SecurityFocus Newsletter #337
Peter Laborge <[email protected]> Tue, 14 Feb 2006 16:53:02 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #337
----------------------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000C3f7
------------------------------------------------------------------
I. FRONT AND CENTER
1. Coffee shop WiFi for dummies
2. Sebek 3: tracking the attackers, part two
3. Privacy and anonymity
II. BUGTRAQ SUMMARY
1. MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
2. Microsoft Windows Media Player Bitmap Handling Buffer Overflow Vulnerability
3. Heimdal RSHD Local Privilege Escalation Vulnerability
4. LinPHA Multiple Local File Inclusion and PHP Code Injection Vulnerabilities
5. Multiple HiveMail Vulnerabilities
6. BlackBerry Enterprise Server Malformed Word Attachment Buffer Overflow Vulnerability
7. Lotus Domino LDAP Denial of Service Vulnerability
8. Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
9. PHP Event Calendar HTML Injection Vulnerability
10. Multiple Scriptme Applications BBCode URL Tag Script Injection Vulnerability
11. IBM AIX ARP Local Buffer Overflow Vulnerability
12. FarsiNews Directory Traversal and Local File Include Vulnerabilities
13. PowerD Remote Format String Vulnerability
14. HP PSC 1210 All-in-One Driver Unspecified Vulnerability
15. Sun ONE Directory Server Remote Denial Of Service Vulnerability
16. ELOG Web Logbook Multiple Remote Vulnerabilities
17. SUSE LD Insecure RPATH / RUNPATH Arbitrary Code Execution Vulnerability
18. GuestBookHost Multiple SQL Injection Vulnerabilities
19. OpenVMPS Logging Function Format String Vulnerability
20. Linux Kernel Multiple Vulnerabilities
21. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
22. Linux Kernel ICMP_Send Remote Denial Of Service Vulnerability
23. CPG Dragonfly CMS Remote Command Execution Vulnerability
24. RunCMS Remote Code Execution Vulnerability
25. IBM Lotus Notes File Attachment Handling Multiple Remote Vulnerabilities
26. IBM Lotus Domino iNotes Multiple HTML and Script Injection Vulnerabilities
27. SSH Tectia Server Remote Format String Vulnerability
28. QwikiWiki Search.PHP Cross-Site Scripting Vulnerability
29. CALimba RB_auth.PHP Multiple SQL Injection Vulnerabilities
30. Time Tracking Software Multiple Input Validation Vulnerabilities
31. Isode M-Vault Server LDAP Memory Corruption Vulnerability
32. MyBBoard Multiple Input Validation Vulnerabilities
33. WebWasher Malicious Script Filter Bypass Vulnerability
34. CGI.pm Start_Form Cross-Site Scripting Vulnerability
35. Safe.PM Unsafe Code Execution Vulnerability
36. Dotproject Multiple Remote File Include Vulnerabilities
37. eStara Softphone Multiple Denial of Service Vulnerabilities
38. Horde Kronolith Multiple HTML Injection Vulnerabilities
39. GNUTLS LibTASN1 DER Decoding Denial of Service Vulnerabilities
40. Microsoft Internet Explorer Drag And Drop File Installation Vulnerability Variant
41. LibPNG Graphics Library PNG_Set_Strip_Alpha Buffer Overflow Vulnerability
42. AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
43. IBM AIX Local Kernel Denial Of Service Vulnerability
44. Nullsoft Winamp M3U File Denial of Service Vulnerability
45. IBM AIX LSCFG Insecure Temporary File Creation Vulnerability
46. Sun Java Runtime Environment Unspecified Privilege Escalation Vulnerability
47. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
48. Gzip Zgrep Arbitrary Command Execution Vulnerability
49. bzip2 Remote Denial of Service Vulnerability
50. BZip2 CHMod File Permission Modification Race Condition Weakness
51. Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability
52. Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
53. Gallery Data Unspecified Code Execution Vulnerability
54. PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities
55. Valve Software Half-Life CSTRIKE Server Remote Denial of Service Vulnerability
56. Microsoft Internet Explorer WMF Image Parsing Memory Corruption Vulnerability
57. Flyspray ADODBPath Remote File Include Vulnerability
58. ImageMagick File Name Handling Remote Format String Vulnerability
59. E107 Website System BBCode HTML Injection Vulnerability
60. Avaya VSU/CSU Products ISAKMP IKE Traffic Denial of Service Vulnerability
61. Gastebuch Cross-Site Scripting Vulnerability
62. Invision Power Board User Registration Denial of Service Vulnerability
63. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
64. Noweb Insecure Temporary File Creation Vulnerability
65. OpenSSH SCP Shell Command Execution Vulnerability
66. RunCMS PMLite.PHP SQL Injection Vulnerability
67. NeoMail Neomail-prefs.PL Security Bypass Vulnerability
68. PostgreSQL Set Session Authorization Denial of Service Vulnerability
69. PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
70. sNews Multiple Input Validation Vulnerabilities
71. Magic Calendar Lite Index.PHP Multiple SQL Injection Vulnerabilities
72. Microsoft Windows IGMPv3 Denial of Service Vulnerability
73. Microsoft Windows Korean Input Method Editor Privilege Escalation Vulnerability
74. DeltaScripts PHP Classifieds Member_Login.PHP SQL Injection Vulnerability
75. Microsoft Windows Web Client Buffer Overflow Vulnerability
76. Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
77. WebGUI User Creation Security Bypass Vulnerability
78. Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
79. Multiple Vendor C Library realpath() Off-By-One Buffer Overflow Vulnerability
80. PHPNuke Header.PHP Pagetitle Parameter Cross-Site Scripting Vulnerability
81. IPB Army System Army.PHP SQL Injection Vulnerability
82. Hitachi Business Logic Multiple Input Validation Vulnerabilities
83. Scriptme SmE GB Host Login.PHP SQL Injection Vulnerability
84. Clever Copy Multiple HTML Injection Vulnerabilities
85. Ansilove Multiple Input Validation Vulnerabilities
86. Adobe Acrobat and Adobe Reader Remote Buffer Overflow Vulnerability
87. DocMGR Process.PHP Remote File Include Vulnerability
88. XMB Forum Multiple Input Validation Vulnerabilities
89. Metamail Message Processing Remote Buffer Overflow Vulnerability
90. XTux Server Garbage Denial of Service Vulnerability
91. Virtual Hosting Control System Multiple Input Validation And Access Validation Vulnerabilities
92. Lawrence Osiris DB_eSession Class SQL Injection Vulnerability
93. Fortinet FortiGate URL Filtering Bypass Vulnerability
94. SCPOnly Multiple Local Vulnerabilities
95. Siteframe Beaumont Search.PHP Q Parameter Cross-Site Scripting Vulnerability
96. Fortinet FortiGate Antivirus Engine Bypass Vulnerability
97. Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
98. ImageVue Multiple Vulnerabilities
99. IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
100. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
III. SECURITYFOCUS NEWS
1. Startup tries to spin a safer Web
2. Apple's in the eye of flaw finders
3. Blackmal virus set to delete files
4. Good worms back on the agenda
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Consultant, Vienna
2. [SJ-JOB] Sr. Security Engineer, San Jose
3. [SJ-JOB] Security Consultant, Washington DC
4. [SJ-JOB] Security Consultant, Wilmington
5. [SJ-JOB] Security Consultant, Baltimore
6. [SJ-JOB] Security Consultant, Walnut Creek
7. [SJ-JOB] Account Manager, Northern
8. [SJ-JOB] Developer, Superior
9. [SJ-JOB] Security Engineer, Charlotte
10. [SJ-JOB] Sr. Security Engineer, New Orleans
11. [SJ-JOB] Security Engineer, Morrisville
12. [SJ-JOB] Manager, Information Security, Chicago Metro
13. [SJ-JOB] Auditor, All over the UK
14. [SJ-JOB] Sales Representative, Herndon
15. [SJ-JOB] CISO, London
16. [SJ-JOB] Developer, San Jose
17. [SJ-JOB] Security Engineer, Mt. Laurel
18. [SJ-JOB] Sales Engineer, Herndon
19. [SJ-JOB] Information Assurance Analyst, San Francisco
20. [SJ-JOB] Sales Representative, Herndon
21. [SJ-JOB] Security Consultant, Philadelphia
22. [SJ-JOB] Sales Engineer, San Jose
23. [SJ-JOB] Security Engineer, Herndon
24. [SJ-JOB] Security Consultant, Richmond
25. [SJ-JOB] VP of Regional Sales, New York
26. [SJ-JOB] Security Auditor, Steinsel
27. [SJ-JOB] Security Engineer, Austin
28. [SJ-JOB] Sales Engineer, New York
29. [SJ-JOB] Security Engineer, Miami, Florida
30. [SJ-JOB] Security Consultant, Dallas
31. [SJ-JOB] Sales Engineer, Southern
32. [SJ-JOB] Quality Assurance, Lincroft
33. [SJ-JOB] Security Consultant, Baltimore
34. [SJ-JOB] Security Architect, Herndon
35. [SJ-JOB] Security Consultant, Washington
36. [SJ-JOB] Application Security Engineer, Riyadh
37. [SJ-JOB] Sr. Security Engineer, Parsippany
38. [SJ-JOB] Sr. Security Analyst, Bloomington
39. [SJ-JOB] Application Security Architect, Basking Ridge
40. [SJ-JOB] Sales Engineer, Phoenix
41. [SJ-JOB] Security Engineer, Edison
42. [SJ-JOB] Security Engineer, Los Angeles
43. [SJ-JOB] Security Director, London/Home Counties
44. [SJ-JOB] Sr. Security Analyst, St. Louis
45. [SJ-JOB] Security Consultant, Framingham
46. [SJ-JOB] Security Consultant, Atlanta
47. [SJ-JOB] Security Consultant, Atlanta
48. [SJ-JOB] Security Consultant, Columbus
49. [SJ-JOB] Jr. Security Analyst, St. Louis
50. [SJ-JOB] Sr. Security Analyst, Phoenix
51. [SJ-JOB] Security Consultant, Chicago
52. [SJ-JOB] Security Consultant, Raleigh
53. [SJ-JOB] Security Architect, Atlanta
54. [SJ-JOB] Security Consultant, Mississauga
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Buffer Overrun Newbie
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #277
2. SNMP service
VIII. SUN FOCUS LIST SUMMARY
1. Filtering out P2P traffic
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Coffee shop WiFi for dummies
By Scott Granneman
The average user has no idea of the risks associated with public WiFi hotspots. Here are some very simple tips for them to keep their network access secure.
http://www.securityfocus.com/columnists/385
2. Sebek 3: tracking the attackers, part two
By Raul Siles, GSE
The second article in this honeypot series discusses best practices for deploying Sebek 3 inside a GenIII honepot, and shows how to patch Sebek to watch all the attacker's activities in real-time.
http://www.securityfocus.com/infocus/1858
3. Privacy and anonymity
By Kelly Martin
Privacy and anonymity on the Internet are as important as they are difficult to achieve. Here are some of the the current issues we face, along with a few suggestions on how we can become a little more anonymous on the Web.
http://www.securityfocus.com/columnists/386
II. BUGTRAQ SUMMARY
--------------------
1. MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
BugTraq ID: 13660
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/13660
Summary:
MySQL is reportedly affected by a vulnerability that can allow local attackers to gain unauthorized access to the database or gain elevated privileges. This issue results from a design error due to the creation of temporary files in an insecure manner.
The vulnerability affects the 'mysql_install_db' script.
Due to the nature of the script, an attacker may create database accounts or gain elevated privileges.
MySQL versions prior to 4.0.12 and MySQL 5.x releases 5.0.4 and prior are reported to be affected.
2. Microsoft Windows Media Player Bitmap Handling Buffer Overflow Vulnerability
BugTraq ID: 16633
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16633
Summary:
Microsoft Windows Media Player is prone to a remote buffer overflow vulnerability.
The vulnerability arises when the application handles a skin file containing a specially crafted Bitmap image. This issue can also be triggered by just supplying a malicious Bitmap to the application, however, it should be noted that Windows Media Player is not the default handler for bitmap files.
A successful attack can corrupt process memory and result in arbitrary code execution. This may facilitate a remote compromise in the context of the vulnerable user.
3. Heimdal RSHD Local Privilege Escalation Vulnerability
BugTraq ID: 16524
Remote: No
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16524
Summary:
Heimdal rshd is prone to a local privilege-escalation vulnerability.
A local attacker can gain ownership of a file by overwriting its credential cache. This may lead to various attacks, including privilege escalation.
Heimdal versions prior to 0.7.2 and 0.6.6 are vulnerable.
4. LinPHA Multiple Local File Inclusion and PHP Code Injection Vulnerabilities
BugTraq ID: 16592
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16592
Summary:
LinPHA is prone to multiple local file-inclusion and PHP code-injection vulnerabilities. The local file-inclusion issues are due to insecure use of the 'include_once()' PHP function in multiple scripts. The PHP code-injection vulnerabilities are due to insufficient input validation of data that is saved to log files.
This will permit an attacker to influence the include path to point to files that are hosted on the computer that is running the affected application. In this manner, files that are readable by the webserver process may be output to the attacker.
Attackers may also inject arbitrary PHP code into the log files and cause it to be interpreted. This would occur in the context of the server hosting the application.
5. Multiple HiveMail Vulnerabilities
BugTraq ID: 16591
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16591
Summary:
HiveMail is prone to multiple vulnerabilities. These vulnerabilities may allow the execution of arbitrary PHP code, cross-site scripting attacks, and SQL injection.
The PHP code-execution issues are the result of an input-validation error that may allow user-supplied PHP code to be evaluated by the interpreter.
The cross-site scripting vulnerabilities may permit a remote attacker to steal cookie-based authentication credentials from legitimate users.
The SQL-injection issues are the result of the application's failure to properly sanitize user-supplied input that will be included in SQL queries. Successful exploitation of SQL-injection vulnerabilities could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
6. BlackBerry Enterprise Server Malformed Word Attachment Buffer Overflow Vulnerability
BugTraq ID: 16590
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16590
Summary:
BlackBerry Enterprise Server is prone to a buffer overflow in the BlackBerry Attachment Service. This issue can be triggered by a malformed Word document.
Successful exploitation may allow for the execution of arbitrary code in the context of the server.
7. Lotus Domino LDAP Denial of Service Vulnerability
BugTraq ID: 16523
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16523
Summary:
Lotus Domino LDAP server is prone to a denial-of-service vulnerability when handling malformed requests.
Lotus Domino version 7.0 is vulnerable; earlier versions may also be affected.
8. Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
BugTraq ID: 16479
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16479
Summary:
Multiple Nortel Networks products are reportedly prone to a remote denial-of-service vulnerability. The specific content and type of network traffic sufficient to trigger this issue are currently unknown.
This issue is reportedly being tracked by Nortel as support case 060110-04843.
When the network traffic is processed, the vulnerability is triggered, and the IPSec software fails to process further ESP traffic, effectively denying service for legitimate users.
Nortel IPSec client software version v04_60.51 and newer is reportedly susceptible to this issue.
Further reports indicate this issue is exploitable only through an existing IPSec tunnel and only via a valid remote access account.
NOTE: Further analysis and reports have indicated that this issue is limited to the VPN Client. Therefore, we have determined that this does not present a security threat. This BID is being retired.
9. PHP Event Calendar HTML Injection Vulnerability
BugTraq ID: 16588
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16588
Summary:
PHP Event Calendar is prone to an HTML-injection vulnerability.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
PHP Event Calendar version 1.5 is reportedly vulnerable; other versions may also be affected.
10. Multiple Scriptme Applications BBCode URL Tag Script Injection Vulnerability
BugTraq ID: 16585
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16585
Summary:
Multiple applications from the Scriptme site are prone to a script-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible.
11. IBM AIX ARP Local Buffer Overflow Vulnerability
BugTraq ID: 16584
Remote: No
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16584
Summary:
IBM AIX ARP is prone to a local buffer-overflow vulnerability. This issue may allow a local attacker to gain elevated privileges on a vulnerable computer.
12. FarsiNews Directory Traversal and Local File Include Vulnerabilities
BugTraq ID: 16580
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16580
Summary:
FarsiNews is prone to directory-traversal and local file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit the directory-traversal vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process.
The local file-include vulnerability lets the attacker include arbitrary local files. The impact of this issue depends on the content of the files included. If an attacker can place a malicious script on the vulnerable computer (either through legitimate means or through other latent vulnerabilities), then the attacker may be able to execute arbitrary code in the context of the webserver process. The attacker may also be able to use existing scripts to perform some malicious activity.
13. PowerD Remote Format String Vulnerability
BugTraq ID: 16582
Remote: Yes
Last Updated: 2006-02-12
Relevant URL: http://www.securityfocus.com/bid/16582
Summary:
A remote format-string vulnerability affects PowerD. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of an affected computer.
14. HP PSC 1210 All-in-One Driver Unspecified Vulnerability
BugTraq ID: 16583
Remote: No
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16583
Summary:
HP PSC 1210 All-in-One printer driver is reportedly prone to an unspecified vulnerability.
The cause and impact of this issue are currently unknown.
HP PSC 1210 All-in-One driver versions prior to 1.0.06 are vulnerable.
15. Sun ONE Directory Server Remote Denial Of Service Vulnerability
BugTraq ID: 16550
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16550
Summary:
Sun ONE Directory Server is prone to a remote denial-of-service vulnerability. This issue is due to the application's failure to handle malformed network traffic.
This issue allows remote attackers to crash the application, denying service to legitimate users.
16. ELOG Web Logbook Multiple Remote Vulnerabilities
BugTraq ID: 16579
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16579
Summary:
ELOG Web Logbook is prone to multiple remote vulnerabilities.
These issues include boundary-condition errors, denial-of-service attacks, and information disclosure.
An attacker can exploit these issues to facilitate a compromise of the application and the underlying computer. This includes crashing the application, executing arbitrary code, and retrieving information that may aid in further attacks.
17. SUSE LD Insecure RPATH / RUNPATH Arbitrary Code Execution Vulnerability
BugTraq ID: 16581
Remote: No
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16581
Summary:
SUSE LD is susceptible to an insecure RPATH / RUNPATH vulnerability.
This issue can allow attackers to place malicious libraries in a directory and to trick users to execute an application from that directory, which would be dynamically linked at run time when the application is executed. This would result in the execution of arbitrary code with the privileges of a user that executes the application.
Note that this issue is specific to SUSE.
18. GuestBookHost Multiple SQL Injection Vulnerabilities
BugTraq ID: 16545
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16545
Summary:
GuestBookHost is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 2005.04.25 is vulnerable; other versions may also be affected.
19. OpenVMPS Logging Function Format String Vulnerability
BugTraq ID: 15072
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/15072
Summary:
OpenVMPS is affected by a remote format-string vulnerability. The application fails to properly sanitize user-supplied input before using it as the format specifier in a system-log entry.
Remote attackers may exploit this issue to execute arbitrary machine code in the context of the affected service.
20. Linux Kernel Multiple Vulnerabilities
BugTraq ID: 12598
Remote: No
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/12598
Summary:
Linux Kernel is reported prone to multiple vulnerabilities. These issues may allow a local attacker to carry out denial-of-service attacks, disclose kernel memory, and potentially gain elevated privileges.
The following specific issues were identified:
- Reportedly, the filesystem Native Language Support ASCII translation table is affected by a vulnerability that results from the use of incorrect tables sizes. This issue can lead to a crash.
- Another issue affecting the kernel may allow users to unlock arbitrary shared-memory segments.
- Another vulnerability is reported to affect the 'netfilter/iptables' module. An attacker can exploit this issue to crash the kernel or bypass firewall rules.
- Reportedly, a vulnerability affects the OUTS instruction on the AMD64 and Intel EM64T architecture. This issue may lead to privilege escalation.
These issues reportedly affect Linux kernel 2.6.x versions.
Due to lack of details, further information is not available at the moment. This BID will be updated when more information becomes available.
21. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
BugTraq ID: 15968
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/15968
Summary:
Info-ZIP unzip is susceptible to a filename buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
22. Linux Kernel ICMP_Send Remote Denial Of Service Vulnerability
BugTraq ID: 16532
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16532
Summary:
Linux kernel is prone to a remote denial-of-service vulnerability.
Remote attackers can exploit this vulnerability to crash affected kernels, effectively denying service to legitimate users.
Linux kernel versions 2.6.15.2 and prior in the 2.6 series are vulnerable to this issue.
23. CPG Dragonfly CMS Remote Command Execution Vulnerability
BugTraq ID: 16546
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16546
Summary:
CPG Dragonfly CMS is prone to a remote command-execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.
Successful exploitation could facilitate unauthorized access; other attacks are also possible.
24. RunCMS Remote Code Execution Vulnerability
BugTraq ID: 16578
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16578
Summary:
RunCMS is prone to a remote code-execution vulnerability. This issue exists because the application allows remote users to upload files and call a connector script to execute the files.
This issue affects RunCMS version 1.3a2 and earlier.
25. IBM Lotus Notes File Attachment Handling Multiple Remote Vulnerabilities
BugTraq ID: 16576
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16576
Summary:
IBM Lotus Notes is prone to multiple remote vulnerabilities. The buffer-overflow issues could allow arbitrary code execution in the context of the user running the application.
The issues are:
- A buffer overflow exists when extracting files from ZIP archives.
- A buffer overflow exists when extracting files from UUE encoded files.
- A buffer overflow exists when extracting files from TAR archives.
- A buffer overflow exists when handling HTML file attachments with malicious links.
- A directory traversal exists when generating previews of ZIP, UUE, and TAR archives. This could be exploited to overwrite arbitrary files in the context of the current user.
Lotus Notes 6.5.4 and 7.0 are prone to these issues. Other versions may also be vulnerable.
26. IBM Lotus Domino iNotes Multiple HTML and Script Injection Vulnerabilities
BugTraq ID: 16577
Remote: Yes
Last Updated: 2006-02-10
Relevant URL: http://www.securityfocus.com/bid/16577
Summary:
IBM Lotus Domino iNotes is prone to multiple HTML- and script-injection vulnerabilities.
These vulnerabilities can allow attackers to carry out a variety of attacks, including theft of cookie-based authentication credentials.
27. SSH Tectia Server Remote Format String Vulnerability
BugTraq ID: 16640
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16640
Summary:
A remote format-string vulnerability affects SSH Tectia Server. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers.
28. QwikiWiki Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16638
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16638
Summary:
QwikiWiki is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before including it in dynamically generated HTML content.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
QwikiWiki version 1.5 is vulnerable to this issue; other versions may also be affected.
29. CALimba RB_auth.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 16632
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16632
Summary:
CALimba is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 0.99.1 and 0.99.2 are vulnerable; other versions may also be affected.
30. Time Tracking Software Multiple Input Validation Vulnerabilities
BugTraq ID: 16630
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16630
Summary:
Time Tracking Software is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.
31. Isode M-Vault Server LDAP Memory Corruption Vulnerability
BugTraq ID: 16635
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16635
Summary:
Isode M-Vault Server is prone to a memory corruption. This issue may be triggered by malformed LDAP data.
The exact impact of this vulnerability is not known at this time. Although the issue is known to crash the server, the possibility of remote code execution is unconfirmed.
The vulnerability was reported for version 11.3 on the Linux platform; other versions and platforms may also be affected.
This vulnerability will be updated as further information is made available.
32. MyBBoard Multiple Input Validation Vulnerabilities
BugTraq ID: 16631
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16631
Summary:
MyBBoard is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
33. WebWasher Malicious Script Filter Bypass Vulnerability
BugTraq ID: 16047
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16047
Summary:
WebWasher is prone to a filter-bypass vulnerability.
Successful exploitation can allow an attacker to bypass the security filter responsible for blocking malicious scripts.
Webwasher CSM Appliance and CSM Suite are vulnerable to this issue.
UPDATE: Further testing and reports from the vendor indicate that this issue cannot be reproduced. This BID is now retired.
34. CGI.pm Start_Form Cross-Site Scripting Vulnerability
BugTraq ID: 8231
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/8231
Summary:
CGI.pm is prone to cross-site scripting attacks under some circumstances. This issue occurs because the 'start_form()' function (or other functions that use this function) does not sufficiently sanitize HTML and script code when a form action isn't specified. This could expose scripts that use the function to cross-site scripting attacks.
35. Safe.PM Unsafe Code Execution Vulnerability
BugTraq ID: 6111
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/6111
Summary:
When Perl code is executed within a Safe compartment, it cannot access variables outside of the compartment unless the outside code chooses to share the variables with the code inside the compartment.
If code inside a Safe compartment is executed via 'Safe->reval()' twice, it can change its operation mask the second time. This could allow the code to access variables outside the Safe compartment.
36. Dotproject Multiple Remote File Include Vulnerabilities
BugTraq ID: 16648
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16648
Summary:
Dotproject is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
37. eStara Softphone Multiple Denial of Service Vulnerabilities
BugTraq ID: 16629
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16629
Summary:
eStara Smartphone is prone to multiple denial-of-service vulnerabilities when processing malformed VOIP headers. Successful exploitation will cause the device to crash.
38. Horde Kronolith Multiple HTML Injection Vulnerabilities
BugTraq ID: 15808
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/15808
Summary:
Kronolith is prone to multiple HTML-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
39. GNUTLS LibTASN1 DER Decoding Denial of Service Vulnerabilities
BugTraq ID: 16568
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16568
Summary:
Libtasn1 is prone to multiple denial-of-service vulnerabilities. A remote attacker can send specifically crafted data to trigger these flaws, leading to denial-of-service condition.
These issues have been addressed in Libtasn1 versions 0.2.18; earlier versions are vulnerable.
40. Microsoft Internet Explorer Drag And Drop File Installation Vulnerability Variant
BugTraq ID: 16352
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16352
Summary:
Microsoft Internet Explorer is reported prone to a vulnerability that may allow unauthorized installation of malicious executables.
This vulnerability is a variant of the issue described in BID 10973 Microsoft Internet Explorer Drag And Drop File Installation Vulnerability.
41. LibPNG Graphics Library PNG_Set_Strip_Alpha Buffer Overflow Vulnerability
BugTraq ID: 16626
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16626
Summary:
LibPNG is reported susceptible to a buffer-overflow vulnerability. The library fails to perform proper bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer.
This vulnerability may be exploited to execute attacker-supplied code in the context of an application that relies on the affected library.
42. AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
BugTraq ID: 16625
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16625
Summary:
A remote format-string vulnerability affects AttachmateWRQ Reflection for Secure IT. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers. Attackers may also cause a denial-of-service condition against the affected SSH server.
43. IBM AIX Local Kernel Denial Of Service Vulnerability
BugTraq ID: 16624
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16624
Summary:
IBM AIX is prone to a local denial-of-service vulnerability.
A local attacker can exploit this issue to crash an affected kernel, effectively denying service to legitimate users.
44. Nullsoft Winamp M3U File Denial of Service Vulnerability
BugTraq ID: 16623
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16623
Summary:
Winamp is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the application, effectively denying service to legitimate users. An attacker may be able to exploit this issue to execute arbitrary code on the victim user's computer; this has not been confirmed.
This issue is reported to affect version 5.13; other versions may also be vulnerable.
This issue may be related to BID 9923 (NullSoft Winamp Malformed File Name Denial of Service Vulnerability).
45. IBM AIX LSCFG Insecure Temporary File Creation Vulnerability
BugTraq ID: 15105
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/15105
Summary:
IBM AIX LSCFG creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Reports indicate that an attacker can exploit this issue to overwrite the '/etc/passwd', which can lead to privilege escalation.
46. Sun Java Runtime Environment Unspecified Privilege Escalation Vulnerability
BugTraq ID: 13958
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/13958
Summary:
Sun Java Runtime Environment is susceptible to an unspecified privilege-escalation vulnerability.
This vulnerability allows remote, untrusted Java applications to gain elevated privileges. This allows them to read or write local files or to execute arbitrary local applications. These actions are normally forbidden for untrusted applications running in the Java virtual machine.
Further details are not available at this time. This BID will be updated as more information is disclosed.
Reports from Harry Johnston indicate the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
47. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
BugTraq ID: 14531
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/14531
Summary:
Gaim is prone to multiple vulnerabilities affecting the AIM and ICQ protocols. These issues may allow remote attackers to trigger a buffer overflow or a denial-of-service condition.
All versions of Gaim 1.x are considered vulnerable at the moment.
48. Gzip Zgrep Arbitrary Command Execution Vulnerability
BugTraq ID: 13582
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/13582
Summary:
The 'zgrep' utility is reportedly affected by an arbitrary command-execution vulnerability.
An attacker may execute arbitrary commands through zgrep command arguments to potentially gain unauthorized access to the affected computer. Note that this issue poses a security threat only if the arguments originate from a malicious source.
Version 1.2.4 was reported vulnerable. Other versions may be affected as well.
49. bzip2 Remote Denial of Service Vulnerability
BugTraq ID: 13657
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/13657
Summary:
The 'bzip2' utility is prone to a remote denial-of-service vulnerability. This issue arises when the application processes malformed archives.
A successful attack can exhaust system resources and trigger a denial-of-service condition.
Version 1.0.2 is reportedly affected by this issue. Other version are likely vulnerable as well.
50. BZip2 CHMod File Permission Modification Race Condition Weakness
BugTraq ID: 12954
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/12954
Summary:
The 'bzip2' utility is reported prone to a security weakness. The issue is present only when an archive is extracted into a world- or group-writeable directory. It is reported that bzip2 employs non-atomic procedures to write a file and later changes the permissions on the newly extracted file.
A local attacker may leverage this issue to modify file permissions of target files.
This weakness is reported to affect bzip2 version 1.0.2 and previous versions.
51. Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability
BugTraq ID: 16644
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16644
Summary:
The Microsoft Windows Media Player plugin for non-Microsoft browsers is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite sized buffer.
An attacker can exploit this issue to execute arbitrary code on the victim userĂ¢??s computer in the context of the victim user. This may facilitate a compromise of the affected computer.
This issue is only exploitable through non-Microsoft browsers that have the Media Player plugin installed. Possible browsers include Firefox versions .9 and later and Netscape version 8; other browsers with the plugin installed may also be affected.
52. Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
BugTraq ID: 16621
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16621
Summary:
Multiple D-Link devices are susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected devices that causes them to fail when attempting to reassemble certain IP packets.
This issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
D-Link DI-524, DI-624, and Di-784 devices are affected by this issue. Due to code reuse among routers, other devices may also be affected.
It is reported that US Robotics USR8054 devices are also affected.
53. Gallery Data Unspecified Code Execution Vulnerability
BugTraq ID: 16533
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16533
Summary:
Gallery is prone to an unspecified code-execution vulnerability. This issue may allow a remote attacker to potentially execute commands on an affected computer.
A successful attack would lead to the execution of malicious code.
Very little is known regarding this vulnerability; this BID will be updated when more information is available.
Gallery 1.5.2 is affected by this issue.
54. PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities
BugTraq ID: 16620
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16620
Summary:
PHP/MYSQL Timesheet is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 1 and 2 are vulnerable; other versions may also be affected.
55. Valve Software Half-Life CSTRIKE Server Remote Denial of Service Vulnerability
BugTraq ID: 16619
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16619
Summary:
Valve Software Half-Life CSTRIKE Dedicated Server is reportedly prone to a remote denial-of-service vulnerability.
Half-Life CSTRIKE 1.6 Dedicated Server for Windows and Linux are prone to this vulnerability. Earlier versions may also be affected.
56. Microsoft Internet Explorer WMF Image Parsing Memory Corruption Vulnerability
BugTraq ID: 16516
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16516
Summary:
Microsoft Internet Explorer is affected by an WMF image parsing memory-corruption vulnerability. This issue is allegedly due to an integer-overflow flaw that leads to corrupted heap memory.
This problem presents itself when a user views a malicious WMF-formatted file containing specially crafted data.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploitation attempts likely result in crashing the application.
57. Flyspray ADODBPath Remote File Include Vulnerability
BugTraq ID: 16618
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16618
Summary:
Flyspray is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue is reported to affect Flyspray version 0.9.7; other versions may also be vulnerable.
EGS Enterprise Groupware System version 1.0rc4 ships with a vulnerable version of Flyspray and is also vulnerable to this issue. Other versions of EGS may also be vulnerable.
Remote file inclusion is reported to be possible on systems using PHP 5 only. However, systems using PHP 4 can still be exploited to include local files.
58. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.
Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.
Note that there are other attack vectors that may not require user interaction, since the application can be used with custom printing systems and web applications.
A successful attack may crash the application or lead to arbitrary code execution.
All versions of ImageMagick are considered vulnerable at the moment.
59. E107 Website System BBCode HTML Injection Vulnerability
BugTraq ID: 16614
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16614
Summary:
The e107 content management system (CMS) is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
60. Avaya VSU/CSU Products ISAKMP IKE Traffic Denial of Service Vulnerability
BugTraq ID: 16613
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16613
Summary:
Avaya VSU/CSU Products are prone to a denial of service when handling malformed IKE traffic.
It is conjectured that the issue can occur if a packet with a malformed payload is sent during an IKE exchange, causing the daemon to crash.
61. Gastebuch Cross-Site Scripting Vulnerability
BugTraq ID: 16615
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16615
Summary:
Gastebuch is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before including it in dynamically generated HTML content.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Gastebuch version 1.3.2 is vulnerable to this issue; prior versions may also be affected.
62. Invision Power Board User Registration Denial of Service Vulnerability
BugTraq ID: 16616
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16616
Summary:
Invision Power Board is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the application, effectively denying service to legitimate users.
This issue is reported to affect Invision Power Board version 2.0.1; other versions may also be vulnerable.
63. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
BugTraq ID: 14242
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/14242
Summary:
The Mozilla Foundation has released 12 security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, and Thunderbird.
These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, to bypass security checks, and to execute script code in the context of targeted websites to disclose confidential information; other attacks are also possible.
These vulnerabilities have been addressed in Firefox version 1.0.5 and in Mozilla Suite 1.7.9. At this time, Mozilla Thunderbird has not been fixed.
The issues described here will be split into individual BIDs as further analysis is completed. This BID will then be retired.
Reportedly, Netscape is also vulnerable to the issue described in MFSA 2005-47. Due to the nature of Netscape's fork from the Mozilla codebase, Netscape is also likely affected by most if not all of the issues that affect Mozilla Firefox. This has not been confirmed at this time.
64. Noweb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16610
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16610
Summary:
Noweb creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
65. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
66. RunCMS PMLite.PHP SQL Injection Vulnerability
BugTraq ID: 16652
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16652
Summary:
RunCMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
67. NeoMail Neomail-prefs.PL Security Bypass Vulnerability
BugTraq ID: 16651
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16651
Summary:
NeoMail is prone to a vulnerability that bypasses security settings.
An attacker can exploit this issue to create and delete arbitrary user account directories.
This may aid an attacker in further attacks and may give users a false sense of security, and lead to loss of data integrity.
68. PostgreSQL Set Session Authorization Denial of Service Vulnerability
BugTraq ID: 16650
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16650
Summary:
PostgreSQL is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the application, effectively denying service to legitimate users.
Successful exploitation of this issue requires that the application is compiled with 'Asserts' enabled; this is not the default setting.
69. PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
BugTraq ID: 16649
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16649
Summary:
PostgreSQL is susceptible to a remote privilege escalation vulnerability. This issue is due to a flaw in the error path of the 'SET ROLE' function.
This issue allows remote attackers with database access to gain administrative access to affected database servers. As administrative access to the database allows filesystem access, other attacks against the underlying operating system may also be possible.
70. sNews Multiple Input Validation Vulnerabilities
BugTraq ID: 16647
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16647
Summary:
sNews is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.
71. Magic Calendar Lite Index.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 16646
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16646
Summary:
Magic Calendar Lite is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
72. Microsoft Windows IGMPv3 Denial of Service Vulnerability
BugTraq ID: 16645
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16645
Summary:
A vulnerability in the handling of IGMPv3 (Internet Group Management Protocol) packets could result in a denial of service.
An attacker can exploit this issue through a broadcast attack to cause vulnerable computers on the subnet to become unresponsive, effectively denying service to legitimate users.
73. Microsoft Windows Korean Input Method Editor Privilege Escalation Vulnerability
BugTraq ID: 16643
Remote: No
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16643
Summary:
Microsoft Windows Korean Input Method Editor is prone to a local privilege escalation vulnerability.
Successful exploitation can allow local attackers to completely compromise a vulnerable computer.
74. DeltaScripts PHP Classifieds Member_Login.PHP SQL Injection Vulnerability
BugTraq ID: 16642
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16642
Summary:
PHP Classifieds is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. An attacker can exploit this issue to bypass the authentication mechanism and gain access as an arbitrary user.
75. Microsoft Windows Web Client Buffer Overflow Vulnerability
BugTraq ID: 16636
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16636
Summary:
The Microsoft Windows Web Client is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with System privileges.
76. Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
BugTraq ID: 16634
Remote: Yes
Last Updated: 2006-02-14
Relevant URL: http://www.securityfocus.com/bid/16634
Summary:
Microsoft PowerPoint 2000 is prone to a remote information disclosure vulnerability. Information gathered may be used to launch further attacks against a vulnerable computer.
77. WebGUI User Creation Security Bypass Vulnerability
BugTraq ID: 16612
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16612
Summary:
WebGUI is prone to a vulnerability that bypasses security settings during user creation.
An attacker can exploit this issue to create an anonymous new user, regardless of the security settings. This may aid an attacker in further attacks and may give users a false sense of security.
78. Zen Cart Password_Forgotten.PHP SQL Injection Vulnerability
BugTraq ID: 15690
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/15690
Summary:
Zen Cart is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
79. Multiple Vendor C Library realpath() Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 8315
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/8315
Summary:
The 'realpath()' function is a C-library procedure to resolve the canonical, absolute pathname of a file based on a path that may contain values such as '/', './', '../', or symbolic links. A vulnerability that was reported to affect the implementation of 'realpath()' in WU-FTPD has lead to the discovery that at least one implementation of the C library is also vulnerable. FreeBSD has announced that the off-by-one stack- buffer-overflow vulnerability is present in their libc. Other systems are
also likely vulnerable.
Reportedly, this vulnerability has been successfully exploited against WU-FTPD to execute arbitrary instructions.
** NOTE: Patching the C library alone may not remove all instances of this vulnerability. Statically linked programs may need to be re-built with a patched version of the C library. Also, some applications may implement their own version of 'realpath()'. These applications would require their own patches. FreeBSD has published a large list of applications that use 'realpath()'. Administrators of FreeBSD and other systems are urged to review it. The advisory, FreeBSD-SA-03:08.realpath, is
available in the reference section.
80. PHPNuke Header.PHP Pagetitle Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 16608
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16608
Summary:
PHPNuke is prone to a cross-site scripting vulnerability.
This issue affects the 'header.php' script.
PHPNuke 7.8 and prior versions are reportedly vulnerable.
81. IPB Army System Army.PHP SQL Injection Vulnerability
BugTraq ID: 16606
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16606
Summary:
IPB Army System is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 2.1 and earlier are vulnerable; other versions may also be affected.
82. Hitachi Business Logic Multiple Input Validation Vulnerabilities
BugTraq ID: 16602
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16602
Summary:
Hitachi Business Logic - Container is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.
83. Scriptme SmE GB Host Login.PHP SQL Injection Vulnerability
BugTraq ID: 16609
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16609
Summary:
SmE GB Host is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
84. Clever Copy Multiple HTML Injection Vulnerabilities
BugTraq ID: 16607
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16607
Summary:
Clever Copy is prone to multiple HTML-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
85. Ansilove Multiple Input Validation Vulnerabilities
BugTraq ID: 16603
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16603
Summary:
Ansilove is prone to multiple input-validation vulnerabilities. These issues could be exploited to obtain sensitive information or upload arbitrary scripts. Due to a missing '.htaccess' file in the upload directory, the uploaded scripts may be accessed directly and executed.
Ansilove versions prior to 1.03 are vulnerable to these issues.
86. Adobe Acrobat and Adobe Reader Remote Buffer Overflow Vulnerability
BugTraq ID: 14603
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/14603
Summary:
Adobe Acrobat and Adobe Reader are affected by a remote buffer overflow vulnerability. This issue presents itself because the application fails to perform boundary checks prior to copying user-supplied data into sensitive process buffers.
An attacker can exploit this issue by crafting a malicious PDF file and sending it to a vulnerable user. If the victim user opens this PDF file, the attacker may be able to execute arbitrary code on the affected computer and gain unauthorized access in the context of the user.
87. DocMGR Process.PHP Remote File Include Vulnerability
BugTraq ID: 16601
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16601
Summary:
DocMGR is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue is reported to affect versions 0.54.2 and earlier; other versions may also be vulnerable.
88. XMB Forum Multiple Input Validation Vulnerabilities
BugTraq ID: 16604
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16604
Summary:
XMB Forum is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
89. Metamail Message Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 16611
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16611
Summary:
Metamail is prone to a remote buffer overflow vulnerability.
This issue arises when the application handles messages with large string values for boundaries.
This can cause memory corruption and trigger a crash in the application. Although unconfirmed, this issue may lead to arbitrary code execution.
Metamail 2.7 is reportedly vulnerable, however, other versions may be affected as well.
90. XTux Server Garbage Denial of Service Vulnerability
BugTraq ID: 4260
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/4260
Summary:
XTux is a multiplayer network game for Linux. The server component (June 01, 2001 version) is vulnerable to a denial of service initiated by connecting to the server and sending unexpected characters. This causes the server to become unresponsive and consume resources.
91. Virtual Hosting Control System Multiple Input Validation And Access Validation Vulnerabilities
BugTraq ID: 16600
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16600
Summary:
Virtual Hosting Control System (VHCS) is prone to multiple input and access vulnerabilities.
VHCS is prone to an HTML-injection vulnerability and an authentication-bypass vulnerability. These issues could be exploited to gain administrative access to the application; other attacks are also possible.
92. Lawrence Osiris DB_eSession Class SQL Injection Vulnerability
BugTraq ID: 16598
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16598
Summary:
DB_eSession is prone to an SQL-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
93. Fortinet FortiGate URL Filtering Bypass Vulnerability
BugTraq ID: 16599
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16599
Summary:
Fortinet FortiGate is prone to a vulnerability that could allow users to bypass the device's URL filtering.
FortiGate devices running FortiOS v2.8MR10 and v3beta are vulnerable to this issue. Other versions may also be affected.
94. SCPOnly Multiple Local Vulnerabilities
BugTraq ID: 16051
Remote: No
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16051
Summary:
The 'scponly' program is prone to multiple local vulnerabilities. These issues can allow local attackers to gain elevated privileges.
The application is affected by a design error affecting the 'scponlyc' binary.
An attacker can also issue malicious command-line arguments to 'rsync' or scp to execute arbitrary applications with elevated privileges.
Successful exploitation of these issues can facilitate a complete compromise.
95. Siteframe Beaumont Search.PHP Q Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 16596
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16596
Summary:
Siteframe Beaumont is prone to a cross-site scripting vulnerability.
This issue affects the 'search.php' script.
Siteframe Beaumont 5.0.1 and prior versions are reportedly vulnerable.
96. Fortinet FortiGate Antivirus Engine Bypass Vulnerability
BugTraq ID: 16597
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16597
Summary:
Fortinet FortiGate is reportedly prone to a vulnerability that allows an attacker to bypass antivirus protection. This issue is said to occur when files are transferred using the FTP protocol under certain conditions. Specific details are not currently available. This record will be updated when further information is disclosed.
FortiGate devices running FortiOS v2.8MR10 and v3beta are affected by this issue. Other versions may also be vulnerable.
97. Honeyd IP Reassembly Remote Virtual Host Detection Vulnerability
BugTraq ID: 16595
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16595
Summary:
Honeyd is prone to a virtual host-detection vulnerability.
The vulnerability presents itself in the IP reassembly code.
A successful attack may allow remote attackers to enumerate the existence of simulated Honeyd hosts and then either target specific attacks against these hosts or avoid them altogether.
This issue affects all versions of Honeyd prior to 1.5.
98. ImageVue Multiple Vulnerabilities
BugTraq ID: 16594
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16594
Summary:
ImageVue is prone to multiple vulnerabilities, including unauthorized uploading of files with arbitrary extensions, authentication bypass, information disclosure, and content injection.
Successful exploitation could allow attackers to upload and possibly execute malicious files, gain access to restrict areas of the site, or inject hostile content into the site.
99. IBM Tivoli Directory Server Unspecified LDAP Memory Corruption Vulnerability
BugTraq ID: 16593
Remote: Yes
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/16593
Summary:
IBM Tivoli Directory Server is prone to an unspecified memory corruption. This issue may be triggered by malformed LDAP data.
The exact impact of this vulnerability is not known at this time. Although the issue is known to crash the server, the possibility of remote code execution is unconfirmed.
The vulnerability was reported for version 6.0 on the Linux platform. Other versions or platforms are not known to be affected.
This vulnerability will be updated as further information is made available.
100. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
BugTraq ID: 14807
Remote: No
Last Updated: 2006-02-13
Relevant URL: http://www.securityfocus.com/bid/14807
Summary:
XFree86 is prone to a buffer overrun in its pixmap-processing code.
This issue can potentially allow an attacker to execute arbitrary code and to escalate privileges. An attacker may possibly gain superuser privileges by exploiting this issue.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Startup tries to spin a safer Web
By: Robert Lemos
Armed with client-side honeypots and a low-cost team in India, a group of MIT graduates aims to create a system to warn Web surfers about the seedier sites, and outright malicious servers, on the Internet.
http://www.securityfocus.com/news/11376
2. Apple's in the eye of flaw finders
By: Robert Lemos
With the move to Intel processors and a larger share of the market, Apple's Mac OS X could find itself a more popular target of attack, security professionals say.
http://www.securityfocus.com/news/11375
3. Blackmal virus set to delete files
By: Robert Lemos
Security experts urge companies to clean their networks of a malicious mass-mailing computer virus, before compromised systems reach the first trigger date and start deleting eleven types of files.
http://www.securityfocus.com/news/11374
4. Good worms back on the agenda
By: Robert Lemos
A researcher argues that the spreading capabilities of worms could better perform penetration testing inside networks, turning vulnerable systems into distributed scanners.
http://www.securityfocus.com/news/11373
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Vienna
http://www.securityfocus.com/archive/77/424964
2. [SJ-JOB] Sr. Security Engineer, San Jose
http://www.securityfocus.com/archive/77/424961
3. [SJ-JOB] Security Consultant, Washington DC
http://www.securityfocus.com/archive/77/424962
4. [SJ-JOB] Security Consultant, Wilmington
http://www.securityfocus.com/archive/77/424965
5. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/424963
6. [SJ-JOB] Security Consultant, Walnut Creek
http://www.securityfocus.com/archive/77/424874
7. [SJ-JOB] Account Manager, Northern
http://www.securityfocus.com/archive/77/424875
8. [SJ-JOB] Developer, Superior
http://www.securityfocus.com/archive/77/424873
9. [SJ-JOB] Security Engineer, Charlotte
http://www.securityfocus.com/archive/77/424871
10. [SJ-JOB] Sr. Security Engineer, New Orleans
http://www.securityfocus.com/archive/77/424872
11. [SJ-JOB] Security Engineer, Morrisville
http://www.securityfocus.com/archive/77/424829
12. [SJ-JOB] Manager, Information Security, Chicago Metro
http://www.securityfocus.com/archive/77/424830
13. [SJ-JOB] Auditor, All over the UK
http://www.securityfocus.com/archive/77/424835
14. [SJ-JOB] Sales Representative, Herndon
http://www.securityfocus.com/archive/77/424833
15. [SJ-JOB] CISO, London
http://www.securityfocus.com/archive/77/424834
16. [SJ-JOB] Developer, San Jose
http://www.securityfocus.com/archive/77/424813
17. [SJ-JOB] Security Engineer, Mt. Laurel
http://www.securityfocus.com/archive/77/424815
18. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/424817
19. [SJ-JOB] Information Assurance Analyst, San Francisco
http://www.securityfocus.com/archive/77/424814
20. [SJ-JOB] Sales Representative, Herndon
http://www.securityfocus.com/archive/77/424812
21. [SJ-JOB] Security Consultant, Philadelphia
http://www.securityfocus.com/archive/77/424582
22. [SJ-JOB] Sales Engineer, San Jose
http://www.securityfocus.com/archive/77/424585
23. [SJ-JOB] Security Engineer, Herndon
http://www.securityfocus.com/archive/77/424586
24. [SJ-JOB] Security Consultant, Richmond
http://www.securityfocus.com/archive/77/424581
25. [SJ-JOB] VP of Regional Sales, New York
http://www.securityfocus.com/archive/77/424583
26. [SJ-JOB] Security Auditor, Steinsel
http://www.securityfocus.com/archive/77/424575
27. [SJ-JOB] Security Engineer, Austin
http://www.securityfocus.com/archive/77/424577
28. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/424572
29. [SJ-JOB] Security Engineer, Miami, Florida
http://www.securityfocus.com/archive/77/424580
30. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/424573
31. [SJ-JOB] Sales Engineer, Southern
http://www.securityfocus.com/archive/77/424568
32. [SJ-JOB] Quality Assurance, Lincroft
http://www.securityfocus.com/archive/77/424569
33. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/424559
34. [SJ-JOB] Security Architect, Herndon
http://www.securityfocus.com/archive/77/424564
35. [SJ-JOB] Security Consultant, Washington
http://www.securityfocus.com/archive/77/424566
36. [SJ-JOB] Application Security Engineer, Riyadh
http://www.securityfocus.com/archive/77/424562
37. [SJ-JOB] Sr. Security Engineer, Parsippany
http://www.securityfocus.com/archive/77/424556
38. [SJ-JOB] Sr. Security Analyst, Bloomington
http://www.securityfocus.com/archive/77/424557
39. [SJ-JOB] Application Security Architect, Basking Ridge
http://www.securityfocus.com/archive/77/424558
40. [SJ-JOB] Sales Engineer, Phoenix
http://www.securityfocus.com/archive/77/424561
41. [SJ-JOB] Security Engineer, Edison
http://www.securityfocus.com/archive/77/424510
42. [SJ-JOB] Security Engineer, Los Angeles
http://www.securityfocus.com/archive/77/424506
43. [SJ-JOB] Security Director, London/Home Counties
http://www.securityfocus.com/archive/77/424509
44. [SJ-JOB] Sr. Security Analyst, St. Louis
http://www.securityfocus.com/archive/77/424526
45. [SJ-JOB] Security Consultant, Framingham
http://www.securityfocus.com/archive/77/424515
46. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/424529
47. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/424533
48. [SJ-JOB] Security Consultant, Columbus
http://www.securityfocus.com/archive/77/424505
49. [SJ-JOB] Jr. Security Analyst, St. Louis
http://www.securityfocus.com/archive/77/424434
50. [SJ-JOB] Sr. Security Analyst, Phoenix
http://www.securityfocus.com/archive/77/424443
51. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/424380
52. [SJ-JOB] Security Consultant, Raleigh
http://www.securityfocus.com/archive/77/424383
53. [SJ-JOB] Security Architect, Atlanta
http://www.securityfocus.com/archive/77/424381
54. [SJ-JOB] Security Consultant, Mississauga
http://www.securityfocus.com/archive/77/424393
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Buffer Overrun Newbie
http://www.securityfocus.com/archive/82/424156
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #277
http://www.securityfocus.com/archive/88/424635
2. SNMP service
http://www.securityfocus.com/archive/88/424634
VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. Filtering out P2P traffic
http://www.securityfocus.com/archive/92/424850
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000C3f7