SecurityFocus Newsletter #339
Peter Laborge <[email protected]> Tue, 28 Feb 2006 15:06:05 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #339
----------------------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics White Paper It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000C543
------------------------------------------------------------------
I. FRONT AND CENTER
1. John the Ripper 1.7, by Solar Designer
2. Zero to IPSec in 4 minutes
3. Spreading security awareness for OS X
II. BUGTRAQ SUMMARY
1. Gaim IRC Protocol Plug-in Markup Language Injection Vulnerability
2. Gaim Gaim_Markup_Strip_HTML Remote Denial Of Service Vulnerability
3. Thomson SpeedTouch 500 Series Cross-Site Scripting Vulnerability
4. PHP-Nuke Mainfile.PHP SQL Injection Vulnerability
5. iGenus WebMail Config_Inc.PHP Remote File Include Vulnerability
6. DCI-Taskeen Multiple SQL Injection Vulnerabilities
7. Sun Solaris HSFS Filesystem Local Denial Of Service Vulnerability
8. PHPWebSite Topics.PHP SQL Injection Vulnerability
9. FreeHostShop Website Generator Arbitrary File Upload Vulnerability
10. SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
11. Battleaxe Software BttlxeForum Failure.ASP Cross-Site Scripting Vulnerability
12. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
13. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
14. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
15. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
16. Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
17. Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
18. Sudo Python Environment Variable Handling Security Bypass Vulnerability
19. GNUTLS LibTASN1 DER Decoding Denial of Service Vulnerabilities
20. GnuPG Detached Signature Verification Bypass Vulnerability
21. Todd Miller Sudo Local Race Condition Vulnerability
22. The Bat! Remote Buffer Overflow Vulnerability
23. CubeCart Arbitrary File Upload Vulnerability
24. NOCC Webmail Multiple Input Validation Vulnerabilities
25. Zoo Misc.c Buffer Overflow Vulnerability
26. Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
27. Gaim Multiple Remote Denial of Service Vulnerabilities
28. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
29. ArGoSoft FTP Server DELE Command Remote Buffer Overrun Vulnerability
30. Gaim Remote Denial of Service Vulnerability
31. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
32. Linux Kernel IP6_Input_Finish Remote Denial Of Service Vulnerability
33. Linux Kernel ICMP_Push_Reply Remote Denial Of Service Vulnerability
34. Linux Kernel NFS ACL Access Control Bypass Vulnerability
35. Linux Kernel SET_MEMPOLICY Local Denial of Service Vulnerability
36. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
37. Linux Kernel Find_Target Local Denial Of Service Vulnerability
38. Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
39. Mozilla Browser/Firefox XBM Image Processing Heap Overflow Vulnerability
40. Fortinet FortiGate Antivirus Engine Bypass Vulnerability
41. Linux Kernel PROC Filesystem Local Information Disclosure Vulnerability
42. Papoo Multiple SQL Injection Vulnerabilities
43. Fortinet FortiGate URL Filtering Bypass Vulnerability
44. PHPLIB Unspecified Code Execution Vulnerability
45. PerlBlog Multiple Input Validation and Information Disclosure Vulnerabilities
46. XPDF Multiple Unspecified Vulnerabilities
47. SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
48. Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnerability
49. Pentacle In-Out Board Multiple SQL Injection Vulnerabilities
50. EZ Publish ImageCatalogue Cross-Site Scripting Vulnerability
51. Mozilla Firefox Large History File Buffer Overflow Vulnerability
52. TMSPublisher Search.CFM Cross-Site Scripting Vulnerability
53. MyPHPNuke Multiple Cross-Site Scripting Vulnerabilities
54. Cilem News Unspecified SQL Injection Vulnerability
55. Mambo Open Source Multiple SQL Injection Vulnerabilities
56. DEV Web Management System HTML Injection Vulnerability
57. ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
58. JGS-Gallery Module Multiple Cross-Site Scripting Vulnerabilities
59. ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
60. PwsPHP Index.PHP SQL Injection Vulnerability
61. Multiple Reamday Enterprises Products Multiple Variable Overwrite Vulnerabilities
62. StuffIt and ZipMagic Remote Directory Traversal Vulnerability
63. PHP PEAR::Archive_Tar Remote Directory Traversal Vulnerability
64. PHP Error Message Cross-Site Scripting Vulnerability
65. Heimdal RSHD Local Privilege Escalation Vulnerability
66. Heimdal TelnetD Denial Of Service Vulnerability
67. PostgreSQL Set Session Authorization Denial of Service Vulnerability
68. 4images Index.PHP Remote File Include Vulnerability
69. Alt-N MDaemon IMAP Server Remote Format String Vulnerability
70. Calcium EventText Cross-Site Scripting Vulnerability
71. MySQL Query Logging Bypass Vulnerability
72. DirectContact Directory Traversal Vulnerability
73. Archangel Weblog Authentication Bypass Vulnerability
74. iCal Calendar Text Cross-Site Scripting Vulnerability
75. Oracle Diagnostics Multiple Vulnerabilities
76. Woltlab Burning Board Multiple Cross-Site Scripting Vulnerabilities
77. Fantastic Scripts Fantastic News SQL Injection Vulnerability
78. MTS Professional Open EMail Relay Vulnerability
79. FreeBSD Remote NFS Mount Request Denial of Service Vulnerability
80. Netgear WGT624 Wireless Firewall Router Information Disclosure Vulnerability
81. Lansuite Board Module SQL Injection Vulnerability
82. Netgear WGT624 Wireless Access Point Default Backdoor Account Vulnerability
83. ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
84. PHPRPC Library Remote Code Execution Vulnerability
85. ImageMagick File Name Handling Remote Format String Vulnerability
86. Noweb Insecure Temporary File Creation Vulnerability
87. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
88. Gaim MSN Protocol Malformed Message Denial of Service Vulnerability
89. Gaim Yahoo! Protocol Support File Download Denial of Service Vulnerability
90. EKG Libgadu Multiple Memory Alignment Remote Denial of Service Vulnerabilities
91. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
92. Gaim Remote MSN Empty SLP Message Denial Of Service Vulnerability
93. Gaim Remote URI Handling Buffer Overflow Vulnerability
94. Gaim Jabber File Request Remote Denial Of Service Vulnerability
95. POPFile Denial Of Service Vulnerability
96. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
97. Winace Remote Directory Traversal Vulnerability
98. PHPX XCode Tag HTML Injection Vulnerability
99. PHP 5 User-Supplied Session ID Input Validation Vulnerability
100. D3Jeeb Multiple SQL Injection Vulnerabilities
III. SECURITYFOCUS NEWS
1. Triple threat to Mac OS X largely academic
2. Private identities become a corporate focus
3. Startup tries to spin a safer Web
4. Apple's in the eye of flaw finders
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sales Engineer, New York
2. [SJ-JOB] Security System Administrator, Tampa
3. [SJ-JOB] Information Assurance Engineer, BWI Area
4. [SJ-JOB] Compliance Officer, Surrey - Flexible Locations ie. client sites
5. [SJ-JOB] Sr. Product Manager, Northern
6. [SJ-JOB] CHECK Team Leader, Surrey
7. [SJ-JOB] Database Security Engineer, Riyad
8. [SJ-JOB] Security Consultant, London
9. [SJ-JOB] Security Consultant, London
10. [SJ-JOB] Security Consultant, Tampa
11. [SJ-JOB] Director of Privacy and Security, Louisville
12. [SJ-JOB] Security Engineer, Framingham
13. [SJ-JOB] Sales Engineer, Oxford
14. [SJ-JOB] Security Consultant, Amsterdam
15. [SJ-JOB] Technical Marketing Engineer, Redwood City
16. [SJ-JOB] Database Security Engineer, Kolkata
17. [SJ-JOB] Database Security Architect, Redmond
18. [SJ-JOB] Information Assurance Analyst, Linthicum
19. [SJ-JOB] Training / Awareness Specialist, Washington, DC
20. [SJ-JOB] Security Engineer, Reston
21. [SJ-JOB] Security Engineer, Alviso/Silicon Valley
22. [SJ-JOB] Security Engineer, Brooklyn (Metrotech)
23. [SJ-JOB] Sales Engineer, Abingdon, Oxfordshire
24. [SJ-JOB] Technical Marketing Engineer, Redwood City
25. [SJ-JOB] Security Engineer, Palo Alto
26. [SJ-JOB] Sr. Security Engineer, Irvine
27. [SJ-JOB] Sales Engineer, Fort Lauderdale
28. [SJ-JOB] Security Engineer, Houston
29. [SJ-JOB] Security Engineer, Dallas
30. [SJ-JOB] Security Engineer, Seattle
31. [SJ-JOB] Security Engineer, Salt lake City
32. [SJ-JOB] Security Consultant, Bangalore,Delhi,Mumbai,Chennai,Hyderabad
33. [SJ-JOB] Security Engineer, Highland Ranch
34. [SJ-JOB] Auditor, Denver
35. [SJ-JOB] Security Architect, Beverly
36. [SJ-JOB] Security Product Marketing Manager, Northern
37. [SJ-JOB] Security Product Manager, Northern
38. [SJ-JOB] Security Consultant, Cambridge
39. [SJ-JOB] Security Consultant, Riyad
40. [SJ-JOB] CSO, Calgary
41. [SJ-JOB] Sales Engineer, Reston
42. [SJ-JOB] Account Manager, Chicago
43. [SJ-JOB] Application Security Architect, Riyadh
44. [SJ-JOB] Auditor, San Antonio
45. [SJ-JOB] Sr. Product Manager, Calabasas/LA Area
46. [SJ-JOB] Sr. Security Engineer, Sterling
47. [SJ-JOB] Director, Information Security, London or Bournmouth
48. [SJ-JOB] Developer, Superior
49. [SJ-JOB] Quality Assurance, Superior
50. [SJ-JOB] Manager, Information Security, Manhattan
51. [SJ-JOB] Chief Scientist, Chambersburg
52. [SJ-JOB] Sales Representative, ALEXANDRIA
53. [SJ-JOB] Manager, Information Security, Manhattan
V. INCIDENTS LIST SUMMARY
1. Strange Traffic to ports 139 and 137 from a machine with no data
2. announcement: reporting and mitigating botnets
3. How to determine which PHP-script allows spamming?
4. Increase in MS-SQL Probes
VI. VULN-DEV RESEARCH LIST SUMMARY
1. DEF CON 14 is now in effect! The Call for Papers is open.
VII. MICROSOFT FOCUS LIST SUMMARY
1. Domain policy getting override on local
2. SecurityFocus Microsoft Newsletter #279
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. John the Ripper 1.7, by Solar Designer
By Federico Biancuzzi
Federico Biancuzzi interviews Solar Designer, creator of the popular John the Ripper password cracker. Solar Designer discusses what's new in version 1.7, the advantages of popular cryptographic hashes, the relative speed at which many passwords can now be cracked, and how one can choose strong passphrases (forget passwords) that are harder to break.
http://www.securityfocus.com/columnists/388
2. Zero to IPSec in 4 minutes
By Dragos Ruiu
This short article looks at how to get a fully functional IPSec VPN up and running between two fresh OpenBSD installations in about four minutes flat.
http://www.securityfocus.com/infocus/1859
3. Spreading security awareness for OS X
By Robert Lemos
Robert Lemos interviews Kevin Finisterre, founder of security startup Digital Munition, who created the three recent versions of the InqTana worm to raise awareness of security in Apple's OS X. Finisterre discusses his reasons for creating the worms, the problems with Mac OS X security, and why he does not fear prosecution.
http://www.securityfocus.com/columnists/389
II. BUGTRAQ SUMMARY
--------------------
1. Gaim IRC Protocol Plug-in Markup Language Injection Vulnerability
BugTraq ID: 13003
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/13003
Summary:
Gaim IRC protocol plug-in is reported prone to an input-validation vulnerability. The issue is reported to occur because of a lack of sufficient sanitization performed on 'irc_msg' data.
A remote attacker may exploit this vulnerability to execute arbitrary Gaim and Pango Markup language in the context of the user that is running the affected software.
This vulnerability is reported to affect Gaim version 1.2.0 and previous versions.
2. Gaim Gaim_Markup_Strip_HTML Remote Denial Of Service Vulnerability
BugTraq ID: 12999
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/12999
Summary:
Gaim is reported prone to a remote denial-of-service vulnerability. The issue manifests when the Gaim client handles a malformed HTML string triggering an out-of-bounds read operation.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
This vulnerability is reported to affect Gaim version 1.2.0 and previous versions.
3. Thomson SpeedTouch 500 Series Cross-Site Scripting Vulnerability
BugTraq ID: 16839
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16839
Summary:
The SpeedTouch 500 series are prone to a cross-site scripting vulnerability. This issue is due to a failure in the devices to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the compromise of the device.
4. PHP-Nuke Mainfile.PHP SQL Injection Vulnerability
BugTraq ID: 16831
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16831
Summary:
PHP-Nuke is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Reports indicate this issue is directly related to the filtering mechanisms PHP-Nuke uses to prevent SQL injection type attacks. Therefore, this issue may affect all scripts and parameters utilizing the vulnerable filtering mechanisms.
5. iGenus WebMail Config_Inc.PHP Remote File Include Vulnerability
BugTraq ID: 16829
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16829
Summary:
iGenus WebMail is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
6. DCI-Taskeen Multiple SQL Injection Vulnerabilities
BugTraq ID: 16828
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16828
Summary:
DCI-Taskeen is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
7. Sun Solaris HSFS Filesystem Local Denial Of Service Vulnerability
BugTraq ID: 16826
Remote: No
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16826
Summary:
Sun Solaris is prone to a local denial of service vulnerability.
A local unprivileged attacker can cause a system panic in the 'hsfs' module. This will crash the computer, denying further service to legitimate users. Arbitrary code execution may also be possible.
8. PHPWebSite Topics.PHP SQL Injection Vulnerability
BugTraq ID: 16825
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16825
Summary:
phpWebSite is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
9. FreeHostShop Website Generator Arbitrary File Upload Vulnerability
BugTraq ID: 16823
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16823
Summary:
Website generator is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
10. SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
BugTraq ID: 16822
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16822
Summary:
SPiD is prone to a local file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this issue may facilitate the unauthorized viewing of files and unauthorized execution of local scripts.
11. Battleaxe Software BttlxeForum Failure.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16821
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16821
Summary:
bttlxeForum is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
12. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 16076
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16076
Summary:
The Ethereal GTP protocol dissector is prone to a remotely exploitable denial-of-service vulnerability.
Successful exploitation will cause a denial-of-service condition in the Ethereal application.
Further details are not currently available. This BID will be updated as more information is disclosed.
13. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15794
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/15794
Summary:
A remote buffer-overflow vulnerability affects Ethereal. This issue is due to the application's failure to securely copy network-derived data into sensitive process buffers. The specific issue occurs in the OSPF dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
14. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.
Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.
This issue affects Apache 2.x versions.
15. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
16. Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
BugTraq ID: 16798
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16798
Summary:
VPMi Enterprise is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
17. Nullsoft Winamp M3U File Processing Buffer Overflow Vulnerability
BugTraq ID: 16785
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16785
Summary:
Nullsoft Winamp is prone to a buffer-overflow vulnerability when processing malformed M3U files. The overrun occurs when the M3U playlist is paused or stopped.
This issue is reported to affect Winamp versions 5.12 and 5.13. Earlier versions may also be vulnerable.
18. Sudo Python Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 16184
Remote: No
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16184
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.
A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. That attacker may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.
An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.
This issue is similar to BID 15394 (Sudo Perl Environment Variable Handling Security Bypass Vulnerability).
19. GNUTLS LibTASN1 DER Decoding Denial of Service Vulnerabilities
BugTraq ID: 16568
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16568
Summary:
Libtasn1 is prone to multiple denial-of-service vulnerabilities. A remote attacker can send specifically crafted data to trigger these flaws, leading to denial-of-service condition.
These issues have been addressed in Libtasn1 versions 0.2.18; earlier versions are vulnerable.
20. GnuPG Detached Signature Verification Bypass Vulnerability
BugTraq ID: 16663
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16663
Summary:
GnuPG is affected by a detached signature verification-bypass vulnerability. This issue is due to the application's failure to properly notify scripts that an invalid detached signature was presented and that the verification process has failed.
This issue allows attackers to bypass the signature-verification process used in some automated scripts. Depending on the use of GnuPG, this may result in a false sense of security, the installation of malicious packages, the execution of attacker-supplied code, or other attacks.
21. Todd Miller Sudo Local Race Condition Vulnerability
BugTraq ID: 13993
Remote: No
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/13993
Summary:
Sudo is prone to a local race-condition vulnerability. The issue manifests itself only under certain conditions, specifically, when the 'sudoers' configuration file contains a pseudo-command 'ALL' that directly follows a user's 'sudoers' entry.
When such a configuration exists, local attackers may leverage this issue to execute arbitrary executables with escalated privileges. Attackers may achieve this by creating symbolic links to target files.
22. The Bat! Remote Buffer Overflow Vulnerability
BugTraq ID: 16797
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16797
Summary:
The Bat! is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to perform proper bounds checking on user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to control program flow and execute arbitrary attacker-supplied code in the context of the victim user running the affected application.
23. CubeCart Arbitrary File Upload Vulnerability
BugTraq ID: 16796
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16796
Summary:
CubeCart is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
24. NOCC Webmail Multiple Input Validation Vulnerabilities
BugTraq ID: 16793
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16793
Summary:
NOCC Webmail is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to inject arbitrary PHP code and execute it in the context of the vulnerable webserver. An attacker can also exploit these issues to execute arbitrary HTML or script code in the browser of a victim user in the context of the webserver process. This may facilitate the theft of cookie-based authentication credentials; other attacks are also possible.
25. Zoo Misc.c Buffer Overflow Vulnerability
BugTraq ID: 16790
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16790
Summary:
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.
26. Macromedia Shockwave Player ActiveX Control Buffer Overflow Vulnerability
BugTraq ID: 16791
Remote: Yes
Last Updated: 2006-02-24
Relevant URL: http://www.securityfocus.com/bid/16791
Summary:
Macromedia Shockwave Player is prone to a buffer overflow when a particular ActiveX control is passed malicious parameters. Attackers can exploit this vulnerability to crash the application or to potentially execute arbitrary code.
Macromedia Shockwave Player versions 10.1.0.11 and earlier are vulnerable.
27. Gaim Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 12589
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/12589
Summary:
Gaim is prone to multiple remote denial-of-service vulnerabilities. These issues can allow remote attackers to crash an affected client.
The following specific issues were identified:
- Remote AIM or ICQ users may trigger a crash in a client by sending malformed SNAC packets.
- Another vulnerability in the client arises during the parsing of malformed HTML data.
Gaim versions prior to 1.1.3 are affected by these issues.
28. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
BugTraq ID: 16756
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16756
Summary:
SquirrelMail is susceptible to multiple cross-site scripting and IMAP-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.
An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
An attacker may leverage the IMAP-injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid attackers in further attacks as well as allow them to exploit latent vulnerabilities in the IMAP server.
29. ArGoSoft FTP Server DELE Command Remote Buffer Overrun Vulnerability
BugTraq ID: 12755
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/12755
Summary:
ArGoSoft FTP Server is prone to a buffer overrun when handling data through the DELE command.
It is reported that passing excessive data may overrun a finite sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data.
This issue may lead to a denial of service condition or the execution of arbitrary code.
ArGoSoft FTP Server 1.4.2.8 is reported vulnerable. It is possible that other versions are affected as well.
**Update: it is reported that the vendor attempted to address the vulnerability described in this BID in version 1.4.2.29 but was not successful. However, reports indicate that data that is written into the affected buffer is now Unicode format. This results in exploit data containing NULL bytes, hindering exploitation of the vulnerability. A proof of concept that triggers a denial of service is available.
30. Gaim Remote Denial of Service Vulnerability
BugTraq ID: 12660
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/12660
Summary:
Gaim is affected by a remote denial-of-service vulnerability. This issue can allow remote attackers to crash an affected client.
A vulnerability in the client arises during the parsing of malformed HTML data. This issue is nearly identical to that reported in BID 12589, but is a separate issue.
Gaim versions prior to 1.1.4 are affected by this issue.
31. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
BugTraq ID: 16284
Remote: No
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16284
Summary:
The Linux kernel is affected by a local memory-disclosure vulnerability.
This issue allows an attacker to read kernel memory. Information gathered via exploitation may aid malicious users in further attacks.
This issue affects the 2.6 series of the Linux kernel, prior to 2.6.15.
32. Linux Kernel IP6_Input_Finish Remote Denial Of Service Vulnerability
BugTraq ID: 16043
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16043
Summary:
Linux kernel is prone to a remote denial of service vulnerability.
Remote attackers can exploit this to leak kernel memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.
Linux kernel versions 2.6.12.5 and prior in the 2.6 series are vulnerable to this issue.
33. Linux Kernel ICMP_Push_Reply Remote Denial Of Service Vulnerability
BugTraq ID: 16044
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16044
Summary:
Linux kernel is prone to a remote denial of service vulnerability.
Remote attackers can exploit this to leak kernel memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.
Linux kernel versions 2.6.12.5 and prior in the 2.6 series are vulnerable to this issue.
34. Linux Kernel NFS ACL Access Control Bypass Vulnerability
BugTraq ID: 16570
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16570
Summary:
The Linux kernel's NFS implementation is susceptible to a remote access-control-bypass vulnerability. This issue is due to a failure to validate the privileges of remote users before setting ACLs.
This issue allows remote attackers to improperly alter ACLs on NFS filesystems, allowing them to bypass access controls. Disclosure of sensitive information, modification of arbitrary files, and other attacks are possible.
Kernel versions prior to 2.6.14.5 in the 2.6 kernel series are vulnerable to this issue.
35. Linux Kernel SET_MEMPOLICY Local Denial of Service Vulnerability
BugTraq ID: 16135
Remote: No
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16135
Summary:
Linux kernel is prone to a local denial-of-service vulnerability.
This issue affects the 'set_mempolicy()' function of the 'mm/mempolicy.c' file.
Successful exploitation causes the kernel to crash, leading to a denial-of-service condition.
36. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
BugTraq ID: 16283
Remote: No
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16283
Summary:
Linux kernel 'mq_open()' system call is prone to a local denial-of-service vulnerability. Further information is not currently available. This record will be updated when more details are disclosed.
This issue affects Linux kernel 2.6.9. Earlier kernel versions may be affected.
37. Linux Kernel Find_Target Local Denial Of Service Vulnerability
BugTraq ID: 14965
Remote: No
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/14965
Summary:
A local denial-of-service vulnerability affects the 'find_target()' function of the Linux kernel. This issue is due to this function's failure to properly handle unexpected conditions when trying to handle a NULL return value from another function.
Local attackers may exploit this vulnerability to trigger a kernel crash, denying service to legitimate users.
This issue likely affects only the x86_64 architecture.
38. Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
BugTraq ID: 11785
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/11785
Summary:
It is reported that 'rpc.statd' is vulnerable to a remote denial-of-service vulnerability.
This vulnerability allows remote attackers to crash the affected application. This may result in the failure to clean up NFS network locks, possibly resulting in denied access to files, because they may be considered permanently locked.
Version 1.0.6 of nfs-utils is reported vulnerable to this issue. Other versions may also be affected.
39. Mozilla Browser/Firefox XBM Image Processing Heap Overflow Vulnerability
BugTraq ID: 14916
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/14916
Summary:
Mozilla and Firefox browsers are prone to a heap overflow when processing malformed XBM images. Successful exploitation can result in arbitrary code execution.
40. Fortinet FortiGate Antivirus Engine Bypass Vulnerability
BugTraq ID: 16597
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16597
Summary:
Fortinet FortiGate is reportedly prone to a vulnerability that allows an attacker to bypass antivirus protection. This issue is said to occur when files are transferred using the FTP protocol under certain conditions.
FortiGate devices running FortiOS v2.8MR10 and v3beta are affected by this issue. Other versions may also be vulnerable.
41. Linux Kernel PROC Filesystem Local Information Disclosure Vulnerability
BugTraq ID: 11937
Remote: No
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/11937
Summary:
The Linux kernel /proc filesystem is reported susceptible to an information-disclosure vulnerability. This issue is due to a race-condition allowing unauthorized access to potentially sensitive process information.
This vulnerability may allow malicious local users to gain access to potentially sensitive environment variables in other users processes. Since some programs pass passwords and other sensitive information in environment variables, this may aid a malicious user in further attacks.
Further details are unavailable at this time. This BID will be updated as further analysis is completed.
42. Papoo Multiple SQL Injection Vulnerabilities
BugTraq ID: 16020
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16020
Summary:
Papoo is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
These issues affect version 2.1.2; other versions may also be vulnerable.
43. Fortinet FortiGate URL Filtering Bypass Vulnerability
BugTraq ID: 16599
Remote: Yes
Last Updated: 2006-02-28
Relevant URL: http://www.securityfocus.com/bid/16599
Summary:
Fortinet FortiGate is prone to a vulnerability that could allow users to bypass the device's URL filtering.
FortiGate devices running FortiOS v2.8MR10 and v3beta are vulnerable to this issue. Other versions may also be affected.
44. PHPLIB Unspecified Code Execution Vulnerability
BugTraq ID: 16801
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16801
Summary:
PHPLIB is prone to an unspecified code-execution vulnerability.
Presumably, an attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
PHPLIB version 7.4 is vulnerable; other versions may also be affected.
45. PerlBlog Multiple Input Validation and Information Disclosure Vulnerabilities
BugTraq ID: 16707
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16707
Summary:
PerlBlog is prone to multiple input-validation and information-disclosure vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary attacker-supplied HTML and script code in the browser of a victim user, read arbitrary '.txt' files, and create arbitrary files on the affected computer all in the context of the webserver process.
Successful exploitation of these issues may allow an attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, to retrieve sensitive information, and to execute arbitrary script code in the context of the webserver process; other attacks are also possible.
46. XPDF Multiple Unspecified Vulnerabilities
BugTraq ID: 16748
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16748
Summary:
The 'xpdf' utility is reportedly prone to multiple unspecified security vulnerabilities. The cause and impact of these issues are currently unknown.
All versions of xpdf are considered vulnerable at the moment. This BID will update when more information becomes available.
47. SCO UnixWare Ptrace Local Privilege Escalation Vulnerability
BugTraq ID: 16765
Remote: No
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16765
Summary:
SCO UnixWare is prone to a local privilege-escalation vulnerability.
This issue allows local attackers to 'ptrace' privileged processes. Attackers may call arbitrary system calls, and then alter the behavior of the traced process, leading to a full system compromise.
SCO UnixWare 7.1.3 and 7.1.4 are vulnerable.
48. Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnerability
BugTraq ID: 11911
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/11911
Summary:
A remote buffer overflow reportedly affects the disk quota functionality of the Linux NFS utilities. This issue is due to the software's failure to properly validate the length of user-supplied strings before copying them into static process buffers.
An attacker may leverage this issue to execute arbitrary code on an affected computer with superuser privileges. This may be exploited to gain unauthorized access or privilege escalation.
49. Pentacle In-Out Board Multiple SQL Injection Vulnerabilities
BugTraq ID: 16818
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16818
Summary:
Pentacle In-Out Board is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
50. EZ Publish ImageCatalogue Cross-Site Scripting Vulnerability
BugTraq ID: 16817
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16817
Summary:
eZ Publish is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
51. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.
This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.
This may cause a denial-of-service condition.
**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.
52. TMSPublisher Search.CFM Cross-Site Scripting Vulnerability
BugTraq ID: 16816
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16816
Summary:
tmsPUBLISHER is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
53. MyPHPNuke Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16815
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16815
Summary:
MyPHPNuke is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
54. Cilem News Unspecified SQL Injection Vulnerability
BugTraq ID: 16813
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16813
Summary:
Cilem News is prone to an unspecified SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Very little information has been provided regarding this vulnerability; this BID will be updated when details become available.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Exploitation may also cause a denial-of-service condition.
55. Mambo Open Source Multiple SQL Injection Vulnerabilities
BugTraq ID: 16775
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16775
Summary:
Mambo is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
56. DEV Web Management System HTML Injection Vulnerability
BugTraq ID: 16812
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16812
Summary:
DEV Web Management System is prone to an HTML-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue is reported to affect version 1.5; other versions may also be vulnerable.
57. ArGoSoft Mail Server Pro IMAP Server Remote Directory Traversal Vulnerability
BugTraq ID: 16809
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16809
Summary:
The ArGoSoft Mail Server Pro IMAP service is susceptible to a remote directory-traversal vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.
This issue allows remote, authenticated attackers to create and possibly modify arbitrary files with the privileges of the server process. Since the server process requires elevated privileges to listen on the IMAP TCP port, attackers may likely be able to overwrite or modify any file with SYSTEM-level privileges.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
58. JGS-Gallery Module Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16810
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16810
Summary:
JGS-Gallery is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
59. ArGoSoft Mail Server Pro POP3 Server Remote Information Disclosure Vulnerability
BugTraq ID: 16808
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16808
Summary:
The ArGoSoft Mail Server Pro POP3 service is susceptible to a remote information-disclosure vulnerability. This issue is due to the application's failure to require authentication before allowing a command that discloses potentially sensitive information.
This issue allows remote, unauthenticated attackers to gain access to potentially sensitive configuration information. Information that the attacker harvests in this manner may then aid in further attacks.
Version 1.8.8.1 is vulnerable to this issue; other versions may also be affected.
60. PwsPHP Index.PHP SQL Injection Vulnerability
BugTraq ID: 16567
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16567
Summary:
PwsPHP is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue is reported to affect version 1.2.3; other versions may also be vulnerable.
61. Multiple Reamday Enterprises Products Multiple Variable Overwrite Vulnerabilities
BugTraq ID: 16665
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16665
Summary:
Multiple Reamday Enterprises products are prone to multiple vulnerabilities regarding the overwriting of application variables. These issues are due to a failure in the applications to properly initialize various application variables.
An attacker can exploit these issues to overwrite various application variables with attacker-supplied data. Successful exploitation may result in the attacker gaining administrative access to the vulnerable application.
62. StuffIt and ZipMagic Remote Directory Traversal Vulnerability
BugTraq ID: 16806
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16806
Summary:
Reportedly, an attacker can carry out attacks similar to directory traversals. These issues present themselves when the application processes malicious archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.
63. PHP PEAR::Archive_Tar Remote Directory Traversal Vulnerability
BugTraq ID: 16805
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16805
Summary:
Reportedly, an attacker can carry out directory traversal type attacks. These issues present themselves when the application processes malformed archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.
64. PHP Error Message Cross-Site Scripting Vulnerability
BugTraq ID: 16803
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16803
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploitation of this issue requires PHP to be configured with 'display_errors' and 'html_errors' enabled in the local site configuration.
65. Heimdal RSHD Local Privilege Escalation Vulnerability
BugTraq ID: 16524
Remote: No
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16524
Summary:
Heimdal 'rshd' is prone to a local privilege-escalation vulnerability.
A local attacker can gain ownership of a file by overwriting its credential cache. This may lead to various attacks, including privilege escalation.
Heimdal versions prior to 0.7.2 and 0.6.6 are vulnerable.
66. Heimdal TelnetD Denial Of Service Vulnerability
BugTraq ID: 16676
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16676
Summary:
Heimdal 'telnetd' is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause telnetd to crash, subsequently triggering 'inetd' to temporarily limit further telnetd requests, effectively denying service to legitimate users.
67. PostgreSQL Set Session Authorization Denial of Service Vulnerability
BugTraq ID: 16650
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16650
Summary:
PostgreSQL is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause a loss of service to other database users. Repeated attacks will result in a prolonged denial-of-service condition.
Successful exploitation of this issue requires that the application be compiled with 'Asserts' enabled; this is not the default setting.
68. 4images Index.PHP Remote File Include Vulnerability
BugTraq ID: 16855
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16855
Summary:
4images is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
69. Alt-N MDaemon IMAP Server Remote Format String Vulnerability
BugTraq ID: 16854
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16854
Summary:
Alt-N MDaemon IMAP Server is affected by a remote format-string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to its use in the format-specifier argument to a formatted printing function.
This vulnerability may be leveraged to consume excessive CPU resources or to crash the service. Due to the nature of this issue, it is likely that remote code execution may also be possible, although this has not been confirmed.
Alt-N MDaemon 8.1.1 is reported to be vulnerable. Other versions are likely affected as well.
70. Calcium EventText Cross-Site Scripting Vulnerability
BugTraq ID: 16851
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16851
Summary:
Calcium is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
71. MySQL Query Logging Bypass Vulnerability
BugTraq ID: 16850
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16850
Summary:
MySQL is susceptible to a query logging bypass vulnerability. This issue is due to a discrepency between the handling of NULL bytes in input data.
This issue allows attackers to bypass the query logging functionality of the database, so they can cause malicious SQL queries to be improperly logged. This may aid them in hiding the traces of malicious activity from administrators.
This issue affects MySQL version 5.0.18; other versions may also be affected.
72. DirectContact Directory Traversal Vulnerability
BugTraq ID: 16849
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16849
Summary:
DirectContact is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
73. Archangel Weblog Authentication Bypass Vulnerability
BugTraq ID: 16848
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16848
Summary:
Archangel Weblog is prone to an authentication bypass vulnerability. This issue is due to a failure in the application to properly validate user-supplied data.
An attacker can exploit this issue to bypass the authentication mechanism and gain access to the affected application as an administrative user. This may facilitate a compromise of the underlying system; other attacks are also possible.
74. iCal Calendar Text Cross-Site Scripting Vulnerability
BugTraq ID: 16845
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16845
Summary:
iCal is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
75. Oracle Diagnostics Multiple Vulnerabilities
BugTraq ID: 16844
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16844
Summary:
The Oracle Diagnostics module is susceptible to multiple vulnerabilities. These issues include insecure permissions vulnerabilities, and SQL injection vulnerabilities.
The first issue is an insecure permissions vulnerability. This may allow remote attackers to gain access to potentially sensitive information that may aid them in further attacks.
Multiple unspecified SQL injection issues are also present. Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Oracle has released the 'Diagnostics Support Pack February 2006' with 'Oracle Diagnostics 2.3 RUP A' to address these vulnerabilities. This update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Other issues may have also been addressed with these fixes. This BID will be updated as further information is disclosed.
76. Woltlab Burning Board Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16843
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16843
Summary:
Woltlab Burning Board is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.
77. Fantastic Scripts Fantastic News SQL Injection Vulnerability
BugTraq ID: 16842
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16842
Summary:
Fantastic News is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Fantastic News 2.1.1 is affected.
78. MTS Professional Open EMail Relay Vulnerability
BugTraq ID: 16840
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16840
Summary:
MTS Professional is susceptible to a remote open-email-relay vulnerability. This issue is due to the application failing to properly verify the source of emails when configured to forward emails.
This issue allows remote attackers to use vulnerable servers to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from a trusted mail server.
79. FreeBSD Remote NFS Mount Request Denial of Service Vulnerability
BugTraq ID: 16838
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16838
Summary:
FreeBSD is susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected kernels that potentially results in a crash when handling malformed NFS mount requests.
This issue allows remote attackers to cause affected kernels to crash, denying further network service to legitimate users.
80. Netgear WGT624 Wireless Firewall Router Information Disclosure Vulnerability
BugTraq ID: 16837
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16837
Summary:
A vulnerability has been reported in NetGear WGT624 Wireless Firewall Routers.
When configured to backup configuration settings, the device will store various information in cleartext. Accessing this file could allow an attacker to obtain sensitive information which could aid the attacker in compromising the web administration interface of the device.
It should be noted that the backup option is not enabled by default, but is a common feature used by administrators.
81. Lansuite Board Module SQL Injection Vulnerability
BugTraq ID: 16836
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16836
Summary:
Lansuite is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Lansuite 2.1.0 Beta is reportedly affected by this issue.
82. Netgear WGT624 Wireless Access Point Default Backdoor Account Vulnerability
BugTraq ID: 16835
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16835
Summary:
Netgear WGT624 reportedly contains a default administrative account. This issue can allow a remote attacker to gain administrative access to the device.
83. ArGoSoft Mail Server Pro Multiple HTML Injection Vulnerabilities
BugTraq ID: 16834
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16834
Summary:
ArGoSoft Mail Server Pro is prone to multiple HTML-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
ArGoSoft Mail Server Pro 1.8.8.5 and prior versions are vulnerable.
84. PHPRPC Library Remote Code Execution Vulnerability
BugTraq ID: 16833
Remote: Yes
Last Updated: 2006-02-27
Relevant URL: http://www.securityfocus.com/bid/16833
Summary:
phpRPC is prone to a remote code execution vulnerability. This issue exists because the library fails to adequately sanitize user-supplied data.
PHP scripts that implement the phpRPC library, such as RunCMS, may also be affected by this issue.
85. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-02-26
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.
Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.
Note that there are other attack vectors that may not require user interaction, since the application can be used with custom printing systems and web applications.
A successful attack may crash the application or lead to arbitrary code execution.
All versions of ImageMagick are considered vulnerable at the moment.
86. Noweb Insecure Temporary File Creation Vulnerability
BugTraq ID: 16610
Remote: No
Last Updated: 2006-02-26
Relevant URL: http://www.securityfocus.com/bid/16610
Summary:
Noweb creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
87. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
BugTraq ID: 15629
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/15629
Summary:
Perl is susceptible to a format-string vulnerability. This issue is due to the programming language's failure to properly handle format specifiers in formatted printing functions.
An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.
Developers should treat the formatted printing functions in Perl as equivalently vulnerable to exploitation as the C library versions, and should properly sanitize all data passed in the format specifier argument.
All applications that use formatted printing functions in an unsafe manner should be considered exploitable.
88. Gaim MSN Protocol Malformed Message Denial of Service Vulnerability
BugTraq ID: 13932
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/13932
Summary:
Gaim is affected by a denial of service vulnerability when handling malformed messages using the MSN protocol. This issue can allow remote attackers to cause an affected client to fail.
Gaim versions prior to 1.3.1 are reportedly affected by this vulnerability; other versions may also be affected.
89. Gaim Yahoo! Protocol Support File Download Denial of Service Vulnerability
BugTraq ID: 13931
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/13931
Summary:
Gaim is affected by a denial of service vulnerability during the download of a file using the Yahoo! protocol. This issue can allow remote attackers to cause an affected client to fail.
A vulnerability in the client manifests when it tries to download a file that contains non-ASCII characters in the filename.
Gaim versions prior to 1.3.1 are reportedly affected by this vulnerability; other versions may also be affected.
90. EKG Libgadu Multiple Memory Alignment Remote Denial of Service Vulnerabilities
BugTraq ID: 14415
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/14415
Summary:
EKG libgadu is susceptible to multiple remote denial of service vulnerabilities.
A malformed incoming message can trigger a bus error and lead to a crash.
It should be noted that these issues do not affect the application running on x86 architecture.
91. Gaim AIM/ICQ Protocols Multiple Vulnerabilities
BugTraq ID: 14531
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/14531
Summary:
Gaim is prone to multiple vulnerabilities affecting the AIM and ICQ protocols. These issues may allow remote attackers to trigger a buffer overflow or a denial-of-service condition.
All versions of Gaim 1.x are considered vulnerable at the moment.
92. Gaim Remote MSN Empty SLP Message Denial Of Service Vulnerability
BugTraq ID: 13591
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/13591
Summary:
Gaim is susceptible to a remote denial of service vulnerability in its MSN protocol handling code.
This vulnerability allows remote attackers to crash affected clients, denying service to them.
Gaim versions prior to 1.3.0 are vulnerable to this issue.
93. Gaim Remote URI Handling Buffer Overflow Vulnerability
BugTraq ID: 13590
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/13590
Summary:
Gaim is susceptible to a remote buffer overflow vulnerability when handling long URIs. This issue is due to a failure of the application to properly bounds check user-supplied input data prior to copying it to a fixed-size stack buffer.
Due to the multiple protocol support of Gaim, and the nature of the differing IM protocols, only some of the IM networks are reported vulnerable. This is due to message length limits imposed by the IM networks. Currently, the Jabber, and SILC IM network protocols are known to be vulnerable. Other protocols may also be affected.
This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application.
Gaim versions prior to 1.3.0 are vulnerable to this issue.
94. Gaim Jabber File Request Remote Denial Of Service Vulnerability
BugTraq ID: 13004
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/13004
Summary:
Gaim is reported prone to a remote denial of service vulnerability. The issue manifests when the Gaim client handles an unspecified Jabber file transfer request, triggering an out-of-bounds read operation.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
This vulnerability is reported to affect Gaim version 1.2.0 and previous versions.
95. POPFile Denial Of Service Vulnerability
BugTraq ID: 16792
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16792
Summary:
A denial-of-service vulnerability has been reported in POPFile.
A remote attacker may cause a denial-of-service condition in the application, effectively halting service to legitimate users.
96. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
BugTraq ID: 16802
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16802
Summary:
Crypt::CBC is susceptible to a weak ciphertext vulnerability. This issue is due to a flaw in its creation of IVs (Initialization Vectors) for ciphers with a blocksize larger than 8.
This issue results in the creation of ciphertext that contains bytes encrypted with a constant null IV. This ciphertext is prone to differential cryptanalysis, aiding attackers in compromising the plaintext of encrypted data.
The level of difficulty attackers may face trying to exploit this flaw is currently unknown, but data encrypted with vulnerable versions of Crypt::CBC should be considered insecure.
Crypt::CBC versions prior to 2.17 are vulnerable to this issue if they use the 'RandomIV' header style.
97. Winace Remote Directory Traversal Vulnerability
BugTraq ID: 16800
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16800
Summary:
Reportedly, an attacker can carry out directory-traversal attacks. These issues present themselves when the application processes malformed archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.
98. PHPX XCode Tag HTML Injection Vulnerability
BugTraq ID: 16799
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16799
Summary:
PHPX is prone to an HTML-injection vulnerability. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
PHPX version 3.5.9 is vulnerable; other versions may also be affected.
99. PHP 5 User-Supplied Session ID Input Validation Vulnerability
BugTraq ID: 16220
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16220
Summary:
PHP 5 is prone to an input-validation vulnerability. This is due to a lack of proper sanitization of user-supplied input of PHP session IDs, transmitted by way of HTTP headers.
An attacker may use this vulnerability to perform HTTP response splitting, often resulting in content spoofing and cross-site scripting attacks.
PHP 5 version 5.1.1 and prior are affected.
100. D3Jeeb Multiple SQL Injection Vulnerabilities
BugTraq ID: 16853
Remote: Yes
Last Updated: 2006-02-25
Relevant URL: http://www.securityfocus.com/bid/16853
Summary:
D3Jeeb is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Triple threat to Mac OS X largely academic
By: Robert Lemos
Two worms and an exploit for Apple's operating system hardly threaten consumers' computers, but should act as a wake-up call for Mac users.
http://www.securityfocus.com/news/11378
2. Private identities become a corporate focus
By: Robert Lemos
Technology companies at the RSA Security Conference expound on the privacy benefits of online services that authenticate users based on the least amount of information possible.
http://www.securityfocus.com/news/11377
3. Startup tries to spin a safer Web
By: Robert Lemos
Armed with client-side honeypots and a low-cost team in India, a group of MIT graduates aims to create a system to warn Web surfers about the seedier sites, and outright malicious servers, on the Internet.
http://www.securityfocus.com/news/11376
4. Apple's in the eye of flaw finders
By: Robert Lemos
With the move to Intel processors and a larger share of the market, Apple's Mac OS X could find itself a more popular target of attack, security professionals say.
http://www.securityfocus.com/news/11375
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/426309
2. [SJ-JOB] Security System Administrator, Tampa
http://www.securityfocus.com/archive/77/426310
3. [SJ-JOB] Information Assurance Engineer, BWI Area
http://www.securityfocus.com/archive/77/426312
4. [SJ-JOB] Compliance Officer, Surrey - Flexible Locations ie. client sites
http://www.securityfocus.com/archive/77/426307
5. [SJ-JOB] Sr. Product Manager, Northern
http://www.securityfocus.com/archive/77/426308
6. [SJ-JOB] CHECK Team Leader, Surrey
http://www.securityfocus.com/archive/77/426269
7. [SJ-JOB] Database Security Engineer, Riyad
http://www.securityfocus.com/archive/77/426268
8. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/426271
9. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/426270
10. [SJ-JOB] Security Consultant, Tampa
http://www.securityfocus.com/archive/77/426254
11. [SJ-JOB] Director of Privacy and Security, Louisville
http://www.securityfocus.com/archive/77/426253
12. [SJ-JOB] Security Engineer, Framingham
http://www.securityfocus.com/archive/77/426263
13. [SJ-JOB] Sales Engineer, Oxford
http://www.securityfocus.com/archive/77/426255
14. [SJ-JOB] Security Consultant, Amsterdam
http://www.securityfocus.com/archive/77/426256
15. [SJ-JOB] Technical Marketing Engineer, Redwood City
http://www.securityfocus.com/archive/77/426238
16. [SJ-JOB] Database Security Engineer, Kolkata
http://www.securityfocus.com/archive/77/426239
17. [SJ-JOB] Database Security Architect, Redmond
http://www.securityfocus.com/archive/77/426233
18. [SJ-JOB] Information Assurance Analyst, Linthicum
http://www.securityfocus.com/archive/77/426235
19. [SJ-JOB] Training / Awareness Specialist, Washington, DC
http://www.securityfocus.com/archive/77/426236
20. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/426201
21. [SJ-JOB] Security Engineer, Alviso/Silicon Valley
http://www.securityfocus.com/archive/77/426199
22. [SJ-JOB] Security Engineer, Brooklyn (Metrotech)
http://www.securityfocus.com/archive/77/426203
23. [SJ-JOB] Sales Engineer, Abingdon, Oxfordshire
http://www.securityfocus.com/archive/77/426219
24. [SJ-JOB] Technical Marketing Engineer, Redwood City
http://www.securityfocus.com/archive/77/426202
25. [SJ-JOB] Security Engineer, Palo Alto
http://www.securityfocus.com/archive/77/425976
26. [SJ-JOB] Sr. Security Engineer, Irvine
http://www.securityfocus.com/archive/77/425995
27. [SJ-JOB] Sales Engineer, Fort Lauderdale
http://www.securityfocus.com/archive/77/425977
28. [SJ-JOB] Security Engineer, Houston
http://www.securityfocus.com/archive/77/426038
29. [SJ-JOB] Security Engineer, Dallas
http://www.securityfocus.com/archive/77/426011
30. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/425787
31. [SJ-JOB] Security Engineer, Salt lake City
http://www.securityfocus.com/archive/77/425773
32. [SJ-JOB] Security Consultant, Bangalore,Delhi,Mumbai,Chennai,Hyderabad
http://www.securityfocus.com/archive/77/425774
33. [SJ-JOB] Security Engineer, Highland Ranch
http://www.securityfocus.com/archive/77/425847
34. [SJ-JOB] Auditor, Denver
http://www.securityfocus.com/archive/77/425856
35. [SJ-JOB] Security Architect, Beverly
http://www.securityfocus.com/archive/77/425719
36. [SJ-JOB] Security Product Marketing Manager, Northern
http://www.securityfocus.com/archive/77/425665
37. [SJ-JOB] Security Product Manager, Northern
http://www.securityfocus.com/archive/77/425725
38. [SJ-JOB] Security Consultant, Cambridge
http://www.securityfocus.com/archive/77/425658
39. [SJ-JOB] Security Consultant, Riyad
http://www.securityfocus.com/archive/77/425659
40. [SJ-JOB] CSO, Calgary
http://www.securityfocus.com/archive/77/425729
41. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/425654
42. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/425655
43. [SJ-JOB] Application Security Architect, Riyadh
http://www.securityfocus.com/archive/77/425656
44. [SJ-JOB] Auditor, San Antonio
http://www.securityfocus.com/archive/77/425660
45. [SJ-JOB] Sr. Product Manager, Calabasas/LA Area
http://www.securityfocus.com/archive/77/425652
46. [SJ-JOB] Sr. Security Engineer, Sterling
http://www.securityfocus.com/archive/77/425663
47. [SJ-JOB] Director, Information Security, London or Bournmouth
http://www.securityfocus.com/archive/77/425643
48. [SJ-JOB] Developer, Superior
http://www.securityfocus.com/archive/77/425649
49. [SJ-JOB] Quality Assurance, Superior
http://www.securityfocus.com/archive/77/425640
50. [SJ-JOB] Manager, Information Security, Manhattan
http://www.securityfocus.com/archive/77/425636
51. [SJ-JOB] Chief Scientist, Chambersburg
http://www.securityfocus.com/archive/77/425634
52. [SJ-JOB] Sales Representative, ALEXANDRIA
http://www.securityfocus.com/archive/77/425635
53. [SJ-JOB] Manager, Information Security, Manhattan
http://www.securityfocus.com/archive/77/425632
V. INCIDENTS LIST SUMMARY
---------------------------
1. Strange Traffic to ports 139 and 137 from a machine with no data
http://www.securityfocus.com/archive/75/426352
2. announcement: reporting and mitigating botnets
http://www.securityfocus.com/archive/75/426018
3. How to determine which PHP-script allows spamming?
http://www.securityfocus.com/archive/75/426022
4. Increase in MS-SQL Probes
http://www.securityfocus.com/archive/75/425899
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. DEF CON 14 is now in effect! The Call for Papers is open.
http://www.securityfocus.com/archive/82/425896
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Domain policy getting override on local
http://www.securityfocus.com/archive/88/425884
2. SecurityFocus Microsoft Newsletter #279
http://www.securityfocus.com/archive/88/425748
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!"- SPI Dynamics White Paper It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000C543