SecurityFocus Newsletter #345

Peter Laborge <[email protected]> Tue, 11 Apr 2006 15:25:20 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #345
----------------------------------------

This Issue is Sponsored By: SPI Dynamics

ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000CGKl

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. This Means Warcraft!
        2. Two attacks against VoIP
II.   BUGTRAQ SUMMARY
        1. VBook Multiple Cross-Site Scripting Vulnerabilities
        2. Clever Copy Connect.INC Information Disclosure Vulnerability
        3. Microsoft Internet Explorer Invalid HTML Parsing Code Execution Vulnerability
        4. JetPhoto Multiple Cross-Site Scripting Vulnerabilities
        5. SIRE Lire.PHP Remote File Include Vulnerability
        6. APT-webshop Modules.PHP Multiple SQL Injection Vulnerabilities
        7. Easy Software Products CUPS HTTP GET Denial Of Service Vulnerability
        8. MyBulletinBoard Newthread.PHP HTML Injection Vulnerability
        9. SPIP Spip_login.PHP Remote File Include Vulnerability
        10. ADOdb Server.PHP SQL Injection Vulnerability
        11. SCO OpenServer Backupsh Local Buffer Overflow Vulnerability
        12. JBook Index.PHP Cross-Site Scripting Vulnerability
        13. PHPWebGallery Multiple Cross-Site Scripting Vulnerabilities
        14. Simple Machines X-Forwarded-For HTML Injection Vulnerability
        15. phpMyForum Index.PHP Multiple Cross-Site Scripting Vulnerabilities
        16. TalentSoft Web+ Shop Deptname Parameter Cross-Site Scripting Vulnerability
        17. Sudo Python Environment Variable Handling Security Bypass Vulnerability
        18. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
        19. PHP File Upload GLOBAL Variable Overwrite Vulnerability
        20. AWeb's Scripts Seller Buy.PHP Authorization Bypass Vulnerability
        21. AWeb's Banner Generator Cross-Site Scripting Vulnerability
        22. MPlayer Multiple Integer Overflow Vulnerabilities
        23. SCO UnixWare PPP Prompt Local Buffer Overflow Vulnerability
        24. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
        25. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
        26. Tony Cook Imager JPEG and TGA Images Denial Of Service Vulnerability
        27. PHPList Index.PHP Local File Include Vulnerability
        28. Clansys Index.PHP SQL Injection Vulnerability
        29. CenterICQ Malformed Packet Handling Remote Denial of Service Vulnerability
        30. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
        31. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
        32. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
        33. Linux Kernel ELF Core Dump Local Buffer Overflow Vulnerability
        34. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
        35. Linux Kernel IA32 ExecVE Local Buffer Overflow Vulnerability
        36. Linux Kernel Elf Binary Loading Local Denial of Service Vulnerability
        37. Linux Kernel Process Spawning Race Condition Environment Variable Disclosure Vulnerability
        38. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
        39. Linux Kernel Multiple Vulnerabilities
        40. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
        41. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
        42. Linux Kernel Local MEMLOCK RLIMIT Bypass Denial Of Service Vulnerability
        43. Linux Kernel __keyring_search_one Local Denial of Service Vulnerability
        44. SmartISoft phpListPro Config.PHP Remote File Include Vulnerability
        45. PNMToPNG Alphas_Of_Color Buffer Overflow Vulnerability
        46. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
        47. Linux Kernel SYSFS_Write_File Local Integer Overflow Vulnerability
        48. VBook Index.PHP SQL Injection Vulnerability
        49. AzDGVote Remote File Include Vulnerability
        50. Linux Kernel Multiple Local Vulnerabilities
        51. Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
        52. Microsoft Windows Media Player Bitmap Handling Buffer Overflow Vulnerability
        53. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
        54. Microsoft Internet Explorer Unspecified Remote HTA Execution Vulnerability
        55. Microsoft Internet Explorer Script Action Handler Buffer Overflow Vulnerability
        56. Clam AntiVirus ClamAV Multiple Vulnerabilities
        57. Microsoft Windows XP Self-Executing Folder Vulnerability
        58. Zlib Compression Library Buffer Overflow Vulnerability
        59. RealNetworks Multiple Products Multiple Buffer Overflow Vulnerabilities
        60. Zlib Compression Library Decompression Buffer Overflow Vulnerability
        61. OpenVPN Client Remote Code Execution Vulnerability
        62. NetPBM PNMToPNG Long Text Line Buffer Overflow Vulnerability
        63. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
        64. Apple Mac OS X Security Update 2006-001 Multiple Vulnerabilities
        65. PHP PHPInfo Cross-Site Scripting Vulnerability
        66. PHP Parse_Str Register_Globals Activation Weakness
        67. XMB Forum Flash Video Cross-Site Scripting Vulnerability
        68. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
        69. VWar Admin.PHP Remote File Include Vulnerability
        70. ShopWeezle Multiple SQL Injection Vulnerabilities
        71. KAME Racoon Malformed ISAKMP Packet Headers Denial of Service Vulnerability
        72. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
        73. Gallery Unspecified Cross-Site Scripting Vulnerability
        74. Matt Wright Guestbook Guestbook.PL Multiple HTML Injection Vulnerabilities
        75. Fbida FBGS Insecure Temporary File Creation Vulnerability
        76. XBrite Members.PHP SQL Injection Vulnerability
        77. Shadowed Portal Load.PHP Cross-Site Scripting Vulnerability
        78. Oracle Database Access Restriction Bypass Vulnerability
        79. SQuery LibPath Parameter Multiple Remote File Include Vulnerabilities
        80. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
        81. VegaDNS Multiple Input Validation Vulnerabilities
        82. Design Nation DNGuestbook Admin.PHP SQL Injection Vulnerabilities
        83. TUGZip Remote Directory Traversal Vulnerability
        84. SIRE Arbitrary File Upload Vulnerability
        85. Horde Help Viewer Remote PHP Code Execution Vulnerability
        86. Indexu Multiple Remote File Include Vulnerabilities
        87. Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
        88. PHPKIT Include.PHP SQL Injection Vulnerability
        89. SWSoft Confixx Jahr Parameter Cross-Site Scripting Vulnerability
        90. Blursoft Blur6ex Multiple Input Validation Vulnerabilities
        91. Microsoft Windows Shell COM Object Remote Code Execution Vulnerability
        92. Dokeos Viewtopic.PHP SQL Injection Vulnerability
        93. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
        94. Microsoft Internet Explorer Persistent Window Content Address Bar Spoofing Vulnerability
        95. JBook Form.PHP SQL Injection Vulnerabilities
        96. Microsoft Internet Explorer Popup Cross-Domain Information Disclosure Vulnerability
        97. Microsoft Internet Explorer Erroneous IOleClientSite Data Zone Bypass Vulnerability
        98. Microsoft Internet Explorer Double Byte Character Memory Corruption Vulnerability
        99. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
        100. Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability
III.  SECURITYFOCUS NEWS
        1. Groups argue over merits of flaw bounties
        2. Seven arrested in online fraud crackdown
        3. Patches released for zero-day IE threat
        4. Check Point calls off Sourcefire buy
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Auditor, Detroit
        2. [SJ-JOB] Auditor, New York
        3. [SJ-JOB] Security Product Marketing Manager, Sunnyvale
        4. [SJ-JOB] Security Consultant, Detroit
        5. [SJ-JOB] Security Auditor, Detroit
        6. [SJ-JOB] Auditor, Los Angeles
        7. [SJ-JOB] Security Consultant, Los Angeles
        8. [SJ-JOB] Security Auditor, Los Angeles
        9. [SJ-JOB] Technical Support Engineer, Riyad
        10. [SJ-JOB] Developer, Annapolis Junction
        11. [SJ-JOB] Account Manager, London
        12. [SJ-JOB] Security Consultant, New York
        13. [SJ-JOB] Sales Representative, San Francisco
        14. [SJ-JOB] Auditor, San Francisco
        15. [SJ-JOB] Security Auditor, San Francisco
        16. [SJ-JOB] Auditor, Columbus
        17. [SJ-JOB] Security Auditor, Columbus
        18. [SJ-JOB] Security Consultant, Baltimore
        19. [SJ-JOB] Auditor, Washington
        20. [SJ-JOB] Security Auditor, Washington
        21. [SJ-JOB] Security Consultant, Washington
        22. [SJ-JOB] Auditor, Baltimore
        23. [SJ-JOB] Security Consultant, Columbus
        24. [SJ-JOB] Auditor, Atlanta
        25. [SJ-JOB] Security Auditor, Baltimore
        26. [SJ-JOB] Security Consultant, Rome
        27. [SJ-JOB] Security Consultant, Richmond
        28. [SJ-JOB] Security Auditor, Richmond
        29. [SJ-JOB] Auditor, Richmond
        30. [SJ-JOB] Security Consultant, london
        31. [SJ-JOB] Sr. Security Engineer, Atlanta
        32. [SJ-JOB] Sr. Security Engineer, Bailey's Crossroads, Fairfax    County, VA
        33. [SJ-JOB] Sr. Security Analyst, London
        34. [SJ-JOB] Security Engineer, Reston/Herndon
        35. [SJ-JOB] Disaster Recovery Coordinator, Evansville
        36. [SJ-JOB] CHECK Team Leader, london
        37. [SJ-JOB] Security Engineer, London
        38. [SJ-JOB] Sr. Security Analyst, RTP
        39. [SJ-JOB] Manager, Information Security, Moncton
        40. [SJ-JOB] Security Engineer, washington
        41. [SJ-JOB] Sr. Security Analyst, Jersey City
        42. [SJ-JOB] Instructor, Boston
        43. [SJ-JOB] Technical Support Engineer, Columbia
        44. [SJ-JOB] Security System Administrator, Parsippany
        45. [SJ-JOB] Application Security Engineer, Mumbai
        46. [SJ-JOB] Disaster Recovery Coordinator, Shelton
        47. [SJ-JOB] Developer, Bhubaneswar
        48. [SJ-JOB] Security Consultant, San Francisco
        49. [SJ-JOB] Security Consultant, Chicago
        50. [SJ-JOB] Security Consultant, Philadelphia
        51. [SJ-JOB] Security Auditor, Philadelphia
        52. [SJ-JOB] Security Auditor, Chicago
        53. [SJ-JOB] Auditor, Philadelphia
        54. [SJ-JOB] Management, Slough
        55. [SJ-JOB] Security Consultant, Raleigh
        56. [SJ-JOB] Security Engineer, Rome
        57. [SJ-JOB] Auditor, Raleigh
        58. [SJ-JOB] Security Auditor, Raleigh
        59. [SJ-JOB] Auditor, Chicago
        60. [SJ-JOB] Auditor, Dallas
        61. [SJ-JOB] Security Auditor, Dallas
        62. [SJ-JOB] Security Consultant, Dallas
        63. [SJ-JOB] Sales Engineer, Portland
        64. [SJ-JOB] Sales Engineer, New York
        65. [SJ-JOB] Security Engineer, Eastern Iowa
        66. [SJ-JOB] Security System Administrator, Mumbai
        67. [SJ-JOB] Sales Engineer, Chicago
        68. [SJ-JOB] Technical Marketing Engineer, Redwood City
        69. [SJ-JOB] Technology Risk Consultant, Eastern Iowa
        70. [SJ-JOB] Application Security Engineer, Cupertino
        71. [SJ-JOB] Sr. Security Analyst, Metro Area
        72. [SJ-JOB] Account Manager, herdnon
        73. [SJ-JOB] Security Researcher, Chicago
        74. [SJ-JOB] Sales Engineer, Cincinnati or Indianapolis
        75. [SJ-JOB] Channel / Business Development, Chicago
        76. [SJ-JOB] Technology Risk Consultant, Chicago
        77. [SJ-JOB] Security Researcher, Chicago
        78. [SJ-JOB] Security Consultant, Various/ Winnipeg
        79. [SJ-JOB] Application Security Engineer, Dubai
        80. [SJ-JOB] Technology Risk Consultant, Chicago
        81. [SJ-JOB] Technology Risk Consultant, Chicago
        82. [SJ-JOB] Sr. Security Engineer, Austin
        83. [SJ-JOB] Management, Glasgow
        84. [SJ-JOB] Account Manager, Parsippany
        85. [SJ-JOB] Security Consultant, Various locations across UK
        86. [SJ-JOB] Account Manager, San Francisco
        87. [SJ-JOB] Account Manager, New York
        88. [SJ-JOB] Security Engineer, San Francisco
        89. [SJ-JOB] Security Engineer, San Jose
        90. [SJ-JOB] Account Manager, Chicago
        91. [SJ-JOB] Sales Representative, Chicago
        92. [SJ-JOB] Manager, Information Security, Los Angeles
        93. [SJ-JOB] Sales Representative, Atlanta
        94. [SJ-JOB] Sales Representative, New York
        95. [SJ-JOB] Sales Engineer, Herndon
        96. [SJ-JOB] Sales Representative, Herndon
        97. [SJ-JOB] Account Manager, Atlanta
        98. [SJ-JOB] Account Manager, New York
        99. [SJ-JOB] Manager, Information Security, New York
        100. [SJ-JOB] Director, Information Security, New York
        101. [SJ-JOB] Security Consultant, San Francisco
        102. [SJ-JOB] Security Auditor, Seattle
        103. [SJ-JOB] Security Engineer, Cambridge
        104. [SJ-JOB] Security Consultant, Seattle
        105. [SJ-JOB] Forensics Engineer, Midlands
        106. [SJ-JOB] Account Manager, South East England
        107. [SJ-JOB] Security Product Manager, Santa Clara
        108. [SJ-JOB] Sr. Product Manager, Sunnyvale
        109. [SJ-JOB] Disaster Recovery Coordinator, Fairfax
        110. [SJ-JOB] Security Consultant, Baltimore
        111. [SJ-JOB] Security Architect, Baltimore
        112. [SJ-JOB] Technical Support Engineer, Cupertino
        113. [SJ-JOB] Security Researcher, Various
        114. [SJ-JOB] Account Manager, Houston
        115. [SJ-JOB] Developer, Columbia
        116. [SJ-JOB] Sales Representative, San Mateo
        117. [SJ-JOB] Security Consultant, Boston
        118. [SJ-JOB] Security Consultant, Deerfield
V.    INCIDENTS LIST SUMMARY
        1. RATs in our Honeypot
        2. Bogon IPs traffic only seen by netflow, confined within a VLAN only
        3. They got me!!!
        4. What a strange route (The DoD inside)!
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Sourceforge.net XSS
        2. Myspace.com - Intricate Script Injection
        3. FW: Google Reader "preview" and "lens" script improper feed validation
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Adding Users via Web Interface
        2. SecurityFocus Microsoft Newsletter #285
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. Syncing iptables rules between two servers
        2. R: IPtables and C programming??
        3. IPtables and C programming??
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. This Means Warcraft!
By Mark Rasch
A recent World of Warcraft case involved a WoW book by Brian Knopp that was being sold on eBay. It resulted in automated takedown notices by "lawyerbots" and shows how the legal process today can end up silencing legitimate uses of trademarks and copyrights.
http://www.securityfocus.com/columnists/396

2. Two attacks against VoIP
By Peter Thermos
This purpose of this article is to discuss two of the most well known attacks that can be carried out in current VoIP deployments. The first attack demonstrates the ability to hijack a user's VoIP Subscription and subsequent communications. The second attack looks at the ability to eavesdrop in to VoIP communications.
http://www.securityfocus.com/infocus/1862


SecurityFocus is looking for the best technical articles from the community. In addition to becoming instantly famous, publication of your research, technical work, installation guide or security HOWTO will benefit the community as a whole. Interested parties should consult the submission guidelines below and review some recent Infocus articles. Start with an idea and a one-page outline. Submit your article idea now!
http://www.securityfocus.com/static/submissions.html


II.  BUGTRAQ SUMMARY
--------------------
1. VBook Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17319
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17319
Summary:
VBook is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

2. Clever Copy Connect.INC Information Disclosure Vulnerability
BugTraq ID: 17461
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17461
Summary:

Clever Copy is prone to an information-disclosure vulnerability. A remote attacker could leverage this issue to gain access to sensitive configuration information. The attacker could then use this information to launch further attacks against the system.

Clever Copy 3.0 is affected; other versions may also be vulnerable.

3. Microsoft Internet Explorer Invalid HTML Parsing Code Execution Vulnerability
BugTraq ID: 17450
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17450
Summary:
Microsoft Internet Explorer is prone to a vulnerability that may permit remote attackers to execute arbitrary code.  This vulnerability occurs when the browser parses invalid HTML.

This vulnerability could be exploited through a malicious web page or HTML email.

4. JetPhoto Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17449
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17449
Summary:
JetPhoto is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

5. SIRE Lire.PHP Remote File Include Vulnerability
BugTraq ID: 17428
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17428
Summary:
SIRE is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

6. APT-webshop Modules.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 17425
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17425
Summary:
APT-webshop is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

APT-webshop 3.0 light, 3.0 basic, and 4.0 pro are reported prone to these issues. Other versions may be vulnerable as well.

7. Easy Software Products CUPS HTTP GET Denial Of Service Vulnerability
BugTraq ID: 12200
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/12200
Summary:
CUPS is prone to a remotely exploitable denial-of-service vulnerability. This condition occurs when the server receives an HTTP GET request containing the string '/..'. This vulnerability is reportedly caused by a logic error.

This issue was introduced in the 1.1.21 release.

8. MyBulletinBoard Newthread.PHP HTML Injection Vulnerability
BugTraq ID: 17427
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17427
Summary:
MyBulletinBoard is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

9. SPIP Spip_login.PHP Remote File Include Vulnerability
BugTraq ID: 17423
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17423
Summary:
SPIP is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

10. ADOdb Server.PHP SQL Injection Vulnerability
BugTraq ID: 16187
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/16187
Summary:
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Exploitation of this issue requires the root password for MySQL to be empty and the affected script to be located inside the web root.

11. SCO OpenServer Backupsh Local Buffer Overflow Vulnerability
BugTraq ID: 15160
Remote: No
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15160
Summary:
The 'backupsh' utility is prone to a local buffer-overflow vulnerability.

The vulnerability presents itself when the utility processes excessive data, which may corrupt process memory. The specific details about this issue are not currently available.

A successful attack allows arbitrary machine code execution with group backup privileges.

OpenServer 5.0.7 is reported prone to this issue.

The 'authsh' utility is also vulnerable to this issue; successful exploitation could result in an attacker gaining group auth privileges.

12. JBook Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17419
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17419
Summary:
JBook is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

JBook 1.3 is reported vulnerable. Other versions may be affected as well.

13. PHPWebGallery Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17421
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17421
Summary:
PHPWebGallery is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

14. Simple Machines X-Forwarded-For HTML Injection Vulnerability
BugTraq ID: 16841
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/16841
Summary:

Simple Machines is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


This issue is reported to affect Simple Machines version 1.0.6 and earlier.

15. phpMyForum Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17420
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17420
Summary:

phpMyForum is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

phpMyForum 4.0 is reported prone to these issues. Other versions may be affected as well.

16. TalentSoft Web+ Shop Deptname Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17418
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17418
Summary:
Web+ Shop is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

17. Sudo Python Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 16184
Remote: No
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/16184
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.

A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. That attacker may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.

An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.

This issue is similar to BID 15394 (Sudo Perl Environment Variable Handling Security Bypass Vulnerability).

18. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 15394
Remote: No
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15394
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored.

An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.

  To exploit this vulnerability, an attacker must be able to run Perl scripts through Sudo.

19. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.

By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

20. AWeb's Scripts Seller Buy.PHP Authorization Bypass Vulnerability
BugTraq ID: 17417
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17417
Summary:
AWeb's Scripts Seller is prone to an authorization-bypass vulnerability. This issue is due to a failure in the application to properly verify user-supplied input.

An attacker can exploit this issue to bypass the authorization mechanism and download arbitrary scritps without paying.

21. AWeb's Banner Generator Cross-Site Scripting Vulnerability
BugTraq ID: 17416
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17416
Summary:
AWeb's Banner Generator is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

22. MPlayer Multiple Integer Overflow Vulnerabilities
BugTraq ID: 17295
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17295
Summary:
MPlayer is susceptible to two integer-overflow vulnerabilities. An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may help the attacker gain unauthorized access or escalate privileges.

MPlayer version 1.0.20060329 is affected by these issues; other versions may also be affected.

23. SCO UnixWare PPP Prompt Local Buffer Overflow Vulnerability
BugTraq ID: 15159
Remote: No
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15159
Summary:
SCO UnixWare is prone to a local buffer-overflow vulnerability.

The vulnerability presents itself when the application processes excessive data supplied through the Unixware point-to-point protocol (PPP) prompt.

UnixWare 7.1.4 and 7.1.3 are reported prone to this issue.

24. GDK-Pixbuf/GTK XPM Images Buffer Overflow Vulnerability
BugTraq ID: 15435
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15435
Summary:
The gdk-pixbuf and gtk2 packages are prone to a buffer overflow. When an application that uses a vulnerable library processes a malformed XPM image file, it results in a heap-based buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the victim user.

25. GDK-Pixbuf/GTK XPM Images Infinite Loop Denial Of Service Vulnerability
BugTraq ID: 15429
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/15429
Summary:
The 'gdk-pixbuf' and 'gtk2' libraries are prone to a denial-of-service vulnerability. This issue occurs when an application using one of the affected libraries handles a malformed XPM image file.

Exploitation could cause an application using a vulnerable library to enter an infinite loop, resulting in a denial of service.

26. Tony Cook Imager JPEG and TGA Images Denial Of Service Vulnerability
BugTraq ID: 17415
Remote: Yes
Last Updated: 2006-04-10
Relevant URL: http://www.securityfocus.com/bid/17415
Summary:
The Perl Imager module is susceptible to a denial-of-service vulnerability. This issue is due to a failure of the software to properly handle unexpected image data.

Malformed image files may cause a crash in applications that use the affected Perl module, resulting in a denial-of-service condition.

27. PHPList Index.PHP Local File Include Vulnerability
BugTraq ID: 17429
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17429
Summary:
PHPList is prone to a local file-include vulnerability. This may facilitate the unauthorized viewing of files and unauthorized execution of local scripts.

Attackers may exploit this issue to execute arbitrary code by manipulating log files.

28. Clansys Index.PHP SQL Injection Vulnerability
BugTraq ID: 17456
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17456
Summary:
Clansys is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Clansys version 1.1 is reported to be affected. Other versions may be vulnerable as well.

29. CenterICQ Malformed Packet Handling Remote Denial of Service Vulnerability
BugTraq ID: 15649
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15649
Summary:
CenterICQ is prone to a remote denial-of-service vulnerability.

The vulnerability presents itself when the client is running on a computer that is directly connected to the Internet and handles malformed packets on the listening port for ICQ messages.

A successful attack can cause the client to crash.

30. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
BugTraq ID: 15642
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15642
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

In instances where a process is created via the 'clone()' system call with the 'CLONE_THREAD' argument ptraced, the kernel fails to properly ensure that the ptracing process is not attempting to trace itself.

This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.14.2 are vulnerable to this issue.

31. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
BugTraq ID: 11646
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/11646
Summary:
Multiple vulnerabilities have been identified in the Linux ELF binary loader. These issues can allow local attackers to gain elevated privileges. The source of these issues resides in the 'load_elf_binary' function of the 'binfmt_elf.c' file.

The first issue results from an improper check performed on the return value of the 'kernel_read()' function. An attacker may gain control over execution flow of a setuid binary by modifying the memory layout of a binary.

The second issue results from improper error-handling when the 'mmap()' function fails.

The third vulnerability results from a bad return value when the program interpreter (linker) is mapped into memory. It is reported that this issue occurs only in the 2.4.x versions of the Linux kernel.

The fourth issue presents itself because a user can execute a binary with a malformed interpreter name string. This issue can lead to a system crash.

The final issue resides in the 'execve()' code. This issue may allow an attacker to disclose sensitive data that can potentially be used to gain elevated privileges.

These issues are currently undergoing further analysis. This BID will be updated and divided into separate BIDS in the future.

32. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
BugTraq ID: 15531
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15531
Summary:
Linux Kernel is reported prone to a denial-of-service vulnerability.

Due to a design error in the kernel, an attacker can cause a memory corruption that will ultimately crash the kernel, denying service to legitimate users.

33. Linux Kernel ELF Core Dump Local Buffer Overflow Vulnerability
BugTraq ID: 13589
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/13589
Summary:
The Linux kernel is susceptible to a local buffer-overflow vulnerability when attempting to create ELF coredumps. This issue is due to an integer-overflow flaw that results in a kernel buffer overflow during a 'copy_from_user()' call.

To exploit this vulnerability, a malicious user creates a malicious ELF executable designed to create a negative 'len' variable in 'elf_core_dump()'.

Local users may exploit this vulnerability to execute arbitrary machine code in the context of the kernel, facilitating privilege escalation.

**Update: This vulnerability does not exist in the 2.6 kernel tree.

34. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
BugTraq ID: 15627
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15627
Summary:

Linux kernel is susceptible to a local denial-of-service vulnerability.

Local attackers may trigger this issue by obtaining numerous file-lock leases, which will consume excessive kernel log memory. Once the leases timeout, the event will be logged, and kernel memory will be consumed.

This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and a denial of service for legitimate users.

Kernel versions prior to 2.6.15-rc3 are vulnerable to this issue.

35. Linux Kernel IA32 ExecVE Local Buffer Overflow Vulnerability
BugTraq ID: 14205
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/14205
Summary:
The Linux kernel is susceptible to a local buffer-overflow vulnerability. This issue is due to a race condition in an ia32 emulation system call that leads to a memory copy operation that overflows a previously allocated memory buffer.

During the time between two function calls to obtain buffer sizes, a window of opportunity exists for attackers to alter memory contents. This race condition allows local attackers to overwrite critical kernel memory, facilitating kernel-level machine code execution and privilege escalation.

On multiprocessor computers, attackers can directly alter the memory contents to exploit this race condition. On uniprocessor computers, a blocking function call allows attackers to exploit the race condition.

Versions of Linux 2.4 prior to 2.4.32-pre1, and Linux 2.4prior to 2.6.7 are susceptible to this issue.

This vulnerability affects only computers running on either the ia64 or the amd64 hardware platforms with ia32 emulation enabled.

36. Linux Kernel Elf Binary Loading Local Denial of Service Vulnerability
BugTraq ID: 12935
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/12935
Summary:
Linux Kernel is prone to a potential local denial of service vulnerability.

It is reported that issue exists in the 'load_elf_library' function.

Linux Kernel 2.6.11.5 and prior versions are affected by this issue.

37. Linux Kernel Process Spawning Race Condition Environment Variable Disclosure Vulnerability
BugTraq ID: 11052
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/11052
Summary:
The Linux Kernel is prone to a race condition that may potentially expose information about the environment of a process.

The race condition is reported to occur while a process is spawning.  If the condition is successfully exploited, an attacker could read environment variables associated with a process they do not own.

38. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
BugTraq ID: 12837
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/12837
Summary:
The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines.

An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges.

These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11.

39. Linux Kernel Multiple Vulnerabilities
BugTraq ID: 12598
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/12598
Summary:
Linux Kernel is reported prone to multiple vulnerabilities. These issues may allow a local attacker to carry out denial-of-service attacks, access kernel memory, and potentially gain elevated privileges.

The following specific issues were identified:

- Reportedly, the filesystem Native Language Support ASCII translation table is affected by a vulnerability that results from the use of incorrect tables sizes. This issue can lead to a crash.

- Another issue affecting the kernel may allow users to unlock arbitrary shared-memory segments.

- Another vulnerability is reported to affect the 'netfilter/iptables' module. An attacker can exploit this issue to crash the kernel or bypass firewall rules.

- Reportedly, a vulnerability affects the OUTS instruction on the AMD64 and Intel EM64T architecture. This issue may lead to privilege escalation.

These issues reportedly affect Linux kernel 2.6.x versions.

Due to lack of details, further information is not available at the moment. This BID will be updated when more information becomes available.

40. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
BugTraq ID: 11715
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/11715
Summary:
It is reported that a serialization error exists in the AF_UNIX address family that creates a race condition. This race condition reportedly allows local users to repeatedly increment arbitrary kernel memory locations.

This vulnerability allows local users to modify arbitrary kernel memory, facilitating privilege escalation, or possibly allowing code execution in the context of the kernel.

Versions prior to 2.4.28 are reportedly affected by this vulnerability.

41. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
BugTraq ID: 16993
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/16993
Summary:

The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'die_if_kernel()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.15.6 running on Itanium systems.

42. Linux Kernel Local MEMLOCK RLIMIT Bypass Denial Of Service Vulnerability
BugTraq ID: 13769
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/13769
Summary:
The 'linux-2.4.21-mlock.patch' for the Linux kernel contains a security vulnerability. Reports indicate that the rlimit restrictions do not correctly account for IPC (Inter-process Communications) functionality; this may result in unprivileged users having the right to mlock memory.

A local attacker may exploit this issue to deny service for legitimate users.

43. Linux Kernel __keyring_search_one Local Denial of Service Vulnerability
BugTraq ID: 17451
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17451
Summary:

Linux kernel is susceptible to a local denial-of-service vulnerability. This vulnerability arises in the '__keyring_search_one' function. This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.16.3 are vulnerable to this issue.

44. SmartISoft phpListPro Config.PHP Remote File Include Vulnerability
BugTraq ID: 17448
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17448
Summary:
phpListPro is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

45. PNMToPNG Alphas_Of_Color Buffer Overflow Vulnerability
BugTraq ID: 15427
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15427
Summary:
The pnmtopng utility is prone to a buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer. This issue reportedly occurs only when the '-alpha' command-line option is used.

This issue allows attackers to create malicious PNM files that, when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.

46. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
BugTraq ID: 14902
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/14902
Summary:
A local denial-of-service vulnerability affects the Linux kernel on 64-bit Symmetric Multi-Processor (SMP) platforms.

Specifically, the vulnerability presents itself due to an omitted call to the 'sockfd_put()' function in the 32-bit-compatible 'routing_ioctl()' function.

The 32-bit-compatible 'tiocgdev ioctl()' function on x86-64 platforms is affected by this issue as well.

47. Linux Kernel SYSFS_Write_File Local Integer Overflow Vulnerability
BugTraq ID: 13091
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/13091
Summary:
A local integer overflow vulnerability affects the Linux kernel.  This issue is due to a mismanagement of integer signedness by the affected '/sys' file system.

An attacker may leverage this issue to crash the affected computer or potentially run arbitrary code in the context of the superuser, facilitating privilege escalation.

48. VBook Index.PHP SQL Injection Vulnerability
BugTraq ID: 17320
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17320
Summary:
VBook is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

VBook version 2.0 is reported affected. Other versions may be vulnerable as well.

49. AzDGVote Remote File Include Vulnerability
BugTraq ID: 17447
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17447
Summary:
AzDGVote is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

50. Linux Kernel Multiple Local Vulnerabilities
BugTraq ID: 11956
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/11956
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities. The following individual issues are reported:

An integer overflow is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file, this vulnerability is only reported to exist in the 2.6 kernel tree.

Although unconfirmed, due to the nature of this vulnerability it is conjectured that this issue may be further leveraged to provide for arbitrary code execution with ring 0 privileges.

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.

A second integer overflow vulnerability is reported to exist in the 'vc_resize()' function of the Linux kernel, this vulnerability is reported to exist in the 2.6 and 2.4 kernel trees.

Although unconfirmed, due to the nature of this vulnerability it is conjectured that this issue may be further leveraged to provide for arbitrary code execution with ring 0 privileges.

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.

A third vulnerability, a memory leak, is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file, this vulnerability is reported to exist in the 2.6, and 2.4 kernel tree.

A local attacker may exploit this vulnerability to consume kernel heap memory resources and in doing so may impact system performance ultimately resulting in a denial of service to legitimate users.

51. Microsoft Outlook Express Windows Address Book File Parsing Buffer Overflow Vulnerability
BugTraq ID: 17459
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17459
Summary:


Microsoft Outlook Express is prone to a remote buffer-overflow vulnerability.

This vulnerability presets itself when the application processes a specially crafted Windows Address Book (.wab) file.

An attacker may exploit this issue to execute arbitrary code in the context of a user running the vulnerable application. This may result in a remote compromise.

52. Microsoft Windows Media Player Bitmap Handling Buffer Overflow Vulnerability
BugTraq ID: 16633
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/16633
Summary:
Microsoft Windows Media Player is prone to a remote buffer-overflow vulnerability.

The vulnerability arises when the application handles a skin file containing a specially crafted bitmap image. This issue can also be triggered by just supplying a malicious bitmap to the application. Note, however, that Windows Media Player is not the default handler for bitmap files.

A successful attack can corrupt process memory and result in arbitrary code execution. This may facilitate a remote compromise in the context of the vulnerable user.

53. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
BugTraq ID: 17196
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17196
Summary:

Microsoft Internet Explorer is susceptible to a remote code-execution vulnerability. This issue is due to a flaw that results in an invalid table-pointer dereference.

Remote attackers may exploit this issue to crash affected browsers or to execute arbitrary machine code in the context of affected users.

Microsoft has reported that this issue does not affect the March 20, 2006 release of Internet Explorer 7 Beta 2 Preview.

54. Microsoft Internet Explorer Unspecified Remote HTA Execution Vulnerability
BugTraq ID: 17181
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17181
Summary:
Microsoft Internet Explorer is affected by an unspecified remote vulnerability.

This vulnerability affects Internet Explorer 6.0 running on Microsoft Windows 98, Windows XP, and Windows Server 2003. A successful attack may allow remote attackers to execute HTA applications in the context of targeted users. This may allow remote attackers to execute code and potentially to compromise affected computers.

Due to a lack of information, further details cannot be provided. This BID will be updated when more information becomes available.

55. Microsoft Internet Explorer Script Action Handler Buffer Overflow Vulnerability
BugTraq ID: 17131
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17131
Summary:
Microsoft Internet Explorer is susceptible to a remote buffer-overflow vulnerability in 'MSHTML.DLL'. The application fails to properly bounds-check user-supplied input data before copying it into an insufficiently sized memory buffer.

Remote attackers may exploit this issue to crash affected web browsers. Remote code execution may also be possible, but this has not been confirmed.

Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.

56. Clam AntiVirus ClamAV Multiple Vulnerabilities
BugTraq ID: 17388
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17388
Summary:

ClamAV is prone to multiple vulnerabilities:

- An integer-overflow vulnerability.
- A format-string vulnerability.
- A denial-of-service vulnerability.

The first two issues may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer.

If an attacker can successfully exploit the denial-of-service issue, this may crash the affected application, which may aid an attacker in further attacks if the antivirus software no longer works.

57. Microsoft Windows XP Self-Executing Folder Vulnerability
BugTraq ID: 10363
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/10363
Summary:
A vulnerability has been reported in Microsoft Windows XP that may result in execution of malicious code in the context of the currently logged in user.  The flaw exists in Windows Explorer and may allow for executable content that is referenced from inside of a folder to be executed automatically when the folder is accessed.

This vulnerability poses a security risk since it is assumed that opening a folder is a safe action and that executable content cannot be run when a folder is accessed.  Additionally, it has been reported that this issue may be exploitable remotely if the malicious folder is accessed from an SMB share.

A proof of concept exploit has been provided that executes NetMeeting and installs a keylogger on a vulnerable system.

58. Zlib Compression Library Buffer Overflow Vulnerability
BugTraq ID: 14162
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/14162
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the application's failure to properly validate input data before using it in a memory copy operation.

In certain circumstances, malformed input data during decompression may result in a memory buffer being overflowed. This may result in denial-of-service conditions or may allow remote code to execute in the context of applications that use the affected library.

59. RealNetworks Multiple Products Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 17202
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17202
Summary:
Various RealNetworks products are prone to multiple buffer-overflow vulnerabilities.

These issues can result in memory corruption and facilitate arbitrary code execution. A successful attack can allow remote attackers to execute arbitrary code in the context of the application to gain unauthorized access.

60. Zlib Compression Library Decompression Buffer Overflow Vulnerability
BugTraq ID: 14340
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/14340
Summary:
Zlib is susceptible to a buffer-overflow vulnerability. This issue is due to the library's failure to properly handle unexpected input to its decompression routines.

Certain values used during decompression are incorrectly specified, allowing invalid inflate input to corrupt memory.

This vulnerability allows attackers to crash applications that use the affected library. This could also potentially allow for arbitrary code execution in the context of an affected application.

61. OpenVPN Client Remote Code Execution Vulnerability
BugTraq ID: 17392
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17392
Summary:
OpenVPN is reported prone to a remote code-execution vulnerability. This issue is due to a lack of proper sanitization of server-supplied data.

A remote attacker may exploit this issue to execute arbitrary code with elevated privileges on a vulnerable computer to gain unauthorized access.

To be vulnerable to this issue, client OpenVPN computers must be configured to use 'up' or 'down' scripts and must have either the 'pull' configuration directive or a 'client' macro set up.

OpenVPN versions 2.0.0 through 2.0.5 are affected by this issue.

62. NetPBM PNMToPNG Long Text Line Buffer Overflow Vulnerability
BugTraq ID: 15514
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15514
Summary:
Netpbm 'pnmtopng' is susceptible to a buffer-overflow vulnerability. The utility fails to do proper bounds checks on user-supplied data before copying it to an insufficiently sized memory buffer. This issue reportedly occurs only when the '-text' command-line option is used.

This issue allows attackers to create malicious PNM files that, when parsed by the affected utility, allow arbitrary machine code to be executed. This occurs in the context of the user running the affected utility.

This vulnerability was reported in versions 9.20 and 10.0 of Netpbm. Other versions may also be affected.

63. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
BugTraq ID: 17446
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17446
Summary:
Cyrus SASL is affected by a remote denial-of-service vulnerability. This issue occurs before successful authentication, allowing anonymous remote attackers to trigger it.

This vulnerability allows remote attackers to crash services using the affected SASL library, denying service to legitimate users.

This issue reportedly affects version 2.1.18 of Cyrus SASL; other versions may also be affected.

64. Apple Mac OS X Security Update 2006-001 Multiple Vulnerabilities
BugTraq ID: 16907
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/16907
Summary:
Apple has released Security Update 2006-001 to address multiple remote and local Mac OS X vulnerabilities.

Apple has also released updates to address these issues.

65. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

66. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to reenable the 'register_globals' directive. This issue is due to the application's failure to handle a memory-limit exception.

The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the process's life. If PHP is being run as a CGI process, this issue is not likely exploitable.

By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

67. XMB Forum Flash Video Cross-Site Scripting Vulnerability
BugTraq ID: 17445
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17445
Summary:
XMB Forum is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

68. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash.

This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.15 are vulnerable to this issue.

69. VWar Admin.PHP Remote File Include Vulnerability
BugTraq ID: 17443
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17443
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

70. ShopWeezle Multiple SQL Injection Vulnerabilities
BugTraq ID: 17441
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17441
Summary:
ShopWeezle is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

71. KAME Racoon Malformed ISAKMP Packet Headers Denial of Service Vulnerability
BugTraq ID: 12804
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/12804
Summary:
KAME's racoon is reported prone to a vulnerability that may allow a remote attacker to cause a denial-of-service condition in the application.

This issue arises from a boundary condition error when the application handles malformed ISAKMP packets.

Versions of racoon prior to 20050307 are considered vulnerable to this issue.

72. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 17439
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17439
Summary:
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.

These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, when the 'safe_mode' and 'open_basedir' restrictions are expected to isolate the users from each other.

These issues are reported to affect PHP versions 4.4.2 and 5.1.2; other versions may also be vulnerable.

73. Gallery Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 17437
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17437
Summary:
Gallery is prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

74. Matt Wright Guestbook Guestbook.PL Multiple HTML Injection Vulnerabilities
BugTraq ID: 17438
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17438
Summary:
Guestbook is prone to multiple HTML-injection vulnerabilities; the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

75. Fbida FBGS Insecure Temporary File Creation Vulnerability
BugTraq ID: 17436
Remote: No
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17436
Summary:
The 'fbida' utilities create temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.

A successful attack would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive files. This may result in a denial of service; other attacks may also be possible.

76. XBrite Members.PHP SQL Injection Vulnerability
BugTraq ID: 17424
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17424
Summary:
XBrite is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

XBrite version 1.1 is reported affected. Other versions may be vulnerable as well.

77. Shadowed Portal Load.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17430
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17430
Summary:
Shadowed Portal is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

All versions of Shadowed Portal are considered vulnerable at the moment.

78. Oracle Database Access Restriction Bypass Vulnerability
BugTraq ID: 17426
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17426
Summary:
Oracle Database is susceptible to a vulnerability that allows attackers to bypass access restrictions. This issue is due to a failure of the application to properly enforce read-only privileges for user roles in certain circumstances.

To exploit this issue, a user must have 'CREATE VIEW' and 'CREATE DATABASE LINK' privileges. Also, the base table must have a primary key.

This issue allows attackers to modify data stored in affected databases, even if they are granted just read-only access. This may allow them to gain elevated privileges in the database.

Oracle versions 9.2.0.0 through 10.2.0.3 are affected by this issue.

This issue was originally disclosed by the vendor via Metalink, under the title "363848.1 - A User with SELECT Object Privilege on Base Tables Can Delete Rows from a View". This article has reportedly been removed since its initial disclosure.

79. SQuery LibPath Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 17434
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17434
Summary:
SQuery is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

80. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

81. VegaDNS Multiple Input Validation Vulnerabilities
BugTraq ID: 17433
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17433
Summary:
VegaDNS is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

82. Design Nation DNGuestbook Admin.PHP SQL Injection Vulnerabilities
BugTraq ID: 17435
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17435
Summary:
dnGuestbook is prone to SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

dnGuestbook 2.0 is vulnerable; earlier versions may also be affected.

83. TUGZip Remote Directory Traversal Vulnerability
BugTraq ID: 17432
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17432
Summary:
Reportedly, an attacker can carry out attacks similar to directory traversals. These issues present themselves when the application processes malicious archives.

A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploitation may aid in further attacks.

84. SIRE Arbitrary File Upload Vulnerability
BugTraq ID: 17431
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17431
Summary:
SIRE is prone to an arbitrary file-upload vulnerability.

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

85. Horde Help Viewer Remote PHP Code Execution Vulnerability
BugTraq ID: 17292
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17292
Summary:
Horde is prone to a remote PHP code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.

86. Indexu Multiple Remote File Include Vulnerabilities
BugTraq ID: 17470
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17470
Summary:
The 'indexu' application is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

These issues are reported to affect versions 5.0.0 and 5.0.1; other versions may also be vulnerable.

87. Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
BugTraq ID: 17468
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17468
Summary:

Microsoft Internet Explorer is prone to a memory corruption vulnerability. This is related to the handling of certain HTML tags.

This issue could be exploited by a malicious web page to execute arbitrary code in the context of the currently logged in user. The issue could also be exploited through HTML email.

88. PHPKIT Include.PHP SQL Injection Vulnerability
BugTraq ID: 17467
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17467
Summary:
PHPKIT is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

89. SWSoft Confixx Jahr Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17466
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17466
Summary:
Confixx is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Confixx 3.1.2 is reported vulnerable.  Other versions may be affected as well.

90. Blursoft Blur6ex Multiple Input Validation Vulnerabilities
BugTraq ID: 17465
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17465
Summary:
Blur6ex is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

91. Microsoft Windows Shell COM Object Remote Code Execution Vulnerability
BugTraq ID: 17464
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17464
Summary:
Microsoft Windows Shell is susceptible to a remote code execution vulnerability. This issue is due to a flaw in its handling of remote COM objects.

This issue may be exploited by remote attackers to execute arbitrary machine code in the context of the targeted user. This may facilitate the remote compromise of affected computers.

This issue is described as a variant of the one described in BID 10363 (Microsoft Windows XP Self-Executing Folder Vulnerability).

92. Dokeos Viewtopic.PHP SQL Injection Vulnerability
BugTraq ID: 17463
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17463
Summary:
Dokeos is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

93. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 17462
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17462
Summary:

The Microsoft MDAC RDS.Dataspace ActiveX control is vulnerable to remote code execution.  An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

94. Microsoft Internet Explorer Persistent Window Content Address Bar Spoofing Vulnerability
BugTraq ID: 17460
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17460
Summary:
Microsoft Internet Explorer is prone to an address bar spoofing vulnerability.

This issue may be exploited by a malicious web page to spoof the contents of a page that the victim of the attack may trust.  This vulnerability may be useful in phishing or other attacks that rely on content spoofing.

95. JBook Form.PHP SQL Injection Vulnerabilities
BugTraq ID: 17458
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17458
Summary:
JBook is prone to SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

96. Microsoft Internet Explorer Popup Cross-Domain Information Disclosure Vulnerability
BugTraq ID: 17457
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17457
Summary:
Microsoft Internet Explorer is prone to a cross-domain information disclosure vulnerability.

This vulnerability may let a malicious web site access properties of a site in an arbitrary external domain.  This could be exploited to gain access to sensitive information that is associated with the external domain, such as cookies associated with a userĂ¢??s session on the external web site.

97. Microsoft Internet Explorer Erroneous IOleClientSite Data Zone Bypass Vulnerability
BugTraq ID: 17455
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17455
Summary:
Microsoft Internet Explorer is prone to a zone bypass vulnerability.  This issue is due to the browser returning erroneous IOleClientSite when dynamically creating an embedded object.  This could cause malicious script code to be executed in a security zone with fewer restrictions than the zone that the content originates from.

This issue may be exploited to execute arbitrary code in the context of the currently logged in user on the affected computer.  It may also be possible to execute malicious script code in the context of a site that exists in another domain.  The issue could be exploited through a malicious web page.

98. Microsoft Internet Explorer Double Byte Character Memory Corruption Vulnerability
BugTraq ID: 17454
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17454
Summary:
Microsoft Internet Explorer is prone to a memory corruption vulnerability.  This is related to an error in how double byte character set (DBCS) characters are handled in IP addresses from rendered HTML content.

This issue could be exploited by a malicious web page to execute arbitrary code in the context of the currently logged in user.  The issue could also be exploited through HTML email.

Microsoft has stated that this issue is not applicable to Internet Explorer 6.0 on Windows Server 2003 SP1.

99. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
BugTraq ID: 17453
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17453
Summary:
Microsoft Internet Explorer is prone to a memory corruption vulnerability that is related to the instantiation of COM objects. This issue results from a design error.

The vulnerability arises because of the way Internet Explorer attempts to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution.  The affected objects are not intended to be instantiated through Internet Explorer.

This BID is related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability), however, a different set of COM objects are affected that were not addressed in the previous BIDs.

100. Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability
BugTraq ID: 17452
Remote: Yes
Last Updated: 2006-04-11
Relevant URL: http://www.securityfocus.com/bid/17452
Summary:

Microsoft FrontPage Server Extensions are prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before it is rendered to other users.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user, with the privileges of the victim userĂ¢??s account. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Groups argue over merits of flaw bounties
By: Robert Lemos
Vulnerability researchers like getting paid for their research, but software companies criticize the programs. Do vulnerability-purchasing initiatives make sense?
http://www.securityfocus.com/news/11386

2. Seven arrested in online fraud crackdown
By: Robert Lemos
An ongoing investigation, dubbed Operation Rolling Stone by the U.S. Secret Service, has turned up links to the massive debit-card breaches that have worried banks and consumers.
http://www.securityfocus.com/news/11385

3. Patches released for zero-day IE threat
By: Robert Lemos
UPDATE: As hundreds of malicious Web sites attempt to exploit the most critical of two Internet Explorer flaws disclosed last week, two third-party firms release fixes to nix the threat.<br />
See also: <a href="http://www.securityfocus.com/brief/174">Thousands download third-party patches</a>
http://www.securityfocus.com/news/11384

4. Check Point calls off Sourcefire buy
By: Robert Lemos
Citing an ongoing investigation into the deal by the U.S. Treasury Department, the companies decide to call it quits.
http://www.securityfocus.com/news/11382

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Auditor, Detroit
http://www.securityfocus.com/archive/77/430670

2. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/430665

3. [SJ-JOB] Security Product Marketing Manager, Sunnyvale
http://www.securityfocus.com/archive/77/430667

4. [SJ-JOB] Security Consultant, Detroit
http://www.securityfocus.com/archive/77/430666

5. [SJ-JOB] Security Auditor, Detroit
http://www.securityfocus.com/archive/77/430664

6. [SJ-JOB] Auditor, Los Angeles
http://www.securityfocus.com/archive/77/430619

7. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/430622

8. [SJ-JOB] Security Auditor, Los Angeles
http://www.securityfocus.com/archive/77/430625

9. [SJ-JOB] Technical Support Engineer, Riyad
http://www.securityfocus.com/archive/77/430609

10. [SJ-JOB] Developer, Annapolis Junction
http://www.securityfocus.com/archive/77/430610

11. [SJ-JOB] Account Manager, London
http://www.securityfocus.com/archive/77/430620

12. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/430628

13. [SJ-JOB] Sales Representative, San Francisco
http://www.securityfocus.com/archive/77/430606

14. [SJ-JOB] Auditor, San Francisco
http://www.securityfocus.com/archive/77/430618

15. [SJ-JOB] Security Auditor, San Francisco
http://www.securityfocus.com/archive/77/430629

16. [SJ-JOB] Auditor, Columbus
http://www.securityfocus.com/archive/77/430616

17. [SJ-JOB] Security Auditor, Columbus
http://www.securityfocus.com/archive/77/430627

18. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/430611

19. [SJ-JOB] Auditor, Washington
http://www.securityfocus.com/archive/77/430615

20. [SJ-JOB] Security Auditor, Washington
http://www.securityfocus.com/archive/77/430617

21. [SJ-JOB] Security Consultant, Washington
http://www.securityfocus.com/archive/77/430626

22. [SJ-JOB] Auditor, Baltimore
http://www.securityfocus.com/archive/77/430608

23. [SJ-JOB] Security Consultant, Columbus
http://www.securityfocus.com/archive/77/430623

24. [SJ-JOB] Auditor, Atlanta
http://www.securityfocus.com/archive/77/430632

25. [SJ-JOB] Security Auditor, Baltimore
http://www.securityfocus.com/archive/77/430633

26. [SJ-JOB] Security Consultant, Rome
http://www.securityfocus.com/archive/77/430604

27. [SJ-JOB] Security Consultant, Richmond
http://www.securityfocus.com/archive/77/430605

28. [SJ-JOB] Security Auditor, Richmond
http://www.securityfocus.com/archive/77/430602

29. [SJ-JOB] Auditor, Richmond
http://www.securityfocus.com/archive/77/430603

30. [SJ-JOB] Security Consultant, london
http://www.securityfocus.com/archive/77/430576

31. [SJ-JOB] Sr. Security Engineer, Atlanta
http://www.securityfocus.com/archive/77/430586

32. [SJ-JOB] Sr. Security Engineer, Bailey's Crossroads, Fairfax    County, VA
http://www.securityfocus.com/archive/77/430587

33. [SJ-JOB] Sr. Security Analyst, London
http://www.securityfocus.com/archive/77/430574

34. [SJ-JOB] Security Engineer, Reston/Herndon
http://www.securityfocus.com/archive/77/430575

35. [SJ-JOB] Disaster Recovery Coordinator, Evansville
http://www.securityfocus.com/archive/77/430585

36. [SJ-JOB] CHECK Team Leader, london
http://www.securityfocus.com/archive/77/430571

37. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/430577

38. [SJ-JOB] Sr. Security Analyst, RTP
http://www.securityfocus.com/archive/77/430570

39. [SJ-JOB] Manager, Information Security, Moncton
http://www.securityfocus.com/archive/77/430573

40. [SJ-JOB] Security Engineer, washington
http://www.securityfocus.com/archive/77/430568

41. [SJ-JOB] Sr. Security Analyst, Jersey City
http://www.securityfocus.com/archive/77/430566

42. [SJ-JOB] Instructor, Boston
http://www.securityfocus.com/archive/77/430567

43. [SJ-JOB] Technical Support Engineer, Columbia
http://www.securityfocus.com/archive/77/430569

44. [SJ-JOB] Security System Administrator, Parsippany
http://www.securityfocus.com/archive/77/430564

45. [SJ-JOB] Application Security Engineer, Mumbai
http://www.securityfocus.com/archive/77/430562

46. [SJ-JOB] Disaster Recovery Coordinator, Shelton
http://www.securityfocus.com/archive/77/430563

47. [SJ-JOB] Developer, Bhubaneswar
http://www.securityfocus.com/archive/77/430560

48. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/430565

49. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/430557

50. [SJ-JOB] Security Consultant, Philadelphia
http://www.securityfocus.com/archive/77/430559

51. [SJ-JOB] Security Auditor, Philadelphia
http://www.securityfocus.com/archive/77/430554

52. [SJ-JOB] Security Auditor, Chicago
http://www.securityfocus.com/archive/77/430555

53. [SJ-JOB] Auditor, Philadelphia
http://www.securityfocus.com/archive/77/430558

54. [SJ-JOB] Management, Slough
http://www.securityfocus.com/archive/77/430556

55. [SJ-JOB] Security Consultant, Raleigh
http://www.securityfocus.com/archive/77/430551

56. [SJ-JOB] Security Engineer, Rome
http://www.securityfocus.com/archive/77/430552

57. [SJ-JOB] Auditor, Raleigh
http://www.securityfocus.com/archive/77/430537

58. [SJ-JOB] Security Auditor, Raleigh
http://www.securityfocus.com/archive/77/430553

59. [SJ-JOB] Auditor, Chicago
http://www.securityfocus.com/archive/77/430536

60. [SJ-JOB] Auditor, Dallas
http://www.securityfocus.com/archive/77/430539

61. [SJ-JOB] Security Auditor, Dallas
http://www.securityfocus.com/archive/77/430542

62. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/430535

63. [SJ-JOB] Sales Engineer, Portland
http://www.securityfocus.com/archive/77/430527

64. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/430528

65. [SJ-JOB] Security Engineer, Eastern Iowa
http://www.securityfocus.com/archive/77/430521

66. [SJ-JOB] Security System Administrator, Mumbai
http://www.securityfocus.com/archive/77/430522

67. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/430525

68. [SJ-JOB] Technical Marketing Engineer, Redwood City
http://www.securityfocus.com/archive/77/430529

69. [SJ-JOB] Technology Risk Consultant, Eastern Iowa
http://www.securityfocus.com/archive/77/430518

70. [SJ-JOB] Application Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/430519

71. [SJ-JOB] Sr. Security Analyst, Metro Area
http://www.securityfocus.com/archive/77/430520

72. [SJ-JOB] Account Manager, herdnon
http://www.securityfocus.com/archive/77/430526

73. [SJ-JOB] Security Researcher, Chicago
http://www.securityfocus.com/archive/77/430493

74. [SJ-JOB] Sales Engineer, Cincinnati or Indianapolis
http://www.securityfocus.com/archive/77/430513

75. [SJ-JOB] Channel / Business Development, Chicago
http://www.securityfocus.com/archive/77/430515

76. [SJ-JOB] Technology Risk Consultant, Chicago
http://www.securityfocus.com/archive/77/430516

77. [SJ-JOB] Security Researcher, Chicago
http://www.securityfocus.com/archive/77/430517

78. [SJ-JOB] Security Consultant, Various/ Winnipeg
http://www.securityfocus.com/archive/77/430491

79. [SJ-JOB] Application Security Engineer, Dubai
http://www.securityfocus.com/archive/77/430514

80. [SJ-JOB] Technology Risk Consultant, Chicago
http://www.securityfocus.com/archive/77/430485

81. [SJ-JOB] Technology Risk Consultant, Chicago
http://www.securityfocus.com/archive/77/430486

82. [SJ-JOB] Sr. Security Engineer, Austin
http://www.securityfocus.com/archive/77/430484

83. [SJ-JOB] Management, Glasgow
http://www.securityfocus.com/archive/77/430509

84. [SJ-JOB] Account Manager, Parsippany
http://www.securityfocus.com/archive/77/430510

85. [SJ-JOB] Security Consultant, Various locations across UK
http://www.securityfocus.com/archive/77/430508

86. [SJ-JOB] Account Manager, San Francisco
http://www.securityfocus.com/archive/77/430511

87. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/430512

88. [SJ-JOB] Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/430502

89. [SJ-JOB] Security Engineer, San Jose
http://www.securityfocus.com/archive/77/430503

90. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/430504

91. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/430500

92. [SJ-JOB] Manager, Information Security, Los Angeles
http://www.securityfocus.com/archive/77/430501

93. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/430495

94. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/430497

95. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/430498

96. [SJ-JOB] Sales Representative, Herndon
http://www.securityfocus.com/archive/77/430499

97. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/430496

98. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/430457

99. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/430459

100. [SJ-JOB] Director, Information Security, New York
http://www.securityfocus.com/archive/77/430460

101. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/430458

102. [SJ-JOB] Security Auditor, Seattle
http://www.securityfocus.com/archive/77/430468

103. [SJ-JOB] Security Engineer, Cambridge
http://www.securityfocus.com/archive/77/430472

104. [SJ-JOB] Security Consultant, Seattle
http://www.securityfocus.com/archive/77/430467

105. [SJ-JOB] Forensics Engineer, Midlands
http://www.securityfocus.com/archive/77/430450

106. [SJ-JOB] Account Manager, South East England
http://www.securityfocus.com/archive/77/430444

107. [SJ-JOB] Security Product Manager, Santa Clara
http://www.securityfocus.com/archive/77/430445

108. [SJ-JOB] Sr. Product Manager, Sunnyvale
http://www.securityfocus.com/archive/77/430470

109. [SJ-JOB] Disaster Recovery Coordinator, Fairfax
http://www.securityfocus.com/archive/77/430446

110. [SJ-JOB] Security Consultant, Baltimore
http://www.securityfocus.com/archive/77/430447

111. [SJ-JOB] Security Architect, Baltimore
http://www.securityfocus.com/archive/77/430441

112. [SJ-JOB] Technical Support Engineer, Cupertino
http://www.securityfocus.com/archive/77/430047

113. [SJ-JOB] Security Researcher, Various
http://www.securityfocus.com/archive/77/430042

114. [SJ-JOB] Account Manager, Houston
http://www.securityfocus.com/archive/77/430043

115. [SJ-JOB] Developer, Columbia
http://www.securityfocus.com/archive/77/430044

116. [SJ-JOB] Sales Representative, San Mateo
http://www.securityfocus.com/archive/77/430040

117. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/430045

118. [SJ-JOB] Security Consultant, Deerfield
http://www.securityfocus.com/archive/77/430046

V.   INCIDENTS LIST SUMMARY
---------------------------
1. RATs in our Honeypot
http://www.securityfocus.com/archive/75/430436

2. Bogon IPs traffic only seen by netflow, confined within a VLAN only
http://www.securityfocus.com/archive/75/430349

3. They got me!!!
http://www.securityfocus.com/archive/75/430059

4. What a strange route (The DoD inside)!
http://www.securityfocus.com/archive/75/429638

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Sourceforge.net XSS
http://www.securityfocus.com/archive/82/430379

2. Myspace.com - Intricate Script Injection
http://www.securityfocus.com/archive/82/430263

3. FW: Google Reader "preview" and "lens" script improper feed validation
http://www.securityfocus.com/archive/82/430265

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Adding Users via Web Interface
http://www.securityfocus.com/archive/88/430662

2. SecurityFocus Microsoft Newsletter #285
http://www.securityfocus.com/archive/88/430424

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Syncing iptables rules between two servers
http://www.securityfocus.com/archive/91/430423

2. R: IPtables and C programming??
http://www.securityfocus.com/archive/91/430003

3. IPtables and C programming??
http://www.securityfocus.com/archive/91/429848

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SPI Dynamics

ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000CGKl