SecurityFocus Newsletter #245

John Boletta <[email protected]> 19 Apr 2004 22:40:14 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #245
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Solaris 10 Security
     2. Basic Web Session Impersonation
     3. Forensic Analysis of a Live Linux System, Part Two
II. BUGTRAQ SUMMARY
     1. Scorched 3D Server Memory Corruption Vulnerabilities
     2. Open WebMail Arbitrary Directory Creation Vulnerability
     3. Sun Cluster Global File System Denial of Service Vulnerabili...
     4. 1st Class Internet Solutions 1st Class Mail Server Multiple ...
     5. IBM HTTP Server PQ86671 and PQ85834 Fixes Released - Multipl...
     6. Crackalaka IRC Server Remote Denial of Service Vulnerability
     7. RSniff Remote Denial of Service Vulnerability
     8. HP AAA Server Denial of Service Vulnerability
     9. X-Micro WLAN 11b Broadband Router Backdoor Administration Ac...
     10. Linux Kernel Sigqueue Blocking Denial Of Service Vulnerabili...
     11. Microsoft Internet Explorer Bitmap File Processing Denial of...
     12. Microsoft Outlook Express Malformed EML File Denial of Servi...
     13. Eazel Nautilus Trash Folder Handler Buffer Overflow Vulnerab...
     14. TikiWiki Project Multiple Input Validation Vulnerabilities
     15. Blackboard Learning System Multiple Cross-Site Scripting Vul...
     16. Citadel/UX Insecure File Permissions Vulnerability
     17. SurgeLDAP User.CGI Directory Traversal Vulnerability
     18. Nuked-Klan Multiple Vulnerabilities
     19. Ipswitch IMail Express Web Messaging Buffer Overrun Vulnerab...
     20. KDE Konqueror Bitmap File Processing Denial of Service Vulne...
     21. Microsoft Windows LSASS Buffer Overrun Vulnerability
     22. Microsoft Windows H.323 Remote Buffer Overflow Vulnerability
     23. Microsoft Jet Database Engine Remote Code Execution Vulnerab...
     24. Microsoft Negotiate SSP Remote Buffer Overflow Vulnerability
     25. Microsoft Windows 2000 Domain Controller LDAP Denial Of Serv...
     26. Microsoft Windows SSL Library Denial of Service Vulnerabilit...
     27. Microsoft Windows Private Communications Transport Protocol ...
     28. Microsoft Virtual DOS Machine Local Privilege Escalation Vul...
     29. Microsoft ASN.1 Library Double Free Memory Corruption Vulner...
     30. Microsoft Windows Help And Support Center URI Validation Cod...
     31. Microsoft Windows WMF/EMF Image Formats Remote Buffer Overfl...
     32. Microsoft Windows Object Identity Network Communication Vuln...
     33. Microsoft Windows Local Descriptor Table Local Privilege Esc...
     34. Microsoft Windows COM Internet Service/RPC Over HTTP Remote ...
     35. Microsoft Windows Utility Manager Local Privilege Escalation...
     36. Microsoft Windows Management Local Privilege Escalation Vuln...
     37. Microsoft Windows Logon Process Remote Buffer Overflow Vulne...
     38. Microsoft Windows RPCSS Service Remote Denial Of Service Vul...
     39. PHP-Nuke CookieDecode Cross-Site Scripting Vulnerability
     40. TUTOS Multiple Input Validation Vulnerabilities
     41. BEA WebLogic Authentication Provider Privilege Inheritance V...
     42. BEA WebLogic Server/Express Potential Password Disclosure We...
     43. BEA WebLogic Server and WebLogic Express Certificate Chain U...
     44. BEA WebLogic Local Password Disclosure Vulnerability
     45. Novell Nsure Identity Manager Password Hint Plaintext Storag...
     46. PHP-Nuke Multiple SQL Injection Vulnerabilities
     47. Neon WebDAV Client Library Format String Vulnerabilities
     48. Qualcomm Eudora MIME Message Nesting Denial of Service Vulne...
     49. CVS Client RCS Diff File Corruption Vulnerability
     50. Rhino Software Zaep AntiSpam Cross-Site Scripting Vulnerabil...
     51. CVS Server Piped Checkout Access Validation Vulnerability
     52. Linux Kernel ISO9660 File System Buffer Overflow Vulnerabili...
     53. MySQL MYSQLD_Multi Insecure Temporary File Creation Vulnerab...
     54. Linux Kernel JFS File System Information Leakage Vulnerabili...
     55. Microsoft Outlook/Outlook Express Remote Denial Of Service V...
     56. Mozilla Messenger Remote Denial Of Service Vulnerability
     57. PostNuke Pheonix Multiple Module SQL Injection Vulnerabiliti...
     58. Red Hat Linux GNU Mailman Remote Denial Of Service Vulnerabi...
     59. ZoneLabs ZoneAlarm Pro/Plus MailSafe Filter Bypass Vulnerabi...
     60. Xonix X11 Game Insecure Privilege Dropping Vulnerability
     61. ssmtp Mail Transfer Agent Multiple Format String Vulnerabili...
     62. Linux Kernel XFS File System Information Leakage Vulnerabili...
     63. Linux Kernel EXT3 File System Information Leakage Vulnerabil...
     64. PHPBugTracker Multiple Input Validation Vulnerabilities
     65. SCT Campus Pipeline Email Attachment Script Injection Vulner...
     66. Cisco IPsec VPN Client Group Password Disclosure Vulnerabili...
     67. Gemitel Affich.PHP Remote File Include Command Injection Vul...
     68. Real Networks Helix Universal Server Denial of Service Vulne...
     69. Macromedia ColdFusion MX File Upload Denial Of Service Vulne...
III. SECURITYFOCUS NEWS ARTICLES
     1. Former anti-piracy 'bag man' turns on DirecTV
     2. War of words rages over Internet taps
     3. Lamo sentencing postponed
     4. SurfControl secures MessageSoft
     5. PGP to integrate anti-virus defences
     6. The average PC: spyware hotel
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Data Keeper v1.05
     2. XML Security Library v1.2.5
     3. Samhain v1.8.6
     4. Epylog v1.0
     5. Rootkit Hunter v1.06
     6. Plugdaemon v2.5.3
V. SECURITYJOBS LIST SUMMARY
     1. ** IT Application Security & Risk Assessment - 6 ope... (Thread)
     2. Security sales Engineer NJ/TX (Thread)
     3. XSP Sales Engineer - CA (Thread)
     4. Chief Security Officer - Raleigh, NC (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Strange set of TCP ports (Thread)
     2. Follow-up: Strange network activity (Thread)
     3. Strange network activity (Thread)
     4. maoqmwgn.exe (Thread)
     5. IPv4 fragmentation --> The Rose Attack (Thread)
     6. Fw: maoqmwgn.exe (Thread)
     7. incident tracking software (Thread)
     8. Anomalous tcp scan (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Windows Heap Overflow (Thread)
     2. changes between gcc 2.95 and 3.3 (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Location Aware GPO question (Thread)
     2. OWA (exchange 5.5) broken by patching? (Thread)
     3. SecurityFocus Microsoft Newsletter #184 (Thread)
     4. Article Announcement: Chat, Copy, Paste, Prison (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-04-12 to 2004-04-19.
X. LINUX FOCUS LIST SUMMARY
     1. decent loadbalancing with 2 different ISP's with min... (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Solaris 10 Security
By Ravi Iyer
This article discusses the many new security features in Sun's Solaris 10 
operating system, as well as Sun's holistic approach to security. 

http://www.securityfocus.com/infocus/1776

2. Basic Web Session Impersonation
By Rohyt Belani 

This article gives a basic introduction to common flaws in web 
applications that allow a malicious user to hijack a legitimate user's web 
session. Some practical countermeasures that reduce this threat are also 
discussed.

http://www.securityfocus.com/infocus/1774

3. Forensic Analysis of a Live Linux System, Part Two 
by Mariusz Burdach 

Last month in the first part of this article series, we discussed some of 
the preparation and steps that must be taking when analyzing a live Linux 
system that has been compromised. Now we'll continue our analysis by 
looking for malicious code on the running system, and then discuss some of 
the searches that can be done with the data once it has been transferred 
to our remote host.

http://www.securityfocus.com/infocus/1773

II. BUGTRAQ SUMMARY
-------------------
1. Scorched 3D Server Memory Corruption Vulnerabilities
BugTraq ID: 10086
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10086
Summary:
The Scorched 3D server component has been reported prone to multiple memory corruption vulnerabilities.  One of the issues is reportedly a heap-based buffer overrun that is exposed when a client supplies an excessive number of format string characters in the server chat box text input field.  

Other unspecified issues related to bounds checking were also reported.

These issues could be exploited to crash the server or potentially execute arbitrary code.

2. Open WebMail Arbitrary Directory Creation Vulnerability
BugTraq ID: 10087
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10087
Summary:
It has been reported that Open WebMail may be prone to an arbitrary directory creation vulnerability that may allow remote attackers to create potentially malicious directories in the underlying file system through the web interface.

Open WebMail versions 2.30 and prior are vulnerable to these issues, however, the problem has been addressed in the product CVS.

3. Sun Cluster Global File System Denial of Service Vulnerabili...
BugTraq ID: 10088
Remote: No
Date Published: Apr 08 2004
Relevant URL: http://www.securityfocus.com/bid/10088
Summary:
It has been reported that Sun Cluster is prone to a denial of service issue allowing local unprivileged attackers to cause a cluster node to panic.

Sun Cluster 3.0 and 3.1 for Solaris 8 and Solaris 9 are reported to be affected by this issue.

4. 1st Class Internet Solutions 1st Class Mail Server Multiple ...
BugTraq ID: 10089
Remote: Yes
Date Published: Apr 08 2004
Relevant URL: http://www.securityfocus.com/bid/10089
Summary:
Multiple vulnerabilities have been identified in the application that may allow a remote attacker to carry out directory traversal and cross-site scripting attacks.

1st Class Mail Server version 4.01 is reported to be prone to these issues, however, it is possible that other versions are affected as well.

5. IBM HTTP Server PQ86671 and PQ85834 Fixes Released - Multipl...
BugTraq ID: 10091
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10091
Summary:
IBM has announced the release of PQ86671 and PQ85834 cumulative fixes to address various issues in IBM HTTP Server.

PQ86671 has been released to address an unspecified denial of service issue in SSL.  It has been reported that this issue concerns certain malformed SSL records that may lead to a denial of service condition.  Although unconfirmed, this fix may address the issue described in BID 8746 (OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability) or BID 8732 (OpenSSL ASN.1 Parsing Vulnerabilities).  PQ86671 has been released for IBM HTTP Server versions 1.3.12, 1.3.12.1, 1.3.12.2, 1.3.12.3, 1.3.12.4, 1.3.12.5, 1.3.12.6, 1.3.12.7, 1.3.19, 1.3.19.1, 1.3.19.2, 1.3.19.3, 1.3.19.4, 1.3.19.5, 1.3.26, 1.3.26.1, 1.3.26.2, and 1.3.28. 

PQ85834 has been released to address multiple issues affecting IBM HTTP Server as well.  The issues addressed by this fix may be new, however, older issues have been fixed as well.  PQ85834 has been released for IBM HTTP Server 2.0.42.2 and 2.0.47.

6. Crackalaka IRC Server Remote Denial of Service Vulnerability
BugTraq ID: 10092
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10092
Summary:
It has been reported that Crackalaka may be prone to a remote denial of service vulnerability that may allow an attacker to crash the server by sending an excessive amount of data.

Crackalaka version 1.0.8 is reported to be prone to this issue, however, other versions could be vulnerable as well.

7. RSniff Remote Denial of Service Vulnerability
BugTraq ID: 10093
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10093
Summary:
It has been reported that RSniff may be prone to a remote denial of service issue when a client repeatedly connects to the RSniff daemon and does not issue the 'AUTHENTICATE' command to log in or simply closes the connection.  The server fails to accept new connections after about 1024 malicious connection attempts have been made.

RSniff 1.0 has been reported to be prone to this issue.

8. HP AAA Server Denial of Service Vulnerability
BugTraq ID: 10094
Remote: Yes
Date Published: Apr 09 2004
Relevant URL: http://www.securityfocus.com/bid/10094
Summary:
HP has issued a notice, SSRT3622, stating that a remotely exploitable denial of service condition affects AAA Server.  Further details are unknown as the advisory (document ID: HPSBUX01011) appears to be unavailable at this time.  It is likely that attackers need not authenticate prior to exploiting the vulnerability.  A successful attack may result in a prolonged denial of service, perhaps of complete network service, as users may not be able to authenticate.  

This entry will be updated as more information becomes available.  The link to the ITRC (login required):

http://itrc.hp.com

9. X-Micro WLAN 11b Broadband Router Backdoor Administration Ac...
BugTraq ID: 10095
Remote: Yes
Date Published: Apr 10 2004
Relevant URL: http://www.securityfocus.com/bid/10095
Summary:
It has been reported that the firmware shipped with the X-Micro 11b Broadband Router has built-in an administrative account that cannot be disabled.  The account, username and password "super", appears to be a backdoor and may provide remote attackers possessing knowledge of the account with complete control over the device.  According to the author of the report, the built-in administration webserver listens on both internal and external interfaces.  Attackers may authenticate with the "super" account from outside of the LAN and gain control of the device through this web interface.  Once authenticated, it is possible for attackers to install new firmware on the device.

**It has been reported that version 1.6.0.1 of WLAN 11b Broadband Router also contains a built-in an administrative account that cannot be disabled.  The account, username and password "1502", appears to be a backdoor and may provide remote attackers possessing knowledge of the account with complete control over the device.

10. Linux Kernel Sigqueue Blocking Denial Of Service Vulnerabili...
BugTraq ID: 10096
Remote: No
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10096
Summary:
A vulnerability has been reported in the Linux Kernel that may permit a malicious local user to affect a system-wide denial of service condition.  This issue may be triggered via the Kernel signal queue (struct sigqueue) and may be exploited to exhaust the system process table by causing an excessive number of threads to be left in a zombie state.

11. Microsoft Internet Explorer Bitmap File Processing Denial of...
BugTraq ID: 10097
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10097
Summary:
It has been reported that Internet Explorer may be prone to a denial of service vulnerability when processing malformed bitmap files.  An attacker can cause a denial of service condition in the system by specifying a large value for a bitmap file to be loaded by the browser.

This attack may lead to a denial of service condition in the system to the exhaustion of memory resources.

12. Microsoft Outlook Express Malformed EML File Denial of Servi...
BugTraq ID: 10098
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10098
Summary:
It has been reported that Outlook Express may be prone to a denial of service vulnerability that may allow an attacker to cause the application to crash by supplying a malformed e-mail (.eml) file.

Outlook Express 6.0 is reported to be prone to this issue.

13. Eazel Nautilus Trash Folder Handler Buffer Overflow Vulnerab...
BugTraq ID: 10099
Remote: No
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10099
Summary:
Nautilus has been reported to be prone to a buffer overflow vulnerability.

The vulnerability is reported to present itself when Nautilus attempts to delete a malicious directory and that directory is later operated on in the "Trash" folder.

An attacker who has some degree of interactive access to an affected system may attempt to exploit this vulnerability to execute code in the context of the user who is invoking Nautilus file manager.

14. TikiWiki Project Multiple Input Validation Vulnerabilities
BugTraq ID: 10100
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10100
Summary:
Multiple vulnerabilities have been identified in various modules of the application.  These vulnerabilities may allow a remote attacker to carry out various attacks such as path disclosure, cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload.

15. Blackboard Learning System Multiple Cross-Site Scripting Vul...
BugTraq ID: 10101
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10101
Summary:
Blackboard Learning System has been reported prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly validate user supplied URI input.

The first issue is reported to affect the "addressbook.pl" script.  The second issue is reported to affect the "tasks.pl" script. The third issue is reported to affect three URI parameters, of the "calendar.pl" script.

In all cases the user-supplied parameters are not sufficiently sanitized prior to being rendered in the browser of the target user.

These issues could permit a remote attacker to create a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

16. Citadel/UX Insecure File Permissions Vulnerability
BugTraq ID: 10102
Remote: No
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10102
Summary:
Citadel/UX has been reported prone to a weak file permissions vulnerability. The issue is reported to present itself because Citadel/UX sets insecure permissions on the "data" directory and files contained within, during installation.

As a direct result of this, any user who has interactive shell access to a system may disclose potentially sensitive data that is contained in the Citadel/UX database and data files.

17. SurgeLDAP User.CGI Directory Traversal Vulnerability
BugTraq ID: 10103
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10103
Summary:
SurgeLDAP is prone to a directory traversal vulnerability in one of the scripts included with the built-in web administrative server, potentially resulting in disclosure of files.  

A remote attacker could exploit this issue to gain access to system files outside of the web root directory of the built-in web server.  Files that are readable by the web server could be disclosed via this issue.

18. Nuked-Klan Multiple Vulnerabilities
BugTraq ID: 10104
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10104
Summary:
Nuked-Klan is prone to multiple vulnerabilities.  These issues include information disclosure via inclusion of local files, an issue that may permit remote attackers to corrupt configuration files and an SQL injection vulnerability.

19. Ipswitch IMail Express Web Messaging Buffer Overrun Vulnerab...
BugTraq ID: 10106
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10106
Summary:
A remotely exploitable buffer overrun vulnerability has been reported in Ipswitch IMail Express.  This condition exists in the Web Messaging component and is due to insufficient bounds checking of HTML messages.  

This issue could potentially be exploited to execute arbitrary code in the context of the software.

20. KDE Konqueror Bitmap File Processing Denial of Service Vulne...
BugTraq ID: 10107
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10107
Summary:
It has been reported that Konqueror may be prone to a denial of service vulnerability when processing malformed bitmap files.  An attacker can cause a denial of service condition in the system by specifying a large value for a bitmap file to be loaded by the browser.

This attack may lead to a denial of service condition in the system to the exhaustion of memory resources.

This vulnerability has been tested on KDE 3.2.1 running on a Freebsd5.2-CURRENT system, however, it is possible that other versions running on different platforms are vulnerable as well.  It is likely that this issue is present in a shared KDE bitmap processing component, presenting attack vectors in other applications that use the component.

This vulnerability is similar to the issue described in BID 10097 (Microsoft Internet Explorer Bitmap File Processing Denial of Service Vulnerability).

21. Microsoft Windows LSASS Buffer Overrun Vulnerability
BugTraq ID: 10108
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10108
Summary:
Microsoft Windows LSASS (Local Security Authority Subsystem Service) is prone to a remotely exploitable buffer overrun vulnerability.  The specific vulnerable system component is LSASRV.DLL.  Successful exploitation of this issue could allow a remote attacker to execute malicious code on a vulnerable system, resulting in full system compromise.

This issue could be exploited by an anonymous user on Microsoft Windows 2000 and XP operating systems.  The issue may reportedly only be exploited by local, authenticated users on Microsoft Windows Server 2003 and Microsoft Windows XP 64-Bit Edition 2003.  Microsoft has stated that a local administrator could exploit the issue on these platforms, though this does not appear to pose any additional security risk as the administrator will likely already have complete control over the system.

It is possible that an exploit for this vulnerability could be incorporated into a worm.

22. Microsoft Windows H.323 Remote Buffer Overflow Vulnerability
BugTraq ID: 10111
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10111
Summary:
The Microsoft Windows H.323 protocol implementation is prone to a remote buffer overflow.  Successful exploitation could allow for execution of arbitrary code.

This vulnerability could only be exploited if an H.323 application such as NetMeeting were running on the system.

23. Microsoft Jet Database Engine Remote Code Execution Vulnerab...
BugTraq ID: 10112
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10112
Summary:
It has been reported that Microsoft Jet Database Engine (Jet) is prone to a remote code execution vulnerability that that may allow remote attackers to execute arbitrary code in order to gain unauthorized access to a vulnerable system.  This issue presents itself when a specially crafted database query is sent by an attacker to be interpreted by Jet.  A successful attack may allow the attacker to gain complete control of the affected system.

Microsoft Jet Database Engine version 4.0 running on various Microsoft operating systems is reported to be vulnerable to this issue.

24. Microsoft Negotiate SSP Remote Buffer Overflow Vulnerability
BugTraq ID: 10113
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10113
Summary:
The Microsoft Negotiate Security Software Provider (SSP) interface is prone to a remote buffer overflow vulnerability.  In most cases, exploitation would result in a denial of service, but arbitrary code execution is possible.

25. Microsoft Windows 2000 Domain Controller LDAP Denial Of Serv...
BugTraq ID: 10114
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10114
Summary:
A denial of service vulnerability has been reported in Microsoft Windows 2000 Server systems that are acting as Domain Controllers.  

This issue may be triggered by sending a malformed LDAP query to an affected Windows 2000 Domain Controller.  This will cause a reboot in the Domain Controller and may be exploited repeatedly to cause a persistent denial of service.

26. Microsoft Windows SSL Library Denial of Service Vulnerabilit...
BugTraq ID: 10115
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10115
Summary:
Microsoft Windows SSL library is reported to be prone to a denial of service vulnerability.  It has been reported that an attacker could trigger this issue by sending a specially crafted TCP message that causes the protocol to fail resulting in a denial of service.

Successful exploitation of this issue in Windows 2000 and Windows XP would cause the systems to stop accepting SSL connections.  The issue leads to a system restart in Windows Server 2003.

27. Microsoft Windows Private Communications Transport Protocol ...
BugTraq ID: 10116
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10116
Summary:
Various Microsoft Windows operating systems are prone to a remotely exploitable stack-based buffer overrun via the PCT (Private Communications Transport) protocol.  Successful exploitation of this issue could allow a remote attacker to execute malicious code on a vulnerable system, resulting in full system compromise.

The vulnerability may also reportedly be exploitable by a local user who passes malicious parameters to the vulnerable component interactively or through another application.

This issue is reported to only affect systems that have SSL enabled, such as web servers, but could also affect Windows 2000 Domain Controllers under some circumstances.  For Windows Server 2003, PCT must be manually enabled in addition to enabling SSL support to be affected.  Reportedly, both PCT 1.0 and SSL 2.0 must be enabled for successful exploitation.

28. Microsoft Virtual DOS Machine Local Privilege Escalation Vul...
BugTraq ID: 10117
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10117
Summary:
A problem exists in the Virtual DOS Machine (VDM) that may allow a local user to elevate their privilege level.  The issue exists because an attacker may use the VDM to write arbitrary code to protected kernel memory locations.

29. Microsoft ASN.1 Library Double Free Memory Corruption Vulner...
BugTraq ID: 10118
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10118
Summary:
It has been reported that Microsoft ASN.1 library is prone to a double free heap memory corruption vulnerability that may allow a remote attacker to execute arbitrary code on a vulnerable system.  

Exploitation of this issue is likely to cause a denial of service condition due to the unique layout of memory structures in affected systems, however, it is possible to leverage this issue via arbitrary code execution to gain system level privileges on a system.

This vulnerability only affects systems that have installed the patch (MS04-007) for BID 9743 (Microsoft ASN.1 Library Multiple Stack-Based Buffer Overflow Vulnerabilities).

30. Microsoft Windows Help And Support Center URI Validation Cod...
BugTraq ID: 10119
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10119
Summary:
Microsoft has reported a vulnerability in the Help and Support Center that is related to how HCP URIs are validated.  This issue could reportedly be exploited via a malicious web page or HTML e-mail to execute arbitrary code on a client system.  

The issue may permit an attacker to inject invocation arguments when HCP URIs cause the HelpCtr.exe component to be executed.  By placing malicious content into a known location on the system, whose contents the attacker may influence via a malicious web page, it is possible to exploit this issue to cause the malicious content to be executed in the Local Zone.

It should be noted that the vulnerable functionality is included in Microsoft Windows ME but that the vendor has not considered this vulnerability to pose a serious threat to users of this operating system.  The vendor has not qualified why the threat is reduced for Windows ME users.

31. Microsoft Windows WMF/EMF Image Formats Remote Buffer Overfl...
BugTraq ID: 10120
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10120
Summary:
It has been reported that Windows may be prone to a remote buffer overflow vulnerability when rendering WMF/EMF image files.  An attacker could create a malicious WMF or EMF file and entice a user to view the file via an application that supports the WMF and EMF formats.  Immediate consequences of this attack may result in a denial of service condition, however, it is possible that an attacker could leverage this issue to execute arbitrary code in the context of the vulnerable user.  

This issue may be similar to the vulnerabilities described in BID 9892 (Microsoft Windows XP explorer.exe Remote Denial of Service Vulnerability) and BID 9707 (Microsoft Windows XP explorer.exe Multiple Memory Corruption Vulnerabilities).

32. Microsoft Windows Object Identity Network Communication Vuln...
BugTraq ID: 10121
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10121
Summary:
It has been reported that Microsoft Windows is prone to a vulnerability in the method of creation of object identities that may allow unauthorized network communication.  This issue is due to a design error that causes the process to be carried out insecurely.

This issue may be leveraged by a local attacker to open unauthorized network ports on the affected system.  This may facilitate remote attacks against the affected system.  There may also be other consequences.

33. Microsoft Windows Local Descriptor Table Local Privilege Esc...
BugTraq ID: 10122
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10122
Summary:
Microsoft Windows Local Descriptor Table programming interface has been reported prone to a privilege escalation vulnerability

As a result of this it is reportedly possible for a local attacker to create a malicious entry into the Local Descriptor Table. This entry may point into protected memory. Because this memory space is reserved for kernel operations, it is likely that an attacker will exploit this condition to execute arbitrary code with elevated privileges.

34. Microsoft Windows COM Internet Service/RPC Over HTTP Remote ...
BugTraq ID: 10123
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10123
Summary:
It has been reported that a denial of service condition exists in the COM Internet Service and RPC over HTTP services.  This issue is due to a failure of the services to properly handle malformed network responses.

Successful exploitation of this issue may allow a remote attacker to cause the affected server to crash or stop responding.  It is currently not known whether this issue could be leveraged to execute arbitrary code on the affected system.

35. Microsoft Windows Utility Manager Local Privilege Escalation...
BugTraq ID: 10124
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10124
Summary:
Microsoft Utility Manager has been reported prone to a local privilege escalation vulnerability. It is reported that a local user may influence the Utility Manager into executing arbitrary code. 

A local attacker may exploit this vulnerability to have arbitrary attacker-supplied code executed with SYSTEM privileges.

36. Microsoft Windows Management Local Privilege Escalation Vuln...
BugTraq ID: 10125
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10125
Summary:
Microsoft Windows Management has been reported prone to a local privilege escalation vulnerability. It is reported that a local user may employ Windows Management through some means to gain elevated privileges.

A local attacker may exploit this vulnerability to have arbitrary attacker-supplied code executed with SYSTEM privileges.

37. Microsoft Windows Logon Process Remote Buffer Overflow Vulne...
BugTraq ID: 10126
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10126
Summary:
Microsoft Windows logon process "winlogon" has been reported to be prone to a remote buffer overflow vulnerability. The issue is reported to exist when the vulnerable host is a member of an Active Directory domain. When processing logon information, the windows logon process will read data from the Active Directory. This read call does not sufficiently perform bounds checking on received data before said data is copied into a reserved buffer in process memory.

Supplied data that exceeds the size of the allocated buffer in Windows logon process memory will overrun its bounds, this will result in the corruption of memory that is adjacent to the affected buffer.

38. Microsoft Windows RPCSS Service Remote Denial Of Service Vul...
BugTraq ID: 10127
Remote: Yes
Date Published: Apr 12 2004
Relevant URL: http://www.securityfocus.com/bid/10127
Summary:
It has been reported that a denial of service condition exists in the RPCSS service.  This issue is due to a failure of the application to properly handle malformed network messages.

Successful exploitation of this issue may allow a remote attacker to cause the affected server to crash or stop responding.  On Microsoft Windows 2000, XP and Server 2003 this will cause the affected system to reboot, on all other Windows platforms the system will have to be manually rebooted.  It is currently not known whether this issue could be leveraged to execute arbitrary code on the affected system.

39. PHP-Nuke CookieDecode Cross-Site Scripting Vulnerability
BugTraq ID: 10128
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10128
Summary:
Reportedly PHP-NuKe is prone to a remote cross-site scripting vulnerability.  This issue is due to a failure of the 'cookiedecode()' function to properly sanitize user supplied cookie parameters.

These issues could permit a remote attacker to create a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

40. TUTOS Multiple Input Validation Vulnerabilities
BugTraq ID: 10129
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10129
Summary:
Multiple vulnerabilities have been identified in various modules of TUTOS.  These vulnerabilities may allow a remote attacker to carry out various attacks such as path disclosure, cross-site scripting, and possibly SQL injection.

41. BEA WebLogic Authentication Provider Privilege Inheritance V...
BugTraq ID: 10130
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10130
Summary:
BEA WebLogic Server and Express are prone to an issue that may cause administrative privileges to be inherited by a secondary group that these permissions have not been explicitly granted to.  This issue exists in the default Authentication provider and may allow for unauthorized administrative access to a security realm.

42. BEA WebLogic Server/Express Potential Password Disclosure We...
BugTraq ID: 10131
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10131
Summary:
BEA has reported a weakness affecting WebLogic Server and WebLogic Express. Due to a flaw, vulnerable versions of WebLogic Server/Express may write the clear text database password to a configuration file. This is reported to occur only when a server is configured to employ untargeted JDBC connection pools and have passwords configured.

An attacker may harvest the password and use it to gain unauthorized access to the database.

43. BEA WebLogic Server and WebLogic Express Certificate Chain U...
BugTraq ID: 10132
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10132
Summary:
It has been reported that BEA WebLogic Server and WebLogic Express are prone to a user impersonation vulnerability that may allow an attacker to impersonate an administrator or a remote server.

This issue may be related to the vulnerability described in BID 8320 (BEA WebLogic Server and WebLogic Express User Impersonation Vulnerability).

44. BEA WebLogic Local Password Disclosure Vulnerability
BugTraq ID: 10133
Remote: No
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10133
Summary:
Reportedly WebLogic Server and Express are prone to a local username/password disclosure vulnerability.  This issue is due to a design error that implements certain internal methods that can reveal the username and passwords that were used to boot the system.

This issue will allow a local user with the ability to authenticate using the username and password that were used to boot the system; the username and password will necessarily correspond to an administrator.

45. Novell Nsure Identity Manager Password Hint Plaintext Storag...
BugTraq ID: 10134
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10134
Summary:
When Novell Identity Manager Password Policies has been installed and the universal password option has been enabled, Novell Nsure may be prone to a weakness.

The password hint may be disclosed because it is stored in plaintext format.

Information harvested in this manner may be used in further attacks that are launched against the target system.

46. PHP-Nuke Multiple SQL Injection Vulnerabilities
BugTraq ID: 10135
Remote: Yes
Date Published: Apr 13 2004
Relevant URL: http://www.securityfocus.com/bid/10135
Summary:
Reportedly PHP-Nuke is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure of the application to properly sanitize user supplied input.

As a result of these issues an attacker could modify the logic and structure of database queries. Other attacks may also be possible, such as gaining access to sensitive information.

47. Neon WebDAV Client Library Format String Vulnerabilities
BugTraq ID: 10136
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10136
Summary:
It has been reported that the Neon client library is prone to multiple remote format string vulnerabilities.  This issue is due to a failure of the application to properly implement format string functions.

Ultimately this vulnerability could allow for execution of arbitrary code on the system implementing the affected client software, which would occur in the security context of the server process.

48. Qualcomm Eudora MIME Message Nesting Denial of Service Vulne...
BugTraq ID: 10137
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10137
Summary:
It has been reported that Eudora is prone to a denial of service vulnerability when handling e-mail containing excessive MIME nesting.  The problem is known to occur when the application attempts to decode the deeply nested message.

Successful exploitation of this issue may allow an attacker to cause the application to crash due to corruption of stack memory.  It is not known if this issue is further exploitable to execute arbitrary code.

It should be noted that this condition may be persistent since the offending message may remain in the client's mail spool.

Eudora 6.0.3 is reported to be vulnerable to this issue, however, other versions may be affected as well.

49. CVS Client RCS Diff File Corruption Vulnerability
BugTraq ID: 10138
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10138
Summary:
A vulnerability has been discovered in the CVS client. It is reported that a problem in the revision control system (RCS) diff files may allow an attacker to create an arbitrary file on a remote system. The file will be created with the privileges of the user who is invoking the CVS client.

50. Rhino Software Zaep AntiSpam Cross-Site Scripting Vulnerabil...
BugTraq ID: 10139
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10139
Summary:
It has been reported that Zaep AntiSpam is prone to a cross-site scripting vulnerability.  This issue is due to a failure of the application to properly sanitize user supplied URI input.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

51. CVS Server Piped Checkout Access Validation Vulnerability
BugTraq ID: 10140
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10140
Summary:
CVS server has been reported prone to an access validation vulnerability. It is reported that the CVS server does not sufficiently validate piped checkouts. The CVS server may honor a request for a piped checkout for a path that resides outside of the cvsroot.

Data that is harvested in this manner may be used to aid in further attacks that are launched against the target server.

52. Linux Kernel ISO9660 File System Buffer Overflow Vulnerabili...
BugTraq ID: 10141
Remote: No
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10141
Summary:
It has been reported that the Linux Kernel is prone to a local ISO9660 file system buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate buffer boundaries when processing file system information.  An attacker must have adequate permissions to mount the malicious file system to exploit the issue.  This is not enabled by default on a number of available Linux distributions.

This issue may be exploited by an attacker to overflow and modify kernel memory, potentially allowing the attacker to create an arbitrary data structure in kernel memory.  This issue may be leveraged to gain kernel level access to the affected system.

53. MySQL MYSQLD_Multi Insecure Temporary File Creation Vulnerab...
BugTraq ID: 10142
Remote: No
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10142
Summary:
mysqld_multi is reported prone to insecure temporary file handling. The script likely creates temporary files with predictable filenames.

An attacker may exploit this issue to launch symbolic link attacks that will most likely result in corruption of files when the vulnerable script is launched.

This issue would only affect Unix/Linux-based operating systems.

54. Linux Kernel JFS File System Information Leakage Vulnerabili...
BugTraq ID: 10143
Remote: No
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10143
Summary:
A vulnerability has been reported in the Linux Kernel that is related to how JFS file systems are cleaned up.  In particular, a root user may potentially gain access to private or sensitive information on these file systems.  

This really only poses a security risk if the root user is not intended to access this information already.

55. Microsoft Outlook/Outlook Express Remote Denial Of Service V...
BugTraq ID: 10144
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10144
Summary:
Microsoft Outlook and Outlook Express have been reported prone to a remote denial of service vulnerability. The issue is reported to present itself when a NULL is encountered in the message body of an e-mail.

It is reported that when the vulnerable software encounters a malicious e-mail as described above, the GUI will cease to respond.

A remote attacker may potentially exploit this condition to deny service to Microsoft Outlook and Outlook Express users.

56. Mozilla Messenger Remote Denial Of Service Vulnerability
BugTraq ID: 10145
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10145
Summary:
Mozilla Messenger has been reported prone to a remote denial of service vulnerability. The issue is reported to present itself when a NULL is encountered in the message body of an e-mail.

It is reported that when the vulnerable software encounters a malicious e-mail as described above, the GUI will cease to respond properly.

A remote attacker may potentially exploit this condition to deny service to Mozilla Messenger users.

57. PostNuke Pheonix Multiple Module SQL Injection Vulnerabiliti...
BugTraq ID: 10146
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10146
Summary:
It has been reported that PostNuke Pheonix is prone to a remote SQL injection vulnerability in multiple modules.  This issue is due to a failure of the application to properly sanitize user supplied URI input.

This may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

58. Red Hat Linux GNU Mailman Remote Denial Of Service Vulnerabi...
BugTraq ID: 10147
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10147
Summary:
An update that was released by Red Hat(RHSA-2004:019) to address the issue described in BID 9620 (GNU Mailman Malformed Message Remote Denial Of Service Vulnerability), is reported to introduce a denial of service vulnerability.

A remote attacker may exploit this vulnerability to cause the mailman to crash, effectively denying service to legitimate users.

59. ZoneLabs ZoneAlarm Pro/Plus MailSafe Filter Bypass Vulnerabi...
BugTraq ID: 10148
Remote: Yes
Date Published: Apr 14 2004
Relevant URL: http://www.securityfocus.com/bid/10148
Summary:
A vulnerability has been reported in some versions of ZoneAlarm Pro/Plus MailSafe. MailSafe may be configured to quarantine file attachments with a certain extension. It is reported that, if the file name of a restricted attachment contains certain extended characters, MailSafe may fail to quarantine the attachment.

60. Xonix X11 Game Insecure Privilege Dropping Vulnerability
BugTraq ID: 10149
Remote: No
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10149
Summary:
It has been reported that Xonix is prone to a vulnerability that may allow an attacker to gain elevated privileges.  This issue occurs because the application fails to drop privileges.  Successful exploitation of this issue may result in a local attacker gaining gid 'games' privileges.

This issue has been reported to affect Xonix version 1.4, however, it is possible that other versions are affected as well.

Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.

61. ssmtp Mail Transfer Agent Multiple Format String Vulnerabili...
BugTraq ID: 10150
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10150
Summary:
It has been reported that ssmtp may be prone to multiple format string vulnerabilities that could allow a remote attacker to execute arbitrary code in the context of the vulnerable process.  A successful attack may allow an attacker to gain root privileges.

62. Linux Kernel XFS File System Information Leakage Vulnerabili...
BugTraq ID: 10151
Remote: No
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10151
Summary:
An information leakage vulnerability has been reported to exist in the Linux kernel when writing to an XFS file system.  This issue is due to a design error that causes some kernel information to be leaked.

It has been reported that this issue requires that the attacker be able to read the raw device; an action which is restricted to privileges users.  Due to the nature of the issue, this really only poses a security risk if the privileged user is not intended to access this information already.

63. Linux Kernel EXT3 File System Information Leakage Vulnerabil...
BugTraq ID: 10152
Remote: No
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10152
Summary:
An information leakage vulnerability has been reported to exist in the Linux kernel when writing to an ext3 file system.  This issue is due to a design error that causes some kernel information to be leaked.

It has been reported that this issue requires that the attacker be able to read the raw device; an action which is restricted to privileged users.  Due to the nature of the issue, this really only poses a security risk if the privileged user is not intended to access this information already.

64. PHPBugTracker Multiple Input Validation Vulnerabilities
BugTraq ID: 10153
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10153
Summary:
Reportedly phpBugTracker contains multiple input validation vulnerabilities; it is prone to multiple SQL injection, cross-site scripting and HTML injection issues.  These issues are all due to a failure of the application to properly sanitize user supplied input.

The SQL injection issues may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

The cross-site scripting and HTML injection issues may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user. It may be possible to steal the unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks may also be possible.

65. SCT Campus Pipeline Email Attachment Script Injection Vulner...
BugTraq ID: 10154
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10154
Summary:
It has been reported that Campus Pipeline is prone to a remote email attachment script injection vulnerability.  This issue is due to a failure of the application to properly sanitize user supplied HTML and script code contained in email documents.

This issue may allow a remote attacker to gain control of an unsuspecting user's email account; by executing specific script code an attacker can manipulate the victim's email account.  It may be possible for an attacker to steal cookie based authentication credentials as well, and due to the integrated nature of this software this may potentially lead to further compromise of the victim's account.  It should be noted that this has not been confirmed.

66. Cisco IPsec VPN Client Group Password Disclosure Vulnerabili...
BugTraq ID: 10155
Remote: No
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10155
Summary:
The Cisco IPsec VPN client has been reported prone to a vulnerability, which may result in the compromise of the Group Password. The issue is reported to present itself because the Group Password is not encrypted or obfuscated in any way when it is stored in process memory.

67. Gemitel Affich.PHP Remote File Include Command Injection Vul...
BugTraq ID: 10156
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10156
Summary:
A vulnerability has been identified in the handling of input by Gemitel.  Because of this, it may be possible for a remote user to gain unauthorized access to a system using the vulnerable software.

It is possible to influence the include path of certain files, which could lead to an attacker including arbitrary PHP files from an external system.

68. Real Networks Helix Universal Server Denial of Service Vulne...
BugTraq ID: 10157
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10157
Summary:
It has been reported that Real Networks Helix Universal Server is affected by a remote denial of service vulnerability.  This issue is due to a failure of the application to properly handle malformed RTSP (Real-Time Streaming Protocol) requests.

An attacker may leverage this issue to trigger a denial of service condition in the affected server.

69. Macromedia ColdFusion MX File Upload Denial Of Service Vulne...
BugTraq ID: 10158
Remote: Yes
Date Published: Apr 15 2004
Relevant URL: http://www.securityfocus.com/bid/10158
Summary:
A denial of service vulnerability has been reported to exist in Macromedia ColdFusion MX that may allow a remote attacker to deny service to legitimate users. The issue is reported to present itself when a vulnerable server handles multiple file uploads that are interrupted before the upload procedure is completed.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Former anti-piracy 'bag man' turns on DirecTV
By: Kevin Poulsen

A one-time enforcer in DirecTV's war on signal pirates sues the company for allegedly making him use strong arm tactics against innocent computer geeks.
http://www.securityfocus.com/news/8472

2. War of words rages over Internet taps
By: Kevin Poulsen

It's law enforcement versus  ISPs and public interest advocates in the battle over wiring the Internet for surveillance.

http://www.securityfocus.com/news/8454

3. Lamo sentencing postponed
By: Kevin Poulsen

The hacker's judicial fate won't be decided until June, or later.

http://www.securityfocus.com/news/8425

4. SurfControl secures MessageSoft
By: John Leyden, The Register

http://www.securityfocus.com/news/8474

5. PGP to integrate anti-virus defences
By: John Leyden, The Register

http://www.securityfocus.com/news/8470

6. The average PC: spyware hotel
By: John Leyden, The Register

http://www.securityfocus.com/news/8469

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Data Keeper v1.05
By: Gregory Hull
Relevant URL: http://www.synack.com/dkeeper.html
Platforms: MacOS
Summary: 

Data Keeper is a secure document creation and storage application. It features TwoFish encryption with 256-bit keys generated from user passwords and SHA256, rich text support including images and backgrounds, and support for printing. Documents are automatically encrypted after a user-specified time interval. It is designed for the rapid viewing of encrypted documents, such as when quickly trying to find a password or ID number.

2. XML Security Library v1.2.5
By: aleksey
Relevant URL: http://www.aleksey.com/xmlsec/
Platforms: N/A
Summary: 

XML Security Library is a C library based on LibXML2 and OpenSSL. The library was created with a goal to support major XML security standards: XML Signature and XML Encryption.

3. Samhain v1.8.6
By: rainer
Relevant URL: http://la-samhna.de/samhain/
Platforms: AIX, Digital UNIX/Alpha, FreeBSD, HP-UX, Linux, Solaris, Unixware
Summary: 

samhain is a daemon that can check file integrity, search the file tree for SUID files, and detect kernel module rootkits (Linux only). It can be used either standalone or as a client/server system for centralized monitoring, with strong (192-bit AES) encryption for client/server connections and the option to store databases and configuration files on the server. For tamper resistance, it supports signed database/configuration files and signed reports/audit logs. It has been tested on Linux, FreeBSD, Solaris, AIX, HP-UX, and Unixware.

4. Epylog v1.0
By: Konstantin Riabitsev
Relevant URL: http://linux.duke.edu/projects/epylog/
Platforms: UNIX
Summary: 

Epylog is a log notifier and parser that periodically tails system logs on Unix systems, parses the output in order to present it in an easily readable format (parsing modules currently exist only for Linux), and mails the final report to the administrator. It can run daily or hourly. Epylog is written specifically for large clusters where many systems log to a single loghost using syslog or syslog-ng. Although Epylog can be used on standalone systems, other packages (like logwatch) are probably better suited for such purposes.

5. Rootkit Hunter v1.06
By: M. Boelen
Relevant URL: http://www.rootkit.nl/
Platforms: UNIX
Summary: 

Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.

6. Plugdaemon v2.5.3
By: Peter da Silva <[email protected]>
Relevant URL: http://www.taronga.com/plugdaemon/
Platforms: UNIX
Summary: 

plugdaemon is a load-balancing "plug" proxy. It allows you to forward TCP connections to one or multiple hosts, using load balancing or failover, and to route the connections through an HTTPS proxy. Access control is done by source interface or by originating IP. Outgoing connections can be bound to a specific IP address.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. ** IT Application Security & Risk Assessment - 6 ope... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/360656

2. Security sales Engineer NJ/TX (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/360650

3. XSP Sales Engineer - CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/360614

4. Chief Security Officer - Raleigh, NC (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/360598

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Strange set of TCP ports (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360586

2. Follow-up: Strange network activity (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360501

3. Strange network activity (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360472

4. maoqmwgn.exe (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360436

5. IPv4 fragmentation --> The Rose Attack (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360415

6. Fw: maoqmwgn.exe (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360389

7. incident tracking software (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360260

8. Anomalous tcp scan (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/360226

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Windows Heap Overflow (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/360568

2. changes between gcc 2.95 and 3.3 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/360178

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Location Aware GPO question (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/360450

2. OWA (exchange 5.5) broken by patching? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/360310

3. SecurityFocus Microsoft Newsletter #184 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/360255

4. Article Announcement: Chat, Copy, Paste, Prison (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/360238

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-04-12 to 2004-04-19.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. decent loadbalancing with 2 different ISP's with min... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/360618

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml
------------------------------------------------------------------------