SecurityFocus Newsletter #331
Peter Laborge <[email protected]> Wed, 04 Jan 2006 11:09:17 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #331
----------------------------------------
Sponsored by: Watchfire AppScan 6.0
It's been reported that 75% of websites are vulnerable to attack. That's because hackers know to exploit weaknesses in web applications. Traditional approaches to securing these assets no longer apply. Address Application Security Challenges -- download this white paper today.
https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000003SsZ
------------------------------------------------------------------
I. FRONT AND CENTER
1. Zero-day holiday
II. BUGTRAQ SUMMARY
1. SimpBook Guestbook HTML Injection Vulnerability
2. Sun Solaris PC NetLink Insecure Permissions Vulnerability
3. Golden FTP Server APPE Command Buffer Overflow Vulnerability
4. Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
5. Cerberus Helpdesk Multiple Input Validation Vulnerabilities
6. Dev Web Management System Multiple Input Validation Vulnerabilities
7. TkDiff Insecure Temporary File Creation Vulnerability
8. Debian DHIS-TOOLS-DNS Insecure Temporary File Creation Vulnerability
9. BZFlag Unterminated Callsign Denial Of Service Vulnerability
10. Hitachi Business Logic Multiple Input Validation Vulnerabilities
11. IceWarp Universal WebMail Multiple Input Validation Vulnerabilities
12. Microsoft Internet Explorer HTML Parsing Denial of Service Vulnerabilities
13. Day Communique Search Cross-Site Scripting Vulnerability
14. FatWire UpdateEngine Multiple Cross-Site Scripting Vulnerabilities
15. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
16. Juniper NetScreen-Security Manager Remote Denial of Service Vulnerability
17. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
18. PHPSurveyor SID Parameter SQL Injection Vulnerability
19. Koobi BBCode URL Tag Script Injection Vulnerability
20. Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
21. PHPDocumentor Remote and Local File Include Vulnerabilities
22. GMailSite Cross-Site Scripting Vulnerability
23. MyBB Globa.PHP Cookie Data SQL Injection Vulnerability
24. TinyMCE Compressor Multiple Vulnerabilities
25. TUGZip ARJ Archive Filename Handling Buffer Overflow Vulnerability
26. Web Wiz Multiple Products SQL Injection Vulnerability
27. VMWare ESX Server Management Interface Unspecified Code Execution Vulnerability
28. Gentoo Linux XnView Insecure RPATH Vulnerability
29. PHPBB Multiple Unspecified Remote Input Validation Vulnerabilities
30. PTnet IRCD Remote Denial of Service Vulnerability
31. Ades Design AdesGuestbook Read Script Cross-Site Scripting Vulnerability
32. OOApp Guestbook Home Script Cross-Site Scripting Vulnerability
33. iPei Guestbook Index.PHP Cross-Site Scripting Vulnerability
34. ImageMagick Image Filename Remote Command Execution Vulnerability
35. Kayako SupportSuite Multiple Cross-Site Scripting Vulnerabilities
36. MTink Home Environment Variable Buffer Overflow Vulnerability
37. MyBB Print Thread Script HTML Injection Vulnerability
38. MyBB File Upload SQL Injection Vulnerability
39. Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
40. Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
41. Blackberry Enterprise Server Router SRP Packet Denial Of Service Vulnerability
42. PHPDocumentor Forum Lib Variable Cross-Site Scripting Vulnerability
III. SECURITYFOCUS NEWS
1. Data security moves front and center in 2005
2. Sober virus scares up child-porn confession
3. Researchers: Flaw auctions would improve security
4. eBay pulls vulnerability auction
5. Skype under scrutiny for bugs
6. Say hello to the Skype Trojan
7. Shared music abuse bug hits iTunes
8. US cybersecurity all at sea
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sr. Security Engineer, Dublin
2. [SJ-JOB] Technical Writer, Columbia
3. [SJ-JOB] Security Engineer, Dublin
4. [SJ-JOB] Sales Engineer, Any City
5. [SJ-JOB] Sr. Security Analyst, Dorking
6. [SJ-JOB] Security Consultant, Baroda
7. [SJ-JOB] Security Engineer, San Francisco
8. [SJ-JOB] Sr. Security Engineer, San Antonio
9. [SJ-JOB] Jr. Security Analyst, San Antonio
10. [SJ-JOB] Sr. Security Analyst, San Antonio
11. [SJ-JOB] Manager, Information Security, South Denver
12. [SJ-JOB] Security Engineer, Fredericton
13. [SJ-JOB] Sales Representative, Washington DC
14. [SJ-JOB] Instructor, Greater London
15. [SJ-JOB] Sales Representative, Toronto
16. [SJ-JOB] Sales Representative, Greater London
17. [SJ-JOB] Security Consultant, Toronto
18. [SJ-JOB] Forensics Engineer, Minneapolis
19. [SJ-JOB] Security Consultant, Kirkland
20. [SJ-JOB] Security Researcher, Tel Aviv
21. [SJ-JOB] Sales Engineer, Austin
22. [SJ-JOB] Security Engineer, Washington - Union Station Area
23. [SJ-JOB] Security Consultant, Kent
24. [SJ-JOB] Security Consultant, Anywhere
25. [SJ-JOB] Sales Representative, Superior
V. INCIDENTS LIST SUMMARY
1. Strange SMTP sessions with 'helo=<large negative number>' syntax
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Black Hat Federal and Europe Call for Papers
VII. MICROSOFT FOCUS LIST SUMMARY
1. Security events with same timestamp
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Zero-day holiday
By Kelly Martin
A few hundred million Windows XP machines lay vulnerable on the Web today, a week after a zero-day exploit was discovered. Meanwhile, new approaches and ideas from the academic world - that focus exclusively on childen - may give us hope for the future after all.
http://www.securityfocus.com/columnists/377
II. BUGTRAQ SUMMARY
--------------------
1. SimpBook Guestbook HTML Injection Vulnerability
BugTraq ID: 16058
Remote: Yes
Date Published: 2005-12-26
Relevant URL: http://www.securityfocus.com/bid/16058
Summary:
SimpBook is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
2. Sun Solaris PC NetLink Insecure Permissions Vulnerability
BugTraq ID: 16059
Remote: No
Date Published: 2005-12-26
Relevant URL: http://www.securityfocus.com/bid/16059
Summary:
PC NetLink is susceptible to an insecure permissions vulnerability. This issue is due to a flaw in the 'slsadmin' and 'slsmgr' scripts.
This issue allows local attackers to improperly access files on the local filesystem. Malicious users may write to the local filesystem with the privileges of the user running the affected scripts.
3. Golden FTP Server APPE Command Buffer Overflow Vulnerability
BugTraq ID: 16060
Remote: Yes
Date Published: 2005-12-26
Relevant URL: http://www.securityfocus.com/bid/16060
Summary:
Golden FTP Server is prone to a remote buffer overflow vulnerability.
An attacker can exploit this issue to crash the server resulting in a denial of service to legitimate users. Arbitrary code execution may also be possible, which may facilitate a complete compromise of the underlying system.
4. Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16061
Remote: No
Date Published: 2005-12-26
Relevant URL: http://www.securityfocus.com/bid/16061
Summary:
Bugzilla creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
5. Cerberus Helpdesk Multiple Input Validation Vulnerabilities
BugTraq ID: 16062
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16062
Summary:
Cerberus Helpdesk is prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues are the result of inadequate validation of user-supplied input that will be included in site output or in SQL queries.
The cross-site scripting vulnerability may permit a remote attacker to steal cookie-based authentication credentials from legitimate users. Successful exploitation of SQL injection vulnerabilities could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
6. Dev Web Management System Multiple Input Validation Vulnerabilities
BugTraq ID: 16063
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16063
Summary:
Dev Web Management System is prone to multiple input validation vulnerabilities. These issues may allow SQL injection and cross-site scripting attacks.
Dev Web Management System versions 1.5 and earlier are prone to these issues.
7. TkDiff Insecure Temporary File Creation Vulnerability
BugTraq ID: 16064
Remote: No
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16064
Summary:
TkDiff creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
TkDiff 4.1 and prior versions are vulnerable to this issue.
8. Debian DHIS-TOOLS-DNS Insecure Temporary File Creation Vulnerability
BugTraq ID: 16065
Remote: No
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16065
Summary:
Debian dhis-tools-dns creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
dhis-tools-dns 5.0 is vulnerable to this issue.
9. BZFlag Unterminated Callsign Denial Of Service Vulnerability
BugTraq ID: 16066
Remote: Yes
Date Published: 2005-12-25
Relevant URL: http://www.securityfocus.com/bid/16066
Summary:
BZFlag is prone to a denial of service vulnerability.
This vulnerability may be triggered by a malformed callsign message.
10. Hitachi Business Logic Multiple Input Validation Vulnerabilities
BugTraq ID: 16067
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16067
Summary:
Hitachi Business Logic is prone to multiple input validation vulnerabilities. These issues can lead to SQL injection, cross-site scripting and HTTP response splitting attacks.
Hitachi Business Logic - Container versions 1-00 to 2-06 for Windows and Business Logic - Container versions 1-01 through 2-00 for AIX are vulnerable to these issues.
As specific details about these issues are not currently available, further information cannot be provided. This BID will be updated when more details are available.
11. IceWarp Universal WebMail Multiple Input Validation Vulnerabilities
BugTraq ID: 16069
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16069
Summary:
IceWarp Universal WebMail is prone to multiple input validation vulnerabilities. Deerfield VisNetic Mail Server and Merak Mail Server integrate IceWarp Universal WebMail into their suites.
An attacker can exploit these issues to include arbitrary local or remote files containing malicious PHP code and execute it in the context of the Web server process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Additionally, an attacker can exploit these issues to obtain the contents of local files.
Merak Mail Server 8.3.0.r and VisNetic MailServer 8.3.0 build 1 are affected by these issues.
12. Microsoft Internet Explorer HTML Parsing Denial of Service Vulnerabilities
BugTraq ID: 16070
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16070
Summary:
Microsoft Internet Explorer is affected by multiple denial of service vulnerabilities.
An attacker may exploit these issues by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
13. Day Communique Search Cross-Site Scripting Vulnerability
BugTraq ID: 16072
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16072
Summary:
Day Communique is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Day Communique version 4 and earlier are affected.
14. FatWire UpdateEngine Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16073
Remote: Yes
Date Published: 2005-12-27
Relevant URL: http://www.securityfocus.com/bid/16073
Summary:
FatWire UpdateEngine is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
These issues affect versions 6.2 and prior.
15. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
BugTraq ID: 16074
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16074
Summary:
Microsoft Windows WMF graphics rendering engine is affected by a remote code execution vulnerability. This issue affects the 'SetAbortProc' function.
The problem presents itself when a user views a malicious WMF formatted file, triggering the vulnerability when the engine attempts to parse the file.
The issue may be exploited remotely or by a local attacker. Any remote code execution that occurs will be with the privileges of the user viewing a malicious image. An attacker may gain SYSTEM privileges if an administrator views the malicious file.
Local code execution may facilitate a complete compromise.
16. Juniper NetScreen-Security Manager Remote Denial of Service Vulnerability
BugTraq ID: 16075
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16075
Summary:
Juniper NSM is prone to a remote denial of service vulnerability.
A remote attacker may trigger a crash or hang in the server and deny service to legitimate users. It should be noted that the application ships with a watchdog service that periodically restarts the services.
NSM 2004 FP2 and FP3 are reportedly vulnerable.
17. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 16076
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16076
Summary:
The Ethereal GTP protocol dissector is prone to remotely exploitable denial of service vulnerability.
Successful exploitation will cause a denial of service condition in the Ethereal application.
Further details are not currently available. This BID will be updated as more information is disclosed.
18. PHPSurveyor SID Parameter SQL Injection Vulnerability
BugTraq ID: 16077
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16077
Summary:
PHPSurveyor is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
PHPSurveyor 0.99 is vulnerable to this issue.
19. Koobi BBCode URL Tag Script Injection Vulnerability
BugTraq ID: 16078
Remote: Yes
Date Published: 2005-12-28
Relevant URL: http://www.securityfocus.com/bid/16078
Summary:
Koobi is prone to a script injection vulnerability.
An attacker can nest BBCode URL tags to trigger this issue and execute arbitrary code in a user's browser.
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.
Koobi 5 is reportedly prone to this vulnerability.
20. Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
BugTraq ID: 16079
Remote: Yes
Date Published: 2005-12-29
Relevant URL: http://www.securityfocus.com/bid/16079
Summary:
Microsoft Internet Explorer is affected by a denial of service vulnerability.
An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
21. PHPDocumentor Remote and Local File Include Vulnerabilities
BugTraq ID: 16080
Remote: Yes
Date Published: 2005-12-29
Relevant URL: http://www.securityfocus.com/bid/16080
Summary:
phpDocumentor is affected by remote and local file include vulnerabilities.
An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
phpDocumentor 1.3.0 RC4 and prior versions are vulnerable to these issues.
22. GMailSite Cross-Site Scripting Vulnerability
BugTraq ID: 16081
Remote: Yes
Date Published: 2005-12-29
Relevant URL: http://www.securityfocus.com/bid/16081
Summary:
GMailSite is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
GMailSite 1.0.4 and prior versions are affected by this issue. GFHost 0.4.2 and prior versions are also vulnerable.
23. MyBB Globa.PHP Cookie Data SQL Injection Vulnerability
BugTraq ID: 16082
Remote: Yes
Date Published: 2005-12-29
Relevant URL: http://www.securityfocus.com/bid/16082
Summary:
MyBB is prone to an SQL injection vulnerability.
The vulnerability presents itself when user-supplied input via cookie data is passed to the 'admin/globa.php' script.
Successful exploitation can allow an attacker to bypass authentication and gain administrative access to a site. Other attacks may also be possible.
MyBB 1.0 is reportedly vulnerable.
24. TinyMCE Compressor Multiple Vulnerabilities
BugTraq ID: 16083
Remote: Yes
Date Published: 2005-12-29
Relevant URL: http://www.securityfocus.com/bid/16083
Summary:
TinyMCE Compressor is prone to multiple remote vulnerabilities.
The script is affected by a file disclosure vulnerability. Information gathered through the exploitation of this issue may aid in other attacks.
The script is also affected by multiple cross-site scripting and HTML injection vulnerabilities. An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
TinyMCE Compressor 1.0.5 and prior versions are vulnerable to these issues.
25. TUGZip ARJ Archive Filename Handling Buffer Overflow Vulnerability
BugTraq ID: 16084
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16084
Summary:
TUGZip is prone to a buffer overflow vulnerability.
This vulnerability could be exploited to execute arbitrary code in the context of the user who extracts a malicious archive.
TUGZip 3.4.0.0 is reportedly vulnerable. Other versions may be affected as well.
26. Web Wiz Multiple Products SQL Injection Vulnerability
BugTraq ID: 16085
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16085
Summary:
Multiple Products by Web Wiz are prone to an SQL injection vulnerability.
Successful exploitation can allow an attacker to bypass authentication and gain unauthorized access to a site.
Attacks may also result in disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97 are vulnerable to this issue. Prior versions are reportedly affected as well.
27. VMWare ESX Server Management Interface Unspecified Code Execution Vulnerability
BugTraq ID: 16086
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16086
Summary:
VMWare ESX Server is prone to an unspecified remote code execution vulnerability. This issue exists in the Management Interface.
28. Gentoo Linux XnView Insecure RPATH Vulnerability
BugTraq ID: 16087
Remote: No
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16087
Summary:
Gentoo Linux XnView is susceptible to an insecure RPATH vulnerability.
This issue may allow local attackers to execute code with the privileges of a user that executes the application.
Gentoo Linux XnView versions prior to 1.70-r1 are vulnerable to this issue.
29. PHPBB Multiple Unspecified Remote Input Validation Vulnerabilities
BugTraq ID: 16088
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16088
Summary:
phpBB is prone to multiple unspecified vulnerabilities.
The following security vulnerabilities were identified by the vendor:
The application is affected by a cross-site scripting vulnerability.
The application is also prone to a bbcode script injection vulnerability.
phpBB versions prior to 2.0.19 are vulnerable.
30. PTnet IRCD Remote Denial of Service Vulnerability
BugTraq ID: 16089
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16089
Summary:
PTnet IRCD is prone to a remote denial of service vulnerability.
A remote attacker may deny service to legitimate users by opening restricted channels.
PTnet IRCD 1.5 and 1.6 are reportedly vulnerable to this issue.
31. Ades Design AdesGuestbook Read Script Cross-Site Scripting Vulnerability
BugTraq ID: 16090
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16090
Summary:
Ades Design AdesGuestbook is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
32. OOApp Guestbook Home Script Cross-Site Scripting Vulnerability
BugTraq ID: 16091
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16091
Summary:
OOApp Guestbook is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
33. iPei Guestbook Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16092
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16092
Summary:
iPei Guestbook is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
iPei Guestbook versions 1.7 and earlier are prone to this issue.
34. ImageMagick Image Filename Remote Command Execution Vulnerability
BugTraq ID: 16093
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16093
Summary:
ImageMagick is prone to a remote shell command execution vulnerability.
Successful exploitation can allow arbitrary commands to be executed in the context of the affected user. It should be noted that this issue could also be exploited through other applications that use ImageMagick as the default image viewer.
ImageMagick 6.2.4.5 is reportedly vulnerable. Other versions may be affected as well.
35. Kayako SupportSuite Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16094
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16094
Summary:
Kayako SupportSuite is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
These issues affect versions 3.00.26 and prior.
36. MTink Home Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 16095
Remote: No
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16095
Summary:
A buffer overflow vulnerability affects MTink. This vulnerability may permit local attackers to execute arbitrary code with superuser privileges.
37. MyBB Print Thread Script HTML Injection Vulnerability
BugTraq ID: 16096
Remote: Yes
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16096
Summary:
MyBB (MyBulletinBoard) is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
38. MyBB File Upload SQL Injection Vulnerability
BugTraq ID: 16097
Remote: Yes
Date Published: 2005-12-31
Relevant URL: http://www.securityfocus.com/bid/16097
Summary:
MyBB (MyBulletinBoard) is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
39. Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
BugTraq ID: 16098
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16098
Summary:
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks. This issue affects the Attachment Service and may be triggered by a malformed TIFF attachment.
The issue is reportedly caused by a heap-based buffer overflow. The vendor has stated that this issue will result in a denial of service, and it is therefore not believed that the issue is exploitable beyond a denial of service. However, other sources indicate that this issue may allow arbitrary code execution to occur upon successful exploitation. Specific details regarding code execution are not currently available and have not been confirmed. This record will be updated when more information is available.
40. Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
BugTraq ID: 16099
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16099
Summary:
Blackberry Handheld devices are prone to a denial of service attack. The embedded Web browser will stop responding due to a dialog box that has not been properly dismissed when handling a malformed JAD (Java Application Description) file.
41. Blackberry Enterprise Server Router SRP Packet Denial Of Service Vulnerability
BugTraq ID: 16100
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16100
Summary:
The Blackberry Enterprise Server Router component is prone to a denial of service vulnerability.
This vulnerability may be triggered by sending malformed SRP (Server Routing Protocol) packets to the Router. This could only be exploited by an attacker who can communicate with the Router.
42. PHPDocumentor Forum Lib Variable Cross-Site Scripting Vulnerability
BugTraq ID: 16101
Remote: Yes
Date Published: 2005-12-30
Relevant URL: http://www.securityfocus.com/bid/16101
Summary:
phpDocumentor is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Data security moves front and center in 2005
By: Robert Lemos
YEAR IN REVIEW: High-profile data breaches leaked more than 50 million database records in the United States, while phishing, bot networks, and targeted Trojan horses compromised millions of PCs worldwide.
http://www.securityfocus.com/news/11366
2. Sober virus scares up child-porn confession
By: Robert Lemos
A 20-year-old German man turned himself in to authorities after receiving a copy of the mass-mailing virus, which arrives attached to an e-mail message claiming that law enforcement is investigating the recipient.
http://www.securityfocus.com/news/11365
3. Researchers: Flaw auctions would improve security
By: Robert Lemos
Online auctioneer eBay pulls a seller's second attempt to make money from a vulnerability in Microsoft Excel as security professionals argue that a free market in vulnerabilities could improve software security.
http://www.securityfocus.com/news/11364
4. eBay pulls vulnerability auction
By: Robert Lemos
The online auction giant shuts down the bidding for a vulnerability in Microsoft's Excel spreadsheet program, saying that the sale of flaw research violates the site's policy against encouraging illegal activity.
http://www.securityfocus.com/news/11363
5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354
6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348
7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347
8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Engineer, Dublin
http://www.securityfocus.com/archive/77/420697
2. [SJ-JOB] Technical Writer, Columbia
http://www.securityfocus.com/archive/77/420693
3. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/420694
4. [SJ-JOB] Sales Engineer, Any City
http://www.securityfocus.com/archive/77/420695
5. [SJ-JOB] Sr. Security Analyst, Dorking
http://www.securityfocus.com/archive/77/420636
6. [SJ-JOB] Security Consultant, Baroda
http://www.securityfocus.com/archive/77/420632
7. [SJ-JOB] Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/420559
8. [SJ-JOB] Sr. Security Engineer, San Antonio
http://www.securityfocus.com/archive/77/420561
9. [SJ-JOB] Jr. Security Analyst, San Antonio
http://www.securityfocus.com/archive/77/420558
10. [SJ-JOB] Sr. Security Analyst, San Antonio
http://www.securityfocus.com/archive/77/420560
11. [SJ-JOB] Manager, Information Security, South Denver
http://www.securityfocus.com/archive/77/420557
12. [SJ-JOB] Security Engineer, Fredericton
http://www.securityfocus.com/archive/77/420494
13. [SJ-JOB] Sales Representative, Washington DC
http://www.securityfocus.com/archive/77/420490
14. [SJ-JOB] Instructor, Greater London
http://www.securityfocus.com/archive/77/420495
15. [SJ-JOB] Sales Representative, Toronto
http://www.securityfocus.com/archive/77/420489
16. [SJ-JOB] Sales Representative, Greater London
http://www.securityfocus.com/archive/77/420491
17. [SJ-JOB] Security Consultant, Toronto
http://www.securityfocus.com/archive/77/420477
18. [SJ-JOB] Forensics Engineer, Minneapolis
http://www.securityfocus.com/archive/77/420471
19. [SJ-JOB] Security Consultant, Kirkland
http://www.securityfocus.com/archive/77/420472
20. [SJ-JOB] Security Researcher, Tel Aviv
http://www.securityfocus.com/archive/77/420470
21. [SJ-JOB] Sales Engineer, Austin
http://www.securityfocus.com/archive/77/420454
22. [SJ-JOB] Security Engineer, Washington - Union Station Area
http://www.securityfocus.com/archive/77/420452
23. [SJ-JOB] Security Consultant, Kent
http://www.securityfocus.com/archive/77/420453
24. [SJ-JOB] Security Consultant, Anywhere
http://www.securityfocus.com/archive/77/420451
25. [SJ-JOB] Sales Representative, Superior
http://www.securityfocus.com/archive/77/420475
V. INCIDENTS LIST SUMMARY
---------------------------
1. Strange SMTP sessions with 'helo=<large negative number>' syntax
http://www.securityfocus.com/archive/75/420405
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Black Hat Federal and Europe Call for Papers
http://www.securityfocus.com/archive/82/420435
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Security events with same timestamp
http://www.securityfocus.com/archive/88/420316
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
Sponsored by: Watchfire AppScan 6.0
It's been reported that 75% of websites are vulnerable to attack. That's because hackers know to exploit weaknesses in web applications. Traditional approaches to securing these assets no longer apply. Address Application Security Challenges -- download this white paper today.
https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000003SsZ