<?xml version="1.0" encoding="utf-8"?>
 
<rss version="2.0">
 
  <channel>
    <title>News from trapkit.de</title>
    <link>http://www.trapkit.de</link>
    <description>News from trapkit.de</description>
    <language>en</language>
    <copyright>tk</copyright>

    <item>
      <title>[16.07.2010] Oracle Solaris Kernel Security Advisory</title>
      <description>Oracle released an updated version of their kernel for Solaris 10 and OpenSolaris. The update fixes a denial of service bug I found in the Solaris kernel. For more information see <a href="http://www.trapkit.de/advisories/TKADV2010-005.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2010/07/zone-crasher.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=30</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=30</guid>
      <pubDate>Fri, 16 Jul 2010 18:07:56</pubDate>
    </item>		
	
    <item>
      <title>[22.02.2010] avast! Security Advisory</title>
      <description>ALWIL software released an updated version of avast!. The update fixes a memory corruption vulnerability I found in one of the kernel drivers shipped with avast! 4.8 and 5.0. For more information see <a href="http://www.trapkit.de/advisories/TKADV2010-003.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2010/02/fix-that-never-was.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=29</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=29</guid>
      <pubDate>Mon, 22 Feb 2010 15:21:39</pubDate>
    </item>			

    <item> 
      <title>[02.02.2010] Apple iPhone OS and Mac OS X Security Advisory</title> 
      <description>Apple released security updates for iPhone OS and Mac OS X that fix a stack buffer overflow vulnerability I found in CoreAudio. For more information see <a href="http://www.trapkit.de/advisories/TKADV2010-002.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2010/02/iphone-os-and-mac-os-x-stack-buffer.html">Related blog entry</a></description> 
      <link>http://www.trapkit.de/?p=28</link> 
      <author>tk</author> 
      <guid>http://www.trapkit.de/?p=28</guid> 
      <pubDate>Tue, 02 Feb 2010 22:08:23</pubDate> 
    </item>	
	
    <item>
      <title>[31.01.2010] Oracle Solaris Kernel Security Advisory</title>
      <description>Oracle released an updated version of their kernel for Solaris 10 and OpenSolaris. The update fixes a NULL pointer dereference I found in the Solaris kernel. For more information see <a href="http://www.trapkit.de/advisories/TKADV2010-001.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2010/01/kernel-null-pointer-dereference-in.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=27</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=27</guid>
      <pubDate>Sun, 31 Jan 2010 12:01:34</pubDate>
    </item>			
	
    <item>
      <title>[27.12.2009] New version of checksec.sh</title>
      <description>I released a new version of checksec.sh. This script is designed to test what standard Linux OS security features are being used. For more information <a href="http://www.trapkit.de/tools/checksec.html">click here</a>.</description>
      <link>http://www.trapkit.de/?p=26</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=26</guid>
      <pubDate>Sun, 27 Dec 2009 12:39:28</pubDate>
    </item>		
	
    <item>
      <title>[09.09.2009] Apple iPhone OS AudioCodecs Heap Buffer Overflow (TKADV2009-007)</title>
      <description>Apple released an updated version of their iPhone OS. The update fixes a heap buffer overflow vulnerability I found in the AudioCodecs library of iPhone OS &lt; 3.1 and iPhone OS &lt; 3.1.1 for iPod touch.<a href="http://www.trapkit.de/advisories/TKADV2009-007.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/09/ringtone-massacre.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=25</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=25</guid>
      <pubDate>Wed, 09 Sep 2009 23:35:23</pubDate>
    </item>	
	
    <item>
      <title>[16.05.2009] libsndfile/Winamp Security Advisory (TKADV2009-006)</title>
      <description>The libsndfile maintainers released an updated version of their multimedia library. The update fixes a heap buffer overflow vulnerability I found in the VOC (Creative Voice) demuxer. As libsndfile is used by Winamp (and other software projects) this popular media player is also affected by this vulnerability.<a href="advisories/TKADV2009-006.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/05/exploitable-vs-tkadv2009-006-vs-static.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=24</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=24</guid>
      <pubDate>Sa, 16 May 2009 08:31:37</pubDate>
    </item>
	
    <item>
      <title>[04.04.2009] xine-lib Security Advisory (TKADV2009-005)</title>
      <description>The xine-lib maintainers released an updated version of their multimedia library. The update fixes an integer overflow vulnerability I found in the Quicktime demuxer.<a href="advisories/TKADV2009-005.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/04/tkadv2009-005.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=23</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=23</guid>
      <pubDate>Sa, 04 Apr 2009 11:41:42</pubDate>
    </item>
	
    <item>
      <title>[15.02.2009] xine-lib also affected by TKADV2009-004</title>
      <description>I updated TKADV2009-004 as xine-lib &lt; version 1.1.16.2 is also affected by a variant of the bug described in the advisory.<a href="advisories/TKADV2009-004.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/02/tkadv2009-004-vs-xine-lib.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=22</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=22</guid>
      <pubDate>Sun, 15 Feb 2009 15:00:43</pubDate>
    </item>		
	
    <item>
      <title>[28.01.2009] FFmpeg Security Advisory (TKADV2009-004)</title>
      <description>Today the FFmpeg maintainers released an updated version of their multimedia framework. The update fixes a type conversion vulnerability I found in FFmpeg.<a href="advisories/TKADV2009-004.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/01/exploitable-userland-null-pointer.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=21</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=21</guid>
      <pubDate>Wed, 28 Jan 2009 21:22:38</pubDate>
    </item>	
	
    <item>
      <title>[22.01.2009] GStreamer Security Advisory (TKADV2009-003)</title>
      <description>Today the GStreamer maintainers released an updated version of their multimedia framework. The update fixes some Heap Buffer Overflows and Array Index Out of Bounds vulnerability I found in GStreamer.<a href="advisories/TKADV2009-003.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/01/gstreamer-bugs.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=20</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=20</guid>
      <pubDate>Thu, 22 Jan 2009 21:17:33</pubDate>
    </item>	
	
    <item>
      <title>[11.01.2009] Amarok Security Advisory (TKADV2009-002)</title>
      <description>Today the Amarok maintainers released an updated version of their media player. The update fixes some Integer Overflow and Unchecked Allocation vulnerabilities I found in Amarok.<a href="advisories/TKADV2009-002.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/01/some-statistics.html">Related blog entry</a></description>
      <link>http://www.trapkit.de/?p=19</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=19</guid>
      <pubDate>Sun, 11 Jan 2009 18:28:26</pubDate>
    </item>
	
    <item>
      <title>[11.01.2009] Sun Solaris Kernel Security Advisory (TKADV2009-001)</title>
      <description>Sun released an updated version of their kernel for Sun Solaris 8, 9, 10 and OpenSolaris. The update fixes an Integer Overflow vulnerability I found in the Sun Solaris kernel.<a href="advisories/TKADV2009-001.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2009/01/vmemxalloc-size-0.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=18</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=18</guid>
      <pubDate>Sun, 11 Jan 2009 17:12:43</pubDate>
    </item>		
	
    <item>
      <title>[17.12.2008] Sun Solaris Kernel Security Advisory (TKADV2008-015)</title>
      <description>After a patch development time of <strong>471 days</strong> Sun released an updated version of their kernel for Sun Solaris 10 and OpenSolaris. The update fixes a NULL pointer dereference vulnerability I found in the Sun Solaris kernel.<a href="advisories/TKADV2008-015.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/12/null-pointer-exploitation.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=17</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=17</guid>
      <pubDate>We, 17 Dec 2008 22:17:54</pubDate>
    </item>		
	
    <item>
      <title>[14.12.2008] MPlayer Security Advisory (TKADV2008-014)</title>
      <description>This security advisory describes the technical details of a stack buffer overflow vulnerability I found in the TwinVQ demuxer of MPlayer.<a href="advisories/TKADV2008-014.txt">Advisory</a></description>
      <link>http://www.trapkit.de/?p=16</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=16</guid>
      <pubDate>So, 14 Dec 2008 16:53:56</pubDate>
    </item>			
	
    <item>
      <title>[30.11.2008] VLC Media Player Security Advisory (TKADV2008-013)</title>
      <description>This security advisory describes the technical details of an integer overflow vulnerability I found in the RealMedia demuxer of VLC media player.<a href="advisories/TKADV2008-013.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/11/oops-i-did-it-again.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=15</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=15</guid>
      <pubDate>So, 30 Nov 2008 15:25:37</pubDate>
    </item>		
	
    <item>
      <title>[05.11.2008] VLC Media Player Advisories (TKADV2008-011/TKADV2008-012)</title>
      <description>These advisories are describing the technical details of two stack overflows I found in the RealText and CUE demuxers of VLC media player.<a href="http://www.trapkit.de/advisories/TKADV2008-011.txt">TKADV2008-011</a> <a href="http://www.trapkit.de/advisories/TKADV2008-012.txt">TKADV2008-012</a></description>
      <link>http://www.trapkit.de/?p=14</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=14</guid>
      <pubDate>We, 5 Nov 2008 23:44:26</pubDate>
    </item>		
	
    <item>
      <title>[20.10.2008] VLC Media Player Security Advisory (TKADV2008-010)</title>
      <description>This security advisory describes the technical details of a security vulnerability I found in the TiVo demuxer of VLC media player.<a href="advisories/TKADV2008-010.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/10/back-to-90s-vlc-case.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=13</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=13</guid>
      <pubDate>Mo, 20 Oct 2008 19:44:34</pubDate>
    </item>		
	
    <item>
      <title>[21.09.2008] WebEx Security Advisory (TKADV2008-009)</title>
      <description>This security advisory describes the technical details of a security vulnerability I found in an activex component of the WebEx Meeting Manager.<a href="advisories/TKADV2008-009.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/09/vulnerability-rediscovery-xss-and-webex.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=12</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=12</guid>
      <pubDate>So, 21 Sep 2008 19:50:34</pubDate>
    </item>	
	
    <item>
      <title>[17.09.2008] G DATA Security Advisory (TKADV2008-008)</title>
      <description>This security advisory describes the technical details of a security vulnerability I found in the G DATA products AntiVirus, InternetSecurity and TotalCare 2008. G DATA needed a patch development time of 294 days to fix the bug.<a href="advisories/TKADV2008-008.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/09/finally-fixed.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=11</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=11</guid>
      <pubDate>Tue, 17 Sep 2008 22:57:45</pubDate>
    </item>	
	
    <item>
      <title>[09.09.2008] Linux Kernel SCTP-AUTH API Advisory (TKADV2008-007)</title>
      <description>This security advisory describes the technical details of some vulnerabilities I found in the SCTP-AUTH API of the Linux Kernel. The kernel maintainers needed a patch development time of 1 day to fix the bugs. <a href="advisories/TKADV2008-007.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/09/linux-kernel-and-silent-fixes.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=10</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=10</guid>
      <pubDate>Tue, 9 Sep 2008 21:32:15</pubDate>
    </item> 
	
    <item>
      <title>[12.08.2008] CA HIPS KmxFw.sys Kernel Memory Corruption (TKADV2008-006)</title>
      <description>After a patch development time of 158 days CA released updates for various of their products. The updates are fixing a memory corruption vulnerability (kernel pool corruption) I found in one of the drivers shipped with these products. <a href="advisories/TKADV2008-006.txt">Advisory</a> <a href="http://tk-blog.blogspot.com/2008/08/reliable-code-execution-with-tkadv2008.html">Exploitability</a></description>
      <link>http://www.trapkit.de/?p=9</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=9</guid>
      <pubDate>Tue, 12 Aug 2008 20:02:15</pubDate>
    </item> 
 
    <item>
      <title>[08.08.2008] Blogging</title>
      <description>(Like everyone else) I now have a <a href="http://tk-blog.blogspot.com/">blog</a> where I will publish random thoughts on security vulnerabilities, exploiting and stories from kernel land from time to time. The news from trapkit.de are now also available as <a href="http://www.trapkit.de/rss.xml">RSS feed</a>.</description>
      <link>http://www.trapkit.de/?p=8</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=8</guid>
      <pubDate>Fri, 8 Aug 2008 20:35:19</pubDate>
    </item>
 
     <item>
      <title>[06.08.2008] Linux Kernel Security Advisory released (TKADV2008-005)</title>
      <description>This security advisory describes the technical details of the vulnerability <a href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=82e68f7ffec3800425f2391c8c86277606860442">CVE-2008-3272</a> I found in the Linux kernel. The kernel maintainers needed a patch development time of 4 days to fix this bug. <a href="advisories/TKADV2008-005.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=7</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=7</guid>
      <pubDate>Wed, 6 Aug 2008 22:23:54</pubDate>
    </item>
 
    <item>
      <title>[13.06.2008] Sun Solaris Security Advisory released (TKADV2008-003)</title>
      <description>After a patch development time of <strong>298 days</strong> (!) Sun finally released an updated version of their kernel for Sun Solaris 10 and OpenSolaris. The update fixes a memory corruption vulnerability (Integer Overlow, described in <a href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-237965-1">SunAlert #237965</a>) I found in the Sun Solaris kernel. <a href="advisories/TKADV2008-003.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=6</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=6</guid>
      <pubDate>Fr, 13 Jun 2008 23:11:24</pubDate>
    </item>
 
    <item>
      <title>[07.06.2008] ScoopyNG - The VMware detection tool v1.0 released</title>
      <description>ScoopyNG combines the detection tricks of <a href="research/vmm/scoopydoo/index.html">Scoopy Doo</a> and <a href="research/vmm/jerry/index.html">Jerry</a> as well as some new techniques to determine if a current OS is running inside a <a href="http://www.vmware.com/">VMware</a>  Virtual Machine (VM) or on a native system. ScoopyNG works on all modern uni-, multi- and multi-core cpu's and is able to detect VMware even if "anti-detection-mechanisms" are deployed. <a href="research/vmm/scoopyng/index.html">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=5</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=5</guid>
      <pubDate>Sat, 7 Jun 2008 16:37:46</pubDate>
    </item>
	
    <item>
      <title>[06.06.2008] Kaspersky Security Advisory released (TKADV2008-004)</title>
      <description>This security advisory describes the technical details of the vulnerability <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1518">CVE-2008-1518</a> I found and published working with iDefense VCP. Kaspersky needed a patch development time of 78 days to fix this bug. <a href="advisories/TKADV2008-004.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=4</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=4</guid>
      <pubDate>Fri, 6 Jun 2008 22:14:34</pubDate>
    </item>
	
    <item>
      <title>[30.03.2008] avast! 4.7 Security Advisory released (TKADV2008-002)</title>
      <description>After a patch development time of only 13 days ALWIL Software released an updated version of their avast! 4 Professional and Home Edition. The update fixes a memory corruption vulnerability (it's possible to write arbitrary data at an arbitrary memory address) I found in one of the drivers shipped with these products. <a href="advisories/TKADV2008-002.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=3</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=3</guid>
      <pubDate>So, 30 Mar 2008 10:23:42</pubDate>
    </item>		
 
    <item>
      <title>[08.03.2008] Panda Internet Security/Antivirus+Firewall 2008 Security Advisory released (TKADV2008-001)</title>
      <description>After a patch development time of 60 days Panda Security released a hotfix for their Panda Internet Security 2008 and Panda Antivirus+Firewall 2008 products. This hotfix fixes a memory corruption vulnerability (overflow in the data section) I found in one of the drivers shipped with these products. <a href="advisories/TKADV2008-001.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=2</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=2</guid>
      <pubDate>Sa, 08 Mar 2008 13:38:09</pubDate>
    </item>	
 
     <item>
      <title>[01.03.2008] Mac OS X AppleTalk AIOCSETZNUSAGE IOCTL Kernel Stack Overflow Security Advisory released (TKADV2007-003)</title>
      <description>This security advisory describes the technical details of the vulnerability <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4267">CVE-2007-4267</a> I found and published working with iDefense VCP. Apple needed a patch development time of 99 days to fix this bug. <a href="advisories/TKADV2007-003.txt">Read more ...</a></description>
      <link>http://www.trapkit.de/?p=1</link>
      <author>tk</author>
      <guid>http://www.trapkit.de/?p=1</guid>
      <pubDate>Sa, 01 Mar 2008 21:32:39</pubDate>
    </item>	
 
  </channel>
 
</rss>

