SecurityFocus Newsletter #285

Peter Laborge <[email protected]> 25 Jan 2005 22:56:34 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #285
------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------
I. FRONT AND CENTER
     1. Unintended Consequences
     2. Blind Buffer Overflows In ISAPI Extensions
II. BUGTRAQ SUMMARY
     1. AWStats Multiple Unspecified Remote Input Validation Vulnera...
     2. IBM z/OS, OS/390, And z/VM Multiple Unspecified Vulnerabilit...
     3. SparkleBlog Multiple Input Validation Vulnerabilities
     4. Gatos xatitv Unspecified Buffer Overflow Vulnerability
     5. PlayMidi Local Buffer Overflow Vulnerability
     6. MySQL Database MySQLAccess Local Insecure Temporary File Cre...
     7. NetGear FVS318 ProSafe VPN Firewall Switch Multiple Vulnerab...
     8. Minis Remote Directory Traversal Vulnerability
     9. INCA nProtect Gameguard Unprivileged Arbitrary Read/Write Ac...
     10. Halocon Remote Denial of Service Vulnerability
     11. Research In Motion Blackberry Enterprise Server Mobile Data ...
     12. Mnet Soft Factory NodeManager Professional SNMP Trap Handlin...
     13. Netegrity SiteMinder HTML Page Injection Vulnerability
     14. Novell GroupWise WebAccess Remote Authentication Bypass Vuln...
     15. Gallery Multiple Unspecified Input Validation Vulnerabilitie...
     16. ImageMagick Photoshop Document Parsing Remote Client-Side Bu...
     17. SafeHTML HTML Entity Bypass Vulnerability
     18. PHP Gift Registry Multiple SQL Injection Vulnerabilities
     19. ITA Forum Multiple SQL Injection Vulnerabilities
     20. Kazaa Sig2Dat Protocol Multiple Remote Vulnerabilities
     21. Gallery Multiple Remote Vulnerabilities
     22. GNU Queue Multiple Unspecified Buffer Overflow Vulnerabiliti...
     23. Microsoft Internet Explorer Remote Information Disclosure Vu...
     24. Mac OS X Kernel searchfs() Integer Overflow Vulnerability
     25. Oracle Database Multiple Unspecified Vulnerabilities
     26. Apple Mac OS X At Utility Local Information Disclosure Vulne...
     27. AWStats Remote Command Execution Vulnerability
     28. VBulletin Init.PHP Unspecified Remote Vulnerability
     29. SCO UnixWare Unspecified CHRoot Breakout Vulnerability
     30. Oracle Database Multiple Vulnerabilities
     31. XPDF MAKEFILEKEY2 Function Remote Buffer Overflow Vulnerabil...
     32. CMSimple Multiple Remote Input Validation Vulnerabilities
     33. Siteman User Database Privilege Escalation Vulnerability
     34. MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilit...
     35. ExBB Nested BBcode Remote Script Injection Vulnerability
     36. Cisco IOS Skinny Call Control Protocol Handler Remote Denial...
     37. Apache Utilities Insecure Temporary File Creation Vulnerabil...
     38. Linux Kernel Audit Subsystem Local Denial Of Service Vulnera...
     39. Novell GroupWise WebAccess Multiple Cross-Site Scripting Vul...
     40. RealNetworks RealOne Player And RealPlayer ShowPreferences A...
     41. Konversation IRC Client Multiple Remote Vulnerabilities
     42. MySQL MaxDB WebAgent Remote Denial of Service Vulnerabilitie...
     43. Darwin Kernel Mach File Parsing Local Integer Overflow Vulne...
     44. RealNetworks RealOne Player And RealPlayer Multiple Potentia...
     45. xtrlock Unspecified Local Buffer Overflow Vulnerability
     46. Sun Java Plug-in Multiple Applet Vulnerabilities
     47. GForge Multiple Information Disclosure Vulnerabilities
     48. JSBoard Local File Include File Disclosure Vulnerability
     49. SWORD Diatheke Script Arbitrary Command Execution Vulnerabil...
     50. Fkey Remote Arbitrary File Disclosure Vulnerability
     51. 3Com OfficeConnect Wireless 11g Access Point 3CRWE454G72 Inf...
     52. Sybari AntiGen For Lotus Domino Multiple Remote Vulnerabilit...
     53. Squid Proxy NTLM Fakeauth_Auth Memory Leak Remote Denial Of ...
     54. Advanced Linux Sound Architecture Library Stack Protection D...
     55. Multiple Ethereal Unspecified Dissector Vulnerabilities
     56. Ghostscript Multiple Local Insecure Temporary File Creation ...
     57. TikiWiki Multiple Remote Unspecified PHP Script Code Executi...
     58. GNU Enscript Multiple Vulnerabilities
     59. Linux Kernel Unspecified Local NFS I/O Denial of Service Vul...
     60. Netscape Navigator Infinite Array Sort Denial of Service Vul...
     61. DivX Player Skin File Directory Traversal Vulnerability
III. SECURITYFOCUS NEWS ARTICLES
     1. FBI retires its Carnivore
     2. Hacker penetrates T-Mobile systems
     3. Netizens eye Web-enabled surveillance cams
     4. FBI chides Hotmail and Yahoo! for sidestepping UK laws
     5. MS AntiSpyware bites BitDefender
     6. Malware poses as CNN news alert
IV. SECURITYFOCUS TOP 6 TOOLS
     1. Firestarter 1.0.0
     2. Network Equipment Performance Monitor 2.2
     3. Etherchange v1.0
     4. BitDefender for qmail v1.5.5-2 
     5. Bilbo 0.11
     6. IPFront 1.0
V. SECURITYJOBS LIST SUMMARY
     1. [SJ-JOB] Sr. Security Engineer, Redwood City, US (Thread)
     2. [SJ-JOB] Certification & Accreditation Engineer, Arl... (Thread)
     3. [SJ-JOB] Sr. Product Manager, Redwood City, US (Thread)
     4. [SJ-JOB] Developer, Redwood City, US (Thread)
     5. [SJ-JOB] Technology Risk Consultant, London, GB (Thread)
     6. [SJ-JOB] Security Researcher, Palo Alto, US (Thread)
     7. [SJ-JOB] Information Assurance Engineer, Annapolis J... (Thread)
     8. [SJ-JOB] Auditor, St. Louis, US (Thread)
     9. [SJ-JOB] Security Consultant, Houston, US (Thread)
     10. [SJ-JOB] MOD CLAS Consultant, London, GB (Thread)
     11. [SJ-JOB] Security Consultant, Roseville (5 mins from... (Thread)
     12. [SJ-JOB] Manager, Information Security, London, GB (Thread)
     13. [SJ-JOB] Account Manager, New York City, US (Thread)
     14. [SJ-JOB] Information Assurance Engineer, New Orleans... (Thread)
     15. [SJ-JOB] Quality Assurance, Redwood City, US (Thread)
     16. [SJ-JOB] Chief Security Strategist, Austin, US (Thread)
     17. [SJ-JOB] Auditor, Redwood City, US (Thread)
     18. [SJ-JOB] Technical Support Engineer, Slough, GB (Thread)
     19. [SJ-JOB] Auditor, Kansas City, US (Thread)
     20. [SJ-JOB] Certification & Accreditation Engineer, Fai... (Thread)
     21. [SJ-JOB] Sales Representative, New York, US (Thread)
     22. [SJ-JOB] Security Consultant, NYC, US (Thread)
     23. [SJ-JOB] Database Security Engineer, Princeton, US (Thread)
     24. [SJ-JOB] Security Consultant, Washington DC / Maryla... (Thread)
     25. [SJ-JOB] Security Engineer, St Louis, US (Thread)
     26. [SJ-JOB] Security Consultant, Leeds, Manchester, Lon... (Thread)
     27. [SJ-JOB] Manager, Information Security, Leeds, Edinb... (Thread)
     28. [SJ-JOB] Auditor, London, GB (Thread)
     29. [SJ-JOB] Security Architect, Fairfax, US (Thread)
     30. [SJ-JOB] Sr. Security Engineer, Atlanta, US (Thread)
     31. [SJ-JOB] Security Consultant, London, GB (Thread)
     32. [SJ-JOB] Account Manager, Fremont, US (Thread)
     33. [SJ-JOB] Developer, Sterling, US (Thread)
     34. [SJ-JOB] Security Engineer, Annapolis Junction, US (Thread)
     35. [SJ-JOB] Security Engineer, Fremont, DE (Thread)
     36. [SJ-JOB] Security Consultant, Boston, US (Thread)
     37. [SJ-JOB] Security Consultant, New York, US (Thread)
     38. [SJ-JOB] Manager, Information Security, New York, US (Thread)
     39. [SJ-JOB] CHECK Team Leader, Various, GB (Thread)
     40. [SJ-JOB] Developer, Dulles, US (Thread)
     41. [SJ-JOB] Regional Channel Manager, Flexible/Home Bas... (Thread)
     42. [SJ-JOB] Information Assurance Analyst, Mississauga,... (Thread)
     43. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
     44. [SJ-JOB] Sales Representative, San Mateo, US (Thread)
     45. [SJ-JOB] Auditor, New York (Tri-State area), US (Thread)
     46. [SJ-JOB] Security Engineer, Baltimore, US (Thread)
     47. [SJ-JOB] Quality Assurance, Redmond, US (Thread)
     48. [SJ-JOB] Security Engineer, Fremont, US (Thread)
     49. [SJ-JOB] CSO, London, GB (Thread)
     50. [SJ-JOB] Application Security Engineer, South San Fr... (Thread)
     51. [SJ-JOB] Security Consultant, South San Francisco, U... (Thread)
     52. [SJ-JOB] Security Consultant, Kansas City, US (Thread)
     53. [SJ-JOB] Sr. Security Analyst, Leeds, GB (Thread)
     54. [SJ-JOB] Security Architect, Baghdad, IQ (Thread)
     55. [SJ-JOB] Sr. Security Engineer, Baghdad, IR (Thread)
     56. [SJ-JOB] Information Assurance Analyst, Kansas City,... (Thread)
     57. [SJ-JOB] Developer, Cherry Hill, US (Thread)
     58. [SJ-JOB] Auditor, New York, US (Thread)
     59. [SJ-JOB] Instructor, Kansas City, US (Thread)
     60. [SJ-JOB] Chief Security Strategist, Toronto, CA (Thread)
VI. INCIDENTS LIST SUMMARY
     1. SQL injection ... another attack (Thread)
VII. VULN-DEV RESEARCH LIST SUMMARY
     1. Security of osCommerce (Thread)
VIII. MICROSOFT FOCUS LIST SUMMARY
     1. AW: IIS6 on W2k3 DCs (Thread)
     2. Dhcp security (Thread)
     3. IIS6 on W2k3 DCs (Thread)
     4. [Maybe Spam] Dhcp security (Thread)
     5. PGP and Outlook (Thread)
     6. SecurityFocus Microsoft Newsletter #224 (Thread)
     7. local admin vs group policy and apps... (Thread)
IX. SUN FOCUS LIST SUMMARY
     NO NEW POSTS FOR THE WEEK 2005-01-18 to 2005-01-25.
X. LINUX FOCUS LIST SUMMARY
     1. Encrypted Filesystems (Thread)
XI. UNSUBSCRIBE INSTRUCTIONS
XII. SPONSOR INFORMATION

I. FRONT AND CENTER
-------------------
1. Unintended Consequences
By Scott Granneman

The law of unintended consequences shows us how many innocent innovations
like email, anti-virus and DRM can become something far worse than the
inventors had ever imagined.

http://www.securityfocus.com/columnists/293


2. Blind Buffer Overflows In ISAPI Extensions
By Isaac Dawson

This paper will outline the risks ISAPI Extensions pose and how they can be
exploited by third parties without any binary exposure or knowledge using
blind stack overflows. This method can enable remote code execution in
proprietary and third party applications.

http://www.securityfocus.com/infocus/1819

II. BUGTRAQ SUMMARY
-------------------
1. AWStats Multiple Unspecified Remote Input Validation Vulnera...
BugTraq ID: 12270
Remote: Yes
Date Published: Jan 15 2005
Relevant URL: http://www.securityfocus.com/bid/12270
Summary:
Multiple unspecified remote input validation vulnerabilities affect AWStats.  These issues are due to a failure of the application to perform proper validation on user-supplied input prior to using it to carry out some critical function.

Although unconfirmed an attacker may leverage these issues to execute commands and disclose sensitive information with the privileges of the underlying Web server.

2. IBM z/OS, OS/390, And z/VM Multiple Unspecified Vulnerabilit...
BugTraq ID: 12271
Remote: Unknown
Date Published: Jan 15 2005
Relevant URL: http://www.securityfocus.com/bid/12271
Summary:
IBM z/OS, OS/390, and z/VM are operating systems developed by IBM.  z/OS is an enterprise operating system designed to facilitate the development and implementation of Internet and Java based applications.  OS/390 is an operating system designed to be implemented on mainframe computers; the OS/390 project has been ended, replaced with z/OS. z/VM is an operating system designed to facilitate extensive testing and production for enterprise business applications.

Multiple, unspecified vulnerabilities affect z/OS, z/VM, and OS/390.  The underlying cause of these issues is unknown.  

The potential impacts of these issues are currently unknown; it is impossible to speculate as very little information is available. This BID will be updated as more information is released.

3. SparkleBlog Multiple Input Validation Vulnerabilities
BugTraq ID: 12272
Remote: Yes
Date Published: Jan 15 2005
Relevant URL: http://www.securityfocus.com/bid/12272
Summary:
Multiple input validation vulnerabilities reportedly affect SparkleBlog.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical actions.

The first issue is a cross-site scripting issue and the second issue is an SQL injection issue.

An attacker may leverage these issues to carry out cross-site scripting and SQL injection attacks against the affected application.  This may result in the theft of authentication credentials, destruction or disclosure of sensitive data, and potentially other attacks.

4. Gatos xatitv Unspecified Buffer Overflow Vulnerability
BugTraq ID: 12273
Remote: Unknown
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12273
Summary:
An unspecified buffer overflow vulnerability affects the gatos xatitv utility, which is setuid by default. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

The details currently available surrounding this issue are insufficient to provide and accurate technical description.  It is not known if this issue is triggered by an excessively long command line argument, or by some configuration file parameter, or by some multimedia file parameter.  

This BID will be updated as more details are released.

An attacker may leverage this issue to execute arbitrary instructions with the privileges of the superuser.  This may potentially lead to privilege escalation or unauthorized access.

5. PlayMidi Local Buffer Overflow Vulnerability
BugTraq ID: 12274
Remote: No
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12274
Summary:
A local buffer overflow vulnerability affects Playmidi.  This issue is due to a failure of the an unspecified setuid utility that is packaged with the Playmidi suite to properly validate the length of user-supplied strings prior to copying them into static process buffers.

This BID will be updated as more information becomes available.

A local attacker may leverage this issue to execute arbitrary instructions with the privileges of the superuser.  This may facilitate privilege escalation and potentially unauthorized access.

6. MySQL Database MySQLAccess Local Insecure Temporary File Cre...
BugTraq ID: 12277
Remote: No
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12277
Summary:
A local insecure temporary file creation vulnerability affects the MySQL Database.  This issue is due to a failure of a script bundled with the application to securely create temporary files in globally accessible locations.

An attacker may leverage this issue to corrupt arbitrary files with the privileges of the user that activates the vulnerable script.

7. NetGear FVS318 ProSafe VPN Firewall Switch Multiple Vulnerab...
BugTraq ID: 12278
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12278
Summary:
NetGear FVS318 is reported prone to multiple vulnerabilities.  These issues result from insufficient sanitization of user-supplied data and may allow an attacker to bypass URI filters and carry out cross-site scripting attacks.

The following issues were identified:

It is reported that an attacker can bypass URI filters of the device.

The URI filter log viewer is reported prone to a cross-site scripting vulnerability. 

The research report specified that FVS318 devices with firmware 2.4 are vulnerable to these issues.  FVS318 and FVS318v2 are shipped with firmware 2.4, however, it is possible that FVS318v3 and other firmware versions are affected as well.  This BID will be updated when more information about affected packages is available.

8. Minis Remote Directory Traversal Vulnerability
BugTraq ID: 12279
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12279
Summary:
Minis is reportedly susceptible to a remote directory traversal vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied input.

A malicious user may issue a request containing directory traversal strings such as '../' to possibly view files outside the server root directory. 

Minis 0.2.1 is affected by this issue.  It is possible that prior versions are vulnerable as well.

9. INCA nProtect Gameguard Unprivileged Arbitrary Read/Write Ac...
BugTraq ID: 12280
Remote: No
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12280
Summary:
It is reported that the INCA nProtect Gameguard kernel driver provides functionality that may impact the security model of a Windows NT/2000/XP computer. Reports indicate the affected kernel driver provides functionality to modify the I/O permission mask of the process that invokes the affected driver to allow for unrestricted I/O operations in unprivileged user-mode.

An unprivileged attacker that has obtainined local interactive access to a computer that is running the vulnerable kernel mode driver may exploit this to make arbitrary read and write operations to a specified device.

10. Halocon Remote Denial of Service Vulnerability
BugTraq ID: 12281
Remote: Yes
Date Published: Jan 16 2005
Relevant URL: http://www.securityfocus.com/bid/12281
Summary:
Halocon is reported prone to a remote denial of service vulnerability.  

It is reported that a vulnerable server may be crashed by sending an empty UDP packet.

Halocon 2.0.0.81 is reported prone to this issue.

11. Research In Motion Blackberry Enterprise Server Mobile Data ...
BugTraq ID: 12282
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12282
Summary:
Blackberry Enterprise Server is reportedly affected by a remote denial of service vulnerability.  This issue is due to an error while processing WML (Wireless Markup Language) pages in the 'Mobile Data Service'.  Exploitation of this issue would cause a 100% processor utilization, thus resulting in a denial of service.

12. Mnet Soft Factory NodeManager Professional SNMP Trap Handlin...
BugTraq ID: 12283
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12283
Summary:
Mnet Soft Factory NodeManager Professional is reported prone to a remote buffer overflow vulnerability. The issue exists due to a lack of sufficient boundary checks performed on SNMP LinkDown-Trap variable-bindings field data.

A remote attacker may exploit this vulnerability to execute arbitrary code in the context of the user that is running the affected software.

13. Netegrity SiteMinder HTML Page Injection Vulnerability
BugTraq ID: 12284
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12284
Summary:
Netegrity SiteMinder is reported prone to a vulnerability that may allow an attacker to inject arbitrary HTML pages that may be rendered in a user's browser through a URI link.  This issue originates in the 'smpwservicescgi.exe' script and can facilitate arbitrary script execution and other attacks such as phishing.

An attacker can manipulate URI parameters to redirect a user to a potentially malicious Web page after authentication to the server.

All versions of SiteMinder are considered vulnerable at the moment.

14. Novell GroupWise WebAccess Remote Authentication Bypass Vuln...
BugTraq ID: 12285
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12285
Summary:
A remote authentication bypass vulnerability reportedly affects Novell GroupWise WebAccess.  This issue is due to a failure of the application to properly handle access validation functionality.

The access gained through this issue grants minimal privileges; loading and storing data is not possible and services such as email or address books.  This issue may be leveraged to exploit other latent vulnerabilities that require authentication.

An attacker may leverage this issue to bypass the required authentication for the affected application.

15. Gallery Multiple Unspecified Input Validation Vulnerabilitie...
BugTraq ID: 12286
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12286
Summary:
Gallery is reported prone to multiple unspecified remote input validation vulnerabilities. It is reported that multiple instances of insufficient sanitization performed on Gallery variables were fixed; reports indicate that these issues may be exploited to disclose Gallery passwords contained in the Gallery database.

16. ImageMagick Photoshop Document Parsing Remote Client-Side Bu...
BugTraq ID: 12287
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12287
Summary:
A client-side buffer overflow vulnerability affects the Photoshop document (PSD) parsing functionality of ImageMagick. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue remotely by sending a malicious file through email or some other means to an unsuspecting user and enticing them to process it with the affected application.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

17. SafeHTML HTML Entity Bypass Vulnerability
BugTraq ID: 12288
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12288
Summary:
It is reported that SafeHTML does not filter HTML entities in a proper manner.  Failure to filter HTML content can result in the exploitation of various latent vulnerabilities in Web based applications.  A successful attack may facilitate HTML injection or cross-site scripting type issues.

SafeHTML 1.2.0 and prior versions are affected by this issue.

18. PHP Gift Registry Multiple SQL Injection Vulnerabilities
BugTraq ID: 12289
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12289
Summary:
PHP Gift Registry is reportedly affected by multiple SQL injection vulnerabilities.  These issues are due to the application failing to properly sanitize user-supplied input before being used in SQL queries.

It is reported that successful exploitation could result in a compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

19. ITA Forum Multiple SQL Injection Vulnerabilities
BugTraq ID: 12290
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12290
Summary:
ITA Forum is reportedly affected by multiple SQL injection vulnerabilities.  These issues are due to the application failing ro properly sanitize user-supplied input before being used in SQL queries.

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

These vulnerabilities reportedly affect ITA Forum 1.49; earlier versions may also be affected.

20. Kazaa Sig2Dat Protocol Multiple Remote Vulnerabilities
BugTraq ID: 12291
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12291
Summary:
Multiple remote vulnerabilities reportedly affect KaZaA's Sig2Dat protocol functionality.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in critical actions.

An attacker may leverage these issues to cause the affected application to crash, denying service to legitimate users, and to create files in arbitrary directories that are readable to the affected application.

21. Gallery Multiple Remote Vulnerabilities
BugTraq ID: 12292
Remote: Yes
Date Published: Jan 17 2005
Relevant URL: http://www.securityfocus.com/bid/12292
Summary:
Gallery is reported prone to multiple remote vulnerabilities. The following issues are reported:

It is reported that multiple cross-site scripting issues exist in Gallery. These vulnerabilities exist because user-supplied input is not sufficiently sanitized before this input is included in dynamically rendered HTML pages that are returned to a user. 

These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected Web site and may allow for theft of cookie-based authentication credentials or other attacks. 

An information disclosure vulnerability is reported to affect Gallery version 2.0 Alpha. It is reported that under some circumstances Gallery may return an error message that contains the installation path of the vulnerable Gallery installation.

A remote attacker may exploit this vulnerability to disclose information about the layout of the filesystem on a vulnerable computer. Information harvested in this manner may then be used to aid in further attacks that are launched against a vulnerable computer.

22. GNU Queue Multiple Unspecified Buffer Overflow Vulnerabiliti...
BugTraq ID: 12293
Remote: Unknown
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12293
Summary:
Multiple unspecified buffer overflow vulnerabilities affect GNU Queue. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may leverage these issues to execute instructions with the privileges of the affected application. Although unconfirmed this may facilitate unauthorized access or privilege escalation.

This BID will be updated as more information becomes available.

23. Microsoft Internet Explorer Remote Information Disclosure Vu...
BugTraq ID: 12294
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12294
Summary:
A remote information disclosure vulnerability affects Microsoft Internet Explorer.  This issue is due to a failure of the application to properly secure scripts that reside on a local computer.

An attacker may leverage this issue to identify any scripts that may reside on an unsuspecting user's computer. Information disclosed in this way may lead to further attacks against affected computers.

Any script access that occurs will take place in the context of the unsuspecting user that views the malicious page.

24. Mac OS X Kernel searchfs() Integer Overflow Vulnerability
BugTraq ID: 12295
Remote: No
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12295
Summary:
Mac OS X kernel is reported prone to a local integer overflow vulnerability. The issue occurs in the searchfs() code.

The vulnerability exists due to an error in calculating size arguments derived from user-controlled integer values, which are then used in a user-land to kernel memory copy operation. 

The issue may be leveraged to corrupt kernel memory and ultimately execute arbitrary code with ring-0 privileges. The issue may also be exploited to trigger a denial of service condition from a kernel panic.

25. Oracle Database Multiple Unspecified Vulnerabilities
BugTraq ID: 12296
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12296
Summary:
It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities.

The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue.

It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service.

NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.

26. Apple Mac OS X At Utility Local Information Disclosure Vulne...
BugTraq ID: 12297
Remote: No
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12297
Summary:
A local information disclosure issue affects the 'at' utility of Apple Mac OS X.  This issue is due to a failure of the application to properly implement access controls on job schedule files.

An attacker may leverage this issue to read arbitrary files on an affected computer.  Information revealed in this way may lead to further attacks.

27. AWStats Remote Command Execution Vulnerability
BugTraq ID: 12298
Remote: Yes
Date Published: Jan 15 2005
Relevant URL: http://www.securityfocus.com/bid/12298
Summary:
AWStats is reported prone to a remote arbitrary command execution vulnerability.  This issue presents itself due to insufficient sanitization of user-supplied data.

An attacker can prefix arbitrary commands with the '|' character and have them executed in the context of the server through a URI parameter.

This issue was originally specified in BID 12270 (AWStats Multiple Unspecified Remote Input Validation Vulnerabilities).  Due to the availability of further details, it is being assigned a new BID.

28. VBulletin Init.PHP Unspecified Remote Vulnerability
BugTraq ID: 12299
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12299
Summary:
VBulletin is reported prone to an unspecified vulnerability that presents itself in the 'includes/init.php' script.

It is reported that this vulnerability may be exploited to compromise an affected VBulletin installation; this compromise may include information disclosure.

This BID will be updated, as further information regarding this vulnerability is made available.

29. SCO UnixWare Unspecified CHRoot Breakout Vulnerability
BugTraq ID: 12300
Remote: No
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12300
Summary:
SCO UnixWare is reported prone to an unspecified chroot breaking vulnerability.

An attacker that has local interactive access to a computer that is running a vulnerable version of UnixWare may exploit this vulnerability to break out of a chroot prison that they reside in.

Specific details in regards to this vulnerability are not currently available. This BID will be updated as soon as further information is made available.

30. Oracle Database Multiple Vulnerabilities
BugTraq ID: 12301
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12301
Summary:
Oracle Database 10g, Oracle9i Database Server, Oracle8i Database Server, Oracle8 Database, Oracle Collaboration Suite, Oracle Application Server, and Oracle E-Business Suite are reported prone to multiple vulnerabilities.

Oracle has released a Critical Patch Update to address these issues in various supported applications.  The following specific issues were identified:

 - A networking component of Oracle8 Database is affected by a vulnerability.

 - The LOB Access component of Oracle8i Database Server is reported prone to an information disclosure vulnerability.

 - The Spatial component of Oracle8i Database Server is reported prone to a vulnerability.

 - The UTL_FILE component of Oracle9i Database Server Release 2 is reported prone to a vulnerability.

 - A Diagnostic component of Oracle8i Database Server is reported prone to a vulnerability.

 - The XDB component of Oracle Database 10g and Oracle9i Database Server Release 2 is reported prone to multiple vulnerabilities.

 - The Dataguard component of Oracle Database 10g is reported prone to a vulnerability.

 - The Log Miner component of Oracle9i Database Server Release 2 is reported prone to a vulnerability.

 - The OLAP component of Oracle9i Database Server Release 2 is reported prone to a vulnerability.

 - The Data Mining component of Oracle Database 10g is reported prone to a vulnerability.

 - The Advanced Queuing component of Oracle Database 10g is reported prone to a vulnerability.

 - The Change Data Capture component of Oracle Database 10g is reported prone to multiple vulnerabilities.

 - The Database Core component of Oracle Database 10g is reported prone to a vulnerability.

 - The OHS component of Oracle Database 10g is reported prone to a vulnerability.

 - The Report Server component of Oracle Application Server is reported prone to a vulnerability.

 - The Forms component of Oracle Application Server is reported prone to a vulnerability.

 - The mod_plsql component of Oracle Application Server is reported prone to a vulnerability.

 - The Calendar component of Oracle Collaboration Suite is reported prone to a vulnerability.

 - The Oracle E-Business Suite is reported prone to multiple vulnerabilities.

The Oracle advisory only addresses those products that are supported. It is likely that earlier versions of the releases may also be affected.  This Critical Patch Update also includes Oracle Security Alert #68 fixes that are specified in BID 10871 (Oracle Multiple Unspecified Vulnerabilities), BID 11120 (Oracle Database 9i SQL Command Buffer Overflow Vulnerability), BID 11099 (Oracle Database Server ctxsys.driload Access Validation Vulnerability), BID 11100 (Oracle Database Server dbms_system.ksdwrt Remote Buffer Overflow Vulnerability), and BID 11091 (Oracle 10g Database DBMS_SCHEDULER Remote Command Execution Vulnerability).  

It is possible that other BIDs such as BID 12296 (Oracle Database Multiple Unspecified Vulnerabilities) are related to these vulnerabilities as well.

This BID will be divided and updated into separate BIDs when more information is available.

31. XPDF MAKEFILEKEY2 Function Remote Buffer Overflow Vulnerabil...
BugTraq ID: 12302
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12302
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data in to process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer. 

It is reported that this issue presents itself in the 'Decrypt::makeFileKey2' function residing in the 'xpdf/Decrypt.cc' file.

This issue is reported to affect xpdf 3.00, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to this issue as well.

32. CMSimple Multiple Remote Input Validation Vulnerabilities
BugTraq ID: 12303
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12303
Summary:
Multiple input validation vulnerabilities affect CMSimple.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.

The first issue is an HTML injection vulnerability in the guestbook functionality of the application.  The second issue is a cross-site script vulnerability in the search functionality of the application. 

An attacker may leverage these issues to have arbitrary script code executed in the context of the vulnerable Web site.  This will facilitate theft of cookie based authentication credentials as well as other attacks.

33. Siteman User Database Privilege Escalation Vulnerability
BugTraq ID: 12304
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12304
Summary:
Siteman is reported prone to a vulnerability that may allow users to gain elevated privileges.  This issue results from insufficient sanitization of user-supplied data.

Apparently, an attacker can supply additional lines to the stream used to write to the user database file through a URI parameter.  This can allow the attacker to corrupt the user database file and potentially gain administrative privileges to the Siteman application.

Siteman 1.1.10 and prior versions are affected by this vulnerability.

34. MediaWiki Multiple Arbitrary PHP Code Execution Vulnerabilit...
BugTraq ID: 12305
Remote: Yes
Date Published: Jan 18 2005
Relevant URL: http://www.securityfocus.com/bid/12305
Summary:
MediaWiki is reported prone to multiple remote code execution vulnerabilities. These issues may allow an attacker gain unauthorized access to a vulnerable computer by executing arbitrary PHP code. 

Further details are not currently available, however, it is conjectured that this issue may allow for file include or arbitrary command execution type attacks.

MediaWiki versions 1.4 beta1 to 1.4 beta4 are affected by this issue.

35. ExBB Nested BBcode Remote Script Injection Vulnerability
BugTraq ID: 12306
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12306
Summary:
ExBB is reported prone to a script injection vulnerability. It is reported that nested BBCode is not sufficiently sanitized of malicious script content. 

Injected code may be rendered in the Web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting ExBB. 

ExBB 1.9.1 is reported vulnerable, however, other versions may be affected as well.

36. Cisco IOS Skinny Call Control Protocol Handler Remote Denial...
BugTraq ID: 12307
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12307
Summary:
Cisco IOS when configured for Cisco IOS Telephony Service (ITS), Cisco CallManager Express (CME), or Survivable Remote Site Telephony (SRST) services is reported prone to a remote denial of service vulnerability.

The issue is reported to exist in the Skinny Call Control Protocol (SCCP) handler. 

A remote attacker may exploit this vulnerability continuously to effectively deny network-based services to legitimate users.

37. Apache Utilities Insecure Temporary File Creation Vulnerabil...
BugTraq ID: 12308
Remote: No
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12308
Summary:
A local insecure temporary file creation vulnerability reportedly affects Apache Software Foundation Apache Utilities.  This issue is due to a failure of the affected utility to securely create temporary files in world writable locations.

An attacker may leverage this issue to corrupt, write to or create arbitrary files with the privileges of the user or process running the vulnerable script.

38. Linux Kernel Audit Subsystem Local Denial Of Service Vulnera...
BugTraq ID: 12309
Remote: No
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12309
Summary:
An unspecified local denial of service vulnerability is reported to affect the system call filtering code in the audit subsystem of the Linux kernel.

Originally, it was believed that this vulnerability was isolated to the kernel that is distributed with Red Hat Enterprise Linux. This is not the case and this BID is updated accordingly.

39. Novell GroupWise WebAccess Multiple Cross-Site Scripting Vul...
BugTraq ID: 12310
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12310
Summary:
Multiple cross-site scripting vulnerabilities reportedly affect Novell GroupWise WebAccess.  These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user.  This issue may allow for the theft of authentication credentials as well as other attacks.

40. RealNetworks RealOne Player And RealPlayer ShowPreferences A...
BugTraq ID: 12311
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12311
Summary:
RealOne Player and RealPlayer are affected by a buffer overflow vulnerability.  This issue may be exploited by a remote attacker to execute arbitrary code in the context of the software.

The application fails to perfrom proper boundary checks before copying the arguments of the 'ShowPreferences' action to a static buffer through a 'sprintf()' function call.

An attacker can design a malicious Web site or skin file and trigger an overflow condition in the application.  This issue may be leveraged to execute arbitrary code in the context of the user running the application.

It is likely that this issue is identical the vulnerability described in BID 11307 (RealNetworks RealOne Player And RealPlayer Unspecified Web Page Code Execution Vulnerability).  This cannot be confirmed at the moment, however, one of the BIDs will be retired, if it turns out that the BIDs represent the same issue.

41. Konversation IRC Client Multiple Remote Vulnerabilities
BugTraq ID: 12312
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12312
Summary:
Konversation is a freely available IRC client for KDE windows environments on Linux platforms.

Multiple remote vulnerabilities affect the Konversation IRC client.  These issues are due to input validation failures and design flaws.

The first issue is due to a failure of the application to filter various parameters from the IRC environment prior to including them in commands made to the underlying operating system.  The second issue affects the QuickButtons functionality of the vulnerable application. Finally a design error causes the quick connect dialogue to confuse a supplied nickname with a supplied password.

An attacker may leverage these issues to execute arbitrary shell and Konversation commands, potentially leading to denial of service attacks and system compromise.

42. MySQL MaxDB WebAgent Remote Denial of Service Vulnerabilitie...
BugTraq ID: 12313
Remote: Yes
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12313
Summary:
MaxDB WebAgent is reported prone to multiple remote denial of service vulnerabilities.  These issues arise as the application fails to handle exceptional conditions properly.

The following specific issues were identified:

The first vulnerability exists due to a NULL pointer dereference.

The second vulnerability arises when the application handles malformed HTTP headers.

MaxDB versions prior to 7.5.0.21 are likely to be vulnerable to these issues.  This issue has been confirmed in version 7.5.0.0.

43. Darwin Kernel Mach File Parsing Local Integer Overflow Vulne...
BugTraq ID: 12314
Remote: No
Date Published: Jan 19 2005
Relevant URL: http://www.securityfocus.com/bid/12314
Summary:
Reportedly a local integer overflow vulnerability affects the Darwin Kernel.  This issue is due to a failure of the affected to properly handle integer signedness.

An attacker may leverage this issue to cause the affected computer to crash, denying service to legitimate users.  It has been speculated that this issue may also be leverage to escalate privileges, although this is unconfirmed.

44. RealNetworks RealOne Player And RealPlayer Multiple Potentia...
BugTraq ID: 12315
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12315
Summary:
RealNetworks RealOne Player And RealPlayer are reported prone to multiple potential vulnerabilities.  These issues may allow an attacker to potentially execute arbitrary code or disclose the presence of files on a vulnerable computer.

The following specific issues were identified:

The first issue presents itself when the application processes Real Metadata Package files containing malformed tags.  The researchers responsible for discovering this issue have reported that this issue may not be exploitable and represents a potential threat.

The second issue may allow attacker to determine the existence of files on a vulnerable computer.  The validity of this issue is not confirmed at the moment is also considered a potential threat.

It is likely that this issues were originally released as unspecified vulnerabilities. This cannot be confirmed at the moment, however, one of the BIDs will be retired, if it turns out that the BIDs represent the same issues.

45. xtrlock Unspecified Local Buffer Overflow Vulnerability
BugTraq ID: 12316
Remote: No
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12316
Summary:
xtrlock is reported prone to an unspecified local buffer overflow vulnerability.  This issue exists due to insufficient boundary checks performed by the application when copying user-supplied data in to process buffers.

xtrlock is likely to be executed with superuser privileges, allowing the attacker to gain elevated privileges.

Due to a lack of information, further details cannot be provided at the moment.  This BID will be updated when more information is available.

46. Sun Java Plug-in Multiple Applet Vulnerabilities
BugTraq ID: 12317
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12317
Summary:
The Sun Java Plug-in is prone to multiple vulnerabilities.

The first issue can allow an untrusted applet to escalate its privileges to access resources with the privilege level of the user running the applet.

This issue only exists in Internet Explorer running on Windows.

The second issue allows an untrusted applet to interfere with another applet embedded in the same web page.

This issue exists in Java running on Windows, Solaris, and Linux.

47. GForge Multiple Information Disclosure Vulnerabilities
BugTraq ID: 12318
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12318
Summary:
GForge is reported prone to multiple input validation vulnerabilities that may be exploited to disclose directory listings outside of the designated CVS root directory. The vulnerabilites exist due to a lack of sufficient sanitization performed on user supplied URI parameters.

Information that is disclosed in this manner may be used to aid in further attacks that are launched against the target computer.

48. JSBoard Local File Include File Disclosure Vulnerability
BugTraq ID: 12319
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12319
Summary:
JSBoard is reported prone to an issue that may allow a remote attacker to view the contents of arbitrary Web server readable files on the local drive.

A successful attack allows an attacker to include and view any Web server readable file on the affected computer.

JSBoard version 2.0.9 and prior when running with PHP 'magic_quotes_gpc' disabled are reported prone to this vulnerability.

49. SWORD Diatheke Script Arbitrary Command Execution Vulnerabil...
BugTraq ID: 12320
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12320
Summary:
The Diatheke script is reported prone to an arbitrary command execution vulnerability.  This issue presents itself due to insufficient sanitization of user-supplied data.

This issue may allow an attacker to gain unauthorized access to a vulnerable computer by supplying arbitrary commands through unspecified parameters of URI links.

50. Fkey Remote Arbitrary File Disclosure Vulnerability
BugTraq ID: 12321
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12321
Summary:
fkey is reported prone to a remote arbitrary file disclosure vulnerability.  This issue can allow an attacker to disclose sensitive files on a computer, which may aid in various attacks.

fkey 0.0.2 and prior versions are affected by this issue.

51. 3Com OfficeConnect Wireless 11g Access Point 3CRWE454G72 Inf...
BugTraq ID: 12322
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12322
Summary:
It is reported that this issue arises due to an access validation error and may allow remote unauthorized attackers to gain access to sensitive hidden Web pages through the product's Web management interface.

3Com OfficeConnect Wireless 11g Access Point 3CRWE454G72 firmware versions prior to 1.03.07A are reported prone to this vulnerability.

52. Sybari AntiGen For Lotus Domino Multiple Remote Vulnerabilit...
BugTraq ID: 12323
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12323
Summary:
Multiple vulnerabilities are reported to exist in Sybari AntiGen For Lotus Domino. The following issues are reported:

An unspecified buffer overflow vulnerability is reported to exist in the Sybari AntiGen MIME handler.

A remote attacker may exploit this vulnerability to crash AntiGen and potentially bypass antivirus detection for malicious emails.

An unspecified remote denial of service vulnerability is reported to affect Sybari AntiGen. It is reported that this issue will only affect Sybari AntiGen For Lotus Domino when it is running on a Sun Solaris platform.

A remote attacker may exploit this vulnerability to crash AntiGen and potentially bypass anti-virus detection for malicious emails.

Finally a scanner bypass vulnerability is reported to affect Sybari AntiGen.

This vulnerability may be exploited by a remote attacker to bypass antivirus detection and deliver malicious applications to a target user.

53. Squid Proxy NTLM Fakeauth_Auth Memory Leak Remote Denial Of ...
BugTraq ID: 12324
Remote: Yes
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12324
Summary:
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module. 

This vulnerability presents itself when an attacker sends unspecified NTLM data to Squid.  The issue exists due to a memory leak that occurs because memory allocated to store a base64-decoded string is not freed.

It is conjectured that this issue allows an attacker to cause the NTLM helper application to run out of memory and fail.

54. Advanced Linux Sound Architecture Library Stack Protection D...
BugTraq ID: 12325
Remote: No
Date Published: Jan 20 2005
Relevant URL: http://www.securityfocus.com/bid/12325
Summary:
The Advanced Linux Sound Architecture (ALSA) library contains a weakness that disables stack protection schemes for its children.

If a child application of the ALSA library contains an exploitable stack overflow, it will not be protected against by any stack protection schemes that may be in place, potentially allowing arbitrary code to be executed on the computer.

55. Multiple Ethereal Unspecified Dissector Vulnerabilities
BugTraq ID: 12326
Remote: Yes
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12326
Summary:
Ethereal is prone to multiple vulnerabilities ranging from denial of service to arbitrary code execution.

The first issue could cause the COPS dissector to go into an infinite loop.

The second issue could cause the DLSw dissector to force Ethereal to exit prematurely.

The third issue could cause the DNP dissector to corrupt memory.

The fourth issue could cause the Gnutella dissector to force Ethereal to exit prematurely.

The fifth issue could cause the MMSE dissector to free statically allocated memory.

The sixth issue could cause a buffer overflow in the X11 dissector.

56. Ghostscript Multiple Local Insecure Temporary File Creation ...
BugTraq ID: 12327
Remote: No
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12327
Summary:
Ghostscript is reportedly affected by multiple local insecure temporary file creation vulnerabilities.  These issues are likely due to a design error that causes the application to fail to verify the existence of a file before writing to it.

An attacker may leverage these issues to overwrite arbitrary files with the privileges of an unsuspecting user that activates a vulnerable application.

AFPL Ghostscript version 8.50, and GNU Ghostscript 8.01 are reportedly affected by these vulnerabilities. Other versions may also be affected.

57. TikiWiki Multiple Remote Unspecified PHP Script Code Executi...
BugTraq ID: 12328
Remote: Yes
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12328
Summary:
TikiWiki is reported prone to multiple unspecified vulnerabilities that may result in a remote attacker executing arbitrary PHP script code in the context of the hosting web server process.

It is reported that these vulnerabilities will allow a remote attacker to write an arbitrary PHP script file into the TikiWiki temporary folder. Once the file has been written the attacker may directly request the file.

This BID will be updated as soon as further details regarding these vulnerabilities is made available.

58. GNU Enscript Multiple Vulnerabilities
BugTraq ID: 12329
Remote: Yes
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12329
Summary:
Multiple vulnerabilities are reported in GNU enscript.

The first issues are reportedly due to insufficient sanitization of user-supplied input data, leading to the possibility of arbitrary command execution.

There are also reportedly multiple unspecified buffer overflow vulnerabilities present in the utility. These issues are due to a failure of the application to properly bounds check user-supplied data prior to copying it into insufficiently sized memory buffers.

These issues are all locally exploitable, as enscript does not contain any network support. By combining enscript in network-based applications such as 'viewcvs', and possibly others, these issues could likely be remotely exploited.

Enscript is not installed with setuid privileges, but it may be utilized as a part of print spooler systems. By exploiting these issues, attackers may be able to execute arbitrary commands or machine code in the context of the affected system that is utilizing the affected utility. Other attacks are also possible depending on how the utility is utilized.

59. Linux Kernel Unspecified Local NFS I/O Denial of Service Vul...
BugTraq ID: 12330
Remote: No
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12330
Summary:
The Linux kernel is reported prone to an unspecified local denial of service vulnerability.  It is reported that issue exists locally and is exploitable through direct I/O access to NFS file systems.

Successful exploitation will lead to a kernel panic on a computer with NFS mounts. This would effectively deny service to legitimate users.

60. Netscape Navigator Infinite Array Sort Denial of Service Vul...
BugTraq ID: 12331
Remote: Yes
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12331
Summary:
Netscape Navigator is prone to a vulnerability that may result in a browser crash.  This issue is exposed when the browser performs an infinite JavaScript array sort operation.  It is conjectured that this will only result in a denial of service and is not further exploitable to execute arbitrary code, though this has not been confirmed.

61. DivX Player Skin File Directory Traversal Vulnerability
BugTraq ID: 12332
Remote: Yes
Date Published: Jan 21 2005
Relevant URL: http://www.securityfocus.com/bid/12332
Summary:
DivX Player is reported prone to a directory traversal vulnerability. The issue presents itself when DPS '.dps', archive files are processed. 

Ultimately an attacker may exploit this issue to save a script or executable file in an arbitrary location. This may lead to the execution of malicious code when the affected system is restarted. Alternatively, the attacker may overwrite a target file with the privileges of a user that is installing a malicious skin file.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. FBI retires its Carnivore
By: Kevin Poulsen

Newly-released reports show the bureau embracing commercial solutions for Internet surveillance, in investigations ranging from providing material support to terrorists to making harassing telephone calls. 
http://www.securityfocus.com/news/10307

2. Hacker penetrates T-Mobile systems
By: Kevin Poulsen

An intruder had access to customer records, Social Security numbers, and private e-mail for at least a year ending last October. Trophies included celebrity cell phone snapshots, and a trove of restricted Secret Service documents stored on an agent's Sidekick.

http://www.securityfocus.com/news/10271

3. Netizens eye Web-enabled surveillance cams
By: Kevin Poulsen

The whole world is watching.

http://www.securityfocus.com/news/10251

4. FBI chides Hotmail and Yahoo! for sidestepping UK laws
By: John Leyden, The Register

Poor controls and lax compliance with local laws by global hosting and webmail firms is hampering the fight against cybercrime, an FBI agent told a London conference yesterday.
http://www.securityfocus.com/news/10349

5. MS AntiSpyware bites BitDefender
By: John Leyden, The Register

A trial version of Microsoft software designed to rid Windows PCs of spyware is provoking complaints about false alerts.
http://www.securityfocus.com/news/10340

6. Malware poses as CNN news alert
By: John Leyden, The Register

Virus writers have created a worm which poses as breaking news alerts. Crowt-A's subject line and attachment share the same name, but continually change to mirror the front-page headline on CNN's website.
http://www.securityfocus.com/news/10339

IV. SECURITYFOCUS TOP 6 TOOLS
-----------------------------
1. Firestarter 1.0.0
By: Tomas Junnonen
Relevant URL: http://www.fs-security.com/
Platforms: Linux
Summary: 

Firestarter is graphical firewall tool for Linux. The program aims to combine
ease of use with powerful features, serving both desktop users and administrators.

2. Network Equipment Performance Monitor 2.2
By: Nova Software, Inc.
Relevant URL: http://www.nepm.net/
Platforms: AIX, FreeBSD, HP-UX, Linux, Solaris, True64 UNIX, UNIX, Windows 2000, Windows NT, Windows XP
Summary: 

NEPM is a very general, highly configurable, two part software system that monitors any type of logged data from IP networked equipment and reports it via E-mail and web pages. Current conditions and history from systems based on Windows NT/2000 and UNIX can be tracked and reported. Most major server, switch and router systems can be monitored, without running agents on the target systems.

3. Etherchange v1.0
By: Arne Vidstrom
Relevant URL: http://www.ntsecurity.nu/toolbox/etherchange/
Platforms: Windows 2000, Windows XP
Summary: 

EtherChange can change the Ethernet address of the network adapters in Windows 2000 / XP.

4. BitDefender for qmail v1.5.5-2 
By: SOFTWIN <[email protected]>
Relevant URL: http://www.bitdefender.com/bd/site/products.php?p_id=10
Platforms: Linux
Summary: 

BitDefender for qmail is a powerful antivirus software for Linux mail servers, which provides proactive protection of message traffic at the email server level, eliminating the risk to the entire network that could be caused by a negligent user. All messages, both sent and received, are scanned in real time, avoiding the possible infections and preventing anyone from sending an infected message. BitDefender claims 100% detection rate for all viruses in the wild (ITW) through its powerful scanning engines certified by the most prestigious testing labs (ICSA in February 2003, Virus Bulletin 100% in June 2003 and CheckMark in August 2003).

5. Bilbo 0.11
By: Bart Somers
Relevant URL: http://doornenburg.homelinux.net/scripts/bilbo/
Platforms: FreeBSD, Linux
Summary: 

Bilbo is an automated, multithreaded nmap-scanner and reporter, capable of header fetching and matching the results against a database from previous scans.

6. IPFront 1.0
By: HernĂ¡n M. Racciatti
Relevant URL: http://www.hernanracciatti.com.ar/ipfront/
Platforms: Windows 2000
Summary: 

IPFront is a small tool named which enables users to generate IPSec rules easily. It really speeds-up the process of hardening Windows 2000/2003 in Bastion Host Environment.

Additionally, it allows to set-up IPSec exceptions, and enables a couple of TCP/IP Stack protections against DoSes.

So, IPFront is nothing more than a small Frontend/GUI that writes small scripts that one can later execute from within IPFront, or externally, as simple script files, in other servers,

V. SECURITYJOBS LIST SUMMARY
----------------------------
1. [SJ-JOB] Sr. Security Engineer, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388282

2. [SJ-JOB] Certification & Accreditation Engineer, Arl... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388279

3. [SJ-JOB] Sr. Product Manager, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388276

4. [SJ-JOB] Developer, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388267

5. [SJ-JOB] Technology Risk Consultant, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388253

6. [SJ-JOB] Security Researcher, Palo Alto, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388234

7. [SJ-JOB] Information Assurance Engineer, Annapolis J... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388233

8. [SJ-JOB] Auditor, St. Louis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388230

9. [SJ-JOB] Security Consultant, Houston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388220

10. [SJ-JOB] MOD CLAS Consultant, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388213

11. [SJ-JOB] Security Consultant, Roseville (5 mins from... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388212

12. [SJ-JOB] Manager, Information Security, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388211

13. [SJ-JOB] Account Manager, New York City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388207

14. [SJ-JOB] Information Assurance Engineer, New Orleans... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388205

15. [SJ-JOB] Quality Assurance, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388204

16. [SJ-JOB] Chief Security Strategist, Austin, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388203

17. [SJ-JOB] Auditor, Redwood City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388202

18. [SJ-JOB] Technical Support Engineer, Slough, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388199

19. [SJ-JOB] Auditor, Kansas City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388196

20. [SJ-JOB] Certification & Accreditation Engineer, Fai... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388195

21. [SJ-JOB] Sales Representative, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388194

22. [SJ-JOB] Security Consultant, NYC, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388193

23. [SJ-JOB] Database Security Engineer, Princeton, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388192

24. [SJ-JOB] Security Consultant, Washington DC / Maryla... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388191

25. [SJ-JOB] Security Engineer, St Louis, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388190

26. [SJ-JOB] Security Consultant, Leeds, Manchester, Lon... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388187

27. [SJ-JOB] Manager, Information Security, Leeds, Edinb... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388186

28. [SJ-JOB] Auditor, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388185

29. [SJ-JOB] Security Architect, Fairfax, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388178

30. [SJ-JOB] Sr. Security Engineer, Atlanta, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388177

31. [SJ-JOB] Security Consultant, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388176

32. [SJ-JOB] Account Manager, Fremont, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388175

33. [SJ-JOB] Developer, Sterling, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388174

34. [SJ-JOB] Security Engineer, Annapolis Junction, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388172

35. [SJ-JOB] Security Engineer, Fremont, DE (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388171

36. [SJ-JOB] Security Consultant, Boston, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388170

37. [SJ-JOB] Security Consultant, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388169

38. [SJ-JOB] Manager, Information Security, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388168

39. [SJ-JOB] CHECK Team Leader, Various, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388166

40. [SJ-JOB] Developer, Dulles, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388165

41. [SJ-JOB] Regional Channel Manager, Flexible/Home Bas... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388164

42. [SJ-JOB] Information Assurance Analyst, Mississauga,... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388162

43. [SJ-JOB] Security Auditor, San Antonio, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388160

44. [SJ-JOB] Sales Representative, San Mateo, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388158

45. [SJ-JOB] Auditor, New York (Tri-State area), US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/388157

46. [SJ-JOB] Security Engineer, Baltimore, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387531

47. [SJ-JOB] Quality Assurance, Redmond, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387530

48. [SJ-JOB] Security Engineer, Fremont, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387529

49. [SJ-JOB] CSO, London, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387528

50. [SJ-JOB] Application Security Engineer, South San Fr... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387527

51. [SJ-JOB] Security Consultant, South San Francisco, U... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387526

52. [SJ-JOB] Security Consultant, Kansas City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387524

53. [SJ-JOB] Sr. Security Analyst, Leeds, GB (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387523

54. [SJ-JOB] Security Architect, Baghdad, IQ (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387522

55. [SJ-JOB] Sr. Security Engineer, Baghdad, IR (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387521

56. [SJ-JOB] Information Assurance Analyst, Kansas City,... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387520

57. [SJ-JOB] Developer, Cherry Hill, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387518

58. [SJ-JOB] Auditor, New York, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387516

59. [SJ-JOB] Instructor, Kansas City, US (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387515

60. [SJ-JOB] Chief Security Strategist, Toronto, CA (Thread)
Relevant URL:

http://www.securityfocus.com/archive/77/387513

VI. INCIDENTS LIST SUMMARY
--------------------------
1. SQL injection ... another attack (Thread)
Relevant URL:

http://www.securityfocus.com/archive/75/387812

VII. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Security of osCommerce (Thread)
Relevant URL:

http://www.securityfocus.com/archive/82/387863

VIII. MICROSOFT FOCUS LIST SUMMARY
----------------------------------
1. AW: IIS6 on W2k3 DCs (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387976

2. Dhcp security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387974

3. IIS6 on W2k3 DCs (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387973

4. [Maybe Spam] Dhcp security (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387964

5. PGP and Outlook (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387687

6. SecurityFocus Microsoft Newsletter #224 (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387682

7. local admin vs group policy and apps... (Thread)
Relevant URL:

http://www.securityfocus.com/archive/88/387556

IX. SUN FOCUS LIST SUMMARY
--------------------------
NO NEW POSTS FOR THE WEEK 2005-01-18 to 2005-01-25.

X. LINUX FOCUS LIST SUMMARY
---------------------------
1. Encrypted Filesystems (Thread)
Relevant URL:

http://www.securityfocus.com/archive/91/388308

XI. UNSUBSCRIBE INSTRUCTIONS
----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.
    
XII. SPONSOR INFORMATION
-----------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------------