forgery

NetBSD Security Advisory 2008-014: Cross-site request forgery in...

netbsd-announce  Mon, 10/27/2008 - 22:40

NetBSD Security Advisory 2008-014: Cross-site request forgery in ftpd(8)


 

Bugtraq: multiple vendor ftpd - Cross-site request forgery

Topix - Linux  Fri, 09/26/2008 - 11:25

Hash: SHA1 [ multiple vendor ftpd - Cross-site request forgery ] Author: Maksymilian Arciemowicz securityreason.com Date: - - Written: 03.09.2008 - - Public: 26.09.2008 SecurityReason Research SecurityAlert Id: ...


 

ProFTPD Command Truncation Cross-Site Request Forgery Vulnerabil...

Topix - Unix  Wed, 09/24/2008 - 02:53

The remote FTP server is prone to a cross-site request forgery attack. Description: The remote host is using ProFTPD, a free FTP server for Unix and Linux.


 

Thursday Security Updates

LWN.net  Thu, 09/04/2008 - 07:06

Mandriva has updated libtiff (denial of service) and django (cross-site request forgery).

Slackware has updated php (multiple vulnerabilities).

SUSE has updated ibmjava5 (multiple vulnerabilities).

Ubuntu has updated libxml2 (denial of service).


 

Bugtraq: PR08-16: CSRF (Cross-site Request Forgery) on Moodle ed...

Topix - Unix  Tue, 07/22/2008 - 20:54

ProCheckUp Research -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-16: CSRF on Moodle edit profile page Vulnerability found: 25/06/2008 Vendor informed: 28/06/2008 Vulnerability fixed: 16/07/2008 Advisory ...


 

PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profil...

Topix - Unix  Tue, 07/22/2008 - 13:20

Hash: SHA1 PR08-16: CSRF on Moodle edit profile page Vulnerability found: 25/06/2008 Vendor informed: 28/06/2008 Vulnerability fixed: 16/07/2008 Advisory publicly released: 22/07/2008 Severity: High ...


 

Debian and Ubuntu Vunerabilities are Ugly

Digg Linux/Unix upcoming  Fri, 05/16/2008 - 06:26

A security researcher recently disclosed vulnerability in widely used Linux distributions where attackers can guess cryptographic keys, possibly leading to the forgery of digital signatures and theft of confidential information.


 

Security advisories for Monday

LWN.net  Mon, 04/21/2008 - 08:21

Debian has updated python2.4 (multiple vulnerabilities), mplayer (arbitrary code execution), ikiwiki (cross-site request forgery).

Gentoo has updated cups (arbitrary code execution), DBMail (authentication bypass).