SecurityFocus Newsletter #323

Peter Laborge <[email protected]> Tue, 08 Nov 2005 16:47:05 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #323
----------------------------------------

Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Automatic graylisting of unwanted software
       2. Windows rootkits in 2005, part one
II.   BUGTRAQ SUMMARY
       1. MG2 Authentication Bypass Vulnerability
       2. PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
       3. Subdreamer Multiple Remote SQL Injection Vulnerabilities
       4. OpenVPN Client Remote Format String Vulnerability
       5. Invision Gallery Index.PHP SQL Injection Vulnerability
       6. Snitz Forum Post.ASP Cross-Site Scripting Vulnerability
       7. NTop Insecure Temporary File Creation Vulnerability
       8. PHPBB Global Variable Deregistration Bypass Vulnerabilities
       9. PHPCafe Tutorial Manager Index.PHP SQL Injection Vulnerability
       10. OaBoard Forum.PHP Multiple SQL Injection Vulnerabilities
       11. PHPBB Multiple Unspecified Vulnerabilities
       12. IBM AIX CHCONS Local Buffer Overflow Vulnerability
       13. PHP PHPInfo Cross-Site Scripting Vulnerability
       14. PHP Parse_Str Register_Globals Activation Weakness
       15. PHP File Upload GLOBAL Variable Overwrite Vulnerability
       16. Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
       17. Apple Mac OS X Security Update 2005-10-31 Multiple Local Vulnerabilities
       18. IOFTPD Username Enumeration Vulnerability
       19. Belchior Foundry vCard Pro Addrbook.PHP SQL Injection Vulnerability
       20. EyeOS Desktop.PHP HTML Injection Vulnerability
       21. EyeOS User And Password Information Disclosure Vulnerability
       22. Elite Forum HTML Injection Vulnerability
       23. Multiple Vendor ReadDir_R Buffer Overflow Vulnerability
       24. VUBB Index.PHP Cross-Site Scripting Vulnerability
       25. OpenVMS Unspecified Local Denial of Service Vulnerability
       26. Pax File Permission Modification Race Condition Weakness
       27. NetBSD Insecure Temporary File Creation Vulnerability
       28. NetBSD KernFS Local Kernel Memory Disclosure Vulnerability
       29. XMB Forum Post.PHP SQL Injection Vulnerability
       30. Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
       31. Cisco Management Center for IPS Sensors Configuration Download Weakness
       32. OpenVPN Server Remote Denial Of Service Vulnerability
       33. Sun Java System Communications Express Information Disclosure Vulnerability
       34. Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
       35. RhinoSoft Serv-U FTP Server Unspecified Denial of Service Vulnerability
       36. News2Net Index.PHP SQL Injection Vulnerability
       37. Cisco IOS System Timers Heap Buffer Overflow Exploitation
       38. phpWebThings Forum.PHP Cross-Site Scripting Vulnerability
       39. PHPWebThing Forum.PHP SQL Injection Vulnerability
       40. MailWatch for MailScanner Authenticate Function SQL Injection Vulnerability
       41. Asus VideoSecurity Online Web Server Authentication Buffer Overflow Vulnerability
       42. Glider Collect'N Kill Remote Buffer Overflow Vulnerability
       43. Asus VideoSecurity Online Web Server Directory Traversal Vulnerability
       44. Battle Carry Remote Denial of Service Vulnerability
       45. Simple PHP Blog Multiple Input Validation Vulnerabilities
       46. F-Secure Web Console Directory Traversal Vulnerability
       47. GraphOn GO-Global For Windows Remote Buffer Overflow Vulnerability
       48. Invision Gallery Image Upload HTML Injection Vulnerability
       49. Johannes F. Kuhlmann FlatFrag Multiple Remote Buffer Overflow And Denial Of Service Vulnerabilities
       50. NeroNet Limited Directory Traversal Vulnerability
       51. NetBSD SO_LINGER DIAGNOSTIC Checking Local Denial of Service Vulnerability
       52. NetBSD Local PTrace Privilege Escalation Vulnerability
       53. IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
       54. Scorched 3D Multiple Vulnerabilities
       55. F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
       56. PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
       57. CutePHP CuteNews Directory Traversal Vulnerability
       58. vBulletin Image Upload HTML Injection Vulnerability
       59. PHP Handicapper Process_signup.PHP SQL Injection Vulnerability
       60. Libungif Colormap Handling Memory Corruption Vulnerability
       61. Microsoft November Advance Notification Unspecified Security Vulnerabilities
       62. PHP Handicapper Process_signup.PHP HTTP Response Splitting Vulnerability
       63. Movable Type Arbitrary Blog Creation Path  Vulnerability
       64. IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
       65. Libungif Null Pointer Dereference Denial of Service Vulnerability
       66. Movable Type Blog Entry Posting HTML Injection Vulnerability
       67. Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
       68. Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
       69. Apple QuickTime Movie Attributes Remote Integer Overflow Vulnerability
       70. Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
       71. Sun Java Development Kit Font Serialization Remote Denial of Service Vulnerability
       72. Galerie ShowGallery.PHP SQL Injection Vulnerability
       73. CHFN User Modification Privilege Escalation Vulnerability
       74. Cerberus Helpdesk Information Disclosure Vulnerability
       75. Clam Anti-Virus ClamAV TNEF File Handling Denial Of Service Vulnerability
       76. Clam Anti-Virus ClamAV CAB File Handling Denial Of Service Vulnerability
       77. Clam Anti-Virus ClamAV FSG File Handling Buffer Overflow Vulnerability
       78. GpsDrive Friendsd Remote Format String Vulnerability
       79. Acme Thttpd Insecure Temporary File Creation Vulnerability
       80. IBM Lotus Domino Multiple Vulnerabilities
       81. PunBB/Blog:CMS Image Upload HTML Injection Vulnerability
       82. IBM AIX SWCONS Local Buffer Overflow Vulnerability
       83. JPortal Multiple SQL Injection Vulnerabilities
       84. Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
       85. PunBB/BLOG:CMS Origin Spoofing Vulnerability
       86. cPanel Chat Message Field HTML Injection Vulnerability
       87. PunBB/BLOG:CMS Unspecified Information Disclosure Vulnerability
       88. Ocean12 ASP Calendar Manager Authentication Bypass Vulnerability
       89. Ocean12 ASP Calendar Manager SQL Injection Vulnerability
       90. Multiple Vendor Web Browser Cookie Hostname Handling Weakness
       91. Macromedia Flash Array Index Memory Access Vulnerability
       92. ibProArcade User ID SQL Injection Vulnerability
III.  SECURITYFOCUS NEWS
       1. Suspected bot master busted
       2. Hidden DRM code's legitimacy questioned
       3. U.S. makes securing SCADA systems a priority
       4. Web defacer sentenced, facing deportation 
       5. Skype under scrutiny for bugs
       6. Say hello to the Skype Trojan
       7. Shared music abuse bug hits iTunes
       8. US cybersecurity all at sea
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Sr. Security Analyst, Philadelphia
       2. [SJ-JOB] Auditor, Charlotte
       3. [SJ-JOB] Security Researcher, Richland
       4. [SJ-JOB] Security Engineer, Phoenix
       5. [SJ-JOB] Security Product Manager, Ft. Lauderdale
       6. [SJ-JOB] Sales Engineer, NYC/NJ/Conn - Metro Area
       7. [SJ-JOB] Sr. Product Manager, Ft. Lauderdale
       8. [SJ-JOB] Sr. Security Engineer, Hoboken
       9. [SJ-JOB] Management, san diego
       10. [SJ-JOB] Security Consultant, Boston
       11. [SJ-JOB] Security Consultant, Chicago
       12. [SJ-JOB] Security Consultant, Dallas
       13. [SJ-JOB] Security Consultant, Boston
       14. [SJ-JOB] Security Consultant, New York, NY
       15. [SJ-JOB] Security Consultant, New York, NY
       16. [SJ-JOB] Security Consultant, Houston Area
       17. [SJ-JOB] Security Consultant, Boston Area
       18. [SJ-JOB] Security Consultant, New York, NY
       19. [SJ-JOB] Security Consultant, Dallas
       20. [SJ-JOB] Security Consultant, New York Metropolitan Area
       21. [SJ-JOB] Security Consultant, Chicago
       22. [SJ-JOB] Security System Administrator, Arlington
       23. [SJ-JOB] Sr. Security Analyst, Columbus
       24. [SJ-JOB] Security Consultant, New York, NY
       25. [SJ-JOB] Security Engineer, Saint Louis
       26. [SJ-JOB] Sales Representative, Atlanta
       27. [SJ-JOB] Security Auditor, Puget Sound
       28. [SJ-JOB] Information Assurance Analyst, DC
       29. [SJ-JOB] Sales Engineer, New York, NY
       30. [SJ-JOB] Security Researcher, Calgary
       31. [SJ-JOB] Security Consultant, Ft Meade
       32. [SJ-JOB] Sales Engineer, Atlanta, GA
       33. [SJ-JOB] Sales Representative, UK Wide
       34. [SJ-JOB] Security Consultant, Boston Area
       35. [SJ-JOB] Security Consultant, New York Metropolitan Area
       36. [SJ-JOB] Sr. Product Manager, Richland
       37. [SJ-JOB] Jr. Security Analyst, Las Vegas
       38. [SJ-JOB] Sr. Security Analyst, Las Vegas
       39. [SJ-JOB] Security Researcher, Richland
       40. [SJ-JOB] Sales Engineer, New York City
       41. [SJ-JOB] Account Manager, San Francisco
       42. [SJ-JOB] Application Security Architect, Mountain View
       43. [SJ-JOB] Account Manager, San Francisco
       44. [SJ-JOB] Sales Representative, Abingdon, Oxfordshire
       45. [SJ-JOB] Technical Writer, Washington
       46. [SJ-JOB] Security Researcher, Richland
       47. [SJ-JOB] Developer, Richland
       48. [SJ-JOB] Sr. Security Engineer, Richland
       49. [SJ-JOB] Auditor, Puget Sound Area
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Stack Overflow Basics
       2. Black Hat Federal and Europe CFP and Registration now open
       3. Vulnerability Assesment tools(Vuln testing tools)
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #263
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Automatic graylisting of unwanted software
By Dr. Todd Brennan
In the race to secure endpoint systems, a new approach known as automatic graylisting can give administrators control over unwanted software installed on end user systems.
http://www.securityfocus.com/columnists/367

2. Windows rootkits in 2005, part one
By James Butler, Sherri Sparks
This three-part article series looks at Windows rootkits indepth. Part one discusses what a rootkit is and what makes them so dangerous, by looking at various modes of execution and how they talk to the Windows kernel.
http://www.securityfocus.com/infocus/1850


II.  BUGTRAQ SUMMARY
--------------------
1. MG2 Authentication Bypass Vulnerability
BugTraq ID: 15235
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15235
Summary:
MG2 is affected by an authentication bypass vulnerability.  This issue can allow remote attackers to gain access to password protected image galleries.

All versions of MG2 are considered to be vulnerable at the moment.  Minigal B13 is likely affected as well.

2. PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
BugTraq ID: 15237
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15237
Summary:
PHP Advanced Transfer Manager can allow remote attackers to gain unauthorized access.  

Access to sensitive files containing authentication credentials is not restricted, therefore an attacker can simply issue a GET request to obtain a user's password hash.  This information can then allow them to successfully authenticate to the service using a cookie.

PHP Advanced Transfer Manager 1.30 is reported to be vulnerable.  Other versions may be affected as well.

3. Subdreamer Multiple Remote SQL Injection Vulnerabilities
BugTraq ID: 15238
Remote: Yes
Date Published: 2005-10-29
Relevant URL: http://www.securityfocus.com/bid/15238
Summary:
Subdreamer is prone to multiple remote SQL injection vulnerabilities.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

Subdreamer 2.2.1 is reported to be vulnerable.  Other versions may be affected as well.

4. OpenVPN Client Remote Format String Vulnerability
BugTraq ID: 15239
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15239
Summary:
OpenVPN is reported prone to a remote format string vulnerability.

A malicious server can send specially crafted command options such as 'dhcp-option' including format specifiers to a client to trigger this vulnerability.

A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution.  This can result in unauthorized remote access.

This issue affects OpenVPN 2.0.x versions.  OpenVPN running on Windows is not vulnerable to this issue.

5. Invision Gallery Index.PHP SQL Injection Vulnerability
BugTraq ID: 15240
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15240
Summary:
Invision Gallery is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

6. Snitz Forum Post.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15241
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15241
Summary:
Snitz Forum is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


7. NTop Insecure Temporary File Creation Vulnerability
BugTraq ID: 15242
Remote: No
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15242
Summary:
ntop creates temporary files in an insecure manner.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

8. PHPBB Global Variable Deregistration Bypass Vulnerabilities
BugTraq ID: 15243
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15243
Summary:
phpBB is prone to multiple vulnerabilities resulting from improper deregistration of global variables.

These issues may allow remote attackers to execute arbitrary PHP code, carry out SQL injection, HTML injection, and cross-site scripting attacks.

phpBB 2.0.17 and prior versions are affected by these issues.

9. PHPCafe Tutorial Manager Index.PHP SQL Injection Vulnerability
BugTraq ID: 15244
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15244
Summary:
PHPcafe Tutorial Manager is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

10. OaBoard Forum.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 15245
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15245
Summary:
OaBoard is prone to multiple SQL injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

11. PHPBB Multiple Unspecified Vulnerabilities
BugTraq ID: 15246
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15246
Summary:
phpBB is prone to multiple unspecified vulnerabilities.  Some of these issues result from insufficient sanitization of user-supplied data, however, the causes and impacts of other issues were not specified.

phpBB 2.0.17 and prior versions are affected by these issues.

Due to a lack of information, further details cannot be provided at the moment.  It is possible that some of these issues were reported prior to the release of this record. This BID will be updated when more information becomes available.

12. IBM AIX CHCONS Local Buffer Overflow Vulnerability
BugTraq ID: 15247
Remote: No
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15247
Summary:
IBM AIX chcons is prone to a local buffer overflow vulnerability. This issue arises because the application fails to perform boundary checks prior to copying user-supplied data into insufficiently-sized memory buffers. This issue presents itself when 'DEBUG MALLOC' is enabled.

If the affected utility has setuid-superuser privileges, then a successful attack allows arbitrary machine code execution with superuser privileges.

13. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

14. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to re-enable the 'register_globals' directive. This issue is due to a failure of the application to handle a memory limit exception.

The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the processes life. If PHP is being run as a CGI process, this issue is not likely exploitable.

By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

15. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.

By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

16. Comersus BackOffice Multiple Input Validation And Information Disclosure Vulnerabilities
BugTraq ID: 15251
Remote: Yes
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15251
Summary:
Comersus BackOfficePlus and BackOfficeLite are prone to multiple input validation and information disclosure vulnerabilities.

The applications are prone to SQL injection attacks, information disclosure and multiple cross-site scripting attacks.

An attacker can exploit these vulnerabilities to retrieve sensitive and privileged information, gain access to the application as an administrative user and perform cross-site scripting attacks to retrieve cookie-based authentication credentials from victim users; other attacks are also possible.

17. Apple Mac OS X Security Update 2005-10-31 Multiple Local Vulnerabilities
BugTraq ID: 15252
Remote: No
Date Published: 2005-10-31
Relevant URL: http://www.securityfocus.com/bid/15252
Summary:
Apple has released Security Update 2005-10-31 to address multiple Mac OS X local  vulnerabilities.

The following vulnerabilities were addressed by the security update:

- A misleading file ownership display, resulting in a false sense of security.

- A software update failure, potentially resulting in a failure to install critical security fixes.

- A group membership alteration issue, potentially resulting in unauthorized access due to a delayed changes to group membership.

- An information disclosure issue with Keychain, potentially allowing unauthorized users to view already displayed plaintext passwords after the Keychain has automatically locked due to a timeout.

- Multiple information disclosure issues in the kernel, potentially allowing local users to gain access to sensitive information, aiding them in further attacks.

These vulnerabilities will be separated into individual BIDs upon further analysis of the issues.

18. IOFTPD Username Enumeration Vulnerability
BugTraq ID: 15253
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15253
Summary:
ioFTPD is prone to a username enumeration vulnerability.  This issue is due to a design error in the application when verifying user-supplied input. 

Attackers may exploit this vulnerability to discern valid usernames. This may aid them in brute force password cracking, or other attacks.

19. Belchior Foundry vCard Pro Addrbook.PHP SQL Injection Vulnerability
BugTraq ID: 15254
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15254
Summary:
vCard PRO is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


20. EyeOS Desktop.PHP HTML Injection Vulnerability
BugTraq ID: 15255
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15255
Summary:
eyeOS is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

21. EyeOS User And Password Information Disclosure Vulnerability
BugTraq ID: 15256
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15256
Summary:
eyeOS is prone to an information disclosure vulnerability.  This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.

An attacker can exploit this vulnerability to obtain a list of valid usernames and their corresponding encrypted passwords.  Information obtained may aid in further attacks against the underlying system; other attacks are also possible.

22. Elite Forum HTML Injection Vulnerability
BugTraq ID: 15257
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15257
Summary:
Elite Forum is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


23. Multiple Vendor ReadDir_R Buffer Overflow Vulnerability
BugTraq ID: 15259
Remote: No
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15259
Summary:
Certain uses of the 'readdir_r' function may result in a buffer overflow vulnerability. This issue is due to a race condition between the allocation of a memory buffer, and the usage of the buffer in further operations.

Specifically, the 'readdir_r' function fails to specify or require a specific size of memory buffer that it returns its results into. By using a memory buffer that is too small for the result, a buffer overflow may occur.

Attackers may exploit this issue to execute arbitrary machine code in the context of affected applications. Failed exploit attempts will likely result in crashes, denying service to legitimate users.

Operating systems with no difference in the maximum path lengths among differing file systems are not affected by this issue.

24. VUBB Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15260
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15260
Summary:
VUBB is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


25. OpenVMS Unspecified Local Denial of Service Vulnerability
BugTraq ID: 15261
Remote: No
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15261
Summary:
OpenVMS is prone to an unspecified local denial of service vulnerability.  This issue is most likely due to a failure in the software to handle exceptional conditions.

An attacker can exploit this vulnerability to cause the application to become unstable or halt, ultimately denying service to legitimate user.

Very little information is currently available on this vulnerability, this BID will be updated as further information becomes available.

26. Pax File Permission Modification Race Condition Weakness
BugTraq ID: 15262
Remote: No
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15262
Summary:
Pax is reported prone to a security weakness; the issue is only present when an archive is extracted into a world or group writable directory. It is reported that pax employs non-atomic procedures to write a file and later change the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.


27. NetBSD Insecure Temporary File Creation Vulnerability
BugTraq ID: 15263
Remote: No
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15263
Summary:
NetBSD creates temporary files in an insecure manner in the X build process.  An attacker with local access could potentially exploit this issue to overwrite files in the context of the victim user.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

28. NetBSD KernFS Local Kernel Memory Disclosure Vulnerability
BugTraq ID: 15264
Remote: No
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15264
Summary:
The kernfs file system in NetBSD is prone to a kernel memory disclosure vulnerability. This issue arises due to insufficient sanitization of user-supplied arguments passed to 'kernfs_xread()'.

Information disclosed through this attack may be used to launch other attacks against a computer and potentially aid in a complete compromise.

29. XMB Forum Post.PHP SQL Injection Vulnerability
BugTraq ID: 15267
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15267
Summary:
XMB Nexus Forum is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.



30. Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
BugTraq ID: 15268
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15268
Summary:
Microsoft Internet Explorer is affected by a denial of service vulnerability. This issue arises because the application fails to properly parse certain malformed HTML content.

An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.

Few details are available at this time; this BID will be updated as further information is disclosed.

31. Cisco Management Center for IPS Sensors Configuration Download Weakness
BugTraq ID: 15269
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15269
Summary:
Cisco Management Center for IPS Sensors is prone to an issue that may cause some IPS signatures to be disabled during deployment.

Cisco IOS IPS devices configured by IPS MC 2.1 are prone to this issue.  Cisco IDS/IPS solution, configured by either Cisco IPS MC v2.1, Cisco IDS MC, Cisco SDM or by using the Cisco IOS CLI are vulnerable as well.

32. OpenVPN Server Remote Denial Of Service Vulnerability
BugTraq ID: 15270
Remote: Yes
Date Published: 2005-11-01
Relevant URL: http://www.securityfocus.com/bid/15270
Summary:
OpenVPN server is prone to a remote denial of service vulnerability. This is due to a design error in which the server, running in TCP mode, will be unable to handle exceptional conditions.

This issue affects all OpenVPN 2.0 versions; the vendor has released version 2.0.4 to address this issue.


33. Sun Java System Communications Express Information Disclosure Vulnerability
BugTraq ID: 15271
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15271
Summary:
Sun Java System Communications Express is prone to an information disclosure vulnerability.

A remote attacker may obtain application configuration files.

34. Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
BugTraq ID: 15272
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15272
Summary:
Cisco Airespace WLAN (Wireless LAN) devices are prone to an issue that may permit unauthorized parties to access a secure network.  

This issue can occur when Cisco access points are configured to run in Lightweight Access Point Protocol (LWAPP) mode.

This vulnerability may allow unauthorized parties to send unencrypted network packets to a secure network by spoofing the MAC address of another host that has already authenticated.  This may bypass the security of the wireless network as it may permit unauthorized access by hosts that have not authenticated.

35. RhinoSoft Serv-U FTP Server Unspecified Denial of Service Vulnerability
BugTraq ID: 15273
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15273
Summary:
Serv-U FTP server is prone to an unspecified denial of service vulnerability.  This issue is most likely due to a failure in the application to handle exceptional conditions.

Specific details regarding this issue are not currently available, this BID will be updated as more information becomes available.

An attacker can exploit this vulnerability to cause the server to crash, effectively denying service to legitimate users.

36. News2Net Index.PHP SQL Injection Vulnerability
BugTraq ID: 15274
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15274
Summary:
News2Net is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

37. Cisco IOS System Timers Heap Buffer Overflow Exploitation
BugTraq ID: 15275
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15275
Summary:
Cisco IOS is prone to heap-based buffer overflow exploitation.  Cisco has released an advisory stating that IOS upgrades are available to address the possibility of exploitation of heap-based buffer overflow vulnerabilities.  It is not known at this time if the advisory addresses a specific heap overflow or just provides security enhancements to mitigate attempts to exploit other heap overflow vulnerabilities.

38. phpWebThings Forum.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15276
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15276
Summary:
phpWebThings is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

phpWebThings version 1.4.4 is affected; other versions may also be vulnerable.


39. PHPWebThing Forum.PHP SQL Injection Vulnerability
BugTraq ID: 15277
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15277
Summary:
phpWebThing is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

40. MailWatch for MailScanner Authenticate Function SQL Injection Vulnerability
BugTraq ID: 15278
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15278
Summary:
MailWatch for MailScanner is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


41. Asus VideoSecurity Online Web Server Authentication Buffer Overflow Vulnerability
BugTraq ID: 15279
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15279
Summary:
Asus VideoSecurity Online is prone to a buffer overflow in the authentication mechanism of the included Web server.  This issue only exists if authentication is enabled on the Web server.

The Web server included with Asus VideoSecurity Online is not enabled by default.

This vulnerability is reported to affect Asus VideoSecurity Online 3.5.0 and earlier.



42. Glider Collect'N Kill Remote Buffer Overflow Vulnerability
BugTraq ID: 15280
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15280
Summary:
Glider Connect'n Kill is prone to a remote buffer overflow vulnerability.  This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.

An attacker can exploit this vulnerability to overflow a memory buffer, possibly resulting in a denial of service condition.  Execution of arbitrary code may also be possible.

43. Asus VideoSecurity Online Web Server Directory Traversal Vulnerability
BugTraq ID: 15281
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15281
Summary:
Asus VideoSecurity Online is prone to a directory traversal vulnerability.  Exploitation could allow a remote attacker to obtain sensitive information that could be used to mount further attacks.

The Web server included with Asus VideoSecurity Online is not enabled by default.

This vulnerability is reported to affect Asus VideoSecurity Online 3.5.0 and earlier.


44. Battle Carry Remote Denial of Service Vulnerability
BugTraq ID: 15282
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15282
Summary:
Battle Carry is prone to a remote denial of service vulnerability.  This issue is due to a failure in the application to handle exceptional conditions.

An attacker can exploit this vulnerability to crash the application, ultimately resulting in a denial of service to legitimate users.

45. Simple PHP Blog Multiple Input Validation Vulnerabilities
BugTraq ID: 15283
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15283
Summary:
Simple PHP Blog is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  These may facilitate the theft of cookie-based authentication credentials as well as other attacks.


46. F-Secure Web Console Directory Traversal Vulnerability
BugTraq ID: 15284
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15284
Summary:
F-Secure Anti-Virus for Microsoft Exchange and F-Secure Internet Gatekeeper are prone to a directory traversal vulnerability.

Reports indicate that the Web Console for the products can allow remote unauthorized attackers to view arbitrary files in the context of the application.

It should be noted that the Web Console for F-Secure Anti-Virus for Microsoft Exchange and F-Secure Internet Gatekeeper is configured by default to accept connections from localhost only.  The remote threat only arises if the application has been configured to accept connections from elsewhere.  The default configuration only poses a local threat.

47. GraphOn GO-Global For Windows Remote Buffer Overflow Vulnerability
BugTraq ID: 15285
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15285
Summary:
GraphOn GO-Global For Windows is prone to a remote buffer overflow vulnerability.  This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.

An attacker can exploit this vulnerability to overflow a memory buffer, possibly resulting in a denial of service condition.  Execution of arbitrary code may also be possible.

Versions 3.1.0.3270 and prior are affected by this issue.

48. Invision Gallery Image Upload HTML Injection Vulnerability
BugTraq ID: 15286
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15286
Summary:
Invision Gallery is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is only present when using the Microsoft Internet Explorer Web browser.


49. Johannes F. Kuhlmann FlatFrag Multiple Remote Buffer Overflow And Denial Of Service Vulnerabilities
BugTraq ID: 15287
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15287
Summary:
Johannes F. Kuhlmann FlatFrag is prone to multiple remote buffer overflow and denial of service vulnerabilities. The buffer overflow issues are due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer. The denial of service issue is due to an attempt to dereference a NULL pointer.

An attacker may exploit these issues to crash the application, or execute arbitrary machine code in the context of the affected application.

Versions 0.3 and prior are affected by these issues.

50. NeroNet Limited Directory Traversal Vulnerability
BugTraq ID: 15288
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15288
Summary:
NeroNet is prone to a directory traversal vulnerability.

Reports indicate that this product can allow remote unauthorized attackers to view arbitrary files in the context of the application.

Exploitation of this vulnerability could lead to a loss of confidentiality. Information obtained may aid in further attacks against the underlying computer.

It is reported that NeroNET versions 1.2.0.2 and earlier are vulnerable.


51. NetBSD SO_LINGER DIAGNOSTIC Checking Local Denial of Service Vulnerability
BugTraq ID: 15289
Remote: No
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15289
Summary:
NetBSD is susceptible to a local denial of service condition due to a kernel-level bug in the SO_LINGER diagnostics checking code. NetBSD versions 2.x are affected.  

This issue only affects NetBSD kernels compiled with the 'DIAGNOSTIC' directive enabled.

This issue allows local attackers to panic the kernel, denying further service to legitimate users.

52. NetBSD Local PTrace Privilege Escalation Vulnerability
BugTraq ID: 15290
Remote: No
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15290
Summary:
NetBSD is susceptible to a local privilege escalation vulnerability in its 'ptrace' process tracing facility. This issue is due to a failure of the kernel to properly validate if an executable is running with elevated privileges prior to allowing the process to be traced.

This issue allows local attackers to ptrace privileged processes. Attackers may call arbitrary system calls, and alter the behavior of the traced process. This likely leads to a full system compromise.

53. IPSwitch WhatsUp Small Business 2004 Report Service Directory Traversal Vulnerability
BugTraq ID: 15291
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15291
Summary:
IPSwitch WhatsUp Small Business 2004 is prone to a directory traversal vulnerability.  Successful exploitation could allow a remote attacker to gain access to files outside the Web root.  Sensitive information may be obtained in this manner.


54. Scorched 3D Multiple Vulnerabilities
BugTraq ID: 15292
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15292
Summary:
Scorched 3D is prone to multiple vulnerabilities.  These issues include numerous buffer overflow, format string, denial of service and arbitrary code execution issues.

These issues are remote in nature and some vulnerabilities require successful authentication prior to exploitation.

Scorched 3D 39.1 and prior versions are affected by these issues.

55. F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
BugTraq ID: 15293
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15293
Summary:
F-prot Antivirus is prone to a scan evasion vulnerability when dealing with ZIP archive attachments.  This issue is due to a design error in the application that flags certain ZIP files as harmless when it is unable to decompress them.

An attacker can exploit this vulnerability by crafting a specially designed ZIP file containing malicious code and bypass the antivirus software. 

56. PHP Handicapper Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15294
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15294
Summary:
PHP Handicapper is prone to multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

57. CutePHP CuteNews Directory Traversal Vulnerability
BugTraq ID: 15295
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15295
Summary:
CuteNews is affected by a directory traversal vulnerability.

An unauthorized attacker can retrieve or upload arbitrary files by supplying directory traversal strings '../' through an affected URI parameter.

Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system. 

An attacker may also upload arbitrary scripts, which may be subsequently executed leading to a remote compromise in the context of the server.

CuteNews 1.4.1 is reported to be vulnerable to this issue.  Other versions may be affected as well.

58. vBulletin Image Upload HTML Injection Vulnerability
BugTraq ID: 15296
Remote: Yes
Date Published: 2005-11-02
Relevant URL: http://www.securityfocus.com/bid/15296
Summary:
vBulletin is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is only present when using the Microsoft Internet Explorer Web browser.


59. PHP Handicapper Process_signup.PHP SQL Injection Vulnerability
BugTraq ID: 15298
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15298
Summary:
PHP Handicapper is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

60. Libungif Colormap Handling Memory Corruption Vulnerability
BugTraq ID: 15299
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15299
Summary:
libungif is prone to a memory corruption vulnerability.

Reports indicate that due to improper handling of colormaps in GIF files an attacker can trigger out-of-bounds writes and corrupt memory.

This may lead to a denial of service condition.

libungif 4.1.3 and prior versions are considered to be vulnerable to this issue.

61. Microsoft November Advance Notification Unspecified Security Vulnerabilities
BugTraq ID: 15300
Remote: Unknown
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15300
Summary:
Microsoft has released advanced notification for one security bulletin that will be released on November 8, 2005.

This bulletin affects Microsoft Windows.

62. PHP Handicapper Process_signup.PHP HTTP Response Splitting Vulnerability
BugTraq ID: 15301
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15301
Summary:
PHP Handicapper is vulnerable to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.


63. Movable Type Arbitrary Blog Creation Path  Vulnerability
BugTraq ID: 15302
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15302
Summary:
Movable Type is prone to an arbitrary blog creation path vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

It should be noted that this vulnerability applies only when a validated user has sufficient permissions to create blog entries.

64. IBM WebSphere Application Server QueryString Information Disclosure Vulnerability
BugTraq ID: 15303
Remote: No
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15303
Summary:
A remote information disclosure vulnerability reportedly affects the IBM WebSphere Application Server.

A malicious user may leverage this issue to disclose potentially sensitive information, aiding them in further attacks.

65. Libungif Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 15304
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15304
Summary:
libungif is prone to a denial of service vulnerability.  This issue is due to a failure in the application to handle exceptional conditions.

Successful exploitation of this vulnerability will cause the application utilizing the affected library to crash, effectively denying service to legitimate users.

libungif 4.1.3 and prior versions are considered to be vulnerable to this issue.

66. Movable Type Blog Entry Posting HTML Injection Vulnerability
BugTraq ID: 15305
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15305
Summary:
Movable Type is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


67. Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
BugTraq ID: 15306
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15306
Summary:
A remote integer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.

An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.

68. Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 15307
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15307
Summary:
QuickTime is prone to a denial of service vulnerability.  This issue is due to a failure in the application to handle exceptional conditions.

Successful exploitation of this vulnerability will cause the application to crash, effectively denying service to legitimate users.

69. Apple QuickTime Movie Attributes Remote Integer Overflow Vulnerability
BugTraq ID: 15308
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15308
Summary:
A remote integer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.

An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.

70. Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
BugTraq ID: 15309
Remote: Yes
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15309
Summary:
A remote buffer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.

An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.

71. Sun Java Development Kit Font Serialization Remote Denial of Service Vulnerability
BugTraq ID: 15312
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15312
Summary:
The Sun Java Development Kit (JDK) is prone to a remote denial of service vulnerability.  This is due to a font deserialization error.  It has been demonstrated that this could be exploited to attack JBoss versions that employ affected versions of the JDK, though the issue itself exists in the JDK.

Successful exploitation could cause an application that implements the JDK to fail, denying service to legitimate users.


72. Galerie ShowGallery.PHP SQL Injection Vulnerability
BugTraq ID: 15313
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15313
Summary:
Galerie is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


73. CHFN User Modification Privilege Escalation Vulnerability
BugTraq ID: 15314
Remote: No
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15314
Summary:
chfn is prone to a privilege escalation vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

A local attacker can exploit this vulnerability to escalate privileges to that of the superuser account.

74. Cerberus Helpdesk Information Disclosure Vulnerability
BugTraq ID: 15315
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15315
Summary:
Cerberus Helpdesk is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary email attachments of other users in the security context of the Web server process.  Information obtained may aid in further attacks against the underlying system; other attacks are also possible.


75. Clam Anti-Virus ClamAV TNEF File Handling Denial Of Service Vulnerability
BugTraq ID: 15316
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15316
Summary:
ClamAV is prone to a denial of service vulnerability. This is due to a failure in the application to handle malformed TNEF files.

Exploitation could cause the application to enter an infinite loop, resulting in a denial of service.


76. Clam Anti-Virus ClamAV CAB File Handling Denial Of Service Vulnerability
BugTraq ID: 15317
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15317
Summary:
ClamAV is prone to a denial of service vulnerability. This is due to a failure in the application to handle malformed CAB files.

Exploitation could cause the application to enter an infinite loop, resulting in a denial of service.


77. Clam Anti-Virus ClamAV FSG File Handling Buffer Overflow Vulnerability
BugTraq ID: 15318
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15318
Summary:
ClamAV is prone to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.

This issue occurs when the application attempts to handle FSG files.

Exploitation of this issue could allow attacker-supplied machine code to be executed in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.

78. GpsDrive Friendsd Remote Format String Vulnerability
BugTraq ID: 15319
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15319
Summary:
GpsDrive is prone to a remote format string vulnerability.  A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution.  This can result in unauthorized remote access.


79. Acme Thttpd Insecure Temporary File Creation Vulnerability
BugTraq ID: 15320
Remote: No
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15320
Summary:
thttpd creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to overwrite files in the context of the Web server process.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.


80. IBM Lotus Domino Multiple Vulnerabilities
BugTraq ID: 15321
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15321
Summary:
IBM Lotus Domino is prone to multiple vulnerabilities.  Some of these issues can be exploited to trigger a crash, however, some unspecified issues with unknown impacts have also been identified.

These issues affect Lotus Domino versions prior to 6.5.4 Fix Pack 2.

81. PunBB/Blog:CMS Image Upload HTML Injection Vulnerability
BugTraq ID: 15322
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15322
Summary:
PunBB and Blog:CMS are prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is only present when using the Microsoft Internet Explorer Web browser.


82. IBM AIX SWCONS Local Buffer Overflow Vulnerability
BugTraq ID: 15323
Remote: No
Date Published: 2005-11-03
Relevant URL: http://www.securityfocus.com/bid/15323
Summary:
IBM AIX swcons is prone to a local buffer overflow vulnerability.

If the affected utility has setuid-superuser privileges, then a successful attack allows arbitrary machine code execution with superuser privileges.

83. JPortal Multiple SQL Injection Vulnerabilities
BugTraq ID: 15324
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15324
Summary:
JPortal is prone to multiple SQL injection vulnerabilities. These are due to a lack of proper sanitization of user-supplied input before being used in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

84. Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
BugTraq ID: 15325
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15325
Summary:
A remote denial of service vulnerability affects Apache Tomcat. This issue is due to a failure of the application to efficiently handle multiple directory listing requests.

Once this issue has been triggered, the application fails to serve further requests to legitimate users until the Tomcat processes have been restarted.

An attacker may leverage this issue to trigger a denial of service condition in the affected software.

85. PunBB/BLOG:CMS Origin Spoofing Vulnerability
BugTraq ID: 15326
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15326
Summary:
PunBB and Blog:CMS allow attackers to hide addresses using the X_FORWARDED_FOR field in the HTTP header.

These applications accept the values supplied by users in HTTP headers as the originating IP address of a request.  It is possible for a remote host to supply a fake IP address in the environment variable that would obscure the origin on the request.

86. cPanel Chat Message Field HTML Injection Vulnerability
BugTraq ID: 15327
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15327
Summary:
cPanel is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

It should be noted that the attacker will most likely need a cPanel account to exploit this vulnerability.


87. PunBB/BLOG:CMS Unspecified Information Disclosure Vulnerability
BugTraq ID: 15328
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15328
Summary:
PunBB and Blog:CMS are prone to an unspecified information disclosure vulnerability.

Very little information is available on this vulnerability.  This BID will be updated as further information becomes available.

88. Ocean12 ASP Calendar Manager Authentication Bypass Vulnerability
BugTraq ID: 15329
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15329
Summary:
Ocean12 ASP Calendar Manager is prone to an authentication bypass vulnerability. This is due to to an access validation error in the application.

The application does properly verify access privileges and allows the attacker to gain access to restricted data.

Version 1.01  is affected; other versions may also be vulnerable.


89. Ocean12 ASP Calendar Manager SQL Injection Vulnerability
BugTraq ID: 15330
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15330
Summary:
Ocean12 ASP Calendar Manager is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


90. Multiple Vendor Web Browser Cookie Hostname Handling Weakness
BugTraq ID: 15331
Remote: Yes
Date Published: 2005-11-04
Relevant URL: http://www.securityfocus.com/bid/15331
Summary:
Multiple Web browsers are susceptible to a cookie hostname handling weakness that potentially discloses sensitive information. This issue is due to a failure of the Web browsers to properly ensure that cookies are properly associated to domain names.

This issue presents itself when the computer running the affected Web browser has the DNS resolver library configured with a search path. 

This issue potentially allows remote attackers to gain access to potentially sensitive information stored in browser cookies, aiding them in further attacks. This may also aid attackers in phishing style attacks, by obfuscating the destination of URIs.

It should be noted that this issue is only exploitable if users utilize hostnames that are simultaneously valid regarding existing top level domains, and internally hosted domains.

91. Macromedia Flash Array Index Memory Access Vulnerability
BugTraq ID: 15332
Remote: Yes
Date Published: 2005-11-05
Relevant URL: http://www.securityfocus.com/bid/15332
Summary:
The Flash plug-in is vulnerable to an input validation error that can be reliably exploited to execute arbitrary code.  The vulnerability is due to an input validation error for a critical array index value. 

An attacker can exploit this vulnerability to execute arbitrary code.  The most likely vector of attack is through a malicious SWF file designed to trigger the vulnerability that has been placed on a web site.

Macromedia Flash 6 and 7 are reported affected.

92. ibProArcade User ID SQL Injection Vulnerability
BugTraq ID: 15333
Remote: Yes
Date Published: 2005-11-05
Relevant URL: http://www.securityfocus.com/bid/15333
Summary:
A SQL injection attack due to an input validation error has been reported.  The vulnerability is said to be in the "index.php" scripts on both PowerBoard and vBulletin installations when the module is enabled.  The HTML variable "id" for PowerBoard users and "userid" for vBulletin users is reportedly not properly escaped before it is embedded in a SQL query string.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Suspected bot master busted
By: Robert Lemos
Prosecutors charge a California man with infecting 400,000 computers with bot software and profiting by selling access to the systems and through fraudulent affiliate referrals.
http://www.securityfocus.com/news/11353

2. Hidden DRM code's legitimacy questioned
By: Robert Lemos
Copy protection shipped with music CDs from Sony BMG installs hidden, hard-to-uninstall digital rights management (DRM) software on Windows computers, causing security professionals to charge record labels with dealing in rootkits.
http://www.securityfocus.com/news/11352

3. U.S. makes securing SCADA systems a priority
By: Robert Lemos
Amongst worries that the nation's power systems and utility networks are at risk, the U.S. Department of Homeland Security spins out new initiatives to help companies lock down their control systems.
http://www.securityfocus.com/news/11351

4. Web defacer sentenced, facing deportation 
By: Robert Lemos
After agreeing to plead guilty to defacing an Air Force Web site, Rafael Nu&ntilde;ez-Aponte gets time served, but possible charges regarding leaked NASA documents could be in the wings.
http://www.securityfocus.com/news/11350

5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354

6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348

7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347

8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Analyst, Philadelphia
http://www.securityfocus.com/archive/77/415931

2. [SJ-JOB] Auditor, Charlotte
http://www.securityfocus.com/archive/77/415929

3. [SJ-JOB] Security Researcher, Richland
http://www.securityfocus.com/archive/77/415930

4. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/415909

5. [SJ-JOB] Security Product Manager, Ft. Lauderdale
http://www.securityfocus.com/archive/77/415906

6. [SJ-JOB] Sales Engineer, NYC/NJ/Conn - Metro Area
http://www.securityfocus.com/archive/77/415907

7. [SJ-JOB] Sr. Product Manager, Ft. Lauderdale
http://www.securityfocus.com/archive/77/415908

8. [SJ-JOB] Sr. Security Engineer, Hoboken
http://www.securityfocus.com/archive/77/415904

9. [SJ-JOB] Management, san diego
http://www.securityfocus.com/archive/77/415905

10. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/415702

11. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/415703

12. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/415704

13. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/415699

14. [SJ-JOB] Security Consultant, New York, NY
http://www.securityfocus.com/archive/77/415700

15. [SJ-JOB] Security Consultant, New York, NY
http://www.securityfocus.com/archive/77/415701

16. [SJ-JOB] Security Consultant, Houston Area
http://www.securityfocus.com/archive/77/415689

17. [SJ-JOB] Security Consultant, Boston Area
http://www.securityfocus.com/archive/77/415690

18. [SJ-JOB] Security Consultant, New York, NY
http://www.securityfocus.com/archive/77/415686

19. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/415687

20. [SJ-JOB] Security Consultant, New York Metropolitan Area
http://www.securityfocus.com/archive/77/415685

21. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/415647

22. [SJ-JOB] Security System Administrator, Arlington
http://www.securityfocus.com/archive/77/415653

23. [SJ-JOB] Sr. Security Analyst, Columbus
http://www.securityfocus.com/archive/77/415654

24. [SJ-JOB] Security Consultant, New York, NY
http://www.securityfocus.com/archive/77/415655

25. [SJ-JOB] Security Engineer, Saint Louis
http://www.securityfocus.com/archive/77/415586

26. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/415587

27. [SJ-JOB] Security Auditor, Puget Sound
http://www.securityfocus.com/archive/77/415588

28. [SJ-JOB] Information Assurance Analyst, DC
http://www.securityfocus.com/archive/77/415584

29. [SJ-JOB] Sales Engineer, New York, NY
http://www.securityfocus.com/archive/77/415585

30. [SJ-JOB] Security Researcher, Calgary
http://www.securityfocus.com/archive/77/415538

31. [SJ-JOB] Security Consultant, Ft Meade
http://www.securityfocus.com/archive/77/415536

32. [SJ-JOB] Sales Engineer, Atlanta, GA
http://www.securityfocus.com/archive/77/415537

33. [SJ-JOB] Sales Representative, UK Wide
http://www.securityfocus.com/archive/77/415539

34. [SJ-JOB] Security Consultant, Boston Area
http://www.securityfocus.com/archive/77/415510

35. [SJ-JOB] Security Consultant, New York Metropolitan Area
http://www.securityfocus.com/archive/77/415511

36. [SJ-JOB] Sr. Product Manager, Richland
http://www.securityfocus.com/archive/77/415507

37. [SJ-JOB] Jr. Security Analyst, Las Vegas
http://www.securityfocus.com/archive/77/415508

38. [SJ-JOB] Sr. Security Analyst, Las Vegas
http://www.securityfocus.com/archive/77/415509

39. [SJ-JOB] Security Researcher, Richland
http://www.securityfocus.com/archive/77/415499

40. [SJ-JOB] Sales Engineer, New York City
http://www.securityfocus.com/archive/77/415505

41. [SJ-JOB] Account Manager, San Francisco
http://www.securityfocus.com/archive/77/415501

42. [SJ-JOB] Application Security Architect, Mountain View
http://www.securityfocus.com/archive/77/415502

43. [SJ-JOB] Account Manager, San Francisco
http://www.securityfocus.com/archive/77/415504

44. [SJ-JOB] Sales Representative, Abingdon, Oxfordshire
http://www.securityfocus.com/archive/77/415492

45. [SJ-JOB] Technical Writer, Washington
http://www.securityfocus.com/archive/77/415409

46. [SJ-JOB] Security Researcher, Richland
http://www.securityfocus.com/archive/77/415406

47. [SJ-JOB] Developer, Richland
http://www.securityfocus.com/archive/77/415407

48. [SJ-JOB] Sr. Security Engineer, Richland
http://www.securityfocus.com/archive/77/415408

49. [SJ-JOB] Auditor, Puget Sound Area
http://www.securityfocus.com/archive/77/415404

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Stack Overflow Basics
http://www.securityfocus.com/archive/82/415628

2. Black Hat Federal and Europe CFP and Registration now open
http://www.securityfocus.com/archive/82/415627

3. Vulnerability Assesment tools(Vuln testing tools)
http://www.securityfocus.com/archive/82/414512

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #263
http://www.securityfocus.com/archive/88/415444

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
Need to know what's happening on YOUR network? Symantec DeepSight Analyzer
is a free service that gives you the ability to track and manage attacks.
Analyzer automatically correlates attacks from various Firewall and network
based Intrusion Detection Systems, giving you a comprehensive view of your
computer or general network. Sign up today!

http://www.securityfocus.com/sponsor/Symantec_sf-news_041130