<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE rss [<!ENTITY % HTMLlat1 PUBLIC "-//W3C//ENTITIES Latin 1 for XHTML//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml-lat1.ent">]>
<rss version="2.0" xml:base="http://www.infigo.hr">
<channel>
 <title>Infigo - Novo sigurnosno upozorenje</title>
 <link>http://www.infigo.hr/taxonomy/term/11/0</link>
 <description></description>
 <language>hr</language>
<item>
 <title>IN Focus</title>
 <link>http://www.infigo.hr/novo_sigurnosno_upozorenje/in_focus</link>
 <description>&lt;p align=&quot;justify&quot;&gt;Istraživanje i razvoj predstavlja vrlo važan segment u području informacijske sigurnosti. Prepoznav&amp;scaron;i važnost kontinuiranog praćenja svjetskih trendova u području otkrivanja novih sigurnosnih ranjivosti i metoda njihovog sprječavanja, INFIGO IS pokrenuo je vlastiti projekt pod nazivom IN Focus. &lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;U ovoj sekciji objavljena su sigurnosna upozorenja koja su rezultat istraživačkog rada, a kojima je cilj podizanje svijesti o informacijskoj sigurnosti te upoznavanje korisnika (domaće i svjetske security zajednice) s novim sigurnosnim prijetnjama i ranjivostima. Dobiveni rezultati također se koriste kao nadopuna komercijalnom djelovanju tvrtke, s ciljem podizanja razine sigurnosti informacijskih sustava svojih klijenata.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;Infigo IS objavljuje sigurnosne propuste i upozorenja u skladu s &lt;a target=&quot;_blank&quot; href=&quot;files/PUBLIC_Policy_002_V1.0_20080627_Disclosure policy.pdf&quot;&gt;Politikom objave sigurnosnih propusta&lt;/a&gt;.&lt;br /&gt;Infigo IS koristi PGP za enkripciju e-mail poruka koje se razmjenjuju s proizvođačima. Javni ključ se može preuzeti &lt;a target=&quot;_blank&quot; href=&quot;files/INFIGO_InFocus_PGP key.asc&quot;&gt;ovdje&lt;/a&gt;. &lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;Sva sigurnosna upozorenja i programski kod objavljen na ovim stranicama predstavlja vlasni&amp;scaron;tvo INFIGO IS i smije se koristiti isključivo u skladu s &lt;a href=&quot;uvjeti_koristenja&quot;&gt;Uvjetima kori&amp;scaron;tenja&lt;/a&gt;. &lt;/p&gt;
&lt;p align=&quot;right&quot;&gt;&lt;a href=&quot;hr/taxonomy/term/11/0/feed&quot;&gt;&lt;img border=&quot;0&quot; alt=&quot;rss&quot; title=&quot;rss&quot; src=&quot;files/rss2.gif&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p align=&quot;justify&quot; class=&quot;crvena_linija&quot;&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Fri, 24 Feb 2006 09:59:40 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2009-07-09</title>
 <link>http://www.infigo.hr/in_focus/2009_07_09_hr</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 222px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#666666&quot;&gt;&lt;a href=&quot;en/in_focus/advisories/INFIGO-2009-07-09&quot;&gt;NASA Common Data Format remote buffer overflow(s)&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2009-07-09&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2009-07-20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot; align=&quot;justify&quot;&gt;
&lt;p&gt;CDF is the Common Data Format. It is a conceptual data abstraction for storing, manipulating, and accessing multidimensional data sets.&amp;nbsp; The basic component of CDF is a software programming interface that is a device-independent view of the CDF data model. &lt;/p&gt;
&lt;p&gt;The CDF software package is used by hundreds of government agencies, universities, and private and commercial organizations as well as&amp;nbsp;independent researchers on both national and international levels.&amp;nbsp; CDF has been adopted by the International Solar-Terrestrial Physics (ISTP) project as well as the Central Data Handling Facilities (CDHF) as their format of choice for storing and distributing key parameter data. A list of some applications that use the CDF library can be found at &lt;a target=&quot;_blank&quot; href=&quot;http://cdf.gsfc.nasa.gov/html/examples.html&quot;&gt;http://cdf.gsfc.nasa.gov/html/examples.html&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Mon, 20 Jul 2009 23:23:27 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-04-08</title>
 <link>http://www.infigo.hr/in_focus/2008_04_08_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2008-04-08&quot;&gt;ICQ 6 remote buffer overflow vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-04-08&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-04-14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;ICQ (I Seek You) je jedan od najpopularnijih IM (Instant Messenger) programa. Od 1996. godine broj korisnika narastao je na preko 180 milijuna. ICQ nudi velik broj funkcionalnosti koje između ostalog uključuju slanje instant poruka, slanje poruka elektroničke po&amp;scaron;te, SMS poruka, prijenos datoteka, itd.&lt;br /&gt;INFIGO IS Istraživački tim otkrio je u posljednjoj ICQ inačici (ICQ 6.0) kritičnu ranjivost udaljenog prepisivanja spremnika. Kad korisnik unese poruku u status manager sučelju, tekst poruke procesira boxelyRenderer modul. Ovaj modul posjeduje ranjivost prilikom procesiranja HTML tagova. Ukoliko se za statusnu&amp;nbsp;poruku (eng. status message) unese posebno kreirani HTML kod, boxelyRenderer&amp;nbsp;modul će poku&amp;scaron;ati procesirati HTML tagove, pri čemu će doći do prepisivanja stoga.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Mon, 14 Apr 2008 16:31:03 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-03-07</title>
 <link>http://www.infigo.hr/in_focus/2008_03_07_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2008-03-07&quot;&gt;Surgemail 38k4 IMAP server remote stack overflow&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-03-07&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-03-21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;SurgeMail Mail Server Software Suite paket kombinira napredne funkcije, visoke performanse te jednostavnost upotrebe. SurgeMail Server radi na Windows, Unix (Linux, Solaris, etc.), Mac OSX, FreeBSD i ostalim platformama. Surgemail integrirani email poslužitelj obuhvaća između ostalog antispam poslužitelj, antivirusni poslužitelj, webmail poslužitelj, blog poslužitelj itd.&lt;br /&gt;Tijekom sigurnosne analize Surgemail IMAP poslužitelja otkrivena je ranjivost prepisivanja stoga, koja je uzrokovana graničnom pogre&amp;scaron;kom IMAP poslužitelja prilikom procesiranja predugih argumenata &#039;LSUB&#039; naredbe.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Fri, 21 Mar 2008 09:59:49 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-02-13</title>
 <link>http://www.infigo.hr/in_focus/2008_02_13_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2008-02-13&quot;&gt;SOPHOS Email Security Appliance Cross Site Scripting Vulnerability&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-02-13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-02-13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Sophosov uređaj Sophos ES1000 Email Security Appliance omogućuje za&amp;scaron;titu od spama, virusa, spyware programa i ostalih oblika malicioznih programa. Sophosov nagrađivani&amp;nbsp;anti-virusni mehanizam detektira sve tipove malicioznih programa u jednom skeniranju velike brzine.&lt;br /&gt;Tijekom sigurnosne analize Sophosovog uređaja ES1000 INFIGO IS istraživački tim otkrio je Cross Site Scripting ranjivost u administracijskom sučelju. Nedostatak provjere unosa za parametre &#039;error&#039; i &#039;go&#039; u &#039;Login&#039; skripti maliciozni korisnik može iskoristiti za krađu administratorskih podataka, te obustavu rada uređaja, ili promjenu konfiguracijskih postavki.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Fri, 15 Feb 2008 15:28:12 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2008-01-06</title>
 <link>http://www.infigo.hr/in_focus/2008_01_06_hr</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 222px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2008-01-06&quot;&gt;McAfee E-Business Server Remote Preauth Code Execution / DoS&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2008-01-06&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2008-01-09&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;McAfee E-business Server &amp;scaron;titi osjetljive poslovne podatake PGP 128-bitnom enkripcijom i autentikacijom, te podržava velik broj platformi i sigurnosnih certifikata.&lt;br /&gt;Tijekom sigurnosne analize McAfee E-business Servera INFIGO IS istraživački tim otkrio je kritični propust u administracijskom sučelju (TCP port 1718).&lt;br /&gt;Kroz navedeni propust moguće je tijekom autentikacijskog procesa izazvati ru&amp;scaron;enje McAfee E-Business Servera. McAfee je daljnjim istraživanjem propusta također potvrdio da je moguće i udaljeno izvr&amp;scaron;avanje koda. &lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Wed, 09 Jan 2008 12:07:37 +0100</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2007-04-05</title>
 <link>http://www.infigo.hr/in_focus/2007_04_05_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&lt;/span&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2007-04-05&quot;&gt;Enterprise Security Analyzer server remote buffer overflows&lt;u&gt;&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2007-04-05&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2007-04-10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&lt;/span&gt;&amp;nbsp;&lt;font color=&quot;#000000&quot;&gt; &amp;nbsp; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Enterprise Security Analyzer (ESA) je produkt tvrtke eIQnetworks (&lt;a href=&quot;http://www.eiqnetworks.com/&quot;&gt;http://www.eIQnetworks.com&lt;/a&gt;) koji omogućuje upravljanje informacijskom sigurno&amp;scaron;ću na razini cjelokupne organizacije ili tvrtke.&lt;br /&gt;Tijekom sigurnosne analize Enterprise Security Analyzer (ESA) alata INFIGO IS istraživački tim otkrio je vi&amp;scaron;e kritičnih propusta u ESA poslužitelju (TCP port 10616).&lt;br /&gt;Propusti se javljaju prilikom obrade posebno kreiranih ESA zahtjeva, koji rezultiraju prepisivanjem spremnika.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Tue, 10 Apr 2007 13:04:24 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-08-04</title>
 <link>http://www.infigo.hr/in_focus/2006_08_04_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;in_focus/advisories/INFIGO-2006-08-04&quot;&gt;MDaemon POP3 server remote buffer overflow (preauth)&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-08-04&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-08-21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Tijekom sigurnosne analize POP3 protokola kod raznih e-mail poslužitelja INFIGO IS istraživački tim otkrio je kritični propust u implementaciji tog protokola kod MDaemon poslužitelja.&lt;br /&gt;Propust omogućava udaljenom napadaču preuzimanje potpune kontrole nad ranjivim poslužiteljem, a dodatni problem predstavlja priroda e-mail, odnosno POP3 protokola, koji je vrlo često dostupan ne samo s interne mreže već i preko Interneta.&lt;br /&gt;U suradnji s INFIGO IS, proizvođač je objavio novu inačicu MDaemon poslužitelja koja ispravlja uočeni nedostatak.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Mon, 21 Aug 2006 11:16:06 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-05-03</title>
 <link>http://www.infigo.hr/in_focus/2006_05_03_hr</link>
 <description>&lt;table style=&quot;height: 222px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2006-05-03&quot;&gt;Multiple FTP Servers vulnerabilities&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-05-03&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-05-05&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Infigo IS je objavio jednostavni GUI FTP fuzzer alat koji se može dohvatiti s &lt;a href=&quot;hr/in_focus/tools&quot;&gt;http://www.infigo.hr/hr/in_focus/tools&lt;/a&gt;. Objava koja je sadržavala opis nekoliko ranjivosti otkrivenih ovim alatom je poslana na nekoliko sigurnosnih grupa.&lt;br /&gt;Zbog pogre&amp;scaron;ne interpretacije spomenutih ranjivosti u prenesenim objavama i sigurnosnim upozorenjima objavljeno je ovo sigurnosno upozorenje.&lt;br /&gt;Ranjivosti opisane u sigurnosnom upozorenju pronađene su u sljedećim FTP poslužiteljima:&lt;br /&gt;- ArgoSoft FTP Server&lt;br /&gt;- Golden FTP Server&lt;br /&gt;- Filezilla&lt;br /&gt;- War FTP Daemon&lt;br /&gt;- Guild FTP Server&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Thu, 04 May 2006 12:48:58 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-04-02</title>
 <link>http://www.infigo.hr/in_focus/2006_04_02_hr</link>
 <description>&lt;table style=&quot;height: 176px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;hr/in_focus/advisories/INFIGO-2006-04-02&quot;&gt;Multiple PHP4/PHP5 vulnerabilities&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-04-02&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-04-24&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;Medium&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;INFIGO IS istraživački tim proveo je analizu koda PHP interpretera i pri tom je otkriveno vi&amp;scaron;e od 20 različitih ranjivosti. Do objave ovog sigurnosnog upozorenja veći dio njih je prijavljen i ispravljen u novim inačicama PHP-a.&lt;br /&gt;Unatoč tome, dio ranjivosti ostao je neispravljen i u trenutno dostupnim inačicama PHP 4 i PHP 5. Proizvođač je kontaktiran u vi&amp;scaron;e navrata tijekom posljednja dva mjeseca, no unatoč tome nije poslao nikakav službeni odgovor, tako da u ovom trenutku službene zakrpe nisu dostupne.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Mon, 24 Apr 2006 15:22:41 +0200</pubDate>
</item>
<item>
 <title>INFIGO IS Security Advisory #INFIGO-2006-03-01</title>
 <link>http://www.infigo.hr/in_focus/2006_03_01</link>
 <description>&lt;table style=&quot;height: 168px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;hr/in_focus/INFIGO-2006-03-01&quot;&gt;PeerCast streaming server remote buffer overflow&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Advisory ID:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;INFIGO-2006-03-01&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;2006-03-08&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Risk Level:&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Sigurnosni stručnajci INFIGO IS prona&amp;scaron;li su u PeerCast Streaming poslužitelju sigurnosni propust visokog rizika koji udaljenim korisnicima, slanjem posebno oblikovanog HTTP zahtjeva može omogućiti izvr&amp;scaron;avanje programskog koda.&lt;br /&gt;PeerCast na jednostavan način omogućava slu&amp;scaron;anje radijskih programa ili pregledavanje video sadržaja na Internetu. Dostupne su inačice za Linux, Windows i MacOS platforme.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
 <category domain="http://www.infigo.hr/in_focus">Novo sigurnosno upozorenje</category>
 <pubDate>Wed, 08 Mar 2006 17:08:27 +0100</pubDate>
</item>
</channel>
</rss>
