SecurityFocus Newsletter #264

Peter Laborge <[email protected]> 31 Aug 2004 21:35:59 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #264
------------------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. A Polluted Internet
     2. Deploying Network Access Quarantine Control, Part 2
II. BUGTRAQ SUMMARY
     1. KDE Konqueror Cookie Domain Validation Vulnerability
     2. Sympa New List HTML Injection Vulnerability
     3. Mantis Remote Server-Side Script Execution Vulnerability
     4. Mantis Multiple Cross-Site Scripting Vulnerabilities
     5. Mantis New Account Signup Mass Emailing Vulnerability
     6. MyDMS SQL Injection Vulnerability And Directory Traversal Vu...
     7. Opera Web Browser JavaScript Denial Of Service Vulnerability
     8. Multiple Vendor Web Browser JavaScript Denial Of Service Vul...
     9. Safari/WebCore HTTP Content Filtering Bypass Vulnerability
     10. Novell NetWare Web Manager Unspecified Vulnerability
     11. Davenport XML Expansion Denial Of Service Vulnerability
     12. Sredird Multiple Remote Vulnerabilities
     13. JShop E-Commerce Suite Page.PHP Cross-Site Scripting Vulnera...
     14. Compulsive Media CNU5 News.mdb Database Disclosure Vulnerabi...
     15. FIDOGATE Logfile Path Input Validation Vulnerability
     16. Music Daemon LOAD Command File Disclosure Vulnerability
     17. IMWheel Predictable Temporary File Creation Vulnerability
     18. PhotoADay Pad_selected Parameter Cross-Site Scripting Vulner...
     19. Bird Chat Remote Denial Of Service Vulnerability
     20. Axis Network Camera And Video Server Multiple Vulnerabilitie...
     21. Hitachi Job Management Partner 1 Multiple Remote Vulnerabili...
     22. EGroupWare Multiple Input Validation Vulnerabilities
     23. EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering W...
     24. Mozilla Network Security Services Library Remote Heap Overfl...
     25. Dominik Hack Ctetris Unspecified Local Vulnerability
     26. Gadu-Gadu File Download Filename Obfuscation Weakness
     27. INL Ulog-php Port.PHP SQL Injection Vulnerability
     28. PostgreSQL Debian GNU/Linux Specific Local Information Discl...
     29. SUPHP Design Flaw Local Privilege Escalation Weakness
     30. Icecast Server Status Display Cross-Site Scripting Vulnerabi...
     31. Hastymail HTML Attachment Script Execution Vulnerability
     32. NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerabi...
     33. SWsoft Plesk Reloaded Login_name Parameter Cross-Site Script...
     34. GNU a2ps File Name Command Execution Vulnerability
     35. Microsoft Internet Explorer Resource Detection Weakness
     36. Sun DtMail Local Command Line Format String Vulnerability
     37. WebAPP Directory Traversal Vulnerability
     38. People Can Fly Painkiller Remote Buffer Overflow Vulnerabili...
     39. Easy File Sharing Web Server Access Control Bypass Vulnerabi...
     40. PvPGN Battle.net Information Disclosure Vulnerability
     41. Easy File Sharing Web Server Remote Denial Of Service Vulner...
     42. Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilit...
     43. PHP Code Snippet Library Multiple Cross-Site Scripting Vulne...
     44. Entrust LibKMP ISAKMP Library Remote IPsec/ISAKMP Buffer Ove...
     45. Microsoft Outlook Express BCC Field Information Disclosure V...
     46. IgnitionServer SERVER Command Remote Denial Of Service Vulne...
     47. Sysinternals Regmon Local Denial of Service Vulnerability
     48. Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability
     49. OpenBSD Bridged Network ICMP Denial Of Service Vulnerability
     50. Webmatic Unspecified Security Vulnerability
     51. Network Everywhere NR041 Router DHCP Log HTML Injection Vuln...
     52. Cisco Secure Access Control Server Multiple Vulnerabilities
     53. RealVNC Server Remote Denial of Service Vulnerability
     54. Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulner...
     55. CDE LibDTHelp LOGNAME Environment Variable Local Buffer Over...
     56. Zlib Compression Library Denial Of Service Vulnerability
     57. Linux Kernel Process Spawning Race Condition Environment Var...
     58. NullSoft Winamp .WSZ File Remote Code Execution Vulnerabilit...
     59. Webroot Software Window Washer Data Exposure Vulnerability
     60. Samba Remote Print Change Notify Denial Of Service Vulnerabi...
     61. Gaim Multiple Vulnerabilities
     62. Keene Digital Media Server Directory Traversal Variant Vulne...
     63. Massive Entertainment Ground Control II Remote Denial of Ser...
     64. Mozilla/Netscape/Firefox Browsers XPCOM Plug-In For Apple Ma...
     65. Cisco IOS Telnet Service Remote Denial of Service Vulnerabil...
     66. Novell iChain Multiple Unspecified Remote Vulnerabilities
     67. MeindlSOFT Cute PHP Library cphplib Input Validation Vulnera...
     68. SugarCRM Unspecified Login Authentication Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. Website offers Caller I.D. falsification service
     2. FBI busts alleged DDoS Mafia
     3. South Pole 'cyberterrorist' hack wasn't the first
     4. Japanese banks deploy biometric palm scanners
     5. Filipino mobile users scammed over virus scare
     6. Aussie PM slammed for spam
IV. SECURITYFOCUS TOP 6 TOOLS
     1. THC-Hydra v4.3
     2. Mutilate File Wiper 2.90
     3. OpenSSH 3.9p1
     4. K-MAC 1.0.0.4
     5. Rootkit Hunter v1.1.6
     6. Honeynet Security Console 1.1.1
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Security Consultant, Bay Area, US (Thread)
     2. [SJ-JOB] Account Manager, London, GB (Thread)
     3. [SJ-JOB] VP of Marketing, Dallas, US (Thread)
     4. [SJ-JOB] Developer, Annapolis, US (Thread)
     5. [SJ-JOB] Security Engineer, Chicago, US (Thread)
     6. [SJ-JOB] Security Consultant, Albany, US (Thread)
     7. [SJ-JOB] Security Researcher, San Diego, US (Thread)
     8. [SJ-JOB] Developer, Santa Clara, US (Thread)
     9. [SJ-JOB] Account Manager, Any, US (Thread)
     10. [SJ-JOB] Security Engineer, Annapolis, US (Thread)
     11. [SJ-JOB] Security Consultant, Los Angeles, US (Thread)
     12. [SJ-JOB] Security Engineer, Washington DC, Altanta G... (Thread)
     13. [SJ-JOB] Developer, San Jose, US (Thread)
     14. [SJ-JOB] Security Director, Stamford, US (Thread)
     15. [SJ-JOB] Security Consultant, Yardley, US (Thread)
     16. [SJ-JOB] Jr. Security Analyst, San Francisco, US (Thread)
     17. [SJ-JOB] Customer Support, Redwood Shores, US (Thread)
     18. [SJ-JOB] Sr. Security Analyst, Redwood Shores, US (Thread)
     19. [SJ-JOB] Sales Engineer, Yardley, US (Thread)
     20. [SJ-JOB] Security Consultant, Dubai, AE (Thread)
     21. [SJ-JOB] Account Manager, Frederick, US (Thread)
     22. [SJ-JOB] Security Consultant, Oberursel, DE (Thread)
     23. [SJ-JOB] Sales Engineer, Any, US (Thread)
     24. [SJ-JOB] Developer, Herndon, US (Thread)
     25. [SJ-JOB] Security Researcher, Santa Clara, US (Thread)
     26. [SJ-JOB] Developer, Charlotte, US (Thread)
     27. [SJ-JOB] Security Architect, Chicago, US (Thread)
     28. [SJ-JOB] Jr. Security Analyst, Atlanta, US (Thread)
     29. [SJ-JOB] Management, Atlanta, US (Thread)
     30. [SJ-JOB] Security Engineer, Whitehouse Station, US (Thread)
     31. [SJ-JOB] Security Consultant, Cupertino, US (Thread)
     32. [SJ-JOB] Security Architect, Dallas, US (Thread)
     33. [SJ-JOB] Security Engineer, dublin, IE (Thread)
     34. [SJ-JOB] Security Architect, Washington, DC area, US (Thread)
     35. [SJ-JOB] Security System Administrator, London , GB (Thread)
     36. [SJ-JOB] Security Consultant, Portland, US (Thread)
     37. [SJ-JOB] Security Consultant, Atlanta, US (Thread)
     38. [SJ-JOB] Certification & Accreditation Engineer, Fai... (Thread)
     39. [SJ-JOB] Information Assurance Engineer, Fairfax, US (Thread)
     40. [SJ-JOB] VP of Regional Sales, San Francisco, US (Thread)
     41. [SJ-JOB] Sales Engineer, Detroit, US (Thread)
     42. [SJ-JOB] Security Consultant, London and South, GB (Thread)
     43. [SJ-JOB] Sr. Security Analyst, West Trenton, US (Thread)
     44. [SJ-JOB] Management, Miami, US (Thread)
     45. [SJ-JOB] Security Researcher, Mt. View, US (Thread)
     46. [SJ-JOB] Account Manager, Herndon, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. [Full-Disclosure] RE: block all popups [google knock... (Thread)
     2. compromised machines (Thread)
     3. block all popups [google knockoff] (Thread)
     4. [Full-Disclosure] RE: block all popups [google knock... (Thread)
     5. Bad options? (Thread)
     6. Request for Research Assistance (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. 21st Chaos Communication Congress 2004: Call for Pap... (Thread)
     2. GADU-GADU Instant messanger - long file name (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. ADSI question (Thread)
     2. Password policy enforcement tools was RE: ADSI quest... (Thread)
     3. Disable 'Save Password' feature on MS VPN client (Thread)
     4. COM+ with ASP web site on W2K3 (Thread)
     5. Signed Email w/Exchange 2003, Windows 2003 PKI (Thread)
     6. SecurityFocus Microsoft Newsletter #203 (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-08-24 to 2004-08-31.
X. LINUX FOCUS LIST SUMMARY
     1. Reverse SSH tunelling (Thread)
     2. Attempts to push spam through apache (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. A Polluted Internet
By Kelly Martin

Worms and viruses that pollute the Internet aren't new. What's new is the
incredible magnitude of the problem and how it's growing. 

http://www.securityfocus.com/columnists/263


2. Deploying Network Access Quarantine Control, Part 2
By Jonathan Hassell

This article discusses Network Access Quarantine Control in Windows Server
2003, which allows administrators to quarantine mobile users and verify
their security posture before giving them full access to the network. Part
2 of 2.

http://www.securityfocus.com/infocus/1799

II. BUGTRAQ SUMMARY
-------------------
1. KDE Konqueror Cookie Domain Validation Vulnerability
BugTraq ID: 10991
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10991
Summary:
It is reported that Konqueror is susceptible to a vulnerability while validating cookie domains, allowing web servers to receive potentially sensitive cookie data not intended for them.

This vulnerability presents itself when Konqueror allows a web site to set a cookie with domain restrictions containing certain country-specific top-level domains.

Attackers may exploit this vulnerability to inject cookie data into the domains of third party web servers. This may allow for denial of service attacks against other web services, by injecting invalid or conflicting cookie data. Other attacks are also likely possible, depending on the design of targeted web services.

Further details are unknown at this time. This BID will be updated as further information is disclosed.

2. Sympa New List HTML Injection Vulnerability
BugTraq ID: 10992
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10992
Summary:
An HTML injection vulnerability is reported in Sympa. The problem occurs due to a failure of the application to properly sanitize user-supplied input data.

Unsuspecting users viewing the affected page will have attacker-supplied malicious code interpreted by their browser in the security context of the website hosting Sympa.

Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.

Versions 4.1, and all 4.1.x releases are reported vulnerable to this issue.

3. Mantis Remote Server-Side Script Execution Vulnerability
BugTraq ID: 10993
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10993
Summary:
Mantix is reportedly susceptible to a remote server-side script execution vulnerability. This vulnerability only presents itself when PHP is configured on the hosting computer with 'register_globals = on'.

When PHP is configured to register global variables, an attacker can override variables used by the application in require() statements. By including a URI reference to a web server hosting a malicious script in GET, POST, or cookie data, an attacker can cause the PHP interpreter on the server hosting the affected package to request and execute attacker-supplied code.

This vulnerability could be exploited by a remote attacker to execute arbitrary script code in the context of the server hosting the affected application.

Version 0.19.0a is reported vulnerable to this issue. Other versions are also likely affected.

4. Mantis Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 10994
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10994
Summary:
Mantis is a web-based bug tracking system. It is written in PHP and supported by a MySQL database.

It is reported that Mantis is affected by cross-site scripting vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input.

These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

These vulnerabilities are reported to be fixed in the CVS version of Mantis as of 1 Aug 2004.

5. Mantis New Account Signup Mass Emailing Vulnerability
BugTraq ID: 10995
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10995
Summary:
Mantis is reportedly susceptible to a vulnerability in its signup process allowing mass email attacks.

When a new user signs up to Mantis, the system automatically sends an email message to the given email address. This email contains the users new password for the affected Mantis bug tracking system.

Mantis fails to ensure that only one account exists with the specified email address, and therefor an attacker can create a massive amount of email, directed at any target they wish. This email will originate from the Mantis server, and not the attacker.

The vendor has implemented a captcha system for new account signup requests in the CVS version of the software. All currently released versions of the software are reported vulnerable.

6. MyDMS SQL Injection Vulnerability And Directory Traversal Vu...
BugTraq ID: 10996
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10996
Summary:
MyDMS is reportedly susceptible to both a directory traversal vulnerability and an SQL injection vulnerability.

The SQL injection vulnerability is present because a script improperly sanitizes user-supplied data located in a URI argument before using the value in an SQL statement.

Successful exploitation of the SQL injection vulnerability could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

The directory traversal vulnerability reportedly allows registered users to download arbitrary web server readable files from the hosting computer. This is due to a failure of the application to properly sanitize user-supplied input data consisting of '../' directory traversal sequences.

Successful exploitation of the directory traversal vulnerability could result in an attacker gaining access to the contents of potentially sensitive files on the hosting computer. This may aid them in further attacks against the host computer.

The SQL injection is reportedly fixed in version 1.4.2. Versions prior to this are reported to be susceptible. The directory traversal vulnerability is fixed in version 1.4.3.

7. Opera Web Browser JavaScript Denial Of Service Vulnerability
BugTraq ID: 10997
Remote: Yes
Date Published: Aug 21 2004
Relevant URL: http://www.securityfocus.com/bid/10997
Summary:
Opera is a web browser available for a number of platforms, including Microsoft Windows, Linux and Unix variants and Apple MacOS.

Opera Web Browser is reported to be susceptible to a JavaScript denial of service vulnerability.

This vulnerability presents itself when Opera attempts to execute a specific JavaScript command. Upon executing this command, Opera will reportedly crash.

This vulnerability was reported to exist in version 7.23 of Opera for Microsoft Windows. Other versions are also likely affected.

8. Multiple Vendor Web Browser JavaScript Denial Of Service Vul...
BugTraq ID: 10998
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/10998
Summary:
Web browsers from multiple different vendors are reported susceptible to a denial of service vulnerability.

The specified JavaScript code will consume 100% of the CPU resources of the affected computer. The browser will then reportedly crash.

Mozilla Firefox, Microsoft Internet Explorer, and Opera are all reportedly affected by this vulnerability.

Update: This BID is being retired as this is not considered a security vulnerability.

9. Safari/WebCore HTTP Content Filtering Bypass Vulnerability
BugTraq ID: 10999
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/10999
Summary:
It is reported that Safari and WebCore contain a vulnerability that may allow users to bypass access restrictions or content filters.

This vulnerability may allow users to bypass access restrictions that are in place for HTML documents. It may also allow HTMl documents to bypass inline content filters, potentially allowing malicious or inappropriate content to pass the filtering engine.

10. Novell NetWare Web Manager Unspecified Vulnerability
BugTraq ID: 11000
Remote: Yes
Date Published: Aug 20 2004
Relevant URL: http://www.securityfocus.com/bid/11000
Summary:
Novell NetWare Web Manager is reported prone to an unspecified vulnerability.  This issue was disclosed by the vendor.  The cause and impacts of this issue are currently unknown as few details about this issue were released.  It is conjectured that this vulnerability is remote in nature.

This BID will be updated as more information becomes available.

Novell NetWare 6.5 is affected by this issue.

11. Davenport XML Expansion Denial Of Service Vulnerability
BugTraq ID: 11001
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11001
Summary:
Davenport is reportedly affected by a denial of service vulnerability in its XML parsing functionality.  This issue is due to a failure of the application to properly handle exceptional conditions.

Exploitation of this issue will allow an attacker to cause the affected application to hang, denying service to legitimate users.

12. Sredird Multiple Remote Vulnerabilities
BugTraq ID: 11002
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11002
Summary:
sredird is reported prone to multiple vulnerabilities.  These issue may allow a remote attacker execute arbitrary code on a vulnerable computer to gain unauthorized access.

The issues include a format string vulnerability and a remote buffer overflow vulnerability.  Successful exploitation of these issues may allow an attacker to gain unauthorized access to a vulnerable computer in the context of the affected process.

sredird versions 2.2.1 and prior are reportedly affected by these vulnerabilities.

This BID is now split into BIDs 11031 and 11033. This one will be retired shortly.

13. JShop E-Commerce Suite Page.PHP Cross-Site Scripting Vulnera...
BugTraq ID: 11003
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11003
Summary:
Reportedly the JShop E-Commerce Suite is affected by a cross-site scripting vulnerability in the 'page.php' script.  This issue is due to a failure of the application to properly santitize user-supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

14. Compulsive Media CNU5 News.mdb Database Disclosure Vulnerabi...
BugTraq ID: 11004
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11004
Summary:
CNU5 is reported prone to a database disclosure vulnerability. It is reported that remote users may download the database file 'news.mdb' and gain access to sensitive information including unencrypted authentication credentials.

CNU5 version 1.2 is reported vulnerable to this issue. CNU5 Extra may be affected as well.

This issue is being retired due to the fact that this is not a vulnerability in the application.  Configuring the Web server to restrict access to sensitive files can prevent this problem.

15. FIDOGATE Logfile Path Input Validation Vulnerability
BugTraq ID: 11005
Remote: No
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11005
Summary:
FIDOGATE is prone to an input validation error that may permit local users to append to or create files with the privileges of the program.  The source of the problem is that the attacker may control the location of the logfile.  Since the program is typically setuid 'news', this could be exploited to append to or create files in the context of that user.

This issue would only affect versions of the software for UNIX/Linux variants.

16. Music Daemon LOAD Command File Disclosure Vulnerability
BugTraq ID: 11006
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11006
Summary:
Music daemon is reported prone to a remote file disclosure vulnerability. The vulnerability presents itself due to a lack of sufficient sanitization performed on Music daemon command arguments.

A remote attacker may exploit this vulnerability in order to disclose the contents of files with the privilege of the Music daemon (musicd) process.

It is reported that if a binary file is specified as an argument for the affected command the attacker may cause the affected daemon to crash.

17. IMWheel Predictable Temporary File Creation Vulnerability
BugTraq ID: 11008
Remote: No
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11008
Summary:
IMWheel is reported prone to a predictable temporary file creation vulnerability.  This issue is a race condition error and may allow a local attacker to carry out denial of service attacks against other users and possibly gain elevated privileges.

This vulnerability was identified in IMWheel 1.0.0pre11, however, other versions may be affected as well.

18. PhotoADay Pad_selected Parameter Cross-Site Scripting Vulner...
BugTraq ID: 11009
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11009
Summary:
It is reported that PhotoADay is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks. 

All versions of PhotoADay are considered vulnerable at the moment.

19. Bird Chat Remote Denial Of Service Vulnerability
BugTraq ID: 11010
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11010
Summary:
Bird Chat has been reported to be affected by a remote denial of service vulnerability.  This issue is likely due to a failure of the application to properly sanitize user-supplied input, although this is not confirmed.

An attacker can leverage this issue to cause all chat clients connected to a vulnerable server to crash, denying service to legitimate users.

20. Axis Network Camera And Video Server Multiple Vulnerabilitie...
BugTraq ID: 11011
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11011
Summary:
Multiple vulnerabilities are reported to exist in multiple Axis network video and camera servers.

The first reported issue is a shell metacharacter command execution vulnerability. This is reported to allow an anonymous user download the contents of the '/etc/passwd' file on the device. Other commands are also likely to work, facilitating other attacks.

The first vulnerability is reported to affect:
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.34 thru 2.40
- Axis 2130 network cameras
- Axis 2401, and 2401 video servers

The second vulnerability is a directory traversal vulnerability in HTTP POST requests. This attack is demonstrated by an anonymous user calling protected administration scripts. This allows remote adminitration of the devices by anonymous users, bypassing authentication checks.

The second vulnerability is reported to affect:
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.12 thru 2.40
- Axis 2130 network cameras
- Axis 2401, and 2401 video servers

The third vulnerability is reported to be a hard-coded backdoor administrative user. This allows remote attackers to administer affected devices, and it likely cannot be disabled.

The third vulnerability is reported to affect:
- Axis StorePoint CD E100 CD-ROM Server with firmware version 5.30

Other products and versions of firmware are likely affected by one or more of these vulnerabilities.

21. Hitachi Job Management Partner 1 Multiple Remote Vulnerabili...
BugTraq ID: 11012
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11012
Summary:
Reportedly Hitachi Job Management Partner 1 is affected by multiple remote vulnerabilities.  These issues are likely due to a failure of the application to handle exceptional conditions.

These issue include a denial of service vulnerability in the bundled FTP server, allowing attackers to stop the affected server and deny service to legitimate users.

The second issue is an unspecified vulnerability surrounding the login authentication functionality of which the impact is currently unknown.

22. EGroupWare Multiple Input Validation Vulnerabilities
BugTraq ID: 11013
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11013
Summary:
It is reported that eGroupWare is susceptible to multiple cross-site scripting and HTML injection vulnerabilities.

The cross-site scripting issues present themselves in the various parameters of the 'addressbook' and 'calendar' modules. It is also reported that data input through the 'Search' fields of the 'addressbook', 'calendar', and 'search between projects' functionality are not sufficiently sanitized. 

An attacker can exploit these issues for theft of cookie-based authentication credentials and other attacks.

Additionally HTML injection vulnerabilities are reported for the eGroupWare 'Messenger' module and 'Ticket' module. 

Attackers may potentially exploit these issues to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.

23. EnderUNIX Hafiye Remote Terminal Escape Sequence Filtering W...
BugTraq ID: 11014
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11014
Summary:
EnderUNIX Hafiye is affected by a remote terminal escape sequence weakness.  This issue is caused by a failure of the application to properly sanitize user-supplied input.

An attacker might leverage this issue to inject terminal escape sequences into data that will be displayed on in a terminal window; if the terminal is vulnerable to escape sequence issues code execution is possible.

24. Mozilla Network Security Services Library Remote Heap Overfl...
BugTraq ID: 11015
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11015
Summary:
NSS is reported prone to a remote heap overflow vulnerability.  This issue arises due to insufficient boundary checks performed by the application.  Successful exploitation of this issue may result in arbitrary code execution leading to an attacker gaining unauthorized access to a vulnerable computer.

The NSS library is commonly used by Netscape Enterprise Server and Sun One/iPlanet servers.  The SSLv2 protocol is not enabled by default on these servers.  Other products may be affected as well.

25. Dominik Hack Ctetris Unspecified Local Vulnerability
BugTraq ID: 11016
Remote: No
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11016
Summary:
ctetris is reported prone to an unspecified local vulnerability.  This issue was disclosed in the product change log by the vendor.  Further details were not released therefore the cause and impact of this issue are unknown.

ctetris 0.28 and prior are affected by this issue.

26. Gadu-Gadu File Download Filename Obfuscation Weakness
BugTraq ID: 11017
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11017
Summary:
Gadu-Gadu is a Polish instant messaging application for Microsoft Windows operating systems.

It is reported that the Gadu-Gadu instant messenger application contains a weakness allowing attackers to obfuscate file extensions.

This may allow an attacker to send potentially malicious executable files to users who think that they are downloading files that are believed to be harmless.

27. INL Ulog-php Port.PHP SQL Injection Vulnerability
BugTraq ID: 11018
Remote: Yes
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11018
Summary:
It is reported that INL Ulog-php is susceptible to an SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query. 

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

Versions prior to 0.8.2 are reported to be affected.

28. PostgreSQL Debian GNU/Linux Specific Local Information Discl...
BugTraq ID: 11019
Remote: No
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11019
Summary:
The version of PostgreSQL contained in Debian/GNU Linux is reported susceptible to an information disclosure vulnerability. This issue is due to improper file permissions in the default installation of the PostgreSQL package.

This may aid attackers in further system compromise.

Versions up to, and including version 7.4.3-3 of the Debian package for PostgreSQL are reported affected by this vulnerability.

29. SUPHP Design Flaw Local Privilege Escalation Weakness
BugTraq ID: 11020
Remote: No
Date Published: Aug 23 2004
Relevant URL: http://www.securityfocus.com/bid/11020
Summary:
suPHP is reported prone to a design flaw that may permit a user with some degree of local interactive access to a system to execute arbitrary PHP script code with the privileges of a targeted user.

The weakness occurs due to a lack of sufficient validation employed when performing access control checks prior to executing PHP contained in a target file.

If an attacker had the ability to write to a target file by exploiting another vulnerability, and the target file meets the suPHP security criteria, then the attacker may potentially execute arbitrary PHP script code in the context of the target user.

30. Icecast Server Status Display Cross-Site Scripting Vulnerabi...
BugTraq ID: 11021
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11021
Summary:
Reportedly Icecast Server is affected by a cross-site scripting vulnerability in the status display functionality.  This issue is due to a failure of the application to properly sanitize user-supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

31. Hastymail HTML Attachment Script Execution Vulnerability
BugTraq ID: 11022
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11022
Summary:
Hastymail is reported prone to a script execution vulnerability that could allow a remote attacker to execute arbitrary HTML or script code in the browser of a vulnerable user.

It is reported that if a user attempts to download an HTML attachment through the application's interface, the browser may examine the file extension and open the file inline.

A remote attacker can create a malicious HTML attachment and send it to a user.  If the user attempts to download the attachment, the user's browser will open the unfiltered attachment.  This can allow for JavaScript or HTML code to execute in the browser leading to cookie-based credential theft or other attacks.

Hastymail Stable version 1.0.1 and Development version 1.1 are affected by this issue.  It is likely that prior versions are affected as well.

32. NakedSoft Gaucho POP3 Email Header Buffer Overflow Vulnerabi...
BugTraq ID: 11023
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11023
Summary:
NakedSoft Gaucho is affected by an email header buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate user input string lengths before copying them to finite process buffers.

Ultimately a malicious attacker may exploit this issue to execute arbitrary code on the affected computer with the privileges of the user who started the affected application by sending a specially crafted malicious email.

33. SWsoft Plesk Reloaded Login_name Parameter Cross-Site Script...
BugTraq ID: 11024
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11024
Summary:
It is reported that Plesk Reloaded may be affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input. 

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks. 

This issue was identified in the demo version of Plesk Reloaded 7.1.  It is likely that other versions are affected as well.

34. GNU a2ps File Name Command Execution Vulnerability
BugTraq ID: 11025
Remote: No
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11025
Summary:
Reportedly GNU a2ps is affected by a file name command execution vulnerability.  This issue is due to a failure of the application to properly sanitize filenames.

This issue might be leveraged by an attacker to execute arbitrary shell commands with the privileges of an unsuspecting user running the vulnerable application.

Although this issue reportedly affects only a2ps version 4.13 it is likely that other versions are affected as well.

35. Microsoft Internet Explorer Resource Detection Weakness
BugTraq ID: 11026
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11026
Summary:
Microsoft Internet Explorer is prone to a security weakness that may permit an attacker to determine the existence of resources on a vulnerable computer.

An attacker can use an IFRAME that is accessible within the same domain and change its URI to the location of a file or directory.  The attacker can then determine the existence of the resource by the error message returned by Internet Explorer.

This weakness can then allow the attacker to carry out other attacks against a vulnerable computer.

This issue was tested on Microsoft Internet Explorer 5.0 and 6.0.  Other versions of the browser are likely affected as well.

36. Sun DtMail Local Command Line Format String Vulnerability
BugTraq ID: 11027
Remote: No
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11027
Summary:
Reportedly Sun DtMail is affected by a local format string vulnerability in its processing of command line arguments.  This issue is due to a failure to securely implement a formatted string function.

Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the mail group.

NOTE: This issue is reported by Sun to be a buffer overflow vulnerability, however iDEFENSE has defined it as a format string vulnerability.  It is currently believed that these issues are the same, and that some misclassification has occurred.  If there is more than a single issue a new BID will be created.

37. WebAPP Directory Traversal Vulnerability
BugTraq ID: 11028
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11028
Summary:
WebAPP is reported prone to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.

This vulnerability can be exploited to retrieve arbitrary, potentially sensitive files from the hosting computer with the privileges of the web server. This may aid a malicious user in further attacks. It has been demonstrated that DES encrypted password hashes for all the users of the application can be trivially retrieved by exploiting this vulnerability.

38. People Can Fly Painkiller Remote Buffer Overflow Vulnerabili...
BugTraq ID: 11029
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11029
Summary:
Painkiller is reported prone to a remote buffer overflow vulnerability.  This issue presents itself due to insufficient boundary checks performed by the application during a connection request.

Painkiller versions 1.3.1 and prior are reported vulnerable to this issue.

39. Easy File Sharing Web Server Access Control Bypass Vulnerabi...
BugTraq ID: 11034
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11034
Summary:
Easy File Sharing Web Server is reported prone to an access control bypass vulnerability.

It is reportedly possible for a remote attacker to gain read access to the filesystem on the underlying computer by making a request for the name of a virtual folder on the Web Server.

Information harvested by exploiting this vulnerability may be used to aid in further attacks launched against the vulnerable computer.

40. PvPGN Battle.net Information Disclosure Vulnerability
BugTraq ID: 11035
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11035
Summary:
It is reported that PvPGN is susceptible to an information disclosure vulnerability.

This vulnerability allows an attacker to request information about any arbitrary user contained in the server. The information that an attacker can retrieve includes password hashes, which allows an attacker to gain access to any account.

Versions prior to 1.6.4, or CVS users dated before 2004-08-23 are reported vulnerable to this issue.

41. Easy File Sharing Web Server Remote Denial Of Service Vulner...
BugTraq ID: 11036
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11036
Summary:
Easy File Sharing Web Server is reported prone to a remote denial of service vulnerability. 

It is reported that the vulnerability will present itself when the Easy File Sharing Web Server handles large HTTP requests.

A remote attacker may exploit this vulnerability to deny service to legitimate users.

42. Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilit...
BugTraq ID: 11037
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11037
Summary:
It is reported that WebPac contains multiple undisclosed SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data before using it in an SQL query.

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

This BID will be updated as further information is disclosed.

43. PHP Code Snippet Library Multiple Cross-Site Scripting Vulne...
BugTraq ID: 11038
Remote: Yes
Date Published: Aug 24 2004
Relevant URL: http://www.securityfocus.com/bid/11038
Summary:
PHP Code Snippet Library is reported prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.

These issues could permit a remote attacker to create a malicious URI link to the PHP Code Snippet Library site that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

44. Entrust LibKMP ISAKMP Library Remote IPsec/ISAKMP Buffer Ove...
BugTraq ID: 11039
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11039
Summary:
The Entrust LibKMP ISAKMP library is reported to be affected by a remote buffer overflow vulnerability.  Malicious ISAKMP packets may trigger a buffer overrun in the affected library resulting in the corruption of process memory.

It is reported that a remote attacker may exploit this condition to deny service to the Entrust library or to execute arbitrary code in the context of an implementation that uses the library.

Although unconfirmed, it is conjectured that this vulnerability may be related to the vulnerability described in BID 10273, as Checkpoint VPN-1 may use the affected library.

45. Microsoft Outlook Express BCC Field Information Disclosure V...
BugTraq ID: 11040
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11040
Summary:
Microsoft Outlook Express is reported prone to a BCC field information disclosure vulnerability.  It is reported that Outlook Express does not properly handle BCC headers, disclosing the email address on the blind carbon copy list to the 'To:' and 'CC:' field recipients of such a message.  It is also reported that this issue only occurs if Outlook Express is configured to break messages into larger than a specific size.

This issue affects Microsoft Outlook Express 6.0.

46. IgnitionServer SERVER Command Remote Denial Of Service Vulne...
BugTraq ID: 11041
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11041
Summary:
ingitionServer is affected by a remote SERVER command denial of service vulnerability.  This issue is due to a failure of the application to properly handle exceptional conditions.

An attacker might leverage this issue to cause an affected server to crash or hang, denying service to legitimate users.

47. Sysinternals Regmon Local Denial of Service Vulnerability
BugTraq ID: 11042
Remote: No
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11042
Summary:
Regmon is reported prone to a local denial of service vulnerability.  This issue presents itself because the application fails to handle exceptional conditions and references unvalidated pointers to kernel functions.

Successful exploitation may allow a local unauthorized attacker to cause a denial of service condition in the application.  The attacker may then obfuscate changes to the registry from the administrator and carry out further attacks against a vulnerable computer.

Regmon 6.11 for NT/9x and prior versions are reportedly affected by this issue.

48. Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability
BugTraq ID: 11043
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11043
Summary:
Ipswitch WhatsUp Gold is affected by a remote buffer overflow vulnerability.  This issue is due to a failure of the application to properly validate user-supplied string lengths before copying them into static process buffers.

An attacker might leverage this issue to execute arbitrary code on the affected computer with the privileges of the user that started the vulnerable application.

49. OpenBSD Bridged Network ICMP Denial Of Service Vulnerability
BugTraq ID: 11044
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11044
Summary:
The implementation of bridging in OpenBSD is reportedly susceptible to a denial of service vulnerability.

This vulnerability presents itself when an OpenBSD host is configured to bridge two or more networks. Additionally, the 'link2' flag must be set on the bridging device. This flag is designed to transparently join multiple networks via an IPSec VPN tunnel.

This vulnerability may allow an attacker to crash or reboot affected computers, denying service to legitimate users.

A fix was applied in CVS to OpenBSD-current on 18 Aug 2004.

50. Webmatic Unspecified Security Vulnerability
BugTraq ID: 11045
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11045
Summary:
Webmatic is reported prone to an unspecified security vulnerability.  The cause and impact of this issue are currently unknown as very few details were released.  This issue was disclosed by the vendor.  It is conjectured that this vulnerability is remote in nature.

Webmatic versions 1.8 and prior are affected by this issue.

51. Network Everywhere NR041 Router DHCP Log HTML Injection Vuln...
BugTraq ID: 11046
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11046
Summary:
It is reported that the Network Everywhere NR041 Router is susceptible to an HTML injection vulnerability in its DHCP log.

An attacker can craft successive DHCP requests, which when viewed by the administrator, will be combined to create longer strings of HTML that are interpreted by the administrator's web browser.

The injected HTML can be used to cause the administrator to make unintended changes to the configuration of the router. Other attacks may be possible.

52. Cisco Secure Access Control Server Multiple Vulnerabilities
BugTraq ID: 11047
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11047
Summary:
Cisco Secure Access Control Server and Secure Access Control Server Solution Engine are reported prone to multiple vulnerabilities.  These vulnerabilities may allow remote attackers to cause denial of service conditions and gain unauthorized access to AAA clients and ACS administration interface.

The following specific vulnerabilities were reported by the vendor:

A remote attacker can trigger a denial of service condition in ACS Windows and ACS Solution Engine by establishing a large amount of TCP connections to the CSAdmin application.

Cisco Secure ACS is reported prone to another denial of service vulnerability when handling Light Extensible Authentication Protocol (LEAP) authentication requests.

Cisco Secure ACS is reported prone to an authentication bypass vulnerability when configured to communicate to a Novell Directory Services (NDS) database for authenticating NDS users.

Another vulnerability affecting ACS may allow remote attackers to gain unauthenticated access to the administration interface of the service.

53. RealVNC Server Remote Denial of Service Vulnerability
BugTraq ID: 11048
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11048
Summary:
RealVNC server is reported prone to a remote denial of service vulnerability.  This issue presents itself when an attacker establishes a large amount connections to the server.

This issue was reportedly tested on RealVNC 4.0 running on Microsoft Windows 2000.

54. Top Layer Attack Mitigator IPS 5500 Denial Of Service Vulner...
BugTraq ID: 11049
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11049
Summary:
The Attack Mitigator IPS 5500 is reportedly susceptible to a denial of service vulnerability.

This vulnerability presents itself when the device is bombarded with a very high volume of HTTP traffic.

The vendor reports that in certain configurations, it is possible for the devices overload protection feature to incorrectly activate, causing a denial of service condition. Once this condition has occurred, the device is reportedly unable to process HTTP traffic.

The IPS 5500 with firmware versions prior to 3.11.014 are reported susceptible to this vulnerability.

55. CDE LibDTHelp LOGNAME Environment Variable Local Buffer Over...
BugTraq ID: 11050
Remote: No
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11050
Summary:
A buffer overflow vulnerability is identified in CDE libDtHelp.  Because of this, it may be possible for a local attacker to gain elevated privileges.

The problem is in the handling of data contained in a certain environment variable. Due to insufficient bounds checking, it is possible that system memory will be corrupted potentially overwriting sensitive values when the environment variable data is copied into memory.

A local attacker may exploit this vulnerability in order to execute arbitrary code in the context software that is linked to the vulnerable library.

56. Zlib Compression Library Denial Of Service Vulnerability
BugTraq ID: 11051
Remote: Yes
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11051
Summary:
The Zlib compression library is reportedly susceptible to a denial of service vulnerability. This vulnerability is caused by a failure of the application to properly handle malformed input during the decompression process.

This vulnerability is reported to exist in version 1.2.1 of the library. Other versions are also likely affected.

57. Linux Kernel Process Spawning Race Condition Environment Var...
BugTraq ID: 11052
Remote: No
Date Published: Aug 25 2004
Relevant URL: http://www.securityfocus.com/bid/11052
Summary:
The Linux Kernel is prone to a race condition that may potentially expose information about the environment of a process.  

The race condition is reported to occur while a process is spawning.  If the condition is successfully exploited, an attacker could read environment variables associated with a process they do not own.

58. NullSoft Winamp .WSZ File Remote Code Execution Vulnerabilit...
BugTraq ID: 11053
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11053
Summary:
A vulnerability in Winamp has been discovered that may permit remote attackers to execute arbitrary code on client computers through a malicious .WSZ Winamp skin file.  This issue is currently being exploited in the wild.

This vulnerability may be exploited through a Web site, or any other means that will allow the attacker to transmit the malicious file to a victim user.

This vulnerability is reported to affect all versions of Winamp up to and including 5.04.

59. Webroot Software Window Washer Data Exposure Vulnerability
BugTraq ID: 11054
Remote: No
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11054
Summary:
Window Washer is reported prone to a data exposure vulnerability.  It is reported that the 'Add Bleach to Wash' setting allows users to delete files securely by writing random data to the drive repreatedly.   Due to an unspecified design error, this feature does not work properly and may allow a local attacker to expose data that was deleted by the application.

Window Washer version 5.5 is reportedly affected by this issue.  Other versions may be affected as well.

60. Samba Remote Print Change Notify Denial Of Service Vulnerabi...
BugTraq ID: 11055
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11055
Summary:
Samba is reportedly vulnerable to a remote denial of service vulnerability in the processing of print change notify requests.  This issue is due to a failure of the application to handle out of sequence requests.

An attacker might leverage this issue to cause the affected server to crash, denying service to legitimate users.

61. Gaim Multiple Vulnerabilities
BugTraq ID: 11056
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11056
Summary:
Gaim version 0.82 has been released.  This version addressed various security vulnerabilities.

The following specific issues have been disclosed by the vendor:

Gaim is reported prone to a remote arbitrary command execution vulnerability during the installation of a smiley theme.

The Gaim client is reported prone to a remote heap overflow vulnerability when processing data from a groupware server.

A remote buffer overflow vulnerability exists in the URI parsing utility.

A buffer overflow vulnerability arises when the application performs a DNS query to obtain a hostname when signing on to zephyr.

Another buffer overflow presents itself when the application processes Rich Text Format (RTF) messages.

A malicious server can trigger a buffer overflow vulnerability in Gaim by supplying an excessive value for the 'content-length' header.

These issues affect Gaim versions prior to 0.82.  Some of these issues may have been reported previously.  This BID will be updated and divided into individual BIDs as more information becomes available.

62. Keene Digital Media Server Directory Traversal Variant Vulne...
BugTraq ID: 11057
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11057
Summary:
It is reported that DMS is susceptible to a directory traversal vulnerability.

The directory traversal issue is present upon requesting files outside the webroot of the application using hex encoded directory traversal character sequences to create a relative path to the target file.

This vulnerability will allow a remote attacker to retrieve potentially sensitive files, possibly aiding them in further system compromise.

Version 1.0.2 of the software is reported vulnerable to this issue. Other versions may also be affected.

63. Massive Entertainment Ground Control II Remote Denial of Ser...
BugTraq ID: 11058
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11058
Summary:
Ground Control II is reported prone to a remote denial of service vulnerability.  This issue presents itself when a game client or server receives a packet larger than 512 bytes.

Ground Control II versions 1.0.0.7 and prior are affected by this issue.

64. Mozilla/Netscape/Firefox Browsers XPCOM Plug-In For Apple Ma...
BugTraq ID: 11059
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11059
Summary:
Browsers based on the Gecko engine are reported prone to a content spoofing vulnerability when they are running on the Apple Mac OS X platform. It is reported that the vulnerability occurs when the browser is configured to employ 'Tabbed Browsing' functionality. 

In essence, an XPCOM plug-in that is invoked in one tab will be drawn into the environment of alternate tabs that are open in the same browser window.

This vulnerability may be eexploited to spoof content and to aid in phishing style attacks.

65. Cisco IOS Telnet Service Remote Denial of Service Vulnerabil...
BugTraq ID: 11060
Remote: Yes
Date Published: Aug 27 2004
Relevant URL: http://www.securityfocus.com/bid/11060
Summary:
Cisco IOS telnet service is reported prone to a remote denial of service vulnerability.  It is reported that an attacker can trigger this issue by sending a specially crafted TCP packet to a telnet or reverse telnet port of a Cisco device running IOS.

All Cisco devices running IOS with a telnet or reverse telnet service are affected by this issue.

66. Novell iChain Multiple Unspecified Remote Vulnerabilities
BugTraq ID: 11061
Remote: Yes
Date Published: Aug 27 2004
Relevant URL: http://www.securityfocus.com/bid/11061
Summary:
Novell iChain has been reported prone to multiple unspecified remote vulnerabilities.

The first issue reported is an access control bypass issue surrounding the processing of UTF-8 encoded strings.

The second issue surrounds the manipulation of login credentials through a cross-site scripting vulnerability.

The third issue is a denial of service vulnerability triggered when a malicious URL request is made against the server.

A fourth issue surrounds an information disclosure vulnerability in the VIA header.

The fifth issue surrounds the insecure transmission of password and username credentials.

These issue might allow an attacker to carry out denial of service attacks against the affected computer, gain unauthorized access to the affected software, manipulate login credentials of unsuspecting users, disclose sensitive iChain configuration information, and steal authentication credentials transmitted insecurely over public networks.

It should be noted that these issues reportedly affected iChain version 2.3, however it is likely that other versions are affected as well.

67. MeindlSOFT Cute PHP Library cphplib Input Validation Vulnera...
BugTraq ID: 11062
Remote: Yes
Date Published: Aug 27 2004
Relevant URL: http://www.securityfocus.com/bid/11062
Summary:
meindlSOFT Cute PHP Library cphplib is affected by input validation vulnerabilities.  These issues are due to a design error.

These issues may allow an attacker to carry out HTML injection, cross-site scripting, and SQL injection attacks against applications that utilize the Cute PHP library.  It should be noted that such exploitation relies on the third party software to be implemented in such a way as to facilitate such vulnerabilities.

68. SugarCRM Unspecified Login Authentication Vulnerability
BugTraq ID: 11063
Remote: Yes
Date Published: Aug 26 2004
Relevant URL: http://www.securityfocus.com/bid/11063
Summary:
SugarCRM is reported prone to an unspecified vulnerability.  The impact and cause of this issue is currently unknown.  The vulnerability was reported to exist in the login authentication functionality of the application.

SugarCRM versions 1.1e and prior are affected by this issue.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Website offers Caller I.D. falsification service
By: Kevin Poulsen

Not just for phone hackers anymore, a California entrepreneur hopes to sell bill collectors and private investigators on the virtues of spoofing.

http://www.securityfocus.com/news/9419

2. FBI busts alleged DDoS Mafia
By: Kevin Poulsen

A corporate executive goes on the lam after being charged with paying hackers to virtually rub out the competition.  
http://www.securityfocus.com/news/9411

3. South Pole 'cyberterrorist' hack wasn't the first
By: Kevin Poulsen

Internal reports show that Romanian cyber extortionists weren't the first to penetrate the South Pole Research Station, and cast doubt on a U.S. claim that life support systems were compromised in the attack.

http://www.securityfocus.com/news/9356

4. Japanese banks deploy biometric palm scanners
By: Lucy Sherriff, The Register

Japanese banks are turning to a new biometric identification system, based on the unique nature of the patterns of veins in our palms.

http://www.securityfocus.com/news/9417

5. Filipino mobile users scammed over virus scare
By: John Leyden, The Register

Unscrupulous Filipino phone shops are cashing on recent stories about mobile phone viruses to flog worried punters services they don't need.
http://www.securityfocus.com/news/9416

6. Aussie PM slammed for spam
By: Tim Richardson, The Register

The Prime Minister of Australia has been accused of "double standards" after employing his son's company to spam voters in his Sydney constituency of Bennelong.

http://www.securityfocus.com/news/9415

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. THC-Hydra v4.3
By: THC
Relevant URL: http://www.thc.org/releases/hydra-4.3-src.tar.gz
Platforms: AIX, FreeBSD, HP-UX, IRIX, Linux, NetBSD, OpenBSD, Solaris, UNIX
Summary: 

THC-Hydra - parallized login hacker is available: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus. Visit the project web site to download Win32, Palm and ARM binaries. Changes: important bugfix!

2. Mutilate File Wiper 2.90
By: Craig Christensen, [email protected]
Relevant URL: http://mutilatefilewiper.com
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

Delete your sensitive files permanently. Mutilate File Wiper prevents recovery of deleted files from your hard drive by data recovery or forensic software. Choose one of three security levels or configure a customizable level for up to 297 overwrite passes. Mutilate supports complete folder shredding including subfolders. With Mutilate's disk free space wiper, you can even use Mutilate to permanently erase previously deleted files on your hard drive.

3. OpenSSH 3.9p1
By: OpenBSD Project
Relevant URL: http://www.openssh.com/
Platforms: UNIX
Summary: 

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

4. K-MAC 1.0.0.4
By: M. Neset KABAKLI
Relevant URL: http://www.neset.com
Platforms: Windows 2000, Windows NT, Windows XP
Summary: 

K-MAC is an ethernet MAC address changer for Windows. It's very useful for dealing with MAC filters and other MAC based controls.

5. Rootkit Hunter v1.1.6
By: M. Boelen
Relevant URL: http://www.rootkit.nl/
Platforms: UNIX
Summary: 

Rootkit scanner is scanning tool to ensure you for about 99.9% you're clean of nasty tools. This tool scans for rootkits, backdoors and local exploits by running tests like:

- MD5 hash compare
- Look for default files used by rootkits
- Wrong file permissions for binaries
- Look for suspected strings in LKM and KLD modules
- Look for hidden files
- Optional scan within plaintext and binary files

Rootkit Hunter is released as GPL licensed project and free for everyone to use.

6. Honeynet Security Console 1.1.1
By: Activeworx, Inc.
Relevant URL: http://www.activeworx.org
Platforms: Windows 2000, Windows XP
Summary: 

Honeynet Security Console is an analysis tool to view events on your personal honeynet. It gives you the power to view events from Snort, TCPDump, Firewall, Syslog and Sebek logs. It also allows you to correlate events from each of these data types to have a full grasp of the attackers' actions.

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Security Consultant, Bay Area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373502

2. [SJ-JOB] Account Manager, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373501

3. [SJ-JOB] VP of Marketing, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373499

4. [SJ-JOB] Developer, Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373498

5. [SJ-JOB] Security Engineer, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373496

6. [SJ-JOB] Security Consultant, Albany, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373495

7. [SJ-JOB] Security Researcher, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373494

8. [SJ-JOB] Developer, Santa Clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373492

9. [SJ-JOB] Account Manager, Any, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373490

10. [SJ-JOB] Security Engineer, Annapolis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373476

11. [SJ-JOB] Security Consultant, Los Angeles, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373472

12. [SJ-JOB] Security Engineer, Washington DC, Altanta G... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373471

13. [SJ-JOB] Developer, San Jose, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373470

14. [SJ-JOB] Security Director, Stamford, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373468

15. [SJ-JOB] Security Consultant, Yardley, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373467

16. [SJ-JOB] Jr. Security Analyst, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373466

17. [SJ-JOB] Customer Support, Redwood Shores, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373461

18. [SJ-JOB] Sr. Security Analyst, Redwood Shores, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373458

19. [SJ-JOB] Sales Engineer, Yardley, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373457

20. [SJ-JOB] Security Consultant, Dubai, AE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373456

21. [SJ-JOB] Account Manager, Frederick, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373453

22. [SJ-JOB] Security Consultant, Oberursel, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373450

23. [SJ-JOB] Sales Engineer, Any, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373440

24. [SJ-JOB] Developer, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373168

25. [SJ-JOB] Security Researcher, Santa Clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373158

26. [SJ-JOB] Developer, Charlotte, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373132

27. [SJ-JOB] Security Architect, Chicago, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373124

28. [SJ-JOB] Jr. Security Analyst, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373123

29. [SJ-JOB] Management, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373121

30. [SJ-JOB] Security Engineer, Whitehouse Station, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373109

31. [SJ-JOB] Security Consultant, Cupertino, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373099

32. [SJ-JOB] Security Architect, Dallas, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373098

33. [SJ-JOB] Security Engineer, dublin, IE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373097

34. [SJ-JOB] Security Architect, Washington, DC area, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373086

35. [SJ-JOB] Security System Administrator, London , GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/373085

36. [SJ-JOB] Security Consultant, Portland, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372898

37. [SJ-JOB] Security Consultant, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372893

38. [SJ-JOB] Certification & Accreditation Engineer, Fai... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372891

39. [SJ-JOB] Information Assurance Engineer, Fairfax, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372883

40. [SJ-JOB] VP of Regional Sales, San Francisco, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372878

41. [SJ-JOB] Sales Engineer, Detroit, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372809

42. [SJ-JOB] Security Consultant, London and South, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372783

43. [SJ-JOB] Sr. Security Analyst, West Trenton, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372777

44. [SJ-JOB] Management, Miami, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372764

45. [SJ-JOB] Security Researcher, Mt. View, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372746

46. [SJ-JOB] Account Manager, Herndon, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/372745

VI. INCIDENTS LIST SUMMARY
--------------------------
1. [Full-Disclosure] RE: block all popups [google knock... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/373383

2. compromised machines (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/373382

3. block all popups [google knockoff] (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/373381

4. [Full-Disclosure] RE: block all popups [google knock... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/373299

5. Bad options? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/373205

6. Request for Research Assistance (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/372831

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. 21st Chaos Communication Congress 2004: Call for Pap... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/373242

2. GADU-GADU Instant messanger - long file name (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/373203

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. ADSI question (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/373526

2. Password policy enforcement tools was RE: ADSI quest... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/373391

3. Disable 'Save Password' feature on MS VPN client (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/373248

4. COM+ with ASP web site on W2K3 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/372948

5. Signed Email w/Exchange 2003, Windows 2003 PKI (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/372934

6. SecurityFocus Microsoft Newsletter #203 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/372869

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-08-24 to 2004-08-31.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Reverse SSH tunelling (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/373398

2. Attempts to push spam through apache (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/372845

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

This Issue is Sponsored By: SecurityFocus 

Want to keep up on the latest security vulnerabilities? Don't have time to
visit a myriad of mailing lists and websites to read the news? Just add the
new SecurityFocus RSS feeds to your freeware RSS reader, and see all the
latest posts for Bugtraq and the SF Vulnernability database in one
convenient place. Or, pull in the latest news, columnists and feature
articles in the SecurityFocus aggregated news feed, and stay on top of
what's happening in the community!

http://www.securityfocus.com/rss/index.shtml

------------------------------------------------------------------------