SecurityFocus Newsletter #335

Peter Laborge <[email protected]> Wed, 01 Feb 2006 11:41:50 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #335
----------------------------------------

This Issue is Sponsored By: CipherTrust

Messaging Security: It's more than just e-mail.
Today's businesses are struggling with a new breed of threats to more than just their e-mail environments, and despite best efforts, hackers and spammers continue to exploit new attack vectors to break into enterprise networks. Please join CipherTrust to discuss best practices and approaches to comprehensive messaging security. Register Now in a city near you.

http://www.ciphertrust.com/seminars/sf

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Google's data minefield
        2. Nmap 4.00 with Fyodor
        3. Malicious Malware: attacking the attackers, part 1
II.   BUGTRAQ SUMMARY
        1. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        2. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
        3. ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
        4. Macromedia Flash Array Index Memory Access Vulnerability
        5. Sylpheed LDIF Import Remote Buffer Overflow Vulnerability
        6. MiniGal MG2 Image Gallery Name Field HTML Injection Vulnerability
        7. Ashwebstudio Ashnews Cross-Site Scripting Vulnerability
        8. Nuked-klaN Index.PHP Cross-Site Scripting Vulnerability
        9. CRE Loaded Files.PHP Access Validation Vulnerability
        10. sPaiz-Nuke Modules.PHP Cross-Site Scripting Vulnerability
        11. Joshua Chamas Crypt::SSLeay Perl Module Insecure Entropy Source Vulnerability
        12. GDB Multiple Vulnerabilities
        13. Net-SNMP Fixproc Insecure Temporary File Creation Vulnerability
        14. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
        15. Drupal Image Upload HTML Injection Vulnerability
        16. Drupal View User Profile Authorization Bypass Vulnerability
        17. Drupal Submitted Content HTML Injection Vulnerability
        18. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
        19. Computer Associates iTechnology iGateway Service Content-Length Heap Overflow Vulnerability
        20. Nullsoft SHOUTcast File Request Format String Vulnerability
        21. ImageMagick File Name Handling Remote Format String Vulnerability
        22. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
        23. Convert-UUlib Perl Module Buffer Overflow Vulnerability
        24. Exiv2 Corrupted EXIF Data Denial Of Service Vulnerability
        25. Elido Face Control Multiple Directory Traversal Vulnerabilities
        26. Shareaza Multiple Remote Integer Overflow Vulnerabilities
        27. OpenSSH SCP Shell Command Execution Vulnerability
        28. Wzdftpd SITE Command Arbitrary Command Execution Vulnerability
        29. YahooPOPS! Multiple Remote Buffer Overflow Vulnerabilities
        30. PHP File Upload GLOBAL Variable Overwrite Vulnerability
        31. Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
        32. PHP Parse_Str Register_Globals Activation Weakness
        33. PHP PHPInfo Cross-Site Scripting Vulnerability
        34. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        35. AOL Client Software Unspecified Local Privilege Escalation Vulnerability
        36. Adobe Multiple Unspecified Local Privilege Escalation Vulnerabilities
        37. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        38. Invision Power Board Portal Plugin Index.PHP SQL Injection Vulnerability
        39. Macromedia eLicensing Client Activation Code Local Privilege Escalation Vulnerability
        40. Cisco VPN 3000 Concentrator Malformed HTTP Packet Remote Denial of Service Vulnerability
        41. MailEnable Professional EXAMINE Command Remote Denial of Service Vulnerability
        42. Calendarix Multiple SQL Injection Vulnerabilities
        43. SZUserMgnt Username Parameter SQL Injection Vulnerability
        44. Microsoft Internet Explorer Dialog Manipulation Vulnerability
        45. Microsoft Windows Asynchronous Procedure Call Local Privilege Escalation Vulnerability
        46. Microsoft Windows Embedded Web Font Buffer Overflow Vulnerability
        47. Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
        48. Microsoft Outlook / Microsoft Exchange TNEF Decoding Remote Code Execution Vulnerability
        49. MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
        50. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
        51. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
        52. Microsoft Internet Explorer Flash ActionScript JScript Handling Denial of Service Vulnerability
        53. FarsiNews Loginout.PHP Remote File Include Vulnerability
        54. EMC Legato Networker Multiple Remote Vulnerabilities
        55. Multiple Vendor TCP Timestamp PAWS Remote Denial Of Service Vulnerability
        56. Oracle January Security Update Multiple Vulnerabilities
        57. ht://Dig Config Parameter Cross-Site Scripting Vulnerability
        58. OpenSSH GSSAPI Credential Disclosure Vulnerability
        59. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
        60. SCO UnixWare UIDAdmin Local Buffer Overflow Vulnerability
        61. Lynx URI Handlers Arbitrary Command Execution Vulnerability
        62. Blackboard Learning System Access Validation Vulnerability
        63. Mail-Audit Insecure Temporary File Creation Vulnerability
        64. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
        65. OpenSSL Insecure Protocol Negotiation Weakness
        66. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
        67. Communigate Pro Server LDAP Denial of Service Vulnerability
        68. EasyCMS Multiple Cross-Site Scripting Vulnerabilities
        69. phpBB Rlink Module Rlink.PHP Cross-Site Scripting Vulnerability
        70. PunctWeb MyCO Name Field HTML Injection Vulnerability
        71. MyBB Index.PHP Referrer Cookie SQL Injection Vulnerability
        72. Cerberus Helpdesk Clients.PHP Cross-Site Scripting Vulnerability
        73. AshWebStudio AshNews Remote File Include Vulnerability
        74. BrowserCRM Results.PHP Cross-Site Scripting Vulnerability
        75. GNU Mailman Attachment Scrubber UTF8 Filename Denial Of Service Vulnerability
        76. Daffodil CRM Userlogin.ASP SQL Injection Vulnerability
        77. MyDNS DNS Query Denial Of Service Vulnerability
        78. Gzip Zgrep Arbitrary Command Execution Vulnerability
        79. BZip2 CHMod File Permission Modification Race Condition Weakness
        80. Pioneers Chat Buffer Denial Of Service Vulnerability
        81. Edgewall Software Trac HTML WikiProcessor Wiki Content HTML Injection Vulnerability
        82. Unalz Archive Filename Buffer Overflow Vulnerability
        83. Soti Pocket Controller-Professional Remote Command Execution Vulnerability
        84. PmWiki Multiple Input Validation Vulnerabilities
        85. Arescom Net DSL 1000 telnet Denial of Service Vulnerability
        86. Mozilla Firefox XBL -MOZ-BINDING Property Cross-Domain Scripting Vulnerability
        87. GIT Remote Buffer Overflow Vulnerability
        88. MiniNuke Multiple Input Validation Vulnerabilities
        89. Edgewall Software Trac Search Module SQL Injection Vulnerability
        90. Linux Kernel Multiple Security Vulnerabilities
        91. UebiMiau HTML Email HTML Injection Vulnerability
        92. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
        93. Phpclanwebsite Multiple Input Validation Vulnerabilities
        94. Phpclanwebsite BBCode IMG Tag Script Injection Vulnerability
        95. GNU Mailman Large Date Data Denial Of Service Vulnerability
        96. Eterm LibAST Library Local Buffer Overflow Vulnerability
        97. Paros HSQLDB Remote Authentication Bypass Vulnerability
        98. AZ Bulletin Board Post.PHP HTML Injection Vulnerabilities
        99. Microsoft Internet Explorer ActiveX Control Kill Bit Bypass Vulnerability
        100. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
III.  SECURITYFOCUS NEWS
        1. Good worms back on the agenda
        2. Researchers: Rootkits headed for BIOS
        3. Zero-day details underscore criticism of Oracle
        4. Bot herder pleads guilty to 'zombie' sales
        5. Skype under scrutiny for bugs
        6. Say hello to the Skype Trojan
        7. Shared music abuse bug hits iTunes
        8. US cybersecurity all at sea
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Security Architect, Alexandria
        2. [SJ-JOB] Security System Administrator, San Francisco
        3. [SJ-JOB] Sr. Security Engineer, North Bergen
        4. [SJ-JOB] Security Consultant, Bangalore
        5. [SJ-JOB] Security Engineer, Reston
        6. [SJ-JOB] Security Consultant, San Franciso and Irvine
        7. [SJ-JOB] Security Consultant, Atlanta
        8. [SJ-JOB] Security Architect, San Franciso and Irvine
        9. [SJ-JOB] Sales Engineer, Reston
        10. [SJ-JOB] Sales Engineer, Reston
        11. [SJ-JOB] Sales Engineer, Herndon
        12. [SJ-JOB] Sales Engineer, Charlotte
        13. [SJ-JOB] Developer, Charlotte
        14. [SJ-JOB] Application Security Architect, Eastern Iowa
        15. [SJ-JOB] Sr. Product Manager, San Diego
        16. [SJ-JOB] Product Strategist, San Diego
        17. [SJ-JOB] Sales Representative, Chicago
        18. [SJ-JOB] Sr. Security Engineer, Eastern Iowa
        19. [SJ-JOB] Security System Administrator, Santa Barbara
        20. [SJ-JOB] Certification & Accreditation Engineer, Washington,DC
        21. [SJ-JOB] Security Engineer, Arlington
        22. [SJ-JOB] Security System Administrator, Ft Lauderdale
        23. [SJ-JOB] Security Consultant, Ft Lauderdale
        24. [SJ-JOB] Sales Engineer, San Francisco
        25. [SJ-JOB] Sales Engineer, Salt Lake City
        26. [SJ-JOB] Account Manager, Paramus
        27. [SJ-JOB] Sr. Security Analyst, Boston
        28. [SJ-JOB] Account Manager, New York
        29. [SJ-JOB] Account Manager, Northern CA
        30. [SJ-JOB] Security Engineer, Twin Cities
        31. [SJ-JOB] Security Auditor, Washington
        32. [SJ-JOB] Application Security Engineer, Arlington
        33. [SJ-JOB] Security System Administrator, Arlington
        34. [SJ-JOB] Technology Risk Consultant, Arlington
        35. [SJ-JOB] Database Security Engineer, Arlington
        36. [SJ-JOB] Application Security Engineer, Arlington
        37. [SJ-JOB] Quality Assurance, Silicon Valley
        38. [SJ-JOB] VP / Dir / Mgr engineering, Silicon Valley
        39. [SJ-JOB] Threat Analyst, Calgary
        40. [SJ-JOB] Threat Analyst, Calgary
        41. [SJ-JOB] Threat Analyst, Calgary
        42. [SJ-JOB] Developer, Silicon Valley
        43. [SJ-JOB] Management, Boulder
        44. [SJ-JOB] Developer, Boulder
        45. [SJ-JOB] Quality Assurance, Silicon Valley
        46. [SJ-JOB] Developer, Boulder
        47. [SJ-JOB] Security Auditor, Miami
        48. [SJ-JOB] Security Auditor, Columbus
        49. [SJ-JOB] Auditor, Miami
        50. [SJ-JOB] Auditor, Columbus
        51. [SJ-JOB] Security Engineer, Saint Louis
        52. [SJ-JOB] Jr. Security Analyst, LONDON,KENT
        53. [SJ-JOB] Security Auditor, New York
        54. [SJ-JOB] Auditor, New York
        55. [SJ-JOB] Security Consultant, LONDON-
        56. [SJ-JOB] Application Security Architect, LONDON
        57. [SJ-JOB] Security Consultant, Laval
        58. [SJ-JOB] Sales Engineer, New York
        59. [SJ-JOB] Security Engineer, New York
        60. [SJ-JOB] Sales Engineer, Boston
        61. [SJ-JOB] Application Security Architect, Arlington
        62. [SJ-JOB] Sr. Security Engineer, Oxford
        63. [SJ-JOB] Account Manager, New York
        64. [SJ-JOB] Channel / Business Development, Atlanta
        65. [SJ-JOB] Sales Engineer, NY city area
        66. [SJ-JOB] Sr. Security Engineer, New York City
        67. [SJ-JOB] Forensics Engineer, UK (home-based)
        68. [SJ-JOB] Sales Engineer, Washington
        69. [SJ-JOB] Sr. Security Engineer, Milton Keynes
        70. [SJ-JOB] Sales Representative, Maidstone
        71. [SJ-JOB] Sr. Security Engineer, Washington, DC
        72. [SJ-JOB] Channel / Business Development, Boston
        73. [SJ-JOB] Channel / Business Development, Raleigh
V.    INCIDENTS LIST SUMMARY
        1. wired traffic
        2. Decrease in Threats?
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Google's data minefield
By Mark Rasch
The U.S. government's broad subpoena to search engines effectively seeks to mine the data of the Internet. While Google has resisted the subpoena, there may be little they can do to protect our privacy from many prying eyes.
http://www.securityfocus.com/columnists/383

2. Nmap 4.00 with Fyodor
By Federico Biancuzzi
After more than eight years since its first release in Phrack magazine, Fyodor has announced Nmap 4.00. Curious as usual, Federico Biancuzzi interviewed Fyodor on behalf of SecurityFocus to discuss the new port scanning engine, version detection improvements, and the new stack fingerprinting algorithm under work by the community.
http://www.securityfocus.com/columnists/384

3. Malicious Malware: attacking the attackers, part 1
By Thorsten Holz, Frederic Raynal
This article explores measures to attack those malicious attackers who seek to harm our legitimate systems. The proactive use of exploits and bot networks that fight other bot networks, along with social engineering and attacker techniques are all discussed in an ethical manner. Part one of two.
http://www.securityfocus.com/infocus/1856


II.  BUGTRAQ SUMMARY
--------------------
1. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

It is reported that this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

2. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
BugTraq ID: 16147
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16147
Summary:
A remote buffer overflow vulnerability affects Blue Coat Systems WinProxy. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.

Blue Coat Systems WinProxy version 6.0 is vulnerable to this issue; other versions may also be affected.

3. ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
BugTraq ID: 16406
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16406
Summary:
ZixForum is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

4. Macromedia Flash Array Index Memory Access Vulnerability
BugTraq ID: 15332
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15332
Summary:
The Flash plug-in is vulnerable to an input-validation error that can be reliably exploited to execute arbitrary code. The vulnerability is due to an input-validation error for a critical array index value.

An attacker can exploit this vulnerability to execute arbitrary code. The most likely vector of attack is through a malicious SWF file designed to trigger the vulnerability that has been placed on a website.

Macromedia Flash 6 and 7 are reported affected.

5. Sylpheed LDIF Import Remote Buffer Overflow Vulnerability
BugTraq ID: 15363
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15363
Summary:
Sylpheed is prone to a buffer-overflow vulnerability.

A buffer overflow can occur when an unsuspecting user imports a malicious LFID file into an address book.

Exploitation of this vulnerability may allow an attacker to gain unauthorized access to the computer in the context of the Sylpheed client.

6. MiniGal MG2 Image Gallery Name Field HTML Injection Vulnerability
BugTraq ID: 16428
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16428
Summary:
MG2 Image Gallery is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

7. Ashwebstudio Ashnews Cross-Site Scripting Vulnerability
BugTraq ID: 16426
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16426
Summary:
Ashnews is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

8. Nuked-klaN Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16424
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16424
Summary:
Nuked-klaN is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

9. CRE Loaded Files.PHP Access Validation Vulnerability
BugTraq ID: 16415
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16415
Summary:
CRE Loaded is prone to an access validation vulnerability. This issue is due to a failure in the application to limit access to administrative sections of the application.

An attacker can exploit this vulnerability to overwrite, delete and create files and directories in the context of the Web server process. This may result in a loss of confidentiality. Information obtained may also be used in further attacks.

This issue is reported to affect CRE Loaded version 6.15; other versions may also be vulnerable.

10. sPaiz-Nuke Modules.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16412
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16412
Summary:
sPaiz-Nuke is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

11. Joshua Chamas Crypt::SSLeay Perl Module Insecure Entropy Source Vulnerability
BugTraq ID: 13471
Remote: No
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/13471
Summary:
Crypt::SSLeay is prone to a security vulnerability. Reports indicate that the library employs a file from a world-writable location for its fallback entropy source. The module defaults to this file if a proper entropy source is not set.

If the affected library is using the insecure file as a source of entropy, a local attacker may replace the contents of the file with known text. This known text is then employed to seed cryptographic operations. This may lead to weak cryptographic operations.

12. GDB Multiple Vulnerabilities
BugTraq ID: 13697
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/13697
Summary:
GDB is reportedly affected by multiple vulnerabilities. These issues can allow an attacker to execute arbitrary code and commands on an affected computer. A successful attack may allow the attacker to gain elevated privileges or unauthorized access.

The following specific issues were identified:

- a remote heap-overflow vulnerability when loading malformed object files.
- a local privilege-escalation vulnerability.

GDB 6.3 is reportedly affected by these issues; other versions are likely vulnerable as well. GNU binutils 2.14 and 2.15 are affected by the heap-overflow issue as well.

13. Net-SNMP Fixproc Insecure Temporary File Creation Vulnerability
BugTraq ID: 13715
Remote: No
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/13715
Summary:
A local insecure temporary file-creation vulnerability affects Net-SNMP's fixproc. This issue is due to the utility's failure to securely create temporary files in world-writable locations.

An attacker may leverage this issue to corrupt, write to, or create arbitrary files, as well as execute arbitrary code with the privileges of the user or process running the vulnerable script. This may facilitate privilege escalation.

14. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
BugTraq ID: 14168
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/14168
Summary:
Net-SNMP is prone to a remote denial-of-service vulnerability. The issue is exposed when Net-SNMP is configured to have an open stream-based protocol port, such as TCP.

The exact details describing this issue are not available. This BID will be updated when further details are made available.

15. Drupal Image Upload HTML Injection Vulnerability
BugTraq ID: 15663
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/15663
Summary:
Drupal is prone to an HTML-injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue is present only when using Microsoft Internet Explorer.

16. Drupal View User Profile Authorization Bypass Vulnerability
BugTraq ID: 15674
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/15674
Summary:
Drupal is prone to an authorization-bypass vulnerability. This issue is due to an unspecified error when the application is running under PHP5.

An attacker can exploit this vulnerability to bypass permissions and gain access to user profiles; this may result in information disclosure.

17. Drupal Submitted Content HTML Injection Vulnerability
BugTraq ID: 15677
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/15677
Summary:
Drupal is prone to an HTML-injection vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

18. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
BugTraq ID: 15148
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/15148
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.

These issues include:
- Buffer-overflow vulnerabilities
- Null-pointer dereference denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Memory exhaustion denial-of-service vulnerabilities
- Division by zero denial-of-service vulnerabilities
- Invalid pointer free() attempt denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities

These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.

Various vulnerabilities affect different versions of Ethereal, from 0.7.7 through to 0.10.12.

19. Computer Associates iTechnology iGateway Service Content-Length Heap Overflow Vulnerability
BugTraq ID: 16354
Remote: Yes
Last Updated: 2006-01-29
Relevant URL: http://www.securityfocus.com/bid/16354
Summary:

The iGateway component of various Computer Associates products allows remote attackers to execute arbitrary code by exploiting a heap-overflow vulnerability.

The attacker can trigger the vulnerability by supplying a negative HTTP Content-Length value and a large URI to the service.

A successful attack can result in corrupting process memory and the execution of arbitrary code with SYSTEM privileges on Windows platforms. The vendor has reported that this issue triggers only a denial-of-service condition on other platforms.

Products containing iGateway 4.0.051230 are vulnerable to this issue.

20. Nullsoft SHOUTcast File Request Format String Vulnerability
BugTraq ID: 12096
Remote: Yes
Last Updated: 2006-01-28
Relevant URL: http://www.securityfocus.com/bid/12096
Summary:
Nullsoft SHOUTcast is prone to a remotely exploitable format string vulnerability.  The vulnerability is exposed when the server attempts to handle a client request for a file.

Successful exploitation may allow execution of arbitrary code in the context of the server process.  This could also be exploited to crash the server and, possibly, to read process memory (which could increase reliability of an exploit).

This issue was reported to exist in version 1.9.4 on Linux.  It is likely that versions for other platforms are also affected by the vulnerability, though it is not known to what degree they are exploitable.  Earlier versions of the software are also likely affected.

21. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.

Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.

Note that other attack vectors also exist that may not require user interaction, since the application can be used with custom printing systems and web applications.

A successful attack may crash the application or lead to arbitrary code execution.

All versions of ImageMagick are considered vulnerable at the moment.

22. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.

Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.

This issue affects Apache 2.x versions.

23. Convert-UUlib Perl Module Buffer Overflow Vulnerability
BugTraq ID: 13401
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/13401
Summary:
Convert-UUlib Perl module is prone to a remotely exploitable buffer-overflow vulnerability.

This condition may be leveraged to overwrite sensitive program control variables, allowing a remote attacker to control the process's execution flow.

This BID will be updated as soon as further information regarding this issue is made available.

24. Exiv2 Corrupted EXIF Data Denial Of Service Vulnerability
BugTraq ID: 16400
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/16400
Summary:
Exiv2 is susceptible to a denial-of-service vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input data before attempting to read it, resulting in an out-of-bounds memory access crash.

This issue allows attackers to crash applications that use the affected library to process malicious image data. Depending on the nature of applications, this may be local or remote in nature.

This issue is present in Exiv2 versions prior to 0.9.

25. Elido Face Control Multiple Directory Traversal Vulnerabilities
BugTraq ID: 16401
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/16401
Summary:
Face Control is prone to multiple directory-traversal vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks; other attacks are also possible.

26. Shareaza Multiple Remote Integer Overflow Vulnerabilities
BugTraq ID: 16399
Remote: Yes
Last Updated: 2006-01-27
Relevant URL: http://www.securityfocus.com/bid/16399
Summary:


Shareaza is prone to multiple integer-overflow vulnerabilities. These issues are due to the application's failure to properly ensure that user-supplied input does not result in the overflowing of integer values. This may result in data being copied past the end of a memory buffer.

Attackers may exploit these vulnerabilities to execute arbitrary code in the context of the application.

Shareaza 2.2.1.0 is reportedly vulnerable. Other versions may be affected as well.

27. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.

28. Wzdftpd SITE Command Arbitrary Command Execution Vulnerability
BugTraq ID: 14935
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/14935
Summary:
wzdftpd is affected by a remote arbitrary command execution vulnerability.

This issue can allow an attacker to execute commands in the context of an affected server and potentially gain unauthorized access.

wzdftpd 0.5.4 is reported to be vulnerable.  Other versions may be affected as well.

29. YahooPOPS! Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 11256
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/11256
Summary:
It is reported that YahooPOPS! contains multiple buffer overflow vulnerabilities. These vulnerabilities are due to a failure of the application to properly bounds check user-supplied input data before copying it into finite sized memory buffers. This allows attackers to overwrite adjacent memory, potentially overwriting critical memory structures and altering the flow of execution. This will likely allow for remote code execution in the context of the affected application.

Versions of YahooPOPS! from 0.4 through to, and including 0.6 are reportedly affected by these vulnerabilities.

30. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.

By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

31. Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 16410
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16410
Summary:

Winamp is susceptible to a buffer-overflow vulnerability when handling specially crafted playlist files.
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.

Winamp 5.12 and prior versions are reportedly affected.

32. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to re-enable the 'register_globals' directive. This issue is due to a failure of the application to handle a memory limit exception.

The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the processes life. If PHP is being run as a CGI process, this issue is not likely exploitable.

By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

33. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

34. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:

The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

35. AOL Client Software Unspecified Local Privilege Escalation Vulnerability
BugTraq ID: 16453
Remote: No
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16453
Summary:
AOL Client Software is susceptible to a local privilege-escalation vulnerability. This issue is due to insecure permissions on an unspecified registry key.

This issue allows local users to execute arbitrary machine code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.

36. Adobe Multiple Unspecified Local Privilege Escalation Vulnerabilities
BugTraq ID: 16451
Remote: No
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16451
Summary:
Multiple unspecified Adobe products are susceptible to privilege-escalation vulnerabilities. These issues are due to insecure permissions on unspecified executable files.

These issues allow unprivileged local users to execute arbitrary machine code with elevated privileges.

Specific details regarding affected packages were not disclosed in the original paper describing this issue. This BID will be updated as further information is disclosed.

37. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:

The xpdf utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.

It is reported that this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The kpdf utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

38. Invision Power Board Portal Plugin Index.PHP SQL Injection Vulnerability
BugTraq ID: 16447
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16447
Summary:

Portal is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

39. Macromedia eLicensing Client Activation Code Local Privilege Escalation Vulnerability
BugTraq ID: 13925
Remote: No
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/13925
Summary:
The Macromedia installer and eLicensing client for Microsoft Windows platforms install a service ('Macromedia Licensing Service') when installing Macromedia products.

The service is a local service only; it runs with SYSTEM privileges. The vendor reports that this service is installed with insecure permissions that allow unprivileged members of the 'Users' group to make changes to the 'Macromedia Licensing Service' configuration. In making those changes, a local attacker may leverage this issue to gain SYSTEM-level access to a target computer.

40. Cisco VPN 3000 Concentrator Malformed HTTP Packet Remote Denial of Service Vulnerability
BugTraq ID: 16394
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16394
Summary:

Cisco VPN 3000 Concentrator is prone to a remote denial-of-service vulnerability when handling a specially crafted HTTP packet.

A successful attack can cause the device to restart.

41. MailEnable Professional EXAMINE Command Remote Denial of Service Vulnerability
BugTraq ID: 16457
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16457
Summary:


MailEnable Professional is prone to a remote denial of service vulnerability.

Successful exploitation can allow remote attackers to trigger a crash in the IMAP service.

MailEnable Professional versions prior to 1.72 are vulnerable.

42. Calendarix Multiple SQL Injection Vulnerabilities
BugTraq ID: 16456
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16456
Summary:

Calendarix is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. If the PHP global variable 'gpc_magic_quotes' is set to 'off', the attacker may be able to bypass authentication to the application.

Version 0.6.20050830 is vulnerable; other versions may also be affected.

43. SZUserMgnt Username Parameter SQL Injection Vulnerability
BugTraq ID: 16454
Remote: Yes
Last Updated: 2006-02-01
Relevant URL: http://www.securityfocus.com/bid/16454
Summary:
SZUserMgnt is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

44. Microsoft Internet Explorer Dialog Manipulation Vulnerability
BugTraq ID: 15823
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15823
Summary:
Internet Explorer is prone to a remote code-execution vulnerability through manipulation of custom dialog boxes. Keystrokes entered while one of these dialogs is displayed may be buffered and passed to a download dialog, allowing attacker-supplied code to be executed.

45. Microsoft Windows Asynchronous Procedure Call Local Privilege Escalation Vulnerability
BugTraq ID: 15826
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15826
Summary:
Microsoft Windows is susceptible to a local privilege-escalation vulnerability. This issue is due to a flaw in the Asynchronous Procedure Calls implementation in Microsoft Windows.

This issue allows local attackers to gain elevated privileges, facilitating the complete compromise of affected computers.

46. Microsoft Windows Embedded Web Font Buffer Overflow Vulnerability
BugTraq ID: 16194
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16194
Summary:
Microsoft Windows is susceptible to a remotely exploitable buffer-overflow vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable software on the targeted user's computer.

47. Mercury Mail Remote Mailbox Name Service Buffer Overflow Vulnerability
BugTraq ID: 16396
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16396
Summary:
Mercury Mail is reported susceptible to a remote buffer-overflow vulnerability in its mailbox name service. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to a finite-sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected server process. The machine code executes with SYSTEM privileges.

Version 4.01b of Mercury Mail is reportedly affected by this issue. Other versions may also be affected.

48. Microsoft Outlook / Microsoft Exchange TNEF Decoding Remote Code Execution Vulnerability
BugTraq ID: 16197
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16197
Summary:
Microsoft Exchange Server and Outlook email clients are prone to a remote code-execution vulnerability.

This vulnerability presents itself when the applications decode a message containing a specially crafted TNEF MIME attachment. Successful exploitation may result in arbitrary code execution facilitating a remote compromise.

An attack against Microsoft Exchange Server could lead to a SYSTEM-level remote compromise, while attacks against Outlook would result in arbitrary code execution in the context of the current user.

49. MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
BugTraq ID: 13660
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/13660
Summary:
MySQL is reportedly affected by a vulnerability that can allow local attackers to gain unauthorized access to the database or gain elevated privileges. This issue results from a design error due to the creation of temporary files in an insecure manner.

The vulnerability affects the 'mysql_install_db' script.

Due to the nature of the script, an attacker may create database accounts or gain elevated privileges.

MySQL versions prior to 4.0.12 and MySQL 5.x releases 5.0.4 and prior are reported to be affected.

50. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
BugTraq ID: 16203
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16203
Summary:
XMame is prone to locally exploitable buffer-overflow vulnerabilities. These issues are due to insufficient bounds checking of command-line parameters.

Successful exploitation on some systems could result in execution of malicious instructions with elevated privileges, since XMame may be installed with setuid-superuser privileges.

XMame version 0.102 is vulnerable to these issues; other versions may also be affected.

This issue may be related to BID 7773 (XMame Lang Local Buffer Overflow Vulnerability).

51. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code Execution Vulnerability
BugTraq ID: 16074
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16074
Summary:
Microsoft Windows WMF graphics rendering engine is affected by a remote code-execution vulnerability. This issue affects the 'SetAbortProc' function.

The problem presents itself when a user views a malicious WMF formatted file, triggering the vulnerability when the engine attempts to parse the file.

The issue may be exploited remotely or locally. Any remote code execution that occurs will be with the privileges of the user viewing a malicious image. An attacker may gain SYSTEM privileges if an administrator views the malicious file.

Local code execution may facilitate a complete compromise.

52. Microsoft Internet Explorer Flash ActionScript JScript Handling Denial of Service Vulnerability
BugTraq ID: 16441
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16441
Summary:

Microsoft Internet Explorer is reportedly prone to a denial-of-service vulnerability.

This issue arises when the browser handles specially crafted JScript contained in ActionScript code of a Flash animation.

A remote attacker may trigger a crash in the browser by enticing users to visit a malicious website.

53. FarsiNews Loginout.PHP Remote File Include Vulnerability
BugTraq ID: 16440
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16440
Summary:

FarsiNews is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This issue is reported to affect versions 2.1 Beta2 and earlier.

54. EMC Legato Networker Multiple Remote Vulnerabilities
BugTraq ID: 16275
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16275
Summary:
EMC Legato Networker is affected by multiple remote vulnerabilities. A denial-of-service issue and two remote code-execution issues have been identified.

Version 7.2.1 of Legato Networker is vulnerable to these issues; prior versions may also be affected.

55. Multiple Vendor TCP Timestamp PAWS Remote Denial Of Service Vulnerability
BugTraq ID: 13676
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/13676
Summary:
A denial-of-service vulnerability exists for the TCP RFC 1323. The issue resides in the Protection Against Wrapped Sequence Numbers (PAWS) technique that was included to increase overall TCP performance.

When TCP 'timestamps' are enabled, both hosts at the endpoints of a TCP connection employ internal clocks to mark TCP headers with a 'timestamp' value.

When TCP PAWS is configured to employ timestamp values, this functionality exposes TCP PAWS implementations to a denial-of-service vulnerability.

The issue manifests if an attacker transmits a sufficient TCP PAWS packet to a vulnerable computer. The attacker sets a large value as the packet timestamp. When the target computer processes this packet, the internal timer is updated to the large value that the attacker supplied. This causes all other valid packets that are received subsequent to an attack to be dropped, because they are deemed to be too old or invalid. This type of attack will effectively deny service for a target connection.

56. Oracle January Security Update Multiple Vulnerabilities
BugTraq ID: 16287
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16287
Summary:
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, PeopleSoft Enterprise Portal, JD Edwards EnterpriseOne Tools, OneWorld Tools, Oracle Developer Suite, and Oracle Workflow are prone to multiple vulnerabilities.

The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.

Oracle has released a Critical Patch Update advisory for January 2006 to address these vulnerabilities.  This Critical Patch Update addresses the vulnerabilities for supported releases.  Earlier, unsupported releases are likely to be affected by the issues as well.

57. ht://Dig Config Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 12442
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/12442
Summary:
ht://Dig is reported prone to a cross-site scripting vulnerability.  This issue is due to a failure of the application to properly sanitize user-supplied URI data prior to including it in dynamically generated Web page content.

All versions of ht://Dig are considered vulnerable at the moment.

58. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability.

Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user uses authentication methods other than GSSAPI to connect, which is not usually expected.

This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use the credentials to access resources granted to the original principal.

This issue affects versions of OpenSSH prior to 4.2.

59. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
BugTraq ID: 14727
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/14727
Summary:
OpenSSH is susceptible to a vulnerability that causes improper activation of the 'GatewayPorts' option, allowing unintended hosts to use the SSH SOCKS proxy.

Specifically, if the 'DynamicForward' option is activated, 'GatewayPorts' is also unconditionally enabled.

This vulnerability allows remote attackers to use the SOCKS proxy to make arbitrary TCP connections through the configured SSH session, allowing them to attack computers and services through a connection that was wrongly thought to be secure.

This issue affects OpenSSH 4.0, and 4.1.

60. SCO UnixWare UIDAdmin Local Buffer Overflow Vulnerability
BugTraq ID: 15811
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15811
Summary:
SCO UnixWare is prone to a local buffer-overflow vulnerability.

The vulnerability presents itself when the application processes excessive data supplied to the 'uidadmin' utility.

UnixWare 7.1.3 and UnixWare 7.1.4 are affected by this issue. Previous versions may also be affected.

61. Lynx URI Handlers Arbitrary Command Execution Vulnerability
BugTraq ID: 15395
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15395
Summary:
Lynx is prone to an arbitrary command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.

A remote attacker can exploit this vulnerability by tricking a victim user into following a malicious link, thus enabling the attacker to execute arbitrary commands in the context of the victim user.

62. Blackboard Learning System Access Validation Vulnerability
BugTraq ID: 16438
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16438
Summary:

Blackboard is prone to a vulnerability that may permit an attacker to gain access to another user account. This issue is due to an error in the authentication mechanism.

An attacker with a valid account that has access to a Blackboard session of another user that is currently timed out, can gain access to that user's account. Successful exploitation will grant the attacker complete access to the victim user's account.

63. Mail-Audit Insecure Temporary File Creation Vulnerability
BugTraq ID: 16434
Remote: No
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16434
Summary:

Mail-Audit creates temporary files in an insecure manner. This issue arises only when logging has been enabled.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.


Mail-Audit 2.1 and prior versions are considered vulnerable.

64. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
BugTraq ID: 15629
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15629
Summary:
Perl is susceptible to a format-string vulnerability. This issue is due to the programming language's failure to properly handle format specifiers in formatted printing functions.

An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.

Developers should treat the formatted printing functions in Perl as equivalently vulnerable to exploitation as the C library versions, and should properly sanitize all data passed in the format specifier argument.

All applications that use formatted printing functions in an unsafe manner should be considered exploitable.

65. OpenSSL Insecure Protocol Negotiation Weakness
BugTraq ID: 15071
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15071
Summary:
OpenSSL is susceptible to a remote protocol-negotiation weakness. This issue is due to the implementation of the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option to maintain compatibility with third-party software.

This issue presents itself when two peers try to negotiate the protocol they wish to communicate with. Attackers who can intercept and modify the SSL communications may exploit this weakness to force SSL version 2 to be chosen.

The attacker may then exploit various insecurities in SSL version 2 to gain access to or tamper with the cleartext communications between the targeted client and server.

Note that the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option is enabled with the frequently used 'SSL_OP_ALL' option.

SSL peers that are configured to disallow SSL version 2 are not affected by this issue.

66. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15158
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/15158
Summary:
A remote buffer-overflow vulnerability affects Ethereal. This issue is due to the application's failure to securely copy network-derived data into sensitive process buffers. The specific issue resides in the Service Location Protocol dissector.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

This issue may be exploited by a single TCP packet to port 427, since Ethereal does not keep track of connection states. This allows malicious users to spoof the origin of attacks and to exploit this vulnerability when no services are actively listening on TCP port 427.

Note that this issue was originally disclosed in BID 15148 "Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13".

67. Communigate Pro Server LDAP Denial of Service Vulnerability
BugTraq ID: 16407
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16407
Summary:

CommuniGate Pro Server is prone to a remote denial-of-service vulnerability with a potential for arbitrary code execution. This issue reportedly resides in the LDAP component of the application.

CommuniGate Pro Server 5.0.6 is vulnerable; earlier versions may also be affected.

68. EasyCMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16430
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16430
Summary:
EasyCMS is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

69. phpBB Rlink Module Rlink.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16448
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16448
Summary:
The phpBB Rlink module is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

70. PunctWeb MyCO Name Field HTML Injection Vulnerability
BugTraq ID: 16444
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16444
Summary:
MyCO is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

71. MyBB Index.PHP Referrer Cookie SQL Injection Vulnerability
BugTraq ID: 16443
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16443
Summary:
MyBB is prone to an SQL injection vulnerability.

The vulnerability presents itself when user-supplied input via cookie data is passed to the 'index.php' script.

Successful exploitation can allow an attacker to bypass authentication and gain administrative access to a site. Other attacks may also be possible.

MyBB 1.2 is reported to be vulnerable.

72. Cerberus Helpdesk Clients.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16439
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16439
Summary:
Cerberus Helpdesk is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

73. AshWebStudio AshNews Remote File Include Vulnerability
BugTraq ID: 16436
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16436
Summary:

Ashnews is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the Web server process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

74. BrowserCRM Results.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16435
Remote: Yes
Last Updated: 2006-01-31
Relevant URL: http://www.securityfocus.com/bid/16435
Summary:
BrowserCRM is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

75. GNU Mailman Attachment Scrubber UTF8 Filename Denial Of Service Vulnerability
BugTraq ID: 15408
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15408
Summary:
GNU Mailman is prone to denial-of-service attacks. This issue affects the attachment scrubber utility.

The vulnerability could be triggered by mailing-list posts and will impact the availability of mailing lists hosted by the application.

76. Daffodil CRM Userlogin.ASP SQL Injection Vulnerability
BugTraq ID: 16433
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16433
Summary:
Daffodil CRM is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.


Version 8.0 and earlier are reported to be vulnerable; other versions may also be affected. Version 8.5 and later are reported to be invulnerable.

77. MyDNS DNS Query Denial Of Service Vulnerability
BugTraq ID: 16431
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16431
Summary:

MyDNS is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle DNS queries.

An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.

The vendor has addressed this issue in version 1.1.0; earlier versions are reportedly vulnerable.

78. Gzip Zgrep Arbitrary Command Execution Vulnerability
BugTraq ID: 13582
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/13582
Summary:
zgrep is reportedly affected by an arbitrary command execution vulnerability.

An attacker may execute arbitrary commands through zgrep command arguments to potentially gain unauthorized access to the affected computer.  It should be noted that this issue only poses a security threat if the arguments originate from a malicious source.

zgrep 1.2.4 was reported vulnerable.  Other versions may be affected as well.

79. BZip2 CHMod File Permission Modification Race Condition Weakness
BugTraq ID: 12954
Remote: No
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/12954
Summary:
The 'bzip2' utility is reported prone to a security weakness. The issue is present only when an archive is extracted into a world- or group-writeable directory. It is reported that bzip2 employs non-atomic procedures to write a file and later changes the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.

This weakness is reported to affect bzip2 version 1.0.2 and previous versions.

80. Pioneers Chat Buffer Denial Of Service Vulnerability
BugTraq ID: 16429
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16429
Summary:

Pioneers is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.

An attacker can exploit this issue to crash the affected Pioneers server and possibly clients connected to a vulnerable Pioneers server.

This issue is reported to affect version 0.9.40; other versions may also be vulnerable.

81. Edgewall Software Trac HTML WikiProcessor Wiki Content HTML Injection Vulnerability
BugTraq ID: 16198
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16198
Summary:
Trac is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

82. Unalz Archive Filename Buffer Overflow Vulnerability
BugTraq ID: 15577
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15577
Summary:

The 'unalz' utility is prone to a buffer-overflow vulnerability. This issue is exposed when the application extracts an ALZ archive that contains a file with a long name.

An attacker could exploit this vulnerability to execute arbitrary code in the context of the user who extracts a malicious archive.

83. Soti Pocket Controller-Professional Remote Command Execution Vulnerability
BugTraq ID: 15775
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15775
Summary:
Soti Pocket Controller-Professional is prone to a remote command-execution vulnerability. Successful exploitation could allow an attacker to cause a hard reset of the device, resulting in a loss of data and installed applications.

Pocket Controller-Professional v5 is vulnerable; other versions may also be affected.

84. PmWiki Multiple Input Validation Vulnerabilities
BugTraq ID: 16421
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16421
Summary:

PmWiki is prone to multiple input-validation vulnerabilities. These issues are due to failures in the application to properly sanitize user-supplied input.

- Arbitrary remote file-include vulnerability. Exploitation of this issue will result in the execution of attacker-supplied code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system.

- Unspecified HTML-injection issues. Successful exploitation will permit an attacker to inject arbitrary HTML code. When viewed, this code will be executed in the browser of a victim user in the context of the webserver process. Successful exploitation may aid in the theft of cookie-based authentication credentials, or allow the attacker to control how the site is rendered to the user; other attacks are also possible.

These issues affect version 2.1 beta20; other versions may also be vulnerable.

85. Arescom Net DSL 1000 telnet Denial of Service Vulnerability
BugTraq ID: 4067
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/4067
Summary:
The Arescom NETDSL 1000 Series ADSL router provides a telnet-based management interface for configuration. An attacker can crash this interface by repeatedly connecting and sending long strings (256 characters) when prompted for a password. This does not affect normal router function, but shuts down the management console until the router is powered down and restarted.

86. Mozilla Firefox XBL -MOZ-BINDING Property Cross-Domain Scripting Vulnerability
BugTraq ID: 16427
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16427
Summary:


Mozilla Firefox is prone to a security vulnerability that may let a Web page execute malicious script code in the context of an arbitrary domain.

The issue affects the '-moz-binding' property.


This could allow a malicious site to access the properties of a trusted site and facilitate various attacks including disclosure of sensitive information.

87. GIT Remote Buffer Overflow Vulnerability
BugTraq ID: 16417
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16417
Summary:
GIT is prone to a remote buffer-overflow vulnerability.

The issue presents itself when a large symbolic link in an index file is processed. A successful attack may result in arbitrary code execution in the context of the user.

88. MiniNuke Multiple Input Validation Vulnerabilities
BugTraq ID: 16416
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16416
Summary:

MiniNuke is prone to multiple input-validation vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.

MiniNuke is prone to an SQL-injection vulnerability.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

MiniNuke is also prone to a vulnerability that could permit an attacker to change an arbitrary user's password to an attacker-supplied value. Successful exploitation may result in a complete compromise of the application; other attacks are also possible.

These issues are reported to affect version 1.8.2; other versions may also be vulnerable.

89. Edgewall Software Trac Search Module SQL Injection Vulnerability
BugTraq ID: 15720
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15720
Summary:
Trac is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

90. Linux Kernel Multiple Security Vulnerabilities
BugTraq ID: 16414
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16414
Summary:
Linux kernel is prone to multiple vulnerabilities. These issues can allow local and remote attackers to trigger denial-of-service conditions or to corrupt memory to potentially execute arbitrary code.

These issues affect kernel versions 2.6.15 and prior.

91. UebiMiau HTML Email HTML Injection Vulnerability
BugTraq ID: 16413
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16413
Summary:

UebiMiau is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 2.7.9; other versions may also be vulnerable.

92. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
BugTraq ID: 16301
Remote: No
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16301
Summary:
The Linux kernel dm-crypt module is susceptible to a local information-disclosure vulnerability. This issue is due to the module's failure to properly zero-sensitive memory buffers before freeing the memory.

This issue may allow local attackers to gain access to potentially sensitive memory that contains information on the cryptographic key used for the encrypted storage. This may aid them in further attacks.

This issue affects the 2.6 series of the Linux kernel.

93. Phpclanwebsite Multiple Input Validation Vulnerabilities
BugTraq ID: 16391
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16391
Summary:

Phpclanwebsite is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. If successful, an attacker may also exploit vulnerabilities in the underlying database implementation as well as conduct other attacks.

Phpclanwebsite version 1.23.1 is vulnerable; other versions may also be affected.

94. Phpclanwebsite BBCode IMG Tag Script Injection Vulnerability
BugTraq ID: 16300
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16300
Summary:
Phpclanwebsite is prone to a script-injection vulnerability.

An attacker can nest BBCode IMG tags to trigger this issue and execute arbitrary code in a user's browser.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.

Reports have not specified which version is vulnerable. The current version (1.23.1) is assumed to be vulnerable; other versions may also be affected.

95. GNU Mailman Large Date Data Denial Of Service Vulnerability
BugTraq ID: 16248
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16248
Summary:
GNU Mailman is prone to a denial-of-service attack. This issue affects the email date parsing functionality of Mailman.

The vulnerability could be triggered by mailing-list posts and will impact the availability of mailing lists hosted by the application.

96. Eterm LibAST Library Local Buffer Overflow Vulnerability
BugTraq ID: 16350
Remote: No
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16350
Summary:
Eterm LibAST library is prone to a local buffer-overflow vulnerability.

An attacker can trigger this issue by supplying a long filename through the '-X' option of Eterm. A successful attack can corrupt memory and facilitate arbitrary code execution with the privileges of the 'utmp' user.

LibAST versions 0.6.1 and prior are vulnerable to this issue.

Note that other applications using the affected library may be vulnerable as well.

97. Paros HSQLDB Remote Authentication Bypass Vulnerability
BugTraq ID: 15141
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/15141
Summary:
Paros is prone to a remote authentication-bypass vulnerability.

This issue may result in the disclosure of sensitive information, and possible execution of commands on the victim machine.

Paros version 3.2.5 is affected; earlier versions may also be vulnerable.

Update: version 3.2.6 was released and addresses this issue from remote computers, because the database listens only on localhost by default. This still allows local users to connect, since the default username of 'sa' with a blank password is still used.

98. AZ Bulletin Board Post.PHP HTML Injection Vulnerabilities
BugTraq ID: 16351
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16351
Summary:
AZbb is prone to HTML-injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

99. Microsoft Internet Explorer ActiveX Control Kill Bit Bypass Vulnerability
BugTraq ID: 16409
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16409
Summary:

Microsoft Internet Explorer fails to properly check the kill bit for ActiveX controls.  This could allow a remote attacker to invoke an unsafe control to execute arbitrary code on the vulnerable computer.

100. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
BugTraq ID: 16408
Remote: Yes
Last Updated: 2006-01-30
Relevant URL: http://www.securityfocus.com/bid/16408
Summary:

GNOME Evolution email client is prone to a denial-of-service vulnerability when processing messages containing inline XML file attachments with excessively long strings.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Good worms back on the agenda
By: Robert Lemos
A researcher argues that the spreading capabilities of worms could better perform penetration testing inside networks, turning vulnerable systems into distributed scanners.
http://www.securityfocus.com/news/11373

2. Researchers: Rootkits headed for BIOS
By: Robert Lemos
UPDATE: Insider attacks and industrial espionage could
become more stealthy by hiding code in the
core system functions stored on the motherboard,
researchers say.
http://www.securityfocus.com/news/11372

3. Zero-day details underscore criticism of Oracle
By: Robert Lemos
A security researcher releases detailed information about a critical vulnerability in Oracle's application and Web servers, taking the company to task for not fixing the issues quickly.
http://www.securityfocus.com/news/11371

4. Bot herder pleads guilty to 'zombie' sales
By: Robert Lemos
A 20-year-old California man plead guilty to federal charges that he sold access to networks of compromised PCs and made money from illicitly installed adware.
http://www.securityfocus.com/news/11370

5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354

6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348

7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347

8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Architect, Alexandria
http://www.securityfocus.com/archive/77/423669

2. [SJ-JOB] Security System Administrator, San Francisco
http://www.securityfocus.com/archive/77/423668

3. [SJ-JOB] Sr. Security Engineer, North Bergen
http://www.securityfocus.com/archive/77/423582

4. [SJ-JOB] Security Consultant, Bangalore
http://www.securityfocus.com/archive/77/423578

5. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/423579

6. [SJ-JOB] Security Consultant, San Franciso and Irvine
http://www.securityfocus.com/archive/77/423575

7. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/423576

8. [SJ-JOB] Security Architect, San Franciso and Irvine
http://www.securityfocus.com/archive/77/423574

9. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/423571

10. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/423572

11. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/423573

12. [SJ-JOB] Sales Engineer, Charlotte
http://www.securityfocus.com/archive/77/423560

13. [SJ-JOB] Developer, Charlotte
http://www.securityfocus.com/archive/77/423558

14. [SJ-JOB] Application Security Architect, Eastern Iowa
http://www.securityfocus.com/archive/77/423554

15. [SJ-JOB] Sr. Product Manager, San Diego
http://www.securityfocus.com/archive/77/423555

16. [SJ-JOB] Product Strategist, San Diego
http://www.securityfocus.com/archive/77/423556

17. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/423552

18. [SJ-JOB] Sr. Security Engineer, Eastern Iowa
http://www.securityfocus.com/archive/77/423553

19. [SJ-JOB] Security System Administrator, Santa Barbara
http://www.securityfocus.com/archive/77/423498

20. [SJ-JOB] Certification & Accreditation Engineer, Washington,DC
http://www.securityfocus.com/archive/77/423519

21. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/423520

22. [SJ-JOB] Security System Administrator, Ft Lauderdale
http://www.securityfocus.com/archive/77/423517

23. [SJ-JOB] Security Consultant, Ft Lauderdale
http://www.securityfocus.com/archive/77/423518

24. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/423460

25. [SJ-JOB] Sales Engineer, Salt Lake City
http://www.securityfocus.com/archive/77/423461

26. [SJ-JOB] Account Manager, Paramus
http://www.securityfocus.com/archive/77/423458

27. [SJ-JOB] Sr. Security Analyst, Boston
http://www.securityfocus.com/archive/77/423320

28. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/423322

29. [SJ-JOB] Account Manager, Northern CA
http://www.securityfocus.com/archive/77/423319

30. [SJ-JOB] Security Engineer, Twin Cities
http://www.securityfocus.com/archive/77/423307

31. [SJ-JOB] Security Auditor, Washington
http://www.securityfocus.com/archive/77/423308

32. [SJ-JOB] Application Security Engineer, Arlington
http://www.securityfocus.com/archive/77/423298

33. [SJ-JOB] Security System Administrator, Arlington
http://www.securityfocus.com/archive/77/423299

34. [SJ-JOB] Technology Risk Consultant, Arlington
http://www.securityfocus.com/archive/77/423295

35. [SJ-JOB] Database Security Engineer, Arlington
http://www.securityfocus.com/archive/77/423296

36. [SJ-JOB] Application Security Engineer, Arlington
http://www.securityfocus.com/archive/77/423297

37. [SJ-JOB] Quality Assurance, Silicon Valley
http://www.securityfocus.com/archive/77/423281

38. [SJ-JOB] VP / Dir / Mgr engineering, Silicon Valley
http://www.securityfocus.com/archive/77/423280

39. [SJ-JOB] Threat Analyst, Calgary
http://www.securityfocus.com/archive/77/423279

40. [SJ-JOB] Threat Analyst, Calgary
http://www.securityfocus.com/archive/77/423277

41. [SJ-JOB] Threat Analyst, Calgary
http://www.securityfocus.com/archive/77/423278

42. [SJ-JOB] Developer, Silicon Valley
http://www.securityfocus.com/archive/77/423200

43. [SJ-JOB] Management, Boulder
http://www.securityfocus.com/archive/77/423202

44. [SJ-JOB] Developer, Boulder
http://www.securityfocus.com/archive/77/423203

45. [SJ-JOB] Quality Assurance, Silicon Valley
http://www.securityfocus.com/archive/77/423199

46. [SJ-JOB] Developer, Boulder
http://www.securityfocus.com/archive/77/423205

47. [SJ-JOB] Security Auditor, Miami
http://www.securityfocus.com/archive/77/423159

48. [SJ-JOB] Security Auditor, Columbus
http://www.securityfocus.com/archive/77/423158

49. [SJ-JOB] Auditor, Miami
http://www.securityfocus.com/archive/77/423160

50. [SJ-JOB] Auditor, Columbus
http://www.securityfocus.com/archive/77/423157

51. [SJ-JOB] Security Engineer, Saint Louis
http://www.securityfocus.com/archive/77/423176

52. [SJ-JOB] Jr. Security Analyst, LONDON,KENT
http://www.securityfocus.com/archive/77/423146

53. [SJ-JOB] Security Auditor, New York
http://www.securityfocus.com/archive/77/423149

54. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/423153

55. [SJ-JOB] Security Consultant, LONDON-
http://www.securityfocus.com/archive/77/423144

56. [SJ-JOB] Application Security Architect, LONDON
http://www.securityfocus.com/archive/77/423150

57. [SJ-JOB] Security Consultant, Laval
http://www.securityfocus.com/archive/77/423151

58. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/423091

59. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/423099

60. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/423100

61. [SJ-JOB] Application Security Architect, Arlington
http://www.securityfocus.com/archive/77/423085

62. [SJ-JOB] Sr. Security Engineer, Oxford
http://www.securityfocus.com/archive/77/423089

63. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/423096

64. [SJ-JOB] Channel / Business Development, Atlanta
http://www.securityfocus.com/archive/77/423022

65. [SJ-JOB] Sales Engineer, NY city area
http://www.securityfocus.com/archive/77/423031

66. [SJ-JOB] Sr. Security Engineer, New York City
http://www.securityfocus.com/archive/77/423076

67. [SJ-JOB] Forensics Engineer, UK (home-based)
http://www.securityfocus.com/archive/77/423069

68. [SJ-JOB] Sales Engineer, Washington
http://www.securityfocus.com/archive/77/423082

69. [SJ-JOB] Sr. Security Engineer, Milton Keynes
http://www.securityfocus.com/archive/77/423026

70. [SJ-JOB] Sales Representative, Maidstone
http://www.securityfocus.com/archive/77/423032

71. [SJ-JOB] Sr. Security Engineer, Washington, DC
http://www.securityfocus.com/archive/77/423058

72. [SJ-JOB] Channel / Business Development, Boston
http://www.securityfocus.com/archive/77/423067

73. [SJ-JOB] Channel / Business Development, Raleigh
http://www.securityfocus.com/archive/77/423084

V.   INCIDENTS LIST SUMMARY
---------------------------
1. wired traffic
http://www.securityfocus.com/archive/75/423416

2. Decrease in Threats?
http://www.securityfocus.com/archive/75/423083

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: CipherTrust

Messaging Security: It's more than just e-mail.
Today's businesses are struggling with a new breed of threats to more than just their e-mail environments, and despite best efforts, hackers and spammers continue to exploit new attack vectors to break into enterprise networks. Please join CipherTrust to discuss best practices and approaches to comprehensive messaging security. Register Now in a city near you.

http://www.ciphertrust.com/seminars/sf