 | News Feed |
 | Jobs Feed |
Sections
|
| feed this: |  |
Community News: Avaya Products PHP Multiple Vulnerabilities
by Chris Cornutt November 06, 2007 @ 07:56:00
As mentioned in this new security advisory from Avaya, there's a risk that the PHP version included with their Messaging systems could provide a hole for a would-be attacker to gain access.
Issues have been reported in the following:
- integer overflow vulnerabilities in the PHP gd extension
- integer overflow vulnerability in the PHP chunk_split function
- a security update has introduced a bug into PHP session cookie handling
- vulnerability in the PHP money_format function
- vulnerability in the PHP wordwrap function
- vulnerability in PHP session cookie handling
- vulnerability in the PHP gc extension
The advisory contains links to more information from RedHat on these issues and includes a list of systems effected as well as recommended actions to take.
voice your opinion now!
secunia advisory avaya security messaging secunia advisory avaya security messaging
Secunia.com: rPath Update for Multiple php Packages
by Chris Cornutt September 18, 2007 @ 07:51:00
According to this new advisory on the Secunia website, rPath has updated more of their PHP packages and has marked the update as "moderately critical" to keeping your systems safe.
rPath has issued an update for multiple php packages. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious, local users and malicious users to bypass certain security restrictions.
The original advisory has links to the updated versions and to references as to what has changed.
In its default configuration, rPath Linux 1 does not install php5 and is thus not vulnerable to these attacks; however, systems to which php5 has been added may be vulnerable to one or more of these attacks.
voice your opinion now!
secunia rpath update package php5 critical secunia rpath update package php5 critical
Secunia.com: Joomla! Multiple Vulnerabilities
by Chris Cornutt July 30, 2007 @ 10:26:00
Secunia.com reports that multiple vulnerabilities have been found in the Joomla! content management system:
Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct session fixation attacks, cross-site scripting attacks or HTTP response splitting attacks.
The issues are marked as "less critical" but users should still update to the latest version to avoid these issues:
- Certain unspecified input passed in com_search, com_content and mod_login is not properly sanitised before being returned to a user
- Input passed to the "url" parameter is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers.
- An error exists in the handling of sessions and can be exploited to hijack another user's session by tricking the user into logging in after following a specially crafted link.
See the original advisory post here.
voice your opinion now!
joomla content management cms vulnerability secunia joomla content management cms vulnerability secunia
|
Community Events
Don't see your event here? Let us know!
|