|
Memory, the warder of the brain.
William Shakespeare (1564-1616); English poet and dramatist.
- Weekly summary -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)
Madrid, March 13 2004 - Over the last five days, Oxygen3 24h-365d has dealt
with the issues summarized below. Full details are available at:
http://www.pandasoftware.com/about/press/oxygen3/oxygen.asp
- Vulnerability in Adobe Acrobat Reader 5.1 (03/08/04).
According to NGSSoftware, a security problem has been detected which affects
version 5.1 of Adobe Acrobat Reader when specially crafted XFDF documents
are processed. Due to this vulnerability, an attacker could construct a file
with an .xfdf extension which, when a user tried to view it with version 5.1
of Acrobat Reader, could cause a buffer overflow and allow the execution of
arbitrary code.
- Vulnerability reported in Squid Proxy Cache access control (03/09/04).
SecurityTracker has reported that a vulnerability has been detected in the
Squid Proxy Cache server. This flaw could allow remote users to skip certain
access controls. The security problem lies in the processing of URLs
containing the '%00' character combination.
- Updates to Microsoft for Windows 2000, Office XP, Outlook 2002 and MSN
Messenger (03/10/04).
Microsoft has released its security updates for March, which correct three
vulnerabilities affecting Windows 2000, Office XP and Outlook 2002, and MSN
Messenger respectively. The most serious of these vulnerabilities affects
Office XP Service Pack 2 and Outlook 2002 Service Pack 2, as it allows code
to be run just by viewing a web page or HTML e-mail.
- Vulnerability in the processing of cookies (03/11/04).
SecurityTracker has reported a security warning stating that the majority of
web browsers could allow servers to access cookies in restricted files. The
attack would need to be launched from the same server as the one with rights
on the cookies, therefore the vulnerability does not allow indiscriminate
access.
- Execution of code in Unreal servers (03/12/04).
A vulnerability has been detected in Unreal gaming servers, that could allow
the execution of arbitrary code. This problem occurs when a user sends a
specially constructed class name, with formatting parameters.
NOTE: The address above may not show up on your screen as a single line.
This would prevent you from using the link to access the web page. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.
|
|
|
|
Posted on Sunday, 14 March 2004 @ 09:01:29 EST by phoenix22
|
|
|
|
|
Login |
|
|
|
|
|
· New User? ·
Click here to create a registered account.
|
|
|
Article Rating |
|
|
|
|
|
Average Score: 0
Votes: 0
|
|
|