Contribuez à SecuObs en envoyant des bitcoins ou des dogecoins.
Nouveaux articles (fr): 1pwnthhW21zdnQ5WucjmnF3pk9puT5fDF
Amélioration du site: 1hckU85orcGCm8A9hk67391LCy4ECGJca

Contribute to SecuObs by sending bitcoins or dogecoins.

Chercher :
Newsletter :  


Revues :
- Presse
- Presse FR
- Vidéos
- Twitter
- Secuobs





Sommaires :
- Tendances
- Failles
- Virus
- Concours
- Reportages
- Acteurs
- Outils
- Breves
- Infrastructures
- Livres
- Tutoriels
- Interviews
- Podcasts
- Communiques
- USBsploit
- Commentaires


Revue Presse:
- Tous
- Francophone
- Par mot clé
- Par site
- Le tagwall


Top bi-hebdo:
- Ensemble
- Articles
- Revue
- Videos
- Twitter
- Auteurs


Articles :
- Par mot clé
- Par auteur
- Par organisme
- Le tagwall


Videos :
- Toutes
- Par mot clé
- Par site
- Le tagwall


Twitter :
- Tous
- Par mot clé
- Par compte
- Le tagwall


Commentaires :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS/XML :
- Articles
- Commentaires
- Revue
- Revue FR
- Videos
- Twitter


RSS SecuObs :
- sécurité
- exploit
- windows
- attaque
- outil
- microsoft


RSS Revue :
- security
- microsoft
- windows
- hacker
- attack
- network


RSS Videos :
- curit
- security
- biomet
- metasploit
- biometric
- cking


RSS Twitter :
- security
- linux
- botnet
- attack
- metasploit
- cisco


RSS Comments :
- Breves
- Virus
- Failles
- Outils
- Tutoriels
- Tendances
- Acteurs
- Reportages
- Infrastructures
- Interviews
- Concours
- Livres
- Communiques


RSS OPML :
- Français
- International











Revue de presse francophone :
- Appaloosa AppDome nouent un partenariat pour accompagner les entreprises dans le déploiement et la protection des applications mobiles
- D-Link offre une avec un routeur VPN sans fil AC
- 19 mai Paris Petit-Déjeuner Coreye Développer son business à l'abri des cyberattaques
- POYNTING PRESENTE LA NOUVELLE ANTENNE OMNI-291, SPECIALE MILIEU MARITIME, CÔTIER ET MILIEU HUMIDE
- Flexera Software Les utilisateurs français de PC progressent dans l'application de correctifs logiciels, mais des défis de tailles subsistent
- Riverbed lance SD-WAN basé sur le cloud
- Fujitsu multi-récompensé VMware lui décerne plusieurs Partner Innovation Awards à l'occasion du Partner Leadership Summit
- Zscaler Private Access sécuriser l'accès à distance en supprimant les risques inhérents aux réseaux privés virtuels
- QNAP annonce la sortie de QTS 4.2.1
- Une enquête réalisée par la société de cyber sécurité F-Secure a décelé des milliers de vulnérabilités graves, potentiellement utilisables par des cyber criminels pour infiltrer l'infrastru
- Trouver le juste équilibre entre une infrastructure dédiée et cloud le dilemme de la distribution numérique
- 3 juin - Fleurance - Cybersécurité Territoires
- Cyber-assurances Seules 40 pourcents des entreprises françaises sont couvertes contre les violations de sécurité et les pertes de données
- Des étudiants de l'ESIEA inventent CheckMyHTTPS un logiciel qui vérifie que vos connexions WEB sécurisées ne sont pas interceptées
- Les produits OmniSwitch d'Alcatel-Lucent Enterprise ALE gagnent en sécurité pour lutter contre les cyber-attaques modernes

Dernier articles de SecuObs :
- DIP, solution de partage d'informations automatisée
- Sqreen, protection applicative intelligente de nouvelle génération
- Renaud Bidou (Deny All): "L'innovation dans le domaine des WAFs s'oriente vers plus de bon sens et d'intelligence, plus de flexibilité et plus d'ergonomie"
- Mises à jour en perspective pour le système Vigik
- Les russes ont-ils pwn le système AEGIS ?
- Le ministère de l'intérieur censure une conférence au Canada
- Saut d'air gap, audit de firmware et (in)sécurité mobile au programme de Cansecwest 2014
- GCHQ: Le JTRIG torpille Anonymous qui torpille le JTRIG (ou pas)
- #FIC2014: Entrée en territoire inconnu
- Le Sénat investit dans les monnaies virtuelles

Revue de presse internationale :
- VEHICLE CYBERSECURITY DOT and Industry Have Efforts Under Way, but DOT Needs to Define Its Role in Responding to a Real-world Attack
- Demand letter served on poll body over disastrous Comeleak breach
- The Minimin Aims To Be The Simplest Theremin
- Hacking group PLATINUM used Windows own patching system against it
- Hacker With Victims in 100 Nations Gets 7 Years in Prison
- HPR2018 How to make Komboucha Tea
- Circuit Bender Artist bends Fresnel Lens for Art
- FBI Director Suggests iPhone Hacking Method May Remain Secret
- 2016 Hack Miami Conference May 13-15, 2016
- 8-bit Video Wall Made From 160 Gaming Keyboards
- In An Era Of Decline, News Sites Can t Afford Poor Web Performance
- BeautifulPeople.com experiences data breach 1m affected
- Swedish Air Space Infringed, Aircraft Not Required
- Why cybercriminals attack healthcare more than any other industry
- Setting the Benchmark in the Network Security Forensics Industry

Annuaire des videos
- FUZZING ON LINE PART THREE
- Official Maltego tutorial 5 Writing your own transforms
- Official Maltego tutorial 6 Integrating with SQL DBs
- Official Maltego tutorial 3 Importing CSVs spreadsheets
- install zeus botnet
- Eloy Magalhaes
- Official Maltego tutorial 1 Google s websites
- Official Maltego tutorial 4 Social Networks
- Blind String SQL Injection
- backdoor linux root from r57 php shell VPS khg crew redc00de
- How To Attaque Pc With Back Track 5 In Arabique
- RSA Todd Schomburg talks about Roundup Ready lines available in 2013
- Nessus Diagnostics Troubleshooting
- Panda Security Vidcast Panda GateDefender Performa Parte 2 de 2
- MultiPyInjector Shellcode Injection

Revue Twitter
- RT @fpalumbo: Cisco consistently leading the way ? buys vCider to boost its distributed cloud vision #CiscoONE
- @mckeay Looks odd... not much to go on (prob some slideshow/vid app under Linux)
- [SuggestedReading] Using the HTML5 Fullscreen API for Phishing Attacks
- RT @BrianHonan: Our problems are not technical but cultural. OWASP top 10 has not changed over the years @joshcorman #RSAC
- RT @mikko: Wow. Apple kernels actually have a function called PE_i_can_has_debugger:
- [Blog Spam] Metasploit and PowerShell payloads
- PinkiePie Strikes Again, Compromises Google Chrome in Pwnium Contest at Hack in the Box: For the second time thi...
- @mikko @fslabs y'all wldn't happen to have lat/long data sets for other botnets, wld you? Doing some research (free/open info rls when done)
- RT @nickhacks: Want to crash a remote host running Snow Leopard? Just use: nmap -P0 -6 --script=targets-ipv6-multicast-mld #wishiwaskidding
- An inexpensive proxy service called is actually a front for #malware distribution -

Mini-Tagwall
Revue de presse : security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone

+ de mots clés pour la revue de presse

Annuaires des videos : curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit

+ de mots clés pour les videos

Revue Twitter : security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall

+ de mots clés pour la revue Twitter

Top bi-hebdo des articles de SecuObs
- [Ettercap – Partie 2] Ettercap par l'exemple - Man In the Middle et SSL sniffing
- [Infratech - release] version 0.6 de Bluetooth Stack Smasher
- [IDS Snort Windows – Partie 2] Installation et configuration
- [Infratech - vulnérabilité] Nouvelle version 0.8 de Bluetooth Stack Smasher
- Mises à jour en perspective pour le système Vigik
- USBDumper 2 nouvelle version nouvelles fonctions !
- EFIPW récupère automatiquement le mot de passe BIOS EFI des Macbook Pro avec processeurs Intel
- La sécurité des clés USB mise à mal par USBDUMPER
- Une faille critique de Firefox expose les utilisateurs de Tor Browser Bundle
- Installation sécurisée d'Apache Openssl, Php4, Mysql, Mod_ssl, Mod_rewrite, Mod_perl , Mod_security

Top bi-hebdo de la revue de presse
- StackScrambler and the Tale of a Packet Parsing Bug

Top bi-hebdo de l'annuaire des videos
- DC++ Botnet. How To DDos A Hub With Fake IPs.
- Comment creer un server botnet!!!!(Réseau de pc zombies)
- Defcon 14 Hard Drive Recovery Part 3

Top bi-hebdo de la revue Twitter
- RT @secureideas: I believe that all the XSS flaws announced are fixed in CVS. Will test again tomorrow if so, release 1.4.3. #BASESnort
- Currently, we do not support 100% of the advanced PDF features found in Adobe Reader... At least that's a good idea.
- VPN (google): German Foreign Office Selects Orange Business for Terrestrial Wide: Full
- @DisK0nn3cT Not really, mostly permission issues/info leak...they've had a couple of XSS vulns but nothing direct.
- Swatting phreaker swatted and heading to jail: A 19-year-old American has been sentenced to eleven years in pris..
- RT @fjserna You are not a true hacker if the calc.exe payload is not the scientific one... infosuck.org/0x0035.png

Top des articles les plus commentés
- [Metasploit 2.x – Partie 1] Introduction et présentation
- Microsoft !Exploitable un nouvel outil gratuit pour aider les développeurs à évaluer automatiquement les risques
- Webshag, un outil d'audit de serveur web
- Les navigateurs internet, des mini-systèmes d’exploitation hors de contrôle ?
- Yellowsn0w un utilitaire de déblocage SIM pour le firmware 2.2 des Iphone 3G
- CAINE un Live[CD|USB] pour faciliter la recherche légale de preuves numériques de compromission
- Nessus 4.0 placé sous le signe de la performance, de l'unification et de la personnalisation
- [Renforcement des fonctions de sécurité du noyau Linux – Partie 1] Présentation
- [IDS Snort Windows – Partie 1] Introduction aux IDS et à SNORT
- Origami pour forger, analyser et manipuler des fichiers PDF malicieux



[Message Precedent sur la mailing][Message Suivant sur la mailing][Precedent dans le fil][Prochain dans le fil][Index par Date][Index par fil] [Full-disclosure] [SECURITY] [DSA 1745-2] New lcms packages fix regression

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1745-2                  security@xxxxxxxxxx
link://[click]                      Steffen Joeris
March 25, 2009                   	link://[click]
- ------------------------------------------------------------------------

Package        : lcms
Vulnerability  : several vulnerabilities
Problem type   : local (remote)
Debian-specific: no
CVE Ids        : CVE-2009-0581 CVE-2009-0723 CVE-2009-0733


This update fixes a possible regression introduced in DSA-1745-1 and
also enhances the security patch. For reference the original advisory
text is below.

Several security issues have been discovered in lcms, a color management library. The Common Vulnerabilities andi Exposures project identifies the following problems: CVE-2009-0581 Chris Evans discovered that lcms is affected by a memory leak, which could result in a denial of service via specially crafted image files.

CVE-2009-0723 Chris Evans discovered that lcms is prone to several integer overflows via specially crafted image files, which could lead to the execution of arbitrary code.

CVE-2009-0733 Chris Evans discovered the lack of upper-gounds check on sizes leading to a buffer overflow, which could be used to execute arbitrary code.

For the stable distribution (lenny), these problems have been fixed in version 1.17.dfsg-1+lenny2.

For the oldstable distribution (etch), these problems have been fixed in version 1.15-1.1+etch3.

For the testing distribution (squeeze) and the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your lcms packages.

Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 4.0 alias etch - ------------------------------- Debian (oldstable) - ------------------ Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives: link://[click] Size/MD5 checksum: 5160 16d7404b4dc2f31cfe8c83336013cddd link://[click] Size/MD5 checksum: 644 5fe77039701cfa261d3ef84842d0e81e link://[click] Size/MD5 checksum: 791543 95a710dc757504f6b02677c1fab68e73 alpha architecture (DEC Alpha) link://[click] Size/MD5 checksum: 181316 b06ba5e4b64f5199ef241bd9fe8f293c link://[click] Size/MD5 checksum: 60246 89c087c9dd7e2d5dd2d78cbfb80c4017 link://[click] Size/MD5 checksum: 154378 9ab10ab4eae2ad103b2a7abc18e6cfc4 amd64 architecture (AMD x86_64 (AMD64)) link://[click] Size/MD5 checksum: 149534 1c06e35f87a683ad05c0fb1503859b4b link://[click] Size/MD5 checksum: 141016 f957d77d929d2e5ab9a4749cafab3b65 link://[click] Size/MD5 checksum: 53242 52fe759a62f8b111a65550f074c5037b arm architecture (ARM) link://[click] Size/MD5 checksum: 136610 d7c849cdf0eef3e2c0c1318a31f9e7c1 link://[click] Size/MD5 checksum: 135176 501beeb4b4309ae863c8c0d46fde6b1a link://[click] Size/MD5 checksum: 51742 bc7e60d9b5ac44efdf24a0b384f0f173 hppa architecture (HP PA RISC) link://[click] Size/MD5 checksum: 169464 312f7f7f841c09396a6c30ca76a35754 link://[click] Size/MD5 checksum: 158496 9d0fa35be0159f82709447b53df2a003 link://[click] Size/MD5 checksum: 59260 88e7279014e0482a797d54140e74e828 i386 architecture (Intel ia32) link://[click] Size/MD5 checksum: 50258 fa63f21e62c9fc8b863b60a3b470a840 link://[click] Size/MD5 checksum: 144134 58a63611f27e80b39537c28171211699 link://[click] Size/MD5 checksum: 138128 4c01410bae1d6508a77708206032871d ia64 architecture (Intel ia64) link://[click] Size/MD5 checksum: 78588 17da81143523be8e6ea70be3c4044422 link://[click] Size/MD5 checksum: 196180 68a05087486894adae92031ed3c7d510 link://[click] Size/MD5 checksum: 205450 66244f6ebdf34dd656cf7bbbe649e110 mips architecture (MIPS (Big Endian)) link://[click] Size/MD5 checksum: 149686 8d5cb21c8f47d5576aa8d7aa5bfc6aa8 link://[click] Size/MD5 checksum: 173982 7101d5218722dc09f7c89e09b93bd9be link://[click] Size/MD5 checksum: 52094 72ec336e06cf4042648d9ddd00509f35 mipsel architecture (MIPS (Little Endian)) link://[click] Size/MD5 checksum: 150926 c6a286b60bc31d2f48f3fb05209f0c83 link://[click] Size/MD5 checksum: 52290 91070dc723d6e000a7b78cb3221ef280 link://[click] Size/MD5 checksum: 175070 6f59ce0571035853680e96134062857d powerpc architecture (PowerPC) link://[click] Size/MD5 checksum: 148372 30e1c544cbe11d7b207a361d0f8fadc7 link://[click] Size/MD5 checksum: 148342 68e7d1bd20e8a05ea8edc165e746a784 link://[click] Size/MD5 checksum: 57778 ac6467e6d888c9e64aed8612f0ec0f16 s390 architecture (IBM S/390) link://[click] Size/MD5 checksum: 54298 37e6c4d12f4f33b9b0e95119a27e9714 link://[click] Size/MD5 checksum: 143172 a95270d1b8a7c1f282fabdf349bea783 link://[click] Size/MD5 checksum: 145324 619d5b581922e40d17de03b31db02faf sparc architecture (Sun SPARC/UltraSPARC) link://[click] Size/MD5 checksum: 51562 bf67e60a217cf1157fcd0a29a8ac1907 link://[click] Size/MD5 checksum: 147482 cfef0937ca2d432f04bacbd1e7f8472a link://[click] Size/MD5 checksum: 138088 e40a9fb196fd26caec11619fbaf60cda Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives: link://[click] Size/MD5 checksum: 1299 196c0beecdeffca26d4fd76bfa1f13fa link://[click] Size/MD5 checksum: 883148 efe7467bac4f10d9b354d5733489334d link://[click] Size/MD5 checksum: 11880 df69500e72128def5994ef29c66a213a alpha architecture (DEC Alpha) link://[click] Size/MD5 checksum: 153634 0e6eec2a3310e2e1f700b2a05fd9130d link://[click] Size/MD5 checksum: 66082 d78ea1ba9b77d499abfcd32762a1cb4d link://[click] Size/MD5 checksum: 227824 daa5711586870a1c9ed8d3e522e13a5f link://[click] Size/MD5 checksum: 117318 d9a92db2a1208ce29f0907156c0f21ec amd64 architecture (AMD x86_64 (AMD64)) link://[click] Size/MD5 checksum: 109436 ca441d44b110249b98976d93ee948968 link://[click] Size/MD5 checksum: 156844 eeaac6c774c317469343296904f2d8f2 link://[click] Size/MD5 checksum: 198650 cba03a4c26fbf1d306d669301375d741 link://[click] Size/MD5 checksum: 59352 5d8f067f54a1a1d1236100ec3198e07b arm architecture (ARM) link://[click] Size/MD5 checksum: 187620 69df7534d2350b0d746a4c54c822a272 link://[click] Size/MD5 checksum: 100818 03391efaf6b0e8a2a557fa18fb593a96 link://[click] Size/MD5 checksum: 56184 d40c2a788175ea465fddf9695ae0c74e link://[click] Size/MD5 checksum: 135840 b184dfae5d2bc6f63118183b70746792 armel architecture (ARM EABI) link://[click] Size/MD5 checksum: 136226 0bbf79f1a6a8be0ff7543c3cd4e42140 link://[click] Size/MD5 checksum: 108536 e28f48cfbca91daa41344b019cf7d5c0 link://[click] Size/MD5 checksum: 195116 6460336eb5a0445b0c03d9696fb5fcbc link://[click] Size/MD5 checksum: 60304 e851d20fb24e31bde2831f74c1fd73d8 hppa architecture (HP PA RISC) link://[click] Size/MD5 checksum: 217310 640dccdf2c7840500c4d4df9f53d1764 link://[click] Size/MD5 checksum: 181886 dff1392a724aec6efe449767176dfd48 link://[click] Size/MD5 checksum: 63650 6108c4ddbb4d2b168fb9579e263d89ec link://[click] Size/MD5 checksum: 120824 fa7b2afd7746de92c8dbbf777a63be00 i386 architecture (Intel ia32) link://[click] Size/MD5 checksum: 149512 a52ab7fa8e0e8b7876770443f7b33d26 link://[click] Size/MD5 checksum: 191776 67f020fc2fee74112c13c67b62bd33ac link://[click] Size/MD5 checksum: 55334 d67ca2db867df6f180f370ea71352ba9 link://[click] Size/MD5 checksum: 102528 fce72bbf31189287d737104df10fb860 ia64 architecture (Intel ia64) link://[click] Size/MD5 checksum: 85106 bdb601f8e0628a183552ca9662395003 link://[click] Size/MD5 checksum: 261388 1f4587b160e1417f7862062607aa9428 link://[click] Size/MD5 checksum: 168410 32803bd752ab02745c1f5421d77e76e4 link://[click] Size/MD5 checksum: 184744 c1fc1cfab42a15f14069c7b4291b58d5 mips architecture (MIPS (Big Endian)) link://[click] Size/MD5 checksum: 113914 720820898fadfe0f5c9577b94d7d596d link://[click] Size/MD5 checksum: 133806 7c5158967ab58f8361c728470a8cf3ca link://[click] Size/MD5 checksum: 57094 0c5f8a8e4b11636ee422e67a400d276a link://[click] Size/MD5 checksum: 221442 cf73eb40bf7fca081eb72164cbad007b mipsel architecture (MIPS (Little Endian)) link://[click] Size/MD5 checksum: 116858 5cc0672b4e6631a065822c4dbef8f6dd link://[click] Size/MD5 checksum: 57180 e788b1715e993fd87bd450c05c8a4edb link://[click] Size/MD5 checksum: 224906 9af1ae4fd0719c03af6bcd20c06fe8b1 link://[click] Size/MD5 checksum: 130228 d0ab9d0595147cc05012d6d85c649c16 powerpc architecture (PowerPC) link://[click] Size/MD5 checksum: 197118 e968b8dc68cade76a972984ee7be6a42 link://[click] Size/MD5 checksum: 115862 6c63f6f6e720988973299bb7aaf16be1 link://[click] Size/MD5 checksum: 70946 87bf7ecd279df9b7a4378ad2aa0568b9 link://[click] Size/MD5 checksum: 163524 888ccce8725b23b03e19ff03cd7c1dba s390 architecture (IBM S/390) link://[click] Size/MD5 checksum: 61034 91931f080c60c2bed98b07c93a1d815c link://[click] Size/MD5 checksum: 137822 57fe47c765d8dd2bd68282180786a22a link://[click] Size/MD5 checksum: 109236 12d604eb4030d11e5396cab3ad2be461 link://[click] Size/MD5 checksum: 191326 ab66b338cb32e84f441c45d07e44c744 sparc architecture (Sun SPARC/UltraSPARC) link://[click] Size/MD5 checksum: 58624 973b4ab50eaf18dbb55648a3b49e982c link://[click] Size/MD5 checksum: 156994 d5a82f96ef78ee2739e35548c1d89953 link://[click] Size/MD5 checksum: 102080 5aa8adf1027ae2a771f538b0630bcc77 link://[click] Size/MD5 checksum: 195704 5040b60f738977f0686ab32e1b705bcc These files will probably be moved into the stable distribution on its next update.

- --------------------------------------------------------------------------------- For apt-get: deb link://[click] stable/updates main For dpkg-ftp: link://[click] dists/stable/updates/main Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx Package info: `apt-cache show <pkg>' and link://[click]<pkg> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAknKFP4ACgkQ62zWxYk/rQdg0gCeNPzrr/e/sg+UdyIwtEPTanhl sS0Ani3D50rMKSZXBNaZIg5GygAk8Lio =F3JP -----END PGP SIGNATURE----- Full-Disclosure - We believe in it.

Charter: link://[click] Hosted and sponsored by Secunia - link://[click]



Archives de la liste de diffusion Secunia
Archives de la liste de diffusion Full Disclosure





SecuToolBox :

Mini-Tagwall des articles publiés sur SecuObs :

Mini-Tagwall de l'annuaire video :

Mini-Tagwall des articles de la revue de presse :

Mini-Tagwall des Tweets de la revue Twitter :