<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE rss [<!ENTITY % HTMLlat1 PUBLIC "-//W3C//ENTITIES Latin 1 for XHTML//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml-lat1.ent">]>
<rss version="2.0" xml:base="http://www.infigo.hr">
<channel>
 <title>Infigo - New Security Announcement</title>
 <link>http://www.infigo.hr/taxonomy/term/27/0</link>
 <description></description>
 <language>en</language>
<item>
 <title>IN Focus</title>
 <link>http://www.infigo.hr/en/novo_sigurnosno_upozorenje/in_focus</link>
 <description>&lt;p align=&quot;justify&quot;&gt;Research and development is an important element in the information security area. INFIGO IS understands the importance of continuous investment in research about vulnerabilities and prevention methods. That&#039;s why INFIGO IS started the In Focus project.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;Security advisories published in this section are result of the INFIGO IS research. The main goal of that research work is raising consciousness about information security and making the security community aware of new security threats and vulnerabilities. Research results are also used for company&#039;s commercial activities in order to raise our clients&#039; overall information systems&#039; security.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;INFIGO IS publishes security advisories according to &lt;a target=&quot;_blank&quot; href=&quot;files/PUBLIC_Policy_002_V1.0_20080627_Disclosure policy.pdf&quot;&gt;INFIGO IS Disclosure policy&lt;/a&gt;.&lt;br /&gt;All e-mail communication with the vendor must be encrypted. INFIGO IS uses PGP for e-mail encryption. Public key can be downloaded &lt;a href=&quot;files/INFIGO_InFocus_PGP key.asc&quot;&gt;here&lt;/a&gt;. &lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;Security advisories and the program code published on these pages are sole property of INFIGO IS and can be used only according to the &lt;a href=&quot;en/uvjeti_koristenja&quot;&gt;Terms of Use&lt;/a&gt;.&lt;/p&gt;
&lt;p align=&quot;right&quot;&gt;&lt;a href=&quot;en/taxonomy/term/27/0/feed&quot;&gt;&lt;img border=&quot;0&quot; alt=&quot;rss&quot; title=&quot;rss&quot; src=&quot;files/rss2.gif&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p align=&quot;justify&quot; class=&quot;crvena_linija&quot;&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Thu, 30 Mar 2006 16:25:03 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2009-07-09</title>
 <link>http://www.infigo.hr/in_focus/2009_07_09_en</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 222px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#666666&quot;&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2009-07-09&quot;&gt;NASA Common Data Format remote buffer overflow(s)&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2009-07-09&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2009-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot; align=&quot;justify&quot;&gt;
&lt;p&gt;CDF is the Common Data Format. It is a conceptual data abstraction for storing, manipulating, and accessing multidimensional data sets.&amp;nbsp; The basic component of CDF is a software programming interface that is a device-independent view of the CDF data model. &lt;/p&gt;
&lt;p&gt;The CDF software package is used by hundreds of government agencies, universities, and private and commercial organizations as well as&amp;nbsp;independent researchers on both national and international levels.&amp;nbsp; CDF has been adopted by the International Solar-Terrestrial Physics (ISTP) project as well as the Central Data Handling Facilities (CDHF) as their format of choice for storing and distributing key parameter data. A list of some applications that use the CDF library can be found at &lt;a target=&quot;_blank&quot; href=&quot;http://cdf.gsfc.nasa.gov/html/examples.html&quot;&gt;http://cdf.gsfc.nasa.gov/html/examples.html&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Mon, 20 Jul 2009 23:19:13 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-04-08</title>
 <link>http://www.infigo.hr/in_focus/2008_04_08_en</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;u&gt;&lt;font color=&quot;#666666&quot;&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2008-04-08&quot;&gt;ICQ 6 remote buffer overflow vulnerability&lt;/a&gt;&lt;/font&gt;&lt;/u&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-04-08&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-04-14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;ICQ (I Seek You) Instant Messenger is one of the most popular internet chat software. Since 1996, it has grown to a community of over 180&amp;nbsp;million users. It has features for instant messaging, chat, sending e-mail, SMS, file transfer, wireless-pager messages, etc.&lt;br /&gt;INFIGO IS&#039;s security team identified a critical remote buffer overflow vulnerability in the latest ICQ version (ICQ 6.0). When a user writes a message in the status manager, the text string is processed with the boxelyRenderer module. The boxelyRenderer module has a vulnerability in the HTML tags processing code. If malformed HTML tags are set for the &#039;status message&#039;, boxelyRenderer will try to process the HTML tags, and a UNICODE heap overflow will occur. &lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Mon, 14 Apr 2008 16:26:23 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-03-07</title>
 <link>http://www.infigo.hr/in_focus/2008_03_07_en</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2008-03-07&quot;&gt;Surgemail 38k4 IMAP server remote stack overflow&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-03-07&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-03-21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;SurgeMail Mail Server Software Suite - combines advanced features, high performance and ease of use. Works on Windows, UNIX (Linux, Solaris etc.), Mac OSX, FreeBSD and others. Surgemail integrated email server is an Antispam Server, Antivirus Server, Webmail Server, Groupware Server, Blog Server and much more. &lt;br /&gt;A remote vanilla stack overflow vulnerability exists in the Surgemail IMAP server. The vulnerability is caused due to a boundary error in the IMAP server, when processing overly long arguments of the &#039;LSUB&#039; command.&amp;nbsp;The vulnerability results in a simple stack overflow condition that can be trivially exploited.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Fri, 21 Mar 2008 10:02:59 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-02-13</title>
 <link>http://www.infigo.hr/in_focus/2008_02_13_en</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2008-02-13&quot;&gt;SOPHOS Email Security Appliance Cross Site Scripting Vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-02-13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-02-13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Sophos ES1000 Email Security Appliance delivers protection against spam, viruses, Trojans, spyware and other malware. Sophos&#039;s award-winning anti-virus engine detects all types of malware in a single, high-speed&amp;nbsp;scan.&lt;br /&gt;During an audit of Sophos ES1000 Email Security Appliance, a Cross Site Scripting&lt;br /&gt;vulnerability was discovered in its web administration interface. Lack of input validation for &#039;error&#039; and &#039;go&#039; parameters of the &#039;Login&#039; script can be exploited by a malicious user to steal Sophos ES1000 Email Security Appliance administrator credentials, and shut down the appliance, or change its configuration.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Fri, 15 Feb 2008 14:50:54 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-01-06</title>
 <link>http://www.infigo.hr/in_focus/2008_01_06_en</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2008-01-06&quot;&gt;McAfee E-Business Server Remote Preauth Code Execution / DoS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-01-06&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-01-06&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;McAfee E-Business Server guards sensitive corporate data with industry-standard PGP 128-bit encryption and authentication. McAfee E-Business Server supports a variety of platforms and security certificates.&lt;br /&gt;During an audit of McAfee E-Business Server, we have discovered a vulnerability in the administration interface (TCP port 1718).&lt;br /&gt;It is possible to crash McAfee E-Business Server during the authentication process.&lt;br /&gt;McAfee further researched the vulnerability and confirmed that it also allows an attacker to execute code remotely.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Wed, 09 Jan 2008 14:00:26 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2007-04-05</title>
 <link>http://www.infigo.hr/in_focus/2007_04_05_en</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 222px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2007-04-05&quot;&gt;Enterprise Security Analyzer server remote buffer overflows&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2007-04-05&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2007-04-10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Enterprise Security Analyzer (ESA) from eIQnetworks (&lt;a href=&quot;http://www.eiqnetworks.com/&quot;&gt;http://www.eIQnetworks.com&lt;/a&gt;) is a Security Information Management (SIM) solution that provides security intelligence across the enterprise.&lt;br /&gt;During an audit of Enterprise Security Analyzer, multiple remote buffer overflows have been discovered in the ESA server (TCP port 10616).&lt;br /&gt;Specially crafted ESA requests can lead to various stack and heap overflows. &lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Tue, 10 Apr 2007 13:38:57 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-08-04</title>
 <link>http://www.infigo.hr/in_focus/2006_08_04_en</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2006-08-04&quot;&gt;MDaemon POP3 server remote buffer overflow (preauth)&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-08-04&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-08-21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;During security analysis of POP3 protocol in various e-mail server software products INFIGO IS research team discovered a critical vulnerability in the MDaemon e-mail server software.&lt;br /&gt;After successful exploitation, remote attacker can take complete control of the vulnerable e-mail server. Nature of the e-mail and POP3 protocol which are often accessible not only form internal network, but from the Internet furthermore increases severity of the problem.&lt;br /&gt;With assistance of INFIGO IS, the vendor has released a new version of MDaemon e-mail server which eliminates the vulnerability.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Mon, 21 Aug 2006 11:17:40 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-05-03</title>
 <link>http://www.infigo.hr/in_focus/2006_05_03_eng</link>
 <description>&lt;table style=&quot;height: 231px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2006-05-03&quot;&gt;Multiple FTP Servers vulnerabilities&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-05-03&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-05-05&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Infigo IS released a simple GUI FTP fuzzer which can be downloaded from &lt;a href=&quot;en/in_focus/tools&quot;&gt;http://www.infigo.hr/en/in_focus/tools&lt;/a&gt;. An announcement which was posted to the multiple security groups included overview of several vulnerabilities discovered with the Fuzzer.&lt;br /&gt;This advisory is published due to some misinterpretations in further reposts discussing vulnerabilities discovered.&lt;br /&gt;Vulnerabilities described in this advisory were found in the following FTP server software products:&lt;br /&gt;- ArgoSoft FTP Server&lt;br /&gt;- Golden FTP Server&lt;br /&gt;- Filezilla&lt;br /&gt;- War FTP Daemon&lt;br /&gt;- Guild FTP Server&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Thu, 04 May 2006 10:54:02 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-04-02</title>
 <link>http://www.infigo.hr/in_focus/2006_04_02_eng</link>
 <description>&lt;table style=&quot;height: 176px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2006-04-02&quot;&gt;Multiple PHP4/PHP5 vulnerabilities&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-04-02&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-04-24&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;The INFIGO IS research team audited the PHP interpreter code and more than 20 vulnerabilities in PHP4 and PHP5 have been discovered. Most of them have been reported and fixed.&lt;br /&gt;However, several vulnerabilities are still present in current PHP 4 and PHP 5 versions. During the last two months the vendor has been contacted several times but no official response has been received. At the moment no official patches are available.&lt;br /&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Mon, 24 Apr 2006 15:17:58 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-03-01</title>
 <link>http://www.infigo.hr/in_focus/2006_03_01_eng</link>
 <description>&lt;table style=&quot;height: 168px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;en/in_focus/INFIGO-2006-03-01&quot;&gt;PeerCast streaming server remote buffer overflow&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-03-01&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-03-08&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;INFIGO IS security research team discovered a high risk vulnerability in PeerCast Streaming server software. Malicious remote user can exploit this vulnerability by sending specialy crafted HTTP request.&lt;br /&gt;PeerCast is a simple, free way to listen to radio and watch video on the Internet. Versions for Linux,Windows and MacOS platforms are available.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/en/in_focus">New Security Announcement</category>
 <pubDate>Fri, 31 Mar 2006 11:11:27 +0200</pubDate>
</item>
</channel>
</rss>
