Dear All,
Good day!
Attached please you find the file of IP Camera with Network Video Server.
If you are interested in them or have any questions, and can feel free to contact me.
Looking forwards…
Regards,
Carl
Everything related to Computer Security - Security Audits, Security Vulnerabilities, Intrusion Detection, Incident Handling, Forensics and Investigation, Information Security Policies, and a whole lot more.
Dear All,
Good day!
Attached please you find the file of IP Camera with Network Video Server.
If you are interested in them or have any questions, and can feel free to contact me.
Looking forwards…
Regards,
Carl
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2250-1 security@debian.org
http://www.debian.org/security/ Nico Golde
March 31, 2011 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : citadel
Vulnerability : denial of service
Problem type : remote
Debian-specific: no
CVE ID : CVE-2011-1756
Wouter Coekaerts discovered that the jabber server component of citadel,
a complete and feature-rich groupware server, is vulnerable to the so-called
"billion laughs" attack because it does not prevent entity expansion on
received data. This allows an attacker to perform denial of service
attacks against the service by sending specially crafted XML data to it.
For the oldstable distribution (lenny), this problem has been fixed in
version 7.37-8+lenny1.
For the stable distribution (squeeze), this problem has been fixed in
version 7.83-2squeeze2.
For the testing (wheezy) and unstable(sid) distributions,
this problem will be fixed soon.
We recommend that you upgrade your citadel packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iEYEARECAAYFAk3lWZ0ACgkQHYflSXNkfP931ACeNRFzg5jx3Ca7zotWpQs42S8h
h4UAn2pNrf9/sr6duOU05yG3bauDiBjI
=ah12
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20110531211157.GA13526@ngolde.de
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2249-1 security@debian.org
http://www.debian.org/security/ Nico Golde
March 31, 2011 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : jabberd14
Vulnerability : denial of service
Problem type : remote
Debian-specific: no
CVE ID : CVE-2011-1754
Wouter Coekaerts discovered that jabberd14, an instant messaging server
using the Jabber/XMPP protocol, is vulnerable to the so-called
"billion laughs" attack because it does not prevent entity expansion on
received data. This allows an attacker to perform denial of service
attacks against the service by sending specially crafted XML data to it.
The oldstable distribution (lenny), does not contain jabberd14.
For the stable distribution (squeeze), this problem has been fixed in
version 1.6.1.1-5+squeeze1.
For the testing distribution (wheezy), this problem will be fixed soon.
For the unstable distribution (sid), this problem has been fixed in
version 1.6.1.1-5.1
We recommend that you upgrade your jabberd14 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iEYEARECAAYFAk3lWGYACgkQHYflSXNkfP+4IACeJxeVkXTIlPONJB4qs0FYTI4b
BXQAoI1epUV+r6p3P+NOEoA+fRVxQ3yq
=64+6
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20110531210646.GA12024@ngolde.de
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2248-1 security@debian.org
http://www.debian.org/security/ Nico Golde
March 31, 2011 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : ejabberd
Vulnerability : denial of service
Problem type : remote
Debian-specific: no
CVE ID : CVE-2011-1753
Wouter Coekaerts discovered that ejabberd, a distributed XMPP/Jabber server
written in Erlang, is vulnerable to the so-called "billion laughs" attack
because it does not prevent entity expansion on received data.
This allows an attacker to perform denial of service attacks against the
service by sending specially crafted XML data to it.
For the oldstable distribution (lenny), this problem has been fixed in
version 2.0.1-6+lenny3.
For the stable distribution (squeeze), this problem has been fixed in
version 2.1.5-3+squeeze1.
For the testing distribution (wheezy), this problem will be fixed soon.
For the unstable distribution (sid), this problem has been fixed in
version 2.1.6-2.1.
We recommend that you upgrade your ejabberd packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iEYEARECAAYFAk3lVy8ACgkQHYflSXNkfP9+XwCZASQIxH5wedS/Sv5RVbLq72TX
BCQAmwa5smfQdADSxcAw9vRXuTPmuck4
=s7fb
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20110531210135.GA10081@ngolde.de
More malware apps sneak into Google Market | Steve Ballmer: Office 365 to launch in June | ||||||||||
Network World Daily News PM | ||||||||||
Cell phone use 'possibly' a cause of brain cancer, says WHO panel RESOURCE COMPLIMENTS OF: Cisco Systems, Inc. World IPv6 Day with Cisco By the end of 2011, there will be no more IPv4 addresses. Cisco IPv6 solutions can help your organization extend its reach and harness the power of the growing Internet. Based on your industry, we can help you maximize the value of your existing investments while you prepare for the next wave of Internet growth. Learn More> In this Issue
WEBCAST: F5 Networks Ensuring High Availability for Client Access F5's integrated application delivery solutions for Microsoft Exchange Server 2010 provide the required hardware load balancing for CAS servers. Learn More! More malware apps sneak into Google Market Steve Ballmer: Office 365 to launch in June Jobs to keynote Apple WWDC, introduce iCloud WHITE PAPER: F5 Networks Providing Security and Acceleration for Remote Users Delivering applications to remote users is a significant undertaking. Applications need to be available, and they must be delivered securely and quickly. Through a range of products, F5 has solved the security plus acceleration challenge for remote users with BIG-IP Edge Gateway and BIG-IP APM. Read More! Daily innovation smackdown: Biz Stone vs. Lou Gerstner Spending on new software projects rises, survey says Ricoh announces enterprise device with tablet features WHITE PAPER: Siemens 3 Steps for Choosing the Right UC Solution Communication is at the heart of how many small businesses operate. However, few organizations stop to consider how the way they communicate is inefficient. Many consider this to be a cost of doing business. But what if your business could overcome these problems? Learn More Why Microsoft and Citrix need each other IBM improves Sametime platform Oracle says ERP software woes are school's own fault | ||||||||||
SURVEY: Future-proofing the cloud GOODIES FROM THE SUBNETS SLIDESHOWS 7 things we love about Drupal 7 MOST-READ STORIES
| ||||||||||
Do You Tweet? You are currently subscribed to networkworld_daily_news_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** |
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2247-1 security@debian.org
http://www.debian.org/security/ Thijs Kinkhorst
May 31, 2011 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : rails
Vulnerability : several vulnerabilities
Problem type : remote
Debian-specific: no
CVE ID : CVE-2011-0446 CVE-2011-0447
Debian Bug : 614864
Several vulnerabilities have been discovered in Rails, the Ruby web
application framework. The Common Vulnerabilities and Exposures project
identifies the following problems:
CVE-2011-0446
Multiple cross-site scripting (XSS) vulnerabilities when JavaScript
encoding is used, allow remote attackers to inject arbitrary web
script or HTML.
CVE-2011-0447
Rails does not properly validate HTTP requests that contain an
X-Requested-With header, which makes it easier for remote attackers
to conduct cross-site request forgery (CSRF) attacks.
For the oldstable distribution (lenny), this problem has been fixed in
version 2.1.0-7+lenny0.1.
For the stable distribution (squeeze), this problem has been fixed in
version 2.3.5-1.2+squeeze0.1.
For the unstable distribution (sid), this problem has been fixed in
version 2.3.11-0.1.
We recommend that you upgrade your rails packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQEcBAEBAgAGBQJN5TtyAAoJEOxfUAG2iX57LXsH/3eyIiCabIgvXydXhFhz0sCG
DvIJt4Mg9ficfkI73Mxsq3ERhUiXXi4cpqLaAKQxa3Nd4rYuMu5Ir7zR5i5SOOUe
8pRx2wARb28uEzmvbcWvyIXxkxYXKwaUJgtK4Vaq6JBTx5LpBJyZojJ/JFLX07Ca
15H44DLSdd1pJOwj4iLpkGP2I3uS1eL0KU2yatRNApz7zelCGmzJVoOtbdBNe0jt
WdIwW1NqynEi5g3GSatMqj0mGWZ9Wp8VgIayPjqpJv3mCyesSxJ4IQXzaq8Rs+4W
Iuzv4h3SrM4OfGA8uYYxPtps6vpDIqc2l8oVQK8/f3qS1uTAMAN2d/Wh90P7UZw=
=YPdC
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20110531190422.55CC559BBA@kinkhorst.com
Skype issues software fix for Windows and Mac users | IE Flaw Could Allow Hackers Access to your Facebook, Gmail, Twitter Accounts | ||||||||||
Network World Microsoft | ||||||||||
The hubris of years: IT prowess can't be measured only by time on the job WHITE PAPER: Quest Software Transaction Tracing through Complex Web Applications In this Quest white paper, learn about the components of a transaction as they cross various application domains. Then, discover the difficulty in connecting transaction components for monitoring, why continuously monitoring is key and how a third-party solution simplifies the challenge. Learn more. In this Issue
WHITE PAPER: HP & Intel 3PAR Storage: Tailor-Made for Virtual Infrastructures As users have adopted virtual server technology for their less critical applications, many are now seriously considering the idea of moving their Tier 1 production applications. Done properly, virtualizing these types of applications will bring compelling benefits, including increased IT agility and lower costs of ownership. Read now Skype issues software fix for Windows and Mac users IE Flaw Could Allow Hackers Access to your Facebook, Gmail, Twitter Accounts WHITE PAPER: F5 Networks ROI of Application Delivery Controllers How modern offload technologies in Application Delivery Controllers can drastically reduce expenses in traditional and virtualized architectures, with a fast ROI. Learn More! Ballmer ignores call for his head, talks Windows 8, China piracy Samsung latest Galaxy Tab: Sleeker than the Xoom, still no iPad WHITE PAPER: Diskeeper Corporation NEW Diskeeper 2011 Pro Premier Edition Diskeeper 2011 Pro Premier edition provides essential performance and efficiency increases for power workstation users as well as all the features of the Professional edition. Learn more! PBS hacked by LulzSec: Lulz Boat Sailed, PBS Failed Hotmail Exploit Silently Snooped & Microsoft Audio CAPTCHA Easily Defeated Visit Microsoft Subnet for more daily news, blogs | ||||||||||
SURVEY: Future-proofing the cloud GOODIES FROM THE SUBNETS SLIDESHOWS 7 things we love about Drupal 7 MOST-READ STORIES
| ||||||||||
Do You Tweet? You are currently subscribed to networkworld_microsoft_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** |
5 top social media security threats | Can you have too much security? | ||||||||||
Network World Security Strategies | ||||||||||
Hidden URLs in phone and tablet browsers WHITE PAPER: Dell The Business Case for Security Information Management It is a mistake to assume that information security is solely a technical problem left for IT to solve. This guide is a non-technical discussion of security information management. Learn more. In this Issue
WEBCAST: Oracle Oracle Business Intelligence Foundation Oracle BI Foundation Suite delivers the broadest end to end BI functionality from reporting, dashboards, scorecards, scenario modeling, forecasting to ad-hoc analysis. Register Today! 5 top social media security threats Can you have too much security? PBS hacked by LulzSec: Lulz Boat Sailed, PBS Failed WEBCAST: Oracle How Oracle Exalogic and Exadata Deliver Extreme Java View this webcast to learn why Exalogic and Exadata are the definitive engineered platforms for enterprise application and database consolidation, with added advantage of extreme Java and database performance, unmatched reliability and scalability, and cloud-enabling elastic capacity. Register Today! Memory encryption breakthrough claimed by NC State researchers RSA tokens may be behind major network security problems at Lockheed Martin New malware scanner finds 5% of Windows PCs infected WHITE PAPER: Quest Software Transaction Tracing through Complex Web Applications In this Quest white paper, learn about the components of a transaction as they cross various application domains. Then, discover the difficulty in connecting transaction components for monitoring, why continuously monitoring is key and how a third-party solution simplifies the challenge. Learn more. Key lessons learned from Sony hack-fest Microsoft downplays IE 'cookiejacking' bug Cloud CIO: The Two Biggest Lies About Cloud Security Mobile phones are great for phishers, researchers find Not even security managers immune to FakeAV infection | ||||||||||
SURVEY: Future-proofing the cloud GOODIES FROM THE SUBNETS SLIDESHOWS 7 things we love about Drupal 7 MOST-READ STORIES
| ||||||||||
Do You Tweet? You are currently subscribed to networkworld_security_strategies_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** |