SecurityFocus Newsletter #338
Peter Laborge <[email protected]> Tue, 21 Feb 2006 16:12:14 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #338
----------------------------------------
This Issue is Sponsored By: Lancope
"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."
http://www.lancope.com/resource/
------------------------------------------------------------------
I. FRONT AND CENTER
1. Strict liability for data breaches?
2. Privacy and anonymity
II. BUGTRAQ SUMMARY
1. Squid Proxy Client NTLM Authentication Denial Of Service Vulnerability
2. Squid Proxy SSLConnectTimeout Remote Denial Of Service Vulnerability
3. Apache MPM Worker.C Denial Of Service Vulnerability
4. OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
5. Squid Proxy NTLM Authentication Denial Of Service Vulnerability
6. RunCMS PMLite.PHP SQL Injection Vulnerability
7. Leif M. Wright Blog HTML Injection Vulnerability
8. Linux Kernel ICMP_Send Remote Denial Of Service Vulnerability
9. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
10. ClamAV FSG Compressed Executable Infinite Loop Denial Of Service Vulnerability
11. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
12. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
13. ClamAV UPX Compressed Executable Buffer Overflow Vulnerability
14. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
15. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
16. Linux Kernel IPV6 Local Denial of Service Vulnerability
17. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
18. Leif M. Wright Blog Information Disclosure Vulnerability
19. E-Blah Routines.PL HTML Injection Vulnerability
20. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
21. Teca Scripts Guestex Multiple Input Validation Vulnerabilities
22. Teca Scripts Quirex Convert.CGI Information Disclosure Vulnerability
23. MyBB Multiple Cross-Site Scripting Vulnerabilities
24. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
25. V-webmail Multiple Cross-Site Scripting Vulnerabilities
26. PerlBlog Multiple Input Validation and Information Disclosure Vulnerabilities
27. Squid Proxy Aborted Requests Remote Denial Of Service Vulnerability
28. Squid Proxy Failed DNS Lookup Random Error Messages Information Disclosure Vulnerability
29. Squid Proxy Unspecified DNS Spoofing Vulnerability
30. BirthSys Multiple SQL Injection Vulnerabilities
31. Squid cachemgr.cgi Unauthorized Connection Vulnerability
32. Squid Proxy Aborted Connection Remote Denial Of Service Vulnerability
33. PHP Input/Output Wrapper Remote Include Function Command Execution Weakness
34. GNU Tar Hostile Destination Path Variant Vulnerability
35. Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
36. Squid Proxy DNS Name Resolver Remote Denial Of Service Vulnerability
37. SuSE XScreenSaver Package Multiple Vulnerabilities
38. Linux Kernel SDLA IOCTL Unauthorized Local Firmware Access Vulnerability
39. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
40. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
41. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
42. Linux Kernel IP_VS_CONN_FLUSH Local Denial of Service Vulnerability
43. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vulnerability
44. GNU WGet Multiple Remote Vulnerabilities
45. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnerability
46. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerability
47. Squid Proxy Malformed NTLM Type 3 Message Remote Denial of Service Vulnerability
48. Squid Proxy NTLM Fakeauth_Auth Memory Leak Remote Denial Of Service Vulnerability
49. Linux Kernel Find_Target Local Denial Of Service Vulnerability
50. Linux Kernel Stack Fault Exceptions Unspecified Local Denial of Service Vulnerability
51. Squid Proxy Web Cache Communication Protocol Denial Of Service Vulnerability
52. Squid Proxy Gopher To HTML Remote Buffer Overflow Vulnerability
53. Metamail Message Processing Remote Buffer Overflow Vulnerability
54. Squid Proxy SNMP ASN.1 Parser Denial Of Service Vulnerability
55. Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
56. PHPNuke CAPTCHA Bypass Weakness
57. Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
58. Webpagecity WPC easy SQL Injection Vulnerability
59. ADOdb Multiple Cross-Site Scripting Vulnerabilities
60. RCBlog Index.PHP Directory Traversal Vulnerability
61. Noweb Insecure Temporary File Creation Vulnerability
62. E107 Website System Chatbox Plugin HTML Injection Vulnerability
63. Coppermine Multiple File Include Vulnerabilities
64. Microsoft Internet Explorer Script Engine Buffer Overflow Vulnerability
65. Todd Miller Sudo Local Privilege Escalation Vulnerability
66. AWStats Referrer Arbitrary Command Execution Vulnerability
67. Microsoft Windows Color Management Module ICC Profile Buffer Overflow Vulnerability
68. PHPNuke Search Module SQL Injection Vulnerability
69. Sun Java Runtime Environment Unspecified Privilege Escalation Vulnerability
70. LibTIFF TIFFOpen Buffer Overflow Vulnerability
71. Linux Kernel SDLA_XFER Kernel Memory Disclosure Vulnerability
72. PEAR::Auth Multiple Unspecified SQL Injection Vulnerabilities
73. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
74. Geeklog Multiple Input Validation Vulnerabilities
75. Admbook Remote PHP Script Code Execution Vulnerability
76. PostNuke Multiple Input Validation Vulnerabilities
77. Guestbox HTML Injection Vulnerability
78. Melange Chat Session Header Information Disclosure Vulnerability
79. Barracuda Directory Multiple HTML Injection Vulnerabilities
80. Bugzilla User Credentials Information Disclosure Vulnerability
81. True North Software IA EMailServer Remote Buffer Overflow Vulnerability
82. Mozilla Firefox HTML Parsing Denial of Service Vulnerability
83. Bugzilla Whinedays SQL Injection Vulnerability
84. Apple Mac OS X Archive Metadata Command Execution Vulnerability
85. IlchClan Multiple SQL Injection Vulnerabilities
86. GBook Multiple Unspecified Cross-Site Scripting Vulnerabilities
87. Time Tracking Software Multiple Input Validation Vulnerabilities
88. OpenSSH SCP Shell Command Execution Vulnerability
89. GnuPG Detached Signature Verification Bypass Vulnerability
90. PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
91. Magic Calendar Lite Index.PHP SQL Injection Vulnerability
92. EmuLinker Malformed Packet Remote Denial Of Service Vulnerability
93. PHPNuke Index.PHP Search Module SQL Injection Vulnerability
94. TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
95. MiniNuke CMS Pages.ASP SQL Injection Vulnerability
96. Fedora Directory Server Password Information Disclosure Vulnerability
97. Tin News Reader Buffer Overflow Vulnerability
98. Xerox WorkCentre Products Local Authentication Bypass Vulnerability
99. Xerox WorkCentre Unspecified Denial of Service Vulnerability
100. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
III. SECURITYFOCUS NEWS
1. Private identities become a corporate focus
2. Startup tries to spin a safer Web
3. Apple's in the eye of flaw finders
4. Blackmal virus set to delete files
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sales Representative, Bloomfield Hills
2. [SJ-JOB] CHECK Team Leader, Reading
3. [SJ-JOB] Security Consultant, Charlotte
4. [SJ-JOB] Sr. Security Analyst, Jacksonville
5. [SJ-JOB] Sales Representative, San Mateo
6. [SJ-JOB] Sales Engineer, Columbus
7. [SJ-JOB] Sales Engineer, Cincinnati
8. [SJ-JOB] Security Consultant, San Antonio
9. [SJ-JOB] Security Consultant, Minneapolis
10. [SJ-JOB] Sr. Security Engineer, St. Paul
11. [SJ-JOB] Sales Engineer, Dayton
12. [SJ-JOB] Sales Engineer, Cleveland
13. [SJ-JOB] Security Consultant, Phoenix
14. [SJ-JOB] Security Consultant, Chicago
15. [SJ-JOB] Security Consultant, Los Angeles
16. [SJ-JOB] Sales Engineer, Minneapolis
17. [SJ-JOB] Sales Engineer, Chicago
18. [SJ-JOB] Security Engineer, Herndon
19. [SJ-JOB] Security Consultant, Atlanta
20. [SJ-JOB] Security Consultant, San Francisco
21. [SJ-JOB] Application Security Engineer, Columbia
22. [SJ-JOB] Application Security Engineer, Columbia
23. [SJ-JOB] Security Consultant, Boston
24. [SJ-JOB] Security Consultant, New York City
25. [SJ-JOB] Security Consultant, Philadelphia
26. [SJ-JOB] Security Auditor, Huntsville
27. [SJ-JOB] Manager, Information Security, Westlake Village / LA Area
28. [SJ-JOB] Disaster Recovery Coordinator, London
29. [SJ-JOB] Security Engineer, Lanham
30. [SJ-JOB] Security Consultant, Toronto
31. [SJ-JOB] Security Engineer, Norcross
32. [SJ-JOB] Management, Silicon Valley/Bay Area
33. [SJ-JOB] Security Consultant, Charlotte
34. [SJ-JOB] Security Consultant, Washington
35. [SJ-JOB] Security Consultant, Charlotte
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. PHP and SCRIPT_NAME variable
2. CALL FOR PAPER - SYSCAN'06
3. BCS Asia 2006 - Call for Papers
VII. MICROSOFT FOCUS LIST SUMMARY
1. Retriving ACL's on 60 thousand folders
2. SecurityFocus Microsoft Newsletter #278
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Kryptor Whitepaper released
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Strict liability for data breaches?
By Mark Rasch
A recent case involving a stolen laptop containing 550,000 people's full credit information sheds new night on what "reasonable" protections a company must make to secure its customer data - and what customers need to prove in order to sue for damages.
http://www.securityfocus.com/columnists/387
2. Privacy and anonymity
By Kelly Martin
Privacy and anonymity on the Internet are as important as they are difficult to achieve. Here are some of the the current issues we face, along with a few suggestions on how we can become a little more anonymous on the Web.
http://www.securityfocus.com/columnists/386
II. BUGTRAQ SUMMARY
--------------------
1. Squid Proxy Client NTLM Authentication Denial Of Service Vulnerability
BugTraq ID: 14977
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14977
Summary:
Squid Proxy is prone to a denial-of-service vulnerability. This issue may occur when the proxy handles certain client NTLM-authentication request sequences.
2. Squid Proxy SSLConnectTimeout Remote Denial Of Service Vulnerability
BugTraq ID: 14731
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14731
Summary:
A remote denial-of-service vulnerability affects the Squid Proxy. The application fails to properly handle exceptional network requests.
A remote attacker may leverage this issue to crash the affected Squid Proxy, denying service to legitimate users.
3. Apache MPM Worker.C Denial Of Service Vulnerability
BugTraq ID: 15762
Remote: Yes
Last Updated: 2006-02-18
Relevant URL: http://www.securityfocus.com/bid/15762
Summary:
Apache is prone to a memory leak, causing a denial-of-service vulnerability.
An attacker may consume excessive memory resources, resulting in a denial of service for legitimate users.
Apache 2.x versions are vulnerable; other versions may also be affected.
4. OpenSSH LoginGraceTime Remote Denial Of Service Vulnerability
BugTraq ID: 14963
Remote: Yes
Last Updated: 2006-02-18
Relevant URL: http://www.securityfocus.com/bid/14963
Summary:
OpenSSH is susceptible to a remote denial of service vulnerability. This issue is due to a design flaw when servicing timeouts related to the 'LoginGraceTime' server configuration directive.
Specifically, when 'LoginGraceTime', in conjunction with 'MaxStartups' and 'UsePrivilegeSeparation' are configured and enabled in the server, a condition may arise where the server refuses further remote connection attempts.
This issue may be exploited by remote attackers to deny SSH service to legitimate users.
5. Squid Proxy NTLM Authentication Denial Of Service Vulnerability
BugTraq ID: 11098
Remote: Yes
Last Updated: 2006-02-18
Relevant URL: http://www.securityfocus.com/bid/11098
Summary:
Squid is reported to be susceptible to a denial of service vulnerability in its NTLM authentication module.
This vulnerability presents itself when attacker supplied input data is passed to the affected NTLM module without proper sanitization.
This vulnerability allows an attacker to crash the NTLM helper application. Squid will respawn new helper applications, but with a sustained, repeating attack, it is likely that proxy authentication depending on the NTLM helper application would fail. Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
Squid versions 2.x and 3.x are all reported to be vulnerable to this issue. A patch is available from the vendor.
6. RunCMS PMLite.PHP SQL Injection Vulnerability
BugTraq ID: 16652
Remote: Yes
Last Updated: 2006-02-18
Relevant URL: http://www.securityfocus.com/bid/16652
Summary:
RunCMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
7. Leif M. Wright Blog HTML Injection Vulnerability
BugTraq ID: 16715
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16715
Summary:
Blog is prone to an HTML-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect version 3.5; other versions may also be vulnerable.
8. Linux Kernel ICMP_Send Remote Denial Of Service Vulnerability
BugTraq ID: 16532
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16532
Summary:
Linux kernel is prone to a remote denial-of-service vulnerability.
Remote attackers can exploit this vulnerability to crash affected kernels, effectively denying service to legitimate users.
Linux kernel versions 2.6.15.2 and prior in the 2.6 series are vulnerable to this issue.
9. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
BugTraq ID: 16301
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16301
Summary:
The Linux kernel 'dm-crypt' module is susceptible to a local information-disclosure vulnerability. This issue is due to the module's failure to properly zero-sensitive memory buffers before freeing the memory.
This issue may allow local attackers to gain access to potentially sensitive memory that contains information on the cryptographic key used for the encrypted storage. This may aid attackers in further attacks.
This issue affects the 2.6 series of the Linux kernel.
10. ClamAV FSG Compressed Executable Infinite Loop Denial Of Service Vulnerability
BugTraq ID: 14867
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/14867
Summary:
ClamAV is prone to a remote denial-of-service vulnerability. This issue occurs when the application handles a malformed FSG-compressed executable.
Exploitation could cause the application to enter an infinite loop, resulting in a denial of service.
11. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
BugTraq ID: 16142
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16142
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. This issue is due to a flaw in the DVB (Digital Video Broadcasting) driver subsystem. This issue is exploitable only on computers with the affected DVB module compiled, enabled, and accessible to local malicious users.
A successful attack may result in a denial-of-service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
12. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
BugTraq ID: 16141
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16141
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. This issue is due to an off-by-one error in the 'sysctl' subsystem.
A successful attack may result in a denial-of-service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
13. ClamAV UPX Compressed Executable Buffer Overflow Vulnerability
BugTraq ID: 14866
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/14866
Summary:
ClamAV is prone to a remote buffer-overflow vulnerability. This condition occurs when the program processes malformed UPX-compressed executables.
Successful exploitation may result in the execution of arbitrary code in the context of the application.
14. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
BugTraq ID: 16284
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16284
Summary:
The Linux kernel is affected by a local memory-disclosure vulnerability.
This issue allows an attacker to read kernel memory. Information gathered via exploitation may aid malicious users in further attacks.
This issue affects the 2.6 series of the Linux kernel, prior to 2.6.15.
15. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
BugTraq ID: 16283
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16283
Summary:
Linux kernel 'mq_open()' system call is prone to a local denial-of-service vulnerability. Further information is not currently available. This record will be updated when more details are disclosed.
This issue affects Linux kernel 2.6.9. Earlier kernel versions may be affected.
16. Linux Kernel IPV6 Local Denial of Service Vulnerability
BugTraq ID: 15156
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/15156
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability.
This issue arises from an infinite loop when binding IPv6 UDP ports.
17. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
18. Leif M. Wright Blog Information Disclosure Vulnerability
BugTraq ID: 16712
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16712
Summary:
Blog is prone to an information-disclosure vulnerability.
This can allow attackers to access sensitive information. Information gathered through the exploitation of this issue may aid in other attacks.
Blog version 3.5 is affected by this issue.
19. E-Blah Routines.PL HTML Injection Vulnerability
BugTraq ID: 16713
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16713
Summary:
E-Blah is prone to an HTML-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect E-Blah Platinum version 9.7; other versions may also be vulnerable.
20. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
BugTraq ID: 16710
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16710
Summary:
Libapreq2 is prone to a vulnerability that may allow attackers to trigger a denial-of-service condition.
Libapreq2 versions prior to 2.0.7 are vulnerable.
21. Teca Scripts Guestex Multiple Input Validation Vulnerabilities
BugTraq ID: 16711
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16711
Summary:
Guestex is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute all of the following in the context of the webserver process:
- arbitrary shell commands
- attacker-supplied HTML
- attacker-supplied script code
This may enable an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, or facilitate a compromise of the application and the underlying computer; other attacks are also possible.
22. Teca Scripts Quirex Convert.CGI Information Disclosure Vulnerability
BugTraq ID: 16709
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16709
Summary:
Quirex is prone to a remote information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve arbitrary files in the context of the webserver process. Information obtained may aid in further attacks.
23. MyBB Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16708
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16708
Summary:
MyBB is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Successful exploitation requires that the user's browser hasn't URL-encoded the attacker's request and that the victim user has administrative privileges to the application.
Version 1.0.4 is vulnerable; other versions may also be affected.
24. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
BugTraq ID: 14807
Remote: No
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/14807
Summary:
XFree86 is prone to a buffer overrun in its pixmap-processing code.
This issue can potentially allow an attacker to execute arbitrary code and to escalate privileges. An attacker may possibly gain superuser privileges by exploiting this issue.
25. V-webmail Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16706
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16706
Summary:
V-webmail is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Specific information regarding affected versions is not currently available; this BID will be updated as further information is disclosed.
26. PerlBlog Multiple Input Validation and Information Disclosure Vulnerabilities
BugTraq ID: 16707
Remote: Yes
Last Updated: 2006-02-17
Relevant URL: http://www.securityfocus.com/bid/16707
Summary:
PerlBlog is prone to multiple input-validation and information-disclosure vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary attacker-supplied HTML and script code in the browser of a victim user, read arbitrary '.txt' files, and create arbitrary files on the affected computer all in the context of the webserver process.
Successful exploitation of these issues may allow an attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, to retrieve sensitive information, and to execute arbitrary script code in the context of the webserver process; other attacks are also possible.
27. Squid Proxy Aborted Requests Remote Denial Of Service Vulnerability
BugTraq ID: 14761
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14761
Summary:
A remote denial-of-service vulnerability affects the Squid Proxy.
The problem arises under certain circumstances while handling aborted requests.
A remote attacker may leverage this issue to crash the affected Squid Proxy, denying service to legitimate users.
28. Squid Proxy Failed DNS Lookup Random Error Messages Information Disclosure Vulnerability
BugTraq ID: 11865
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/11865
Summary:
Squid Proxy is reported prone to an information-disclosure vulnerability. This issue may allow an attacker to gain access to potentially sensitive information.
An attacker can trigger this condition by supplying malformed host names to the proxy. The attacker may use information gathered through exploiting this condition to carry out further attacks against the application or other users.
This vulnerability is reported to affect Squid 2.5, but other versions may be affected as well.
29. Squid Proxy Unspecified DNS Spoofing Vulnerability
BugTraq ID: 13592
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/13592
Summary:
Squid Proxy is prone to an unspecified DNS-spoofing vulnerability. This could allow malicious users to perform DNS-spoofing attacks on Squid Proxy clients on unprotected networks.
This issue affects Squid Proxy versions 2.5 and earlier.
30. BirthSys Multiple SQL Injection Vulnerabilities
BugTraq ID: 16684
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16684
Summary:
BirthSys is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
An attacker can exploit these issues to bypass the authentication mechanism and gain access as an arbitrary user.
31. Squid cachemgr.cgi Unauthorized Connection Vulnerability
BugTraq ID: 2059
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/2059
Summary:
The 'cachemgr.cgi' module is a management interface for the Squid proxy service. It was installed by default in '/cgi-bin' by Red Hat Linux 5.2 and 6.0 installed with Squid. This script prompts for a host and port, which it then tries to connect to. If a webserver such as Apache is running, this can be used to connect to arbitrary hosts and ports, allowing for potential use as an intermediary in denial-of-service attacks, proxied port scans, etc. Interpreting the output of the script can allow
the attacker to determine whether or not a connection was established.
32. Squid Proxy Aborted Connection Remote Denial Of Service Vulnerability
BugTraq ID: 13166
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/13166
Summary:
A remote denial-of-service vulnerability affects the Squid Proxy. The application fails to properly handle exceptional network requests. The problem presents itself when a remote attacker prematurely aborts a connection during a PUT or POST request.
A remote attacker may leverage this issue to crash the affected Squid Proxy, denying service to legitimate users.
33. PHP Input/Output Wrapper Remote Include Function Command Execution Weakness
BugTraq ID: 10427
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/10427
Summary:
PHP is reportedly affected by an arbitrary command execution weakness through the PHP include() function. This issue is due to a design error that allows the execution of attacker supplied POST PHP commands when URI data is used as an argument to an 'include()' function.
This issue affect the PHP module itself; however the problem only presents itself when an application uses a user-supplied URI parameter as an argument to the 'include()' function.
This issue is reported to affect all version of PHP since 3.0.13. Furthermore this issue is not resolved by setting the 'php.ini' variable 'allow_url_fopen' to off.
Successful exploitation of this issue will allow an attacker to execute arbitrary PHP code on the affected computer; this will allow the execution of commands to the underlying operating system with the privileges of the affected web server process.
34. GNU Tar Hostile Destination Path Variant Vulnerability
BugTraq ID: 5834
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/5834
Summary:
GNU Tar 1.13.25 contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item which points outside the expected directory scope, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - including paths containing system binaries and other sensitive or confidential information.
This can be used to create or overwrite binaries in any desired location.
This issue is a variant of the vulnerability described in BID 3024. It is not known whether earlier versions are also affected by this variant.
35. Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
BugTraq ID: 12716
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12716
Summary:
Squid Proxy is prone to an information-disclosure vulnerability.
Reportedly, remote attackers may gain access to Set-Cookie headers related to another user. Information gathered through exploiting this issue may aid in further attacks against services related to the cookie, potentially allowing for session hijacking.
Squid Proxy 2.5 STABLE7 to 2.5 STABLE9 are vulnerable to this issue.
36. Squid Proxy DNS Name Resolver Remote Denial Of Service Vulnerability
BugTraq ID: 12551
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12551
Summary:
A remote denial-of-service vulnerability is reported to exist in Squid. The issue is reported to present itself when the affected server performs a Fully Qualify Domain Name (FQDN) lookup and receives an unexpected response.
The vendor reports that under the above circumstances, the affected service will crash due to an assertion error, effectively denying service to legitimate users.
37. SuSE XScreenSaver Package Multiple Vulnerabilities
BugTraq ID: 9125
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/9125
Summary:
SuSE have reported that xscreensaver packages shipped with SuSE Linux 9.0, are prone to multiple vulnerabilities. These issues include a crash when xscreensaver is handling the verification of authentication credentials. SuSE has also reported that xscreensaver is prone to several insecure temporary file creation vulnerabilities.
38. Linux Kernel SDLA IOCTL Unauthorized Local Firmware Access Vulnerability
BugTraq ID: 16304
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16304
Summary:
The Linux kernel is susceptible to a local access validation vulnerability in the SDLA driver.
This issue allows local users with the 'CAP_NET_ADMIN' capability, but without the 'CAP_SYS_RAWIO' capability to read and write to the SDLA device firmware. This may cause a denial of service issue if attackers write an invalid firmware. Other attacks may also be possibly by writing modified firmware files.
39. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial-of-service vulnerability.
Local attackers can exploit this vulnerability to corrupt kernel memory or free non-allocated memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.
40. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
BugTraq ID: 15531
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/15531
Summary:
Linux Kernel is reported prone to a denial of service vulnerability.
Due to a design error in the kernel an attacker can cause a memory corruption, utilmately crashing the kernel, denying service to legitimate users.
41. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
BugTraq ID: 12432
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12432
Summary:
The Squid proxy server is vulnerable to a remotely exploitable buffer-overflow vulnerability. The vulnerability resides in Squid's implementation of WCCP (web cache communication protocol), a UDP-based web cache management protocol. The condition is triggered when the server reads a packet that is larger than the size of the buffer allocated to store it. This can occur because 'recvfrom()' is passed an incorrect value for its 'len' argument.
42. Linux Kernel IP_VS_CONN_FLUSH Local Denial of Service Vulnerability
BugTraq ID: 15528
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/15528
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability.
Reports indicate that the 'ip_vs_conn_flush' function may allow local users to cause a denial of service due to a NULL-pointer dereference.
Kernel versions prior to 2.6.13 and 2.4.32-pre2 are affected.
43. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vulnerability
BugTraq ID: 12433
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12433
Summary:
Squid Proxy is reported prone to a cache-poisoning vulnerability when processing malformed HTTP requests and responses. This issue results from insufficient sanitization of user-supplied data.
Squid versions 2.5 and earlier are reported prone to this issue.
44. GNU WGet Multiple Remote Vulnerabilities
BugTraq ID: 11871
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/11871
Summary:
Mutliple remote vulnerabilities reported affects GNU wget. These issues are due to a failure of the application to properly sanitize user-supplied input and to properly validate the existence of files prior to writing to them..
The first issue is a potential directory traversal issue. The second issue is an arbitrary file overwriting vulnerability. The final issue is weakness caused by a failure of the application to filter potentially malicious characters from server-supplied input.
These issues may be exploited by a malicious server to arbitrarily overwrite files in the current directory and potentially write outside of the current directory. This may facilitate file corruption, denial of service and further attacks against the affected computer. Any file overwriting would take place with the privileges of the user that activates the vulnerable application.
45. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnerability
BugTraq ID: 12412
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12412
Summary:
A remote unspecified vulnerability reportedly affects Squid Proxy. This issue is due to the application's failure to properly handle malformed HTTP headers.
The impact of this issue is currently unknown. This BID will be updated when more information becomes available.
46. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerability
BugTraq ID: 12431
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12431
Summary:
Squid Proxy is reported prone to an authentication-bypass vulnerability. This issue seems to result from insufficient input validation.
The 'squid_ldap_auth' module is reported affected by this issue. A remote attacker may gain unauthorized access or gain elevated privileges from bypassing access controls.
Squid versions 2.5 and earlier are reported prone to this vulnerability.
47. Squid Proxy Malformed NTLM Type 3 Message Remote Denial of Service Vulnerability
BugTraq ID: 12220
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12220
Summary:
Squid is reported to be susceptible to a denial-of-service vulnerability in its NTLM authentication module. This vulnerability presents itself when an attacker sends a malformed NTLM Type 3 message to Squid.
Failure of NTLM authentication would result in the Squid application denying access to legitimate users of the proxy.
This vulnerability affects Squid 2.5.
48. Squid Proxy NTLM Fakeauth_Auth Memory Leak Remote Denial Of Service Vulnerability
BugTraq ID: 12324
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12324
Summary:
Squid is reported to be susceptible to a denial-of-service vulnerability in its NTLM authentication module.
This vulnerability presents itself when an attacker sends unspecified NTLM data to Squid. The issue is caused by a memory leak -- memory allocated to store a base64-decoded string is not freed.
Presumably, this issue allows an attacker to cause the NTLM helper application to run out of memory and fail.
49. Linux Kernel Find_Target Local Denial Of Service Vulnerability
BugTraq ID: 14965
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14965
Summary:
A local denial of service vulnerability affects the 'find_target' function of the Linux kernel. This issue is due to a failure of this function to properly handle unexpected conditions when attempting to handle a NULL return value from another function.
This vulnerability may be exploited by local users to trigger a kernel crash, denying service to legitimate users.
This issue likely only affects the x86_64 architecture.
50. Linux Kernel Stack Fault Exceptions Unspecified Local Denial of Service Vulnerability
BugTraq ID: 14467
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14467
Summary:
Linux kernel is reported prone to an unspecified local denial of service vulnerability.
It was reported that this issue arises when a local user triggers stack fault exceptions. A local attacker may exploit this issue to carry out a denial of service attack against a vulnerable computer by crashing the kernel.
51. Squid Proxy Web Cache Communication Protocol Denial Of Service Vulnerability
BugTraq ID: 12275
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12275
Summary:
A remote denial-of-service vulnerability affects the Web Cache Communication Protocol (WCCP) functionality of Squid Proxy. This issue is due to the application's failure to handle unexpected network data.
A remote attacker may leverage this issue to crash the affected Squid Proxy, denying service to legitimate users.
UPDATE: This issue was thought to result from a call to the 'recvfrom()' function. This has turned out to be incorrect; the buffer overflow from the call to 'recvfrom()' has been determined to be a new vulnerability (BID 12432).
52. Squid Proxy Gopher To HTML Remote Buffer Overflow Vulnerability
BugTraq ID: 12276
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/12276
Summary:
A remote buffer-overflow vulnerability affects the Gopher-to-HTML functionality of Squid Proxy. This issue is due to the application's failure to properly validate the length of user-supplied strings before copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.
53. Metamail Message Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 16611
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16611
Summary:
Metamail is prone to a remote buffer overflow vulnerability.
This issue arises when the application handles messages with large string values for boundaries.
This can cause memory corruption and trigger a crash in the application. Although unconfirmed, this issue may lead to arbitrary code execution.
Metamail 2.7 is reportedly vulnerable, however, other versions may be affected as well.
54. Squid Proxy SNMP ASN.1 Parser Denial Of Service Vulnerability
BugTraq ID: 11385
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/11385
Summary:
Squid is reported susceptible to a denial-of-service vulnerability in its SNMP ASN.1 parser. SNMP support is not enabled by default as provided by the vendor, but may be enabled by default when Squid is included as a binary application in certain unconfirmed operating systems.
This vulnerability allows remote attackers to crash affected Squid proxies with single UDP datagrams that may be spoofed. Squid will attempt to restart itself automatically, but an attacker sending repeated malicious SNMP packets can effectively deny service to legitimate users.
Squid versions 2.5-STABLE6 and earlier, as well as 3.0-PRE3-20040702, are reported vulnerable to this issue.
55. Squid Proxy NTLM Authentication Buffer Overflow Vulnerability
BugTraq ID: 10500
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/10500
Summary:
Squid Web Proxy Cache is reportedly affected by a buffer-overflow vulnerability when processing NTLM authentication credentials. The application fails to properly validate buffer boundaries when copying user-supplied input.
This would allow an attacker to modify stack-based process memory to cause a denial-of-service condition and execute arbitrary code in the context of the vulnerable web proxy. This will most likely facilitate unauthorized access to the affected computer.
56. PHPNuke CAPTCHA Bypass Weakness
BugTraq ID: 16722
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16722
Summary:
The CAPTCHA implementation of PHPNuke may be bypassed by remote attackers due to a design error.
This may be used to carry out other attacks such as brute-force attempts against the login page.
57. Mozilla Thunderbird Address Book Import Remote Denial of Service Vulnerability
BugTraq ID: 16716
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16716
Summary:
Mozilla Thunderbird is prone to a remote denial-of-service vulnerability.
The issue presents itself when the application handles a specially crafted address book file.
Mozilla Thunderbird 1.5 is reportedly affected by this issue. Other versions may be vulnerable as well.
58. Webpagecity WPC easy SQL Injection Vulnerability
BugTraq ID: 16721
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16721
Summary:
Webpagecity 'WPC.easy' is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
59. ADOdb Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16720
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16720
Summary:
ADOdb is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
ADOdb versions 4.71 and prior are vulnerable.
60. RCBlog Index.PHP Directory Traversal Vulnerability
BugTraq ID: 16342
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16342
Summary:
RCBlog is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
Version 1.0.3 is vulnerable; other versions may also be affected.
61. Noweb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16610
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16610
Summary:
Noweb creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
62. E107 Website System Chatbox Plugin HTML Injection Vulnerability
BugTraq ID: 16719
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16719
Summary:
The e107 content management system (CMS) Chatbox Plugin is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
63. Coppermine Multiple File Include Vulnerabilities
BugTraq ID: 16718
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16718
Summary:
Coppermine is affected by multiple local and remote file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary server-side script code that resides on an affected computer or a remote location with the privileges of the webserver process. This may potentially facilitate unauthorized access.
Coppermine 1.4.3 and prior versions are affected.
64. Microsoft Internet Explorer Script Engine Buffer Overflow Vulnerability
BugTraq ID: 16687
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16687
Summary:
The Internet Explorer VBScript and JScript engines are prone to a remote buffer-overflow vulnerability. Successful exploitation causes the browser to fail. The possibility of arbitrary code execution has not been confirmed.
This vulnerability affects Internet Explorer 6 running on Windows 2000 SP4, Windows XP Professional, and Windows 98SE. Other versions of Internet Explorer and Windows may also be affected.
65. Todd Miller Sudo Local Privilege Escalation Vulnerability
BugTraq ID: 15191
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/15191
Summary:
Sudo is prone to a local privilege-escalation vulnerability.
The vulnerability presents itself because the application fails to properly sanitize malicious data supplied through environment variables.
A successful attack may result in a complete compromise.
66. AWStats Referrer Arbitrary Command Execution Vulnerability
BugTraq ID: 14525
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14525
Summary:
AWStats is affected by an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this vulnerability will permit an attacker to execute arbitrary Perl code on the system hosting the affected application in the security context of the webserver process. This may aid in further attacks against the underlying system; other attacks are also possible.
Note that this vulnerability is possible only if the affected application has at least one URLPlugin enabled.
67. Microsoft Windows Color Management Module ICC Profile Buffer Overflow Vulnerability
BugTraq ID: 14214
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/14214
Summary:
Microsoft Windows is prone to a buffer-overflow vulnerability in the Color Management Module. The issue is due to a boundary-condition error related to the parsing of ICC (International Color Consortium) Profile tags in various supported image and document formats.
ICC Profile data may possibly be embedded in various file formats, including JPEG, GIF, EXIF, TIFF, PNG, PICT, PDF, PostScript, SVG, JDF, and CSS3. Some of these formats may not provide an attack vector, especially if Microsoft doesn't provide native support or doesn't call the vulnerable functionality when handling certain formats.
Successful exploitation may result in the execution of arbitrary code in the context of the currently logged-in user. An attacker could exploit this vulnerability by posting a malicious document on a website, by sending malicious content via email, or through other means.
There is also a risk that other Microsoft or third-party applications that rely on the affected functionality may be vulnerable. Since a number of third-party applications may ship with vulnerable libraries, they may remain vulnerable despite having applied the Microsoft patch. Symantec is not aware of any such vendors at the time of writing.
68. PHPNuke Search Module SQL Injection Vulnerability
BugTraq ID: 15421
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/15421
Summary:
PHPNuke is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
69. Sun Java Runtime Environment Unspecified Privilege Escalation Vulnerability
BugTraq ID: 13958
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/13958
Summary:
Sun Java Runtime Environment is susceptible to an unspecified privilege-escalation vulnerability.
This vulnerability allows remote, untrusted Java applications to gain elevated privileges. This allows them to read or write local files or to execute arbitrary local applications. These actions are normally forbidden for untrusted applications running in the Java virtual machine.
Further details are not available at this time. This BID will be updated as more information is disclosed.
NOTE: Reports from Harry Johnston indicate that the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
70. LibTIFF TIFFOpen Buffer Overflow Vulnerability
BugTraq ID: 13585
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/13585
Summary:
LibTIFF is prone to a buffer-overflow vulnerability. The issue occurs in the 'TIFFOpen()' function when malformed TIFF files are opened. Successful exploitation could lead to arbitrary code execution.
71. Linux Kernel SDLA_XFER Kernel Memory Disclosure Vulnerability
BugTraq ID: 16759
Remote: No
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16759
Summary:
The Linux kernel is affected by a local memory-disclosure vulnerability.
This issue allows an attacker to read kernel memory. Information gathered via exploitation may aid malicious users in further attacks.
This issue affects kernel versions 2.4.x up to 2.4.29-rc1, and 2.6.x up to 2.6.5.
72. PEAR::Auth Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 16758
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16758
Summary:
PEAR::Auth is prone to multiple unspecified SQL injection vulnerabilities. This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
PEAR::Auth versions prior to 1.2.4 and prior to 1.3.0r4 are vulnerable.
73. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
BugTraq ID: 16756
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16756
Summary:
SquirrelMail is susceptible to multiple cross-site scripting and IMAP injection vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input.
An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An attacker may leverage the IMAP injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid the attacker in further attacks as well as allow them to exploit latent vulnerabilities in the IMAP server.
74. Geeklog Multiple Input Validation Vulnerabilities
BugTraq ID: 16755
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16755
Summary:
Geeklog is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Geeklog is prone to multiple SQL injection vulnerabilities, and an arbitrary local file include vulnerability.
Further information reports Media Gallery is also vulnerable to these issues as it shares the same code base.
75. Admbook Remote PHP Script Code Execution Vulnerability
BugTraq ID: 16753
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16753
Summary:
Admbook is prone to a remote PHP script code execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the Web server process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Admbook version 1.2.2 is vulnerable to these issues; other versions may also be affected.
76. PostNuke Multiple Input Validation Vulnerabilities
BugTraq ID: 16752
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16752
Summary:
PostNuke is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as control how the site is rendered to the user; other attacks are also possible.
77. Guestbox HTML Injection Vulnerability
BugTraq ID: 16751
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16751
Summary:
Guestbox is prone to an HTML-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
78. Melange Chat Session Header Information Disclosure Vulnerability
BugTraq ID: 16747
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16747
Summary:
Melange Chat is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly secure HTTP request data.
An attacker can exploit this issue to retrieve the credentials of an arbitrary user.
If an administrative user's credentials are retrieved, successful exploitation may result in the compromise of the affected application; other attacks are also possible.
79. Barracuda Directory Multiple HTML Injection Vulnerabilities
BugTraq ID: 16746
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16746
Summary:
Barracuda Directory is prone to multiple HTML injection vulnerabilities. Successful exploitation could result in arbitrary script execution in the browser of a site administrator.
Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
These issues affect Barracuda Directory version 1.1. Other versions may also be vulnerable.
80. Bugzilla User Credentials Information Disclosure Vulnerability
BugTraq ID: 16745
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16745
Summary:
Bugzilla is prone to an information disclosure vulnerability. This issue is due to a design error in the application.
An attacker can exploit this issue by tricking a victim user into following a malicious URI and retrieve the victim user's login credentials.
Successful exploitation of this issue requires the name of the path where the login page resides, resolves to a computer on the local network of the victim user.
81. True North Software IA EMailServer Remote Buffer Overflow Vulnerability
BugTraq ID: 16744
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16744
Summary:
True North Software IA eMailServer is prone to a remote buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected service. Failed exploitation attempts likely result in the service crashing.
IA eMailServer version 5.3.4 is prone to this issue; previous versions may also be affected.
82. Mozilla Firefox HTML Parsing Denial of Service Vulnerability
BugTraq ID: 16741
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16741
Summary:
Mozilla Firefox is prone to a denial of service condition when parsing certain malformed HTML content. Successful exploitation will cause the browser to fail or hang.
This issue may be related to BID 11440 Mozilla Invalid Pointer Dereference Vulnerability, however, this has not been confirmed.
Mozilla Firefox versions prior to 1.5.0.1 are prone to this issue.
83. Bugzilla Whinedays SQL Injection Vulnerability
BugTraq ID: 16738
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16738
Summary:
Bugzilla is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploitation of this issue requires the attacker to have administrative access to the affected application.
84. Apple Mac OS X Archive Metadata Command Execution Vulnerability
BugTraq ID: 16736
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16736
Summary:
Apple Mac OS X is prone to an arbitrary command execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file.
Mac OS X 10.4.5 is reported to be vulnerable. Earlier versions may also be affected.
85. IlchClan Multiple SQL Injection Vulnerabilities
BugTraq ID: 16735
Remote: Yes
Last Updated: 2006-02-21
Relevant URL: http://www.securityfocus.com/bid/16735
Summary:
ilchClan is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
An attacker may exploit these issues to gain access as an arbitrary user.
86. GBook Multiple Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 14725
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/14725
Summary:
gBook is prone to multiple unspecified cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
87. Time Tracking Software Multiple Input Validation Vulnerabilities
BugTraq ID: 16630
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16630
Summary:
Time Tracking Software is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.
88. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
89. GnuPG Detached Signature Verification Bypass Vulnerability
BugTraq ID: 16663
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16663
Summary:
GnuPG is affected by a detached signature verification-bypass vulnerability. This issue is due to the application's failure to properly notify scripts that an invalid detached signature was presented and that the verification process has failed.
This issue allows attackers to bypass the signature-verification process used in some automated scripts. Depending on the use of GnuPG, this may result in a false sense of security, the installation of malicious packages, the execution of attacker-supplied code, or other attacks.
90. PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
BugTraq ID: 16649
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16649
Summary:
PostgreSQL is susceptible to a remote privilege-escalation vulnerability. This issue is due to a flaw in the error path of the 'SET ROLE' function.
This issue allows remote attackers with database access to gain administrative access to affected database servers. Since such access also allows filesystem access, other attacks against the underlying operating system may also be possible.
91. Magic Calendar Lite Index.PHP SQL Injection Vulnerability
BugTraq ID: 16734
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16734
Summary:
Magic Calendar Lite is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.02 is vulnerable; other versions may also be affected.
92. EmuLinker Malformed Packet Remote Denial Of Service Vulnerability
BugTraq ID: 16733
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16733
Summary:
EmuLinker is susceptible to a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed network packets from other game players.
This issue results in a crash of the server application, denying further service to users.
EmuLinker versions prior to 0.99.17 are affected by this issue.
93. PHPNuke Index.PHP Search Module SQL Injection Vulnerability
BugTraq ID: 16732
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16732
Summary:
PHPNuke is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 7.5.0 up to 7.8.0 are vulnerable; other versions may also be affected.
94. TTS Software Time Tracking Software Edituser.PHP Access Validation Vulnerability
BugTraq ID: 16731
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16731
Summary:
Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application.
An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks.
This issue is reported to affect Time Tracking Software version 3.0; other versions may also be vulnerable.
95. MiniNuke CMS Pages.ASP SQL Injection Vulnerability
BugTraq ID: 16730
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16730
Summary:
MiniNuke CMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 1.8.2. and earlier are vulnerable; other versions may also be affected.
96. Fedora Directory Server Password Information Disclosure Vulnerability
BugTraq ID: 16729
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16729
Summary:
Fedora Directory Server is prone to an information disclosure vulnerability. This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.
An attacker can exploit this vulnerability to obtain escalated privileges within the context of the server application. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
97. Tin News Reader Buffer Overflow Vulnerability
BugTraq ID: 16728
Remote: Yes
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16728
Summary:
The Tin news reader is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code on the victim userĂ¢??s computer in the context of the victim user. This may facilitate a compromise of the affected computer.
Versions 1.8.0 and earlier are vulnerable.
98. Xerox WorkCentre Products Local Authentication Bypass Vulnerability
BugTraq ID: 16726
Remote: No
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16726
Summary:
Xerox WorkCentre products are susceptible to an authentication bypass vulnerability. This issue is due to a flaw in the authentication process.
This issue allows local attackers to gain unauthorized access to the affected devices.
WorkCentre 232, 238, 245, 255, 265, 275 and WorkCentre Pro 232, 238, 245, 255, 265, and 275 are affected by this issue.
99. Xerox WorkCentre Unspecified Denial of Service Vulnerability
BugTraq ID: 16723
Remote: No
Last Updated: 2006-02-20
Relevant URL: http://www.securityfocus.com/bid/16723
Summary:
Xerox WorkCentre products are prone to an unspecified denial of service vulnerability. This issue is most likely due to a failure in the software to handle exceptional conditions.
An attacker can exploit this vulnerability to cause the application to become unstable or halt, ultimately denying service to legitimate user.
Very little information is currently available on this vulnerability, this BID will be updated as further information becomes available.
WorkCentre 232, 238, 245, 255, 265, and 275 and WorkCentre Pro 232, 238, 245, 255, 265, and 275 are reported to be affected; other versions may also be vulnerable.
100. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-02-18
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.
Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.
This issue affects Apache 2.x versions.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Private identities become a corporate focus
By: Robert Lemos
Technology companies at the RSA Security Conference expound on the privacy benefits of online services that authenticate users based on the least amount of information possible.
http://www.securityfocus.com/news/11377
2. Startup tries to spin a safer Web
By: Robert Lemos
Armed with client-side honeypots and a low-cost team in India, a group of MIT graduates aims to create a system to warn Web surfers about the seedier sites, and outright malicious servers, on the Internet.
http://www.securityfocus.com/news/11376
3. Apple's in the eye of flaw finders
By: Robert Lemos
With the move to Intel processors and a larger share of the market, Apple's Mac OS X could find itself a more popular target of attack, security professionals say.
http://www.securityfocus.com/news/11375
4. Blackmal virus set to delete files
By: Robert Lemos
Security experts urge companies to clean their networks of a malicious mass-mailing computer virus, before compromised systems reach the first trigger date and start deleting eleven types of files.
http://www.securityfocus.com/news/11374
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sales Representative, Bloomfield Hills
http://www.securityfocus.com/archive/77/425581
2. [SJ-JOB] CHECK Team Leader, Reading
http://www.securityfocus.com/archive/77/425579
3. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/425576
4. [SJ-JOB] Sr. Security Analyst, Jacksonville
http://www.securityfocus.com/archive/77/425577
5. [SJ-JOB] Sales Representative, San Mateo
http://www.securityfocus.com/archive/77/425580
6. [SJ-JOB] Sales Engineer, Columbus
http://www.securityfocus.com/archive/77/425271
7. [SJ-JOB] Sales Engineer, Cincinnati
http://www.securityfocus.com/archive/77/425275
8. [SJ-JOB] Security Consultant, San Antonio
http://www.securityfocus.com/archive/77/425206
9. [SJ-JOB] Security Consultant, Minneapolis
http://www.securityfocus.com/archive/77/425266
10. [SJ-JOB] Sr. Security Engineer, St. Paul
http://www.securityfocus.com/archive/77/425203
11. [SJ-JOB] Sales Engineer, Dayton
http://www.securityfocus.com/archive/77/425160
12. [SJ-JOB] Sales Engineer, Cleveland
http://www.securityfocus.com/archive/77/425200
13. [SJ-JOB] Security Consultant, Phoenix
http://www.securityfocus.com/archive/77/425255
14. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/425256
15. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/425253
16. [SJ-JOB] Sales Engineer, Minneapolis
http://www.securityfocus.com/archive/77/425118
17. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/425119
18. [SJ-JOB] Security Engineer, Herndon
http://www.securityfocus.com/archive/77/425121
19. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/425117
20. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/425122
21. [SJ-JOB] Application Security Engineer, Columbia
http://www.securityfocus.com/archive/77/425098
22. [SJ-JOB] Application Security Engineer, Columbia
http://www.securityfocus.com/archive/77/425096
23. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/425138
24. [SJ-JOB] Security Consultant, New York City
http://www.securityfocus.com/archive/77/425140
25. [SJ-JOB] Security Consultant, Philadelphia
http://www.securityfocus.com/archive/77/425124
26. [SJ-JOB] Security Auditor, Huntsville
http://www.securityfocus.com/archive/77/425074
27. [SJ-JOB] Manager, Information Security, Westlake Village / LA Area
http://www.securityfocus.com/archive/77/425068
28. [SJ-JOB] Disaster Recovery Coordinator, London
http://www.securityfocus.com/archive/77/425070
29. [SJ-JOB] Security Engineer, Lanham
http://www.securityfocus.com/archive/77/425069
30. [SJ-JOB] Security Consultant, Toronto
http://www.securityfocus.com/archive/77/425073
31. [SJ-JOB] Security Engineer, Norcross
http://www.securityfocus.com/archive/77/425051
32. [SJ-JOB] Management, Silicon Valley/Bay Area
http://www.securityfocus.com/archive/77/425137
33. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/425052
34. [SJ-JOB] Security Consultant, Washington
http://www.securityfocus.com/archive/77/425135
35. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/425136
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. PHP and SCRIPT_NAME variable
http://www.securityfocus.com/archive/82/425607
2. CALL FOR PAPER - SYSCAN'06
http://www.securityfocus.com/archive/82/425598
3. BCS Asia 2006 - Call for Papers
http://www.securityfocus.com/archive/82/425297
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Retriving ACL's on 60 thousand folders
http://www.securityfocus.com/archive/88/425192
2. SecurityFocus Microsoft Newsletter #278
http://www.securityfocus.com/archive/88/425033
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Kryptor Whitepaper released
http://www.securityfocus.com/archive/91/425067
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Lancope
"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."
http://www.lancope.com/resource/