Release Date: 2008-10-21
Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch
OS: Fedora 8
Fedora 9
Description:
Fedora has issued an update for jhead. This fixes a security issue, which potentially can be exploited by malicious, local users to gain escalated privileges.
For more information:
SA32340
Solution:
Apply updated packages via the yum utility ("yum update jhead").
Original Advisory:
FEDORA-2008-8941:
https://www.redhat.com/archives/fedor...e-announce/2008-October/msg00531.html
FEDORA-2008-8928:
https://www.redhat.com/archives/fedor...e-announce/2008-October/msg00511.html
Other References:
SA32340:
http://secunia.com/advisories/32340/
TYPO3 simplesurvey Extension SQL Injection Vulnerability
Release Date: 2008-10-21
Critical:
Moderately critical
Impact: Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: Simple survey (simplesurvey) Extension for TYPO3 1.x
Description:
A vulnerability has been reported in the Simple survey (simplesurvey) extension for TYPO3, which can be exploited by malicious people to conduct SQL injection attacks.
Certain unspecified input is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is reported in version 1.7.0 and prior.
Solution:
Update to version 1.7.1 or later.
http://typo3.org/extensions/repository/view/simplesurvey/1.8.1/
Provided and/or discovered by:
The vendor credits Andreas Bouch

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic