<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Multiple Vendors libc fnmatch 3  DoS</title><description>2011-05-13 01:30:08 - SecurityReason IT News : Author   SecurityReason New advisory about vulnerabilities in libc for multiple vendors  Multiple Vendors libc fnmatch 3  DoS  incl apache  A 'resource exhaustion' vulnerability has been identified in fnmatch 3  function Attacker, what may modify first and second parameters pattern,string  of fnmatch 3 , may cause to CPU resource exhaustion More  http securityreasoncom achievement_securityalert 98 Exploit  http cxibnet stuff apr_fnmatchtxt References  http cvswebnetbsdorg bsdwebcgi src lib libc gen fnmatchc https rhnredhatcom errata RHSA-2011-0507html http httpdapacheorg security vulnerabilities_22html http wwwapacheorg dist apr CHANGES-APR-14 http cwemitreorg data definitions 399html  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/304441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/304441.shtml</guid></item>
<item><title>PHP 533 Null Pointer Dereference</title><description>Secuobs.com : 2011-03-09 22:47:39 - SecurityReason IT News - Author   SecurityReason SecurityReason realised new advisory about vulnerabilities in PHP 533 and PHP 5214  PHP 533 5214 ZipArchive getArchiveComment NULL Pointer Deference  The main problem exist in function ZipArchive getArchiveComment  More  http securityreasoncom achievement_securityalert 90 Fix 52  http svnphpnet viewvc php php-src branches PHP_5_2 ext zip php_zipc Fix 53  http svnphpnet viewvc php php-src branches PHP_5_3 ext zip php_zipc MDVSA-2010 218 http listsmandrivacom security-announce 2010-10 msg00044php </description><link>http://www.secuobs.com/revue/news/290558.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/290558.shtml</guid></item>
<item><title>vsftpd flaw could disable wide range of servers</title><description>Secuobs.com : 2011-03-01 01:18:16 - SecurityReason IT News - Author   SecurityReason New advisory about vulnerability in vsftpd server  vsftpd 232 remote denial-of-service  A 'resource exhaustion' vulnerability has been identified in lsc file The potential scale of risk is high Examples of vulnerable servers  - ftpgnuorg - ftpkernelorg - ftpgenwip4adobecom - ftporaclecom - ftpfreebsdorg Any code with huge complexity, could allow of denial of service if an affected system received vulnerable pattern More  http securityreasoncom achievement_securityalert 95 Exploit  http cxibnet stuff vspoc232c Fix for this issue has been created together with vsftpd projects ChangeLog  ftp vsftpdbeastsorg users cevans untar vsftpd-234 Changelog  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/288336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/288336.shtml</guid></item>
<item><title>GNU libc Multiple Vulnerabilities</title><description>Secuobs.com : 2011-01-07 22:03:12 - SecurityReason IT News - Author   Maksymilian Arciemowicz New advisory about vulnerabilities in GNU libc  GNU libc regcomp 3  Multiple Vulnerabilities  A 'resource exhaustion' vulnerabilities has been identified in GNU C library exploit  http cxibnet stuff proftpdgnuc Exploit can be used to attack some proftpd servers with wirtting privialges More  http securityreasoncom achievement_securityalert 93 http wwwkbcertorg vuls id 912279  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/276672.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/276672.shtml</guid></item>
<item><title>Apache Insecure mod_rewrite PCRE Resource Exhaustion</title><description>Secuobs.com : 2010-12-21 02:52:16 - SecurityReason IT News - Author   Maksymilian Arciemowicz New advisory about vulnerabilities in apache mod_rewrite  Apache Insecure mod_rewrite PCRE Resource Exhaustion  A 'resource exhaustion' vulnerability has been identified in PCRE library Using mod_rewrite and PCRE libs can dangerous for stability apache server Everybody know that using pcre regular expressions can be dangerous, and using multiple regular expressions in htaccess is no good idea More  http securityreasoncom achievement_securityalert 92 PoC  http cxibnet stuff rewritepcretxt  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/273245.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273245.shtml</guid></item>
<item><title>PHP 533 Null Pointer Deference</title><description>Secuobs.com : 2010-11-06 16:11:51 - SecurityReason IT News - Author   SecurityReason SecurityReason realised new advisory about vulnerabilities in PHP 533 and PHP 5214  PHP 533 5214 ZipArchive getArchiveComment NULL Pointer Deference  The main problem exist in function ZipArchive getArchiveComment  More  http securityreasoncom achievement_securityalert 90 Fix 52  http svnphpnet viewvc php php-src branches PHP_5_2 ext zip php_zipc Fix 53  http svnphpnet viewvc php php-src branches PHP_5_3 ext zip php_zipc MDVSA-2010 218 http listsmandrivacom security-announce 2010-10 msg00044php  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/262964.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/262964.shtml</guid></item>
<item><title>New issues in libc glob 3  with PoC for ftpd servers </title><description>Secuobs.com : 2010-10-07 10:56:58 - SecurityReason IT News - Author   SecurityReason New advisory about vulnerabilities in libc for multiple vendors  Multiple Vendors libc glob 3  resource exhaustion  0day remote ftpd-anon  A 'resource exhaustion' vulnerability has been identified in GLOB_LIMIT flags 0day exploit  http cxibnet stuff glob-0dayc Similar Exploit has been used to attack ftpopenbsdorg and ftpnetbsdorg  02072010  Several hours after the attack, we informed NetBSD and OpenBSD projects about new vulnerabilities in libc glob 3  GLOB_LIMIT flag don't give control over the computing power in glob 3  and good fix for this issue, should control, how many times glob 3  will call to  readdirfunc , stat 2  and reducing memory usage The potential scale of risk is high Examples of vulnerable servers  - ftpopenbsdorg  verified 02072010  connection refused  - ftpnetbsdorg  verified 02072010  connection limit of 160 reached  - ftpfreebsdorg - ftpadobecom - ftphpcom - ftpsuncom Fix for this issue has been created together with NetBSD projects Fix libc globc for netbsd-4,netbsd-5 branches  http cvswebbenetbsdorg cgi-bin cvswebcgi src lib libc gen globc rev118101 http cvswebbenetbsdorg cgi-bin cvswebcgi src lib libc gen glob3 rev130121 Fix for openssh  sftp  http cvswebbenetbsdorg cgi-bin cvswebcgi src crypto dist ssh Attic sftpc rev12161 http cvswebbenetbsdorg cgi-bin cvswebcgi src crypto dist ssh Attic sftp-globc rev113121 More  http securityreasoncom securityalert 7822 http ftpnetbsdorg pub NetBSD security advisories NetBSD-SA2010-008txtasc  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/255007.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/255007.shtml</guid></item>
<item><title>Race Condition in FreeBSD 81 73 with PoC</title><description>Secuobs.com : 2010-09-17 02:31:05 - SecurityReason IT News - Author   SecurityReason New advisory about vulnerabilities in FreeBSD kernel A race condition vulnerability has been identified in pmap To the successive attack is needed to run parallel PoC with the different users To bypass the MAXPROC from loginconf, we can use a few users to run PoC in this same time, to reach kernmaxproc suphp can be very usefully PoC  http securityreasoncom achievement_exploitalert 16 More about this issue  http securityreasoncom achievement_securityalert 88  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/248416.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/248416.shtml</guid></item>
<item><title>libopie __readrec  off-by one  FreeBSD ftpd remote PoC </title><description>Secuobs.com : 2010-05-27 13:28:08 - SecurityReason IT News - Author   SecurityReason New advisory about vulnerabilities in OPIE Authentication System  libopie __readrec  off-by one  FreeBSD ftpd remote PoC  This advisory is related to new FreeBSD advisory FreeBSD-SA-10 05opie A off-by one vulnerability has been identified in ftpd deamon More  http securityreasoncom achievement_securityalert 87 http securityfreebsdorg advisories FreeBSD-SA-10 05opieasc http blogpi3compl p 111 http securityreasoncom exploitalert 8294  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/226243.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/226243.shtml</guid></item>
<item><title>Sun Solaris 10 Multiple Vulnerabilities</title><description>Secuobs.com : 2010-05-21 15:59:00 - SecurityReason IT News - Author   SecurityReason Our team is pleased to present another security notes of Sun Solaris 10  ftpd Cross-site request forgery ,  filesystem rm 1 ,find 1 ,etc, Denial-of-service  and  libc convert  cvt  buffer overflow  A buffer overflow vulnerability has been identified in function ecvt 3  from libc library More functions are also affected Description of  libc convert  cvt  buffer overflow  http securityreasoncom achievement_securityalert 86 Description of  filesystem rm 1 ,find 1 ,etc, Denial-of-service  http securityreasoncom achievement_securityalert 85 Description of  ftpd Cross-site request forgery  http securityreasoncom achievement_securityalert 84  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/224429.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/224429.shtml</guid></item>
<item><title>MacOS X 1063 filesystem hfs Denial of Service Vulnerabilitys</title><description>Secuobs.com : 2010-04-23 02:49:00 - SecurityReason IT News - Author   Maksymilian Arciemowicz New advisory about vulnerabilitys in file system hfs for MacOSX 106 Operating Systems  MacOS X 1063 filesystem hfs Denial of Service Vulnerability  The problem came, when we create a special structure with hardlinks In 106 we can't use ln 1  command to create hardlink to directory Anyway, we can use link 3  function and we don't need any special privileges More  http securityreasoncom achievement_securityalert 83 PoC  http securityreasoncom achievement_exploitalert 15  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/215163.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215163.shtml</guid></item>
<item><title>Security Notes for MacOS X, Matlab, and J</title><description>Secuobs.com : 2010-01-08 02:01:47 - SecurityReason IT News - Author   SecurityReason Team Our team is pleased to release a new security notes for applications such as Matlab and J In addition, a buffer overflow vulnerability has been diagnosed in libc gdtoa All vulnerability related to the same issue in gdtoa, discovered in the standard MacOS X C language library in functions atof  3 , strtod  3  The example, using the printf 1 , as shown in Multiple Vendors libc   gdtoa printf  3  Array Overrun  URLstart  http securityreasoncom achievement_securityalert 63  URLend  does not reflect the fact that there is faulty gdtoa in MacOS X The vulnerability exists and we can see it when we put a long string as a parameter of function atof  char   wsk  Often in many applications, the possibility of introducing such a long string is limited, but practical use of this issue is proved and reported to the Apple team Notes related to application MatLab and J, describes the problem of issue in the gdtoa library MacOS X 105 106 Note  http securityreasoncom achievement_securityalert 81 Matlab Note  http securityreasoncom achievement_securityalert 80 J 602023 Note  http securityreasoncom achievement_securityalert 79  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/179438.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179438.shtml</guid></item>
<item><title>PHP 5212 Released unpatched</title><description>Secuobs.com : 2009-12-19 02:11:38 - SecurityReason IT News - Author   Maksymilian Arciemowicz In 17 December 2009 PHP Team have released new PHP version 5212 We have tested this version and now we can say, that not all issues has been fixed It is possible localy bypass safe_mode and open_basedir Security Note  http securityreasoncom achievement_securityalert 70 is still available in the latest versions of PHP Exploit  http securityreasoncom achievement_exploitalert 14  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/174163.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/174163.shtml</guid></item>
<item><title>New Security Notes for  Thunderbird, Camino, Sunbird and Flock</title><description>Secuobs.com : 2009-12-11 04:10:37 - SecurityReason IT News - Author   SecurityReason Our team is pleased to present another security notes of products such as Thuderbird, Camino, Sunbird and Flock Identified vulnerability, originally was discovered in May this year, however, a list of all vendors using gdtoa faulty implementations, it is not yet closed Today we added new affected products to the list Mozilla team released Thunderbird 3, that's fixes the problem with this vulnerability However the user is not forced to install new thunderbird 3 There will be new version of Thunderbird 2 - 20024 , that's fixes this issue Thunderbird 20024pre  http ftpmozillaorg pub mozillaorg thunderbird nightly latest-mozilla18  Thunderbird Note  http securityreasoncom achievement_securityalert 78 Sunbird Note  http securityreasoncom achievement_securityalert 77 Camino Note  http securityreasoncom achievement_securityalert 76 Flock Note  http securityreasoncom achievement_securityalert 75  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/170867.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/170867.shtml</guid></item>
<item><title>glibc holes for years</title><description>Secuobs.com : 2009-11-20 12:36:43 - SecurityReason IT News - Author   Maksymilian Arciemowicz Many people aren't aware of the danger of using glibc Many issues from other libc libraries are undiagnosed in glibc In March 2008, our team has released an official note about security bug in the function strfmon  from BSD libc Problem was officially diagnosed in the FreeBSD, NetBSD and MacOS We have tried to inform the GNU team about the existing problems Official note  http securityreasoncom achievement_securityalert 67 Description note  http xorlwordpresscom 2009 04 11 cve-2008-1391-netbsd-strfmon-integer-overflow   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/163390.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163390.shtml</guid></item>
<item><title>New vulnerabilities in libc fts 3 </title><description>Secuobs.com : 2009-11-20 12:36:43 - SecurityReason IT News - Author   Maksymilian Arciemowicz New advisory about vulnerabilities in libc for OpenBSD and NetBSD products  libc fts_  Multiple Denial of Service  A Integer Overflow vulnerability has been identified in march 2009 In March 2009, we have reported an issue  SREASONRES 20090304  in libc  ftsc  Now we want to present the conclusions and show the usefulness of this vulnerability More  http securityreasoncom achievement_securityalert 68  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/163389.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163389.shtml</guid></item>
<item><title>Multiple BSD printf 1  and multiple dtoa printf 3  vulnerabilities</title><description>Secuobs.com : 2009-11-20 12:36:43 - SecurityReason IT News - Author   SecurityReason New advisory about vulnerabilities in libc gdtoa and printf 1  for BSD Operating Systems  Multiple BSD printf 1  and multiple dtoa printf 3  vulnerabilities  A buffer overflow vulnerability has been identified in printf 1  More  http securityreasoncom achievement_securityalert 69  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/163388.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163388.shtml</guid></item>
<item><title>Update  False Security Advisory from Mozilla</title><description>Secuobs.com : 2009-11-20 12:36:43 - SecurityReason IT News - Author   SecurityReason In last week, the Mozilla team released a new security notes for Firefox We were able to prove that one note was falsified In June this year, our team published a security advisory about libc We had indications that other projects  software  also are affected At the end of September, the Google Chrome Team, gave a security note about this problem http googlechromereleasesblogspotcom 2009 09 stable-channel-update_30html They met with criticism because of slow patching this issue However, the Firefox developers have decided to avoid bad comments They Released a note MFSA 2009-59 - http wwwmozillaorg security announce 2009 mfsa2009-59html Firefox team maintains that the flaw was published, detected by the Secunia Research Team It would not be any problem in that if the PoC  Proof of Concept  was available since June Many months ignoring the vulnerability contributed to the exposure of millions Firefox users giving potential attackers full control over their computer To the confusion, officially acknowledged a portal Secuniacom An interesting element is the lack of use of the module name  dtoa  in which the error was detected Link to a false note  http wwwmozillaorg security announce 2009 mfsa2009-59html Link to PoC  http securityreasoncom achievement_securityalert 63 Below there is source code of changes that were made for Security Advisory MFSA 2009-59   http bonsaimozillaorg cvsview2cgi diff_mode context whitespace_mode show file jsdtoac branch root cvsroot subdir mozilla js src command DIFF_FRAMESET rev1 341 rev2 342 Here we present fix for libc library   http wwwopenbsdorg cgi-bin cvsweb src lib libc gdtoa miscc annotate 12 More details   http wwwsecurity-databasecom detailphp alert CVE-2009-1563 - informations about Vulnerability, reference in Bugzilla http bonsaimozillaorg cvslogcgi file mozilla js src jsdtoac rev HEAD mark 343 - informations about fix from Bugzilla number 516862, related to Secunia Research Team At the end of this news we inform that we published new advisory about vulnerabilities in libc for BSD Operating Systems  Multiple Vendors libc gdtoa printf 3  Array Overrun  A Array Overrun vulnerability has been identified in new gdtoa implementation in libc library http securityreasoncom achievement_securityalert 69 Update   Mozilla Team updated the Mozilla Foundation Security Advisory 2009-59 adding note    The underlying flaw in the dtoa routines used by Mozilla appears to be essentially the same as that reported against the libc gdtoa routine by Maksymilian Arciemowicz   CVE-2009-0689  Secunia also updated their advisory   http secuniacom advisories 36711 2  adding note    1    Reported in libc by Maksymilian Arciemowicz of SecurityReason   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/163387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163387.shtml</guid></item>
<item><title>New security notes for KDE, Opera, SeaMonkey and K-Meleon</title><description>Secuobs.com : 2009-11-20 12:36:43 - SecurityReason IT News - Author   SecurityReason Team Our team is pleased to present a new security notes of products such as KDE, Opera, SeaMonkey and K-Meleon Identified vulnerability, originally was discovered in May this year in the standard C library The problem concerns the implementation gdtoa defective Currently, our team is at the phase of determining all possible vendors Array index error allows remote attackers to execute arbitrary code via a long string that triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number Until now, the security official notes were released by Chrome and Mozilla Teams Chrome Note  http googlechromereleasesblogspotcom 2009 09 stable-channel-update_30html Mozilla Note  http wwwmozillaorg security announce 2009 mfsa2009-59html SecurityReason Research advisories   http securityreasoncom achievement_securityalert 71 http securityreasoncom achievement_securityalert 72 http securityreasoncom achievement_securityalert 73 http securityreasoncom achievement_securityalert 74  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/163386.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/163386.shtml</guid></item>
</channel>
</rss>
 
