Release Date: 2008-11-03
Critical:
Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: GeSHi 1.x
Description:
A vulnerability has been reported in GeSHI, which can potentially be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an unspecified error, which may allow execution of arbitrary code on an affected system.
The vulnerability is reported in versions prior to 1.0.8.1.
Solution:
Update to version 1.0.8.1.
Provided and/or discovered by:
Reported by the vendor.
Original Advisory:
http://sourceforge.net/project/shownotes.php?release_id=637321
Net-snmp GETBULK Integer Overflow Denial of Service
Release Date: 2008-11-03
Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch
Software: Net-snmp 5.x
Description:
A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an integer overflow error within the "netsnmp_create_subtree_cache()" function in agent/snmp_agent.c. This can be exploited to cause a crash via a specially crafted SNMP GETBULK request.
The vulnerability is reported in 5.2.x versions prior to 5.2.5.1, 5.3.x versions prior to 5.3.2.3, and 5.4.x versions prior to 5.4.2.1.
Solution:
Update to version 5.2.5.1, 5.3.2.3, or 5.4.2.1.
Provided and/or discovered by:
Oscar Mira-Sanchez, reported via ZDI.
Original Advisory:
http://sourceforge.net/forum/forum.php?forum_id=882903
http://sourceforge.net/tracker/index....39&group_id=12694&atid=112694

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic