SecurityFocus Newsletter #342

Peter Laborge <[email protected]> Tue, 21 Mar 2006 17:06:39 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #342
----------------------------------------

This Issue is Sponsored By: Lancope

"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."

http://www.lancope.com/resource/

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Encryption for the masses
        2. Social engineering reloaded
II.   BUGTRAQ SUMMARY
        1. ASP Portal Multiple SQL Injection Vulnerabilities
        2. Macromedia Flash Multiple Unspecified Security Vulnerabilities
        3. Sylpheed LDIF Import Remote Buffer Overflow Vulnerability
        4. PHPMyAdmin Set_Theme Cross-Site Scripting Vulnerability
        5. Metamail Message Processing Remote Buffer Overflow Vulnerability
        6. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
        7. Heimdal RSHD Local Privilege Escalation Vulnerability
        8. PEAR::Auth Multiple Unspecified SQL Injection Vulnerabilities
        9. Apache HTTP Request Smuggling Vulnerability
        10. Apache CGI Byterange Request Denial of Service Vulnerability
        11. PCRE Regular Expression Heap Overflow Vulnerability
        12. NetPBM PNMToPNG Long Text Line Buffer Overflow Vulnerability
        13. Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
        14. Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
        15. Monotone MT File Arbitrary Code Execution Vulnerability
        16. Inprotect Zones.PHP Cross-Site Scripting Vulnerability
        17. BorderWare MXtreme Web Administration Unspecified Remote Vulnerability
        18. Novell Netware FTP Server Denial Of Service Vulnerability
        19. Wzdftpd SITE Command Arbitrary Command Execution Vulnerability
        20. Drupal Multiple Input Validation Vulnerabilities
        21. Skype Technologies Skype Networking Routine Heap Overflow Vulnerability
        22. Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
        23. PHPSysInfo Multiple Cross-Site Scripting Vulnerabilities
        24. Oxynews Index.PHP SQL Injection Vulnerability
        25. SPIP Research Module Cross-Site Scripting Vulnerability
        26. D2-Shoutbox SQL Injection Vulnerability
        27. Util-VServer Unknown Linux Capabilities Vulnerability
        28. Libcgi-session-perl Multiple Insecure Temporary File Creation Vulnerabilities
        29. cURL / libcURL TFTP URL Parser Buffer Overflow Vulnerability
        30. RunIt CHPST Privilege Escalation Vulnerability
        31. Novell SSL Server Multiple Vulnerabilities
        32. Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
        33. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
        34. Linux Kernel Netfilter Do_Replace Remote Buffer Overflow Vulnerability
        35. Tenes Empanadas Graciela Remote Denial Of Service Vulnerability
        36. F5 Firepass 4100 SSL VPN Cross-Site Scripting Vulnerability
        37. Linux VServer Project CHRoot Breakout Vulnerability
        38. Virtual Communication Services VPMi Service_Requests.ASP Cross-Site Scripting Vulnerability
        39. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
        40. Peercast.org PeerCast Remote Buffer Overflow Vulnerability
        41. Zlib Compression Library Decompression Buffer Overflow Vulnerability
        42. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
        43. X.Org X Window Server Local Privilege Escalation Vulnerability
        44. Verisign MPKI 6.0 Haydn.EXE Cross-Site Scripting Vulnerability
        45. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
        46. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
        47. Linux Kernel Raw_sendmsg() Kernel Memory Access Vulnerability
        48. gCards Multiple Input Validation Vulnerabilities
        49. BEA WebLogic Server Remote Denial Of Service Vulnerability
        50. BEA WebLogic Portal JSR-168 Portlets Information Disclosure Vulnerability
        51. BEA WebLogic Server Remote Filesystem Access Vulnerability
        52. BEA WebLogic Server and WebLogic Express HTTP Response Splitting Vulnerability
        53. WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
        54. BEA WebLogic Multiple Vulnerabilities
        55. ProFTPD SQLShowInfo SQL Output Format String Vulnerability
        56. ProFTPD Shutdown Message Format String Vulnerability
        57. MERCUR Messaging 2005 IMAP Remote Buffer Overflow Vulnerability
        58. MailEnable Unspecified POP Authentication Bypass Vulnerability
        59. MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
        60. SoftBB Reg.PHP SQL Injection Vulnerability
        61. Avast! Antivirus Local Insecure Permissions Vulnerability
        62. Maian Weblog Multiple SQL Injection Vulnerabilities
        63. Jabber Studio JabberD Remote Denial Of Service Vulnerability
        64. Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
        65. Skull-Splitter Download Counter for Wallpapers Count.PHP SQL Injection Vulnerability
        66. Todd Miller Sudo Local Privilege Escalation Vulnerability
        67. Streber Unspecified HTML Injection Vulnerability
        68. WinHKI Remote Directory Traversal Vulnerability
        69. CutePHP CuteNews Function.PHP Local File Include Vulnerability
        70. Noah's Classifieds Index.PHP Multiple Cross-Site Scripting Vulnerabilities
        71. Light Weight Calendar Cal.PHP Remote Command Execution Vulnerability
        72. Skull-Splitter PHP Guestbook HTML Injection Vulnerability
        73. PHPWebSite Multiple SQL Injection Vulnerabilities
        74. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
        75. Apache Log4Net Denial Of Service Vulnerability
        76. CrossFire SetUp Remote Buffer Overflow Vulnerability
        77. IlohaMail Email Message Remote HTML Injection Vulnerability
        78. Mail-Audit Insecure Temporary File Creation Vulnerability
        79. MusicBox Multiple Input Validation Vulnerabilities
        80. BetaParticle Blog Multiple SQL Injection Vulnerabilities
        81. Woltlab Burning Board Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
        82. ExtCalendar Cross-Site Scripting Vulnerabilities
        83. KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
        84. Multiple Web Browser International Domain Name Handling Site Property Spoofing Vulnerabilities
        85. HP-UX Usermod Local Unauthorized Access Vulnerability
        86. KDE Kate, KWrite Local Backup File Information Disclosure Vulnerability
        87. Invision Power Board Multiple Cross-Site Scripting Vulnerabilities
        88. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        89. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        90. XPDF Loca Table Verification Remote Denial of Service Vulnerability
        91. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        92. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        93. Libungif Null Pointer Dereference Denial of Service Vulnerability
        94. Freeciv Remote Denial Of Service Vulnerability
        95. Libungif Colormap Handling Memory Corruption Vulnerability
        96. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
        97. GDK-Pixbuf XPM Images Integer Overflow Vulnerability
        98. Veritas Backup Exec Media Server BEngine Service Job Log Remote Format String Vulnerability
        99. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
        100. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
III.  SECURITYFOCUS NEWS
        1. Debit-card fraud underscores legal loopholes
        2. Virus names likely a lost cause
        3. Antivirus groups fight over Crossover sharing
        4. Triple threat to Mac OS X largely academic
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Developer, Superior
        2. [SJ-JOB] Quality Assurance, Superior
        3. [SJ-JOB] Sr. Security Analyst, Bangalore
        4. [SJ-JOB] Security Engineer, Commack
        5. [SJ-JOB] Manager, Information Security, New York
        6. [SJ-JOB] Auditor, INDIANAPOLIS
        7. [SJ-JOB] Sales Engineer, Washington DC
        8. [SJ-JOB] Security Engineer, Providence
        9. [SJ-JOB] Sr. Security Engineer, Richland
        10. [SJ-JOB] Security Engineer, Chicago
        11. [SJ-JOB] Developer, Santa Clara
        12. [SJ-JOB] CHECK Team Leader, London
        13. [SJ-JOB] Security Product Marketing Manager, Ft Lauderdale
        14. [SJ-JOB] Security Engineer, Ft Lauderdale
        15. [SJ-JOB] Sr. Security Engineer, Tempe
        16. [SJ-JOB] Sales Engineer, San Francisco Bay Area
        17. [SJ-JOB] Developer, Consulting Position
        18. [SJ-JOB] Application Security Engineer, Jacksonville
        19. [SJ-JOB] Sr. Security Analyst, London
        20. [SJ-JOB] Quality Assurance, Bangalore
        21. [SJ-JOB] Threat Analyst, Wilimngton
        22. [SJ-JOB] Sales Engineer, DC area
        23. [SJ-JOB] Application Security Engineer, Milpitas
        24. [SJ-JOB] Application Security Architect, Milpitas
        25. [SJ-JOB] Sr. Security Engineer, Milpitas
        26. [SJ-JOB] Application Security Engineer, Milpitas
        27. [SJ-JOB] Application Security Engineer, Milpitas
        28. [SJ-JOB] Security Consultant, Chicago
        29. [SJ-JOB] Technical Marketing Engineer, Ann Arbor
        30. [SJ-JOB] Auditor, Dallas
        31. [SJ-JOB] Security Auditor, Chicago
        32. [SJ-JOB] Auditor, Chicago
        33. [SJ-JOB] Security Consultant, Raleigh
        34. [SJ-JOB] Security Consultant, San Francisco
        35. [SJ-JOB] VP of Regional Sales, San Francisco and East Coast
        36. [SJ-JOB] Security Auditor, Dallas
        37. [SJ-JOB] Sales Representative, San Francisco
        38. [SJ-JOB] Security Consultant, Dallas
        39. [SJ-JOB] Sr. Product Manager, Crystal City
        40. [SJ-JOB] Sales Engineer, San Francisco
        41. [SJ-JOB] Application Security Engineer, Crystal City
        42. [SJ-JOB] Security Auditor, Raleigh
        43. [SJ-JOB] Auditor, Raleigh
        44. [SJ-JOB] Developer, San Francisco
        45. [SJ-JOB] Developer, San Francisco
        46. [SJ-JOB] Quality Assurance, San Francisco
        47. [SJ-JOB] Security Consultant, Philadelphia
        48. [SJ-JOB] Security Auditor, Philadelphia
        49. [SJ-JOB] Security Engineer, Crystal City
        50. [SJ-JOB] Auditor, Crystal City
        51. [SJ-JOB] Threat Analyst, Crystal City
        52. [SJ-JOB] Auditor, Philadelphia
        53. [SJ-JOB] Security Consultant, Richmond
        54. [SJ-JOB] Sales Representative, New York
        55. [SJ-JOB] Security Researcher, Atlanta
        56. [SJ-JOB] Information Assurance Analyst, Crystal City
        57. [SJ-JOB] Forensics Engineer, Crystal City
        58. [SJ-JOB] Auditor, Richmond
        59. [SJ-JOB] Security Auditor, Richmond
        60. [SJ-JOB] Application Security Architect, New York
        61. [SJ-JOB] Security Architect, Crystal City
        62. [SJ-JOB] Certification & Accreditation Engineer, Crystal City
        63. [SJ-JOB] Security Consultant, Baltimore
        64. [SJ-JOB] Security Auditor, Baltimore
        65. [SJ-JOB] Auditor, Baltimore
        66. [SJ-JOB] Security Consultant, Atlanta
V.    INCIDENTS LIST SUMMARY
        1. SSH Scans
        2. New Phishing Technique?
        3. unicast netbios name service nbtstat query to/from same ip?
        4. Possible AIM Hack? - Follow-up
        5. good list of live CDs
        6. Possible AIM Hack?
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. debugging seh overwrite
        2. HTTP proxy/redirector to a unique virtual host ....
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. virtual memory protection using AWE
        2. SecurityFocus Microsoft Newsletter #282
        3. Moderation in moderation
        4. EFS disaster!
        5. trouble using SSL on WSUS
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. Libnids
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Encryption for the masses
By Kelly Martin
File and disk encryption needs to be simple and easy if it's going to be used. This article looks at Apple's FileVault and takes a sneak peak at what's coming in Windows Vista.
http://www.securityfocus.com/columnists/393

2. Social engineering reloaded
By Sarah Granger
The purpose of this article is to go beyond the basics and explore how social engineering, employed as technology, has evolved over the past few years. A case study of a typical Fortune 1000 company will be discussed, putting emphasis on the importance of education about social engineering for every corporate security program.
http://www.securityfocus.com/infocus/1860


II.  BUGTRAQ SUMMARY
--------------------
1. ASP Portal Multiple SQL Injection Vulnerabilities
BugTraq ID: 17174
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17174
Summary:
ASP Portal is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Some of these issues may require administrative privileges to exploit.

2. Macromedia Flash Multiple Unspecified Security Vulnerabilities
BugTraq ID: 17106
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17106
Summary:
The Macromedia Flash plug-in is susceptible to multiple unspecified vulnerabilities.

An attacker can potentially exploit these vulnerabilities to execute arbitrary code. The most likely vector of attack is through a malicious SWF file that has been designed to trigger the vulnerability and has been placed on a website. A denial-of-service condition may also occur.

Versions of the Flash Player prior to 7.0.63.0 and 8.0.24.0 are vulnerable to these issues.

3. Sylpheed LDIF Import Remote Buffer Overflow Vulnerability
BugTraq ID: 15363
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15363
Summary:
Sylpheed is prone to a buffer-overflow vulnerability.

A buffer overflow can occur when an unsuspecting user imports a malicious LFID file into an address book.

Exploitation of this vulnerability may allow an attacker to gain unauthorized access to the computer in the context of the Sylpheed client.

4. PHPMyAdmin Set_Theme Cross-Site Scripting Vulnerability
BugTraq ID: 17142
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17142
Summary:
phpMyAdmin is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

5. Metamail Message Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 16611
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16611
Summary:

Metamail is prone to a remote buffer-overflow vulnerability.

This issue arises when the application handles messages with large string values for boundaries.

This can cause memory corruption and trigger a crash in the application. This issue may also lead to arbitrary code execution, but this is unconfirmed.

Metamail 2.7 is reportedly vulnerable, but other versions may be affected as well.

6. Lincoln D. Stein Crypt::CBC Perl Module Weak Ciphertext Vulnerability
BugTraq ID: 16802
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16802
Summary:
Crypt::CBC is susceptible to a weak-ciphertext vulnerability. This issue is due to a flaw in its creation of IVs (Initialization Vectors) for ciphers with a blocksize larger than 8.

This issue results in the creation of ciphertext that contains bytes encrypted with a constant null IV. This ciphertext is prone to differential cryptanalysis, aiding attackers in compromising the plaintext of encrypted data.

The level of difficulty attackers may face trying to exploit this flaw is currently unknown, but data encrypted with vulnerable versions of Crypt::CBC should be considered insecure.

Crypt::CBC versions prior to 2.17 are vulnerable to this issue if they use the 'RandomIV' header style.

7. Heimdal RSHD Local Privilege Escalation Vulnerability
BugTraq ID: 16524
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16524
Summary:

Heimdal 'rshd' is prone to a local privilege-escalation vulnerability.

A local attacker can gain ownership of a file by overwriting its credential cache. This may lead to various attacks, including privilege escalation.

Heimdal versions prior to 0.7.2 and 0.6.6 are vulnerable.

8. PEAR::Auth Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 16758
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16758
Summary:

PEAR::Auth is prone to multiple unspecified SQL-injection vulnerabilities. This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

PEAR::Auth versions prior to 1.2.4 and to 1.3.0r4 are vulnerable.

Further information reports these issues affect the DB and LDAP Auth Containers.

9. Apache HTTP Request Smuggling Vulnerability
BugTraq ID: 14106
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14106
Summary:
Apache is prone to an HTTP-request-smuggling attack.

A specially crafted request with a 'Transfer-Encoding: chunked' header and a 'Content-Length' header can cause the server to forward a reassembled request with the original 'Content-Length' header. As a result, the malicious request may piggyback on the valid HTTP request.

This attack may result in cache poisoning, cross-site scripting, session hijacking, and other attacks.

This issue was originally described in BID 13873 (Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities). Due to the availability of more details and vendor confirmation, the issue is now a new BID.

10. Apache CGI Byterange Request Denial of Service Vulnerability
BugTraq ID: 14660
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14660
Summary:
Apache is prone to a denial of service when handling large CGI byterange requests.

11. PCRE Regular Expression Heap Overflow Vulnerability
BugTraq ID: 14620
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14620
Summary:
PCRE is prone to a heap-overflow vulnerability. This issue is due to the library's failure to properly perform boundary checks on user-supplied input before copying data to an internal memory buffer.

The impact of successful exploitation of this vulnerability depends on the application and the user credentials using the vulnerable library. A successful attack may ultimately permit an attacker to control the contents of critical memory control structures and write arbitrary data to arbitrary memory locations.

12. NetPBM PNMToPNG Long Text Line Buffer Overflow Vulnerability
BugTraq ID: 15514
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15514
Summary:
Netpbm 'pnmtopng' is susceptible to a buffer-overflow vulnerability. The utility fails to do proper bounds checks on user-supplied data before copying it to an insufficiently sized memory buffer. This issue reportedly occurs only when the '-text' command-line option is used.

This issue allows attackers to create malicious PNM files that, when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.

This vulnerability was reported in versions 9.20 and 10.0 of Netpbm. Other versions may also be affected.

13. Apache mod_ssl CRL Handling Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 14366
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14366
Summary:
Apache's mod_ssl is prone to an off-by-one buffer-overflow condition.

The vulnerability arising in the mod_ssl CRL verification callback allows for potential memory corruption when a malicious CRL is handled.

An attacker may exploit this issue to trigger a denial-of-service condition. Presumably, arbitrary code execution may be possible as well.

14. Free-AV AntiVir Personal Edition Classic Local Privilege Escalation Vulnerability
BugTraq ID: 17071
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17071
Summary:

AntiVir Personal Edition Classic is prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to launch other applications with SYSTEM privileges. This may facilitate a complete compromise of the affected computer.

AntiVir Personal Edition Classic version 7 is vulnerable; other versions may also be affected.

15. Monotone MT File Arbitrary Code Execution Vulnerability
BugTraq ID: 17139
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17139
Summary:

Monotone is prone to an arbitrary code-execution vulnerability. This issue is due to a design error in the application.

An attacker can exploit this issue to have arbitrary Lua code executed in the context of the victim user running the affected application.

This issue affects Monotone only on case-insensitive filesystems such as Microsoft Windows and Apple Mac OS X.

16. Inprotect Zones.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17141
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17141
Summary:

Inprotect is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Inprotect versions 0.21 and prior are vulnerable.

17. BorderWare MXtreme Web Administration Unspecified Remote Vulnerability
BugTraq ID: 17140
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17140
Summary:
BorderWare MXtreme web administration interface is prone to an unspecified vulnerability.

The cause and impact of this issue are currently unknown.

BorderWare MXtreme versions 5.0 and 6.0 are vulnerable.

18. Novell Netware FTP Server Denial Of Service Vulnerability
BugTraq ID: 17137
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/17137
Summary:
Netware FTP Server is prone to a remote denial-of-service vulnerability.

An attacker may cause the application to crash, thus denying service to legitimate users. Arbitrary code execution may also be possible; this has not been confirmed.

19. Wzdftpd SITE Command Arbitrary Command Execution Vulnerability
BugTraq ID: 14935
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/14935
Summary:
The 'wzdftpd' utility is affected by a remote arbitrary command-execution vulnerability.

This issue can allow an attacker to execute commands in the context of an affected server and potentially gain unauthorized access.

Version 0.5.4 of wzdftpd is reported to be vulnerable. Other versions may be affected as well.

20. Drupal Multiple Input Validation Vulnerabilities
BugTraq ID: 17104
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/17104
Summary:

Drupal is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to:

-  have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site
- access sensitive information
- hijack user sessions
- use a vulnerable Drupal installation as an email relay.

21. Skype Technologies Skype Networking Routine Heap Overflow Vulnerability
BugTraq ID: 15192
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/15192
Summary:
Skype is prone to a heap overflow in its networking routines. Successful exploitation could result in a denial of service or the execution of remote machine code in the context of the affected application.

This issue affects Skype for Windows 1.4.*.83 and earlier, Skype for Mac OS X 1.3.*.16 and earlier, Skype for Linux 1.2.*.17 and earlier, and Skype for Pocket PC 1.1.*.6 and earlier.

22. Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
BugTraq ID: 17134
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/17134
Summary:
Microsoft Commerce Server 2002 is prone to an authentication-bypass vulnerability. This issue is due to a failure in the application to correctly authenticate users due to the possible existence of sample files.

An attacker can exploit this issue to bypass the authentication mechanism and gain access to the affected application as any pre-existing user.

Microsoft Commerce Server 2002 prior to Service Pack 2 are affected by this issue.

23. PHPSysInfo Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 12887
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/12887
Summary:
phpSysInfo is reportedly affected by multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

24. Oxynews Index.PHP SQL Injection Vulnerability
BugTraq ID: 17132
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/17132
Summary:

Oxynews is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

25. SPIP Research Module Cross-Site Scripting Vulnerability
BugTraq ID: 17130
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/17130
Summary:
SPIP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

26. D2-Shoutbox SQL Injection Vulnerability
BugTraq ID: 16984
Remote: Yes
Last Updated: 2006-03-17
Relevant URL: http://www.securityfocus.com/bid/16984
Summary:

D2-Shoutbox is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

27. Util-VServer Unknown Linux Capabilities Vulnerability
BugTraq ID: 17180
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17180
Summary:
The util-vserver package for the Linux-VServer project is susceptible to an unknown Linux capability vulnerability. The package fails to properly handle unknown Linux capabilities.

The exact consequences of this issue are currently unknown. They depend on the nature of the unknown capabilities and on the nature of the applications that use them. Hosted virtual servers may possibly gain inappropriate access to the hosting operating system.

28. Libcgi-session-perl Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 17177
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17177
Summary:


The libcgi-session-perl package is prone to multiple vulnerabilities -- it creates temporary files in an insecure manner. An attacker could exploit these vulnerabilities to overwrite files or gain access to information in sensitive files.

Version 4.03-1 of libcgi-session-perl is vulnerable. Other versions may also be affected.

29. cURL / libcURL TFTP URL Parser Buffer Overflow Vulnerability
BugTraq ID: 17154
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17154
Summary:
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.

The issue occurs when the URL parser handles an excessively long URL string with a TFTP protocol prefix 'tftp://'.


An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.

30. RunIt CHPST Privilege Escalation Vulnerability
BugTraq ID: 17179
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17179
Summary:
Runit is susceptible to a local privilege-escalation vulnerability. This issue is due to a flaw in the 'chpst' utility that results in programs gaining unintended, elevated group privileges.

This issue will have varying consequences depending on the nature of programs executed by the affected utility. Attackers exploiting latent vulnerabilities in applications may gain access to elevated group privileges.

Runit versions prior to 1.4.1 are affected by this issue. This affects only packages that are compiled with 16-bit gid_t types (such as when compiled with dietlibc).

31. Novell SSL Server Multiple Vulnerabilities
BugTraq ID: 17176
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17176
Summary:

Novell SSL Server is prone to multiple vulnerabilities.

These issues affect Novell Open Enterprise Server and Novell NetWare and may allow attackers to gain access to or tamper with seemingly secure communications.

Presumably, these issue are specific to Novell, but this is not confirmed. Due to a lack of details, further information is not available at the moment. This BID will be updated when more details become available.

32. Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
BugTraq ID: 14638
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14638
Summary:
Adobe Version Cue for Mac OS X is prone to two local privilege-escalation vulnerabilities that could allow a local attacker to load arbitrary libraries or overwrite files.

The first issue (CAN-2005-1842) allows a local user to overwrite arbitrary files in the context of the superuser through the VCNative application. This vulnerability permits privilege escalation, because files may be overwritten with custom data.

The second issue (CAN-2005-1843) allows a local user to load arbitrary libraries in the context of the superuser through the VCNative application. This will permit privilege escalation.

Adobe Version Cue 1.0 and 1.0.1 are vulnerable to this issue.

33. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 15394
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/15394
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored.

An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.

  To exploit this vulnerability, an attacker must be able to run Perl scripts through Sudo.

34. Linux Kernel Netfilter Do_Replace Remote Buffer Overflow Vulnerability
BugTraq ID: 17178
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17178
Summary:
The Linux kernel is susceptible to a remote buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows remote attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel versions prior to 2.6.16 in the 2.6 series are affected by this issue.

35. Tenes Empanadas Graciela Remote Denial Of Service Vulnerability
BugTraq ID: 16982
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/16982
Summary:

Tenes Empanadas Graciela is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to cause the application to crash by activating the 'oldsocketmode' option, and then sending an overly large request to the server application.

An attacker may cause the application to crash, thus denying service to legitimate users.

36. F5 Firepass 4100 SSL VPN Cross-Site Scripting Vulnerability
BugTraq ID: 17175
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17175
Summary:
FirePass 4100 SSL VPN is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

37. Linux VServer Project CHRoot Breakout Vulnerability
BugTraq ID: 9596
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/9596
Summary:
VServer is reported prone to a breakout vulnerability that allows a malicious user to escape from the context of the chrooted root directory of the virtual server. This issue is due to the VServer application failing to secure itself against a "chroot-again" style vulnerability. Successful exploitation of this issue may allow an attacker to gain access to the filesystem outside of the chrooted root directory.

38. Virtual Communication Services VPMi Service_Requests.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 17172
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17172
Summary:
VPMi Enterprise is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

39. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
BugTraq ID: 17171
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17171
Summary:

FreeRADIUS is prone to an authentication-bypass vulnerability. The issue exists in the EAP-MSCHAPv2 state machine. Bypassing authentication could also cause the server to crash.

FreeRADIUS versions from 1.0.0 to 1.1.0 are vulnerable.

40. Peercast.org PeerCast Remote Buffer Overflow Vulnerability
BugTraq ID: 17040
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17040
Summary:

PeerCast is prone to a remote buffer-overflow vulnerability. This can facilitate a remote compromise due to arbitrary code execution.

PeerCast 0.1215 and prior versions are vulnerable.

41. Zlib Compression Library Decompression Buffer Overflow Vulnerability
BugTraq ID: 14340
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14340
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the library's failure to properly handle unexpected input to its decompression routines.

Certain values used during decompression are incorrectly specified, allowing invalid inflate input to corrupt memory.

This vulnerability allows attackers to crash applications that use the affected library. This could also potentially allow for arbitrary code execution in the context of an affected application.

42. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
BugTraq ID: 15968
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/15968
Summary:
Info-ZIP 'unzip' is susceptible to a filename buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.

43. X.Org X Window Server Local Privilege Escalation Vulnerability
BugTraq ID: 17169
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17169
Summary:
The X.Org X Window server is prone to a privilege-escalation vulnerability.

A local attacker can exploit this issue to load arbitrary modules and execute them or overwrite arbitrary files with superuser privileges. This may facilitate a complete compromise of the affected computer.

44. Verisign MPKI 6.0 Haydn.EXE Cross-Site Scripting Vulnerability
BugTraq ID: 17170
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17170
Summary:
MPKI 6.0 is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to spoof the results of certificate-validation operations in the browser of an unsuspecting user with the same certificate trust level as that of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

45. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
BugTraq ID: 16408
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/16408
Summary:

GNOME Evolution email client is prone to a denial-of-service vulnerability when processing messages containing inline XML file attachments with excessively long strings.

46. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
BugTraq ID: 14807
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14807
Summary:
XFree86 is prone to a buffer overrun in its pixmap-processing code.

This issue can potentially allow an attacker to execute arbitrary code and to escalate privileges. An attacker may possibly gain superuser privileges by exploiting this issue.

47. Linux Kernel Raw_sendmsg() Kernel Memory Access Vulnerability
BugTraq ID: 14787
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14787
Summary:
Linux Kernel is prone to a kernel memory-access vulnerability.

This issue affects the 'raw_sendmsg()' function and can allow a local attacker to access kernel memory or manipulate the hardware state due to unauthorized access to I/O ports.

Linux kernel 2.6.10 is reportedly vulnerable, but other versions are likely to be affected as well.

48. gCards Multiple Input Validation Vulnerabilities
BugTraq ID: 17165
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17165
Summary:


The gCards application is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. The following vulnerabilities can occur:

- Cross-site scripting
- SQL injection
- directory traversal
- local file include.

An attacker can access sensitive information, possibly obtain authentication credentials, manipulate SQL query logic to compromise data, and retrieve arbitrary files from the vulnerable system in the context of the webserver process.

49. BEA WebLogic Server Remote Denial Of Service Vulnerability
BugTraq ID: 17167
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17167
Summary:
BEA WebLogic Server and WebLogic Server Express are prone to a remote denial-of-service vulnerability.


An attacker with knowledge of this vulnerability may compose and submit XML data that can be used to consume all available memory. This will result in a denial of service for legitimate users.

50. BEA WebLogic Portal JSR-168 Portlets Information Disclosure Vulnerability
BugTraq ID: 17164
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17164
Summary:
BEA WebLogic Portal is prone to an information-disclosure vulnerability. The affected application improperly discloses potentially sensitive information.

This issue can allow attackers to gain access to potentially sensitive information and can result in a loss of confidentiality.

51. BEA WebLogic Server Remote Filesystem Access Vulnerability
BugTraq ID: 17166
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17166
Summary:

BEA WebLogic Server is prone to a vulnerability that could allow remote access to the local filesystem.

WebLogic Server 6.1 is vulnerable.

52. BEA WebLogic Server and WebLogic Express HTTP Response Splitting Vulnerability
BugTraq ID: 17163
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17163
Summary:

WebLogic Server and WebLogic Express are prone to an HTTP response-splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.

This issue was originally reported in BID 15052 (BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities). Due to the availability of more information, this issue is being assigned a new BID.

53. WebLogic Server and WebLogic Express Invalid Login Attempts Weakness
BugTraq ID: 17168
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17168
Summary:
WebLogic Server and WebLogic Express are prone to a weakness facilitating excessive invalid login attempts against a username. This issue can aid in brute-force attacks.

This issue was originally reported in BID 15052 (BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities). Due to the availability of more information, this issue is being assigned a new BID.

54. BEA WebLogic Multiple Vulnerabilities
BugTraq ID: 16358
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/16358
Summary:
BEA has released 10 advisories identifying various vulnerabilities affecting BEA WebLogic Server, WebLogic Portal, and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.

55. ProFTPD SQLShowInfo SQL Output Format String Vulnerability
BugTraq ID: 14380
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14380
Summary:
A format-string vulnerability affects ProFTPD. This issue occurs when the SQLShowInfo directive is enabled. If the attacker can influence data in the backend SQL database, then the attacker may be able to exploit this issue by inserting a malicious format string into data that will be queried by ProFTPD.

A successful attack will allow arbitrary code to execute in the context of the server.

56. ProFTPD Shutdown Message Format String Vulnerability
BugTraq ID: 14381
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/14381
Summary:
A format-string vulnerability affects ProFTPD. This issue occurs when the server prints a shutdown message containing certain variables such as the current directory. If an attacker could create a directory on the server, this may trigger this issue.

Successful exploitation will result in arbitrary code execution in the context of the server.

57. MERCUR Messaging 2005 IMAP Remote Buffer Overflow Vulnerability
BugTraq ID: 17138
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17138
Summary:
MERCUR Messaging 2005 is prone to a remote buffer-overflow vulnerability.

The vulnerability presents itself when the server handles specially crafted IMAP commands.

This may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.

MERCUR Messaging 2005 version 5.0 SP3 is reported to be vulnerable. Other versions may be affected as well.

58. MailEnable Unspecified POP Authentication Bypass Vulnerability
BugTraq ID: 17162
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17162
Summary:

MailEnable is prone to an unspecified authentication-bypass vulnerability.

This vulnerability affects the POP service of various MailEnable versions. Very little information beyond that is available at this time. This BID will be updated as further information becomes available.

59. MailEnable Enterprise/Professional Editions Webmail Denial of Service Vulnerability
BugTraq ID: 17161
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17161
Summary:
MailEnable Enterprise/Professional Editions are prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to cause the application to consume all available resources, effectively denying service to legitimate users.

This issue is reported to be a seperate issue from that discussed in BID 16525 (MailEnable Enterprise Edition Webmail Denial of Service Vulnerability).

60. SoftBB Reg.PHP SQL Injection Vulnerability
BugTraq ID: 17160
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17160
Summary:
SoftBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

61. Avast! Antivirus Local Insecure Permissions Vulnerability
BugTraq ID: 17158
Remote: No
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17158
Summary:
The avast! Antivirus product is prone to a local insecure-permissions vulnerability. This issue is due to the application incorrectly resetting the permissions on critical files during its periodic update process.

A local, unprivileged attacker can exploit this issue to replace critical driver files with malicious executables. This may facilitate a complete compromise of the affected computer.

This issue affects avast! 4.x versions. Other versions may also be vulnerable.

62. Maian Weblog Multiple SQL Injection Vulnerabilities
BugTraq ID: 17159
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17159
Summary:
Maian Weblog is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

63. Jabber Studio JabberD Remote Denial Of Service Vulnerability
BugTraq ID: 17155
Remote: Yes
Last Updated: 2006-03-21
Relevant URL: http://www.securityfocus.com/bid/17155
Summary:
Jabber Studio 'jabberd' is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed network messages.

An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.

64. Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
BugTraq ID: 16798
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16798
Summary:
VPMi Enterprise is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Note: Further information from the vendor indicates that this issue cannot be exploited to inject SQL. Note also that Symantec has not been able to reproduce the vulnerability.

65. Skull-Splitter Download Counter for Wallpapers Count.PHP SQL Injection Vulnerability
BugTraq ID: 17156
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17156
Summary:

Skull-Splitter Download Counter for Wallpapers is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

66. Todd Miller Sudo Local Privilege Escalation Vulnerability
BugTraq ID: 15191
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15191
Summary:
Sudo is prone to a local privilege-escalation vulnerability.

The vulnerability presents itself because the application fails to properly sanitize malicious data supplied through environment variables.

A successful attack may result in a complete compromise.

67. Streber Unspecified HTML Injection Vulnerability
BugTraq ID: 17157
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17157
Summary:
Streber is affected by an unspecified HTML-injection vulnerability. A victim user who views the vulnerable sections of the site would have the attacker-supplied HTML and script code executed in the security context of the affected site.

Streber 0.054 and prior are vulnerable.

68. WinHKI Remote Directory Traversal Vulnerability
BugTraq ID: 17153
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17153
Summary:
Reportedly, an attacker can carry out directory-traversal attacks. These issues present themselves when the application processes malformed archives.

A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. A successful exploit may aid in further attacks.

69. CutePHP CuteNews Function.PHP Local File Include Vulnerability
BugTraq ID: 17152
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17152
Summary:
CuteNews is prone to a local file-include vulnerability. This may facilitate the unauthorized viewing of files and unauthorized execution of local scripts.

Version 1.4.1 is vulnerable; other versions may also be affected.

70. Noah's Classifieds Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17151
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17151
Summary:
Noah's Classifieds is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

71. Light Weight Calendar Cal.PHP Remote Command Execution Vulnerability
BugTraq ID: 17059
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17059
Summary:
Light Weight Calendar is prone to a remote command-execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.

Successful exploitation could facilitate unauthorized access; other attacks are also possible.

72. Skull-Splitter PHP Guestbook HTML Injection Vulnerability
BugTraq ID: 17136
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17136
Summary:
PHP Guestbook is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

73. PHPWebSite Multiple SQL Injection Vulnerabilities
BugTraq ID: 17150
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17150
Summary:
phpWebSite is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

74. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
BugTraq ID: 17058
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17058
Summary:

GnuPG is prone to a vulnerability involving incorrect verification of non-detached signatures.

A successful attack can allow an attacker to simply take a signed message and inject arbitrary data into it and bypass verification.

Note that this issue also affects verification of signatures embedded in encrypted messages. Scripts and applications using gpg are affected, as are applications using the GPGME library.

GnuPG versions prior to 1.4.2.2 are vulnerable to this issue.

75. Apache Log4Net Denial Of Service Vulnerability
BugTraq ID: 17095
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17095
Summary:
Log4net is prone to a remote denial-of-service vulnerability.

An attacker may cause the application to crash, thus denying service to legitimate users.

76. CrossFire SetUp Remote Buffer Overflow Vulnerability
BugTraq ID: 17093
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17093
Summary:

CrossFire is prone to a remote buffer-overflow vulnerability. This can facilitate a remote compromise due to arbitrary code execution.

CrossFire 1.9.0 and prior versions are vulnerable.

77. IlohaMail Email Message Remote HTML Injection Vulnerability
BugTraq ID: 13175
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/13175
Summary:
IlohaMail is affected by an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

78. Mail-Audit Insecure Temporary File Creation Vulnerability
BugTraq ID: 16434
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16434
Summary:

Mail-Audit creates temporary files in an insecure manner. This issue arises only when logging has been enabled.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.


Mail-Audit 2.1 and prior versions are considered vulnerable.

79. MusicBox Multiple Input Validation Vulnerabilities
BugTraq ID: 17149
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17149
Summary:
MusicBox is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

80. BetaParticle Blog Multiple SQL Injection Vulnerabilities
BugTraq ID: 17148
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17148
Summary:

BetaParticle Blog is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

81. Woltlab Burning Board Class_DB_MySQL.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17147
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17147
Summary:
Woltlab Burning Board is prone to a cross-site scripting vulnerability. This issue is due to a lack of proper sanitization of user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks.

82. ExtCalendar Cross-Site Scripting Vulnerabilities
BugTraq ID: 17146
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17146
Summary:

ExtCalendar is prone to four cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

83. KDE KJS Encodeuri / Decodeuri Remote Heap Overflow Vulnerability
BugTraq ID: 16325
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16325
Summary:

KDE KJS is prone to a remote heap-overflow vulnerability.

Specifically, the issue presents itself when the application decodes specially crafted UTF-8 encoded URI sequences.

A successful attack can result in a remote compromise in the context of the user running the vulnerable application.

KDE versions 3.2.0, up to and including KDE 3.5.0, are vulnerable to this issue.

84. Multiple Web Browser International Domain Name Handling Site Property Spoofing Vulnerabilities
BugTraq ID: 12461
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/12461
Summary:
Multiple Web browsers are reported prone to vulnerabilities that surround the handling of International Domain Names.

The vulnerabilities are caused by inconsistencies in how International Domain Names are processed. Reports indicate that attackers can leverage this to spoof address bar, status-bar, and SSL certificate values.

Remote attackers may exploit these vulnerabilities in phishing-style attacks. Through a false sense of trust, users may voluntarily disclose sensitive information to a malicious website.

Although these vulnerabilities are reported to affect browsers, mail clients that depend on the  browser to generate HTML code may also be affected.

85. HP-UX Usermod Local Unauthorized Access Vulnerability
BugTraq ID: 17143
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17143
Summary:

HP-UX usermod(1M) is prone to a local unauthorized-access vulnerability.

This may facilitate various attacks including information disclosure and potential code execution leading to privilege escalation.

HP-UX B.11.00, B.11.11, and B.11.23 are vulnerable.

86. KDE Kate, KWrite Local Backup File Information Disclosure Vulnerability
BugTraq ID: 14297
Remote: No
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14297
Summary:
KDE kate and kwrite are susceptible to a local information-disclosure vulnerability. The applications fail to maintain secure file permissions when creating backup files.

This vulnerability allows local attackers to gain access to the contents of potentially sensitive files.

Note: Since these applications are network-aware, under some unknown circumstances, this issue may not be restricted to local attackers.

87. Invision Power Board Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17144
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17144
Summary:

Invision Power Board is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

88. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The following are vulnerable:

- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier

89. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

90. XPDF Loca Table Verification Remote Denial of Service Vulnerability
BugTraq ID: 14529
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/14529
Summary:
The 'xpdf' utility is prone to a remote denial-of-service vulnerability.

The vulnerability presents itself when the application tries to verify the validity of a malformed 'loca' table in PDF files.

This issue can result in disk consumption and can ultimately lead to a denial-of-service condition.

The 'kpdf', 'gpdf', and 'CUPS' utilities are vulnerable to this issue as well.

91. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:

The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

92. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

93. Libungif Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 15304
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15304
Summary:
The libungif library is prone to a denial-of-service vulnerability. The library fails to handle exceptional conditions.

Successful exploitation of this vulnerability will cause the application using the affected library to crash, effectively denying service to legitimate users.

Version 4.1.3 and prior are considered vulnerable to this issue.

94. Freeciv Remote Denial Of Service Vulnerability
BugTraq ID: 16975
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/16975
Summary:
The Freeciv game server is reported prone to a remote denial-of-service vulnerability.

A remote attacker may exploit this issue to deny service for legitimate users.

95. Libungif Colormap Handling Memory Corruption Vulnerability
BugTraq ID: 15299
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15299
Summary:
The libungif library is prone to a memory-corruption vulnerability.

Reports indicate that due to the library's improper handling of colormaps in GIF files, an attacker can trigger out-of-bounds writes and corrupt memory.

This may lead to a denial-of-service condition.

Version 4.1.3 and prior are considered vulnerable to this issue.

96. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
BugTraq ID: 15429
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15429
Summary:
The 'gdk-pixbuf' and 'gtk2' libraries are prone to a denial-of-service vulnerability. This issue occurs when an application using one of the affected libraries handles a malformed XPM image file.

Exploitation could cause an application using a vulnerable library to enter an infinite loop, resulting in a denial of service.

97. GDK-Pixbuf XPM Images Integer Overflow Vulnerability
BugTraq ID: 15428
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15428
Summary:
A remote integer-overflow vulnerability affects gdk-pixbuf.

When an application that uses the vulnerable library processes a malformed XPM file, the application will crash, denying service to legitimate users. An attacker may also be able to exploit this issue to execute arbitrary code with the privileges of the application using the vulnerable library.

98. Veritas Backup Exec Media Server BEngine Service Job Log Remote Format String Vulnerability
BugTraq ID: 17096
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17096
Summary:
Veritas Backup Exec Media Server is susceptible to a remote format-string vulnerability. This issue occurs because the application fails to do proper input-sanitization of user-supplied input before sing it in the format-specifier argument of a formatted-printing function.

This issue is exploitable only when the job log is configured to run in 'Full Details' mode. This is not the default configuration mode, nor is it recommended in a production environment due to the excessive amount of disk space required for the log.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploitation attempts likely result in a denial-of-service condition.

99. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
BugTraq ID: 15435
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/15435
Summary:
Gdk-pixbuf and gtk2 are prone to a buffer-overflow. When an application that uses a vulnerable library processes a malformed XPM image file, it results in a heap-based buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the victim user.

100. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 17098
Remote: Yes
Last Updated: 2006-03-20
Relevant URL: http://www.securityfocus.com/bid/17098
Summary:
Veritas Backup Exec is prone to multiple remote denial-of-service vulnerabilities.

These issues result in memory violations and memory exhaustion and lead to denial-of-service conditions in the affected applications. A restart is required to regain normal functionality in most cases.

Various versions of Backup Exec for Windows, Linux, and Netware are vulnerable.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Debit-card fraud underscores legal loopholes
By: Robert Lemos
UPDATE: Three major data leaks in the last six months are likely responsible for a recent spate of debit-card fraud, but in two cases, no one has come forward to take responsibility. Under current state laws, such silence may be legal.
http://www.securityfocus.com/news/11381

2. Virus names likely a lost cause
By: Robert Lemos
The Common Malware Enumeration Project clears up confusion for responders, but racing to name the latest virus in the media will continue to be the norm.
http://www.securityfocus.com/news/11380

3. Antivirus groups fight over Crossover sharing
By: Robert Lemos
A young antivirus group's attempts to leverage a rare exclusive virus discovery into greater membership has earned it criticism from the old guard of antivirus companies.
http://www.securityfocus.com/news/11379

4. Triple threat to Mac OS X largely academic
By: Robert Lemos
Two worms and an exploit for Apple's operating system hardly threaten consumers' computers, but should act as a wake-up call for Mac users.
http://www.securityfocus.com/news/11378

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Developer, Superior
http://www.securityfocus.com/archive/77/428317

2. [SJ-JOB] Quality Assurance, Superior
http://www.securityfocus.com/archive/77/428316

3. [SJ-JOB] Sr. Security Analyst, Bangalore
http://www.securityfocus.com/archive/77/428314

4. [SJ-JOB] Security Engineer, Commack
http://www.securityfocus.com/archive/77/428315

5. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/428313

6. [SJ-JOB] Auditor, INDIANAPOLIS
http://www.securityfocus.com/archive/77/428257

7. [SJ-JOB] Sales Engineer, Washington DC
http://www.securityfocus.com/archive/77/428258

8. [SJ-JOB] Security Engineer, Providence
http://www.securityfocus.com/archive/77/428261

9. [SJ-JOB] Sr. Security Engineer, Richland
http://www.securityfocus.com/archive/77/428259

10. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/428260

11. [SJ-JOB] Developer, Santa Clara
http://www.securityfocus.com/archive/77/428255

12. [SJ-JOB] CHECK Team Leader, London
http://www.securityfocus.com/archive/77/428256

13. [SJ-JOB] Security Product Marketing Manager, Ft Lauderdale
http://www.securityfocus.com/archive/77/428250

14. [SJ-JOB] Security Engineer, Ft Lauderdale
http://www.securityfocus.com/archive/77/428252

15. [SJ-JOB] Sr. Security Engineer, Tempe
http://www.securityfocus.com/archive/77/428254

16. [SJ-JOB] Sales Engineer, San Francisco Bay Area
http://www.securityfocus.com/archive/77/428190

17. [SJ-JOB] Developer, Consulting Position
http://www.securityfocus.com/archive/77/428191

18. [SJ-JOB] Application Security Engineer, Jacksonville
http://www.securityfocus.com/archive/77/428192

19. [SJ-JOB] Sr. Security Analyst, London
http://www.securityfocus.com/archive/77/428085

20. [SJ-JOB] Quality Assurance, Bangalore
http://www.securityfocus.com/archive/77/428086

21. [SJ-JOB] Threat Analyst, Wilimngton
http://www.securityfocus.com/archive/77/428083

22. [SJ-JOB] Sales Engineer, DC area
http://www.securityfocus.com/archive/77/428084

23. [SJ-JOB] Application Security Engineer, Milpitas
http://www.securityfocus.com/archive/77/428078

24. [SJ-JOB] Application Security Architect, Milpitas
http://www.securityfocus.com/archive/77/428079

25. [SJ-JOB] Sr. Security Engineer, Milpitas
http://www.securityfocus.com/archive/77/428081

26. [SJ-JOB] Application Security Engineer, Milpitas
http://www.securityfocus.com/archive/77/428076

27. [SJ-JOB] Application Security Engineer, Milpitas
http://www.securityfocus.com/archive/77/428077

28. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/428072

29. [SJ-JOB] Technical Marketing Engineer, Ann Arbor
http://www.securityfocus.com/archive/77/428073

30. [SJ-JOB] Auditor, Dallas
http://www.securityfocus.com/archive/77/428074

31. [SJ-JOB] Security Auditor, Chicago
http://www.securityfocus.com/archive/77/428069

32. [SJ-JOB] Auditor, Chicago
http://www.securityfocus.com/archive/77/428070

33. [SJ-JOB] Security Consultant, Raleigh
http://www.securityfocus.com/archive/77/428071

34. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/428018

35. [SJ-JOB] VP of Regional Sales, San Francisco and East Coast
http://www.securityfocus.com/archive/77/428021

36. [SJ-JOB] Security Auditor, Dallas
http://www.securityfocus.com/archive/77/428022

37. [SJ-JOB] Sales Representative, San Francisco
http://www.securityfocus.com/archive/77/428019

38. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/428020

39. [SJ-JOB] Sr. Product Manager, Crystal City
http://www.securityfocus.com/archive/77/428012

40. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/428014

41. [SJ-JOB] Application Security Engineer, Crystal City
http://www.securityfocus.com/archive/77/428054

42. [SJ-JOB] Security Auditor, Raleigh
http://www.securityfocus.com/archive/77/428053

43. [SJ-JOB] Auditor, Raleigh
http://www.securityfocus.com/archive/77/428013

44. [SJ-JOB] Developer, San Francisco
http://www.securityfocus.com/archive/77/427913

45. [SJ-JOB] Developer, San Francisco
http://www.securityfocus.com/archive/77/427916

46. [SJ-JOB] Quality Assurance, San Francisco
http://www.securityfocus.com/archive/77/427917

47. [SJ-JOB] Security Consultant, Philadelphia
http://www.securityfocus.com/archive/77/427914

48. [SJ-JOB] Security Auditor, Philadelphia
http://www.securityfocus.com/archive/77/427912

49. [SJ-JOB] Security Engineer, Crystal City
http://www.securityfocus.com/archive/77/427870

50. [SJ-JOB] Auditor, Crystal City
http://www.securityfocus.com/archive/77/427871

51. [SJ-JOB] Threat Analyst, Crystal City
http://www.securityfocus.com/archive/77/427869

52. [SJ-JOB] Auditor, Philadelphia
http://www.securityfocus.com/archive/77/427896

53. [SJ-JOB] Security Consultant, Richmond
http://www.securityfocus.com/archive/77/427895

54. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/427767

55. [SJ-JOB] Security Researcher, Atlanta
http://www.securityfocus.com/archive/77/427766

56. [SJ-JOB] Information Assurance Analyst, Crystal City
http://www.securityfocus.com/archive/77/427763

57. [SJ-JOB] Forensics Engineer, Crystal City
http://www.securityfocus.com/archive/77/427765

58. [SJ-JOB] Auditor, Richmond
http://www.securityfocus.com/archive/77/427761

59. [SJ-JOB] Security Auditor, Richmond
http://www.securityfocus.com/archive/77/427762

60. [SJ-JOB] Application Security Architect, New York
http://www.securityfocus.com/archive/77/427735

61. [SJ-JOB] Security Architect, Crystal City
http://www.securityfocus.com/archive/77/427736

62. [SJ-JOB] Certification & Accreditation Engineer, Crystal City
http://www.securityfocus.com/archive/77/427738

63. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/427734

64. [SJ-JOB] Security Auditor, Baltimore
http://www.securityfocus.com/archive/77/427733

65. [SJ-JOB] Auditor, Baltimore
http://www.securityfocus.com/archive/77/427665

66. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/427664

V.   INCIDENTS LIST SUMMARY
---------------------------
1. SSH Scans
http://www.securityfocus.com/archive/75/428106

2. New Phishing Technique?
http://www.securityfocus.com/archive/75/428042

3. unicast netbios name service nbtstat query to/from same ip?
http://www.securityfocus.com/archive/75/427906

4. Possible AIM Hack? - Follow-up
http://www.securityfocus.com/archive/75/427888

5. good list of live CDs
http://www.securityfocus.com/archive/75/427719

6. Possible AIM Hack?
http://www.securityfocus.com/archive/75/427599

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. debugging seh overwrite
http://www.securityfocus.com/archive/82/428178

2. HTTP proxy/redirector to a unique virtual host ....
http://www.securityfocus.com/archive/82/427835

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. virtual memory protection using AWE
http://www.securityfocus.com/archive/88/428309

2. SecurityFocus Microsoft Newsletter #282
http://www.securityfocus.com/archive/88/427942

3. Moderation in moderation
http://www.securityfocus.com/archive/88/427941

4. EFS disaster!
http://www.securityfocus.com/archive/88/427915

5. trouble using SSL on WSUS
http://www.securityfocus.com/archive/88/427610

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Libnids
http://www.securityfocus.com/archive/91/428026

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Lancope

"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."

http://www.lancope.com/resource/