SecurityFocus Newsletter #336

Peter Laborge <[email protected]> Tue, 07 Feb 2006 17:11:29 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #336
----------------------------------------

This Issue is Sponsored By: Watchfire

AppScan 6.0 Available now! Web application security vulnerabilities are a growing threat for anyone doing business online. See if your applications are vulnerable. Download a Free Copy of Watchfire's AppScan 6.0 today. Watchfire named worldwide market share leader in web application security assessment by leading market research firm.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000007kqw

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Malicious Malware: attacking the attackers, part 2
        2. Nmap 4.00 with Fyodor
II.   BUGTRAQ SUMMARY
        1. ADOdb Server.PHP SQL Injection Vulnerability
        2. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
        3. PHP PHPInfo Cross-Site Scripting Vulnerability
        4. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
        5. HP Tru64 DNS BIND Unspecified Remote Unauthorized Access Vulnerability
        6. FarsiNews Loginout.PHP Remote File Include Vulnerability
        7. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
        8. Mozilla Thunderbird File Attachment Spoofing Vulnerability
        9. MyBB Notepad UserCP.PHP HTML Injection Vulnerability
        10. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
        11. Rockliffe MailSite HTTP Mail Management Agent Denial Of Service Vulnerability
        12. @Mail Compose.PL Directory Traversal Vulnerability
        13. Aquifer CMS Index.ASP Cross-Site Scripting Vulnerability
        14. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
        15. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
        16. HP-UX FTPD Remote Denial Of Service Vulnerability
        17. pcAnywhere Authentication Denial of Service Vulnerability
        18. Microsoft Windows Asynchronous Procedure Call Local Privilege Escalation Vulnerability
        19. ImageMagick Image Filename Remote Command Execution Vulnerability
        20. Shareaza Multiple Remote Integer Overflow Vulnerabilities
        21. Eggblog Multiple Input Validation Vulnerabilities
        22. Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
        23. SCO UnixWare UIDAdmin Local Buffer Overflow Vulnerability
        24. Linux Kernel Multiple Security Vulnerabilities
        25. Multiple Vendor Spoofed IGMP Report Denial Of Service Vulnerability
        26. EMC Legato Networker Multiple Remote Vulnerabilities
        27. Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
        28. OpenSSH SCP Shell Command Execution Vulnerability
        29. Blackboard Academic Suite Frameset.JSP Cross-Domain Frameset Loading Vulnerability
        30. CipherTrust IronMail Remote Denial Of Service Vulnerability
        31. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
        32. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
        33. ADOdb PostgreSQL SQL Injection Vulnerability
        34. Apache HTTP Request Smuggling Vulnerability
        35. Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
        36. Qualcomm WorldMail IMAPD Buffer Overflow Vulnerability
        37. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
        38. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
        39. CyberStrong EShop 20review.ASP SQL Injection Vulnerability
        40. Elido Face Control Multiple Directory Traversal Vulnerabilities
        41. Microsoft Windows Media Player Automatic File Download and Execution Vulnerability
        42. DotNetNuke Failed Logon Username Application Logs HTML Injection Vulnerability
        43. DotNetNuke User Registration Information HTML Injection Vulnerability
        44. Cisco IOS Multiple Unspecified EIGRP Vulnerabilities
        45. CRE Loaded Files.PHP Access Validation Vulnerability
        46. SPIP Multiple SQL Injection Vulnerabilities
        47. DotNetNuke User-Agent String Application Logs HTML Injection Vulnerability
        48. WatchGuard ServerLock Physical Memory Device Access Vulnerability
        49. Microsoft Windows Shell Remote Code Execution Vulnerability
        50. UIM LibUIM Environment Variables Privilege Escalation Weakness
        51. PHP GEN Unspecified Cross-Site Scripting Vulnerabilities
        52. CGI.pm Start_Form Cross-Site Scripting Vulnerability
        53. Safe.PM Unsafe Code Execution Vulnerability
        54. Adobe Multiple Local Privilege Escalation Vulnerabilities
        55. Pioneers Chat Buffer Denial Of Service Vulnerability
        56. Mozilla Firefox Large History File Buffer Overflow Vulnerability
        57. GD Graphics Library Remote Integer Overflow Vulnerability
        58. OpenSSH GSSAPI Credential Disclosure Vulnerability
        59. MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
        60. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
        61. ImageMagick File Name Handling Remote Format String Vulnerability
        62. Sudo Python Environment Variable Handling Security Bypass Vulnerability
        63. GIT Remote Buffer Overflow Vulnerability
        64. OpenSSL Insecure Protocol Negotiation Weakness
        65. Microsoft Internet Explorer Dialog Manipulation Vulnerability
        66. MyBB Multiple Cross-Site Scripting Vulnerabilities
        67. Multiple Vendor TCP Timestamp PAWS Remote Denial Of Service Vulnerability
        68. Gzip Zgrep Arbitrary Command Execution Vulnerability
        69. GNU Mailman Large Date Data Denial Of Service Vulnerability
        70. Invision Power Board Portal Plugin Index.PHP SQL Injection Vulnerability
        71. MyBB Signature HTML Injection Vulnerability
        72. BZip2 CHMod File Permission Modification Race Condition Weakness
        73. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        74. Nullsoft Winamp Malformed Playlist File WMA Extention Remote Buffer Overflow Vulnerability
        75. Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
        76. BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
        77. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
        78. PmWiki Multiple Input Validation Vulnerabilities
        79. CheesyBlog Multiple HTML Injection Vulnerabilities
        80. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
        81. ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
        82. Phpclanwebsite Multiple Input Validation Vulnerabilities
        83. BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
        84. LSH Seed File File Descriptor Leakage Vulnerability
        85. RCBlog Index.PHP Directory Traversal Vulnerability
        86. Multiple Vendor KernFS LSEEK Local Kernel Memory Disclosure Vulnerability
        87. AshWebStudio AshNews Remote File Include Vulnerability
        88. Hitachi JP1/NetInsight II - Port Discovery Denial of Service Vulnerability
        89. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
        90. FreeBSD TCP SACK Remote Denial Of Service Vulnerability
        91. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        92. My Amazon Store Manager Search.PHP Cross-Site Scripting Vulnerability
        93. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
        94. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
        95. Samba Directory Access Control List Remote Integer Overflow Vulnerability
        96. My Little Homepage Products BBCode Link Tag Script Injection Vulnerability
        97. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
        98. Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
        99. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
        100. SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
III.  SECURITYFOCUS NEWS
        1. Apple's in the eye of flaw finders
        2. Blackmal virus set to delete files
        3. Good worms back on the agenda
        4. Researchers: Rootkits headed for BIOS
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Security Consultant, Detroit
        2. [SJ-JOB] Security Consultant, Miami
        3. [SJ-JOB] Security Consultant, Los Angeles
        4. [SJ-JOB] Security Consultant, Chicago
        5. [SJ-JOB] Security Consultant, New York
        6. [SJ-JOB] Security Architect, Plano
        7. [SJ-JOB] Application Security Engineer, Pasadena
        8. [SJ-JOB] Security Consultant, Herndon
        9. [SJ-JOB] Security Consultant, San Francisco
        10. [SJ-JOB] Security Consultant, New York
        11. [SJ-JOB] Sales Representative, Northern Virginia / DC
        12. [SJ-JOB] Security Consultant, Chicago
        13. [SJ-JOB] Sr. Security Analyst, Pasadena
        14. [SJ-JOB] Security Engineer, Pasadena
        15. [SJ-JOB] Developer, Pasadena
        16. [SJ-JOB] Security Architect, Pasadena
        17. [SJ-JOB] Security Engineer, London
        18. [SJ-JOB] Sales Representative, Chicago
        19. [SJ-JOB] Sr. Security Analyst, Phoenix
        20. [SJ-JOB] Sales Engineer, Charlotte
        21. [SJ-JOB] Account Manager, San Francisco/San Jose Bay Area
        22. [SJ-JOB] Account Manager, New York
        23. [SJ-JOB] Threat Analyst, Lombard
        24. [SJ-JOB] Sales Engineer, Oxon/Berks
        25. [SJ-JOB] Sales Representative, London
        26. [SJ-JOB] Sr. Security Analyst, Denver
        27. [SJ-JOB] Security Auditor, Milwaukee
        28. [SJ-JOB] Security Auditor, McLean
        29. [SJ-JOB] Manager, Information Security, West Suburbs - Chicago
        30. [SJ-JOB] Application Security Engineer, Greenwich
        31. [SJ-JOB] Sr. Security Analyst, Oak Ridge
        32. [SJ-JOB] Application Security Architect, Ft Lauderdale
        33. [SJ-JOB] Account Manager, Bay Area
        34. [SJ-JOB] Database Security Engineer, Ft Lauderdale
        35. [SJ-JOB] Security Consultant, Irvine
        36. [SJ-JOB] Sales Representative, Mclean
        37. [SJ-JOB] Security Engineer, Bay Area
        38. [SJ-JOB] Security Consultant, San Francisco
        39. [SJ-JOB] Security Consultant, Los Angeles
        40. Working with a recruiter?
        41. [SJ-JOB] Sales Engineer, Mclean
        42. [SJ-JOB] Sales Engineer, Washington DC
        43. [SJ-JOB] Security Consultant, Plano
        44. [SJ-JOB] Auditor, Charlotte
        45. [SJ-JOB] Security Consultant, Denver and/or Chicago
        46. [SJ-JOB] Sr. Security Analyst, Alexandria
        47. [SJ-JOB] Sr. Security Engineer, Reston
        48. [SJ-JOB] Security Architect, Mississauga
        49. [SJ-JOB] Security Architect, Framingham
        50. [SJ-JOB] Security Architect, New York
        51. [SJ-JOB] Security Architect, Los Angeles
        52. [SJ-JOB] Security Architect, Chicago
        53. [SJ-JOB] Security Architect, San Francisco
        54. [SJ-JOB] Incident Handler, Los Angeles
        55. [SJ-JOB] Threat Analyst, Ft. Lauderdale Metro Area
        56. [SJ-JOB] Information Assurance Analyst, Washington, D.C.
        57. [SJ-JOB] Security Engineer, Northern Virginia/Reston/Herndon/Tysons
        58. [SJ-JOB] Technology Risk Consultant, Mclean
        59. [SJ-JOB] Sr. Security Analyst, Los Angeles
        60. [SJ-JOB] Security Consultant, Boston
        61. [SJ-JOB] Security Architect, New York/  Trenton NJ
        62. [SJ-JOB] Auditor, Mclean
        63. [SJ-JOB] Sales Engineer, New York
        64. [SJ-JOB] Sr. Security Engineer, Wilmington
        65. [SJ-JOB] Security Engineer, Santa Barbara
        66. [SJ-JOB] Sr. Security Analyst, Los Angeles
        67. [SJ-JOB] Manager, Information Security, Wilmington
        68. [SJ-JOB] Security Architect, Atlanta
        69. [SJ-JOB] Security Consultant, Alexandria
        70. [SJ-JOB] Security Engineer, Austin
        71. [SJ-JOB] Security Architect, Alexandria
        72. [SJ-JOB] Security System Administrator, San Francisco
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Buffer Overrun Newbie
        2. Black Hat USA CFP opens, Europe early bird reminder, Federal  news
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. SecurityFocus Microsoft Newsletter #276
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Malicious Malware: attacking the attackers, part 2
By Thorsten Holz, Frederic Raynal
This article explores measures to attack those malicious attackers who seek to harm our legitimate systems. The proactive use of exploits and bot networks that fight other bot networks, along with social engineering and attacker techniques are all discussed in an ethical manner. Part two of two.
http://www.securityfocus.com/infocus/1857

2. Nmap 4.00 with Fyodor
By Federico Biancuzzi
After more than eight years since its first release in Phrack magazine, Fyodor has announced Nmap 4.00. Curious as usual, Federico Biancuzzi interviewed Fyodor on behalf of SecurityFocus to discuss the new port scanning engine, version detection improvements, and the new stack fingerprinting algorithm under work by the community.
http://www.securityfocus.com/columnists/384


II.  BUGTRAQ SUMMARY
--------------------
1. ADOdb Server.PHP SQL Injection Vulnerability
BugTraq ID: 16187
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16187
Summary:

ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Exploitation of this issue requires the root password for MySQL to be empty and the affected script to be located inside the web root.

2. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

3. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

4. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
BugTraq ID: 16177
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16177
Summary:
Dave Carrigan's auth_ldap is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in the format-specifier of a formatted printing function.

This issue likely arises only if auth_ldap has been enabled and is used for user authentication.

This issue allows remote attackers to execute arbitrary machine code in the context of Apache webservers that use the affected module. This may facilitate the compromise of affected computers.

5. HP Tru64 DNS BIND Unspecified Remote Unauthorized Access Vulnerability
BugTraq ID: 16455
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16455
Summary:

HP Tru64 DNS BIND is prone to an unspecified remote unauthorized-access vulnerability.

Further details are not currently available; this BID will be updated when more information becomes available.

6. FarsiNews Loginout.PHP Remote File Include Vulnerability
BugTraq ID: 16440
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16440
Summary:

FarsiNews is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This issue is reported to affect versions 2.1 Beta2 and earlier.

7. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15158
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15158
Summary:
A remote buffer-overflow vulnerability affects Ethereal. This issue is due to the application's failure to securely copy network-derived data into sensitive process buffers. The specific issue resides in the Service Location Protocol dissector.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

This issue may be exploited by a single TCP packet to port 427, since Ethereal does not keep track of connection states. This allows malicious users to spoof the origin of attacks and to exploit this vulnerability when no services are actively listening on TCP port 427.

Note that this issue was originally disclosed in BID 15148 "Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13".

8. Mozilla Thunderbird File Attachment Spoofing Vulnerability
BugTraq ID: 16271
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16271
Summary:
Mozilla Thunderbird is prone to a file-attachment spoofing vulnerability.

Successful exploitation may allow attackers to place malicious files on a user's computer by tricking users into saving seemingly safe attachments. If the user subsequently opens the file, this vulnerability may facilitate arbitrary code execution in the context of the user.

Thunderbird versions prior to 1.5 are affected.

9. MyBB Notepad UserCP.PHP HTML Injection Vulnerability
BugTraq ID: 16361
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16361
Summary:
MyBB is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

10. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 15394
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15394
Summary:
Sudo is prone to a security bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored.

An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.

An attacker must have the ability to run Perl scripts through Sudo to exploit this vulnerability.

11. Rockliffe MailSite HTTP Mail Management Agent Denial Of Service Vulnerability
BugTraq ID: 16331
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16331
Summary:

MailSite is prone to a denial-of-service vulnerability. This issue affects the HTTP management agent.

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

12. @Mail Compose.PL Directory Traversal Vulnerability
BugTraq ID: 16470
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16470
Summary:

@Mail is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to overwrite arbitrary files in the context of the affected application. Depending on the files overwritten, this may facilitate a compromise of the underlying system; other attacks are also possible.

This issue is reported to affect @Mail installations on Microsoft Windows only. Note that the default installation of Apache on Microsoft Windows is run with SYSTEM privileges, thus elevating the impact of this issue.

13. Aquifer CMS Index.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16162
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16162
Summary:
Aquifer CMS is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

14. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
BugTraq ID: 16301
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16301
Summary:
The Linux kernel dm-crypt module is susceptible to a local information-disclosure vulnerability. This issue is due to the module's failure to properly zero-sensitive memory buffers before freeing the memory.

This issue may allow local attackers to gain access to potentially sensitive memory that contains information on the cryptographic key used for the encrypted storage. This may aid them in further attacks.

This issue affects the 2.6 series of the Linux kernel.

15. Blue Coat Systems WinProxy Remote Host Header Buffer Overflow Vulnerability
BugTraq ID: 16147
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16147
Summary:
A remote buffer-overflow vulnerability affects Blue Coat Systems WinProxy. This issue is due the application's failure to properly validate the length of user-supplied strings before copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.

Blue Coat Systems WinProxy version 6.0 is vulnerable to this issue; other versions may also be affected.

16. HP-UX FTPD Remote Denial Of Service Vulnerability
BugTraq ID: 16316
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16316
Summary:
A remote denial-of-service vulnerability has been reported in the HP-UX 'ftpd' implementation. A remote unauthenticated user may cause the FTP server process to become unresponsive.

The precise technical details of this vulnerability are currently unknown. This BID will be updated as further information becomes available.

17. pcAnywhere Authentication Denial of Service Vulnerability
BugTraq ID: 15646
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15646
Summary:
Symantec pcAnywhere is vulnerable to a buffer overflow vulnerability.  Because the flaw can be triggered prior to authentication, the vulnerability is exploitable by remote attackers without valid credentials.  It is confirmed that the vulnerability can be exploited to cause a denial of service.  Supported versions 11.0.1 and 11.5.1 are confirmed affected.  Previous versions are vulnerable and users are advised to upgrade to the latest supported version.

Patches are available.

18. Microsoft Windows Asynchronous Procedure Call Local Privilege Escalation Vulnerability
BugTraq ID: 15826
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15826
Summary:
Microsoft Windows is susceptible to a local privilege-escalation vulnerability. This issue is due to a flaw in the Asynchronous Procedure Calls implementation in Microsoft Windows.

This issue allows local attackers to gain elevated privileges, facilitating the complete compromise of affected computers.

19. ImageMagick Image Filename Remote Command Execution Vulnerability
BugTraq ID: 16093
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16093
Summary:
ImageMagick is prone to a remote shell command-execution vulnerability.

Successful exploitation can allow arbitrary commands to be executed in the context of the affected user. Note that this issue could also be exploited through other applications that use ImageMagick as the default image viewer.

ImageMagick 6.2.4.5 is reportedly vulnerable. Other versions may be affected as well.

20. Shareaza Multiple Remote Integer Overflow Vulnerabilities
BugTraq ID: 16399
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16399
Summary:


Shareaza is prone to multiple integer-overflow vulnerabilities. These issues are due to the application's failure to properly ensure that user-supplied input does not result in the overflowing of integer values. This may result in data being copied past the end of a memory buffer.

Attackers may exploit these vulnerabilities to execute arbitrary code in the context of the application.

Shareaza 2.2.1.0 is reportedly vulnerable. Other versions may be affected as well.

21. Eggblog Multiple Input Validation Vulnerabilities
BugTraq ID: 16305
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16305
Summary:
Eggblog is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

22. Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
BugTraq ID: 16384
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16384
Summary:
Oracle PL/SQL gateway is prone to a vulnerability that permits the bypassing of an access control list. This issue is due to an error in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to bypass the exclusion list and to gain access to excluded packages and procedures running in the context of the DBA; this may facilitate privilege escalation.

Successful exploitation may faciliate a compromise of the database server and enable an attacker to gain full DBA access.

23. SCO UnixWare UIDAdmin Local Buffer Overflow Vulnerability
BugTraq ID: 15811
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15811
Summary:
SCO UnixWare is prone to a local buffer-overflow vulnerability.

The vulnerability presents itself when the application processes excessive data supplied to the 'uidadmin' utility.

UnixWare 7.1.3 and UnixWare 7.1.4 are affected by this issue. Previous versions may also be affected.

24. Linux Kernel Multiple Security Vulnerabilities
BugTraq ID: 16414
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16414
Summary:
Linux kernel is prone to multiple vulnerabilities. These issues can allow local and remote attackers to trigger denial-of-service conditions or to corrupt memory to potentially execute arbitrary code.

These issues affect kernel versions 2.6.15 and prior.

25. Multiple Vendor Spoofed IGMP Report Denial Of Service Vulnerability
BugTraq ID: 5020
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/5020
Summary:
Internet Group Management Protocol (IGMP) specifies guidelines for the management of Internet Multicast Routing management.

An arbitrary host may deny service to a system on the same segment of network. In a situation where a multicast router sends a membership report request, a host sending a unicast membership report response to the primary responder can prevent the responder from sending a message to the multicast router. In doing so, the router will not receive a response from any host, and thus the transmission will timeout and cease.

This vulnerability may additionally affect other operating systems, though it is currently unknown which implementations may be vulnerable.

26. EMC Legato Networker Multiple Remote Vulnerabilities
BugTraq ID: 16275
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16275
Summary:
EMC Legato Networker is affected by multiple remote vulnerabilities. A denial-of-service issue and two remote code-execution issues have been identified.

Version 7.2.1 of Legato Networker is vulnerable to these issues; prior versions may also be affected.

27. Fcron Convert-FCronTab Local Buffer Overflow Vulnerability
BugTraq ID: 16467
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16467
Summary:
Fcron is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This issue allows local attackers to execute arbitrary machine code with superuser privileges, since the affected utility is installed setuid-superuser by default in some installations. This allows attackers to completely compromise affected computers.

Fcron version 3.0 is affected by this issue; previous versions may also be affected.

Update: This issue is now retired. Further analysis reveals that this issue cannot be exploited for code execution; therefore, this is not a vulnerability.

28. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.

29. Blackboard Academic Suite Frameset.JSP Cross-Domain Frameset Loading Vulnerability
BugTraq ID: 15814
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15814
Summary:
Blackboard Academic Suite is prone to a cross-domain frameset-loading vulnerability.

Successful exploitation may result in various attacks, such as information disclosure and session hijacking. An attacker may also be able to exploit this vulnerability to carry out phishing-style attacks.

Blackboard Academic Suite version 6.0 is reportedly affected by this issue.

30. CipherTrust IronMail Remote Denial Of Service Vulnerability
BugTraq ID: 16465
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16465
Summary:
IronMail is prone to a remote denial-of-service vulnerability. This issue is due to an error in the device when dealing with SYN flood attacks.

A remote attacker can exploit this issue to cause the device to fail, denying service to legitimate users.

Further information from the vendor reports that this issue doesn'tcause the device to actually fail, but to enter a defensive posture to protect against further denial-of-service attacks. However, this denial-of-service feature does remain in a defensive state for a prolonged period of time after the initial attack has subsided.

31. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.

Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.

This issue affects Apache 2.x versions.

32. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

33. ADOdb PostgreSQL SQL Injection Vulnerability
BugTraq ID: 16364
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16364
Summary:

ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects only ADOdb implementations using PostgreSQL; other databases are not affected.

34. Apache HTTP Request Smuggling Vulnerability
BugTraq ID: 14106
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14106
Summary:
Apache is prone to an HTTP-request-smuggling attack.

A specially crafted request with a 'Transfer-Encoding: chunked' header and a 'Content-Length' header can cause the server to forward a reassembled request with the original 'Content-Length' header. As a result, the malicious request may piggyback on the valid HTTP request.

This attack may result in cache poisoning, cross-site scripting, session hijacking, and other attacks.

This issue was originally described in BID 13873 (Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities). Due to the availability of more details and vendor confirmation, the issue is now a new BID.

35. Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 14366
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14366
Summary:
mod_ssl is prone to an off-by-one buffer overflow condition.

The vulnerability arising in the mod_ssl CRL verification callback allows for potential memory corruption when a malicious CRL is handled.

An attacker may exploit this issue to trigger a denial of service condition.  It is conjectured that arbitrary code execution may be possible as well.

36. Qualcomm WorldMail IMAPD Buffer Overflow Vulnerability
BugTraq ID: 15980
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15980
Summary:
WorldMail IMAPd service is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in finite-sized buffers.

An attacker can exploit this issue to crash the server resulting in a denial of service to legitimate users. Arbitrary code execution may also be possible; this may facilitate a compromise of the underlying system.

This issue is reported to affect IMAPd service version 6.1.19.0 of WorldMail 3.0; other versions may also be vulnerable.

37. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
BugTraq ID: 15523
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15523
Summary:
IPsec-Tools is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions when in 'AGGRESSIVE' mode.

An attacker can exploit this issue to crash the application, thus denying service to legitimate users.

These vulnerabilities were discovered by, and may be reproduced by, the University of Oulu Secure Programming Group PROTOS IPSec Test Suite.

38. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
BugTraq ID: 15743
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15743
Summary:
FFmpeg's libavcodec is susceptible to a heap buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied data before using it in memory allocation and copy operations.

Attackers may exploit this vulnerability to execute arbitrary code in the context of applications that use an affected version of the libavcodec library.

An attacker can exploit this issue by enticing a user to open a malformed PNG file with an application that uses a vulnerable version of libavcodec. If the application is configured as the default handler for PNG files, this could present a viable web or email attack vector -- when the PNG is clicked from an appropriate client application, the application using the vulnerable library will automatically be invoked.

39. CyberStrong EShop 20review.ASP SQL Injection Vulnerability
BugTraq ID: 14101
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14101
Summary:
CyberStrong eShop is prone to an SQL-injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application. The attacker may accomplish this by passing malicious SQL syntax to the vulnerable '20review.asp' script.

Reportedly, the attacker may steal eShop authentication information. Other attacks may be possible, depending on the capabilities of the underlying database and the nature of the affected query.

40. Elido Face Control Multiple Directory Traversal Vulnerabilities
BugTraq ID: 16401
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16401
Summary:
Face Control is prone to multiple directory-traversal vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks; other attacks are also possible.

41. Microsoft Windows Media Player Automatic File Download and Execution Vulnerability
BugTraq ID: 7640
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/7640
Summary:
Windows Media Player reportedly allows for the automatic downloading and execution of files. This is done using a specifically crafted XMLNS (XML Name Space) URI embedded within an HTML email message. Combined with the vulnerability described in BID 5543, this allows Windows Media Player to download and execute the referenced file without user intervention.

42. DotNetNuke Failed Logon Username Application Logs HTML Injection Vulnerability
BugTraq ID: 13647
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13647
Summary:
DotNetNuke is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content. Specifically, the application fails to sanitize user-supplied input that is supplied as a failed logon Username string value, allowing script or HTML code to be included in application log files.

43. DotNetNuke User Registration Information HTML Injection Vulnerability
BugTraq ID: 13644
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13644
Summary:
DotNetNuke is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content. Specifically, the application fails to sanitize user-supplied input that is supplied while registering a user, allowing script or HTML code to be included in user-information pages.

44. Cisco IOS Multiple Unspecified EIGRP Vulnerabilities
BugTraq ID: 14877
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14877
Summary:
Cisco IOS is susceptible to multiple unspecified EIGRP vulnerabilities.

Further details are currently unavailable. This BID will be updated as more information is disclosed.

Due to the nature of the protocol, attackers likely require access to hosts in networks operating with the vulnerable protocol.

45. CRE Loaded Files.PHP Access Validation Vulnerability
BugTraq ID: 16415
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16415
Summary:
CRE Loaded is prone to an access-validation vulnerability. This issue is due to a failure in the application to limit access to administrative sections of the application.

An attacker can exploit this vulnerability to overwrite, delete, and create files and directories in the context of the webserver process. This may result in a loss of confidentiality. The attacker may use this information in further attacks.

This issue is reported to affect CRE Loaded version 6.15; other versions may also be vulnerable.

46. SPIP Multiple SQL Injection Vulnerabilities
BugTraq ID: 16458
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16458
Summary:

SPIP is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Versions prior to and including 1.8.2-e and 1.9 alpha 2 are vulnerable; other versions may also be affected.

47. DotNetNuke User-Agent String Application Logs HTML Injection Vulnerability
BugTraq ID: 13646
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13646
Summary:
DotNetNuke is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.  Specifically user-supplied input supplied as a User-Agent string value is not sanitized, allowing script or HTML code to be included in application log files.

48. WatchGuard ServerLock Physical Memory Device Access Vulnerability
BugTraq ID: 8223
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/8223
Summary:
WatchGuard ServerLock has been reported prone to a vulnerability that may allow a local attacker to bypass ServerLock controls.

The issue presents itself because ServerLock fails to sufficiently secure the physical memory of a device. Reportedly, a local attacker may subvert ServerLock access controls by creating symlinks to a target device.

Note that while this vulnerability has been reported to affect WatchGuard ServerLock version 2.0.3 on Windows 2000 systems, previous versions are also likely vulnerable. Other platforms are not known to be affected.

49. Microsoft Windows Shell Remote Code Execution Vulnerability
BugTraq ID: 13132
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13132
Summary:
Microsoft Windows is prone to a vulnerability that may allow remote attackers to execute code through the Windows Shell.  The cause of the vulnerability is related to how the operating system handles unregistered file types.  The specific issue is that files with an unknown extension may be opened with the application specified in the embedded CLSID.

The victim of the attack would be required to open a malicious file, possibly hosted on a Web site or sent through email.  Social engineering would generally be required to entice the victim into opening the file.

50. UIM LibUIM Environment Variables Privilege Escalation Weakness
BugTraq ID: 15007
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15007
Summary:
Uim is reported prone to a privilege escalation weakness.

An attacker that has local interactive access to a system that has a vulnerable application installed may potentially exploit this weakness to escalate privileges.

This issue is reported to affect all stable versions prior to 0.4.9.1, and in development versions prior to 0.5.0.1.

51. PHP GEN Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 15458
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15458
Summary:
PHP GEN is prone to unspecified cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

52. CGI.pm Start_Form Cross-Site Scripting Vulnerability
BugTraq ID: 8231
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/8231
Summary:
CGI.pm is prone to cross-site scripting attacks under some circumstances. This issue occurs because the 'start_form()' function (or other functions that use this function) does not sufficiently sanitize HTML and script code when a form action isn't specified. This could expose scripts that use the function to cross-site scripting attacks.

53. Safe.PM Unsafe Code Execution Vulnerability
BugTraq ID: 6111
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/6111
Summary:
When Perl code is executed within a Safe compartment, it cannot access variables outside of the compartment unless the outside code chooses to share the variables with the code inside the compartment.

If code inside a Safe compartment is executed via 'Safe->reval()' twice, it can change its operation mask the second time. This could allow the code to access variables outside the Safe compartment.

54. Adobe Multiple Local Privilege Escalation Vulnerabilities
BugTraq ID: 16451
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16451
Summary:
Multiple Adobe products are susceptible to privilege-escalation vulnerabilities. These issues are due to insecure permissions on unspecified executable files.

These issues allow unprivileged local users to execute arbitrary machine code with elevated privileges.

55. Pioneers Chat Buffer Denial Of Service Vulnerability
BugTraq ID: 16429
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16429
Summary:

Pioneers is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.

An attacker can exploit this issue to crash the affected Pioneers server and possibly clients connected to a vulnerable Pioneers server.

This issue is reported to affect version 0.9.40; other versions may also be vulnerable.

56. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.

This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and supplying excessive data to be stored in the affected file.

This may cause a denial-of-service condition.

**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. The alleged flaw cannot be reproduced by Symantec.

57. GD Graphics Library Remote Integer Overflow Vulnerability
BugTraq ID: 11523
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/11523
Summary:
The GD Graphics Library (gdlib) is affected by an integer overflow that facilitates a heap overflow. This issue is due to the library's failure to do proper sanity checking on size values contained within image-format files.

An attacker may leverage this issue to manipulate process heap memory, potentially leading to code execution and compromise of the computer running the affected library.

58. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability.

Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user uses authentication methods other than GSSAPI to connect, which is not usually expected.

This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use the credentials to access resources granted to the original principal.

This issue affects versions of OpenSSH prior to 4.2.

59. MediaWiki Inline Style Attribute Security Check Bypass Vulnerability
BugTraq ID: 16032
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16032
Summary:
MediaWiki is prone to a vulnerability that may allow attackers to execute script code in a user's browser.

Security checks related to inline style attributes can be bypassed, facilitating injection of script code to be executed in a user's browser.

MediaWiki 1.5.3 is known to be vulnerable to this issue; other versions may be affected as well.

60. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 16171
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16171
Summary:
Multiple remote buffer-overflow vulnerabilities affect Bogofilter. These issues are due to the application's failure to properly handle invalid input sequences and to validate the length of user-supplied strings before copying them into static process buffers.

An attacker may exploit these issue to cause a denial-of-service condition or possibly to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.

Note that successful exploitation requires that Bogofilter be used with a Unicode database.

61. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.

Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.

Note that other attack vectors also exist that may not require user interaction, since the application can be used with custom printing systems and web applications.

A successful attack may crash the application or lead to arbitrary code execution.

All versions of ImageMagick are considered vulnerable at the moment.

62. Sudo Python Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 16184
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16184
Summary:
Sudo is prone to a security bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.

A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. Attackers may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.

An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.

This issue is similar to BID 15394 ( Sudo Perl Environment Variable Handling Security Bypass Vulnerability).

63. GIT Remote Buffer Overflow Vulnerability
BugTraq ID: 16417
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16417
Summary:
GIT is prone to a remote buffer-overflow vulnerability.

The issue presents itself when a large symbolic link in an index file is processed. A successful attack may result in arbitrary code execution in the context of the user.

64. OpenSSL Insecure Protocol Negotiation Weakness
BugTraq ID: 15071
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15071
Summary:
OpenSSL is susceptible to a remote protocol-negotiation weakness. This issue is due to the implementation of the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option to maintain compatibility with third-party software.

This issue presents itself when two peers try to negotiate the protocol they wish to communicate with. Attackers who can intercept and modify the SSL communications may exploit this weakness to force SSL version 2 to be chosen.

The attacker may then exploit various insecurities in SSL version 2 to gain access to or tamper with the cleartext communications between the targeted client and server.

Note that the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option is enabled with the frequently used 'SSL_OP_ALL' option.

SSL peers that are configured to disallow SSL version 2 are not affected by this issue.

65. Microsoft Internet Explorer Dialog Manipulation Vulnerability
BugTraq ID: 15823
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15823
Summary:
Internet Explorer is prone to a remote code-execution vulnerability through manipulation of custom dialog boxes. Keystrokes entered while one of these dialogs is displayed may be buffered and passed to a download dialog, allowing attacker-supplied code to be executed.

66. MyBB Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16387
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16387
Summary:
MyBB is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

67. Multiple Vendor TCP Timestamp PAWS Remote Denial Of Service Vulnerability
BugTraq ID: 13676
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13676
Summary:
A denial-of-service vulnerability exists for the TCP RFC 1323. The issue resides in the Protection Against Wrapped Sequence Numbers (PAWS) technique that was included to increase overall TCP performance.

When TCP 'timestamps' are enabled, both hosts at the endpoints of a TCP connection employ internal clocks to mark TCP headers with a 'timestamp' value.

When TCP PAWS is configured to employ timestamp values, this functionality exposes TCP PAWS implementations to a denial-of-service vulnerability.

The issue manifests if an attacker transmits a sufficient TCP PAWS packet to a vulnerable computer. The attacker sets a large value as the packet timestamp. When the target computer processes this packet, the internal timer is updated to the large value that the attacker supplied. This causes all other valid packets that are received subsequent to an attack to be dropped, because they are deemed to be too old or invalid. This type of attack will effectively deny service for a target connection.

68. Gzip Zgrep Arbitrary Command Execution Vulnerability
BugTraq ID: 13582
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13582
Summary:
zgrep is reportedly affected by an arbitrary command execution vulnerability.

An attacker may execute arbitrary commands through zgrep command arguments to potentially gain unauthorized access to the affected computer.  It should be noted that this issue only poses a security threat if the arguments originate from a malicious source.

zgrep 1.2.4 was reported vulnerable.  Other versions may be affected as well.

69. GNU Mailman Large Date Data Denial Of Service Vulnerability
BugTraq ID: 16248
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16248
Summary:
GNU Mailman is prone to a denial-of-service attack. This issue affects the email date parsing functionality of Mailman.

The vulnerability could be triggered by mailing-list posts and will impact the availability of mailing lists hosted by the application.

70. Invision Power Board Portal Plugin Index.PHP SQL Injection Vulnerability
BugTraq ID: 16447
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16447
Summary:

Portal is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

71. MyBB Signature HTML Injection Vulnerability
BugTraq ID: 16308
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16308
Summary:
MyBB is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

The discoverer of this vulnerability has not disclosed which version or
versions of the application may be vulnerable to this issue. It is
conjectured this issue affects recent versions of MyBB.

72. BZip2 CHMod File Permission Modification Race Condition Weakness
BugTraq ID: 12954
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/12954
Summary:
The 'bzip2' utility is reported prone to a security weakness. The issue is present only when an archive is extracted into a world- or group-writeable directory. It is reported that bzip2 employs non-atomic procedures to write a file and later changes the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.

This weakness is reported to affect bzip2 version 1.0.2 and previous versions.

73. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:

The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

74. Nullsoft Winamp Malformed Playlist File WMA Extention Remote Buffer Overflow Vulnerability
BugTraq ID: 16462
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16462
Summary:
Winamp is susceptible to a buffer-overflow vulnerability when handling specially crafted playlist files.
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.

Winamp version 5.094 is reported susceptible to this issue; other versions may also be affected.

This issue is similar to the one described in BID 16410 (Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability), but they likely exist in differing code paths in the application.

75. Cisco CallManager CCMAdmin Remote Privilege Escalation Vulnerability
BugTraq ID: 16293
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16293
Summary:
Cisco CallManager is susceptible to a remote privilege escalation vulnerability. This issue is due to a failure of the application to properly enforce access controls. This issue is only exploitable when Multi Level Administration is enabled, and users are granted read-only administrative access via the CCMAdmin Web interface.

This issue allows remote attackers to gain full read-write administrative access to the Web interface of Cisco CallManager.

76. BEA WebLogic Server and WebLogic Express Multiple Remote Vulnerabilities
BugTraq ID: 13717
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/13717
Summary:
BEA WebLogic is susceptible to multiple vulnerabilities. The following specific issues have been identified:

- A denial-of-service vulnerability allows users with the 'Monitor security' role to reset JDBC connection pools, or to reduce the number of connections available.

- A denial-of-service vulnerability allows attackers to cause the failure of security exception auditing.
- An access-validation vulnerability in the security constraint system fails to force the currently logged-in users to reauthenticate to the application server once security constraints have been altered and the application has been redeployed, even if the new constraints preclude the users access.

- A local information-disclosure vulnerability as the 'UserLogin' control displays cleartext passwords of failed authentication attempts to standard output.

- A denial-of-service vulnerability in the cookie parsing code may cause clustered servers to slow down when cookies with an invalid host or port are processed.

- Multiple unspecified cross-site scripting vulnerabilities reside in the server console and login page. These issues allow attackers to execute script code in the context of the affected website, possibly allowing them to gain administrative access to the affected application server.

- A vulnerability in the embedded LDAP server allows remote attackers to anonymously bind to it. This allows for information disclosure, and possibly a denial-of-service condition due to resource exhaustion.

- An unspecified buffer overflow vulnerability may allow remote attackers to cause the instance to become unstable. This issue may allow remote attackers to cause a thread loop, consuming CPU resources. Due to the nature of buffer-overflow vulnerabilities, an attacker may be able to execute arbitrary machine code in the context of the affected application.

This BID will be split into individual BIDs in the future as further details become available.

77. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
BugTraq ID: 14902
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14902
Summary:
A local denial of service vulnerability affects the Linux on 64 bit Symmetric Multi-Processor (SMP) platforms.

Specifically, the vulnerability presents itself due to an omitted call to the 'sockfd_put()' function in the 32-bit compatible 'routing_ioctl()' function.

The 32-bit compatible 'tiocgdev ioctl()' function on x86-64 platforms is affected by this issue as well.

78. PmWiki Multiple Input Validation Vulnerabilities
BugTraq ID: 16421
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16421
Summary:

PmWiki is prone to multiple input-validation vulnerabilities. These issues are due to failures in the application to properly sanitize user-supplied input.

- Arbitrary remote file-include vulnerability. Exploitation of this issue will result in the execution of attacker-supplied code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system.

- Unspecified HTML-injection issues. Successful exploitation will permit an attacker to inject arbitrary HTML code. When viewed, this code will be executed in the browser of a victim user in the context of the webserver process. Successful exploitation may aid in the theft of cookie-based authentication credentials, or allow the attacker to control how the site is rendered to the user; other attacks are also possible.

These issues affect version 2.1 beta20; other versions may also be vulnerable.

79. CheesyBlog Multiple HTML Injection Vulnerabilities
BugTraq ID: 16376
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16376
Summary:
CheesyBlog is prone to multiple HTML injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

80. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
BugTraq ID: 16203
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16203
Summary:
XMame is prone to locally exploitable buffer-overflow vulnerabilities. These issues are due to insufficient bounds checking of command-line parameters.

Successful exploitation on some systems could result in execution of malicious instructions with elevated privileges, since XMame may be installed with setuid-superuser privileges.

XMame version 0.102 is vulnerable to these issues; other versions may also be affected.

This issue may be related to BID 7773 (XMame Lang Local Buffer Overflow Vulnerability).

81. ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
BugTraq ID: 16406
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16406
Summary:
ZixForum is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

82. Phpclanwebsite Multiple Input Validation Vulnerabilities
BugTraq ID: 16391
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16391
Summary:

Phpclanwebsite is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. If successful, an attacker may also exploit vulnerabilities in the underlying database implementation as well as conduct other attacks.

Phpclanwebsite version 1.23.1 is vulnerable; other versions may also be affected.

83. BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
BugTraq ID: 15052
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15052
Summary:
BEA has released 24 advisories identifying various vulnerabilities affecting BEA WebLogic Server and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.

We conjecture that some of these issues may allow an attacker to completely compromise a vulnerable computer.

These issues are currently being analyzed. This BID will be updated and individual BIDs will be released when further analysis is complete.

84. LSH Seed File File Descriptor Leakage Vulnerability
BugTraq ID: 16357
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16357
Summary:
lsh may leak file descriptors that may allow a local attacker to access sensitive information or to cause a denial-of-service condition.

lsh 2.0.1 is reportedly vulnerable. Other versions may be affected as well.

85. RCBlog Index.PHP Directory Traversal Vulnerability
BugTraq ID: 16342
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16342
Summary:
RCBlog is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks; other attacks are also possible.

Version 1.0.3 is vulnerable; other versions may also be affected.

86. Multiple Vendor KernFS LSEEK Local Kernel Memory Disclosure Vulnerability
BugTraq ID: 16173
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16173
Summary:
The 'kernfs' filesystem in both NetBSD and OpenBSD is prone to a kernel memory disclosure vulnerability. This issue arises due to insufficient sanitization of user-supplied arguments passed to the 'lseek()' system call.

An attacker may use information disclosed through this attack to launch other attacks against a computer and potentially to aid in a complete compromise.

Note that OpenBSD has completely removed kernfs since OpenBSD 3.8; version 3.7 had kernfs support disabled in their GENERIC kernel, and has never mounted the kernfs filesystem by default.

87. AshWebStudio AshNews Remote File Include Vulnerability
BugTraq ID: 16436
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16436
Summary:

Ashnews is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the Web server process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

88. Hitachi JP1/NetInsight II - Port Discovery Denial of Service Vulnerability
BugTraq ID: 16327
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16327
Summary:

JP1/NetInsight II - Port Discovery is prone to a denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.

An attacker can exploit this issue to crash the application denying service to legitmate users.

89. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this vulnerability to corrupt kernel memory or free non-allocated memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.

90. FreeBSD TCP SACK Remote Denial Of Service Vulnerability
BugTraq ID: 16466
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16466
Summary:
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that potentially results in an infinite-loop condition when handling TCP SACK packets.

This issue allows remote attackers to cause affected kernels to enter into an infinite loop, denying further network service to legitimate users.

91. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The kdegraphics package and KPDF versions 3.4.3 and earlier, and KOffice and KWord versions 1.4.2 and earlier are vulnerable.

92. My Amazon Store Manager Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16312
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16312
Summary:
My Amazon Store Manager is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Version 1.0 is reported to be vulnerable; other versions may also be affected.

93. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
BugTraq ID: 15642
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15642
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

In instances where a process is created via the 'clone()' system call with the 'CLONE_THREAD' argument ptraced, the kernel fails to properly ensure that the ptracing process is not attempting to trace itself.

This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.14.2 are vulnerable to this issue.

94. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
BugTraq ID: 14168
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14168
Summary:
Net-SNMP is prone to a remote denial-of-service vulnerability. The issue is exposed when Net-SNMP is configured to have an open stream-based protocol port, such as TCP.

The exact details describing this issue are not available. This BID will be updated when further details are made available.

95. Samba Directory Access Control List Remote Integer Overflow Vulnerability
BugTraq ID: 11973
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/11973
Summary:
A remotely exploitable integer-overflow vulnerability affects Samba's directory access control list (DACL) processing functionality. This issue is due to the application's failure to properly perform sanity checking on calculated data sizes before copying data into static process buffers.

An attacker with access to an SMB share may leverage this issue to overwrite the heap of the affected process, facilitating code execution with superuser privileges.

96. My Little Homepage Products BBCode Link Tag Script Injection Vulnerability
BugTraq ID: 16395
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16395
Summary:
My Little Homepage Web log, guestbook, and forum are prone to a script injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.

97. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
BugTraq ID: 15627
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/15627
Summary:
Linux kernel is susceptible to a local denial of service vulnerability.

This issue is triggered by consuming excessive kernel log memory by obtaining numerous file lock leases. Once the leases timeout, the event will be logged, and kernel memory will be consumed.

This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition, and a denial of service for legitimate users.

Kernel versions prior to 2.6.15-rc3 are vulnerable to this issue.

98. Nullsoft Winamp Malformed Playlist File Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 16410
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/16410
Summary:
Winamp is susceptible to a buffer-overflow vulnerability when handling specially crafted playlist files.
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.

Winamp 5.11 and 5.12 are reportedly affected by this issue.

99. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
BugTraq ID: 12837
Remote: No
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/12837
Summary:
The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines.

An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges.

These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11.

100. SoftiaCom WMailserver Remote Buffer Overflow Vulnerability
BugTraq ID: 14213
Remote: Yes
Last Updated: 2006-02-07
Relevant URL: http://www.securityfocus.com/bid/14213
Summary:
SoftiaCom WMailserver contains a remote buffer-overflow vulnerability in its connection-handling code. This issue is due to the application's  failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

If an attacker can connect to the SMTP service and send an excessive chunk of data, arbitrary machine code execution is possible. Failed exploitation attempts may result in crashing the application.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Apple's in the eye of flaw finders
By: Robert Lemos
With the move to Intel processors and a larger share of the market, Apple's Mac OS X could find itself a more popular target of attack, security professionals say.
http://www.securityfocus.com/news/11375

2. Blackmal virus set to delete files
By: Robert Lemos
Security experts urge companies to clean their networks of a malicious mass-mailing computer virus, before compromised systems reach the first trigger date and start deleting eleven types of files.
http://www.securityfocus.com/news/11374

3. Good worms back on the agenda
By: Robert Lemos
A researcher argues that the spreading capabilities of worms could better perform penetration testing inside networks, turning vulnerable systems into distributed scanners.
http://www.securityfocus.com/news/11373

4. Researchers: Rootkits headed for BIOS
By: Robert Lemos
UPDATE: Insider attacks and industrial espionage could
become more stealthy by hiding code in the
core system functions stored on the motherboard,
researchers say.
http://www.securityfocus.com/news/11372

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Detroit
http://www.securityfocus.com/archive/77/424302

2. [SJ-JOB] Security Consultant, Miami
http://www.securityfocus.com/archive/77/424303

3. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/424298

4. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/424299

5. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/424301

6. [SJ-JOB] Security Architect, Plano
http://www.securityfocus.com/archive/77/424243

7. [SJ-JOB] Application Security Engineer, Pasadena
http://www.securityfocus.com/archive/77/424242

8. [SJ-JOB] Security Consultant, Herndon
http://www.securityfocus.com/archive/77/424245

9. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/424247

10. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/424244

11. [SJ-JOB] Sales Representative, Northern Virginia / DC
http://www.securityfocus.com/archive/77/424168

12. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/424167

13. [SJ-JOB] Sr. Security Analyst, Pasadena
http://www.securityfocus.com/archive/77/424170

14. [SJ-JOB] Security Engineer, Pasadena
http://www.securityfocus.com/archive/77/424171

15. [SJ-JOB] Developer, Pasadena
http://www.securityfocus.com/archive/77/424165

16. [SJ-JOB] Security Architect, Pasadena
http://www.securityfocus.com/archive/77/424169

17. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/424154

18. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/424152

19. [SJ-JOB] Sr. Security Analyst, Phoenix
http://www.securityfocus.com/archive/77/424203

20. [SJ-JOB] Sales Engineer, Charlotte
http://www.securityfocus.com/archive/77/424151

21. [SJ-JOB] Account Manager, San Francisco/San Jose Bay Area
http://www.securityfocus.com/archive/77/424089

22. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/424091

23. [SJ-JOB] Threat Analyst, Lombard
http://www.securityfocus.com/archive/77/424088

24. [SJ-JOB] Sales Engineer, Oxon/Berks
http://www.securityfocus.com/archive/77/424090

25. [SJ-JOB] Sales Representative, London
http://www.securityfocus.com/archive/77/424087

26. [SJ-JOB] Sr. Security Analyst, Denver
http://www.securityfocus.com/archive/77/424102

27. [SJ-JOB] Security Auditor, Milwaukee
http://www.securityfocus.com/archive/77/424103

28. [SJ-JOB] Security Auditor, McLean
http://www.securityfocus.com/archive/77/424104

29. [SJ-JOB] Manager, Information Security, West Suburbs - Chicago
http://www.securityfocus.com/archive/77/424100

30. [SJ-JOB] Application Security Engineer, Greenwich
http://www.securityfocus.com/archive/77/424101

31. [SJ-JOB] Sr. Security Analyst, Oak Ridge
http://www.securityfocus.com/archive/77/424099

32. [SJ-JOB] Application Security Architect, Ft Lauderdale
http://www.securityfocus.com/archive/77/424096

33. [SJ-JOB] Account Manager, Bay Area
http://www.securityfocus.com/archive/77/424097

34. [SJ-JOB] Database Security Engineer, Ft Lauderdale
http://www.securityfocus.com/archive/77/424098

35. [SJ-JOB] Security Consultant, Irvine
http://www.securityfocus.com/archive/77/424065

36. [SJ-JOB] Sales Representative, Mclean
http://www.securityfocus.com/archive/77/424061

37. [SJ-JOB] Security Engineer, Bay Area
http://www.securityfocus.com/archive/77/424063

38. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/424059

39. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/424060

40. Working with a recruiter?
http://www.securityfocus.com/archive/77/423844

41. [SJ-JOB] Sales Engineer, Mclean
http://www.securityfocus.com/archive/77/423842

42. [SJ-JOB] Sales Engineer, Washington DC
http://www.securityfocus.com/archive/77/423843

43. [SJ-JOB] Security Consultant, Plano
http://www.securityfocus.com/archive/77/423975

44. [SJ-JOB] Auditor, Charlotte
http://www.securityfocus.com/archive/77/423834

45. [SJ-JOB] Security Consultant, Denver and/or Chicago
http://www.securityfocus.com/archive/77/423841

46. [SJ-JOB] Sr. Security Analyst, Alexandria
http://www.securityfocus.com/archive/77/423839

47. [SJ-JOB] Sr. Security Engineer, Reston
http://www.securityfocus.com/archive/77/423840

48. [SJ-JOB] Security Architect, Mississauga
http://www.securityfocus.com/archive/77/423838

49. [SJ-JOB] Security Architect, Framingham
http://www.securityfocus.com/archive/77/423826

50. [SJ-JOB] Security Architect, New York
http://www.securityfocus.com/archive/77/423772

51. [SJ-JOB] Security Architect, Los Angeles
http://www.securityfocus.com/archive/77/423776

52. [SJ-JOB] Security Architect, Chicago
http://www.securityfocus.com/archive/77/423715

53. [SJ-JOB] Security Architect, San Francisco
http://www.securityfocus.com/archive/77/423716

54. [SJ-JOB] Incident Handler, Los Angeles
http://www.securityfocus.com/archive/77/423717

55. [SJ-JOB] Threat Analyst, Ft. Lauderdale Metro Area
http://www.securityfocus.com/archive/77/423833

56. [SJ-JOB] Information Assurance Analyst, Washington, D.C.
http://www.securityfocus.com/archive/77/423935

57. [SJ-JOB] Security Engineer, Northern Virginia/Reston/Herndon/Tysons
http://www.securityfocus.com/archive/77/423708

58. [SJ-JOB] Technology Risk Consultant, Mclean
http://www.securityfocus.com/archive/77/423804

59. [SJ-JOB] Sr. Security Analyst, Los Angeles
http://www.securityfocus.com/archive/77/423709

60. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/423710

61. [SJ-JOB] Security Architect, New York/  Trenton NJ
http://www.securityfocus.com/archive/77/423707

62. [SJ-JOB] Auditor, Mclean
http://www.securityfocus.com/archive/77/423922

63. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/423698

64. [SJ-JOB] Sr. Security Engineer, Wilmington
http://www.securityfocus.com/archive/77/423699

65. [SJ-JOB] Security Engineer, Santa Barbara
http://www.securityfocus.com/archive/77/423702

66. [SJ-JOB] Sr. Security Analyst, Los Angeles
http://www.securityfocus.com/archive/77/423832

67. [SJ-JOB] Manager, Information Security, Wilmington
http://www.securityfocus.com/archive/77/423700

68. [SJ-JOB] Security Architect, Atlanta
http://www.securityfocus.com/archive/77/423691

69. [SJ-JOB] Security Consultant, Alexandria
http://www.securityfocus.com/archive/77/423830

70. [SJ-JOB] Security Engineer, Austin
http://www.securityfocus.com/archive/77/423794

71. [SJ-JOB] Security Architect, Alexandria
http://www.securityfocus.com/archive/77/423669

72. [SJ-JOB] Security System Administrator, San Francisco
http://www.securityfocus.com/archive/77/423668

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Buffer Overrun Newbie
http://www.securityfocus.com/archive/82/424156

2. Black Hat USA CFP opens, Europe early bird reminder, Federal  news
http://www.securityfocus.com/archive/82/423770

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #276
http://www.securityfocus.com/archive/88/424054

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Watchfire

AppScan 6.0 Available now! Web application security vulnerabilities are a growing threat for anyone doing business online. See if your applications are vulnerable. Download a Free Copy of Watchfire's AppScan 6.0 today. Watchfire named worldwide market share leader in web application security assessment by leading market research firm.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000007kqw