SecurityFocus Newsletter #344

Peter Laborge <[email protected]> Tue, 04 Apr 2006 12:44:45 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #344
----------------------------------------

This Issue is Sponsored By: Watchfire

Today's hackers exploit web applications to expose, embarrass and even steal. Firewalls and SSL may be commonplace but recent studies indicate 75% of websites remain vulnerable to attack. Watchfire's "Addressing Challenges in Application Security" whitepaper, explains what to do and provides a guideline to improving your own application security. Download this whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000003Stu

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Two attacks against VoIP
        2. Open source security testing methodology
        3. This Means Warcraft!
II.   BUGTRAQ SUMMARY
        1. MPG123 Malformed MP3 File Memory Corruption Vulnerability
        2. KGB Archiver Hostile Destination Path Vulnerability
        3. McAfee Webshield SMTP Remote Format String Vulnerability
        4. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
        5. Esqlanelapse Unspecified Cross-Site Scripting Vulnerability
        6. Mon Album Multiple SQL Injection Vulnerabilities
        7. XFIT/S Unspecified Denial of Service Vulnerability
        8. Mantis View_All_Set.PHP Multiple Cross-Site Scripting Vulnerabilities
        9. Horde Help Viewer Remote PHP Code Execution Vulnerability
        10. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
        11. Microsoft Windows Help Image Processing Heap Overflow Vulnerability
        12. O2PHP Oxygen Post.PHP SQL Injection Vulnerability
        13. MediaSlash Gallery Index.PHP Remote File Include Vulnerability
        14. VNews Multiple Cross-Site Scripting Vulnerabilities
        15. X-Changer Multiple SQL Injection Vulnerabilities
        16. Apple Mac OS X ImageIO Remote Denial Of Service Vulnerability
        17. VBook Index.PHP SQL Injection Vulnerability
        18. Peercast.org PeerCast Remote Buffer Overflow Vulnerability
        19. VBook Multiple Cross-Site Scripting Vulnerabilities
        20. VNews Multiple SQL Injection Vulnerabilities
        21. VWar Functions_Admin.PHP Remote File Include Vulnerability
        22. HP Tru64 NLSPATH Environment Variable Local Buffer Overflow Vulnerability
        23. PHPNewsManager Multiple SQL Injection Vulnerabilities
        24. InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability
        25. Sun Cluster SunPlex Manager Unauthorized File Access Vulnerability
        26. NetBSD If_Bridge(4) Kernel Memory Disclosure Vulnerability
        27. Apple Mac OS X Intel-Based Local Authentication Bypass Vulnerability
        28. Util-VServer SUEXEC Privilege Escalation Weakness
        29. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
        30. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
        31. Zope RestructuredText File Include Vulnerability
        32. PHPNuke-Clan Functions_Common.PHP Remote File Include Vulnerability
        33. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
        34. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
        35. Info-ZIP UnZip CHMod File Permission Modification Race Condition Weakness
        36. VWar Functions_install.PHP Remote File Include Vulnerability
        37. Squid FTP Server Response Denial Of Service Vulnerability
        38. Limbo CMS Frontpage Arbitrary PHP Command Execution Vulnerability
        39. Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
        40. ARJ Software UNARJ Remote Buffer Overflow Vulnerability
        41. Winace UnAce ACE Archive Remote Directory Traversal Vulnerability
        42. Winace UnAce ACE Archive Multiple Remote Buffer Overflow Vulnerabilities
        43. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
        44. Samba Machine Trust Account Local Information Disclosure Vulnerability
        45. Linux Kernel IP ID Information Disclosure Weakness
        46. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
        47. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
        48. FreeRADIUS Multiple Remote Vulnerabilities
        49. Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
        50. Zoo Misc.c Buffer Overflow Vulnerability
        51. StoreBackup Insecure Temporary File Creation Vulnerability
        52. MediaWiki Encoded Page Link HTML Injection Vulnerability
        53. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
        54. AngelineCMS Loadkernel.PHP Remote File Include Vulnerability
        55. Xine-Lib Malformed MPEG Stream Buffer Overflow Vulnerability
        56. Doomsday Multiple Remote Format String Vulnerabilities
        57. MyBulletinBoard Email BBCode Tag HTML Injection Vulnerability
        58. HP Color LaserJet 2500/4600 Toolbox Directory Traversal Vulnerability
        59. MySQL Query Logging Bypass Vulnerability
        60. PHP Html_Entity_Decode() Information Disclosure Vulnerability
        61. LucidCMS Index.PHP Multiple Cross-Site Scripting Vulnerabilities
        62. Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
        63. WebAPP Multiple Cross-Site Scripting Vulnerabilities
        64. Exponent CMS Banner Module Arbitrary Script Execution Vulnerability
        65. GNU Mailman Attachment Scrubber Malformed MIME Message Denial Of Service Vulnerability
        66. Horde MIME Viewer Inline Attachment HTML Injection Vulnerability
        67. Basic Analysis and Security Engine Base_maintenance.PHP Authentication Bypass Vulnerability
        68. VWar Get_header.PHP Remote File Include Vulnerability
        69. ReloadCMS User-Agent HTML Injection Vulnerability
        70. PHPBB Profile.PHP Cross-Site Scripting Vulnerability
        71. AWebBB Multiple Input Validation Vulnerabilities
        72. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
        73. AN HTTPD Source Disclosure Vulnerability
        74. Bugzero Multiple Cross-Site Scripting Vulnerabilities
        75. ISP Site Man Admin_Login.ASP SQL Injection Vulnerability
        76. PHPSelect Submit-A-Link HTML Injection Vulnerability
        77. Blank'N'Berg Directory Traversal Vulnerability
        78. Blank'N'Berg Cross-Site Scripting Vulnerability
        79. Claroline Rqmkhtml.PHP Information Disclosure Vulnerability
        80. Claroline RQMKHTML.PHP Cross-Site Scripting Vulnerability
        81. Apache Struts Multiple Remote Vulnerabilities
        82. Claroline ScormExport.inc.PHP File Include Vulnerability
        83. Mantis Multiple Remote Vulnerabilities
        84. Lynx URI Handlers Arbitrary Command Execution Vulnerability
        85. Google Search Appliance ProxyStyleSheet Multiple Remote Vulnerabilities
        86. RedCMS Multiple Input Validation Vulnerabilities
        87. Softbiz Image Gallery Multiple SQL Injection Vulnerabilities
        88. Hitachi Groupmax World Wide Web Unspecified Cross-Site Scripting Vulnerability
        89. DbbS Topics.PHP SQL Injection Vulnerability
        90. Warcraft III Replay Parser for PHP Index.PHP Remote File Include Vulnerability
        91. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
        92. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
        93. V-creator Remote Shell Code Execution Vulnerability
        94. GDK-Pixbuf XPM Images Integer Overflow Vulnerability
        95. QLnews Multiple Input Validation Vulnerabilities
        96. SiteSearch Indexer Searchresults.ASP Cross-Site Scripting Vulnerability
        97. BusyBox Insecure Password Hash Weakness
        98. ZDaemon Multiple Remote Vulnerabilities
        99. qliteNews Multiple SQL Injection Vulnerabilities
        100. GTD-PHP Multiple Input Validation Vulnerabilities
III.  SECURITYFOCUS NEWS
        1. Seven arrested in online fraud crackdown
        2. Patches released for zero-day IE threat
        3. Check Point calls off Sourcefire buy
        4. Debit-card fraud underscores legal loopholes
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Technical Support Engineer, Columbia
        2. [SJ-JOB] Manager, Information Security, Columbia
        3. [SJ-JOB] Technical Support Engineer, Columbia
        4. [SJ-JOB] Manager, Information Security, Schaumburg
        5. [SJ-JOB] Manager, Information Security, Costa Mesa
        6. [SJ-JOB] Incident Handler, Edison
        7. [SJ-JOB] Security Consultant, NJ, New York, D.C.
        8. [SJ-JOB] Manager, Information Security, Allen
        9. [SJ-JOB] Sr. Security Engineer, Dublin
        10. [SJ-JOB] Security Engineer, Zurich
        11. [SJ-JOB] Security Engineer, Sydney
        12. [SJ-JOB] Security Consultant, Allen
        13. [SJ-JOB] Director, Information Security, Allen
        14. [SJ-JOB] Sales Engineer, Dallas
        15. [SJ-JOB] Security Engineer, Allen
        16. [SJ-JOB] Application Security Architect, Cleveland / Independence
        17. [SJ-JOB] Security Engineer, Chicago
        18. [SJ-JOB] Sr. Security Analyst, Costa Mesa
        19. [SJ-JOB] Sr. Security Analyst, Schaumburg
        20. [SJ-JOB] Sr. Security Analyst, Allen
        21. [SJ-JOB] Security Engineer, Seattle
        22. [SJ-JOB] Security Architect, Jersey City
        23. [SJ-JOB] Developer, Idaho Falls
        24. [SJ-JOB] Sr. Security Engineer, Charlotte
        25. [SJ-JOB] Sr. Security Engineer, Chantilly
        26. [SJ-JOB] Security Architect, Schaumburg
        27. [SJ-JOB] Security Consultant, New York City
        28. [SJ-JOB] Security Engineer, Plantation
        29. [SJ-JOB] Certification & Accreditation Engineer, Columbia
        30. [SJ-JOB] Developer, Idaho Falls
        31. [SJ-JOB] Threat Analyst, Idaho Falls
        32. [SJ-JOB] Training / Awareness Specialist, Idaho Falls
        33. [SJ-JOB] Management, Idaho Falls
        34. [SJ-JOB] Threat Analyst, Idaho Falls
        35. [SJ-JOB] Security Engineer, Plantation
        36. [SJ-JOB] Security Researcher, Anywhere in the World
        37. [SJ-JOB] Application Security Architect, Indianapolis
        38. [SJ-JOB] Security Architect, Portsmouth
        39. [SJ-JOB] Security Engineer, Lanham
        40. [SJ-JOB] Application Security Architect, Portsmouth
        41. [SJ-JOB] Certification & Accreditation Engineer, DC
        42. [SJ-JOB] Security Researcher, Idaho Falls
        43. [SJ-JOB] Security Engineer, Idaho Falls
        44. [SJ-JOB] Security Consultant, Reading
        45. [SJ-JOB] Application Security Architect, London
        46. [SJ-JOB] Manager, Information Security, London
        47. [SJ-JOB] Security Engineer, Sydney
        48. [SJ-JOB] Security Engineer, Zurich
        49. [SJ-JOB] Forensics Engineer, Falls Church
        50. [SJ-JOB] Information Assurance Engineer, Falls Church
        51. [SJ-JOB] Certification & Accreditation Engineer, Arlington    (Crystal City)
V.    INCIDENTS LIST SUMMARY
        1. What a strange route (The DoD inside)!
        2. Win2k Machine contacting Root Server???
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Outlook Express ; UTF-7 ; References header field problem
        2. Black Hat Call for Papers and Registration now open
        3. mpg123 DoS ... It receives a SIGSEGV.
        4. Black Hat Call for Papers and Registration now open
        5. Beating memory address randomization (secuirty) features in Unix/Linux
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. New IE flaw and exploit sites/migration to non-MS browser
        2. SecurityFocus Microsoft Newsletter #284
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. IPtables and C programming??
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Two attacks against VoIP
By Peter Thermos
This purpose of this article is to discuss two of the most well known attacks that can be carried out in current VoIP deployments. The first attack demonstrates the ability to hijack a user's VoIP Subscription and subsequent communications. The second attack looks at the ability to eavesdrop in to VoIP communications.
http://www.securityfocus.com/infocus/1862

2. Open source security testing methodology
By Federico Biancuzzi
Truth is made of numbers. Following this golden rule, Federico Biancuzzi interviewed Pete Herzog, founder of ISECOM and creator of the OSSTMM, to talk about the upcoming revision 3.0 of the Open Source Security Testing Methodology Manual. He discusses why we need a testing methodology, why use open source, the value of certifications, and plans for a new vulnerability scanner developed with a different approach than Nessus.
http://www.securityfocus.com/columnists/395

3. This Means Warcraft!
By Mark Rasch
A recent World of Warcraft case involved a WoW book by Brian Knopp that was being sold on eBay. It resulted in automated takedown notices by "lawyerbots" and shows how the legal process today can end up silencing legitimate uses of trademarks and copyrights.
http://www.securityfocus.com/columnists/396


II.  BUGTRAQ SUMMARY
--------------------
1. MPG123 Malformed MP3 File Memory Corruption Vulnerability
BugTraq ID: 17365
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17365
Summary:
The mpg123 application is prone to a memory-corruption vulnerability related to the handling of MP3 streams.

An attacker may be able to exploit this vulnerability to execute arbitrary code in the context of the user running the player, but this has not been confirmed.

This issue may be related to the one described in BID 12218 (MPG123 Layer 2 Frame Header Heap Overflow Vulnerability).

2. KGB Archiver Hostile Destination Path Vulnerability
BugTraq ID: 17363
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17363
Summary:
KGB Archiver contains a vulnerability in the handling of pathnames for archived files.

By specifying a path for an archived item that points outside the expected destination directory, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem, possibly including paths containing system binaries and other sensitive or confidential information.

Presumably, an attacker could use this to create or overwrite binaries in any desired location, with the privileges of the invoking user.

Version 1.1.5.21 and prior are vulnerable.

3. McAfee Webshield SMTP Remote Format String Vulnerability
BugTraq ID: 16742
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/16742
Summary:
McAfee Webshield SMTP is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in a format-specifier argument to a formatted printing function.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.

4. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
BugTraq ID: 17196
Remote: Yes
Last Updated: 2006-04-01
Relevant URL: http://www.securityfocus.com/bid/17196
Summary:

Microsoft Internet Explorer is susceptible to a remote code-execution vulnerability. This issue is due to a flaw that results in an invalid table-pointer dereference.

Remote attackers may exploit this issue to crash affected browsers or to execute arbitrary machine code in the context of affected users.

Microsoft has reported that this issue does not affect the March 20, 2006 release of Internet Explorer 7 Beta 2 Preview.

5. Esqlanelapse Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 17331
Remote: Yes
Last Updated: 2006-04-01
Relevant URL: http://www.securityfocus.com/bid/17331
Summary:


Esqlanelapse is prone to an unspecified cross-site scripting vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Esqlanelapse 2.0 and 2.2 are vulnerable to this issue.

6. Mon Album Multiple SQL Injection Vulnerabilities
BugTraq ID: 17327
Remote: Yes
Last Updated: 2006-04-01
Relevant URL: http://www.securityfocus.com/bid/17327
Summary:
Mon Album is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 0.8.7 is reported to be vulnerable. Other versions may be affected as well.

7. XFIT/S Unspecified Denial of Service Vulnerability
BugTraq ID: 17329
Remote: Yes
Last Updated: 2006-03-31
Relevant URL: http://www.securityfocus.com/bid/17329
Summary:
XFIT/S is prone to a denial-of-service vulnerability.

The vulnerability presents itself when the application receives data unexpectedly.

Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more details become available.

8. Mantis View_All_Set.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17326
Remote: Yes
Last Updated: 2006-03-31
Relevant URL: http://www.securityfocus.com/bid/17326
Summary:
Mantis is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Mantis 1.0.1 and prior are considered vulnerable.

9. Horde Help Viewer Remote PHP Code Execution Vulnerability
BugTraq ID: 17292
Remote: Yes
Last Updated: 2006-03-31
Relevant URL: http://www.securityfocus.com/bid/17292
Summary:
Horde is prone to a remote PHP code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.

10. GNOME Evolution Inline XML File Attachment Buffer Overflow Vulnerability
BugTraq ID: 16408
Remote: Yes
Last Updated: 2006-03-31
Relevant URL: http://www.securityfocus.com/bid/16408
Summary:

GNOME Evolution email client is prone to a denial-of-service vulnerability when processing messages containing inline XML file attachments with excessively long strings.

11. Microsoft Windows Help Image Processing Heap Overflow Vulnerability
BugTraq ID: 17325
Remote: Yes
Last Updated: 2006-03-31
Relevant URL: http://www.securityfocus.com/bid/17325
Summary:

The Microsoft Windows Help File viewer (winhlp32.exe) is reported prone to a heap-overflow vulnerability.

This vulnerability presents itself when the application handles a specially crafted Windows Help (.hlp) file.

A successful attack may facilitate arbitrary code execution in the context of a vulnerable user who opens a malicious file.

12. O2PHP Oxygen Post.PHP SQL Injection Vulnerability
BugTraq ID: 17324
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17324
Summary:
Oxygen is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Oxygen versions 1.1.3 and prior are reported to be affected.

13. MediaSlash Gallery Index.PHP Remote File Include Vulnerability
BugTraq ID: 17323
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17323
Summary:
MediaSlash Gallery is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

14. VNews Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17317
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17317
Summary:
VNews is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

15. X-Changer Multiple SQL Injection Vulnerabilities
BugTraq ID: 17322
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17322
Summary:
X-Changer is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 0.20 is reported to be vulnerable. Other versions may be affected as well.

16. Apple Mac OS X ImageIO Remote Denial Of Service Vulnerability
BugTraq ID: 17321
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17321
Summary:
ImageIO is susceptible to a remote denial-of-service vulnerability. This issue is do to a failure to properly process malicious image files.

This issue allows remote users to crash applications that use the ImageIO API, denying further service to users.

17. VBook Index.PHP SQL Injection Vulnerability
BugTraq ID: 17320
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17320
Summary:
VBook is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

VBook version 2.0 is reported affected. Other versions may be vulnerable as well.

18. Peercast.org PeerCast Remote Buffer Overflow Vulnerability
BugTraq ID: 17040
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17040
Summary:
PeerCast is prone to a remote buffer-overflow vulnerability. This can facilitate a remote compromise due to arbitrary code execution.

PeerCast 0.1215 and prior versions are vulnerable.

19. VBook Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17319
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17319
Summary:
VBook is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

20. VNews Multiple SQL Injection Vulnerabilities
BugTraq ID: 17316
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17316
Summary:
VNews is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 1.2 is reported to be vulnerable. Other versions may be affected as well.

21. VWar Functions_Admin.PHP Remote File Include Vulnerability
BugTraq ID: 17315
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17315
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.


Versions prior to 1.5.0 R11 are vulnerable.

22. HP Tru64 NLSPATH Environment Variable Local Buffer Overflow Vulnerability
BugTraq ID: 5647
Remote: No
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/5647
Summary:
Tru64 is a commercially available UNIX operating system. Tru64 was originally developed by Digital and is now distributed and maintained by HP.

A buffer overflow has been discovered in a number of Tru64 binaries. Attackers may exploit this via an overly long value for the NLSPATH environment variable. Because of this flaw, a local attacker may be able to execute arbitrary instructions. As a result, the attacker may be able to execute malicious code and elevate privileges.

23. PHPNewsManager Multiple SQL Injection Vulnerabilities
BugTraq ID: 17301
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17301
Summary:

phpNewsManager is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

phpNewsManager 1.48 is vulnerable; other versions may also be affected.

24. InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability
BugTraq ID: 11555
Remote: Yes
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/11555
Summary:
DynaZip is susceptible to a stack-based buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

A remote attacker may exploit this vulnerability to execute arbitrary instructions in the context of an application that uses the affected library.

The following applications are known to include vulnerable versions of the affected library:

- RealPlayer for Microsoft Windows
- RealOne Player for Microsoft Windows
- CheckMark Payroll 2004/2005.

Other applications also likely include the vulnerable library.

25. Sun Cluster SunPlex Manager Unauthorized File Access Vulnerability
BugTraq ID: 17313
Remote: No
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17313
Summary:
Sun Cluster is prone to a vulnerability that can allow local users to gain unauthorized access to files that may contain sensitive information.

An attacker may exploit this issue to gain access to sensitive information, which may aid in other attacks against a vulnerable computer.

This issue affects Sun Cluster 3.1 4/04 for Solaris 8 and 9.

26. NetBSD If_Bridge(4) Kernel Memory Disclosure Vulnerability
BugTraq ID: 17312
Remote: No
Last Updated: 2006-03-30
Relevant URL: http://www.securityfocus.com/bid/17312
Summary:

NetBSD 'if_bridge(4)' is prone to a kernel memory-disclosure vulnerability.

This issue can allow a user-space process to obtain portions of kernel memory, which may aid in further attacks against the vulnerable computer.

27. Apple Mac OS X Intel-Based Local Authentication Bypass Vulnerability
BugTraq ID: 17364
Remote: No
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17364
Summary:
Mac OS X running on Intel-based Macintosh computers is prone to an authentication-bypass vulnerability.

A local attacker can exploit this issue to bypass the firmware password and gain access to Single User Mode.

28. Util-VServer SUEXEC Privilege Escalation Weakness
BugTraq ID: 17361
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17361
Summary:
The util-vserver package for the Linux-VServer project is susceptible to a privilege-escalation weakness.

This issue allows remote attackers that exploit latent vulnerabilities in services to potentially gain superuser privileges in a guest virtual server. This may aid them in further attacks.

29. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:

PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

30. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.

Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.

Sendmail versions prior to 8.13.6 are vulnerable to this issue.

31. Zope RestructuredText File Include Vulnerability
BugTraq ID: 15082
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/15082
Summary:
Zope is prone to a file-include vulnerability in the docutils module because Zope honors file-inclusion directives in RestructuredText objects by default.

An attacker can exploit this vulnerability to include and execute arbitrary Zope code in the security context of the Zope server.

32. PHPNuke-Clan Functions_Common.PHP Remote File Include Vulnerability
BugTraq ID: 17356
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17356
Summary:
PHPNuke-Clan is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 3.0.1; other versions may also be vulnerable.

This issue may be related to that discussed in BID 17290 (VWar Functions_install.PHP Remote File Include Vulnerability).

33. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 15411
Remote: No
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/15411
Summary:
PHP cURL and GD are prone to multiple safe_mode and open_basedir restriction-bypass vulnerabilities. Successful exploitation could allow an attacker to access sensitive information.

This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.

34. Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability
BugTraq ID: 14168
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/14168
Summary:
Net-SNMP is prone to a remote denial-of-service vulnerability. The issue is exposed when Net-SNMP is configured to have an open stream-based protocol port, such as TCP.

The exact details describing this issue are not available. This BID will be updated when further details are made available.

35. Info-ZIP UnZip CHMod File Permission Modification Race Condition Weakness
BugTraq ID: 14450
Remote: No
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/14450
Summary:
Info-ZIP unzip is reported prone to a security weakness. The issue occurs only when an archive is extracted into a world- or group-writable directory. Reportedly, unzip employs non-atomic procedures to write a file and later to change the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.

36. VWar Functions_install.PHP Remote File Include Vulnerability
BugTraq ID: 17290
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17290
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.


Versions 1.5.0 and prior are vulnerable; other versions may also be affected.

37. Squid FTP Server Response Denial Of Service Vulnerability
BugTraq ID: 15157
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/15157
Summary:
Squid is prone to a remote denial-of-service vulnerability. This is due to a flaw in the way that Squid communicates with FTP servers.

This issue has been reported in Squid version 2.5 and prior.

38. Limbo CMS Frontpage Arbitrary PHP Command Execution Vulnerability
BugTraq ID: 16902
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/16902
Summary:

Limbo CMS is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary PHP commands on the vulnerable computer in the context of the webserver process.

39. Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
BugTraq ID: 12960
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/12960
Summary:
Microsoft Jet Database Engine is vulnerable to a buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check the contents of user-supplied database files.

Attackers may exploit this vulnerability to execute arbitrary machine code in the context of the victim user trying to access a malicious Jet database file.

This vulnerability is reported to reside in the 'msjet40.dll' library, version 4.00.8618.0. Older versions may also be affected. The 'msjetole40.dll' OLE (Object Linking and Embedding) library is reportedly immune to this vulnerability.

The Backdoor.Hesive trojan is reported to employ this vulnerability to install itself on vulnerable computers. Please see the web reference for further information.

40. ARJ Software UNARJ Remote Buffer Overflow Vulnerability
BugTraq ID: 11665
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/11665
Summary:
A remote buffer overflow vulnerability affects ARJ Software's unarj.  This issue is caused by a failure of the application to carry out sufficient bounds checking on user-supplied strings prior to processing.

A remote attacker may leverage this issue to execute arbitrary code with the privileges of a user that process a malicious file with the affected application.  This may facilitate unauthorized access or privilege escalation.

41. Winace UnAce ACE Archive Remote Directory Traversal Vulnerability
BugTraq ID: 12628
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/12628
Summary:
A remotely exploitable client-side directory-traversal vulnerability affects Winace unace. The application fails to properly sanitize file and directory names contained within malicious ACE format archives.

An attacker may leverage this issue by distributing malicious ACE archives to unsuspecting users. This issue will allow an attacker to write files to arbitrary locations on the filesystem with the privileges of an unsuspecting user that extracts the malicious ACE archive.

42. Winace UnAce ACE Archive Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 12630
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/12630
Summary:
Multiple remotely exploitable client-side buffer-overflow vulnerabilities reportedly affect WinAce unace. These issues are due to the application's failure to properly validate the length of user-supplied strings before copying them into static process buffers.

An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

**Update: Versions 2.x of unace are reportedly affected by one of these issues as well. The vulnerability has been confirmed in 2.04, 2.2, and 2.5.

43. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
BugTraq ID: 15009
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/15009
Summary:
University of Washington IMAP is prone to a buffer-overflow vulnerability. This issue is exposed when the application parses mailbox names.

If successful, an attacker may execute arbitrary code in the context of the server process. Note that to exploit this issue, the attacker must first authenticate to the service.

44. Samba Machine Trust Account Local Information Disclosure Vulnerability
BugTraq ID: 17314
Remote: No
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17314
Summary:
Samba is susceptible to a local information-disclosure vulnerability. This issue is due to a design error that potentially leads to sensitive information being written to log files. This occurs when the debugging level has been set to 5 or higher.

This issue allows local attackers to gain access to the machine trust account of affected computers. Attackers may then impersonate the affected server in the domain. By impersonating the member server, attackers may gain access to further sensitive information, including the users and groups in the domain; other information may also be available. This may aid attackers in further attacks.

Samba versions 3.0.21 through to 3.0.21c that use the 'winbindd' daemon are susceptible to this issue.

45. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is susceptible to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.

This issue allows remote attackers to use affected computers in stealth network port and trust scans.

The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.

46. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 17310
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17310
Summary:
Dia is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.

These issues allow remote attackers to execute arbitrary machine code in the context of the user running the affected application to open attacker-supplied malicious XFig files.

47. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
BugTraq ID: 17171
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17171
Summary:

FreeRADIUS is prone to an authentication-bypass vulnerability. The issue exists in the EAP-MSCHAPv2 state machine. Bypassing authentication could also cause the server to crash.

FreeRADIUS versions from 1.0.0 to 1.1.0 are vulnerable.

48. FreeRADIUS Multiple Remote Vulnerabilities
BugTraq ID: 14775
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/14775
Summary:
FreeRADIUS is susceptible to multiple remote vulnerabilities.

- Memory-handling vulnerabilities. These issues may allow remote attackers to crash affected services or possibly execute arbitrary machine code in the context of the vulnerable application.

- File descriptor leak. Attackers may exploit this to gain access to files that they may not normally have access to.

- The LDAP module contains a flaw whereby attacker-specified data may be passed on to the configured LDAP database without proper input sanitization.

These issues are all reported to affect version 1.0.4 of FreeRADIUS; previous versions are also likely vulnerable to one or more of these issues.

**Update: The vendor has posted a response to these issues. Please see "Response to Suse Audit Report on FreeRADIUS" for further details.

49. Multiple LHA Buffer Overflow/Directory Traversal Vulnerabilities
BugTraq ID: 10243
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/10243
Summary:
LHA has been reported prone to multiple vulnerabilities that may allow a malicious archive to execute arbitrary code or corrupt arbitrary files when the archive is operated on.

The first issues reported have been assigned the CVE candidate identifier (CAN-2004-0234). It is reported that LHA is prone to two stack based buffer overflow vulnerabilities. These vulnerabilities may be exploited to execute  supplied instructions with the privileges of the user who invoked the affected LHA utility.

The second set of issues has been assigned CVE candidate identifier (CAN-2004-0235). In addition to the buffer overflow vulnerabilities that were reported, LHA has been reported prone to a several directory traversal issues. These directory traversal vulnerabilities may likely be exploited to corrupt/overwrite files in the context of the user who is running the affected LHA utility.

**It has been reported that issue may also cause a denial of service condition in the ClearSwift MAILsweeper products due to code dependency.

**Update: Many F-Secure Anti-Virus products are also reported to be prone to the buffer overflow vulnerability.

50. Zoo Misc.c Buffer Overflow Vulnerability
BugTraq ID: 16790
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/16790
Summary:
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.

An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.

51. StoreBackup Insecure Temporary File Creation Vulnerability
BugTraq ID: 14985
Remote: No
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/14985
Summary:
storeBackup creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to view files and obtain privileged information.  The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.

Exploitation would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may result in sensitive configuration files being overwritten.  This may result in a denial of service; other attacks may also be possible.

52. MediaWiki Encoded Page Link HTML Injection Vulnerability
BugTraq ID: 17269
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17269
Summary:
MediaWiki is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

53. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
BugTraq ID: 17372
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17372
Summary:
Kaffiene is reportedly affected by a remote buffer overflow vulnerability.  The problem presents itself due to insufficient boundary checks on user-supplied strings prior to copying them into finite stack-based buffers.

An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.

54. AngelineCMS Loadkernel.PHP Remote File Include Vulnerability
BugTraq ID: 17371
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17371
Summary:
AngelineCMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.8.1 is vulnerable; other versions may also be affected.

55. Xine-Lib Malformed MPEG Stream Buffer Overflow Vulnerability
BugTraq ID: 17370
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17370
Summary:
Xine-lib is susceptible to a buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds check user-supplied input data prior to copying it to an insufficiently-sized memory buffer.

Successful exploits allow remote attackers to execute arbitrary machine code in the context of the affected application.

Xine-lib version 1.1.1 is reportedly affected. Other versions may also be affected, as well as all applications that use a vulnerable version of the library.

56. Doomsday Multiple Remote Format String Vulnerabilities
BugTraq ID: 17369
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17369
Summary:

Doomsday is prone to multiple remote format string vulnerabilities.

These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary code in the context of the vulnerable application or crash the affected game server, effectively denying service to legitimate users.

57. MyBulletinBoard Email BBCode Tag HTML Injection Vulnerability
BugTraq ID: 17368
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17368
Summary:
MyBulletinBoard is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

58. HP Color LaserJet 2500/4600 Toolbox Directory Traversal Vulnerability
BugTraq ID: 17367
Remote: Yes
Last Updated: 2006-04-04
Relevant URL: http://www.securityfocus.com/bid/17367
Summary:
The HP Color LaserJet 2500/4600 Toolbox is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

59. MySQL Query Logging Bypass Vulnerability
BugTraq ID: 16850
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/16850
Summary:
MySQL is susceptible to a query-logging-bypass vulnerability. This issue is due to a discrepency between the handling of NULL bytes in input data.

This issue allows attackers to bypass the query-logging functionality of the database so they can cause malicious SQL queries to be improperly logged. This may help them hide the traces of malicious activity from administrators.

This issue affects MySQL version 5.0.18; other versions may also be affected.

60. PHP Html_Entity_Decode() Information Disclosure Vulnerability
BugTraq ID: 17296
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17296
Summary:
PHP 'html_entity_decode()' function is prone to an information-disclosure vulnerability. This issue arises when a script using the function accepts data from a remote untrusted source and returns the function's result to an attacker.

Information that the attacker gathers by exploiting this vulnerability may aid in other attacks.

PHP versions prior to 5.1.3-RC1 are vulnerable to this issue.

61. LucidCMS Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17360
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17360
Summary:
LucidCMS is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.


Version 2.0.0 RC4 is reported to be vulnerable; other versions may also be affected.

62. Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
BugTraq ID: 15102
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15102
Summary:
GNU wget and cURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the applications to do proper bounds checking on user-supplied data before using it in a memory copy operation.

An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.

Exploitation of this vulnerability requires that NTLM authentication be enabled in the affected clients.

63. WebAPP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17359
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17359
Summary:
WebAPP is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

64. Exponent CMS Banner Module Arbitrary Script Execution Vulnerability
BugTraq ID: 17357
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17357
Summary:
Exponent CMS is prone to an arbitrary script-execution vulnerability. The application fails to properly sanitize user-supplied input to its banner and image-upload portion.

An attacker can include remote script code and execute it in the context of an affected server.

Versions prior to 0.96.5 RC 1 are reported to be vulnerable.

65. GNU Mailman Attachment Scrubber Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 17311
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17311
Summary:
GNU Mailman is prone to denial-of-service attacks. This issue affects the attachment-scrubber utility.

The vulnerability could be triggered by mailing-list posts and will affect the availability of mailing lists hosted by the application.

This issue presents itself only when Mailman is used in conjunction with Python email version 2.5.

66. Horde MIME Viewer Inline Attachment HTML Injection Vulnerability
BugTraq ID: 15535
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15535
Summary:
Horde MIME Viewer is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

67. Basic Analysis and Security Engine Base_maintenance.PHP Authentication Bypass Vulnerability
BugTraq ID: 17354
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17354
Summary:
Basic Authentication and Security Engine is prone to an unspecified authentication-bypass vulnerability. An attacker could exploit this to gain unauthorized access to sensitive information.

BASE versions prior to 1.2.4 are prone to this issue.

68. VWar Get_header.PHP Remote File Include Vulnerability
BugTraq ID: 17358
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17358
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.


Versions 1.5.0 and prior are vulnerable; other versions may also be affected.

69. ReloadCMS User-Agent HTML Injection Vulnerability
BugTraq ID: 17353
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17353
Summary:

ReloadCMS is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

ReloadCMS 1.2.5 is reported to be vulnerable. Other versions may be affected as well.

70. PHPBB Profile.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17355
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17355
Summary:

phpBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects version 2.0.19; other versions may also be vulnerable.

71. AWebBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17352
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17352
Summary:
aWebBB is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

72. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
BugTraq ID: 16710
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/16710
Summary:
Libapreq2 is prone to a vulnerability that may allow attackers to trigger a denial-of-service condition.


Libapreq2 versions prior to 2.0.7 are vulnerable.

73. AN HTTPD Source Disclosure Vulnerability
BugTraq ID: 17350
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17350
Summary:
A problem with AN HTTPD results in the disclosure of the source code of scripts. This allows attackers to gain unauthorized access to sensitive information, potentially aiding them in further attacks.

This issue affects AN HTTPD 1.42n on Windows. Other versions may be vulnerable as well.

74. Bugzero Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17351
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17351
Summary:
Bugzero is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

75. ISP Site Man Admin_Login.ASP SQL Injection Vulnerability
BugTraq ID: 17347
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17347
Summary:
Site Man is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

All versions of Site Man are considered to be vulnerable.

76. PHPSelect Submit-A-Link HTML Injection Vulnerability
BugTraq ID: 17348
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17348
Summary:
Submit-A-Link is prone to an HTML-injection vulnerability. The script fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

All versions of Submit-A-Link are considered to be vulnerable.

77. Blank'N'Berg Directory Traversal Vulnerability
BugTraq ID: 17345
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17345
Summary:
Blank'N'Berg is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

Blank'N'Berg 0.2 is reportedly vulnerable.

78. Blank'N'Berg Cross-Site Scripting Vulnerability
BugTraq ID: 17346
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17346
Summary:
Blank'N'Berg is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Blank'N'Berg 0.2 is reportedly vulnerable.

79. Claroline Rqmkhtml.PHP Information Disclosure Vulnerability
BugTraq ID: 17343
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17343
Summary:

Claroline is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

Claroline versions 1.7.4 and prior are vulnerable.

80. Claroline RQMKHTML.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17344
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17344
Summary:
Claroline is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

81. Apache Struts Multiple Remote Vulnerabilities
BugTraq ID: 17342
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17342
Summary:

Apache Struts is susceptible to multiple remote vulnerabilities.

The following issues were identified:

- A cross-site scripting vulnerability. An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

- A denial-of-service vulnerability. An attacker may leverage this issue to crash an affected web application, denying further service to legitimate users.

- A validation-bypass vulnerability. An attacker may leverage this issue to bypass validation and authentication checks in a web application. The exact consequences of this issue depend on the nature of the targeted application.

Apache Struts versions prior to 1.2.9 are affected by these issues.

82. Claroline ScormExport.inc.PHP File Include Vulnerability
BugTraq ID: 17341
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17341
Summary:
Claroline is affected by a remote file-include vulnerability.

An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer or a remote location with the privileges of the webserver process. This may potentially facilitate unauthorized access.

83. Mantis Multiple Remote Vulnerabilities
BugTraq ID: 15227
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15227
Summary:
Mantis is prone to multiple remote vulnerabilities. These issues can allow attackers to access sensitive information, execute arbitrary PHP scripts, and carry out cross-site scripting and SQL-injection attacks.

These issues occur in Mantis versions prior to 0.19.3.

84. Lynx URI Handlers Arbitrary Command Execution Vulnerability
BugTraq ID: 15395
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15395
Summary:
Lynx is prone to an arbitrary command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.

A remote attacker can exploit this vulnerability by tricking a victim user into following a malicious link, thus enabling the attacker to execute arbitrary commands in the context of the victim user.

85. Google Search Appliance ProxyStyleSheet Multiple Remote Vulnerabilities
BugTraq ID: 15509
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15509
Summary:
The Google Search Appliance 'proxystylesheet' feature is susceptible to multiple remote vulnerabilities. These issues are due to a failure of the devices to securely implement user-specified XSLT style sheets when displaying search results.

These flaws allow attackers to execute cross-site scripting, information disclosure, and remote command-execution attacks against the users of affected devices or against the devices themselves.

Attackers may leverage the cross-site scripting issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Attackers may leverage the information-disclosure issues to determine the existence of arbitrary files on the targeted computer or to port-scan networks that are accessible to affected devices. This may aid attackers in further attacks.

Attackers may leverage the command-execution vulnerability to execute arbitrary commands as an unprivileged user.

The Google Mini Search Appliance is confirmed vulnerable to these issues. The Google Search Appliance may also be affected.

86. RedCMS Multiple Input Validation Vulnerabilities
BugTraq ID: 17336
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17336
Summary:
RedCMS is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

The application is prone to HTML-injection and SQL-injection vulnerabilities. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Arbitrary script code may also be executed in the browser of an unsuspecting user in the context of the affected site; this may help the attacker steal cookie-based authentication credentials and launch other attacks.

87. Softbiz Image Gallery Multiple SQL Injection Vulnerabilities
BugTraq ID: 17339
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17339
Summary:
Softbiz Image Gallery is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

88. Hitachi Groupmax World Wide Web Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 17337
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17337
Summary:
Hitachi Groupmax World Wide Web is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

89. DbbS Topics.PHP SQL Injection Vulnerability
BugTraq ID: 17338
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17338
Summary:
DbbS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

DbbS versions 2.0-alpha and prior are reported to be affected.

90. Warcraft III Replay Parser for PHP Index.PHP Remote File Include Vulnerability
BugTraq ID: 17334
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17334
Summary:
Warcraft III Replay Parser for PHP is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Warcraft III Replay Parser for PHP 1.8c is reported to be vulnerable. Other versions may be affected as well.

91. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
BugTraq ID: 15429
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15429
Summary:
The 'gdk-pixbuf' and 'gtk2' libraries are prone to a denial-of-service vulnerability. This issue occurs when an application using one of the affected libraries handles a malformed XPM image file.

Exploitation could cause an application using a vulnerable library to enter an infinite loop, resulting in a denial of service.

92. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
BugTraq ID: 15435
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15435
Summary:
The gdk-pixbuf and gtk2 packages are prone to a buffer overflow. When an application that uses a vulnerable library processes a malformed XPM image file, it results in a heap-based buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the victim user.

93. V-creator Remote Shell Code Execution Vulnerability
BugTraq ID: 17328
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17328
Summary:
The v-creator application is prone to a remote shell code-execution vulnerability.

This issue allows attackers to execute arbitrary shell commands with the privileges of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Versions 1.3-pre2 and prior of v-creator are vulnerable; other versions may also be affected.

94. GDK-Pixbuf XPM Images Integer Overflow Vulnerability
BugTraq ID: 15428
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/15428
Summary:
A remote integer-overflow vulnerability affects gdk-pixbuf.

When an application that uses the vulnerable library processes a malformed XPM file, the application will crash, denying service to legitimate users. An attacker may also be able to exploit this issue to execute arbitrary code with the privileges of the application using the vulnerable library.

95. QLnews Multiple Input Validation Vulnerabilities
BugTraq ID: 17335
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17335
Summary:
QLnews is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

The application is prone to HTML-injection and remote PHP code execution vulnerabilities.

QLnews versions 1.2 are vulnerable to these issues; other versions may also be affected.

96. SiteSearch Indexer Searchresults.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 17332
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17332
Summary:
SiteSearch Indexer is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

97. BusyBox Insecure Password Hash Weakness
BugTraq ID: 17330
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17330
Summary:
BusyBox is susceptible to an insecure password-hash weakness. This issue is due to a design flaw that results in password hashes being created in an insecure manner.

This issue allows attackers to use precomputed password hashes in brute-force attacks if they can gain access to password hashes by some means (such as exploiting another vulnerability).

98. ZDaemon Multiple Remote Vulnerabilities
BugTraq ID: 17340
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17340
Summary:

ZDaemon is prone to multiple remote vulnerabilities.

A buffer overflow vulnerability exists in the 'is_client_wad_ok' function.

A remote denial of service condition also affects the server.

ZDaemon 1.08.01 and prior versions are affected.

99. qliteNews Multiple SQL Injection Vulnerabilities
BugTraq ID: 17333
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17333
Summary:
The qliteNews script is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Version 2005.07.01 is reported to be vulnerable. Other versions may be affected as well.

100. GTD-PHP Multiple Input Validation Vulnerabilities
BugTraq ID: 17366
Remote: Yes
Last Updated: 2006-04-03
Relevant URL: http://www.securityfocus.com/bid/17366
Summary:
gtd-php is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Seven arrested in online fraud crackdown
By: Robert Lemos
An ongoing investigation, dubbed Operation Rolling Stone by the U.S. Secret Service, has turned up links to the massive debit-card breaches that have worried banks and consumers.
http://www.securityfocus.com/news/11385

2. Patches released for zero-day IE threat
By: Robert Lemos
UPDATE: As hundreds of malicious Web sites attempt to exploit the most critical of two Internet Explorer flaws disclosed last week, two third-party firms release fixes to nix the threat.<br />
See also: <a href="http://www.securityfocus.com/brief/174">Thousands download third-party patches</a>
http://www.securityfocus.com/news/11384

3. Check Point calls off Sourcefire buy
By: Robert Lemos
Citing an ongoing investigation into the deal by the U.S. Treasury Department, the companies decide to call it quits.
http://www.securityfocus.com/news/11382

4. Debit-card fraud underscores legal loopholes
By: Robert Lemos
UPDATE: Three major data leaks in the last six months are likely responsible for a recent spate of debit-card fraud, but in two cases, no one has come forward to take responsibility. Under current state laws, such silence may be legal.
http://www.securityfocus.com/news/11381

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Technical Support Engineer, Columbia
http://www.securityfocus.com/archive/77/429867

2. [SJ-JOB] Manager, Information Security, Columbia
http://www.securityfocus.com/archive/77/429878

3. [SJ-JOB] Technical Support Engineer, Columbia
http://www.securityfocus.com/archive/77/429882

4. [SJ-JOB] Manager, Information Security, Schaumburg
http://www.securityfocus.com/archive/77/429876

5. [SJ-JOB] Manager, Information Security, Costa Mesa
http://www.securityfocus.com/archive/77/429880

6. [SJ-JOB] Incident Handler, Edison
http://www.securityfocus.com/archive/77/429883

7. [SJ-JOB] Security Consultant, NJ, New York, D.C.
http://www.securityfocus.com/archive/77/429886

8. [SJ-JOB] Manager, Information Security, Allen
http://www.securityfocus.com/archive/77/429879

9. [SJ-JOB] Sr. Security Engineer, Dublin
http://www.securityfocus.com/archive/77/429806

10. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/429805

11. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/429807

12. [SJ-JOB] Security Consultant, Allen
http://www.securityfocus.com/archive/77/429800

13. [SJ-JOB] Director, Information Security, Allen
http://www.securityfocus.com/archive/77/429796

14. [SJ-JOB] Sales Engineer, Dallas
http://www.securityfocus.com/archive/77/429801

15. [SJ-JOB] Security Engineer, Allen
http://www.securityfocus.com/archive/77/429803

16. [SJ-JOB] Application Security Architect, Cleveland / Independence
http://www.securityfocus.com/archive/77/429804

17. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/429794

18. [SJ-JOB] Sr. Security Analyst, Costa Mesa
http://www.securityfocus.com/archive/77/429795

19. [SJ-JOB] Sr. Security Analyst, Schaumburg
http://www.securityfocus.com/archive/77/429799

20. [SJ-JOB] Sr. Security Analyst, Allen
http://www.securityfocus.com/archive/77/429797

21. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/429798

22. [SJ-JOB] Security Architect, Jersey City
http://www.securityfocus.com/archive/77/429676

23. [SJ-JOB] Developer, Idaho Falls
http://www.securityfocus.com/archive/77/429677

24. [SJ-JOB] Sr. Security Engineer, Charlotte
http://www.securityfocus.com/archive/77/429672

25. [SJ-JOB] Sr. Security Engineer, Chantilly
http://www.securityfocus.com/archive/77/429674

26. [SJ-JOB] Security Architect, Schaumburg
http://www.securityfocus.com/archive/77/429675

27. [SJ-JOB] Security Consultant, New York City
http://www.securityfocus.com/archive/77/429669

28. [SJ-JOB] Security Engineer, Plantation
http://www.securityfocus.com/archive/77/429670

29. [SJ-JOB] Certification & Accreditation Engineer, Columbia
http://www.securityfocus.com/archive/77/429671

30. [SJ-JOB] Developer, Idaho Falls
http://www.securityfocus.com/archive/77/429519

31. [SJ-JOB] Threat Analyst, Idaho Falls
http://www.securityfocus.com/archive/77/429516

32. [SJ-JOB] Training / Awareness Specialist, Idaho Falls
http://www.securityfocus.com/archive/77/429517

33. [SJ-JOB] Management, Idaho Falls
http://www.securityfocus.com/archive/77/429518

34. [SJ-JOB] Threat Analyst, Idaho Falls
http://www.securityfocus.com/archive/77/429543

35. [SJ-JOB] Security Engineer, Plantation
http://www.securityfocus.com/archive/77/429409

36. [SJ-JOB] Security Researcher, Anywhere in the World
http://www.securityfocus.com/archive/77/429410

37. [SJ-JOB] Application Security Architect, Indianapolis
http://www.securityfocus.com/archive/77/429404

38. [SJ-JOB] Security Architect, Portsmouth
http://www.securityfocus.com/archive/77/429406

39. [SJ-JOB] Security Engineer, Lanham
http://www.securityfocus.com/archive/77/429408

40. [SJ-JOB] Application Security Architect, Portsmouth
http://www.securityfocus.com/archive/77/429399

41. [SJ-JOB] Certification & Accreditation Engineer, DC
http://www.securityfocus.com/archive/77/429405

42. [SJ-JOB] Security Researcher, Idaho Falls
http://www.securityfocus.com/archive/77/429407

43. [SJ-JOB] Security Engineer, Idaho Falls
http://www.securityfocus.com/archive/77/429400

44. [SJ-JOB] Security Consultant, Reading
http://www.securityfocus.com/archive/77/429173

45. [SJ-JOB] Application Security Architect, London
http://www.securityfocus.com/archive/77/429171

46. [SJ-JOB] Manager, Information Security, London
http://www.securityfocus.com/archive/77/429172

47. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/429175

48. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/429170

49. [SJ-JOB] Forensics Engineer, Falls Church
http://www.securityfocus.com/archive/77/429163

50. [SJ-JOB] Information Assurance Engineer, Falls Church
http://www.securityfocus.com/archive/77/429178

51. [SJ-JOB] Certification & Accreditation Engineer, Arlington    (Crystal City)
http://www.securityfocus.com/archive/77/429156

V.   INCIDENTS LIST SUMMARY
---------------------------
1. What a strange route (The DoD inside)!
http://www.securityfocus.com/archive/75/429638

2. Win2k Machine contacting Root Server???
http://www.securityfocus.com/archive/75/428630

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Outlook Express ; UTF-7 ; References header field problem
http://www.securityfocus.com/archive/82/429884

2. Black Hat Call for Papers and Registration now open
http://www.securityfocus.com/archive/82/429862

3. mpg123 DoS ... It receives a SIGSEGV.
http://www.securityfocus.com/archive/82/429713

4. Black Hat Call for Papers and Registration now open
http://www.securityfocus.com/archive/82/429493

5. Beating memory address randomization (secuirty) features in Unix/Linux
http://www.securityfocus.com/archive/82/429176

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. New IE flaw and exploit sites/migration to non-MS browser
http://www.securityfocus.com/archive/88/429472

2. SecurityFocus Microsoft Newsletter #284
http://www.securityfocus.com/archive/88/429365

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. IPtables and C programming??
http://www.securityfocus.com/archive/91/429848

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Watchfire

Today's hackers exploit web applications to expose, embarrass and even steal. Firewalls and SSL may be commonplace but recent studies indicate 75% of websites remain vulnerable to attack. Watchfire's "Addressing Challenges in Application Security" whitepaper, explains what to do and provides a guideline to improving your own application security. Download this whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000003Stu