<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; User-Assisted</title>
	<atom:link href="http://sechero.com/tag/user-assisted/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-15/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-15/#comments</comments>
		<pubDate>Wed, 27 May 2009 19:20:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code &#60;!&#8211; Envelope-to: email@address Delivery-date: Wed, 27 May 2009 20:19:31 +0100 Received: from outgoing.securityfocus.com ([205.206.231.27] helo=outgoing3.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1M9Oew-0006Yj-QS for email@address; Wed, 27 May 2009 20:19:30 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing3.securityfocus.com (Postfix) with QMQP id 9BD6F236FF8; Wed, 27 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=86338">[ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Wed, 27 May 2009 20:19:31 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.27] helo=outgoing3.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1M9Oew-0006Yj-QS 	for email@address; Wed, 27 May 2009 20:19:30 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing3.securityfocus.com" title="http://outgoing3.securityfocus.com" target="_blank">outgoing3.securityfocus.com</a> (Postfix) with QMQP 	id 9BD6F236FF8; Wed, 27 May 2009 13:16:26 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 5683 invoked from network); 27 May 2009 18:37:25 -0000  arbitrary code Cc: <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a>, 	<a href="mailto:security-alerts@linuxsecurity.com" title="mailto:security-alerts@linuxsecurity.com">security-alerts@linuxsecurity.com</a> Content-Type: multipart/signed; micalg=&quot;pgp-sha1&quot;; protocol=&quot;application/pgp-signature&quot;; boundary=&quot;=-qKcs3BrUY+SMIGtTngxH&quot; Message-Id: &lt;1243449441.4200.1.camel@localhost&gt; Mime-Version: 1.0 X-Mailer: Evolution 2.26.2  X-IMAPbase: 1176125385 9205 Status: O X-UID: 9205 Content-Length: 3703 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-14/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-14/#comments</comments>
		<pubDate>Wed, 27 May 2009 18:37:21 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code Posted by Alex Legler on May 27 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo Linux [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/May/0238.html">[ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code</a></h1>
</p>
<p>Posted by Alex Legler on May 27
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200905-09 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/May/0238.html">http://seclists.org/fulldisclosure/2009/May/0238.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-13/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-13/#comments</comments>
		<pubDate>Mon, 25 May 2009 16:10:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200905-02 ] Cscope: User-assisted execution of arbitrary code &#60;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 17:03:17 +0100 Received: from outgoing.securityfocus.com ([205.206.231.26] helo=outgoing2.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1M8cdx-0000Fq-BQ for email@address; Mon, 25 May 2009 17:03:17 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing2.securityfocus.com (Postfix) with QMQP id 73F8314425B; Mon, 25 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=86251">[ GLSA 200905-02 ] Cscope: User-assisted execution of arbitrary code</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 17:03:17 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.26] helo=outgoing2.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1M8cdx-0000Fq-BQ 	for email@address; Mon, 25 May 2009 17:03:17 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing2.securityfocus.com" title="http://outgoing2.securityfocus.com" target="_blank">outgoing2.securityfocus.com</a> (Postfix) with QMQP 	id 73F8314425B; Mon, 25 May 2009 08:14:36 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 18052 invoked from network); 24 May 2009 13:02:26 -0000 Message-ID: &lt;4A194608.5000400@gentoo.org&gt; User-Agent: Thunderbird 2.0.0.19 (X11/20090120) MIME-Version: 1.0 Cc: <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a>, <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, 	<a href="mailto:security-alerts@linuxsecurity.com" title="mailto:security-alerts@linuxsecurity.com">security-alerts@linuxsecurity.com</a> X-Enigmail-Version: 0.95.7 Content-Type: multipart/signed; micalg=pgp-sha1;  protocol=&quot;application/pgp-signature&quot;;  boundary=&quot;&#8212;&#8212;&#8212;&#8212;enig7908179A37B0D63E2981DCF1&quot; X-IMAPbase: 1176125385 9175 Status: O X-UID: 9175 Content-Length: 3730 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-12/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-12/#comments</comments>
		<pubDate>Sun, 24 May 2009 13:05:12 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200905-02 ] Cscope: User-assisted execution of arbitrary code Posted by Pierre-Yves Rofes on May 24 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo Linux [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/May/0195.html">[ GLSA 200905-02 ] Cscope: User-assisted execution of arbitrary code</a></h1>
</p>
<p>Posted by Pierre-Yves Rofes on May 24
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200905-02 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/May/0195.html">http://seclists.org/fulldisclosure/2009/May/0195.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1311 (firefox, seamonkey)</title>
		<link>http://sechero.com/1311-firefox-seamonkey/</link>
		<comments>http://sechero.com/1311-firefox-seamonkey/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false">http://sechero.com/1311-firefox-seamonkey/</guid>
		<description><![CDATA[CVE-2009-1311 (firefox, seamonkey) Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame&#8217;s URL during a SAVEMODE_FILEONLY save of the inner frame. URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1311]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1311">CVE-2009-1311 (firefox, seamonkey)</a></h1>
</p>
<p>Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame&#8217;s URL during a SAVEMODE_FILEONLY save of the inner frame.
<p>URL: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1311">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1311</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/1311-firefox-seamonkey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1310 (firefox)</title>
		<link>http://sechero.com/1310-firefox/</link>
		<comments>http://sechero.com/1310-firefox/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[User-Assisted]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/1310-firefox/</guid>
		<description><![CDATA[CVE-2009-1310 (firefox) Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element. URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1310]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1310">CVE-2009-1310 (firefox)</a></h1>
</p>
<p>Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.
<p>URL: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1310">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1310</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/1310-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-10/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-10/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 15:44:34 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Bugtraq: [ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code [ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code URL: http://www.securityfocus.com/archive/1/502790]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/archive/1/502790">Bugtraq: [ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code</a></h1>
</p>
<p>[ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code
<p>URL: <a href="http://www.securityfocus.com/archive/1/502790">http://www.securityfocus.com/archive/1/502790</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-11/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-11/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 14:50:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code &#60;!&#8211; Envelope-to: email@address Delivery-date: Mon, 20 Apr 2009 15:45:27 +0100 Received: from outgoing.securityfocus.com ([205.206.231.27] helo=outgoing3.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1LvukQ-0004zH-Qo for email@address; Mon, 20 Apr 2009 15:45:26 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing3.securityfocus.com (Postfix) with QMQP id 53F7C237126; Mon, [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=85158">[ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Mon, 20 Apr 2009 15:45:27 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.27] helo=outgoing3.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1LvukQ-0004zH-Qo 	for email@address; Mon, 20 Apr 2009 15:45:26 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing3.securityfocus.com" title="http://outgoing3.securityfocus.com" target="_blank">outgoing3.securityfocus.com</a> (Postfix) with QMQP 	id 53F7C237126; Mon, 20 Apr 2009 08:38:44 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 26886 invoked from network); 18 Apr 2009 11:05:12 -0000 User-Agent: KMail/1.9.9 Cc: <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a>, 	<a href="mailto:security-alerts@linuxsecurity.com" title="mailto:security-alerts@linuxsecurity.com">security-alerts@linuxsecurity.com</a> MIME-Version: 1.0 Content-Type: multipart/signed;   boundary=&quot;nextPart1499796.gZMa6W10PW&quot;;   protocol=&quot;application/pgp-signature&quot;;   micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: &lt;200904181311.48413.rbu@gentoo.org&gt; X-IMAPbase: 1176125385 8831 Status: O X-UID: 8831 Content-Length: 5063 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-9/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-9/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 11:11:39 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code Posted by Robert Buchholz on Apr 18 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Apr/0192.html">[ GLSA 200904-17 ] Adobe Reader: User-assisted execution of arbitrary code</a></h1>
</p>
<p>Posted by Robert Buchholz on Apr 18
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200904-17 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Apr/0192.html">http://seclists.org/fulldisclosure/2009/Apr/0192.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-8/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-8/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 20:43:40 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false">http://sechero.com/user-assisted-execution-of-arbitrary-code-8/</guid>
		<description><![CDATA[Bugtraq: [ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code [ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code URL: http://www.securityfocus.com/archive/1/502764]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/archive/1/502764">Bugtraq: [ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code</a></h1>
</p>
<p>[ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code
<p>URL: <a href="http://www.securityfocus.com/archive/1/502764">http://www.securityfocus.com/archive/1/502764</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-7/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-7/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 19:20:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code &#60;!&#8211; Envelope-to: email@address Delivery-date: Fri, 17 Apr 2009 20:14:59 +0100 Received: from outgoing.securityfocus.com ([205.206.231.26] helo=outgoing2.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1LutWd-0005B1-Db for email@address; Fri, 17 Apr 2009 20:14:59 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing2.securityfocus.com (Postfix) with QMQP id 0D70A143918; Fri, 17 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=85127">[ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Fri, 17 Apr 2009 20:14:59 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.26] helo=outgoing2.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1LutWd-0005B1-Db 	for email@address; Fri, 17 Apr 2009 20:14:59 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing2.securityfocus.com" title="http://outgoing2.securityfocus.com" target="_blank">outgoing2.securityfocus.com</a> (Postfix) with QMQP 	id 0D70A143918; Fri, 17 Apr 2009 13:08:50 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 2408 invoked from network); 17 Apr 2009 18:53:54 -0000 Message-ID: &lt;49E8D266.8050505@gentoo.org&gt; User-Agent: Thunderbird 2.0.0.19 (X11/20090120) MIME-Version: 1.0 Cc: <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a>, <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, 	<a href="mailto:security-alerts@linuxsecurity.com" title="mailto:security-alerts@linuxsecurity.com">security-alerts@linuxsecurity.com</a>  code X-Enigmail-Version: 0.95.7 Content-Type: multipart/signed; micalg=pgp-sha1;  protocol=&quot;application/pgp-signature&quot;;  boundary=&quot;&#8212;&#8212;&#8212;&#8212;enig467ED426D4320B44AE46D35C&quot; X-IMAPbase: 1176125385 8826 Status: O X-UID: 8826 Content-Length: 3530 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-6/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-6/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 19:03:02 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false">http://sechero.com/user-assisted-execution-of-arbitrary-code-6/</guid>
		<description><![CDATA[[ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code Posted by Pierre-Yves Rofes on Apr 17 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo Linux [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Apr/0189.html">[ GLSA 200904-16 ] libsndfile: User-assisted execution of arbitrary code</a></h1>
</p>
<p>Posted by Pierre-Yves Rofes on Apr 17
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200904-16 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Apr/0189.html">http://seclists.org/fulldisclosure/2009/Apr/0189.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-5/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-5/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 17:40:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false">http://sechero.com/user-assisted-execution-of-arbitrary-code-5/</guid>
		<description><![CDATA[[ GLSA 200904-15 ] mpg123: User-assisted execution of arbitrary code &#60;!&#8211; Envelope-to: email@address Delivery-date: Fri, 17 Apr 2009 18:32:44 +0100 Received: from outgoing.securityfocus.com ([205.206.231.26] helo=outgoing2.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1Lurvg-0002n6-5F for email@address; Fri, 17 Apr 2009 18:32:44 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing2.securityfocus.com (Postfix) with QMQP id 8467A143A00; Fri, 17 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=85118">[ GLSA 200904-15 ] mpg123: User-assisted execution of arbitrary code</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Fri, 17 Apr 2009 18:32:44 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.26] helo=outgoing2.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1Lurvg-0002n6-5F 	for email@address; Fri, 17 Apr 2009 18:32:44 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing2.securityfocus.com" title="http://outgoing2.securityfocus.com" target="_blank">outgoing2.securityfocus.com</a> (Postfix) with QMQP 	id 8467A143A00; Fri, 17 Apr 2009 09:10:10 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 20449 invoked from network); 16 Apr 2009 21:56:40 -0000 User-Agent: KMail/1.9.9 Cc: <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a>, 	<a href="mailto:security-alerts@linuxsecurity.com" title="mailto:security-alerts@linuxsecurity.com">security-alerts@linuxsecurity.com</a> MIME-Version: 1.0 Content-Type: multipart/signed;   boundary=&quot;nextPart5373373.Ui0zdcsk9n&quot;;   protocol=&quot;application/pgp-signature&quot;;   micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: &lt;200904170002.58671.rbu@gentoo.org&gt; X-IMAPbase: 1176125385 8819 Status: O X-UID: 8819 Content-Length: 3719 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>User-assisted execution of arbitrary code</title>
		<link>http://sechero.com/user-assisted-execution-of-arbitrary-code-4/</link>
		<comments>http://sechero.com/user-assisted-execution-of-arbitrary-code-4/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 22:02:51 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[User-Assisted]]></category>

		<guid isPermaLink="false">http://sechero.com/user-assisted-execution-of-arbitrary-code-4/</guid>
		<description><![CDATA[[ GLSA 200904-15 ] mpg123: User-assisted execution of arbitrary code Posted by Robert Buchholz on Apr 17 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo Linux [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Apr/0166.html">[ GLSA 200904-15 ] mpg123: User-assisted execution of arbitrary code</a></h1>
</p>
<p>Posted by Robert Buchholz on Apr 17
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200904-15 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Apr/0166.html">http://seclists.org/fulldisclosure/2009/Apr/0166.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/user-assisted-execution-of-arbitrary-code-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3871 (ultraiso)</title>
		<link>http://sechero.com/3871-ultraiso/</link>
		<comments>http://sechero.com/3871-ultraiso/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[User-Assisted]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://sechero.com/3871-ultraiso/</guid>
		<description><![CDATA[CVE-2008-3871 (ultraiso) Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file. URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3871]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3871">CVE-2008-3871 (ultraiso)</a></h1>
</p>
<p>Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file.
<p>URL: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3871">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3871</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/3871-ultraiso/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

