DoS Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 07:57:18 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2056852838&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=DoS%20Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Ffiles%2Ftags%2Fdenial_of_service%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2056852838.1338191838.1338191838.1338191838.1%3B%2B__utmz%3D32867617.1338191838.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Secunia Security Advisory 49293 http://packetstormsecurity.org/files/113055/sa49293.txt http://packetstormsecurity.org/files/113055/sa49293.txt http://packetstormsecurity.org/files/113055/Secunia-Security-Advisory-49293.html Sat, 26 May 2012 07:07:12 GMT Secunia Security Advisory - Ubuntu has issued an update for openssl. This fixes two vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service) of the application using the library. Ubuntu Security Notice USN-1454-1 http://packetstormsecurity.org/files/113049/USN-1454-1.txt http://packetstormsecurity.org/files/113049/USN-1454-1.txt http://packetstormsecurity.org/files/113049/Ubuntu-Security-Notice-USN-1454-1.html Fri, 25 May 2012 21:02:04 GMT Ubuntu Security Notice 1454-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. ResEdit 1.5.11-win32 Buffer Overflow http://packetstormsecurity.org/files/113041/resedit-overflow.tgz http://packetstormsecurity.org/files/113041/resedit-overflow.tgz http://packetstormsecurity.org/files/113041/ResEdit-1.5.11-win32-Buffer-Overflow.html Fri, 25 May 2012 20:36:33 GMT ResEdit version 1.5.11-win32 suffers from a buffer overflow. Proof of concept denial of service exploits included. Ubuntu Security Notice USN-1453-1 http://packetstormsecurity.org/files/113034/USN-1453-1.txt http://packetstormsecurity.org/files/113034/USN-1453-1.txt http://packetstormsecurity.org/files/113034/Ubuntu-Security-Notice-USN-1453-1.html Fri, 25 May 2012 20:08:29 GMT Ubuntu Security Notice 1453-1 - A flaw was found in the Linux's kernels ext4 file system when mounted with a journal. A local, unprivileged user could exploit this flaw to cause a denial of service. A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed. Ubuntu Security Notice USN-1452-1 http://packetstormsecurity.org/files/113033/USN-1452-1.txt http://packetstormsecurity.org/files/113033/USN-1452-1.txt http://packetstormsecurity.org/files/113033/Ubuntu-Security-Notice-USN-1452-1.html Fri, 25 May 2012 20:08:16 GMT Ubuntu Security Notice 1452-1 - A flaw was found in the Linux kernel's KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed. Ubuntu Security Notice USN-1451-1 http://packetstormsecurity.org/files/113032/USN-1451-1.txt http://packetstormsecurity.org/files/113032/USN-1451-1.txt http://packetstormsecurity.org/files/113032/Ubuntu-Security-Notice-USN-1451-1.html Fri, 25 May 2012 19:52:12 GMT Ubuntu Security Notice 1451-1 - Ivan Nestlerode discovered that the Cryptographic Message Syntax (CMS) and PKCS #7 implementations in OpenSSL returned early if RSA decryption failed. This could allow an attacker to expose sensitive information via a Million Message Attack (MMA). It was discovered that an integer underflow was possible when using TLS 1.1, TLS 1.2, or DTLS with CBC encryption. This could allow a remote attacker to cause a denial of service. Various other issues were also addressed. Secunia Security Advisory 49255 http://packetstormsecurity.org/files/113026/sa49255.txt http://packetstormsecurity.org/files/113026/sa49255.txt http://packetstormsecurity.org/files/113026/Secunia-Security-Advisory-49255.html Fri, 25 May 2012 11:51:56 GMT Secunia Security Advisory - A vulnerability has been reported in Apache Commons Compress, which can be exploited by malicious people to cause a DoS (Denial of Service) in an application using the library. Secunia Security Advisory 49286 http://packetstormsecurity.org/files/113025/sa49286.txt http://packetstormsecurity.org/files/113025/sa49286.txt http://packetstormsecurity.org/files/113025/Secunia-Security-Advisory-49286.html Fri, 25 May 2012 11:51:53 GMT Secunia Security Advisory - Apache has acknowledged a vulnerability in Ant, which can be exploited by malicious people to cause a DoS (Denial of Service). Apache Commons Compress / Apache Ant Denial Of Service http://packetstormsecurity.org/files/113014/CVE-2012-2098.txt http://packetstormsecurity.org/files/113014/CVE-2012-2098.txt http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.html Thu, 24 May 2012 15:24:53 GMT Apache Commons Compress versions 1.0 through 1.4 and Apache Ant versions 1.5 through 1.8.3 suffer from a denial of service vulnerability. The bzip2 compressing streams in Apache Commons Compress and Apache Ant internally use sorting algorithms with unacceptable worst-case performance on very repetitive inputs. A specially crafted input to Compress' BZip2CompressorOutputStream or Ant's <bzip2> task can be used to make the process spend a very long time while using up all available processing time effectively leading to a denial of service. EMC AutoStart Multiple Buffer Overflows http://packetstormsecurity.org/files/113013/ESA-2012-020.txt http://packetstormsecurity.org/files/113013/ESA-2012-020.txt http://packetstormsecurity.org/files/113013/EMC-AutoStart-Multiple-Buffer-Overflows.html Thu, 24 May 2012 15:22:39 GMT EMC AutoStart contains multiple buffer overflow vulnerabilities which can be exploited to potentially cause a denial of service, or possibly, execute arbitrary code within the context of the affected application. Versions 5.3.x and 5.4.x are affected. Wireshark DIAMETER Denial Of Service http://packetstormsecurity.org/files/113010/wiresharkdiameter-dos.tgz http://packetstormsecurity.org/files/113010/wiresharkdiameter-dos.tgz http://packetstormsecurity.org/files/113010/Wireshark-DIAMETER-Denial-Of-Service.html Thu, 24 May 2012 15:15:55 GMT Wireshark versions 1.4.0 through 1.4.12 and 1.6.0 through 1.6.7 suffer from a DIAMETER dissector denial of service vulnerability. Wireshark Dissector Denial Of Service http://packetstormsecurity.org/files/113009/wiresharkdis-dos.tgz http://packetstormsecurity.org/files/113009/wiresharkdis-dos.tgz http://packetstormsecurity.org/files/113009/Wireshark-Dissector-Denial-Of-Service.html Thu, 24 May 2012 15:12:32 GMT Wireshark versions 1.6.0 through 1.6.7 and versions 1.4.0 through 1.4.12 suffer from multiple dissector related denial of service vulnerabilities. Wireshark Misaligned Memory Denial Of Service http://packetstormsecurity.org/files/113008/wiresharkmisalign-dos.tgz http://packetstormsecurity.org/files/113008/wiresharkmisalign-dos.tgz http://packetstormsecurity.org/files/113008/Wireshark-Misaligned-Memory-Denial-Of-Service.html Thu, 24 May 2012 14:53:13 GMT Wireshark versions 1.6.0 through 1.6.7 and versions 1.4.0 through 1.4.12 suffer from a misaligned memory denial of service vulnerability. bsnes 0.87 Denial Of Service http://packetstormsecurity.org/files/113046/bsnes-dos.txt http://packetstormsecurity.org/files/113046/bsnes-dos.txt http://packetstormsecurity.org/files/113046/bsnes-0.87-Denial-Of-Service.html Thu, 24 May 2012 12:12:12 GMT bsnes version 0.87 suffers from a denial of service vulnerability. Ubuntu Security Notice USN-1450-1 http://packetstormsecurity.org/files/112987/USN-1450-1.txt http://packetstormsecurity.org/files/112987/USN-1450-1.txt http://packetstormsecurity.org/files/112987/Ubuntu-Security-Notice-USN-1450-1.html Thu, 24 May 2012 02:21:13 GMT Ubuntu Security Notice 1450-1 - It was discovered that Net-SNMP incorrectly performed entry lookups in the extension table. A remote attacker could send a specially crafted request and cause the SNMP server to crash, leading to a denial of service. Secunia Security Advisory 49191 http://packetstormsecurity.org/files/113019/sa49191.txt http://packetstormsecurity.org/files/113019/sa49191.txt http://packetstormsecurity.org/files/113019/Secunia-Security-Advisory-49191.html Thu, 24 May 2012 02:20:28 GMT Secunia Security Advisory - A vulnerability has been reported in Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service). Secunia Security Advisory 49279 http://packetstormsecurity.org/files/113016/sa49279.txt http://packetstormsecurity.org/files/113016/sa49279.txt http://packetstormsecurity.org/files/113016/Secunia-Security-Advisory-49279.html Thu, 24 May 2012 02:20:19 GMT Secunia Security Advisory - Ubuntu has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service). Secunia Security Advisory 49226 http://packetstormsecurity.org/files/112983/sa49226.txt http://packetstormsecurity.org/files/112983/sa49226.txt http://packetstormsecurity.org/files/112983/Secunia-Security-Advisory-49226.html Wed, 23 May 2012 06:21:02 GMT Secunia Security Advisory - Mutliple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service). Secunia Security Advisory 49254 http://packetstormsecurity.org/files/112982/sa49254.txt http://packetstormsecurity.org/files/112982/sa49254.txt http://packetstormsecurity.org/files/112982/Secunia-Security-Advisory-49254.html Wed, 23 May 2012 06:20:59 GMT Secunia Security Advisory - A vulnerability has been reported in feedparser, which can be exploited by malicious people to cause a DoS (Denial of Service). Secunia Security Advisory 49245 http://packetstormsecurity.org/files/112977/sa49245.txt http://packetstormsecurity.org/files/112977/sa49245.txt http://packetstormsecurity.org/files/112977/Secunia-Security-Advisory-49245.html Wed, 23 May 2012 06:20:43 GMT Secunia Security Advisory - A vulnerability has been reported in Citrix XenApp, which can be exploited by malicious people to cause a DoS (Denial of Service). Secunia Security Advisory 49221 http://packetstormsecurity.org/files/112975/sa49221.txt http://packetstormsecurity.org/files/112975/sa49221.txt http://packetstormsecurity.org/files/112975/Secunia-Security-Advisory-49221.html Wed, 23 May 2012 06:20:37 GMT Secunia Security Advisory - A vulnerability has been reported in Symantec Endpoint Protection, which can be exploited by malicious people to cause a DoS (Denial of Service). Secunia Security Advisory 49256 http://packetstormsecurity.org/files/112972/sa49256.txt http://packetstormsecurity.org/files/112972/sa49256.txt http://packetstormsecurity.org/files/112972/Secunia-Security-Advisory-49256.html Wed, 23 May 2012 06:20:27 GMT Secunia Security Advisory - Ubuntu has issued an update for feedparser. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service). Tftpd32 DHCP Serve 4.00 Denial Of Service http://packetstormsecurity.org/files/112963/tftpd32-dos.txt http://packetstormsecurity.org/files/112963/tftpd32-dos.txt http://packetstormsecurity.org/files/112963/Tftpd32-DHCP-Serve-4.00-Denial-Of-Service.html Wed, 23 May 2012 02:27:39 GMT Tftpd32 DHCP server version 4.00 suffers from a denial of service vulnerability. Ubuntu Security Notice USN-1449-1 http://packetstormsecurity.org/files/112956/USN-1449-1.txt http://packetstormsecurity.org/files/112956/USN-1449-1.txt http://packetstormsecurity.org/files/112956/Ubuntu-Security-Notice-USN-1449-1.html Tue, 22 May 2012 20:37:23 GMT Ubuntu Security Notice 1449-1 - It was discovered that feedparser did not properly sanitize ENTITY declarations in encoded fields. A remote attacker could exploit this to cause a denial of service via memory exhaustion. Secunia Security Advisory 49184 http://packetstormsecurity.org/files/112955/sa49184.txt http://packetstormsecurity.org/files/112955/sa49184.txt http://packetstormsecurity.org/files/112955/Secunia-Security-Advisory-49184.html Tue, 22 May 2012 12:36:48 GMT Secunia Security Advisory - A vulnerability has been reported in Xen, which can be exploited by malicious, local users in a guest virtual machine to cause a DoS (Denial of Service).