Release Date: 2008-11-12
Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch
OS: Fedora 8
Fedora 9
Description:
Fedora has issued an update for blender. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
Solution:
Apply updated packages via the yum utility ("yum update blender").
Original Advisory:
FEDORA-2008-9411:
https://www.redhat.com/archives/fedor...-announce/2008-November/msg00303.html
FEDORA-2008-9447:
https://www.redhat.com/archives/fedor...-announce/2008-November/msg00243.html
Other References:
SA32680:
http://secunia.com/advisories/32680/
ActiveCampaign TrioLive "department_id" SQL Injection
Release Date: 2008-11-12
Critical:
Moderately critical
Impact: Cross Site Scripting
Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: ActiveCampaign TrioLive 1.x
Description:
Russ McRee has reported a vulnerability in ActiveCampaign TrioLive, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "departement_id" parameter in index.php is not properly sanitised before being used in an SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
NOTE: This can further be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site via SQL error messages.
The vulnerability is reported in versions prior to 1.58.7.
Solution:
Update to version 1.58.7 or apply the vendor patch.
http://activecampaign.com/support/forum/showthread.php?t=4554
Provided and/or discovered by:
Russ McRee, HolisticInfoSec
Original Advisory:
ActiveCampaign:
http://activecampaign.com/support/forum/showthread.php?t=4554
HolisticInfoSec:
http://holisticinfosec.org/content/view/93/45/

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic