SecurityFocus Newsletter #341

Peter Laborge <[email protected]> Wed, 15 Mar 2006 17:01:31 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #341
----------------------------------------

ALERT: "How a Hacker Launches a SQL Injection Attack!" - SPI Dynamics White Paper
It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000C543

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Human rights and wrongs online
        2. Social engineering reloaded
II.   BUGTRAQ SUMMARY
        1. Microsoft Excel Malformed Formula Size Remote Code Execution Vulnerability
        2. Microsoft Excel Malformed Graphic File Code Execution Vulnerability
        3. SafeDisc Secdrv.SYS Local Privilege Escalation Vulnerability
        4. BomberClone Error Messages Buffer Overflow Vulnerability
        5. Flex Code Generation Buffer Overflow Vulnerability
        6. WordPress Multiple Cross-Site Scripting Vulnerabilities
        7. CGI.pm Start_Form Cross-Site Scripting Vulnerability
        8. AbiWord Stack-Based Buffer Overflow Vulnerabilities
        9. GNU Tar Invalid Headers Buffer Overflow Vulnerability
        10. GuppY Dwnld.PHP Remote Directory Traversal Vulnerability
        11. AbiWord RTF File Processing Buffer Overflow Vulnerability
        12. DSCounter Index.PHP SQL Injection Vulnerability
        13. DSNewsletter Multiple SQL Injection Vulnerabilities
        14. sa-exim Unauthorized File Access Vulnerability
        15. Linux Kernel IP ID Information Disclosure Weakness
        16. CyBoards PHP Lite Post.PHP SQL Injection Vulnerability
        17. Macromedia Flash Multiple Unspecified Security Vulnerabilities
        18. Unalz Hostile Destination Path Vulnerability
        19. Drupal Multiple Input Validation Vulnerabilities
        20. DSPoll PollID SQL Injection Vulnerability
        21. Simple PHP Blog Install05.PHP Local File Include Vulnerability
        22. CGI::Session Multiple Information Disclosure Vulnerabilities
        23. MyBB Multiple Input Validation Vulnerabilities
        24. GGZ Gaming Zone Multiple Denial Of Service Vulnerabilities
        25. Gemini Createissue.ASPX HTML Injection Vulnerability
        26. Core News Index.PHP Remote Code Execution Vulnerability
        27. Microsoft Excel Unspecified Memory Corruption Vulnerabilities
        28. Microsoft Excel Malformed Record Remote Code Execution Vulnerability
        29. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
        30. PHP File Upload GLOBAL Variable Overwrite Vulnerability
        31. PHP Parse_Str Register_Globals Activation Weakness
        32. Apache Log4Net Denial Of Service Vulnerability
        33. PHP PHPInfo Cross-Site Scripting Vulnerability
        34. WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
        35. WebCalendar Export_Handler.PHP File Corruption Vulnerability
        36. WebCalendar Multiple SQL Injection Vulnerabilities
        37. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
        38. Microsoft Windows Telephony Service Buffer Overflow Vulnerability
        39. CrossFire SetUp Remote Buffer Overflow Vulnerability
        40. PHP Apache 2 Local Denial of Service Vulnerability
        41. PHP Open_BaseDir Security Restriction Bypass Vulnerability
        42. @1 File Store Multiple Input Validation Vulnerabilities
        43. Apple Mac OS X Mail Message Attachment Remote Buffer Overflow Vulnerability
        44. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
        45. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
        46. Mozilla Firefox Large History File Buffer Overflow Vulnerability
        47. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
        48. Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
        49. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        50. W3C Libwww Multiple Vulnerabilities
        51. PCRE Regular Expression Heap Overflow Vulnerability
        52. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
        53. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
        54. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        55. Microsoft Excel Malformed Range Memory Corruption Vulnerability
        56. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        57. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        58. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
        59. PHPsysInfo Multiple Input Validation Vulnerabilities
        60. FUDForum Tree View Access Validation Vulnerability
        61. CrossFire Denial Of Service Vulnerability
        62. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
        63. Lurker Multiple Input Validation Vulnerabilities
        64. XPDF Multiple Unspecified Vulnerabilities
        65. ENet Multiple Denial of Service Vulnerabilities
        66. Linux Kernel sys_mbind System Call Local Denial of Service Vulnerability
        67. IBM Tivoli Lightweight Client Framework Information Disclosure Vulnerability
        68. Bugzilla Internal Error Cross-Site Scripting Vulnerability
        69. Ubuntu Linux Local Installation Password Disclosure Vulnerability
        70. PHPSysInfo Multiple Cross-Site Scripting Vulnerabilities
        71. Zlib Compression Library Buffer Overflow Vulnerability
        72. Linux Kernel Security Key Functions Local Copy_To_User Race Vulnerability
        73. Zlib Compression Library Decompression Buffer Overflow Vulnerability
        74. ASP Portal Multiple Input Validation Vulnerabilities
        75. Adobe Graphics Server / Document Server Remote Command Execution Vulnerability
        76. Apple Mac OS X Archive Metadata Command Execution Vulnerability
        77. Safari Archive JavaScript Same Origin Policy Violation Vulnerability
        78. Linux Kernel NFS Client Denial of Service Vulnerability
        79. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
        80. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
        81. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
        82. Linux Kernel XFS File System Local Information Disclosure Vulnerability
        83. Bugzilla Authentication Information Disclosure Vulnerability
        84. Bugzilla Hidden Product Information Disclosure Vulnerability
        85. Firebird Local Inet_Server Buffer Overflow Vulnerability
        86. OpenSSH GSSAPI Credential Disclosure Vulnerability
        87. OpenSSL Insecure Protocol Negotiation Weakness
        88. Vegas Forum Forumlib.PHP SQL Injection Vulnerability
        89. Lynx NNTP Article Header Buffer Overflow Vulnerability
        90. WMNews Multiple Cross-Site Scripting Vulnerabilities
        91. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
        92. Freeciv Remote Denial Of Service Vulnerability
        93. DirectContact Directory Traversal Vulnerability
        94. Metamail Message Processing Remote Buffer Overflow Vulnerability
        95. Sauerbraten Multiple Remote Vulnerabilities
        96. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
        97. Zeroboard Multiple HTML Injection Vulnerabilities
        98. vCard Create.PHP Multiple Cross-Site Scripting Vulnerabilities
        99. Jupiter CMS BBCode HTML Injection Vulnerability
        100. Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
III.  SECURITYFOCUS NEWS
        1. Virus names likely a lost cause
        2. Antivirus groups fight over Crossover sharing
        3. Triple threat to Mac OS X largely academic
        4. Private identities become a corporate focus
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Application Security Architect, New York
        2. [SJ-JOB] Security Architect, Crystal City
        3. [SJ-JOB] Certification & Accreditation Engineer, Crystal City
        4. [SJ-JOB] Security Consultant, Baltimore
        5. [SJ-JOB] Security Auditor, Baltimore
        6. [SJ-JOB] Auditor, Baltimore
        7. [SJ-JOB] Security Consultant, Atlanta
        8. [SJ-JOB] Management, Crystal City
        9. [SJ-JOB] Database Security Architect, Irvine
        10. [SJ-JOB] Security Researcher, North London
        11. [SJ-JOB] Security Auditor, Atlanta
        12. [SJ-JOB] Management, Crystal City
        13. [SJ-JOB] Disaster Recovery Coordinator, Hartford
        14. [SJ-JOB] Security Consultant, Miami
        15. [SJ-JOB] Security Auditor, Miami
        16. [SJ-JOB] Auditor, Atlanta
        17. [SJ-JOB] Security Director, Calgary
        18. [SJ-JOB] Forensics Engineer, London
        19. [SJ-JOB] Account Manager, New York
        20. [SJ-JOB] Forensics Engineer, London
        21. [SJ-JOB] Auditor, Miami
        22. [SJ-JOB] Developer, Redwood City
        23. [SJ-JOB] Security Consultant, Miami
        24. [SJ-JOB] Security System Administrator, Tampa
        25. [SJ-JOB] Instructor, Atlanta
        26. [SJ-JOB] Security Engineer, Los Angeles
        27. [SJ-JOB] Security System Administrator, Tampa
        28. [SJ-JOB] Security Engineer, Bangalore
        29. [SJ-JOB] Security Auditor, Columbus
        30. [SJ-JOB] Security Consultant, Columbus
        31. [SJ-JOB] Auditor, Columbus
        32. [SJ-JOB] Account Manager, Orlando
        33. [SJ-JOB] Account Manager, Virtual Position
        34. [SJ-JOB] Security Consultant, Washington
        35. [SJ-JOB] Security Auditor, Washington
        36. [SJ-JOB] Auditor, Washington
        37. [SJ-JOB] Sales Engineer, New York
        38. [SJ-JOB] Sales Engineer, New York
        39. [SJ-JOB] Sales Engineer, Reston
        40. [SJ-JOB] Security Consultant, Detroit
        41. [SJ-JOB] Security Auditor, Detroit
        42. [SJ-JOB] Channel / Business Development, Northern, NJ
        43. [SJ-JOB] Sales Engineer, Boston
        44. [SJ-JOB] Technology Risk Consultant, Ottawa
        45. [SJ-JOB] Security Consultant, New York
        46. [SJ-JOB] Auditor, Detroit
        47. [SJ-JOB] Sales Engineer, Reston
        48. [SJ-JOB] Sales Engineer, Reston
        49. [SJ-JOB] Security Auditor, New York
        50. [SJ-JOB] Security Consultant, Los Angeles
        51. [SJ-JOB] Auditor, New York
        52. [SJ-JOB] Account Manager, Chicago
        53. [SJ-JOB] Security System Administrator, Walnut Creek
        54. [SJ-JOB] Security Auditor, Los Angeles
        55. [SJ-JOB] Auditor, Los Angeles
        56. [SJ-JOB] Security Consultant, San Francisco
V.    INCIDENTS LIST SUMMARY
        1. good list of live CDs
        2. Possible AIM Hack?
        3. A pretty neat Chase Phish
        4. Interesting information about SSH scans
        5. Scans for telnetd on DNS servers.
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Adobe Form Designer Overflow
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. trouble using SSL on WSUS
        2. New Sasser variant on the loose? Anyone else?
        3. Automate group membership validation
        4. FW: user logon script context....
        5. SecurityFocus Microsoft Newsletter #281
        6. AW: user logon script context....
        7. user logon script context....
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Human rights and wrongs online
By Mark Rasch
A government's position on censorship used to protect its citizenry is dictated by who they are. The well-popularized censorship of Internet content in China by Google and other big players, and criticism of this by the U.S. government, is really just the tip of the iceburg.
http://www.securityfocus.com/columnists/392

2. Social engineering reloaded
By Sarah Granger
The purpose of this article is to go beyond the basics and explore how social engineering, employed as technology, has evolved over the past few years. A case study of a typical Fortune 1000 company will be discussed, putting emphasis on the importance of education about social engineering for every corporate security program.
http://www.securityfocus.com/infocus/1860


II.  BUGTRAQ SUMMARY
--------------------
1. Microsoft Excel Malformed Formula Size Remote Code Execution Vulnerability
BugTraq ID: 17108
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17108
Summary:
Microsoft Excel is prone to a remote code execution vulnerability.  This issue may be triggered when an Excel document with a malformed formula size is opened.

2. Microsoft Excel Malformed Graphic File Code Execution Vulnerability
BugTraq ID: 16181
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16181
Summary:
Microsoft Excel is susceptible to a code execution vulnerability. The issue presents itself when Microsoft Excel attempts to process malformed or corrupted XLS files.

Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application.

3. SafeDisc Secdrv.SYS Local Privilege Escalation Vulnerability
BugTraq ID: 17070
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17070
Summary:

SafeDisc is prone to a local privilege-escalation vulnerability. This issue is due to the failure of the application to restrict access to the configuration parameters of an installed service.


This vulnerability allows local attackers to execute arbitrary malicious code with SYSTEM-level privileges, facilitating the complete compromise of affected computers.

4. BomberClone Error Messages Buffer Overflow Vulnerability
BugTraq ID: 16697
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16697
Summary:

BomberClone is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to perform proper boundary checks on user-supplied data before storing it in a finite sized buffer.

This issue may be exploited to execute arbitrary code in the context of the user who is running the application.

Version 0.11.6.2 is vulnerable; other versions may also be affected.

5. Flex Code Generation Buffer Overflow Vulnerability
BugTraq ID: 16896
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16896
Summary:
Flex is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in finite-sized memory buffers.

An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. This may facilitate a compromise of the underlying computer.

Flex versions 2.5.31 and prior are vulnerable.

6. WordPress Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17069
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17069
Summary:

WordPress is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

7. CGI.pm Start_Form Cross-Site Scripting Vulnerability
BugTraq ID: 8231
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/8231
Summary:
CGI.pm is prone to cross-site scripting attacks under some circumstances. This issue occurs because the 'start_form()' function (or other functions that use this function) does not sufficiently sanitize HTML and script code when a form action isn't specified. This could expose scripts that use the function to cross-site scripting attacks.

8. AbiWord Stack-Based Buffer Overflow Vulnerabilities
BugTraq ID: 15096
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/15096
Summary:
AbiWord is susceptible to multiple stack-based buffer-overflow vulnerabilities; fixes are available. These issues are due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer while importing RTF files.

These issues likely allow attackers to execute arbitrary machine code in the context of the user running the affected application.

Though similar to the vulnerability described in BID 14971 (AbiWord RTF File Processing Buffer Overflow Vulnerability), these vulnerabilities constitute a separate issue.

9. GNU Tar Invalid Headers Buffer Overflow Vulnerability
BugTraq ID: 16764
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16764
Summary:

GNU Tar is prone to a buffer overflow when handling invalid headers. Successful exploitation could potentially lead to arbitrary code execution, but this has not been confirmed.

Tar versions 1.14 and above are vulnerable.

10. GuppY Dwnld.PHP Remote Directory Traversal Vulnerability
BugTraq ID: 17068
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17068
Summary:
GuppY is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to corrupt files on a computer in the context of the webserver process. A successful exploit may result in a denial-of-service condition if sensitive files are corrupted.

11. AbiWord RTF File Processing Buffer Overflow Vulnerability
BugTraq ID: 14971
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/14971
Summary:
AbiWord is susceptible to a buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer while importing RTF files.

This issue likely allows attackers to execute arbitrary machine code in the context of the user running the affected application.

12. DSCounter Index.PHP SQL Injection Vulnerability
BugTraq ID: 17112
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17112
Summary:
DSCounter is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

13. DSNewsletter Multiple SQL Injection Vulnerabilities
BugTraq ID: 17111
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17111
Summary:
DSNewsletter is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

14. sa-exim Unauthorized File Access Vulnerability
BugTraq ID: 17110
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17110
Summary:
sa-exim is prone to an unauthorized file-access vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to delete arbitrary files in the context of the user running the affected application.

15. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is susceptible to a remote information disclosure weakness. This issue is due to an implementation flaw of a zero IP ID information disclosure countermeasure.

This issue allows remote attackers to utilize affected computers in stealth network port and trust scans.

The Linux kernel 2.6 series, as well as some kernels in the 2.4 series are affected by this weakness.

16. CyBoards PHP Lite Post.PHP SQL Injection Vulnerability
BugTraq ID: 17107
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17107
Summary:
CyBoards PHP Lite is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

17. Macromedia Flash Multiple Unspecified Security Vulnerabilities
BugTraq ID: 17106
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17106
Summary:
The Macromedia Flash plug-in is susceptible to multiple unspecified vulnerabilities.

An attacker can potentially exploit these vulnerabilities to execute arbitrary code.  The most likely vector of attack is through a malicious SWF file designed to trigger the vulnerability that has been placed on a website. A denial of service condition may arise from attack attempts as well.

Versions of the Flash Player prior to 7.0.63.0 and 8.0.24.0 are vulnerable to these issues.

18. Unalz Hostile Destination Path Vulnerability
BugTraq ID: 17105
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17105
Summary:
unalz contains a vulnerability in the handling of pathnames for archived files.

By specifying a path for an archived item that points outside the expected destination directory, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem, possibly including paths containing system binaries and other sensitive or confidential information.

It is conjectured that an attacker could use this to create or overwrite binaries in any desired location, using the privileges of the invoking user.

version 0.53 is vulnerable; other versions may also be affected.

19. Drupal Multiple Input Validation Vulnerabilities
BugTraq ID: 17104
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17104
Summary:

Drupal is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site, disclose sensitive information, hijack user sessions and utilize a vulnerable Drupal installation as an email relay.

20. DSPoll PollID SQL Injection Vulnerability
BugTraq ID: 17103
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17103
Summary:

DSPoll is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

21. Simple PHP Blog Install05.PHP Local File Include Vulnerability
BugTraq ID: 17102
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17102
Summary:
Simple PHP Blog is prone to a local file-include vulnerability. This may facilitate the unauthorized viewing of files and unauthorized execution of local scripts.

Version 0.4.7.1 and prior are vulnerable; other versions may be affected as well.

22. CGI::Session Multiple Information Disclosure Vulnerabilities
BugTraq ID: 17099
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17099
Summary:
CGI::Session is prone to multiple information-disclosure vulnerabilities. These issues are due to a failure in the application to properly set file permissions.

An attacker can exploit these issues to retrieve the session data of an arbitrary user.

If an administrative user's credentials are retrieved, successful exploitation may result in the compromise of the affected application; other attacks are also possible.

23. MyBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17097
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17097
Summary:
MyBB is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may facilitate the theft of cookie-based authentication credentials, allow the attacker to control how the site is rendered to the user, or misrepresent how HTML content is cache, served or interpreted; other attacks are also possible.

24. GGZ Gaming Zone Multiple Denial Of Service Vulnerabilities
BugTraq ID: 17094
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17094
Summary:
GGZ Gaming Zone is prone to multiple remote denial-of-service vulnerabilities. These issues are due to improper input sanitization.

An attacker may cause the victim's connection to the server to terminate, causing a denial of service to legitimate users.

25. Gemini Createissue.ASPX HTML Injection Vulnerability
BugTraq ID: 17092
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17092
Summary:
Gemini is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

26. Core News Index.PHP Remote Code Execution Vulnerability
BugTraq ID: 17067
Remote: Yes
Last Updated: 2006-03-13
Relevant URL: http://www.securityfocus.com/bid/17067
Summary:
Core News is prone to a code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Core News version 2.0.1. is vulnerable; other versions may also be affected.

27. Microsoft Excel Unspecified Memory Corruption Vulnerabilities
BugTraq ID: 15926
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15926
Summary:
Microsoft Excel is susceptible to two unspecified memory corruption vulnerabilities. The issues present themselves when Microsoft Excel attempts to process malformed or corrupted XLS files.

Attackers may exploit these issues to crash the affected application. The possibility to execute arbitrary machine code through these issues has not currently been ruled out.

This BID will be updated, and potentially split into separate records as further information is disclosed.

UPDATE:(Mar 14, 2006):Microsoft has released security advisory MS06-012 addressing this and other issues.

28. Microsoft Excel Malformed Record Remote Code Execution Vulnerability
BugTraq ID: 17101
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17101
Summary:
Microsoft Excel is prone to a remote code execution vulnerability.  This issue may be triggered when a Excel document with malformed record data is opened.

29. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 17000
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17000
Summary:

Microsoft Office is prone to a remote buffer overflow vulnerability.

This vulnerability presents itself when a specially crafted document is handled by the application.

A successful attack can result in a remote compromise in the context of an affected user.

30. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.

By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

31. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to reenable the 'register_globals' directive. This issue is due to the application's failure to handle a memory-limit exception.

The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the process's life. If PHP is being run as a CGI process, this issue is not likely exploitable.

By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

32. Apache Log4Net Denial Of Service Vulnerability
BugTraq ID: 17095
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17095
Summary:
Log4net is prone to a remote denial-of-service vulnerability.

An attacker may cause the application to crash, thus denying service to legitimate users.

33. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

34. WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
BugTraq ID: 15673
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15673
Summary:
WebCalendar is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.

WebCalendar 1.0.1 is vulnerable; other versions may also be affected.

35. WebCalendar Export_Handler.PHP File Corruption Vulnerability
BugTraq ID: 15608
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15608
Summary:
WebCalendar is prone to a file corruption vulnerability. This is due to a lack of proper validation of user-supplied input.

An attacker may leverage this issue to corrupt files with the privileges of an unsuspecting user running a vulnerable version of the affected application.

Version 1.0.1 is reported to be vulnerable; other versions may also be affected.

36. WebCalendar Multiple SQL Injection Vulnerabilities
BugTraq ID: 15606
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15606
Summary:
WebCalendar is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

WebCalendar version 1.0.1 is reported to be vulnerable; other versions may also be affected.

37. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
BugTraq ID: 15358
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15358
Summary:
PHP is prone to a denial-of-service vulnerability.

This issue occurs when parsing EXIF image data in corrupt JPEG files.

An attacker can exploit this vulnerability to crash the system, effectively denying service to legitimate users.

38. Microsoft Windows Telephony Service Buffer Overflow Vulnerability
BugTraq ID: 14518
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14518
Summary:
Microsoft Windows Telephony Service is prone to a buffer overflow vulnerability.  This issue is due to a failure in the application to perform proper bounds checking on user-supplied data.

A successful attack can result in overflowing a finite sized buffer and ultimately leading to arbitrary code execution in the context of the affected service.  This may allow the attacker to execute arbitrary code remotely or locally to gain elevated privileges.

Remote code execution is only possible on Windows 2000 Server and Windows Server 2003; other vulnerable platforms the attacker must have local interactive access.

39. CrossFire SetUp Remote Buffer Overflow Vulnerability
BugTraq ID: 17093
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17093
Summary:

CrossFire is prone to a remote buffer-overflow vulnerability. This can facilitate a remote compromise due to arbitrary code execution.

CrossFire 1.9.0 and prior versions are vulnerable.

40. PHP Apache 2 Local Denial of Service Vulnerability
BugTraq ID: 15177
Remote: No
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15177
Summary:
PHP is prone to a local denial-of-service vulnerability when it is used as an Apache 2 module.

Reports indicate that due to a bug in the apache2handler SAPI (of the 'sapi_apache2.c' file), this issue triggers a segmentation fault and leads to a crash in the server.

This issue affects PHP versions prior to 5.1.0 final and 4.4.1 final.

41. PHP Open_BaseDir Security Restriction Bypass Vulnerability
BugTraq ID: 14957
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14957
Summary:
PHP is prone to a vulnerability regarding the unauthorized access to directories outside the base directory.

The problem presents itself in the way PHP handles the 'open_basedir' directive.

Successful exploitation will grant an attacker access to directories outside the designated base directory. As a result, the attacker may access possibly privileged information.

This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.

42. @1 File Store Multiple Input Validation Vulnerabilities
BugTraq ID: 17090
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17090
Summary:

@1 File Store is prone to multiple input-validation vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.

A successful exploit could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

43. Apple Mac OS X Mail Message Attachment Remote Buffer Overflow Vulnerability
BugTraq ID: 17081
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17081
Summary:
Mac OS X Mail is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.

An attacker can exploit this issue to execute arbitrary attacker-supplied code in the context of Mail. A successful exploit may facilitate a compromise of the underlying computer.

This issue is present in Apple Mail when 'Security Update 2006-001' is applied.

44. Ethereal GTP Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 16076
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16076
Summary:
The Ethereal GTP protocol dissector is prone to a remotely exploitable denial-of-service vulnerability.

Successful exploitation will cause a denial-of-service condition in the Ethereal application.

Further details are not currently available. This BID will be updated as more information is disclosed.

45. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

46. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.

This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.

This may cause a denial-of-service condition.

**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.

47. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
BugTraq ID: 15179
Remote: No
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15179
Summary:
Fetchmail is susceptible to an information-disclosure vulnerability. This issue is due to a race condition in the 'fetchmailconf' configuration utility.

This issue allows local attackers to gain access to potentially sensitive information, including email authentication credentials, aiding them in further attacks.

Versions of Fetchmail prior to 6.2.9-rc6 include a vulnerable version of 'fetchmailconf'. Versions of 'fetchmailconf' prior to 1.43.2 and 1.49 are vulnerable.

48. Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
BugTraq ID: 15102
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15102
Summary:
GNU wget and cURL are prone to a buffer overflow vulnerability.  This issue is due to a failure in the applications to do proper bounds checking on user supplied data before using it in a memory copy operation.

An attacker can exploit this vulnerability to execute arbitrary code in the context of the user utilizing the vulnerable application.

Exploitation of this vulnerability requires that NTLM authentication is enabled in the affected clients.

49. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The following are vulnerable:

- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier

50. W3C Libwww Multiple Vulnerabilities
BugTraq ID: 15035
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15035
Summary:
W3C Libwww is prone to multiple vulnerabilities.

These issues include a buffer overflow vulnerability and some issues related to the handling of multipart/byteranges content.

Libwww 5.4.0 is reported to be vulnerable.  Other versions may be affected as well.  These issues may also be exploited through other applications that implement the library.

51. PCRE Regular Expression Heap Overflow Vulnerability
BugTraq ID: 14620
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14620
Summary:
PCRE is prone to a heap-overflow vulnerability. This issue is due to the library's failure to properly perform boundary checks on user-supplied input before copying data to an internal memory buffer.

The impact of successful exploitation of this vulnerability depends on the application and the user credentials using the vulnerable library. A successful attack may ultimately permit an attacker to control the contents of critical memory control structures and write arbitrary data to arbitrary memory locations.

52. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 15219
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15219
Summary:
The Ethereal IRC protocol dissector is prone to a remotely exploitable denial-of-service vulnerability.

An attacker may exploit this issue by causing Ethereal to process a malformed packet. Successful exploitation will cause a denial-of-service condition in the Ethereal application.

Further details are not currently available. This BID will be updated as more information is disclosed.

53. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15794
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15794
Summary:
A remote buffer-overflow vulnerability affects Ethereal. This issue is due to the application's failure to securely copy network-derived data into sensitive process buffers. The specific issue occurs in the OSPF dissector.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

54. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

55. Microsoft Excel Malformed Range Memory Corruption Vulnerability
BugTraq ID: 15780
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15780
Summary:
An unspecified vulnerability has been reported to exist in Microsoft Excel.  The vulnerability was announced on eBay.  The discoverer was offering to sell the vulnerability details until the auction was terminated by eBay.  According to the auction description, it is possible to have a large value passed to "msvcrt.memmove()" through data fields in an Excel .xls file.  The discoverer has claimed that code execution is possible.

This entry will be updated as more details become available.

**UPDATE (Dec 9, 2005): Microsoft has confirmed that this vulnerability exists.  See eWeek link in reference section.  The original listing on eBay has been pulled.

**UPDATE (Mar 14, 2006): Microsoft has released security advisory MS06-012 addressing this and other issues. This issue is occurs when handling an excel file with a malformed range and can be exploited to execute code.

56. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:

The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

57. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

58. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
BugTraq ID: 17058
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17058
Summary:

GnuPG is prone to a vulnerability involving incorrect verification of non-detached signatures.

A successful attack can allow an attacker to simply take a signed message and inject arbitrary data into it and bypass verification.

Note that this issue also affects verification of signatures embedded in encrypted messages. Scripts and applications using gpg are affected, as are applications using the GPGME library.

GnuPG versions prior to 1.4.2.2 are vulnerable to this issue.

59. PHPsysInfo Multiple Input Validation Vulnerabilities
BugTraq ID: 15414
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/15414
Summary:
phpSysinfo is prone to multiple input validation vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.

phpSysinfo is prone to a local file include vulnerability, an HTTP response splitting vulnerability, and cross-site scripting attacks.

An attacker may exploit these vulnerabilities to access files within the context of the Web server application, poison Web proxy server caches, and execute arbitrary HTML and script code within the context of the victim's Web browser.

Other attacks are also possible.

It should be noted that the cross-site scripting issues are not exploitable on Debian systems.

60. FUDForum Tree View Access Validation Vulnerability
BugTraq ID: 14556
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14556
Summary:
FUDforum is prone to an access validation vulnerability.  This issue is due to a failure in the application to perform proper access validation before granting access to private forums.

An attacker can exploit this vulnerability to obtain posts from private forums.  This may result in a loss of confidentiality.  Information obtained may also be used in further attacks.

This issue is reported to affect FUDforum version 2.6.15; earlier versions may also be vulnerable.

It should be noted this issue is only possible if the 'Tree View' feature is enabled.

61. CrossFire Denial Of Service Vulnerability
BugTraq ID: 16883
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16883
Summary:


CrossFire is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to cause the application to crash by activating the 'oldsocketmode' option, and then sending an overly large request to the server application.

An attacker may cause the application to crash, thus denying service to legitimate users; remote code execution may also be possible.

62. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
BugTraq ID: 16710
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16710
Summary:
Libapreq2 is prone to a vulnerability that may allow attackers to trigger a denial-of-service condition.


Libapreq2 versions prior to 2.0.7 are vulnerable.

63. Lurker Multiple Input Validation Vulnerabilities
BugTraq ID: 17003
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17003
Summary:
Lurker is prone to multiple input-validation vulnerabilities. These issues are due to failures in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to retrieve arbitrary files, overwrite arbitrary files, and have arbitrary script code executed in the browser of an unsuspecting user, all in the context of the affected site. This may facilitate a compromise of the application and the theft of cookie-based authentication credentials as well as other attacks.

64. XPDF Multiple Unspecified Vulnerabilities
BugTraq ID: 16748
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16748
Summary:

The 'xpdf' utility is reportedly prone to multiple unspecified security vulnerabilities. The cause and impact of these issues are currently unknown.

All versions of xpdf are considered vulnerable at the moment. This BID will update when more information becomes available.

65. ENet Multiple Denial of Service Vulnerabilities
BugTraq ID: 17087
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17087
Summary:
ENet is prone to multiple denial-of-service vulnerabilities. A remote attacker can send specifically crafted data to trigger these flaws, leading to a denial-of-service condition.

66. Linux Kernel sys_mbind System Call Local Denial of Service Vulnerability
BugTraq ID: 16924
Remote: No
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/16924
Summary:
The Linux kernel 'sys_mbind' system call is prone to a local denial-of-service vulnerability. This issue is due to a lack of proper input sanitization in the system call's arguments.

This issue allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.15.5.

67. IBM Tivoli Lightweight Client Framework Information Disclosure Vulnerability
BugTraq ID: 17085
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17085
Summary:
Tivoli LCF is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to view sensitive files with elevated privileges. Information obtained may aid in further attacks.

68. Bugzilla Internal Error Cross-Site Scripting Vulnerability
BugTraq ID: 12154
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/12154
Summary:
Bugzilla is prone to a cross-site scripting vulnerability. The issue is exposed when the software renders internal errors that include user-supplied input.

An attacker may exploit this issue by enticing a user to follow a link that will cause hostile HTML and script code to be rendered in an internal error page. Exploitation may allow an attacker to steal cookie-based authentication credentials or to mount other attacks.

69. Ubuntu Linux Local Installation Password Disclosure Vulnerability
BugTraq ID: 17086
Remote: No
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17086
Summary:
Ubuntu Linux is susceptible to a local password-disclosure vulnerability. This issue is due to the installation system improperly storing cleartext passwords in world-readable files.

This issue allows local attackers to gain access to the user account that was created during the initial installation of Ubuntu. Since this user is granted 'sudo' access to the superuser account, this potentially allows local attackers to completely compromise affected computers.

70. PHPSysInfo Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 12887
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/12887
Summary:
phpSysInfo is reportedly affected by multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

71. Zlib Compression Library Buffer Overflow Vulnerability
BugTraq ID: 14162
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14162
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the application's failure to properly validate input data before using it in a memory copy operation.

In certain circumstances, malformed input data during decompression may result in a memory buffer being overflowed. This may result in denial-of-service conditions or may allow remote code to execute in the context of applications that use the affected library.

72. Linux Kernel Security Key Functions Local Copy_To_User Race Vulnerability
BugTraq ID: 17084
Remote: No
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17084
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability in its security-key functionality. This issue is due to a race condition that allows attackers to modify an argument of a copy operation after is has been validated, but before it is used.

This vulnerability allows local attackers to crash the kernel, denying service to legitimate users. It may also allow attackers to read portions of kernel memory, and thus gain access to potentially sensitive information. This may aid them in further attacks.

73. Zlib Compression Library Decompression Buffer Overflow Vulnerability
BugTraq ID: 14340
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/14340
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the library's failure to properly handle unexpected input to its decompression routines.

Certain values used during decompression are incorrectly specified, allowing invalid inflate input to corrupt memory.

This vulnerability allows attackers to crash applications that use the affected library. This could also potentially allow for arbitrary code execution in the context of an affected application.

74. ASP Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 17114
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17114
Summary:
ASP Portal is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

75. Adobe Graphics Server / Document Server Remote Command Execution Vulnerability
BugTraq ID: 17113
Remote: Yes
Last Updated: 2006-03-15
Relevant URL: http://www.securityfocus.com/bid/17113
Summary:


Adobe Graphics Server and Document Server are prone to a vulnerability that may allow remote attackers to disclose arbitrary graphics or PDF files, place arbitrary graphics or PDF files on a server, and potentially execute arbitrary code and gain unauthorized access to a computer.


The code execution is triggered when a user interactively logs into the Adobe Server service account. Adobe Server is installed as SYSTEM by default, which can allow this vulnerability to be triggered when anyone logs into the server interactively.  The server may also be configured to run with lower privileges.

Adobe Graphics Server 2.0, 2.1 and Adobe Document Server 5.0, 6.0 running on Windows are affected.

76. Apple Mac OS X Archive Metadata Command Execution Vulnerability
BugTraq ID: 16736
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16736
Summary:
Apple Mac OS X is prone to an arbitrary command-execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file.

Attackers can reportedly use Safari and Apple Mail as exploitation vectors for this vulnerability.

Mac OS X 10.4.5 is reported to be vulnerable. Earlier versions may also be affected.

77. Safari Archive JavaScript Same Origin Policy Violation Vulnerability
BugTraq ID: 17082
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17082
Summary:
Apple Safari is susceptible to a same-origin policy violation. This issue is due to the application's failure to properly enforce same-origin policy for JavaScript remote data access.

An attacker may create a malicious webpage that can access the properties of another domain. This may lead to disclosure of sensitive information or may facilitate other attacks against a user of the browser.

78. Linux Kernel NFS Client Denial of Service Vulnerability
BugTraq ID: 16922
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16922
Summary:
Linux kernel NFS client is prone to a denial-of-service vulnerability. An unprivileged local user can panic the NFS client and cause it to fail.

This issue was addressed in Linux kernel 2.6.15.5; earlier versions are vulnerable.

79. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
BugTraq ID: 16993
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16993
Summary:

The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error and arises in the 'die_if_kernel()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.15.6 running on Itanium systems.

80. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
BugTraq ID: 16925
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16925
Summary:

Linux kernel is prone to a denial-of-service vulnerability when processing a malformed ELF file. This issue occurs only on Intel EM64T processors.

Linux kernel versions prior to 2.6.15.5 are affected by this issue.

81. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
BugTraq ID: 17078
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17078
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

This vulnerability affects the ATM module and allows local users to panic the kernel by creating inconsistent reference counts, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.14.

82. Linux Kernel XFS File System Local Information Disclosure Vulnerability
BugTraq ID: 16921
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16921
Summary:
The Linux kernel's XFS filesystem is susceptible to a local information-disclosure vulnerablity. This issue is due to a flaw in the filesystem that may result in previously written data being returned to local users.

This issue allows local malicious users to gain access to potentially sensitive data, aiding them in further attacks.

Linux kernel versions prior to 2.6.15.5 are affected by this issue.

83. Bugzilla Authentication Information Disclosure Vulnerability
BugTraq ID: 13605
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/13605
Summary:
Bugzilla is prone to a vulnerability that could allow username and password information to be disclosed in generated links. Any user with access to the server's web logs could potentially gain access to the user's authentication information.

84. Bugzilla Hidden Product Information Disclosure Vulnerability
BugTraq ID: 13606
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/13606
Summary:
Bugzilla is prone to an information-disclosure vulnerability due to improper access validation. This could allow a user to determine the existence of a product in the Bugzilla database even if it should not be visible to them.

85. Firebird Local Inet_Server Buffer Overflow Vulnerability
BugTraq ID: 17077
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17077
Summary:
Firebird is susceptible to a local buffer-overflow vulnerability. This issue is due to the application's failure to properly check boundaries of user-supplied command-line argument data before copying it to an insufficiently sized memory buffer.

Attackers may exploit this issue to execute arbitrary machine code with elevated privileges, because the affected binaries are often installed with setuid privileges.

86. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability.

Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user employs authentication methods other than GSSAPI to connect, which is not usually expected.

This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use the credentials to access resources granted to the original principal.

This issue affects versions of OpenSSH prior to 4.2.

87. OpenSSL Insecure Protocol Negotiation Weakness
BugTraq ID: 15071
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/15071
Summary:
OpenSSL is susceptible to a remote protocol-negotiation weakness. This issue is due to the implementation of the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option to maintain compatibility with third-party software.

This issue presents itself when two peers try to negotiate the protocol they wish to communicate with. Attackers who can intercept and modify the SSL communications may exploit this weakness to force SSL version 2 to be chosen.

The attacker may then exploit various insecurities in SSL version 2 to gain access to or tamper with the cleartext communications between the targeted client and server.

Note that the 'SSL_OP_MSIE_SSLV2_RSA_PADDING' option is enabled with the frequently used 'SSL_OP_ALL' option.

SSL peers that are configured to disallow SSL version 2 are not affected by this issue.

88. Vegas Forum Forumlib.PHP SQL Injection Vulnerability
BugTraq ID: 17079
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17079
Summary:
Vegas Forum is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

89. Lynx NNTP Article Header Buffer Overflow Vulnerability
BugTraq ID: 15117
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/15117
Summary:
Lynx is prone to a buffer overflow when handling NNTP article headers.

This issue may be exploited when the browser handles NNTP content, such as through 'news:' or 'nntp:' URIs.  Successful exploitation will result in code execution in the context of the program user.

90. WMNews Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17076
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17076
Summary:

WMNews is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

91. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
BugTraq ID: 16802
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16802
Summary:
Crypt::CBC is susceptible to a weak ciphertext vulnerability. This issue is due to a flaw in its creation of IVs (Initialization Vectors) for ciphers with a blocksize larger than 8.

This issue results in the creation of ciphertext that contains bytes encrypted with a constant null IV. This ciphertext is prone to differential cryptanalysis, aiding attackers in compromising the plaintext of encrypted data.

The level of difficulty attackers may face trying to exploit this flaw is currently unknown, but data encrypted with vulnerable versions of Crypt::CBC should be considered insecure.

Crypt::CBC versions prior to 2.17 are vulnerable to this issue if they use the 'RandomIV' header style.

92. Freeciv Remote Denial Of Service Vulnerability
BugTraq ID: 16975
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16975
Summary:
The Freeciv game server is reported prone to a remote denial-of-service vulnerability.

A remote attacker may exploit this issue to deny service for legitimate users.

93. DirectContact Directory Traversal Vulnerability
BugTraq ID: 16849
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16849
Summary:
DirectContact is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

94. Metamail Message Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 16611
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16611
Summary:

Metamail is prone to a remote buffer-overflow vulnerability.

This issue arises when the application handles messages with large string values for boundaries.

This can cause memory corruption and trigger a crash in the application. This issue may also lead to arbitrary code execution, but this is unconfirmed.

Metamail 2.7 is reportedly vulnerable, but other versions may be affected as well.

95. Sauerbraten Multiple Remote Vulnerabilities
BugTraq ID: 16986
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16986
Summary:

Sauerbraten is susceptible to multiple remote vulnerabilities:

- A buffer-overflow issue that affects both clients and servers.
- An invalid memory-access, denial-of-service issue that affects both clients and servers.
- An invalid memory-access, denial-of-service issue that affects servers.
- An invalid map-file-processing, denial-of-service issue that affects clients.

These issues allow remote attackers to execute arbitrary machine code in the context of an affected application. Attackers may also crash both clients and servers, denying service to legitimate users.

96. SquirrelMail Multiple Cross-Site Scripting and IMAP Injection Vulnerabilities
BugTraq ID: 16756
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/16756
Summary:
SquirrelMail is susceptible to multiple cross-site scripting and IMAP-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.

An attacker may leverage any of the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

An attacker may leverage the IMAP-injection issue to execute arbitrary IMAP commands on the configured IMAP server. This may aid attackers in further attacks and allow them to exploit latent vulnerabilities in the IMAP server.

97. Zeroboard Multiple HTML Injection Vulnerabilities
BugTraq ID: 17075
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17075
Summary:
Zeroboard is prone to HTML-injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

98. vCard Create.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17073
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17073
Summary:
vCard is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

99. Jupiter CMS BBCode HTML Injection Vulnerability
BugTraq ID: 17072
Remote: Yes
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17072
Summary:
Jupiter CMS is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

100. Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
BugTraq ID: 17071
Remote: No
Last Updated: 2006-03-14
Relevant URL: http://www.securityfocus.com/bid/17071
Summary:

AntiVir Personal Edition Classic is prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to launch other applications with SYSTEM privileges. This may facilitate a complete compromise of the affected computer.

AntiVir Personal Edition Classic version 7 is vulnerable; other versions may also be affected.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Virus names likely a lost cause
By: Robert Lemos
The Common Malware Enumeration Project clears up confusion for responders, but racing to name the latest virus in the media will continue to be the norm.
http://www.securityfocus.com/news/11380

2. Antivirus groups fight over Crossover sharing
By: Robert Lemos
A young antivirus group's attempts to leverage a rare exclusive virus discovery into greater membership has earned it criticism from the old guard of antivirus companies.
http://www.securityfocus.com/news/11379

3. Triple threat to Mac OS X largely academic
By: Robert Lemos
Two worms and an exploit for Apple's operating system hardly threaten consumers' computers, but should act as a wake-up call for Mac users.
http://www.securityfocus.com/news/11378

4. Private identities become a corporate focus
By: Robert Lemos
Technology companies at the RSA Security Conference expound on the privacy benefits of online services that authenticate users based on the least amount of information possible.
http://www.securityfocus.com/news/11377

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Application Security Architect, New York
http://www.securityfocus.com/archive/77/427735

2. [SJ-JOB] Security Architect, Crystal City
http://www.securityfocus.com/archive/77/427736

3. [SJ-JOB] Certification & Accreditation Engineer, Crystal City
http://www.securityfocus.com/archive/77/427738

4. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/427734

5. [SJ-JOB] Security Auditor, Baltimore
http://www.securityfocus.com/archive/77/427733

6. [SJ-JOB] Auditor, Baltimore
http://www.securityfocus.com/archive/77/427665

7. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/427664

8. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/427646

9. [SJ-JOB] Database Security Architect, Irvine
http://www.securityfocus.com/archive/77/427647

10. [SJ-JOB] Security Researcher, North London
http://www.securityfocus.com/archive/77/427639

11. [SJ-JOB] Security Auditor, Atlanta
http://www.securityfocus.com/archive/77/427644

12. [SJ-JOB] Management, Crystal City
http://www.securityfocus.com/archive/77/427630

13. [SJ-JOB] Disaster Recovery Coordinator, Hartford
http://www.securityfocus.com/archive/77/427629

14. [SJ-JOB] Security Consultant, Miami
http://www.securityfocus.com/archive/77/427626

15. [SJ-JOB] Security Auditor, Miami
http://www.securityfocus.com/archive/77/427627

16. [SJ-JOB] Auditor, Atlanta
http://www.securityfocus.com/archive/77/427628

17. [SJ-JOB] Security Director, Calgary
http://www.securityfocus.com/archive/77/427544

18. [SJ-JOB] Forensics Engineer, London
http://www.securityfocus.com/archive/77/427543

19. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/427541

20. [SJ-JOB] Forensics Engineer, London
http://www.securityfocus.com/archive/77/427542

21. [SJ-JOB] Auditor, Miami
http://www.securityfocus.com/archive/77/427540

22. [SJ-JOB] Developer, Redwood City
http://www.securityfocus.com/archive/77/427531

23. [SJ-JOB] Security Consultant, Miami
http://www.securityfocus.com/archive/77/427532

24. [SJ-JOB] Security System Administrator, Tampa
http://www.securityfocus.com/archive/77/427530

25. [SJ-JOB] Instructor, Atlanta
http://www.securityfocus.com/archive/77/427533

26. [SJ-JOB] Security Engineer, Los Angeles
http://www.securityfocus.com/archive/77/427526

27. [SJ-JOB] Security System Administrator, Tampa
http://www.securityfocus.com/archive/77/427527

28. [SJ-JOB] Security Engineer, Bangalore
http://www.securityfocus.com/archive/77/427528

29. [SJ-JOB] Security Auditor, Columbus
http://www.securityfocus.com/archive/77/427523

30. [SJ-JOB] Security Consultant, Columbus
http://www.securityfocus.com/archive/77/427525

31. [SJ-JOB] Auditor, Columbus
http://www.securityfocus.com/archive/77/427524

32. [SJ-JOB] Account Manager, Orlando
http://www.securityfocus.com/archive/77/427486

33. [SJ-JOB] Account Manager, Virtual Position
http://www.securityfocus.com/archive/77/427485

34. [SJ-JOB] Security Consultant, Washington
http://www.securityfocus.com/archive/77/427482

35. [SJ-JOB] Security Auditor, Washington
http://www.securityfocus.com/archive/77/427484

36. [SJ-JOB] Auditor, Washington
http://www.securityfocus.com/archive/77/427483

37. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/427221

38. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/427219

39. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/427220

40. [SJ-JOB] Security Consultant, Detroit
http://www.securityfocus.com/archive/77/427217

41. [SJ-JOB] Security Auditor, Detroit
http://www.securityfocus.com/archive/77/427218

42. [SJ-JOB] Channel / Business Development, Northern, NJ
http://www.securityfocus.com/archive/77/427227

43. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/427228

44. [SJ-JOB] Technology Risk Consultant, Ottawa
http://www.securityfocus.com/archive/77/427224

45. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/427225

46. [SJ-JOB] Auditor, Detroit
http://www.securityfocus.com/archive/77/427226

47. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/427202

48. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/427206

49. [SJ-JOB] Security Auditor, New York
http://www.securityfocus.com/archive/77/427200

50. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/427199

51. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/427201

52. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/427178

53. [SJ-JOB] Security System Administrator, Walnut Creek
http://www.securityfocus.com/archive/77/427177

54. [SJ-JOB] Security Auditor, Los Angeles
http://www.securityfocus.com/archive/77/427176

55. [SJ-JOB] Auditor, Los Angeles
http://www.securityfocus.com/archive/77/427180

56. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/427172

V.   INCIDENTS LIST SUMMARY
---------------------------
1. good list of live CDs
http://www.securityfocus.com/archive/75/427719

2. Possible AIM Hack?
http://www.securityfocus.com/archive/75/427599

3. A pretty neat Chase Phish
http://www.securityfocus.com/archive/75/427489

4. Interesting information about SSH scans
http://www.securityfocus.com/archive/75/427123

5. Scans for telnetd on DNS servers.
http://www.securityfocus.com/archive/75/426781

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Adobe Form Designer Overflow
http://www.securityfocus.com/archive/82/427491

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. trouble using SSL on WSUS
http://www.securityfocus.com/archive/88/427610

2. New Sasser variant on the loose? Anyone else?
http://www.securityfocus.com/archive/88/427492

3. Automate group membership validation
http://www.securityfocus.com/archive/88/427290

4. FW: user logon script context....
http://www.securityfocus.com/archive/88/427243

5. SecurityFocus Microsoft Newsletter #281
http://www.securityfocus.com/archive/88/427144

6. AW: user logon script context....
http://www.securityfocus.com/archive/88/427140

7. user logon script context....
http://www.securityfocus.com/archive/88/427134

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
ALERT: "How a Hacker Launches a SQL Injection Attack!" - SPI Dynamics White Paper
It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000C543