Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: World

» Topic:  Microsoft fixes memory bug in security patch

» Added by:  Robert McMillan

» Date:  19.8.2006

  Microsoft has fixed a bug in a critical security patch that may have been causing problems for some Windows Server 2003 users.

The bug is in the critical MS06-040 Windows Server services update, released earlier in August. It affects programs that use up very large chunks of memory on some versions of Windows. According to Microsoft, programs such as Microsoft Navision 3.7, which require allocations of more than 1G byte of memory, can crash after the update is installed.

Most Windows systems do not experience the bug, but Microsoft Windows Server 2003 and the 64-bit version of Windows XP Professional Edition are affected. Microsoft's hotfix for the problem can be downloaded from their site.

The majority of widely used applications allocate memory in chunks that are smaller than the 1G-byte threshold blamed for the bug, so there have not been widespread reports of problems with this patch, according to Johannes Ullrich, chief research officer for the SANS Institute.

More troublesome has been the MS06-042 update for Internet Explorer, which has caused browser crashes while using Web-based applications such as PeopleSoft, Siebel and Unicenter. Microsoft issued a hotfix for this update earlier in the week and is promising to reissue the buggy update next Tuesday.

SANS is tracking the status of Microsoft's updates.

Microsoft issued a total of 12 updates this month, fixing 23 vulnerabilities. But it's had the most problems with the more serious of these fixes.

"MS06-040 and MS06-042 were probably the most critical issues," he said. "It's unfortunate that they've had problems with both of them."

Source:
http://www.computerworld.com/



Alert

Microsoft VISTA TCP/IP stack buffer overflow

high- 2008-11-27

Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 dba_replace()
   destroying file

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.