![]() |
|
[ advisories ]
• Unrar for Linux Denial Of Service vulnerability.
Vendor: RARLABS (http://www.rarlabs.com) Product: Unrar for linux (freeware). Versions affected: All upto 3.70 beta 4 Severity: Moderate Issue The unrar for Linux results in crash due to processing of standard filters in RAR VM, while Impact Any programs/softwares using the code from unrar for Linux from rarlabs for processing RAR files PoC http://www.metaeye.org/codes/corrupted.rar References Status Reported: 20/06/2007
• Clam AntiVirus RAR File Handling Denial Of Service Vulnerability.
Vendor: Clam AntiVirus (http://www.clamav.net) Product: Clamav (libclamav) Versions Affected: All before 0.91 Severity: Moderate Issue Clamav crashes due to processing of standard filters in RAR VM, while processing a Impact Processing the corrupted file will result in crashing of clamscan application and Fix Upgrade to version 0.91. PoC http://www.metaeye.org/codes/corrupted.rar Vendor Status Reported: 25/06/2007 References 1. Clamav bugzilla bug id 555.
• Redirection Vulnerability in wp-login.php
Vendor: Wordpress (http://www.wordpress.org). Severity: Moderate. Dated: 03 March 2007. Versions Affected: All. Issue The wp-login.php page redirects a user to arbitrary page after For example if a user logins successfully with his credentials http://www.foo.com/wp-login.php?redirect_to=http://www.google.co.in He will be redirected to www.google.co.in. Impact This can lead to credentials stealing. Also cookie stealing Vendor Status Reported on 03 March 2007. References 1. CVE-2007-1599. | |
| [ © MSG ] | |