerslab bug_paper ] Informix-SQL application vulnerability Gary L. Burnore
Linux Administrator's Security Guide (LASG) updated Kurt Seifried
Re: Lotus Domino DoS solution Darren Davison
Re: verizon wireless website gaping privacy holes Kevin Fu
Re: hpux warez Juan Vera
Telnet DoS Vulnerability in Marconi ATM Switch Software Christopher Kruslicky
Re: PGPsdk Key Validity Vulnerability Florian Weimer
Re: S/Key keyinit(1) authentication (lack thereof) + sudo(1) Wietse Venema
Gauntlet Vulnerability aleph1
BUZ.CH Security Advisory 200109041: Inter7 vpopmail DB pw problem Gabriel Ambuehl
Highly respected OpenBSD, OpenSSH programmer censors website, cites DMCA Jon O .
Re: S/Key keyinit(1) authentication (lack thereof) + sudo(1) Frank Tobin

Wednesday, 05 September

ShopPlus Cart Kernel|X|
directorymanager bug Karol Wiesek
Announce: Cerberus Internet Scanner David Litchfield
[CLA-2001:419] Conectiva Linux Security Announcement - fetchmail secure
pam limits drops privileges Tarhon-Onu Victor
%u encoding IDS bypass vulnerability Marc Maiffret
[CLA-2001:420] Conectiva Linux Security Announcement - mailman secure
Various problems in Baltimore WebSweeper URL filtering edvice Security Services

Thursday, 06 September

Re: pam limits drops privileges Chris Adams
Cisco Security Advisory: Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability Cisco Systems Product Security Incident Response Team
NetBSD Security Advisory 2001-015: Insufficient checking of lengths passed to kernel NetBSD Security Officer
NetBSD Security Advisory 2001-016: unsafe chdir usage in fts(3) NetBSD Security Officer
Guntella Built-in DoS Robert Stoll
NetBSD Security Advisory 2001-017: sendmail(8) incorrect command line argument check NetBSD Security Officer
[CLA-2001:421] Conectiva Linux Security Announcement - mod_auth_mysql secure
Re: Guntella Built-in DoS Brian Smith
Re: Guntella Built-in DoS Walker Traylor
ISS Alert: Multiple Vendor IDS Unicode Bypass Vulnerability X-Force
Re: Guntella Built-in DoS Steven M. Bellovin
Microsoft Security Bulletin MS01-047 Microsoft Product Security
CERT Advisory CA-2001-25 CERT Advisory
Re: Microsoft Security Bulletin MS01-047 H D Moore
Malformed Fragmented Packets DoS Dlink Firewall/Routers Fate Research Labs
SuSE Security Announcement: screen (SuSE-SA:2001:030) Roman Drahtmueller

Friday, 07 September

rlmadmin v3.8M view file symlink vulnerability Digital Shadow
Exchange Public Folders Information Leakage Aviram Jenik
Re: pam limits drops privileges Tarhon-Onu Victor
Re: pam limits drops privileges Lukasz Trabinski
Microsoft Exchange + Norton AntiVirus leak local information Matthias Andree
*** Security Advisory *** Power UP HTML Steve Shepherd
Re: tdforum 1.2 Messageboard 5-i's
Re: Microsoft Security Bulletin MS01-047 Craig Boston
ProFTPd and reverse DNS Matthew S . Hallacy
Re: ProFTPd and reverse DNS Michael S. Fischer

Saturday, 08 September

sglMerchant Version 1.0 Alexey Sintsov
Bug in compile portion for older versions of CheckPoint Firewalls adarien
Insecure handling of notes in Slashcode jesus lovejones
Re: ProFTPd and reverse DNS Noah
Shopping Cart Version 1.23 Alexey Sintsov
Bug in remote GUI access in CheckPoint Firewall adarien
Re: ProFTPd and reverse DNS The Flying Hamster
Multiple vendor 'Taylor UUCP' problems. zen-parse
Re: ProFTPd and reverse DNS Peter van Dijk
RE: ProFTPd and reverse DNS Jeroen Massar
Re: ProFTPd and reverse DNS Krzysztof Halasa
Re: Insecure handling of notes in Slashcode Anuff Joey

Sunday, 09 September

Re: Insecure handling of notes in Slashcode Chris Nandor
Re: pam limits drops privileges Lukasz Trabinski
AOLserver exploit code qitest1
Remote Shell Trojan: Threat, Origin and the Solution kai takashi
Notice about seconds overroll - S7K bug Tonu Samuel
PATCH to BIND-8.2.3 to get rid of the, unnecessary, and potentially dangerous fchown() calls Greg A. Woods

Monday, 10 September

Digital Unix 4.0x msgchk multiple vulnerabilities SeungHyun Seo
Re: CERT Advisory CA-2001-25 Steve Watt
[RHSA-2001:103-04] Updated fetchmail packages available bugzilla
More security problems in Apache on Mac OS X Jacques Distler
[RHSA-2001:106-06] New sendmail packages available which fix a local root exploit bugzilla
Re: [ Hackerslab bug_paper ] Informix-SQL application vulnerability Craig Ruefenacht
RUS-CERT Advisory 2001-09:01 Florian Weimer
[RHSA-2001:109-05] Updated xinetd package available for Red Hat Linux 7 and 7.1 bugzilla
Security Update [CSSA-033.0]Linux - uucp argument handling problems Support Info
[RHSA-2001:107-07] New bugzilla packages are available bugzilla
RE: Bug in remote GUI access in CheckPoint Firewall pesto
Re: CERT Advisory CA-2001-25 (smap overflow) Keith Young
SuSE Security Announcement: apache-contrib (SuSE-SA:2001:31) Thomas Biege
Draft Bill on privacy/security -- requires certified security technologies in all devices Jon O .
Re: CERT Advisory CA-2001-25 Ian Finlay
RE: CERT Advisory CA-2001-25 Jeremy Epstein
RE: CERT Advisory CA-2001-25 Carson Gaspar

Tuesday, 11 September

Microsoft Security Bulletin MS01-048 Microsoft Product Security
DeCSS executable prime number Thomas C. Greene
IBM AIX: Buffer Overflow Vulnerabilities in lpd IBM MSS Advisory Service
Re: More security problems in Apache on Mac OS X Eric Bennett
NetOP School Admin Vulnerability for Windows 2000 Terminal Services and NT4 Jesse Smythe
Re: ProFTPd and reverse DNS Karsten W. Rohrbach
[CLA-2001:425] Conectiva Linux Security Announcement - uucp secure
security alert: speechd from speechio.org Tyler Spivey
mailto links [Segmen]
Re: mailto links C. Cooke
Re: More security problems in Apache on Mac OS X Paul Lieberman
RE: mailto links Craig Humphrey
Re: CERT Advisory CA-2001-25 ark
Re: Draft Bill on privacy/security -- requires certified security technologies in all devices David Alban
Re: More security problems in Apache on Mac OS X Jeremey A. Mates
Textor Webmasters Ltd (listrec.pl) Alexey Sintsov
Re: More security problems in Apache on Mac OS X Jeremey A. Mates

Wednesday, 12 September

[SNS Advisory No.42] Trend Micro InterScan eManager for NT Multiple Program Buffer Overflow Vulnerability snsadv () lac co jp
EFTP Version 2.0.7.337 vulnerabilities ByteRage
FW: Digital Unix 4.0x msgchk multiple vulnerabilities Boyce, Nick
Re: mailto links [Segmen]
Is there user Anna at your host ? Alexander A. Kelner
Re: Is there user Anna at your host ? Josha Bronson
Cisco Security Advisory: Vulnerable SSL implementation in iCDN Cisco Systems Product Security Incident Response Team
RE: Is there user Anna at your host ? Andrew Hatfield
Re: Notice about seconds overroll - S7K bug Robert Bihlmeyer
FREAK SHOW: Outlook Express 6.00 http-equiv () excite com
Re: Microsoft Exchange + Norton AntiVirus leak local information Sym Security
Re: Is there user Anna at your host ? ET LoWNOISE
MDKSA-2001:073-1 - xli/xloadimage update Linux Mandrake Security Team
Re: mailto links Martin Stricker
Re: Is there user Anna at your host ? Tobias J. Kreidl
Hushmail.com accounts vulnerable to script attack. onesemicolon
Myownemail.com accounts vulnerable to script attack. onesemicolon
Re: More security problems in Apache on Mac OS X Kee Hinckley
RE: mailto links Lennard Bakker

Thursday, 13 September

leak of information in counterpane/Bruce Schneier's Password Safe program Valentin Butanescu
Re: Hushmail.com accounts vulnerable to script attack. Brian Smith
Re: Is there user Anna at your host ? Mariusz Woloszyn
Re: mailto links Scott Buchanan
Re: Is there user Anna at your host ? Bill Munger
Re: Is there user Anna at your host ? Ram'on Reyes Carri'on
Re: Is there user Anna at your host ? Tobias J. Kreidl
Re: Is there user Anna at your host ? Heikki Korpela

Friday, 14 September

Re: Hushmail.com accounts vulnerable to script attack. Friday Germany
Bank of America Online Banking Security Brad Will
Security Vulnerability with Microsoft Index Server 2.0(Sample fil e reveals file info, physical path etc) Syed Mohamed A
Re: Notice about seconds overroll - S7K bug Tonu Samuel
RE: Security Vulnerability with Microsoft Index Server 2.0(Sample file reveals file info, physical path etc) Matthew Reams
Re: Bank of America Online Banking Security Eric N. Valor
Majordomo default vulns Marco van Berkum

Sunday, 16 September

Proof-Of-Concept Perl Script for Bugtraq-ID: #3334 Mario Schmidt
Statically Detecting Likely Buffer Overflow Vulnerabilities aleph1
Detecting Format-String Vulnerabilities with Type Qualifiers aleph1
ARCserve 6.61 Share Access Vulnerability ron
advisory Kernel|X|
Re: CERT Advisory CA-2001-25 (smap overflow) Keith Young
MySQL (was Re: Notice about seconds overroll - S7K bug) Dennis Murphy

Monday, 17 September

Yet another path disclosure vulnerability KK Mookhey
AW: ARCserve 6.61 Share Access Vulnerability Marcus Bednorz
Re: MySQL (was Re: Notice about seconds overroll - S7K bug) Radu Rendec
RE: ARCserve 6.61 Share Access Vulnerability Paulo Filipe Mira
RE: ARCserve 6.61 Share Access Vulnerability David Sexton
Problems in Forte Developer 6 dbx and install docs Scott Schwartz
Re: ARCserve 6.61 Share Access Vulnerability ron
Lotus Notes: File attachments may be extracted regardless of document security jjore
aa.com not encrypting customer transaction data Chris Fairbourne
RE: MySQL (was Re: Notice about seconds overroll - S7K bug) Rowan Kerr
Re: Lotus Notes: File attachments may be extracted regardless of document security Katherine_Spanbauer

Tuesday, 18 September

Re: FW: aa.com not encrypting customer transaction data (KMM508728C0KM) AA Webmaster
Re: Problems in Forte Developer 6 dbx and install docs Casper Dik
OpenSSH: sftp & bypassing keypair auth restrictions Peter W
SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network Kistler Ueli
MDKSA-2001:077 - apache update Linux Mandrake Security Team
Nimda Worm Dave Ahmad
Re: Hushmail.com accounts vulnerable to script attack. Brian Smith
CERT Advisory CA-2001-26 CERT Advisory
Re: aa.com not encrypting customer transaction data (KMM508728C0KM) Karsten W. Rohrbach

Wednesday, 19 September

New vulnerability in IIS4.0/5.0 ALife // BERG
Websphere cookie/sessionid predictable Marc Heuse
Re: New vulnerability in IIS4.0/5.0 Dave Ahmad
Check Point FireWall-1 GUI Log Viewer vulnerability (vuldb 3336) Scott Walker Register
Security Update: [CSSA-2001-SCO.17] OpenServer: vi /tmp vulnerability sco-security
Re: New vulnerability in IIS4.0/5.0 César González
lotus domino server 5.08 is very gabby Frank . Boldewin
Re: New vulnerability in IIS4.0/5.0 C?sar Gonz?lez

Thursday, 20 September

RE: Websphere cookie/sessionid predictable Dawes, Rogan (ZA - Johannesburg)
ICQ WEB Portal multiple Cross Site Scripting vulnerability acz [iSecureLabs]
RE: New vulnerability in IIS4.0/5.0 Microsoft Security Response Center
Vulnerability in SpoonFTP joetesta
Re: lotus domino server 5.08 is very gabby Darren Davison
Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier) Przemyslaw Frasunek
UPDATE - Cisco Security Advisory: Multiple SSH vulnerabilities Cisco Systems Product Security Incident Response Team
Re: Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier) David Terrell
SuSE Security Announcement: wmaker/WindowMaker (SuSE-SA:2001:032) Thomas Biege
Re: Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier) Alexander Yurchenko
Advisory: Half-Life remote buffer overflow vulnerability Stanley G. Bubrouski

Friday, 21 September

MDKSA-2001:078 - uucp update Linux Mandrake Security Team
script to find apache users gabriel maggiotti
squid DoS Vladimir Ivaschenko
IRM Security Advisory: Xcache Path Disclosure Vulnerability advisories
Question about Local vulnerability in libutil derived with FreeBSD. Rumen Telbizov
Re: Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier) Emre Yildirim
Re: New vulnerability in IIS4.0/5.0 Paul McGovern
Re: Question about Local vulnerability in libutil derived with FreeBSD. Seth Arnold
Re: Question about Local vulnerability in libutil derived with FreeBSD. Przemyslaw Frasunek

Saturday, 22 September

Bug in Apache 1.3.20 Server - Hackemate Research Hackemate.com.ar
Response to "Path disclosure vulnerability in Oracle 9i and 8i Application Server" Oracle Security Alerts
3Com OfficeConnect 812/840 Router DoS exploit code Bruno Ratnieks
Re: Bug in Apache 1.3.20 Server - Hackemate Research Grant Kaufmann

Sunday, 23 September

Re: 3Com OfficeConnect 812/840 Router DoS exploit code Raistlin

Monday, 24 September

Release: RATS 1.2 and EGADS 0.7 rats
Re: Question about Local vulnerability in libutil derived with FreeBSD. Rick Kelly
hylafax christer . oberg
Re: hylafax Robert van der Meulen
Intershop4 MegaHz
twlc advisory: all versions of php nuke are vulnerable... supergate
Regarding: 3Com OfficeConnect 812/840 Router DoS exploit code Tom_Kinahan
HACMP and port scans Eoin D. Fleming
Ports list Kurt Seifried
Re: twlc advisory: all versions of php nuke are vulnerable... Magnus Skjegstad
Re: hylafax KF

Tuesday, 25 September

Re: CERT Advisory CA-2001-25 (smap overflow) mod seven
Re: twlc advisory: all versions of php nuke are vulnerable... Magnus Skjegstad
Re: twlc advisory: all versions of php nuke are vulnerable... Paul Starzetz
Re: Regarding: 3Com OfficeConnect 812/840 Router DoS exploit code Raistlin
Re: HACMP and port scans Alex Polli
Re: HACMP and port scans Andrew Leonard
RE: HACMP and port scans Ali, Farrad

Wednesday, 26 September

Re: HACMP and port scans Andreas Siegert
[RHSA-2001:110-05] Insecure setserial initscript bugzilla
Vulnerabilities in QVT/Term joetesta
3Com® HomeConnect® Cable Modem Denial of Service Alex S. Harasic
Re: HACMP and port scans Jordan Klein
Cisco Security Advisory: Cisco Secure PIX Firewall SMTP Filtering Vulnerability Cisco Systems Product Security Incident Response Team
Re: [RHSA-2001:110-05] Insecure setserial initscript Greg Woods
OpenSSH Security Advisory (adv.option) Markus Friedl
Microsoft Security Bulletin MS01-049 Microsoft Product Security

Thursday, 27 September

New CERT/CC PGP key announcement CERT Advisory
Re: Websphere cookie/sessionid predictable Job de Haas
Re: Vulnerabilities in QVT/Term 3APA3A
Intershop 4 is vulnerable to a directory traversal (By Maarten Va n Horenbeeck) Christian Kahlo
format string attack on the alpha systems SeungHyun Seo
JRun 3.0 SP2 Vulnerability?? Kerry Steele

Friday, 28 September

[CLA-2001:427] Conectiva Linux Security Announcement - mod_auth_pgsql secure
[SNS Advisory No.43] PGP Keyserver Permissions Misconfiguration snsadv () lac co jp
CARTSA-2001-03 Meteor FTPD 1.0 Directory Traversal brulez
Two problems with Alexis/InternetPBX from COM2001 Clint Byrum
RE: HACMP and port scans Steven Bishop

Saturday, 29 September

Vulnerability in Amtote International homebet self service wagering system. Gary O'leary-Steele
Re: Websphere cookie/sessionid predictable Arun Kumar
[U] SSRT0758 Compaq Insight Manager Security Advisory Boren, Rich (SSRT)