Gregg's Security News Aggregator

Currently, this "blog" is nothing more than a news aggregator which

gets security information from over 30 sources. As you'll note,

a number of the sources are not specific to security. Advanced

filtering is definitely needed.






Subscribe to "Gregg's Security News Aggregator" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
 

 

Saturday, July 03, 2004
 

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Tiger Slideshow: Pretty Mac OS X Pictures
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability. Juniper routers running JUNOS use a Packet Forwarding Engine (PFE) to forward packets to specified destinations. X-NAS-Bayes: #0: 5.4852E-030; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2472 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Juniper routers running the JUNOS operating system are r...


11:26:24 PM    comment []


10:26:05 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  RDF For Desktop Metadata?

9:25:44 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  EFF Begins Digital Television Liberation Project
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  BugTraq: Re: DLINK 614+ - SOHO routers, system DOS. Sender: Gregory Duchemin [c3rb3r at sympatico dot ca]
3.  Vulns: IBM Lotus Domino IMAP Quota Changing Vulnerability. IBM Lotus Domino server is the e-mail server distributed by Lotus. It is available for the Unix, Linux, and Microsoft operating systems. It contains support for accessin...
4.  Vulns: IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability. Lotus Domino Server is an application framework for web based collaborative software. X-NAS-Bayes: #0: 3.0908E-085; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2469 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Lotus Domino Server is reported prone to a remote denial of service vulnerability....

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
5.  [SECURITY] [DSA 527-1] New pavuk packages fix buffer overflow
6.  Re: DLINK 614+ - SOHO routers, system DOS
7.  [SECURITY] [DSA 526-1] New webmin packages fix multiple vulnerabilities

8:25:23 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Linux Users Are Spoiled
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  Vulns: phpMyAdmin Multiple Input Validation Vulnerabilities. phpMyAdmin is a freely available tool that provides a web interface for handling MySQL administrative tasks. X-NAS-Bayes: #0: 2.2924E-045; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2468 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

phpMyAdmin is prone to multiple vulnerabilities. The issues...

----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Bugtraq: Fix for IE ADODB.Stream vulnerability is out "There is nothing wrong with the functiona...
4.  eWeek: Pop-Up Program Snatches Banking Passwords "The attack is rather complex and appears to us...
5.  Microsoft: Microsoft Statement Regarding Configuration Change to Windows in Response to Download...
6.  Security Focus: Sun Java Runtime Environment Font Object Assertion Failure Denial Of Service Vul...
7.  passcracking.com - "MD5 Online Cracking, using Rainbow Tables"
8.  BugTraq: [SECURITY] [DSA 527-1] New pavuk packages fix buffer overflow
9.  BugTraq: [SECURITY] [DSA 526-1] New webmin packages fix multiple vulnerabilities
10.  TA04-184A: Internet Explorer Update to Disable ADODB.Stream ActiveX Control

7:25:04 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Shannon Plumb's short online films. X-NAS-Bayes: #0: 1.73488E-126; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2467 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

NYC-based Shannon Plumb makes odd little movies with a Super 8 camera, and you can watch them online. Quirky, funky -- like something Jacques Tati and Charlie Chaplin would brainstorm over a drink in a Brooklyn dive bar.

Link (via collette)

2.  New fiction novel features characters who plot to kill the prez. A new, 115-page fiction book from otherwise easygoing author Nicholson Baker features a pair of protagonists who discuss ways to assasinate George W. Bush. To threaten to kill the president in real life is illegal. To explore such a topic in fiction is presumably protected by the First Amendment.
They don't actually do the deed, or even attempt it, but the book is - according to early snippets - replete with deep-seated anger and elegantly nasty epithets hurled at both the President and his cabinet. Mr Baker's publisher, Alfred Knopf, plans to release the book on 24 August, on the eve of the Republican National Convention in New York. To call it a provocation would be an understatement. The author and publishers have no intention of giving anybody ideas - to do so would be a criminal offence - but they are certainly playing very close to the edge in a United States that, in the wake of the 11 September attacks, has shown no compunction about locking people up and asking questions later.

There was no immediate official reaction yesterday after extracts from Checkpoint were published in The Washington Post. A spokesman for the Secret Service, the uniformed outfit charged with protecting the President and other officials, told the Post merely that "without seeing the work, a determination can't be made at this time".

Link (Thanks, Susannah)
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  How Many TV Channels Will There Be In The Future?
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
4.  BugTraq: [SECURITY] [DSA 526-1] New webmin packages fix multiple vulnerabilities. Sender: Matt Zimmerman [mdz at debian dot org]
5.  BugTraq: [SECURITY] [DSA 527-1] New pavuk packages fix buffer overflow. Sender: Matt Zimmerman [mdz at debian dot org]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  Crackers Unleash Spyware Tactics on IE Holes
7.  thttpd Query String URL Non-local Referer Check Bypass
8.  thttpd Double Dot Virtual Host Directory Listing
9.  thttpd Unknown sockaddr Type DoS
10.  MHonArc MIME Filter IMG Tag XSS
11.  MHonArc MIME Header Name XSS
12.  Gentoo esearch eupdatedb Insecure Temporary File Creation

6:24:44 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Dick Cheney "Fuck Yourself" t-shirts, trucker hats. It was inevitable. Get 'em while they last. Link (thanks, SBDC
2.  Knit-your-own edible thong underwear. Only 302 calories, knit 'em yourself from Twizzlers. Dawn Payne, the crafty chick who designed them says: "Like all fine lingerie, these panties are very delicate. Knit gently. If you need your L-string to last longer than a few hours before use, you will need to keep the panties moist. This can be accomplished by wrapping the panties in plastic, or for extended storage needs, spraying with a vegetable oil spray and then wrapping. Adjustable to fit most any consenting adult!" Link (via Fleshbot)
3.  Shannon Plumb's short online films. X-NAS-Bayes: #0: 3.19029E-037; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2466 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

NYC-based Shannon Plumb makes odd little movies with a Super 8 camera, and you can watch them online. Quirky, funky -- like something Jacques Tati and Charlie Chaplin would brainstorm over a drink in a Brooklyn dive bar.

Link (via collette)

4.  Robotic skin. Interesting article about a new design for "electronic skin" as sensitive to touch as our own:

"Recognition of tactile information will be very important for future generations of robots," says Takao Someya at the University of Tokyo who developed the skin. A sense of touch would help them to identify objects, carry out delicate tasks and avoid collisions. But while a lot of effort has gone into vision and voice recognition for robots, touch sensitivity is still fairly rudimentary.

Our own skin contains a battery of touch receptors that produce nerve signals when pressed. For gentle pressures, the main sensors are tiny bulbs of layered tissue called Meissner's corpuscles. Their behaviour is mimicked in plastics such as polyvinylidene fluoride, which generate an electric field when squeezed and are used to make pressure-sensitive pads for computer keyboards and other touch-triggered devices.

Link (via Beverly)

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
5.  FourHead: One PC, Four Users
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
6.  InfoSec Writers: Training Ethical Hackers: Training the Enemy? "Training information security pr...

5:24:23 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Remote Controls On The March
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  InfoSec Writers: Training Ethical Hackers: Training the Enemy? "Training information security pr...
3.  BugTraq: The 3 D's: Demo for the Dullards and Dunces

4:24:04 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  F is for Photoshopped. baddayResearchers at Dartmouth University College have developed an algorithm to automatically detect when a digital photo has been manipulated. Their statistical technique is based on the fact that altering an image messes with the hidden mathematics inside the photo.
"There is little doubt that counter-measures will be developed to foil our detection schemes," says Farid. "Our hope, however, is that as more authentication tools are developed it will become increasingly more difficult to create convincing digital forgeries."
Difficult, but not impossible, hopes the Weekly World News. X-NAS-Bayes: #0: 8.55651E-025; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2464 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

Link

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  A Video Projector That Fits In Your Pocket
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  BugTraq: The 3 D's: Demo for the Dullards and Dunces. Sender: http-equiv at excite dot com [1 at malware dot com]
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  Backdoor.Ranky.H

3:23:44 PM    comment []

----------------------------------------------------------------------
Boing Boing
----------------------------------------------------------------------
1.  Da Vinci coupe. homeToday's New York Times has a feature about how Italian scientists built a working model of "L'automobile di Leonard da Vinci," a self-propelled vehicle powered by a motor made of coiled springs. Pushing the machine backwards or turning the wheels counterclockwise would wind up the motors like a toy car that you pull back and then release. The car has no seats and was designed as a special effects prop for a theatrical production. It's currently on display at the Institute and Museum for the History of Science in Florence.
"While a scale model of the Da Vinci-mobile has been observed... to move, change direction, start and stop - thus proving that the design works - the full-size model weighing hundreds of pounds is seen, even by its own builders, as too hazardous to set loose on an unsuspecting public."
Link (free NYT reg. required)
2.  Fuck direct quotes. Kudos to the Washington Post for being the only newspaper to actually spell out the word "fuck" when it came from Dick Cheney's lips last week. The LA Weekly has a survey of the substitutions: X-NAS-Bayes: #0: 3.38005E-196; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2463 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

The Boston Globe: Referred to the expletive as a “vulgar directive” and provided no other clues.

Calgary Sun: “(Bleep) off” or “Go (bleep) yourself.”

Daily News (New York): “Go f— yourself.”

Link
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Oracle's chances improve at trial (SiliconValley.com). SiliconValley.com - After a four-week antitrust trial, Oracle's chances of winning the court fight that would let it pursue PeopleSoft appear far better than at the outset, said several legal and industry observers.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
4.  Online MD5 Cracking Service
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
5.  BugTraq: Cart32 Input Validation Flaw in 'GetLatestBuilds?cart32=' Permits Remote Cross-Site Scripting Attacks. Sender: Dr Ponidi [drponidi at hackermail dot com]
6.  Vulns: Multiple Vendor FTP pipe Vulnerability. There is a feature implementation in a number of ftp clients shipped with unix operating systems that may be a security threat.

This issue has to do with handling filena...

7.  Vulns: Juniper JUNOS Packet Forwarding Engine IPv6 Denial of Service Vulnerability. Juniper routers running JUNOS use a Packet Forwarding Engine (PFE) to forward packets to specified destinations.

Juniper routers running the JUNOS operating system are r...

8.  Vulns: Common Desktop Environment DTLogin XDMCP Parser Remote Double Free Vulnerability. The dtlogin application is implemented with the Common Desktop Environment (CDE) that implements the X-Display Manager Control Protocol (XDMCP). The dtlogin process make...
9.  Vulns: RSBAC Jail SUID And SGID File Creation Vulnerability. Rule Set Based Access Control (RSBAC) is a free Linux kernel security extension. It implements many security modules, including mandatory access controls, access control ...
10.  Vulns: New Atlanta ServletExec Unauthorized Access Vulnerability. ServletExec is a Java-based web application server designed for various operating systems; this issue is reported to affect versions implemented on Windows 2000 and Windo...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
11.  Microsoft Plugs IE; Report Warns All Browsers At Risk (TechWeb)
12.  BugTraq: Re: [Full-Disclosure] Fix for IE ADODB.Stream vulnerability is out
13.  BugTraq: THE INSIDER VULNERABILITY STILL WORKS AFTER TODAY'S PATCH
14.  Vulns: OpenSSL Denial of Service Vulnerabilities
15.  Vulns: LibPNG Broken PNG Out Of Bounds Access Denial Of Service Vulnerability
16.  Vulns: Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
17.  Vulns: Invision Power Board SSI.PHP SQL Injection Vulnerability

2:23:25 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  Seagate Accuses Cornice of Patent Infringement
2.  ACM Eyes Policy Position on Electronic Voting
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
3.  BugTraq: Re: [Full-Disclosure] Fix for IE ADODB.Stream vulnerability is out. Sender: http-equiv at excite dot com [1 at malware dot com]
4.  BugTraq: THE INSIDER VULNERABILITY STILL WORKS AFTER TODAY'S PATCH. Sender: [liudieyu at umbrella dot name]
5.  Vulns: OpenSSL Denial of Service Vulnerabilities. Three security vulnerabilities have been reported to affect OpenSSL. Each of these remotely exploitable issues may result in a denial of service in applications which us...
6.  Vulns: LibPNG Broken PNG Out Of Bounds Access Denial Of Service Vulnerability. The libpng graphics library is reported to be prone to a denial of service vulnerability when handling certain types of broken images. Specifically, the issue presents it...
7.  Vulns: OpenSSL ASN.1 Parsing Vulnerabilities. Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. OpenSSL does not directly implement ASN.1 but does use ASN.1 objects in X.509 certificates a...
8.  Vulns: Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability. Open WebMail is an open-source web mail package written in Perl. X-NAS-Bayes: #0: 9.4675E-091; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2462 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A vulnerability is reported in Open WebMail that allows a remote attacker to execute arbitrary commands ...

9.  Vulns: Invision Power Board SSI.PHP SQL Injection Vulnerability. Invision Power Board is web forum software. It is implemented in PHP and is available for Unix and Linux variants and Microsoft Windows operating systems.

Invision Powe...


1:23:03 PM    comment []

----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
1.  No trophy for cell phone at Wimbledon. Maria Sharapova upsets the defending champ at tennis tourney, but can't overcome tech hurdle.
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
2.  BugTraq: Enterasys XSR Security Routers DoS. Sender: Frederico Queiroz [fqueiroz at ish dot com dot br]
3.  BugTraq: Registry Fix For Variant of Scob. Sender: Drew Copley [dcopley at eEye dot com]
4.  BugTraq: RE: [Full-Disclosure] THE VULNERABILITY STILL WORKS AFTER TODAY'S PATCH. Sender: Jelmer [jkuperus at planet dot nl]
5.  Vulns: HP-UX Netscape Browser Multiple Vulnerabilities. HP-UX Netscape browser is reported prone to multiple vulnerabilities. These vulnerabilities can allow a remote attacker to carry out attacks such as denial of service, i...

12:22:44 PM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  China Deploys IPv9 Network
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Microsoft IE Security Storm Builds (NewsFactor)
3.  Microsoft Pushes OS Updates (PC World)

11:22:24 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Warning over cash machine fraud. Thousands of bank customers are being warned to limit their use of cash machines because of the growing risk of fraud.
----------------------------------------------------------------------
CNET News.com
----------------------------------------------------------------------
2.  Microsoft's patchwork mess. ZDNet's David Berlind explains why a sometimes infuriatingly complicated patch process reveals both timing flaws and potential vulnerabilities in Microsoft's thinking.
----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
3.  Netflix Shares Drop on Subscriber Shortfall (Reuters). Reuters - Shares of Netflix Inc. (NFLX.O) were off 10 percent in Friday morning trading on disappointment over the online DVD renter's second-quarter subscriber growth.
4.  'Riddick' Revels in Butchery, Profanity (Reuters). Reuters - In the flourishing forest of computerized adventures, game developers are always looking for something new to make their product stand out.
5.  iMac Computer Delay Drops Apple Shares (Reuters). Reuters - Shares of Apple Computer Inc. (AAPL.O) fell as much as 8 percent on Friday, a day after the maker of personal computers and music players delayed the introduction of its newest iMac computer until after the crucial back-to-school season.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
6.  On PHP and Scaling
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
7.  Vulns: Sun Java Runtime Environment Font Object Assertion Failure Denial Of Service Vulnerability. The Java Runtime Environment (JRE) is the virtual Java platform on which all Java applications are run. It is provided by Sun Microsystems for a number of platforms, incl...
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
8.  Only antivirus firms will survive Earth's predicted demise

10:22:04 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  Bush and Kerry sites 'not secure'. A respected US net privacy advocate uncovers privacy holes in the main presidential candidates' websites.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  Fedora: 2,1: mailman Password leak vulnerability
3.  Fedora: 2,1: kernel Privilege change vulnerability
4.  FreeBSD: kernel Improper memory access vulnerability
5.  Gentoo: Esearch Insecure temp file vulnerability
6.  Fedora: 1: rsync Path escape vulnerability
7.  TA04-184A: Internet Explorer Update to Disable ADODB.Stream ActiveX Control

8:21:24 AM    comment []

----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
1.  How Much Java in the Linux World?
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
2.  CHM_PSYME.B
3.  Lieberman rips DHS wireless

7:21:05 AM    comment []

----------------------------------------------------------------------
Wired News
----------------------------------------------------------------------
1.  Paranoia Goes Better With Coke. A promotional campaign that features special Coke cans containing cell phones and GPS chips has the military obsessing over possible security leaks. Coca-Cola shrugs it off, but the generals aren't kidding, apparently.
2.  A Lively Open-Source Debate. The assumption that all programmers are open-source advocates falls flat at Sun's 'Big Question' debate. In fact, they're pretty well split on the subject. By Michelle Delio.
3.  Oxygen Bursts in Saturn's Rings. Something's going on in Saturn's outermost rings, where oxygen levels jump explosively then diminish over a month. One theory is crashing moonlets. Amit Asaravala reports from Pasadena, California.
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
4.  IBM Informix I-Spy 'runbin' Lets Local Users Grab Root Privileges

6:20:44 AM    comment []

----------------------------------------------------------------------
BBC News | Technology | UK Edition
----------------------------------------------------------------------
1.  When games collide with movie makers. The film industry is becoming more interested in gaming, says Daniel Etherington of BBC Collective.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  Traffic Sim Predicts Jams Before They Happen
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  Iraq courts risks in trying Hussein
4.  Easy Chat Server Can Be Crashed With Long 'username' Or Multiple Fake Users

5:20:23 AM    comment []

----------------------------------------------------------------------
Dilbert
----------------------------------------------------------------------
1.  Dilbert for 03 Jul 2004.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
2.  China Will Monitor, Censor SMS Messages
----------------------------------------------------------------------
NewsIsFree: Security
----------------------------------------------------------------------
3.  McAfee: New Lovegate worm spreading
4.  Microsoft pushes OS updates to fight attacks
5.  BKDR_REVACC.F
6.  BKDR_RICCAIRA.A
7.  Secunia: Red Hat update for kernel | Fedora update for kernel | Linux Kernel File Group ID Manip...
8.  US CERT: TA04-184A - Internet Explorer Update to Disable ADODB.Stream ActiveX Control "Microsoft...
9.  eWeek: eWeek: IE Users, Proceed with Caution—If at All "With more exploits popping up every day,...
10.  Computer Weekly: Security statistics show surprising finds "The Micorsoft Windows application is...

4:20:03 AM    comment []


3:19:44 AM    comment []

----------------------------------------------------------------------
Ars Technica
----------------------------------------------------------------------
1.  Microsoft plugs IE ActiveX hole. Microsoft plugs an IE ActiveX hole that was used by attackers to infect web surfer's computers with a keystroke logging trojan. By Fred "zAmboni" Locklear.
2.  Cassini's hazy encounter with Titan. Photos from Friday's fly-by of Titan disappoint NASA scientists. They are hopeful that further processing will uncover details of the hazy moon's surface. By Fred "zAmboni" Locklear.
----------------------------------------------------------------------
Slashdot
----------------------------------------------------------------------
3.  NVidia Releases Linux Drivers Supporting 4K Stacks
----------------------------------------------------------------------
SecurityFocus Vulns
----------------------------------------------------------------------
4.  Vulns: LibPNG Incorrect Offset Calculation Buffer Overflow Vulnerability. The libpng graphics library may incorrectly calculate some offsets when creating or modifying PNG files. This vulnerability has been reported when manipulating 16-bit sam...
5.  Vulns: Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow Vulnerability. Apache Web server includes a proxying module (mod_proxy) to provide a proxy/cache for FTP, HTTP, and SSL. X-NAS-Bayes: #0: 4.6184E-084; #1: 1 X-NAS-Classification: 0 X-NAS-MessageID: 2451 X-NAS-Validation: {E681C936-E9F0-4DDC-9901-74301AF33E67}

A remote buffer overflow vulnerability exists in Apache mod_pro...

6.  Vulns: Pavuk Remote Stack-Based Buffer Overrun Vulnerability. Pavuk is a UNIX utility that is used to mirror contents of WWW documents or files.

Pavuk is reported prone to a remote buffer overrun vulnerability. It is reported that ...


2:19:23 AM    comment []

----------------------------------------------------------------------
Yahoo! News - Technology
----------------------------------------------------------------------
1.  Sony Debuts 20 Gigabyte Walkman to Silence IPod (Reuters). Reuters - Sony Corp. said on Thursday it is launching a Walkman digital music player capable of storing far more songs than Apple Computer Inc.'s market-leading iPod, while also undercutting iPod's price.

12:11:53 AM    comment []


Click here to visit the Radio UserLand website. © Copyright 2004 Gregg Doherty.
Last update: 7/26/2004; 12:30:12 AM.
This theme is based on the SoundWaves (blue) Manila theme.
July 2004
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jun   Aug