Release Date: 2008-11-10
Critical:
Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
OS: Ubuntu Linux 8.10
Description:
Ubuntu has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Original Advisory:
USN-666-1:
https://lists.ubuntu.com/archives/ubu...ty-announce/2008-November/000775.html
Other References:
SA32479:
http://secunia.com/advisories/32479/
MoinMoin Full Path Disclosure Weakness
Release Date: 2008-11-10
Critical:
Not critical
Impact: Exposure of system information
Where: From remote
Solution Status: Unpatched
Software: MoinMoin 1.x
Description:
Xia Shing Zee has discovered a weakness in MoinMoin, which can be exploited by malicious people to disclose system information.
The weakness is caused due to the application displaying the full installation path in an error report, when an HTTP request for an overly long URL is received.
The weakness is confirmed in version 1.8.0 (standalone server mode). Other versions may also be affected.
Solution:
Filter HTTP requests for overly long URLs in a proxy.
Provided and/or discovered by:
Xia Shing Zee

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic