SecurityFocus Newsletter #280

Peter Laborge <[email protected]> 21 Dec 2004 21:18:57 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #280
------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Zero Viruses In 2005?
     2. Security Holes That Run Deep
II. BUGTRAQ SUMMARY
     1. Opera Web Browser Download Dialogue Box File Name Spoofing V...
     2. MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vu...
     3. Citadel/UX Network Data Logging Remote Format String Vulnera...
     4. phpMyAdmin Multiple Remote Vulnerabilities
     5. Digital Illusions CE Codename Eagle Remote Denial Of Service...
     6. PhpDig Unspecified Remote Vulnerability
     7. Novell Netware Screen Saver Local Authentication Bypass Vuln...
     8. Opentools Attachment Mod Multiple Remote Vulnerabilities
     9. mnoGoSearch Multiple Cross-Site Scripting Vulnerabilities
     10. SugarSales Multiple Remote Vulnerabilities
     11. MediaWiki Images Directory Arbitrary Script Upload and Execu...
     12. SQLgrey Postfix Greylisting Service Unspecified SQL Injectio...
     13. Gadu-Gadu Multiple Remote Vulnerabilities
     14. UBBCentral UBB.threads Multiple Cross-Site Scripting Vulnera...
     15. Opera Web Browser KDE KFMCLIENT Remote Command Execution Vul...
     16. Monolith Lithtech Game Engine Remote Denial Of Service Vulne...
     17. Nullsoft Winamp Tag Processing Remote Denial Of Service Vuln...
     18. Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnera...
     19. Microsoft Windows Kernel Unchecked LPC Buffer Privilege Esca...
     20. Microsoft Windows LSASS Connection Validation Privilege Esca...
     21. ZGV Image Viewer Animated GIF Remote Memory Corruption Vulne...
     22. Hilgraeve HyperTerminal Session Data Buffer Overflow Vulnera...
     23. Linux Kernel IGMP Multiple Vulnerabilities
     24. Sun Java System Web And Application Server Remote Session Di...
     25. Microsoft Windows DHCP Server Logging Remote Denial Of Servi...
     26. Microsoft Windows DHCP Server Remote Buffer Overflow Vulnera...
     27. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
     28. Microsoft Windows WINS Name Value Handling Remote Buffer Ove...
     29. Adobe Acrobat Reader Email Message Remote Buffer Overflow Vu...
     30. UseModWiki Wiki.PL Cross-Site Scripting Vulnerability
     31. Roxio Toast TDIXSupport Local Format String Vulnerability
     32. Microsoft Word for Windows 6.0 Converter Table Conversion Bu...
     33. OpenBSD ISAKMPD Kernel Heap Buffer Overflow Local Denial Of ...
     34. Microsoft Word for Windows 6.0 Converter Font Conversion Buf...
     35. Multiple Kerio Products Universal Secret Key Storage Vulnera...
     36. Active Server Corner ASP Calendar Administrative Access Vuln...
     37. Ricoh Aficio 450/455 PCL Printer Remote ICMP Denial Of Servi...
     38. ASP-Rider Remote SQL Injection Vulnerability
     39. Adobe Acrobat/Acrobat Reader ETD File Parser Format String V...
     40. Linux Kernel Local DRM Denial Of Service Vulnerability
     41. Linux Kernel PROC Filesystem Local Information Disclosure Vu...
     42. Linux Kernel Sys32_NI_Syscall/Sys32_VM86_Warning Local Buffe...
     43. Linux Kernel Sock_DGram_SendMsg Local Denial Of Service Vuln...
     44. Roxio Toast TDIXSupport Local Privilege Escalation Vulnerabi...
     45. Vim Modelines Arbitrary Command Execution Variant Vulnerabil...
     46. Novell NetMail Multiple Remote Vulnerabilities
     47. Ethereal Multiple Unspecified Denial of Service and Potentia...
     48. 3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerabil...
     49. IWebNegar Multiple SQL Injection Vulnerabilities
     50. Asante FM2008 Managed Ethernet Switch Default Backdoor Accou...
     51. SIR GNUBoard Remote File Include Vulnerability
     52. Apple Safari Web Browser HTML Form Status Bar Misrepresentat...
     53. Microsoft Internet Explorer DHTML Edit Control Script Inject...
     54. MoniWiki Remote Server-Side Script Execution Vulnerability
     55. PHPGroupWare Multiple Cross-Site Scripting and SQL Injection...
     56. Cisco Unity With Exchange Default User Accounts and Password...
     57. Linux Kernel Multiple Local Vulnerabilities
     58. ChBg Scenario File Overflow Vulnerability
     59. MPG123 Find Next File Remote Client-Side Buffer Overflow Vul...
     60. Cisco Guard And Traffic Anomaly Detector Default Backdoor Ac...
     61. IglooFTP Server Response Download Filename File Corruption V...
     62. IglooFTP File Upload Insecure Temporary File Vulnerability
     63. MPlayer MMST Get_Header Remote Client-Side Buffer Overflow V...
     64. ChangePassword Local Privilege Escalation Vulnerability
     65. PHP Multiple Local And Remote Vulnerabilities
     66. TNFTP FTP Client Directory Traversal Vulnerability
     67. NapShare Remote Buffer Overflow Vulnerability
     68. CUPS HPGL File Processor Buffer Overflow Vulnerability
     69. Xine-Lib Remote Client-Side Buffer Overflow Vulnerability
     70. XLReader Remote Client-Side Buffer Overflow Vulnerability
     71. Computer Associates eTrust EZ Antivirus Local Insecure Defau...
     72. Sun ONE/iPlanet Messaging Server Webmail HTML Injection Vuln...
     73. Samba Directory Access Control List Remote Integer Overflow ...
     74. VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vul...
     75. Yanf HTTP Response Buffer Overflow Vulnerability
     76. JPegToAvi File List Buffer Overflow Vulnerability
     77. Bolthole Filter Address Parsing Buffer Overflow Vulnerabilit...
     78. Junkie FTP Client Server Response Download Filename Command ...
     79. Vilistextum HTML Attribute Parsing Buffer Overflow Vulnerabi...
     80. 2Fax Tab Expansion Buffer Overflow Vulnerability
     81. PHP Multiple Remote Vulnerabilities
     82. Ikonboard Multiple Remote SQL Injection Vulnerabilities
     83. JSBoard Remote Arbitrary Script Upload Vulnerability
     84. Wordpress Multiple Cross-Site Scripting, HTML Injection, And...
     85. MediaWiki Remote Arbitrary Script Upload Vulnerability
     86. DXFScope Remote Client-Side Buffer Overflow Vulnerability
     87. MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Over...
     88. QwikMail HELO Command Buffer Overflow Vulnerability
     89. Singapore Image Gallery Multiple Remote Vulnerabilities
     90. NASM Error Preprocessor Directive Buffer Overflow Vulnerabil...
     91. PHP JPEG Image Buffer Overflow Vulnerability
     92. Slashcode Slash CVS Unspecified Security Vulnerability
     93. RTF2LATEX2E Stack Buffer Overflow Vulnerability
     94. Convex 3D Buffer Overflow Vulnerability
     95. NetBSD Multiple Local Unspecified Binary Compatibility Layer...
     96. LinPopUp Remote Buffer Overflow Vulnerability
     97. Gadu-Gadu Multiple Remote Input Validation And Denial Of Ser...
     98. YAMT ID3 Tag Sort Command Execution Vulnerability
     99. O3Read HTML Parser Buffer Overflow Vulnerability
     100. Symantec Brightmail Multiple Remote Denial of Service Vulner...
III. SECURITYFOCUS NEWS ARTICLES
     1. Report: DHS cyber security lagging
     2. Long prison term for Lowe's wi-fi hacker
     3. DirecTV hacker sentenced to seven years
     4. Popular BitTorrent site shuts down after flurry of suits
     5. NASA hacker jailed for six months
     6. US ISP wins $1bn damages from spammers
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Colasoft Capsa 4.05
     2. Attack Tool Kit (ATK) 3.0
     3. One-Time Password Generator 1.0
     4. tenshi 0.3.2
     5. pasmal 1.5
     6. AppRecon 1.0.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Manager, Information Security, Ft. Lauderda... (Thread)
     2. [SJ-JOB] Sales Representative, Los Angeles, US (Thread)
     3. [SJ-JOB] Sales Representative, Munich, DE (Thread)
     4. [SJ-JOB] Sales Engineer, Munich, DE (Thread)
     5. [SJ-JOB] Security Consultant, North Bergen, US (Thread)
     6. [SJ-JOB] Sales Representative, New York, US (Thread)
     7. [SJ-JOB] Auditor, Falls Church/Vienna, US (Thread)
     8. [SJ-JOB] Security System Administrator, Milwaukee, U... (Thread)
     9. [SJ-JOB] Sr. Security Analyst, Evansville, US (Thread)
     10. [SJ-JOB] Security Product Marketing Manager, Bay Are... (Thread)
     11. [SJ-JOB] Developer, San Diego, US (Thread)
     12. [SJ-JOB] Channel / Business Development, Boston, US (Thread)
     13. [SJ-JOB] Sr. Product Manager, Alexandria, US (Thread)
     14. [SJ-JOB] Security Consultant, London, GB (Thread)
     15. [SJ-JOB] Security Product Manager, Santa Clara, US (Thread)
     16. [SJ-JOB] Security Consultant, Evansville, US (Thread)
     17. [SJ-JOB] Security Consultant, Columbia, US (Thread)
     18. [SJ-JOB] VP / Dir / Mgr engineering, New York metro ... (Thread)
     19. [SJ-JOB] Security Engineer, London, GB (Thread)
     20. [SJ-JOB] Sales Engineer, New York/New Jersey or Bost... (Thread)
     21. [SJ-JOB] Security System Administrator, Arlington, U... (Thread)
     22. [SJ-JOB] Developer, Arlington, US (Thread)
     23. [SJ-JOB] Security Engineer, Fremont, US (Thread)
VI. INCIDENTS LIST SUMMARY
     1. SSH scans... (Thread)
     2. [incidents] SSH scans... (Thread)
     3. SSH scans... another possible solution (Thread)
     4. Strange command histories in hacked shell server (Thread)
     5. PHP injection attempt from 200.222.244.154 (Thread)
     6. IIS web server hacked..any tips? (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Exploiting network services question (Thread)
     2. HyperTerminal - Buffer Overflow In .ht File (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. Securty Audit Correlating (Thread)
     2. Subdomain security (Thread)
     3. services running in windows domain (winXP clients) (Thread)
     4. iisadmpwd/UPN (Thread)
     5. SV: services running in windows domain (winXP client... (Thread)
     6. Corrupt Certificate information on local system (Thread)
     7. SecurityFocus Microsoft Newsletter #219 (Thread)
     8. Group policy help needed!!! (Thread)
     9. RE : Secondary Storage Device Policy (Thread)
     10. Secondary Storage Device Policy (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2004-12-14 to 2004-12-21.
X. LINUX FOCUS LIST SUMMARY
     1. *nix data wipe tools (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Zero Viruses In 2005?
By Kelly Martin 

It's the time of year to reflect on the good security choices you've made
over the year, the defense-in-depth strategy that you've decided to follow,
and plan for your response to future threats and virus outbreaks.

http://www.securityfocus.com/columnists/284


2. Security Holes That Run Deep
By Mark Burnett

How a seemingly simply Microsoft bug betrayed its author's disdain for a
wide range of secure coding principles.

http://www.securityfocus.com/columnists/285

II. BUGTRAQ SUMMARY
-------------------
1. Opera Web Browser Download Dialogue Box File Name Spoofing V...
BugTraq ID: 11883
Remote: Yes
Date Published: Dec 11 2004
Relevant URL: http://www.securityfocus.com/bid/11883
Summary:
A download dialogue box file name spoofing vulnerability affects Opera. This issue is due to a design error that facilitates the spoofing of file names.

The problem presents itself when an unsuspecting user attempts to download a file from a malicious site. The malicious web site may respond with HTTP header data that is sufficient to trigger the issue. As a result of this attack, the requested filename and file type may be misrepresented in a file download dialog, making it possible for an attacker to make a potentially malicious file seem innocuous.

2. MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vu...
BugTraq ID: 11884
Remote: No
Date Published: Dec 11 2004
Relevant URL: http://www.securityfocus.com/bid/11884
Summary:
MTR is reported prone to an off-by-one buffer overflow vulnerability. The issue is present in the mtr_curses_keyaction() function for the key bindings 's', 'b', 'Q', 'i', 'f', 'm' and 'o'.

Exploitation of this vulnerability could allow a local attacker to hijack a raw socket. The possibility of successful exploitation may depend on certain properties of the underlying environment, including the architecture and the compiler version used.  These factors may limit the possibility of exploiting the condition to corrupt a sensitive value in memory.

3. Citadel/UX Network Data Logging Remote Format String Vulnera...
BugTraq ID: 11885
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11885
Summary:
A remote format string vulnerability reportedly affects the network data logging functionality of Citadel/UX.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.

A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution.  Any code execution would take place with superuser privileges.

4. phpMyAdmin Multiple Remote Vulnerabilities
BugTraq ID: 11886
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11886
Summary:
phpMyAdmin is reported prone to multiple remote vulnerabilities.  These issues can allow remote attackers to execute arbitrary commands and disclose files on a vulnerable computer.  These issues result from insufficient sanitization of user-supplied data.

The command execution is reported to be present since phpMyAdmin 2.6.0-pl2.  The file disclosure is present since phpMyAdmin 2.4.0.

5. Digital Illusions CE Codename Eagle Remote Denial Of Service...
BugTraq ID: 11887
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11887
Summary:
A remote denial of service vulnerability reportedly affects Digital Illusions CE Codename Eagle.  This issue is due to a failure of the application to properly handle exceptional network data.

An attacker may leverage this issue to cause the affected application to stop responding to network-based messages, effectively denying service to legitimate, remote users.  Due to the nature of the network protocol used by the affected application an attacker may spoof their network identity, facilitating anonymous exploitation.

6. PhpDig Unspecified Remote Vulnerability
BugTraq ID: 11889
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11889
Summary:
PhpDig is reported prone to a security vulnerability. The details of this vulnerability are unspecified.

It is conjectured that this vulnerability may be exploited by a remote attacker to compromise a computer that is hosting the vulnerable software.

This BID will be updated as soon as further details are available.

7. Novell Netware Screen Saver Local Authentication Bypass Vuln...
BugTraq ID: 11892
Remote: No
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11892
Summary:
Novell Netware is reported prone to a local authentication bypass vulnerability.  This issue can allow an attacker to gain unauthorized access to a computer.

The operating system may be locked with the SCRSAVER NLM to deny access to the console.  Typically, only a user with supervisor privileges in the e-directory tree is able to unlock the computer, however an attacker can bypass this restriction by invoking the Netware debugger and shutting down the screen saver.

8. Opentools Attachment Mod Multiple Remote Vulnerabilities
BugTraq ID: 11893
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11893
Summary:
Opentools Attachment Mod is reported prone to multiple remote unspecified vulnerabilities. The following issues are reported:

A directory traversal vulnerability is reported to affect 
Attachment Mod. It is reported that a remote attacker may exploit this vulnerability to add, or remove files that resides outside of the prescribed upload root directory.

An access control bypass vulnerability is reported to affect Attachment Mod. Reports indicate that due to insufficient handling of mod_mime on several unspecified file extensions, an attacker may bypass Attachment Mod restrictions and upload arbitrary script files.

9. mnoGoSearch Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 11895
Remote: Yes
Date Published: Dec 10 2004
Relevant URL: http://www.securityfocus.com/bid/11895
Summary:
It is reported that mnoGoSearch is affected by various cross-site scripting vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input. 

These problems present themselves when malicious HTML and script code is sent to the application through the next/prev search results page and extended/simple search form links.

mnoGoSearch 3.2.26 and prior versions are vulnerable to these issues.

10. SugarSales Multiple Remote Vulnerabilities
BugTraq ID: 11896
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11896
Summary:
Multiple remote vulnerabilities are reported to exist in SugarSales.

The first reported issue is an SQL injection vulnerability. This vulnerability is due to a lack of proper input-validation by the application, prior to utilizing attacker-supplied data in and SQL query.

This vulnerability is reported to exist in versions prior to 2.0.1a.

The next issue is reportedly a directory traversal vulnerability. This vulnerability is also due to a lack of proper input-validation by the application.

The last reported issue is a remote denial of service and information disclosure vulnerability.

The directory traversal and installation script vulnerabilities reportedly exist in all current versions of SugarSales.

These vulnerabilities may be related to the issues disclosed in BID 11740.

11. MediaWiki Images Directory Arbitrary Script Upload and Execu...
BugTraq ID: 11897
Remote: Yes
Date Published: Dec 12 2004
Relevant URL: http://www.securityfocus.com/bid/11897
Summary:
MediaWiki is prone to a vulnerability that allows remote attacker to upload and execute arbitrary scripts.  This issue presents itself due to an access validation error and allows unauthorized attackers to upload arbitrary files to the 'images' sub directory residing in the Web root.  

MediaWiki 1.3.8 and prior versions are affected by this issue.

12. SQLgrey Postfix Greylisting Service Unspecified SQL Injectio...
BugTraq ID: 11898
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11898
Summary:
SQLgrey Postfix Greylisting Service is prone to an unspecified SQL injection vulnerability.  This issue is reportedly due to insufficient sanitization of SQL syntax from fields in email processed by the software.  

The issue could be exploited to influence SQL queries, potentially allowing for compromise of the software or other attacks that impact database security.

This issue was reportedly missed by the vendor when they fixed the issue described in BID 11633.

13. Gadu-Gadu Multiple Remote Vulnerabilities
BugTraq ID: 11899
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11899
Summary:
Multiple remote vulnerabilities reportedly affect Gadu-Gadu instant messenger.

The first issue reported is a buffer overflow issue, an HTML injection issue, directory traversal vulnerability, multiple heap overflow issues, a remote code execution issue, and integer overflow issue, and an information disclosure vulnerability.

These issues may be exploited to steal potentially sensitive information, execute arbitrary code with the privileges of the affected user, and execute arbitrary script code in the context of an unsuspecting user's browser.  Successful exploitation may lead to authentication credential theft and unauthorized access.

14. UBBCentral UBB.threads Multiple Cross-Site Scripting Vulnera...
BugTraq ID: 11900
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11900
Summary:
It is reported that UBB.threads is affected by multiple cross-site scripting vulnerabilities.  These issues are due to a failure of the application to properly sanitize user-supplied URI input prior to including it in dynamically generated web pages.

These issues could permit a remote attacker to create malicious URI links that include hostile HTML and script code. If these links were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

These vulnerabilities are reported to exist in versions 6.2.3, and 6.5 of UBB.threads. Other versions may also be affected.

15. Opera Web Browser KDE KFMCLIENT Remote Command Execution Vul...
BugTraq ID: 11901
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11901
Summary:
It is reported that Opera for Linux is susceptible to a remote command execution vulnerability. This issue is due to a default configuration setting in Opera that utilizes the KDE 'kfmclient' utility to open unknown content.

Exploitation of this issue allows attacker-supplied commands to be executed in the context of the user running Opera.

Version 7.54 of Opera for Linux with KDE version 3.2.3 is reported vulnerable to this issue. Other versions may also be affected.

16. Monolith Lithtech Game Engine Remote Denial Of Service Vulne...
BugTraq ID: 11902
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11902
Summary:
Monolith Lithtech game engine is reported prone to a remote denial of service vulnerability. The vulnerability presents itself due to a failure to handle exceptional conditions. 

It is reported that socket handling code of the Lithtech game engine does not handle all potential exceptional conditions correctly, if certain sized UDP datagrams are handled the socket code will fail to handle subsequent network requests.

A remote attacker may exploit this vulnerability to deny service for legitimate users.

17. Nullsoft Winamp Tag Processing Remote Denial Of Service Vuln...
BugTraq ID: 11909
Remote: Yes
Date Published: Dec 13 2004
Relevant URL: http://www.securityfocus.com/bid/11909
Summary:
Winamp is reported prone to a remote denial of service vulnerability. The issue is reported to present itself when certain '.mp4' and '.m4a' files are processed.

It is not known at this point whether this vulnerability may be exploited to any means other than a denial of service.

18. Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnera...
BugTraq ID: 11911
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11911
Summary:
A remote buffer overflow reportedly affects the disk quota functionality of the Linux NFS utilities.  This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may leverage this issue to execute arbitrary on an affected computer with superuser privileges.  This may be exploited to gain unauthorized access or privilege escalation.

19. Microsoft Windows Kernel Unchecked LPC Buffer Privilege Esca...
BugTraq ID: 11913
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11913
Summary:
Microsoft Windows is prone to a locally exploitable privilege escalation vulnerability.  This is reportedly due to an unchecked buffer that is exposed through the LPC (Local Procedure Call) interface in the Windows kernel.  

Successful exploitation would permit a local attacker to compromise the vulnerable computer.

The vendor has stated that this issue may likely only result in a denial of service on Windows XP SP2 and Windows Server 2003 platforms.  This may be due to buffer overflow protection features included in these platforms.  It is possible that a skilled attacker could bypass these security measures.

It is noted that the vulnerability is present in an API, so any applications or libraries that rely on the API may be exposed to this issue.

20. Microsoft Windows LSASS Connection Validation Privilege Esca...
BugTraq ID: 11914
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11914
Summary:
Microsoft Windows is prone to a local privilege escalation vulnerability through LSASS (Local Security Authority Subsystem Service).  The issue is reportedly due to an access validation error in LSASS.

Successful exploitation could result in a local user gaining SYSTEM level access on the computer.

21. ZGV Image Viewer Animated GIF Remote Memory Corruption Vulne...
BugTraq ID: 11915
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11915
Summary:
A remote memory corruption vulnerability affects the animated GIF functionality of zgv. It should be noted that although it is likely that xzgv is also vulnerable to this issue, this has not been confirmed. The underlying issue causing this vulnerability is unknown, although it is likely due to a failure of the application to handle malformed image files.

The full impact of this issue is currently unknown, however this issue can be leveraged to cause the affected application to crash.  It is possible, however unconfirmed, that this issue may be leveraged to execute arbitrary code.

22. Hilgraeve HyperTerminal Session Data Buffer Overflow Vulnera...
BugTraq ID: 11916
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11916
Summary:
A remote buffer overflow vulnerability affects the session parsing functionality of Hilgraeve HyperTerminal.  HyperTerminal is shipped and installed with every copy of Microsoft Windows 98, ME, NT 4.0, 2000, XP, and 2003. It is the default telnet client in Microsoft 98 and ME, but not in Windows NT 4.0, 2000, XP, and 2003.

This issue is due to a failure of the application to properly validate the length of session-related strings prior to copying them into static process buffers.  This may be triggered by a malicious session file or through a telnet URI in circumstances where HyperTerminal is configured to be the default handler for the telnet protocol.

An attacker may exploit this issue to execute arbitrary code with the privileges of the unsuspecting user that activates the vulnerable application. This may facilitate unauthorized access or privilege escalation.

23. Linux Kernel IGMP Multiple Vulnerabilities
BugTraq ID: 11917
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11917
Summary:
Linux kernel IGMP functionality is reported prone to multiple vulnerabilities.  These issues can allow local attackers to carry out denial of service and privilege escalation attacks.  Remote attackers may also cause denial of service conditions in vulnerable computers.

The first issue exists in the 'ip_mc_source()' function and may allow local attackers to cause a denial of service condition or gain elevated privileges.

The second issue is related to the first issue and may allow an attacker to disclose sensitive kernel memory.

The third vulnerability exists in the IGMP/IP networking module and may allow remote attackers to cause a denial of service condition in a vulnerable computer.

24. Sun Java System Web And Application Server Remote Session Di...
BugTraq ID: 11918
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11918
Summary:
A remote session disclosure vulnerability affects the Sun Java System Web and Application Servers.  This issue is due to a design error that may cause sessions IDs to be revealed.

This issue may be exploited to steal session IDs from unsuspecting users and gain access to their current sessions.  Reportedly only sessions that do not require authentication are affected by this issue.

25. Microsoft Windows DHCP Server Logging Remote Denial Of Servi...
BugTraq ID: 11919
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11919
Summary:
Microsoft Windows DHCP server on NT 4 server platforms is reported susceptible to a remote denial of service vulnerability in its logging functionality. This issue is due to a failure of the application to properly handle user-supplied network input.

This vulnerability allows remote attackers to crash the affected service, denying service to legitimate users. This may allow attackers to interrupt network services to an entire network.  It is believed that this issue would only result in a denial of service, though an unconfirmed possibility of code execution exists due to the apparent nature of the vulnerability.

It is noted that the service is not installed by default, nor is the affected logging facility enabled by default where the service has been installed.

26. Microsoft Windows DHCP Server Remote Buffer Overflow Vulnera...
BugTraq ID: 11920
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11920
Summary:
Microsoft Windows DHCP server on NT 4 server platforms is reported susceptible to a remote buffer overflow vulnerability. This issue is due to insufficient bounds checking of  user-supplied network data.

This vulnerability allows remote attackers to execute arbitrary code in the context of the affected service. The DHCP server is running with administrative privileges, allowing remote attackers to gain administrative access, or to crash the affected service, denying service to legitimate users. This may allow attackers to interrupt network services to an entire network.

It is noted that the service is not installed by default.

27. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
BugTraq ID: 11921
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11921
Summary:
Linux kernel is reported prone to a local denial of service vulnerability.  This issue presents itself in the SCM logical sub layer of the socket API. 

An unprivileged application can craft a malformed auxiliary message and send it to a socket, which results in the kernel invoking '__scm_send()' in a manner that leads to a crash.  This issue can allow local attackers to cause a denial of service condition on a vulnerable computer.  It is not confirmed if this vulnerability can be leveraged to gain elevated privileges.

28. Microsoft Windows WINS Name Value Handling Remote Buffer Ove...
BugTraq ID: 11922
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11922
Summary:
It is reported that the WINS server contains a buffer overflow vulnerability that when exploited will result in WINS process memory corruption. The issue exists due to a lack of sufficient boundary checks performed on computer 'name' data that is handled during a WINS transaction. 

Ultimately, the issue could potentially be exploited remotely by a WINS client to execute arbitrary code with SYSTEM level privileges on a target WINS server. The service may be exposed via TCP/UDP port 42 by default, but the vendor has stated that other attack vectors may exist though none are known at this time.

29. Adobe Acrobat Reader Email Message Remote Buffer Overflow Vu...
BugTraq ID: 11923
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11923
Summary:
A remote buffer overflow vulnerability reportedly affects the email message checking functionality in Adobe Acrobat Reader for Unix. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

It should be noted that this issue only affects Adobe Acrobat Reader for the Unix platform.

30. UseModWiki Wiki.PL Cross-Site Scripting Vulnerability
BugTraq ID: 11924
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11924
Summary:
It is reported that UseModWiki is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied URI input before outputting it in Web Pages.

This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the Web browser of the victim user. This would occur in the security context of the affected Web site and may allow for theft of cookie-based authentication credentials or other attacks.

31. Roxio Toast TDIXSupport Local Format String Vulnerability
BugTraq ID: 11926
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11926
Summary:
A local format string vulnerability reportedly affects the TDIXSupport utility of Roxio Toast.  This issue is due to a failure of the application to securely implement a formatted printing function.

A local attacker may leverage this issue to execute arbitrary code on the affected computer with superuser privileges, facilitating privilege escalation.

32. Microsoft Word for Windows 6.0 Converter Table Conversion Bu...
BugTraq ID: 11927
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11927
Summary:
Microsoft Word for Windows 6.0 Converter is reported prone to a buffer overflow vulnerability.  An attacker may exploit this issue to gain unauthorized access to a vulnerable computer in the context of the user running the application.  This issue specifically exists in the Table Conversion functionality of the application.

It is reported that this issue may be exploited when a maliciously crafted file is opened in Microsoft WordPad.

Microsoft Word for Windows 6.0 Converter is not enabled by default on Windows XP Service Pack 2 and Windows Server 2003.  This issue reportedly does not pose a significant risk on Windows 98, 98 SE, and ME; it may only cause a denial of service condition in the application without the possibility of code execution.

33. OpenBSD ISAKMPD Kernel Heap Buffer Overflow Local Denial Of ...
BugTraq ID: 11928
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11928
Summary:
It is reported that OpenBSD's IPSEC implementation is susceptible to a kernel heap buffer overflow local denial of service vulnerability. This issue is reportedly only exploitable by local users when isakmpd(8) is running.

This issue allows attackers with local interactive access on computers running isakmpd(8) to cause kernel crashes, denying service to legitimate users. It is reported that this issue doesn't likely allow privilege escalation or code execution.

It should be noted that isakmpd(8) is not configured to run by default.

34. Microsoft Word for Windows 6.0 Converter Font Conversion Buf...
BugTraq ID: 11929
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11929
Summary:
Microsoft Word for Windows 6.0 Converter is reported prone to a buffer overflow vulnerability.  An attacker may exploit this issue to gain unauthorized access to a vulnerable computer in the context of the user running the application.  This issue specifically exists in the Font Conversion functionality of the application.

It is reported that this issue may be exploited when a maliciously crafted file is opened in Microsoft WordPad.

Microsoft Word for Windows 6.0 Converter is not enabled by default on Windows XP Service Pack 2 and Windows Server 2003.  This issue does not pose a significant risk on Windows 98, 98 SE, and ME; it may only cause a denial of service condition in the application without the possibility of code execution.

35. Multiple Kerio Products Universal Secret Key Storage Vulnera...
BugTraq ID: 11930
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11930
Summary:
Kerio WinRoute Firewall, Kerio ServerFirewall, and Kerio MailServer are all reported prone to a design flaw. It is reported that these products store credentials in a local database store, these credentials are obscured using an unspecified symmetric encryption algorithm. Reports indicate that a universal secret key is employed to extract plain text from the credential hashes; this presents a security risk because the universal secret key is stored in the WinRoute Firewall, Kerio ServerFirewall, and Kerio MailServer binaries.

36. Active Server Corner ASP Calendar Administrative Access Vuln...
BugTraq ID: 11931
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11931
Summary:
ASP Calendar is reported prone to an unauthorized administrative access vulnerability.  An unauthorized remote attacker can access an administrative script and potentially gain administrative access to the application.

It is believed that this issue affects ASP Calendar Version 1.  

Due to a lack of details, further information is not currently available.  This BID will be updated as more information becomes available.

37. Ricoh Aficio 450/455 PCL Printer Remote ICMP Denial Of Servi...
BugTraq ID: 11932
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11932
Summary:
It is reported that Ricoh 450/455 printers are susceptible to a remote denial of service vulnerability. This issue is due to a failure of the device to properly handle exceptional ICMP packets.

Remote attackers may exploit this vulnerability to restart affected devices. Repeated packets may be utilized to sustain the condition, causing the device to repeatedly restart. Source addresses of the malicious ICMP packets may also be spoofed, reducing the likelihood of locating, or blocking access to the attacker.

Due to code reuse among devices, it is likely that other printers are also affected.

38. ASP-Rider Remote SQL Injection Vulnerability
BugTraq ID: 11933
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11933
Summary:
A remote SQL injection vulnerability reportedly affects ASP-Rider Web blog.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.

An attacker may exploit this issue to manipulate SQL queries to the underlying database.  This may facilitate theft sensitive information, potentially including authentication credentials, and data corruption.

39. Adobe Acrobat/Acrobat Reader ETD File Parser Format String V...
BugTraq ID: 11934
Remote: Yes
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11934
Summary:
Adobe Acrobat/Acrobat Reader is reported prone to a remote format string vulnerability. The vulnerability is present in the ETD file parser when processing tag values. Reports indicate that the values supplied for certain tags are used as the format string in an unspecified formatted output function. Because an attacker can control the format string and the variables passed to the formatted output function, this vulnerability may be exploited to write to arbitrary locations within the memory of the process.

40. Linux Kernel Local DRM Denial Of Service Vulnerability
BugTraq ID: 11936
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11936
Summary:
It is reported that the DRM module in the Linux kernel is susceptible to a local denial of service vulnerability.

This vulnerability likely results in the corruption of video memory, crashing the X server. It is also reported that malicious users may be able to modify the video output.

Further details are unavailable at this time. This BID will be updated as further analysis is completed.

41. Linux Kernel PROC Filesystem Local Information Disclosure Vu...
BugTraq ID: 11937
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11937
Summary:
It is reported that the Linux kernel /proc filesystem is susceptible to an information disclosure vulnerability. This issue is due to a race-condition allowing unauthorized access to potentially sensitive process information.

This vulnerability may allow malicious local users to gain access to potentially sensitive environment variables in other users processes. As some programs pass passwords and other sensitive information in environment variables, this may aid a malicious user in further attacks.

Further details are unavailable at this time. This BID will be updated as further analysis is completed.

42. Linux Kernel Sys32_NI_Syscall/Sys32_VM86_Warning Local Buffe...
BugTraq ID: 11938
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11938
Summary:
The Linux kernel for 64-Bit architectures is reported prone to a local buffer overflow vulnerability.

This vulnerability exists in 'sys32_ni_syscall()' and 'sys32_vm86_warning()' as a result of an unbounded copy of a 16 byte string into an 8 byte buffer using the strcpy() function. 

Immediate consequences of exploitation of this vulnerability could be a kernel panic; this could be used to deny service to legitimate users. It is not currently known whether this vulnerability may be leveraged to provide for execution of arbitrary code.

43. Linux Kernel Sock_DGram_SendMsg Local Denial Of Service Vuln...
BugTraq ID: 11939
Remote: No
Date Published: Dec 14 2004
Relevant URL: http://www.securityfocus.com/bid/11939
Summary:
The Linux kernel is reported to be prone to a local denial of service vulnerability. This vulnerability is reported to exist when 'CONFIG_SECURITY_NETWORK=y' and 'CONFIG_SECURITY_SELINUX=y' options are set in the Linux kernel.

A local attacker may exploit this vulnerability to trigger a kernel panic and effectively deny service to legitimate users.

44. Roxio Toast TDIXSupport Local Privilege Escalation Vulnerabi...
BugTraq ID: 11940
Remote: No
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11940
Summary:
A local privilege escalation vulnerability reportedly affects Roxio Toast.  This issue is due to a design error in the application that allows an attacker to execute code with kernel privileges.

A local attacker may leverage this issue to execute arbitrary code on the affected computer with superuser privileges, facilitating privilege escalation.

45. Vim Modelines Arbitrary Command Execution Variant Vulnerabil...
BugTraq ID: 11941
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11941
Summary:
Vim modelines is prone to a vulnerability that may permit execution of arbitrary commands.  Reportedly, certain modelines options expose this issue.  Exploitation could occur when a malicious file is opened in the editor and would occur in the context of the user opening the file.

This issue is similar to BID 6384.

46. Novell NetMail Multiple Remote Vulnerabilities
BugTraq ID: 11942
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11942
Summary:
Multiple remote vulnerabilities reportedly affect Novell NetMail.  These vulnerabilities are due to multiple issues including failure to verify string length before copying them into static process buffers, failure to handle malformed input, and various design errors.

The first issue reported is a buffer overflow vulnerability in the IMAP functionality of the affected application.  The second issue is a failure of the application to properly integrate with Symantec antivirus software.  Finally a number of issues reported may facilitate denial of service attacks, although these are not confirmed.

An attacker may leverage these issues to execute arbitrary code on the affected computer, facilitating system compromise, anti-virus screening bypass, facilitating a false sense of security, and potentially carry out denial of service attacks.

47. Ethereal Multiple Unspecified Denial of Service and Potentia...
BugTraq ID: 11943
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11943
Summary:
Ethereal 0.10.8 has been released to address multiple vulnerabilities.  These vulnerabilities are reported to cause denial of service conditions in the application, however, it is reported that some issues may allow for arbitrary code execution.

The following specific issues were specified:

A denial of service vulnerability presents itself in the DICOM dissector.

The application suffers from a denial of service vulnerability when handling a malformed RTP timestamp.

It is reported that the HTTP dissector may allow a remote attacker to access memory that was previously freed.

Another denial of service issues affecting the application arises when Ethereal processes a specially crafted SMB packet.

This BID will be updated as more information becomes available.

48. 3Com 3CDaemon TFTP Service Remote Buffer Overflow Vulnerabil...
BugTraq ID: 11944
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11944
Summary:
3CDaemon TFTP service is reported to be prone to a remote denial of service vulnerability. The vulnerability presents itself when any command is invoked that contains a superfluous filename parameter. When such a command is handled, the 3CDaemon will fail reporting opmode 0x01.

49. IWebNegar Multiple SQL Injection Vulnerabilities
BugTraq ID: 11946
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11946
Summary:
iWebNegar is reported prone to multiple SQL injection vulnerabilities, these issues exist due to a lack of sufficient boundary checks performed on user-supplied URI parameter data.

These issues could theoretically be exploited to compromise the software by performing unauthorized actions on the database, such as modifying or viewing data. SQL injection attacks may also be used to exploit latent vulnerabilities in the underlying database. This may depend on the nature of the query being manipulated as well as the capabilities of the database implementation.

50. Asante FM2008 Managed Ethernet Switch Default Backdoor Accou...
BugTraq ID: 11947
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11947
Summary:
It is reported that Asante FM2008 managed Ethernet switches contain a default backdoor account vulnerability.

Attackers with network access to the telnet port of affected devices may gain administrative access by using these default credentials. These default credentials are not reportedly usable in the web administration interface, just the telnet or serial interfaces.

Version v01.06 of Asante FM2008 switches are reported susceptible to this vulnerability. Due to code reuse among devices, it is likely that other devices are vulnerable as well.

51. SIR GNUBoard Remote File Include Vulnerability
BugTraq ID: 11948
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11948
Summary:
A remote file include vulnerability reportedly affects SIR GNUBoard.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in an 'include()' function call.

An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the affected Web server.  This issue will facilitate unauthorized access to the affected computer.

52. Apple Safari Web Browser HTML Form Status Bar Misrepresentat...
BugTraq ID: 11949
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11949
Summary:
A vulnerability has been identified in Apple Safari Web Browser that allows an attacker to misrepresent the status bar in the browser, allowing vulnerable users to be mislead into following a link to a malicious site.

The issue presents itself when an attacker creates an HTML form with the submit 'value' property set to a legitimate site and the 'action' property set to the attacker-specified site.  The malicious form could also be embedded in a link using the HTML Anchor tag and specifying the legitimate site as the 'href' property.  As a result, the attacker-supplied link would point to the legitimate site and the status bar would display the address of the legitimate site as well.

53. Microsoft Internet Explorer DHTML Edit Control Script Inject...
BugTraq ID: 11950
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11950
Summary:
Microsoft Internet Explorer DHTML Edit control may be used to carry out cross-domain script injection.  This issue may allow an attacker to execute malicious script code in a user's browser to facilitate cross-site scripting type attacks. 

It is possible to steal cookie-based authentication credentials through this vulnerability.  Other attacks may be possible as well.

54. MoniWiki Remote Server-Side Script Execution Vulnerability
BugTraq ID: 11951
Remote: No
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11951
Summary:
A remote server-side script execution vulnerability affects MoniWiki.  This issue is due to a design error that causes the application to allow an attacker to upload server-side script files and have them executed.

An attacker may exploit this issue to upload and execute arbitrary server-side scripts.  This will facilitate unauthorized access to the affected computer.

55. PHPGroupWare Multiple Cross-Site Scripting and SQL Injection...
BugTraq ID: 11952
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11952
Summary:
Reportedly PHPGroupWare contains multiple input validation vulnerabilities; it is prone to multiple SQL injection and cross-site scripting issues.  These issues are all due to a failure of the application to properly sanitize user-supplied input. 

The SQL injection issues may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information such as the administrator password hash or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation. 

The cross-site scripting issues could permit a remote attacker to create a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks. 

These issues were identified in PHPGroupWare 0.9.16.003, however, it is possible that other versions are affected as well.

56. Cisco Unity With Exchange Default User Accounts and Password...
BugTraq ID: 11954
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11954
Summary:
It is reported that vulnerable Unity systems contain default user accounts and passwords that can be used by an attacker to gain unauthorized access.  This issue only arises when Unity is integrated with Microsoft Exchange.

Unauthorized attakers may use these accounts to gain administrative access to vulnerable systems.  Some accounts can allow attackers to disclose messages going to and from external voicemail systems.

57. Linux Kernel Multiple Local Vulnerabilities
BugTraq ID: 11956
Remote: No
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11956
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities. The following individual issues are reported:

An integer overflow is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file, this vulnerability is only reported to exist in the 2.6 kernel tree. 

Although unconfirmed, due to the nature of this vulnerability it is conjectured that this issue may be further leveraged to provide for arbitrary code execution with ring 0 privileges.

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.

A second integer overflow vulnerability is reported to exist in the 'vc_resize()' function of the Linux kernel, this vulnerability is reported to exist in the 2.6 and 2.4 kernel trees. 

Although unconfirmed, due to the nature of this vulnerability it is conjectured that this issue may be further leveraged to provide for arbitrary code execution with ring 0 privileges.

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.

A third vulnerability, a memory leak, is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file, this vulnerability is reported to exist in the 2.6, and 2.4 kernel tree.

A local attacker may exploit this vulnerability to consume kernel heap memory resources and in doing so may impact system performance ultimately resulting in a denial of service to legitimate users.

58. ChBg Scenario File Overflow Vulnerability
BugTraq ID: 11957
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11957
Summary:
ChBg is reported prone to a remote buffer overflow vulnerability.  This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers.  It is reported that this issue can allow an attacker to gain superuser privileges on a vulnerable computer.

An attacker can exploit this issue by crafting a malicious scenario file. A scenario is a file containing a list of pictures to display.

If a user obtains this file and processes it through ChBg, the attacker-supplied instructions may be executed on the vulnerable computer.

ChBg 1.5 is reported prone to this vulnerability.  It is likely that other versions are affected as well.

59. MPG123 Find Next File Remote Client-Side Buffer Overflow Vul...
BugTraq ID: 11958
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11958
Summary:
A remote client-side buffer overflow vulnerability affects mpg123.  This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

60. Cisco Guard And Traffic Anomaly Detector Default Backdoor Ac...
BugTraq ID: 11959
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11959
Summary:
It is reported that Cisco Guard and Anomaly Detector appliances contain a default backdoor account vulnerability.

These appliances contain an undocumented user with a username of 'root', and an unspecified default password. This is an administrative account, with privileges similar to the Unix superuser.

By exploiting this vulnerability, attackers with SSH or HTTPS access to affected devices may gain administrative access.

Versions of Cisco Guard prior to 3.1, and versions of Cisco Anomaly Detector prior to 3.1 are reportedly affected by this vulnerability.

61. IglooFTP Server Response Download Filename File Corruption V...
BugTraq ID: 11960
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11960
Summary:
IglooFTP does not properly sanitize server-supplied filenames during downloads, potentially allowing for files to be created or overwritten in the context of the client user.  This issue is reported to occur when the FTP client is used to recursively download files from a remote FTP server.

This issue reportedly exists in UNIX/Linux based versions of IglooFTP.  It is not known if Windows versions are affected.

62. IglooFTP File Upload Insecure Temporary File Vulnerability
BugTraq ID: 11961
Remote: No
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11961
Summary:
IglooFTP creates temporary files in an insecure manner.  This issue is reported to occur when the client is uploading files to a remote server.  An attacker could abuse this issue through symbolic link attacks that corrupt files owned by the user, most likely resulting in a loss of data.

This issue reportedly exists in UNIX/Linux based versions of IglooFTP.  It is not known if Windows versions are affected.

63. MPlayer MMST Get_Header Remote Client-Side Buffer Overflow V...
BugTraq ID: 11962
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11962
Summary:
A remote, client-side buffer overflow vulnerability reportedly affects MPlayer. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

64. ChangePassword Local Privilege Escalation Vulnerability
BugTraq ID: 11963
Remote: No
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11963
Summary:
ChangePassword is reported prone to a local privilege escalation vulnerability.  This issue can allow local attackers to gain superuser privileges on a vulnerable computer.

ChangePassword 0.8 and prior versions are believed to be affected by this issue.

65. PHP Multiple Local And Remote Vulnerabilities
BugTraq ID: 11964
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11964
Summary:
PHP4 and PHP5 are reported prone to multiple local and remote vulnerabilities that may lead to code execution within the context of the vulnerable process. The following specific issues are reported:

A heap-based buffer overflow is reported to affect the PHP 'pack()' function call. An attacker that has the ability to make the PHP interpreter run a malicious script may exploit this condition to execute arbitrary instructions in the context of the vulnerable process.

A heap-based memory disclosure vulnerability is reported to affect the PHP 'unpack()' function call. An attacker that has the ability to make the PHP interpreter run a malicious script may exploit this condition to reveal portions of the process heap.

PHP safe_mode_exec_dir is reported prone to an access control bypass vulnerability. A local attacker that can manipulate the directory name from which the PHP script is called, may bypass 'safe_mode_exec_dir' restrictions by placing shell metacharacters and restricted commands into the directory name of the current directory.

PHP safe_mode is reported prone to an access control bypass vulnerability. An attacker that has the ability to make the PHP interpreter run a malicious script may exploit this condition to execute commands that are otherwise restricted by PHP safe_mode.

PHP is reported prone to a 'realpath()' path truncation vulnerability. The vulnerability exists due to a lack of sanitization as to whether a path has been silently truncated by the libc realpath() function or not. This may lead to remote file include vulnerabilities in some cases.

The PHP function 'unserialize()' is reported prone to a memory corruption vulnerability. This corruption may be leveraged by a remote attacker that has the ability to make the PHP interpreter run a malicious script to execute arbitrary code in the context of the vulnerable process.

The PHP function 'unserialize()' is also reported prone to an information disclosure vulnerability. This issue may be leveraged by a remote attacker to disclose the contents of heap memory. This may allow them to gain access to potentially sensitive information, such as database credentials.

Finally, the PHP function 'unserialize()', is reported prone to an additional vulnerability. It is reported that previous versions of this function allow a malicious programmer to set references to entries of a variable hash that have already been freed. This can lead to remote memory corruption.

66. TNFTP FTP Client Directory Traversal Vulnerability
BugTraq ID: 11965
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11965
Summary:
The tnftp FTP client is reported susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.

This vulnerability results in the ability of the attacker controlling a malicious remote server being able to write to arbitrary locations on the client's computer with the privileges of the user invoking the vulnerable FTP client. Depending on the particular configuration of the vulnerable FTP client, new files may be created, files may be overwritten, or appended to. Depending on the configuration, this may also occur without confirmation.

67. NapShare Remote Buffer Overflow Vulnerability
BugTraq ID: 11967
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11967
Summary:
It is reported that NapShare is susceptible to a remote buffer overflow vulnerability. This is due to a failure of the application to properly bounds check user-supplied data prior to copying it to a fixed-size memory buffer.

Attackers running malicious Gnutella servers are reportedly able to exploit this vulnerability to execute arbitrary code in the context of the vulnerable application.

Version 1.2 of NapShare is reported susceptible. Other versions may also be affected.

68. CUPS HPGL File Processor Buffer Overflow Vulnerability
BugTraq ID: 11968
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11968
Summary:
CUPS is reported prone to a remote buffer overflow vulnerability. The issue is reported to exist in the 'hpgl-input.c' source file and is because of a lack of sufficient boundary checks performed on data contained in HPGL files.

A remote attacker may exploit this condition to execute arbitrary code in the context of the vulnerable CUPS daemon.

69. Xine-Lib Remote Client-Side Buffer Overflow Vulnerability
BugTraq ID: 11969
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11969
Summary:
It is reported that the xine media library is affected by a remote buffer overflow vulnerability. This issue can allow a remote attacker to gain unauthorized access to a vulnerable computer. The overflow condition presents itself in the 'demux_aiff.c' file.

70. XLReader Remote Client-Side Buffer Overflow Vulnerability
BugTraq ID: 11970
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11970
Summary:
A remote, client-side buffer overflow vulnerability affects xlreader. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

71. Computer Associates eTrust EZ Antivirus Local Insecure Defau...
BugTraq ID: 11971
Remote: No
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11971
Summary:
A local insecure installation vulnerability affects eTrust EZ Antivirus. This issue is due to a failure of the application to properly secure files upon installation.

An attacker may leverage this issue to manipulate installed files, potentially allowing them to disable anti-virus protection or execute code with SYSTEM privileges.

72. Sun ONE/iPlanet Messaging Server Webmail HTML Injection Vuln...
BugTraq ID: 11972
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11972
Summary:
Sun ONE and iPlanet Messaging Server are prone to an HTML injection vulnerability.  This issue exists in the Webmail facility and may be exploited by injecting hostile HTML and script code through emails.  When such an email is read by a user of the Webmail system, attacker-supplied HTML and script code could be rendered in their browser.

This may facilitate session hijacking, ultimately allowing for compromise of Webmail accounts.  Other attacks are also possible.

73. Samba Directory Access Control List Remote Integer Overflow ...
BugTraq ID: 11973
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11973
Summary:
A remotely exploitable integer overflow vulnerability affects the directory access control list (DACL) processing functionality of Samba.  This issue is due to a failure of the application to properly perform sanity checking on calculated data sizes prior to copying data into static process buffers.

An attacker with access to an SMB share may leverage this issue to overwrite the heap of the affected process, facilitating code execution with superuser privileges.

74. VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vul...
BugTraq ID: 11974
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11974
Summary:
VERITAS Backup Exec is reported prone to a remote buffer overflow vulnerability.  This issue exists because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers.  A remote attacker can exploit this issue to execute arbitrary code on a vulnerable computer leading to a complete compromise.

It is reported that this issue presents itself in an unspecified function that is responsible for handling registration requests.  This function is part of the Agent Browser service code.

75. Yanf HTTP Response Buffer Overflow Vulnerability
BugTraq ID: 11975
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11975
Summary:
Yanf is prone to a buffer overflow vulnerability.  This issue is exposed when the client reads data from a remote HTTP server.  

If this issue is successfully exploited, it could allow for execution of arbitrary code in the context of the user running the client.

76. JPegToAvi File List Buffer Overflow Vulnerability
BugTraq ID: 11976
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11976
Summary:
jpegtoavi is prone to a buffer overflow.  This issue is exposed when the software handles a malformed file list.  As the list originates from an external or untrusted source, this issue is considered remote in nature.  

If this vulnerability is successfully exploited, it will result in execution of arbitrary code in the context of the user running the application.

77. Bolthole Filter Address Parsing Buffer Overflow Vulnerabilit...
BugTraq ID: 11977
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11977
Summary:
Bolthole Filter is prone to a buffer overflow vulnerability.  This issue is exposed when the software parses email address data.

If successfully exploited, this vulnerability could result in execution of arbitrary code in the context of the process.

78. Junkie FTP Client Server Response Download Filename Command ...
BugTraq ID: 11978
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11978
Summary:
A remote command execution vulnerability reportedly affects junkie FTP client.  This issue is due to a failure of the application to sanitize network derived input prior to using it in a using it in a system() command.

An attacker may leverage this issue to execute arbitrary commands with the privileges of the unsuspecting user that activated the affected application.  This may facilitate unauthorized access and privilege escalation.

79. Vilistextum HTML Attribute Parsing Buffer Overflow Vulnerabi...
BugTraq ID: 11979
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11979
Summary:
Vilistextum is prone to a buffer overflow vulnerability.  This issue is exposed when the application parses HTML attributes while converting an HTML file to text/ASCII.  Since HTML files will likely originate from an external or untrusted source, this issue should be considered remote in nature.

Successful exploitation will allow for execution of arbitrary code in the context of the user running the application.

80. 2Fax Tab Expansion Buffer Overflow Vulnerability
BugTraq ID: 11980
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11980
Summary:
2fax is prone to a buffer overflow vulnerability.  This issue is exposed when the software performs tab expansion operations while converting files.  Since files may originate from an external or untrusted source, this issue is considered remote in nature.

Successful exploitation will result in execution of arbitrary code in the context of the user running the application.

81. PHP Multiple Remote Vulnerabilities
BugTraq ID: 11981
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11981
Summary:
PHP4 and PHP5 are reported prone to multiple remotely exploitable vulnerabilities.  These issue result from insufficient sanitization of user-supplied data.  A remote attacker may carry out directory traversal attacks to disclose arbitrary files and upload files to arbitrary locations.

It is reported that these vulnerabilities may only be exploited on Windows.

82. Ikonboard Multiple Remote SQL Injection Vulnerabilities
BugTraq ID: 11982
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11982
Summary:
Multiple remote SQL injection vulnerabilities reportedly affect Ikonboard. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.

An attacker may exploit these issues to manipulate SQL queries to the underlying database.  This may facilitate theft of sensitive information, potentially including authentication credentials, and data corruption.

83. JSBoard Remote Arbitrary Script Upload Vulnerability
BugTraq ID: 11983
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11983
Summary:
JSBoard is reported prone to a vulnerability that can allow a remote attacker to upload arbitrary PHP scripts to a vulnerable server.  This issue results from insufficient sanitization of user-supplied input.  

If successful, the attacker can execute arbitrary script code on a vulnerable server.  This can lead to unauthorized access in the context of the application.

This issue was identified in versions of JSBoard 2.0.8 and prior and JSBoard-win32 1.3.11a prior.

84. Wordpress Multiple Cross-Site Scripting, HTML Injection, And...
BugTraq ID: 11984
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11984
Summary:
Wordpress is reported vulnerable to multiple cross-site scripting, HTML injection, and SQL injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied data.

The cross-site scripting and HTML injection issues could permit a remote attacker to create a malicious URI link, or post data to the affected application that includes hostile HTML and script code. If this link were to be followed, or resulting pages were to be viewed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

An attacker may exploit the SQL injection issues to manipulate SQL queries to the underlying database. This may facilitate theft of sensitive information, potentially including authentication credentials, and data corruption.

Update:  These vulnerabilities were originally reported to affect Wordpress 1.2.1.  Subsequent to the release of this BID, the vendor released Wordpress 1.2.2 to address these issues.  It is reported that version 1.2.2 is still vulnerable to some of these issues.  Wordpress 1.2.2 is being removed as an invulnerable package and the vulnerabilities affecting version 1.2.2 are described in Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (BID 12066).  A message reference with more information is attached to this BID as well.

85. MediaWiki Remote Arbitrary Script Upload Vulnerability
BugTraq ID: 11985
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11985
Summary:
MediaWiki is reported prone to a vulnerability that can allow a remote attacker to upload arbitrary PHP scripts to a vulnerable server. This issue results from insufficient sanitization of user-supplied input. 

If successful, the attacker can execute arbitrary script code on a vulnerable server. This can lead to unauthorized access in the context of the application. 

MediaWiki 1.3.8 and prior versions are affected by this issue.

86. DXFScope Remote Client-Side Buffer Overflow Vulnerability
BugTraq ID: 11986
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11986
Summary:
A remote, client-side buffer overflow vulnerability reportedly affects the DXFscope utility.  This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it as the format specifier string in a formatted printing function.

An attacker may leverage this issue to execute arbitrary code with the privileges on an unsuspecting user that uses the vulnerable application to process a malicious DXF formatted file. This may facilitate unauthorized access or privilege escalation.

87. MPlayer And Xine-Lib Multiple Remote Client-Side Buffer Over...
BugTraq ID: 11987
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11987
Summary:
Multiple remote, client side buffer overflow vulnerabilities reportedly affect xine-lib and MPlayer.  These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

88. QwikMail HELO Command Buffer Overflow Vulnerability
BugTraq ID: 11989
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11989
Summary:
QwikMail (qwik-smtpd) is reported prone to a remotely exploitable buffer overflow vulnerability.  The issue is due to insufficient bounds checking of  client-supplied SMTP HELO request data.

This issue could theoretically be exploited to execute arbitrary code.  Due to the memory layout, it is also reportedly possible to overwrite an adjacent buffer in a manner that will allow a remote attacker to abuse the server as an unauthorized mail relay.

89. Singapore Image Gallery Multiple Remote Vulnerabilities
BugTraq ID: 11990
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11990
Summary:
Singapore is prone to multiple vulnerabilities.  These issues result from insufficient sanitization of user-supplied input and may allow remote attackers to carry out directory traversal, file upload, and cross-site scripting attacks.

An attacker may disclose files from a vulnerable server by issuing a malicious HTTP GET request containing directory traversal sequences.

The application is affected by an arbitrary script upload vulnerability.

An attacker can delete arbitrary files from a vulnerable computer.

The application is also vulnerable to multiple unspecified cross-site scripting issues.

Singapore 0.9.10 and prior versions are believed to be vulnerable to these vulnerabilities.

90. NASM Error Preprocessor Directive Buffer Overflow Vulnerabil...
BugTraq ID: 11991
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11991
Summary:
NASM is prone to a buffer overflow.  This condition is exposed when the application attempts to assemble a source file that contains malformed '%error' preprocessor directive arguments.  Since the source file may originate from an external or untrusted source, this vulnerability is considered remote in nature.

Successful exploitation will permit arbitrary code execution with the privileges of the user running the application.

91. PHP JPEG Image Buffer Overflow Vulnerability
BugTraq ID: 11992
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11992
Summary:
It is reported that PHP is susceptible to a buffer overflow vulnerability in handling JPEG images. This issue is due to a failure of the application to properly bounds check user-supplied image data prior to copying it into a fixed-size memory buffer.

This vulnerability allows remote attackers to alter the proper flow of execution of the application, potentially resulting in the execution of attacker-supplied machine code in the context of the web server executing the PHP interpreter.

92. Slashcode Slash CVS Unspecified Security Vulnerability
BugTraq ID: 11993
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11993
Summary:
An unspecified vulnerability or vulnerabilities affect Slashcode Slash.  The underlying cause of this issue is currently unknown.

The potential impact or impacts of this issue are currently unknown.  This BID will be updated upon the release of more information.

93. RTF2LATEX2E Stack Buffer Overflow Vulnerability
BugTraq ID: 11994
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11994
Summary:
It is reported that rtf2latex2e is susceptible to a stack buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied image data prior to copying it into a fixed-size memory buffer.

This vulnerability allows remote attackers to alter the proper flow of execution of the application, potentially resulting in the execution of attacker-supplied machine code in the context of the application attempting to read the malicious RTF file.

94. Convex 3D Buffer Overflow Vulnerability
BugTraq ID: 11995
Remote: Yes
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11995
Summary:
It is reported that Convex 3D is susceptible to a stack-based buffer overflow vulnerability. This issue is due to a failure of the application to properly check the bounds of user-supplied image data prior to copying it into a fixed-size memory buffer.

This vulnerability allows remote attackers to alter the proper flow of execution of the application, potentially resulting in the execution of attacker-supplied machine code in the context of the application attempting to read a malicious file.

95. NetBSD Multiple Local Unspecified Binary Compatibility Layer...
BugTraq ID: 11996
Remote: No
Date Published: Dec 16 2004
Relevant URL: http://www.securityfocus.com/bid/11996
Summary:
It is reported that NetBSD is susceptible to multiple unspecified local vulnerabilities in its binary compatibility layer. It is reported that many, if not all of the compatibility types are affected by these vulnerabilities. The system call translation functions reportedly execute unsafe operations with the user-supplied system call arguments.

This BID will be updated as further information is disclosed, and as further analysis is performed.

These vulnerabilities affect computers running NetBSD that have any 'COMPAT_*' options defined in the running kernel.

These vulnerabilities allow local users to crash the kernel, denying service to legitimate users. It is also conjectured that some of these issues may allow for code execution in kernel-space, leading to privilege escalation.

96. LinPopUp Remote Buffer Overflow Vulnerability
BugTraq ID: 11997
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11997
Summary:
LinPopUp is reported prone to a remote buffer overflow vulnerability.  This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain unauthorized access to a computer in the context of the application. 

An attacker can exploit this issue by crafting a malicious message that contains excessive string data, replacement memory addresses, and executable instructions to trigger this issue.

LinPopUp version 1.2.0 is reported prone to this vulnerability. It is likely that other versions are affected as well.

97. Gadu-Gadu Multiple Remote Input Validation And Denial Of Ser...
BugTraq ID: 11998
Remote: Yes
Date Published: Dec 17 2004
Relevant URL: http://www.securityfocus.com/bid/11998
Summary:
Multiple remote vulnerabilities reportedly affect Gadu-Gadu instant messenger. It supports the DCC (Direct Client Connection) protocol, facilitating the transfer of files and messages between users.

The input validation issue is an HTML injection vulnerability in the instant messaging system. It is worth noting that this issue, although not exactly the same, resembles closely the HTML injection issue outlined in BID 11899 (Gadu-Gadu Multiple Remote Vulnerabilities). The denial of service vulnerability is due to a bug in the image handling code of the affected application.

An attacker may leverage these issues to carry out HTML injection attacks, potentially stealing sensitive information, and to carry out denial of service attacks, denying legitimate users of access to the affected software.

98. YAMT ID3 Tag Sort Command Execution Vulnerability
BugTraq ID: 11999
Remote: Yes
Date Published: Dec 15 2004
Relevant URL: http://www.securityfocus.com/bid/11999
Summary:
YAMT (Yet Another MP3 Tool) is prone to a vulnerability that may allow attackers to execute arbitrary commands.  This issue is exposed when the program attempts to sort ID3 tags.  As this data may originate from an external or untrusted source, this issue is considered remote in nature.

Successful exploitation will allow an attacker to execute arbitrary commands when the software processes an MP3 that contains malicious ID3 tag data.  This will occur in the context of the user running the application.

99. O3Read HTML Parser Buffer Overflow Vulnerability
BugTraq ID: 12000
Remote: Yes
Date Published: Dec 17 2004
Relevant URL: http://www.securityfocus.com/bid/12000
Summary:
o3read is prone to a buffer overflow vulnerability.  This issue is exposed when the program parses HTML content during file format conversion.  This issue is considered to be remote in nature since it is possible that files may originate from an external or untrusted source.

Successful exploitation will result in code execution with the privileges of the user running the application.

100. Symantec Brightmail Multiple Remote Denial of Service Vulner...
BugTraq ID: 12001
Remote: Yes
Date Published: Dec 17 2004
Relevant URL: http://www.securityfocus.com/bid/12001
Summary:
Brightmail is reported prone to multiple remote denial of service vulnerabilities.  These issues may allow an attacker to crash the application through malicious email messages.

Brightmail 6.0.1 is reported prone to these vulnerabilities.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Report: DHS cyber security lagging
By: Kevin Poulsen

Inspectors find weak passwords, buffer overflows and mystery modems at the Department of Homeland Security.
http://www.securityfocus.com/news/10148

2. Long prison term for Lowe's wi-fi hacker
By: Kevin Poulsen

A 21-year-old Michigan man who tried to steal credit card numbers from a national hardware store chain is sentenced to nine years in federal prison.
http://www.securityfocus.com/news/10138

3. DirecTV hacker sentenced to seven years
By: Kevin Poulsen

A Canadian man arrested in the U.S. was allegedly responsible for putting 68,000 hacked smart cards on the street.

http://www.securityfocus.com/news/10103

4. Popular BitTorrent site shuts down after flurry of suits
By: Peter Svensson, The Associated Press

http://www.securityfocus.com/news/10166

5. NASA hacker jailed for six months
By: John Leyden, The Register

A US man has been jailed for six months for a 2001 attack on the web systems of space agency NASA which cost $200,000 to fix.
http://www.securityfocus.com/news/10164

6. US ISP wins $1bn damages from spammers
By: Drew Cullen, The Register

A small US ISP has been awarded damages of $1bn against three spammers by an Iowa judge.
http://www.securityfocus.com/news/10163

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Colasoft Capsa 4.05
By: Roy Luo
Relevant URL: http://www.colasoft.com/
Platforms: Windows 2000, Windows 95/98, Windows XP
Summary: 

Capsa is a powerful but easy to use network monitor and analyzer designed for packet decoding and network diagnosis. With the abilities of real time monitoring and data analyzing, you can capture and decode network traffic transmitted over local host and local network. Capsa has Packet Analysis Module and three advanced analysis modules: Email Analysis Module, Web Analysis Module and Transaction Analysis Module.

2. Attack Tool Kit (ATK) 3.0
By: Marc Ruef
Relevant URL: http://www.computec.ch/projekte/atk/
Platforms: Windows 2000, Windows 95/98, Windows NT, Windows XP
Summary: 

The Attack Tool Kit (ATK) is an open-source utility to realize penetration tests and enhance security audits. The most important changes in ATK 3.0 are the introduction of a dedicated exploiting routine and the Plugin AutoUpdate (over HTTP).

3. One-Time Password Generator 1.0
By: Marcin Simonides
Relevant URL: http://marcin.studio4plus.com/en/otpgen/
Platforms: Java
Summary: 

A One-Time Password Generator for Java-enabled mobile phones. The interface has been designed to minimize the number of necessary keypresses.

4. tenshi 0.3.2
By: Andrea Barisani
Relevant URL: http://tenshi.gentoo.org/
Platforms: Perl (any system supporting perl)
Summary: 

tenshi is a log monitoring program, designed to watch a log file for lines matching user defined regular expressions and report on the matches. The regular expressions are assigned to queues which have an alert interval and a list of mail recipients.

Queues can be set to send a notification as soon as there is a log line assigned to it, or to send periodic reports.

5. pasmal 1.5
By: James Meehan
Relevant URL: http://www.elitelabs.org/
Platforms: Linux
Summary: 

pasmal 1.5 is a port knocking authentification system using simple or encrypted tcp/udp/icmp packets. pasmal can be used with iptables/ipchains (firewall purposes) or any other program (remote shell, reboot, etc)It is packaged with a php web admin, a command line client pasmal.client, start/stop rc.d scripts.pasmal 1.5 also feature an intrusion/attempts detection system due to its sniffers capabilities, running with syslogd and custom log files.

6. AppRecon 1.0.0
By: Patrik Karlsson
Relevant URL: http://www.cqure.net/tools.jsp?id=21
Platforms: Java
Summary: 

AppRecon is small java tool that tries to identify applications by sending appropriate discovery broadcast packets.

It currently finds;

   - PcDUO
   - SQL Server
   - PCAnywhere

Todo
----
   - Add more discovery plugins

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Manager, Information Security, Ft. Lauderda... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384685

2. [SJ-JOB] Sales Representative, Los Angeles, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384684

3. [SJ-JOB] Sales Representative, Munich, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384671

4. [SJ-JOB] Sales Engineer, Munich, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384670

5. [SJ-JOB] Security Consultant, North Bergen, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384669

6. [SJ-JOB] Sales Representative, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384657

7. [SJ-JOB] Auditor, Falls Church/Vienna, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384609

8. [SJ-JOB] Security System Administrator, Milwaukee, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384570

9. [SJ-JOB] Sr. Security Analyst, Evansville, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384569

10. [SJ-JOB] Security Product Marketing Manager, Bay Are... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384567

11. [SJ-JOB] Developer, San Diego, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384566

12. [SJ-JOB] Channel / Business Development, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384565

13. [SJ-JOB] Sr. Product Manager, Alexandria, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384563

14. [SJ-JOB] Security Consultant, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384562

15. [SJ-JOB] Security Product Manager, Santa Clara, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384559

16. [SJ-JOB] Security Consultant, Evansville, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384558

17. [SJ-JOB] Security Consultant, Columbia, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384555

18. [SJ-JOB] VP / Dir / Mgr engineering, New York metro ... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384411

19. [SJ-JOB] Security Engineer, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384408

20. [SJ-JOB] Sales Engineer, New York/New Jersey or Bost... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384407

21. [SJ-JOB] Security System Administrator, Arlington, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384406

22. [SJ-JOB] Developer, Arlington, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384404

23. [SJ-JOB] Security Engineer, Fremont, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/384345

VI. INCIDENTS LIST SUMMARY
--------------------------
1. SSH scans... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/385057

2. [incidents] SSH scans... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/384980

3. SSH scans... another possible solution (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/384950

4. Strange command histories in hacked shell server (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/384934

5. PHP injection attempt from 200.222.244.154 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/384851

6. IIS web server hacked..any tips? (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/384837

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Exploiting network services question (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/385067

2. HyperTerminal - Buffer Overflow In .ht File (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/384709

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. Securty Audit Correlating (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385085

2. Subdomain security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385079

3. services running in windows domain (winXP clients) (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/385068

4. iisadmpwd/UPN (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384824

5. SV: services running in windows domain (winXP client... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384649

6. Corrupt Certificate information on local system (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384610

7. SecurityFocus Microsoft Newsletter #219 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384592

8. Group policy help needed!!! (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384490

9. RE : Secondary Storage Device Policy (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384448

10. Secondary Storage Device Policy (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/384443

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2004-12-14 to 2004-12-21.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. *nix data wipe tools (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/384971

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------