SecurityFocus Newsletter #247

John Boletta <[email protected]> 3 May 2004 18:56:31 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #247
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. WiFi High Crimes
     2. Stop Being a Victim
II. BUGTRAQ SUMMARY
     1. Netegrity SiteMinder Affiliate Agent Heap Overflow Vulnerabi...
     2. Yahoo! Messenger YInsthelper.DLL Multiple Buffer Overflow Vu...
     3. McAfee ePolicy Orchestrator Undisclosed Command Execution Vu...
     4. Linux Kernel CPUFreq Proc Handler Integer Handling Vulnerabi...
     5. Sun Solaris SendFileV Local Denial Of Service Vulnerability
     6. FusionPHP Fusion News Cross-Site Scripting Vulnerability
     7. Symantec Client Firewall SYMNDIS.SYS Driver Remote Denial Of...
     8. Network Query Tool Cross-Site Scripting Vulnerability
     9. Multiple Protector System Input Validation Vulnerabilities
     10. Artmedic Webdesign Hpmaker Script Multiple Vulnerabilities
     11. Modular Site Management System Ver.asp Information Disclosur...
     12. Advanced Guestbook Password Parameter SQL Injection Vulnerab...
     13. Linux kernel i810 DRM driver Unspecified Vulnerability
     14. Linux kernel Framebuffer Code Unspecified Vulnerability
     15. Apache mod_auth Malformed Password Potential Memory Corrupti...
     16. Microsoft Windows Long Share Name Buffer Overrun Vulnerabili...
     17. OpenBB Multiple Input Validation Vulnerabilities
     18. Sun Solaris TCP/IP Networking Stack Unspecified Denial of Se...
     19. OpenBB Private Message Disclosure Vulnerability
     20. OpenBB Arbitrary Avatar File Upload Vulnerability
     21. Samsung SmartEther Switch Firmware Authentication Bypass Vul...
     22. PHPWebSite phpwsBB and phpwsContacts Modules Information Dis...
     23. Linux kernel do_fork() Memory Leakage Vulnerability
     24. Novell eDirectory Role Based Services Insecure Role Permissi...
     25. HP Web Jetadmin Multiple Vulnerabilities
     26. Zonet Wireless Router NAT Implementation Design Flaw Vulnera...
     27. Veritas NetBackup Multiple Unspecified Local Memory Corrupti...
     28. Siemens S55 Cellular Telephone SMS Confirmation Message Bypa...
     29. DiGi WWW Server Remote Denial Of Service Vulnerability
     30. PAFileDB ID Variable Cross-Site Scripting Vulnerability
     31. Multiple IBM AIX Unspecified LVM Utilities Symbolic Link Vul...
     32. Multiple IBM AIX Unspecified Console Commands Symbolic Link ...
     33. Linux Kernel Panic Function Call Undisclosed Buffer Overflow...
     34. Citrix MetaFrame XP Client Drive Access Vulnerability
     35. Admin Access With Levels Plug-in For osCommerce Access Contr...
     36. McAfee Security Installer Control System ActiveX Information...
III. SECURITYFOCUS NEWS ARTICLES
     1. Charges filed in 'Deceptive Duo' hacks
     2. Mitnick busts bomb hoaxer
     3. U.S. defends cybercrime treaty
     4. Global IT security spend hits $42bn
     5. U.S. charges four under new law against 'spam' e-mails
     6. ACLU challenges FBI use of secret letters to obtain Internet...
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Sentry Firewall CD-ROM v1.5.0-rc12(dev)
     2. Automatic Firewall v0.1
     3. jailed v1.0.0
     4. xmlBlaster v0.901
     5. DNS Blacklist Packet Filter v0.5
     6. File::Scan v1.05
V. SECURITYJOBS LIST SUMMARY
     1. Seattle area: Security Engineer / Sr. Network Engine... (Thread)
     2. San Diego Area - Security Engineer Opening (Thread)
     3. Information Security Analyst - Alexandria, VA (Thread)
     4. Netegrity Integration Architected needed in MidWest (Thread)
     5. Senior Security Consultant with active government cl... (Thread)
     6. Sales Account Managers with Security Services Experi... (Thread)
     7. Certification and Accreditation - DC Area (Thread)
     8. QA Engineer Opening at Sourcefire - Columbia, MD (Thread)
     9. LDAP/Secure Web Architecture (Windows based)- Three ... (Thread)
     10. ArcSight is looking for  a Security Sales Engineer f... (Thread)
     11. Coast-to-Coast Microsoft Security Initiative (Thread)
     12. New CSO Position -  CenturyTel - Monroe, Louisiana (Thread)
     13. IT Audit- Midwest & NYC (Thread)
     14. Senior Security Engineer (Thread)
     15. Security Systems Engineer (Thread)
     16. IDS Testing Engineer (Thread)
     17. Application Security Contractor / Cupertino (Thread)
     18. Security Software Sales-NYC, Bay area, & DFW (Thread)
     19. Antivirus Expert    (Boston area) (Thread)
     20. 3 Post Sales (implementation) Engineer needs....... (Thread)
     21. Senior Security Engineer  -  Philly Area (Thread)
     22. Project Manager ? InfoSec Specialist  (Boston area) (Thread)
     23. SAP Security Consultant Seeking Work in US/Canada (Thread)
     24. Director of Product Marketing Needed for SF-Based Se... (Thread)
     25. Sr. Security Systems Administrator-Redwood City, CA (Thread)
     26. Security Event Analyst (Thread)
     27. Network Security Engineer Position - Cayman Islands (Thread)
     28. Senior Communications Security Scientist/Lead - Sout... (Thread)
     29. NYC   VP Secure Business Communications (Thread)
     30. CA - San Jose - Senior Corporate Security Analyst (Thread)
     31. IT Security Consultant Banking Riyadh Saudi Arabia (Thread)
     32. Telco Security Consultant Saudi Arabia (Thread)
     33. Mid-west search (Thread)
VI. INCIDENTS LIST SUMMARY
     1. Increase in Port Scan Attempts? (Thread)
     2. Massive increase in spam volume? (Thread)
     3. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
     4. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
     5. FW: Massive increase in spam volume? (Thread)
     6. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
     7. MS04-011, Nessus, and SPAM flood (Thread)
     8. Massive increase in spam volume? 'Osama Captured' e-... (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Integer overflows (Thread)
     2. unpacking UPX or PE-packed binaries (Thread)
     3. os/2 shellcode (Thread)
     4. cobol language vulnerabilities (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. IE questions (Thread)
     2. w2k logon from one computer only (Thread)
     3. admiRE: w2k logon from one computer only (Thread)
     4. XP SP2's "Security Center" (Thread)
     5. Article Announcement: Stop Being a Victim (Thread)
     6. Article Announcement: Common Security Vulnerabilitie... (Thread)
     7. SecurityFocus Microsoft Newsletter #186 (Thread)
     8. EventID 256 (Thread)
IX. SUN FOCUS LIST SUMMARY
     1. would like the md5 sums of solaris 9 iso images (Thread)
X. LINUX FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-04-26 to 2004-05-03.
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. WiFi High Crimes
By Mark Rasch 

Before WiFi can entirely fulfill its promise, we'll have to confront an 
oppressive latticework of outdated criminal laws.

http://www.securityfocus.com/columnists/237

2. Stop Being a Victim
By Tim Mullen 

An influential newspaper columnist blames "contemptuous techies" for 
allowing users to fall prey to viruses and spyware. But don't some users 
deserve a little contempt?

http://www.securityfocus.com/columnists/236

II. BUGTRAQ SUMMARY
-------------------
1. Netegrity SiteMinder Affiliate Agent Heap Overflow Vulnerabi...
BugTraq ID: 10198
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10198
Summary:
@Stake has identified a remotely exploitable vulnerability in SiteMinder Affiliate Agent that is due to memory mismanagement.  When a legitimate user connects to a server implementing SiteMinder Agent, the cookie value "SMPROFILE" is transmitted.  The vulnerability is triggered when a value of excessive length for the cookie is sent to the server.  The vulnerability can be exploited to execute arbitrary instructions

2. Yahoo! Messenger YInsthelper.DLL Multiple Buffer Overflow Vu...
BugTraq ID: 10199
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10199
Summary:
Yahoo! Messenger COM objects YInstHelper.YInstStarter.1 and YInstHelper.YSearchSetting2 have been reported prone to remotely exploitable buffer overflow vulnerabilities. 

The conditions are triggered when properties are assigned values (strings) of excessive length.  By crafting a HTML page that invokes this COM object, and passing data to one of the affected properties, an attacker may overwrite values that are crucial to controlling program execution flow. 

Immediate consequences of exploit attempts may result in the web browser instance, and all windows spawned from it, crashing when the malicious site is viewed.  It is likely possible for attackers to execute instructions on affected client systems.

3. McAfee ePolicy Orchestrator Undisclosed Command Execution Vu...
BugTraq ID: 10200
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10200
Summary:
McAfee ePolicy Orchestrator has been reported prone to an undisclosed command execution vulnerability. 

An attacker may exploit this issue to execute commands in the context of the affected software.

Few details regarding this issue are currently available. This BID will be updated as further details are announced.

4. Linux Kernel CPUFreq Proc Handler Integer Handling Vulnerabi...
BugTraq ID: 10201
Remote: No
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10201
Summary:
A local integer handling vulnerability has been announced in the Linux kernel. It is reported that this vulnerability may be exploited by an unprivileged local user to obtain kernel memory contents. Additionally it is reported that a root user may exploit this issue to write to arbitrary regions of kernel memory, which may be a vulnerability in non-standard security enhanced systems where uid 0 does not have this privilege.

The vulnerability presents itself due to integer handling errors in the proc handler for cpufreq.

5. Sun Solaris SendFileV Local Denial Of Service Vulnerability
BugTraq ID: 10202
Remote: No
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10202
Summary:
Sun have reported that an unspecified vulnerability exists in the implementation of the sendfilev() function. This vulnerability may be triggered by a local unprivileged user to trigger a system panic. 

This vulnerability is reported to affect Sun Solaris versions 8, and 9 on x86 and SPARC platforms.

6. FusionPHP Fusion News Cross-Site Scripting Vulnerability
BugTraq ID: 10203
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10203
Summary:
An attacker may be capable of executing arbitrary script code in a browser of a target user and within the context of a visited web site. This may potentially lead to theft of cookie based authentication credentials, other attacks are also possible.

7. Symantec Client Firewall SYMNDIS.SYS Driver Remote Denial Of...
BugTraq ID: 10204
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10204
Summary:
Symantec Client Firewall has been reported to be prone to a remote denial of service vulnerability. The issue is reported to present itself in the TCP packet processing routines of the affected software.

It is reported that this vulnerability will have a system wide impact, causing Windows GUI and peripherals that are attached to the host to become unresponsive. A hard reset is reported to be required to restore normal functionality to the system.

8. Network Query Tool Cross-Site Scripting Vulnerability
BugTraq ID: 10205
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10205
Summary:
A cross-site scripting vulnerability reportedly affects Network Query Tool.  According to the report, data passed to script "nqt.php" via HTML variable "portNum" is not encoded before being included as part of the script's HTML output.  Symantec is not aware of any fixes.

9. Multiple Protector System Input Validation Vulnerabilities
BugTraq ID: 10206
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10206
Summary:
Multiple vulnerabilities were reported to exist in Protector System, which is a third-party module for PHP-Nuke.  Cross-site scripting and SQL injection vulnerabilities were reported.  

Exploitation of these issues may reveal sensitive information, allow for account hijacking, content manipulation and attacks against the underlying database.

These issues were reported to exist in Protector System 1.15b1.  Other versions may also be affected.

10. Artmedic Webdesign Hpmaker Script Multiple Vulnerabilities
BugTraq ID: 10207
Remote: Yes
Date Published: Apr 24 2004
Relevant URL: http://www.securityfocus.com/bid/10207
Summary:
It has been reported that hpmaker is prone to a multiple vulnerabilities that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable system and carry out directory traversal attacks to disclose sensitive information.

11. Modular Site Management System Ver.asp Information Disclosur...
BugTraq ID: 10208
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10208
Summary:
It has been reported that Modular Site Management System may be prone to an information disclosure issue that could allow an attacker to gain access to a server's configuration information.

MSMS version  0.2.1 is reported to be affected by this issue, however, it is possible that other versions are vulnerable as well.

12. Advanced Guestbook Password Parameter SQL Injection Vulnerab...
BugTraq ID: 10209
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10209
Summary:
It has been reported that Advanced Guestbook is prone to a SQL injection vulnerability that could allow an attacker to gain administrative access to the application.

This issue is reported to exist in Advanced Guestbook 2.2, however, it is possible that other versions are affected as well.

13. Linux kernel i810 DRM driver Unspecified Vulnerability
BugTraq ID: 10210
Remote: No
Date Published: Apr 22 2004
Relevant URL: http://www.securityfocus.com/bid/10210
Summary:
An unspecified vulnerability has been identified in the Linux kernel that may allow an attacker to potentially cause a denial of service vulnerability or gain elevated privileges.

Due to a lack of details, further information cannot be provided at the moment.  This BID will be updated as more information becomes available.

This issue has been identified in kernel version 2.4.22.

14. Linux kernel Framebuffer Code Unspecified Vulnerability
BugTraq ID: 10211
Remote: No
Date Published: Apr 22 2004
Relevant URL: http://www.securityfocus.com/bid/10211
Summary:
An unspecified vulnerability has been identified in the Linux kernel.  This vulnerability was reported in a security advisory (FEDORA-2004-111) issued by RedHat for the Fedora operating system. It has been reported that the issue exists in the framebuffer code accessing userspace directly instead of using correct interfaces.  The impact of this issue cannot be confirmed at the moment due to a lack of information. 

This issue has been identified in kernel version 2.4.22.

15. Apache mod_auth Malformed Password Potential Memory Corrupti...
BugTraq ID: 10212
Remote: Yes
Date Published: Apr 24 2004
Relevant URL: http://www.securityfocus.com/bid/10212
Summary:
It has been reported that Apache may be prone to a memory corruption vulnerability when parsing malformed password values during authentication.  The issue is reported to exist in the authentication modules (mod_auth, mod_auth3, mod_auth4) employed by Apache.  All versions of Apache running on 16-bit and 64-bit systems could potentially be vulnerable to this issue.

16. Microsoft Windows Long Share Name Buffer Overrun Vulnerabili...
BugTraq ID: 10213
Remote: Yes
Date Published: Apr 25 2004
Relevant URL: http://www.securityfocus.com/bid/10213
Summary:
Microsoft Windows operating systems have been reported to be prone to a remotely exploitable buffer overrun condition.  

This issue is exposed when a client attempts to connect to an SMB share with an overly long name.  This may cause explorer.exe or Internet Explorer to crash but could also potentially be leveraged to execute arbitrary code as the client user.

Microsoft Windows Server 2003 is reportedly not affected by this issue.

17. OpenBB Multiple Input Validation Vulnerabilities
BugTraq ID: 10214
Remote: Yes
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10214
Summary:
It has been reported that OpenBB is affected by multiple input validation vulnerabilities.  These issues are due to a failure of the application to properly sanitize user supplied user input.

The SQL issues may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.

The cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

18. Sun Solaris TCP/IP Networking Stack Unspecified Denial of Se...
BugTraq ID: 10216
Remote: No
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10216
Summary:
It has been reported that Solaris is affected by a local denial of service vulnerability that may allow an attacker to cause a system panic leading to a denial of service condition.

Due to a lack of details, further information is not available at the moment.  This BID will be updated as more information becomes available.

This issue has been reported in Solaris 8 and 9.

19. OpenBB Private Message Disclosure Vulnerability
BugTraq ID: 10217
Remote: Yes
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10217
Summary:
It has been reported that OpenBB is affected by a private message disclosure vulnerability.  This issue is due to a design error that fails to validate user credentials.

This issue might allow an attacker to read arbitrary private messages posted to the bulletin board; limiting confidentiality.

20. OpenBB Arbitrary Avatar File Upload Vulnerability
BugTraq ID: 10218
Remote: Yes
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10218
Summary:
Reportedly OpenBB is affected by an arbitrary avatar file upload vulnerability.  This issue is due to a failure of the application to restrict the file types that are uploaded.

This issue may allow a malicious user displaying their avatar file with their posts to have arbitrary, client-side script executed in an unsuspecting user's browser within the context if the affected website; facilitating HTML injection. This this may lead to cookie based authentication credential theft as well as other attacks.

21. Samsung SmartEther Switch Firmware Authentication Bypass Vul...
BugTraq ID: 10219
Remote: Yes
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10219
Summary:
When accessing a Samsung SmartEther switch, via the telnet service or serial connection, authentication is required and the user is presented with a logon screen. It has been reported that it is possible to bypass this authentication procedure.

An attacker may potentially exploit this condition to, for example, modify static MAC address mapping and perhaps enable man-in-the-middle style attacks. Other attacks are certainly possible.

22. PHPWebSite phpwsBB and phpwsContacts Modules Information Dis...
BugTraq ID: 10220
Remote: Yes
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10220
Summary:
It has been reported that phpwsBB and phpwsContacts modules for phpWebSite are prone to a vulnerability that could allow an attacker to gather sensitive information.  

Due to a lack of details, further information cannot be provided at the moment.  This BID will be updated as more information becomes available.

phpwsBB version 0.9.1 and phpwsContacts version 0.8.2 and prior versions are reported to be affected by this issue.

23. Linux kernel do_fork() Memory Leakage Vulnerability
BugTraq ID: 10221
Remote: No
Date Published: Apr 26 2004
Relevant URL: http://www.securityfocus.com/bid/10221
Summary:
It has been reported that the Linux kernel may be prone to a memory leakage vulnerability.  The issue exists because memory is allocate for child processes but never freed.

This issue has been identified in kernel versions 2.4 and 2.6.

24. Novell eDirectory Role Based Services Insecure Role Permissi...
BugTraq ID: 10223
Remote: No
Date Published: Apr 27 2004
Relevant URL: http://www.securityfocus.com/bid/10223
Summary:
Novell eDirectory is prone to an issue that could result in unauthorized access to certain administrative rights.  

The issue exists in the Role Based Services (RBS) component.  The result of the issue is that users who have been added to certain Roles may inherit more administrative rights than explicitly required.

25. HP Web Jetadmin Multiple Vulnerabilities
BugTraq ID: 10224
Remote: Yes
Date Published: Apr 27 2004
Relevant URL: http://www.securityfocus.com/bid/10224
Summary:
Multiple vulnerabilities have been identified in the application that may allow remote attackers to disclose sensitive information, carry out denial of service attacks, and gain unauthorized access to a vulnerable server.

These issues are reported to affect HP Web JetAdmin 6.5 and prior, however, version 7.0 may be affected by most of these issues as well.

26. Zonet Wireless Router NAT Implementation Design Flaw Vulnera...
BugTraq ID: 10225
Remote: Yes
Date Published: Apr 23 2004
Relevant URL: http://www.securityfocus.com/bid/10225
Summary:
A vulnerability has been reported to affect the implementation of NAT for the ZSR1104WE model Zonet Wireless Router. NAT for the wireless interface on the ZSR1104WE appliance is reported to modify IP data so that on the internal network, the origin address of forwarded traffic is that of the affected appliance. This issue may render the implementation of access controls on an internal host impossible.

27. Veritas NetBackup Multiple Unspecified Local Memory Corrupti...
BugTraq ID: 10226
Remote: No
Date Published: Apr 27 2004
Relevant URL: http://www.securityfocus.com/bid/10226
Summary:
Multiple unspecified local buffer overrun and format string vulnerabilities have been reported to exist in various setuid Veritas NetBackup binaries.  These issues may be exploited to execute arbitrary code with root privileges.

It should be noted that these issues are confirmed to exist and be exploitable on Linux platforms, however, releases of the software on other Unix-based platforms are also believed to be similarly affected.  

It is also not known at this point which specific NetBackup releases or distributions are affected.

28. Siemens S55 Cellular Telephone SMS Confirmation Message Bypa...
BugTraq ID: 10227
Remote: Yes
Date Published: Apr 27 2004
Relevant URL: http://www.securityfocus.com/bid/10227
Summary:
Reportedly the Siemens S55 is affected by an SMS confirmation message bypass vulnerability.  This issue is due to a race condition error that allows a malicious programmer to send SMS messages from unsuspecting cellular telephone user's telephones while obscuring the confirmation request.

This issue may allow a malicious programmer to develop an application that can send SMS messages without the cellular telephone user's knowledge.

29. DiGi WWW Server Remote Denial Of Service Vulnerability
BugTraq ID: 10228
Remote: Yes
Date Published: Apr 27 2004
Relevant URL: http://www.securityfocus.com/bid/10228
Summary:
The DiGi WWW Server has been reported to contain a remote denial of service vulnerability. It has been reported that when the server receives a malformed HTTP GET request, the web server process will consume large amounts of CPU resources.

Since this is a web server application, this leads to a remotely exploitable denial of service vulnerability.

30. PAFileDB ID Variable Cross-Site Scripting Vulnerability
BugTraq ID: 10229
Remote: Yes
Date Published: Apr 28 2004
Relevant URL: http://www.securityfocus.com/bid/10229
Summary:
A cross-site scripting vulnerability has been reported in paFileDB.

An attacker may construct a malicious link to this web application containing embedded arbitrary HTML and script code.  If the link was followed, this could permit for theft of cookie-based authentication credentials or other attacks.

This issue is reported to exist in version 3.x, and it is possible that other versions are affected as well.

31. Multiple IBM AIX Unspecified LVM Utilities Symbolic Link Vul...
BugTraq ID: 10230
Remote: No
Date Published: Apr 22 2004
Relevant URL: http://www.securityfocus.com/bid/10230
Summary:
IBM has reported that multiple undisclosed LVM utilities are prone to symbolic link attacks.

A local attacker who has interactive access to the system may exploit these vulnerabilities to corrupt files, potentially resulting in a system wide denial of service or elevated privileges.

32. Multiple IBM AIX Unspecified Console Commands Symbolic Link ...
BugTraq ID: 10231
Remote: No
Date Published: Apr 22 2004
Relevant URL: http://www.securityfocus.com/bid/10231
Summary:
IBM has reported that multiple undisclosed console commands are prone to symbolic link attacks.

A local attacker who has interactive access to the system may potentially exploit these vulnerabilities to cause a system wide denial of service or potentially elevate privileges.

33. Linux Kernel Panic Function Call Undisclosed Buffer Overflow...
BugTraq ID: 10233
Remote: No
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10233
Summary:
The panic() function call of the Linux kernel has been reported prone to a buffer overflow vulnerability. The exact details of the overflow are currently unspecified, however it has been reported that this issue cannot be exploited. Other reports suggest that the issue may be exploited to reveal portions of kernel memory space.

34. Citrix MetaFrame XP Client Drive Access Vulnerability
BugTraq ID: 10234
Remote: Yes
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10234
Summary:
Citrix MetaFrame XP has been reported prone to an access validation vulnerability. It is reported that an Administrator may access the drives of a connected client using the clients ICA connection.

35. Admin Access With Levels Plug-in For osCommerce Access Contr...
BugTraq ID: 10235
Remote: Yes
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10235
Summary:
Admin Access With Levels Plug-in for osCommerce is reported prone to an access control bypass vulnerability. The issue is reported to present itself when a user invokes a request for a script contained in the "admin" folder, passing a specific URI parameter in the request. 

An attacker may exploit this condition to ultimately gain administrative access to the affected site.

36. McAfee Security Installer Control System ActiveX Information...
BugTraq ID: 10236
Remote: Yes
Date Published: Apr 29 2004
Relevant URL: http://www.securityfocus.com/bid/10236
Summary:
The McAfee Security Installer Control System ActiveX control is prone to a vulnerability that may reveal sensitive system information remotely.  

This control is marked "Safe for Scripting" and provides remotely accessible methods for querying the host system's registry.  As a result, a malicious web page or HTML e-mail that invokes the control may gain access to information in the registry on a client system that has the control installed.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Charges filed in 'Deceptive Duo' hacks
By: Kevin Poulsen

Benjamin Stark, a.k.a. "The-Rev," faces a felony conviction for allegedly cracking and defacing government systems for our own good. 

http://www.securityfocus.com/news/8559

2. Mitnick busts bomb hoaxer
By: Kevin Poulsen

The ex-hacker helps a small Michigan town solve the mystery of the high school bomb-threats. 

http://www.securityfocus.com/news/8558

3. U.S. defends cybercrime treaty
By: Kevin Poulsen

Critics contend an international treaty aimed at catching computer criminals anywhere in the world could be abused by repressive governments.

http://www.securityfocus.com/news/8529

4. Global IT security spend hits $42bn
By: John Leyden, The Register

http://www.securityfocus.com/news/8557

5. U.S. charges four under new law against 'spam' e-mails
By: Ted Bridis, The Associated Press

http://www.securityfocus.com/news/8552

6. ACLU challenges FBI use of secret letters to obtain Internet...
By: Curt Anderson, The Associated Press

http://www.securityfocus.com/news/8551

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Sentry Firewall CD-ROM v1.5.0-rc12(dev)
By: Obsid
Relevant URL: http://www.SentryFirewall.com/
Platforms: Linux
Summary: 

Sentry Firewall CD-ROM Version 1.0 is a Linux based bootable CD-ROM suitable for use as an inexpensive and easy to maintain Firewall or IDS(Intrusion Detection System) Node. The system is designed to be immediately configurable for a variety of different operating environments via a configuration file located on a floppy disk or a local hard drive.

2. Automatic Firewall v0.1
By: Baruch Even
Relevant URL: http://baruch.ev-en.org/projects.html
Platforms: Linux
Summary: 

Automatic Firewall configures your firewall by looking at your environment and deciding what is a good fit for your needs. It is intended for the novice broadband user to install and forget about, but still be fairly well protected.

3. jailed v1.0.0
By: Johan Lindh
Relevant URL: https://sourceforge.net/projects/jailed/
Platforms: POSIX
Summary: 

jailed implements a nonprivileged jailroot. It allows an environment to be specified, does std(in/out/err) redirection, and can restart a failed child.

4. xmlBlaster v0.901
By: Marcel 
Relevant URL: http://www.xmlBlaster.org/
Platforms: Os Independent
Summary: 

XmlBlaster is XML based MOM (Message oriented Middleware) with a lot of features. It is a publish/subscribe and point-to-point MOM server which exchanges XML-encoded messages. Communication with the server is based on CORBA (using JacORB), RMI, XML-RPC, native socket, or a persistent HTTP plugin. Subscribers can use XPath expressions to filter the messages they wish to receive and add their own MIME-based filter plugins. C/C++, Java, Perl and PHP client demos are included in the xmlBlaster test suite, and Tcl and Python demo clients are scheduled. XmlBlaster also provides a browser callback framework, allowing browsers (Netscape, Mozilla, MSIE) to receive instant callbacks over a persistent http connection. A security plugin framework allows authentication/authorization in many ways. Currently there are LDAP- and passwd-based plugins available.

5. DNS Blacklist Packet Filter v0.5
By: Russell Miller
Relevant URL: 
Platforms: FreeBSD, Linux, NetBSD, OpenBSD, POSIX
Summary: 

DNS Blacklist Packet Filter is a BSD/Linux netfilter client that decides whether to accept or drop packets based on the results of a DNS blacklist query (such as MAPS, SORBS, or SPEWS, to name a few). One use is to filter all incoming SMTP SYN packets for spam filtering.

6. File::Scan v1.05
By: Henrique Dias <[email protected]>
Relevant URL: http://www.cpan.org/authors/id/H/HD/HDIAS/
Platforms: N/A
Summary: 

File::Scan allows users to make multiplataform virus scanners which can detect Windows/DOS/Mac viruses. It include a virus scanner and signatures database.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. Seattle area: Security Engineer / Sr. Network Engine... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361929

2. San Diego Area - Security Engineer Opening (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361915

3. Information Security Analyst - Alexandria, VA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361914

4. Netegrity Integration Architected needed in MidWest (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361913

5. Senior Security Consultant with active government cl... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361822

6. Sales Account Managers with Security Services Experi... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361821

7. Certification and Accreditation - DC Area (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361820

8. QA Engineer Opening at Sourcefire - Columbia, MD (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361819

9. LDAP/Secure Web Architecture (Windows based)- Three ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361818

10. ArcSight is looking for  a Security Sales Engineer f... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361814

11. Coast-to-Coast Microsoft Security Initiative (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361813

12. New CSO Position -  CenturyTel - Monroe, Louisiana (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361812

13. IT Audit- Midwest & NYC (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361811

14. Senior Security Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361808

15. Security Systems Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361807

16. IDS Testing Engineer (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361805

17. Application Security Contractor / Cupertino (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361804

18. Security Software Sales-NYC, Bay area, & DFW (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361801

19. Antivirus Expert    (Boston area) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361577

20. 3 Post Sales (implementation) Engineer needs....... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361574

21. Senior Security Engineer  -  Philly Area (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361560

22. Project Manager ? InfoSec Specialist  (Boston area) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361548

23. SAP Security Consultant Seeking Work in US/Canada (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361505

24. Director of Product Marketing Needed for SF-Based Se... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361504

25. Sr. Security Systems Administrator-Redwood City, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361503

26. Security Event Analyst (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361485

27. Network Security Engineer Position - Cayman Islands (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361483

28. Senior Communications Security Scientist/Lead - Sout... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361482

29. NYC   VP Secure Business Communications (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361479

30. CA - San Jose - Senior Corporate Security Analyst (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361418

31. IT Security Consultant Banking Riyadh Saudi Arabia (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361416

32. Telco Security Consultant Saudi Arabia (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361413

33. Mid-west search (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/361411

VI. INCIDENTS LIST SUMMARY
--------------------------
1. Increase in Port Scan Attempts? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361964

2. Massive increase in spam volume? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361963

3. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361630

4. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361527

5. FW: Massive increase in spam volume? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361525

6. Heads up: Looks like MS04-011 exploit is being tried... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361523

7. MS04-011, Nessus, and SPAM flood (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361498

8. Massive increase in spam volume? 'Osama Captured' e-... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/361391

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Integer overflows (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/361599

2. unpacking UPX or PE-packed binaries (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/361589

3. os/2 shellcode (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/361556

4. cobol language vulnerabilities (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/361481

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. IE questions (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361920

2. w2k logon from one computer only (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361782

3. admiRE: w2k logon from one computer only (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361778

4. XP SP2's "Security Center" (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361735

5. Article Announcement: Stop Being a Victim (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361683

6. Article Announcement: Common Security Vulnerabilitie... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361517

7. SecurityFocus Microsoft Newsletter #186 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361516

8. EventID 256 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/361477

IX. SUN FOCUS LIST SUMMARY
--------------------------
1. would like the md5 sums of solaris 9 iso images (Thread)
Relevant URL:

http://www.securityfocus.com/archive/92/361908

X. LINUX FOCUS LIST SUMMARY
---------------------------
NO NEW POSTS FOR THE WEEK 2004-04-26 to 2004-05-03.

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add
the new SecurityFocus RSS feeds to your freeware RSS reader, and see all
the latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------