Firefox Multiple Vulnerabilities - Highly Critical! More about Read More...

Posted on Friday, June 02, 2006 @ 09:13:49 CDT in Security
by Raven

TITLE: Firefox Multiple Vulnerabilities

SECUNIA ADVISORY ID: SA20376

VERIFY ADVISORY: http://secunia.com/advisories/20376/

CRITICAL: Highly critical

IMPACT: Security Bypass, Cross Site Scripting, System access

WHERE: >From remote

SOFTWARE:
Mozilla Firefox 1.x
http://secunia.com/product/4227/
Mozilla Firefox 0.x
http://secunia.com/product/3256/

DESCRIPTION: Multiple vulnerabilities have been reported in Firefox, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system.

1) An error in the sandbox protection of JavaScript run via EvalInSandbox can be exploited to execute arbitrary JavaScript code with escalated privileges by calling the "valueOf()" function on external objects outside of the sandbox. Successful exploitation requires that the attacker is able to execute JavaScript code inside the EvalInSandbox (e.g. via a Proxy Autoconfig script or a third-party extension using the vulnerable functionality).

2) Some errors in the browser engine can be exploited to cause a memory corruption. Successful exploitation may allow execution of arbitrary code.

3) Two errors in the handling of specially crafted HTTP responses in certain situations can be exploited to cause the browser to process a response as two separate responses from different sites. Successful exploitation allows execution of arbitrary HTML and script in a user's browser session in context of an arbitrary site, but requires that the browser is configured to use a proxy or that the malicious site shares the same IP address as the targeted site.

4) Two errors in the handling of the "View Image" and "Show only this frame" functionalities can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site by e.g. tricking a user into right-clicking and choosing "View Image" on a broken image.

5) An error caused due to persisted XUL attributes in certain situations being associated with an incorrect URL can be exploited to execute arbitrary JavaScript code with escalated privileges.

6) An error caused due to content-defined setters on an object prototype being called by privileged code in the user interface can be exploited to execute arbitrary JavaScript code with escalated privileges.

7) An error caused due to an off-by-two array boundary error in the "crypto.signText()" function can be exploited to cause a buffer overflow by passing optional Certificate Authority name arguments.

8) An error exists due to Unicode Byte-order-Mark (BOM) data being stripped from documents served in UTF-8 during the conversion to Unicode. This can be exploited to bypass certain HTML and JavaScript filtering mechanisms in web applications using the UTF-8 character encoding.

9) An error in the processing of the addSelectionListener when handling notifications in certain situations can be exploited to execute arbitrary JavaScript code with escalated privileges.

SOLUTION: Update to version 1.5.0.4.
http://www.mozilla.com/firefox/
 Read More...
 

 

Thunderbird Multiple Vulnerabilities - Highly Critical More about Read More...

Posted on Friday, June 02, 2006 @ 09:03:58 CDT in Security
by Raven

TITLE: Thunderbird Multiple Vulnerabilities

SECUNIA ADVISORY ID: SA20382

VERIFY ADVISORY: http://secunia.com/advisories/20382/

CRITICAL: Highly critical

IMPACT: Security Bypass, Cross Site Scripting, System access

WHERE: >From remote

SOFTWARE:
Mozilla Thunderbird 0.x
http://secunia.com/product/2637/
Mozilla Thunderbird 1.0.x
http://secunia.com/product/9735/
Mozilla Thunderbird 1.5.x
http://secunia.com/product/4652/

DESCRIPTION: Multiple vulnerabilities have been reported in Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system. For more information, see vulnerabilities #1, #2, #3, #5, #6, #7, and #9 in: SA20376. Successful exploitation of some of the vulnerabilities requires that JavaScript is enabled (not enabled by default).

The following vulnerability has also been reported: The vulnerability is caused due to a double-free error within the processing of large VCards with invalid base64 characters. This may be exploited to execute arbitrary code.

SOLUTION: Update to version 1.5.0.4.
http://www.mozilla.com/thunderbird/
 Read More...
 

 
infovision writes:  
Delhi, India, May 31st, 2006,, Deepak Malik, Sr. Vice President InfoVision, addresses the BPO Summit 2006 on 'Tapping the less explored business opportunities'. The fourth BPO Summit was organized by Voice & Data on May 9th, 2006, at Intercontinental-The Park, New Delhi with the theme "Sustaining India's Competitive Edge."Addressing the audience, Deepak Malik discussed how there are new white spaces in the industry & business was coming in from newer economies and newer industry segments. According to Deepak Malik, these new spaces have opened up without the companies focusing on them too much. The discussion revolved around how these new business opportunities could be better tapped and who are the 'associates' of these new businesses likely to be were.

Quoting from the article - InfoVision Group (IVG) independent IT enabled services companies in India with a focus on providing Customer Centric Process Outsourcing (CPO). It is betting on the CRM market for growth. IVG senior VP Deepak Malik said, "The outsourcing CRM opportunity in B2B services is around $40 billion. Crunching data for things like frequent flier, dining card, etc. presents a big opportunity for growth." To read the complete article log on to:
 Read More...
 

 

NukeSentinel(tm) 2.4.2pl7 Released More about

Posted on Friday, June 02, 2006 @ 03:03:13 CDT in NukeSentinel (tm)
by BobMarion

2.4.2pl7 CHANGES (2006-05-31):
+ Updated to compensate for register_globals being turned off.
+ Improved POST and GET checking.
+ Improved ENV variable pick up.

The new version is ready for you to download. This version is primarily two things, stream lining and adjustiong for when register globals is turned off.
 

 

Continuing On With GT-NExtGEn Concept! More about

Posted on Thursday, June 01, 2006 @ 15:43:34 CDT in Code Hacks
by Montego

montego writes:  
Well, after careful consideration and with the seeming "demise" of the GT-NExtGEn website and all support, my intention now is to take over the development for this great concept! I am going to change the name to TegoNuke(tm) ShortURLs and will be incorporating this into the next release of RavenNuke76.

I will also be making a few improvements along the way and adding support here specific to RavenNuke76 as well as for the standalone version on my Montego Scripts site once I also release this to the public as a standalone product. I hope this will end up serving the PHP-Nuke community better. I just hated to see this great tool go unsupported and not improved upon.

Regards,
montego
 

 

israelim.org: - Nuke bridges time, culture and distance - celebrate this! More about

Posted on Thursday, June 01, 2006 @ 15:41:55 CDT in Community
by Montego

nukeevangelist writes:  
Hebrew Translation available [btw: Nuke bridges time, cultures, and distance - let us celebrate this great community]

yesterday we announced the IranNuke.com-community. Well - we have a global community. hebrew Language Pack for PHP-Nuke 7.xx was created by the devs on israelim.org :: in a new article the Hebrew Language Pack for PHP-Nuke 7.xx was announced.

IsraelDeveloper "Hebrew Language to download here for your site you can have a second language in your site! this is a full pack of this language..."

please travel over to israelim.org and get your lang-file now!

Nuke, it is a synonym for a globalwork: Bridging Distance, Culture & Time! the PHPNuke-project has reached a critical mass, now it functions itself as a giant decentraliced mechanism for generating and distributing knowledge. Some of the globally dispersed ressources are gathered togehter - eg at like warp-speed.de
see more ressources:

-warp-speed.de
-phpnukefiles.com
-nukescripts.net
 



Page 311 of 659 (3950 total stories) [ << | < | 306 | 307 | 308 | 309 | 310 | 311 | 312 | 313 | 314 | 315 | 316 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • kguske
  • rjdias
Server TrafficServer Traffic
  • Total: 574,195,590
  • Today: 66,673
Server InfoServer Info
  • Aug 10, 2026
  • 08:22 pm CDT