SecurityFocus Newsletter #346
Peter Laborge <[email protected]> Tue, 18 Apr 2006 15:38:51 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #346
----------------------------------------
This Issue is Sponsored By: Lancope
"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."
http://www.lancope.com/resource/
------------------------------------------------------------------
I. FRONT AND CENTER
1. Virtualization for security
2. Stop the bots
II. BUGTRAQ SUMMARY
1. Solaris sadmind Disabled Authentication Vulnerability
2. Lighthouse CMS Search Cross-Site Scripting Vulnerability
3. MODxCMS Index.PHP Directory Traversal Vulnerability
4. MODxCMS Index.PHP Cross-Site Scripting Vulnerability
5. AWebBB Multiple Input Validation Vulnerabilities
6. Papoo Multiple Cross-Site Scripting Vulnerabilities
7. Papoo Print.PHP Cross-Site Scripting Vulnerability
8. LifeType Index.PHP Cross-Site Scripting Vulnerability
9. Simplog Multiple SQL Injection Vulnerabilities
10. Simplog Remote File Include Vulnerability
11. Simplog Login.PHP Cross-Site Scripting Vulnerability
12. PowerClan Member.PHP SQL Injection Vulnerability
13. RedCMS Multiple Input Validation Vulnerabilities
14. PlanetSearch + Planetsearchplus.PHP Cross-Site Scripting Vulnerability
15. PHPAlbum Language.PHP File Include Vulnerability
16. FCheck Insecure Temporary File Creation Vulnerability
17. Sysinfo Multiple Input Validation Vulnerabilities
18. ADOdb Multiple Cross-Site Scripting Vulnerabilities
19. ADOdb PostgreSQL SQL Injection Vulnerability
20. ADOdb Server.PHP SQL Injection Vulnerability
21. AR-Blog Print.PHP Cross-Site Scripting Vulnerability
22. Warforge.NEWS Multiple Input Validation Vulnerabilities
23. Horde Help Viewer Remote PHP Code Execution Vulnerability
24. Horde Application Framework Go.PHP Information Disclosure Vulnerability
25. Sybase EAServer Remote Buffer Overflow Vulnerability
26. ShixxNOTE 6.net Remote Buffer Overflow Vulnerability
27. FlexBB Multiple Input Validation Vulnerabilities
28. MD News Admin.PHP SQL Injection Vulnerability
29. Fuju News SQL Injection and Authentication Bypass Vulnerabilities
30. Serendipity Blog Config.PHP Script Injection Vulnerability
31. Coppermine Index.PHP Local File Include Vulnerability
32. Neon Responders Remote Clock Synchronization Denial of Service Vulnerability
33. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
34. FlexBB Index.PHP SQL Injection Vulnerability
35. Novell GroupWise Messenger Accept Language Remote Buffer Overflow Vulnerability
36. Asterisk JPEG File Handling Integer Overflow Vulnerability
37. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
38. MyBB Global Variable Overwrite Vulnerability
39. Manila EditInBrowser Module HTML Injection Vulnerability
40. Manila Multiple Cross-Site Scripting Vulnerabilities
41. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
42. Linux Kernel do_coredump Denial of Service Vulnerability
43. Jax Guestbook Jax_guestbook.PHP Cross-Site Scripting Vulnerability
44. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
45. Calendarix YearCal.PHP Cross-Site Scripting Vulnerability
46. BoastMachine Search.PHP Cross-Site Scripting Vulnerability
47. DbbS Multiple Input Validation Vulnerabilities
48. PHPWebFTP Index.PHP Directory Traversal Vulnerability
49. BetaBoard User Profile HTML Injection Vulnerability
50. Blursoft Blur6ex Index.PHP Local File Include Vulnerability
51. BlackOrpheus Member.PHP SQL Injection Vulnerability
52. Neuron Blog Multiple HTML Injection Vulnerabilities
53. DbbS Topics.PHP SQL Injection Vulnerability
54. TinyPHPForum Multiple Cross-Site Scripting Vulnerabilities
55. Monster Top List Functions.PHP Remote File Include Vulnerability
56. Boardsolution Index.PHP Cross-Site Scripting Vulnerability
57. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
58. ShoutBOOK Multiple HTML Injection Vulnerabilities
59. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
60. myEvent Multiple Remote File Include Vulnerabilities
61. MusicBox Multiple Input Validation Vulnerabilities
62. Snipe Gallery Multiple Cross-Site Scripting Vulnerabilities
63. Snipe Gallery Multiple Input Validation Vulnerabilities
64. PHPGraphy Index.PHP Unauthorized Access Vulnerability
65. Sun Solaris Proc Filesystem Pagedata Subsystem Local Denial Of Service Vulnerability
66. phpFaber TopSites Index.PHP Cross-Site Scripting Vulnerability
67. IBM AIX MKLVCopy Local Privilege Escalation Vulnerability
68. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
69. Fetchmail Missing Email Header Remote Denial of Service Vulnerability
70. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
71. Linux Kernel ICMP_Push_Reply Remote Denial Of Service Vulnerability
72. Linux Kernel IPV6 Local Denial of Service Vulnerability
73. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
74. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
75. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
76. Linux Kernel Multiple Security Vulnerabilities
77. PHPLister Index.PHP Cross-Site Scripting Vulnerability
78. RechnungsZentrale V2 Authent.PHP4 Remote File Include Vulnerability
79. RechnungsZentrale V2 Authent.PHP4 SQL Injection Vulnerability
80. Linux Kernel Shared Memory Security Restriction Bypass Vulnerability
81. phpLinks Index.PHP Cross-Site Scripting Vulnerability
82. Empire Server Multiple Unspecified Vulnerabilities
83. axoverzicht.CGI Cross-Site Scripting Vulnerability
84. LinPHA Multiple Cross-Site Scripting Vulnerabilities
85. myEvent Multiple Input Validation Vulnerabilities
86. Xine Playlist Handling Remote Format String Vulnerability
87. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
88. Linux Kernel SDLA_XFER Kernel Memory Disclosure Vulnerability
89. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
90. Linux Kernel Multithreaded ITimer Leak Local Denial of Service Vulnerability
91. OSCommerce Update.PHP Information Disclosure Vulnerability
92. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
93. BSD-Games Multiple Local Buffer Overflow Vulnerabilities
94. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
95. FlexBB Multiple HTML Injection Vulnerabilities
96. PHPGuestbook HTML Injection Vulnerability
97. Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
98. Avast! Linux Home Edition Insecure Temporary File Creation Vulnerability
99. FarsiNews Search.PHP Cross-Site Scripting Vulnerability
100. AOblogger Multiple Input Validation Vulnerabilities
III. SECURITYFOCUS NEWS
1. Browsers feel the fuzz
2. Groups argue over merits of flaw bounties
3. Seven arrested in online fraud crackdown
4. Patches released for zero-day IE threat
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sr. Security Analyst, London
2. [SJ-JOB] Security Consultant, Edinburgh
3. [SJ-JOB] Regional Channel Manager, San Francisco
4. [SJ-JOB] Security Consultant, san jose
5. [SJ-JOB] Security Engineer, Zurich
6. [SJ-JOB] Database Security Engineer, Hyderabad
7. [SJ-JOB] Security Architect, Seattle
8. [SJ-JOB] Information Assurance Engineer, Sierra Vista/Ft. Huachuca
9. [SJ-JOB] Information Assurance Engineer, Mumbai
10. [SJ-JOB] Security Consultant, New York
11. [SJ-JOB] Director, Information Security, London
12. [SJ-JOB] Security System Administrator, San Diego
13. [SJ-JOB] Sr. Security Analyst, Indian Head
14. [SJ-JOB] Technical Support Engineer, Brussels
15. [SJ-JOB] Disaster Recovery Coordinator, London
16. [SJ-JOB] Sr. Security Engineer, Indian Head
17. [SJ-JOB] Auditor, Miami
18. [SJ-JOB] Security Consultant, Atlanta
19. [SJ-JOB] Security Auditor, Atlanta
20. [SJ-JOB] Security Consultant, Warrington and Durham
21. [SJ-JOB] Security Engineer, Saratoga Region
22. [SJ-JOB] Management, Dubai
V. INCIDENTS LIST SUMMARY
1. Someone scanning for new PHP issues?
VI. VULN-DEV RESEARCH LIST SUMMARY
1. New site about security conferences : www.security-briefings.com
2. IE Update Possible vulnerability
3. Recon 2006: speaker lineup announcement
4. vulnerability research approach
VII. MICROSOFT FOCUS LIST SUMMARY
1. Windows Update error
2. MS06-013 Cumulative IE Update (912812) Issues
3. Detecting PwDump
4. SecurityFocus Microsoft Newsletter #286
5. Laptop Encryption & Write Permissions
6. Adding Users via Web Interface
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. about /dev/shm?
2. Syncing iptables rules between two servers
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Virtualization for security
By Scott Granneman
Scott Granneman gives an overview of the virtualization options for all three major operating system families and looks at the many ways the technology can improve your security posture in an organization or at home.
http://www.securityfocus.com/columnists/397
2. Stop the bots
By Kelly Martin
Botnets are a major source of evil on the Internet, from spam, phishing attacks, virus propagation and denial-of-service attacks to the stealing of financial information and other illegal activity. Does disbanding them raise legal and ethical implications?
http://www.securityfocus.com/columnists/398
II. BUGTRAQ SUMMARY
--------------------
1. Solaris sadmind Disabled Authentication Vulnerability
BugTraq ID: 2354
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/2354
Summary:
Versions of 'sadmind' were shipped with a default of no authentication required. As a result, remote users could access the service and compromise the target system.
2. Lighthouse CMS Search Cross-Site Scripting Vulnerability
BugTraq ID: 15952
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15952
Summary:
Lighthouse is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.1; other versions may also be vulnerable.
NOTE: The vendor disputes this issue, stating that Lighthouse is an application server and is not susceptible to client-side cross-site scripting attacks.
3. MODxCMS Index.PHP Directory Traversal Vulnerability
BugTraq ID: 17533
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17533
Summary:
MODxCMS is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
4. MODxCMS Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17532
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17532
Summary:
MODxCMS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
5. AWebBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17352
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17352
Summary:
aWebBB is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
6. Papoo Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16573
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16573
Summary:
Papoo is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Specific information regarding affected versions is not currently available; this BID will be updated as further information is disclosed.
7. Papoo Print.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17530
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17530
Summary:
Papoo is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
8. LifeType Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17529
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17529
Summary:
LifeType is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
9. Simplog Multiple SQL Injection Vulnerabilities
BugTraq ID: 17491
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17491
Summary:
Simplog is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 0.9.2. is reported to be vulnerable. Other versions may be affected as well.
10. Simplog Remote File Include Vulnerability
BugTraq ID: 17490
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17490
Summary:
Simplog is prone to a remote and local file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote or local file containing malicious PHP code and execute it in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
This issue is reported to affect version 0.9.2; other versions may also be vulnerable.
11. Simplog Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17493
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17493
Summary:
Simplog is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
12. PowerClan Member.PHP SQL Injection Vulnerability
BugTraq ID: 17528
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17528
Summary:
PowerClan is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
PowerClan version 1.14 is reported vulnerable. Other versions may be affected as well.
13. RedCMS Multiple Input Validation Vulnerabilities
BugTraq ID: 17336
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17336
Summary:
RedCMS is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
The application is prone to HTML-injection and SQL-injection vulnerabilities. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Arbitrary script code may also be executed in the browser of an unsuspecting user in the context of the affected site; this may help the attacker steal cookie-based authentication credentials and launch other attacks.
14. PlanetSearch + Planetsearchplus.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17527
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17527
Summary:
PlanetSearch + is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
15. PHPAlbum Language.PHP File Include Vulnerability
BugTraq ID: 17526
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17526
Summary:
phpAlbum is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Versions 0.3.2.3 and prior are affected.
16. FCheck Insecure Temporary File Creation Vulnerability
BugTraq ID: 17524
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17524
Summary:
FCheck creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
A successful attack would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive files. This may result in a denial of service; other attacks may also be possible.
17. Sysinfo Multiple Input Validation Vulnerabilities
BugTraq ID: 17523
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17523
Summary:
Sysinfo is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible. Remote attackers may also obtain the installation path.
Sysinfo 1.21 is reported vulnerable. Other versions may be affected as well.
18. ADOdb Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16720
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16720
Summary:
ADOdb is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may help the attacker steal cookie-based authentication credentials and launch other attacks.
ADOdb versions 4.71 and prior are vulnerable.
19. ADOdb PostgreSQL SQL Injection Vulnerability
BugTraq ID: 16364
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16364
Summary:
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects only ADOdb implementations using PostgreSQL; other databases are not affected.
20. ADOdb Server.PHP SQL Injection Vulnerability
BugTraq ID: 16187
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16187
Summary:
ADOdb is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploitation of this issue requires the root password for MySQL to be empty and the affected script to be located inside the web root.
21. AR-Blog Print.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17522
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17522
Summary:
The ar-blog application is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 5.2 is vulnerable; other versions may also be affected.
22. Warforge.NEWS Multiple Input Validation Vulnerabilities
BugTraq ID: 17520
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17520
Summary:
Warforge.NEWS is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
23. Horde Help Viewer Remote PHP Code Execution Vulnerability
BugTraq ID: 17292
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17292
Summary:
Horde is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.
24. Horde Application Framework Go.PHP Information Disclosure Vulnerability
BugTraq ID: 17117
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17117
Summary:
Horde Application Framework is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve the contents of arbitrary files in the context of the webserver process. Information obtained may aid in further attacks.
25. Sybase EAServer Remote Buffer Overflow Vulnerability
BugTraq ID: 14287
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/14287
Summary:
Sybase EAServer is affected by a remote buffer-overflow vulnerability.
The vulnerability exists in the server's WebConsole. A successful attack can overflow a finite-sized buffer and ultimately lead to arbitrary code execution in the context of the 'jagsrv.exe' process. This may allow the attacker to gain elevated privileges.
Note that an attacker needs to provide authentication credentials before carrying out this attack.
26. ShixxNOTE 6.net Remote Buffer Overflow Vulnerability
BugTraq ID: 11409
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/11409
Summary:
ShixxNOTE 6.net is reported susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly perform boundary checks before copying user-supplied strings into finite process buffers.
An attacker may leverage this issue to execute arbitrary code on a vulnerable computer with the privileges of the user running the vulnerable application.
27. FlexBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17574
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17574
Summary:
FlexBB is prone to multiple input-validation vulnerabilities. The issues include HTML- and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successfully exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Version 0.5.5 of FlexBB is vulnerable to these issues; other versions may also be affected.
28. MD News Admin.PHP SQL Injection Vulnerability
BugTraq ID: 17394
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17394
Summary:
MD News is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
29. Fuju News SQL Injection and Authentication Bypass Vulnerabilities
BugTraq ID: 17572
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17572
Summary:
Fuju News is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Fuju News is also susceptible to an authentication-bypass vulnerability. This issue is due to a design flaw that allows attackers to gain administrative access to the application. A successful exploit could allow an attacker to compromise the application.
Fuju News version 1.0 is vulnerable to these issues. Other versions may be affected as well.
30. Serendipity Blog Config.PHP Script Injection Vulnerability
BugTraq ID: 17566
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17566
Summary:
Serendipity Blog is prone to a script-injection vulnerability. A malicious user can exploit this vulnerability to execute arbitrary, malicious PHP code.
Script code would be executed in the browser of users visiting the site with the privileges of the webserver process.
31. Coppermine Index.PHP Local File Include Vulnerability
BugTraq ID: 17570
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17570
Summary:
Coppermine is prone to a local file-include vulnerability. This may allow unauthorized users to view files and to execute local scripts.
Version 1.4.4 is vulnerable to this issue; other versions may also be affected.
32. Neon Responders Remote Clock Synchronization Denial of Service Vulnerability
BugTraq ID: 17569
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17569
Summary:
Neon Responders is susceptible to a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed network packets.
This issue allows remote attackers to crash the affected application, denying further service to legitimate users.
Version 5.4 of Neon Responders for Windows is vulnerable to this issue; other versions may also be affected.
33. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
BugTraq ID: 14902
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/14902
Summary:
A local denial-of-service vulnerability affects the Linux kernel on 64-bit Symmetric Multi-Processor (SMP) platforms.
Specifically, the vulnerability presents itself due to an omitted call to the 'sockfd_put()' function in the 32-bit-compatible 'routing_ioctl()' function.
The 32-bit-compatible 'tiocgdev ioctl()' function on x86-64 platforms is affected by this issue as well.
34. FlexBB Index.PHP SQL Injection Vulnerability
BugTraq ID: 17568
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17568
Summary:
FlexBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
FlexBB version 0.5.5 is reported vulnerable. Other versions may be affected as well.
35. Novell GroupWise Messenger Accept Language Remote Buffer Overflow Vulnerability
BugTraq ID: 17503
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17503
Summary:
Novell GroupWise Messenger is prone to a remote buffer-overflow vulnerability.
The vulnerability affects the Novell Messaging Agent component and arises when the server handles an 'Accept-Language' header containing excessive data.
A successful attack may lead to arbitrary code execution in the context of SYSTEM or superuser.
Novell GroupWise Messenger 2.0 is vulnerable to this issue.
36. Asterisk JPEG File Handling Integer Overflow Vulnerability
BugTraq ID: 17561
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17561
Summary:
Asterisk is prone to an integer-overflow vulnerability.
This issue arises when the application handles a malformed JPEG file.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application.
37. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
BugTraq ID: 15722
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15722
Summary:
A local denial-of-service vulnerability affects the Linux kernel.
The vulnerability arises due to a race-condition error in the handling of POSIX timer cleanup routines.
A successful attack can result in a kernel crash.
Linux kernel versions 2.6.10 to 2.6.14 are vulnerable to this issue.
38. MyBB Global Variable Overwrite Vulnerability
BugTraq ID: 17564
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17564
Summary:
MyBB is prone to a vulnerability that permits an attacker to overwrite global variables. This issue is due to a design flaw in handling HTTP GET and POST variables.
An attacker can exploit this issue to overwrite the global variables with arbitrary input. Through control of the global variables, the attacker may be able to perform cross-site scripting, SQL-injection, and other attacks.
39. Manila EditInBrowser Module HTML Injection Vulnerability
BugTraq ID: 17565
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17565
Summary:
Manila is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Version 9.0.1 is vulnerable; other versions may also be affected.
40. Manila Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17563
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17563
Summary:
Manila is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
41. Apache Libapreq2 Quadratic Behavior Denial of Service Vulnerability
BugTraq ID: 16710
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/16710
Summary:
Libapreq2 is prone to a vulnerability that may allow attackers to trigger a denial-of-service condition.
Libapreq2 versions prior to 2.0.7 are vulnerable.
42. Linux Kernel do_coredump Denial of Service Vulnerability
BugTraq ID: 15723
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15723
Summary:
Linux kernel is prone to a denial-of-service vulnerability caused by a race condition in 'do_coredump()'.
Successful exploitation can cause the system to stop responding to legitimate requests.
43. Jax Guestbook Jax_guestbook.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17560
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17560
Summary:
Jax Guestbook is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 3.50 is vulnerable to this issue; other versions may also be affected.
44. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released 9 security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted, and further information becomes available. This BID will then be retired.
These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1
45. Calendarix YearCal.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17562
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17562
Summary:
Calendarix is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Specific information regarding affected versions of Calendarix is currently unavailable.
46. BoastMachine Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17550
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17550
Summary:
BoastMachine is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
47. DbbS Multiple Input Validation Vulnerabilities
BugTraq ID: 17559
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17559
Summary:
DbbS is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and command-execution vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based
authentication credentials, execute commands to compromise the server, and launch other attacks.
48. PHPWebFTP Index.PHP Directory Traversal Vulnerability
BugTraq ID: 17557
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17557
Summary:
phpWebFTP is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve and execute arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Reports also indicate that access to the source code of the login script 'script.js' may reveal information that could aid an attacker in further attacks.
49. BetaBoard User Profile HTML Injection Vulnerability
BugTraq ID: 17556
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17556
Summary:
BetaBoard is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Version 0.1 is vulnerable; other versions may also be affected.
50. Blursoft Blur6ex Index.PHP Local File Include Vulnerability
BugTraq ID: 17554
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17554
Summary:
Blur6ex is prone to a local file-include vulnerability. This may allow an unauthorized user to view files and to execute local scripts.
51. BlackOrpheus Member.PHP SQL Injection Vulnerability
BugTraq ID: 17558
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17558
Summary:
BlackOrpheus is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
BlackOrpheus version 1.0 is reported vulnerable. Other versions may be affected as well.
52. Neuron Blog Multiple HTML Injection Vulnerabilities
BugTraq ID: 17552
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17552
Summary:
Neuron Blog is prone to multiple HTML-injection vulnerabilities; the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Neuron Blog 1.1 and prior are vulnerable.
53. DbbS Topics.PHP SQL Injection Vulnerability
BugTraq ID: 17338
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17338
Summary:
DbbS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
DbbS versions 2.0-alpha and prior are reported to be affected.
54. TinyPHPForum Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17553
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17553
Summary:
TinyPHPForum is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
55. Monster Top List Functions.PHP Remote File Include Vulnerability
BugTraq ID: 17546
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17546
Summary:
Monster Top List is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
56. Boardsolution Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17549
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17549
Summary:
Boardsolution is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 1.12 is vulnerable to this issue; other versions may also be affected.
57. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
BugTraq ID: 15745
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15745
Summary:
Linux kernel is susceptible to a local denial of service vulnerability.
This issue is triggered by consuming excessive kernel memory by obtaining numerous file lock leases. This issue is due to a memory leak in the kernel file lock lease code.
This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition, and a denial of service for legitimate users.
Kernel versions from 2.6.10 through to 2.6.14.2 are vulnerable to this issue.
58. ShoutBOOK Multiple HTML Injection Vulnerabilities
BugTraq ID: 17548
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17548
Summary:
ShoutBOOK is prone to multiple HTML-injection vulnerabilities; the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Versions 1.1 and prior are vulnerable.
59. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
60. myEvent Multiple Remote File Include Vulnerabilities
BugTraq ID: 17575
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17575
Summary:
myEvent is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 1.2 is vulnerable to these issues; other versions may also be affected.
61. MusicBox Multiple Input Validation Vulnerabilities
BugTraq ID: 17545
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17545
Summary:
MusicBox is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
62. Snipe Gallery Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17543
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17543
Summary:
Snipe Gallery is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
63. Snipe Gallery Multiple Input Validation Vulnerabilities
BugTraq ID: 15844
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15844
Summary:
Snipe Gallery is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, and exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.
Snipe Gallery versions 3.1.4 and prior are vulnerable; other versions may also be affected.
64. PHPGraphy Index.PHP Unauthorized Access Vulnerability
BugTraq ID: 17567
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17567
Summary:
phpGraphy is prone to an unauthorized-access vulnerability. This issue is due to a failure in the application to properly validate credentials before granting access to sensitive scripts.
An attacker can exploit this issue to inject arbitrary script code into pages of the application; other attacks are also possible.
65. Sun Solaris Proc Filesystem Pagedata Subsystem Local Denial Of Service Vulnerability
BugTraq ID: 16966
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/16966
Summary:
Sun Solaris is prone to a local denial-of-service vulnerability. This issue affects the pagedata subsystem of the Process File System.
A local unauthorized user can cause a system crash.
66. phpFaber TopSites Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17542
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17542
Summary:
phpFaber TopSites is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
67. IBM AIX MKLVCopy Local Privilege Escalation Vulnerability
BugTraq ID: 17115
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17115
Summary:
IBM AIX is susceptible to a local privilege escalation vulnerability in the 'mklvcopy' command.
IBM AIX version 5.3 is affected by this issue.
68. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash.
This issue allows local users to crash the kernel, denying service to legitimate users.
Kernel versions prior to 2.6.15 are vulnerable to this issue.
69. Fetchmail Missing Email Header Remote Denial of Service Vulnerability
BugTraq ID: 15987
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15987
Summary:
Fetchmail is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to handle unexpected input. This issue occurs only when Fetchmail is configured in 'multidrop' mode.
70. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
BugTraq ID: 15179
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15179
Summary:
Fetchmail is susceptible to an information-disclosure vulnerability. This issue is due to a race condition in the 'fetchmailconf' configuration utility.
This issue allows local attackers to gain access to potentially sensitive information, including email authentication credentials, aiding them in further attacks.
Versions of Fetchmail prior to 6.2.9-rc6 include a vulnerable version of 'fetchmailconf'. Versions of 'fetchmailconf' prior to 1.43.2 and 1.49 are vulnerable.
71. Linux Kernel ICMP_Push_Reply Remote Denial Of Service Vulnerability
BugTraq ID: 16044
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/16044
Summary:
Linux kernel is prone to a remote denial-of-service vulnerability.
Remote attackers can exploit this to leak kernel memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.
Linux kernel versions 2.6.12.5 and prior in the 2.6 series are vulnerable to this issue.
72. Linux Kernel IPV6 Local Denial of Service Vulnerability
BugTraq ID: 15156
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15156
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability.
This issue arises from an infinite loop when binding IPv6 UDP ports.
73. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
BugTraq ID: 15627
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15627
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
Local attackers may trigger this issue by obtaining numerous file-lock leases, which will consume excessive kernel log memory. Once the leases timeout, the event will be logged, and kernel memory will be consumed.
This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and a denial of service for legitimate users.
Kernel versions prior to 2.6.15-rc3 are vulnerable to this issue.
74. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial-of-service vulnerability.
Local attackers can exploit this vulnerability to corrupt kernel memory or free non-allocated memory. Successful exploitation will crash the kernel, effectively denying service to legitimate users.
75. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
BugTraq ID: 15642
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15642
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
In instances where a process is created via the 'clone()' system call with the 'CLONE_THREAD' argument ptraced, the kernel fails to properly ensure that the ptracing process is not attempting to trace itself.
This issue allows local users to crash the kernel, denying service to legitimate users.
Kernel versions prior to 2.6.14.2 are vulnerable to this issue.
76. Linux Kernel Multiple Security Vulnerabilities
BugTraq ID: 15049
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/15049
Summary:
Linux kernel is prone to multiple vulnerabilities. These issues may allow local and remote attackers to trigger denial-of-service conditions or to access sensitive kernel memory.
Linux kernel 2.6.x versions are known to be vulnerable at the moment. Other versions may be affected as well.
77. PHPLister Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17591
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17591
Summary:
phpLister is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 0.4.1 is vulnerable to this issue; other versions may also be affected.
78. RechnungsZentrale V2 Authent.PHP4 Remote File Include Vulnerability
BugTraq ID: 17589
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17589
Summary:
RechnungsZentrale V2 is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
79. RechnungsZentrale V2 Authent.PHP4 SQL Injection Vulnerability
BugTraq ID: 17588
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17588
Summary:
RechnungsZentrale V2 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.1.3 is vulnerable; other versions may also be affected.
80. Linux Kernel Shared Memory Security Restriction Bypass Vulnerability
BugTraq ID: 17587
Remote: No
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17587
Summary:
The Linux kernel is prone to a vulnerability regarding shared memory access.
A local attacker could potentially gain read and write access to shared memory and write access to read-only tmpfs filesystems, bypassing security restrictions.
An attacker can exploit this issue to possibly corrupt applications and their data when the applications use temporary files or shared memory.
81. phpLinks Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17586
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17586
Summary:
phpLinks is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 2.1.3.1 and prior are vulnerable to this issue; other versions may also be affected.
82. Empire Server Multiple Unspecified Vulnerabilities
BugTraq ID: 17585
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17585
Summary:
Empire Server is reportedly prone to multiple unspecified security vulnerabilities. The cause and impact of these issues are currently unknown.
This BID will update when more information becomes available.
83. axoverzicht.CGI Cross-Site Scripting Vulnerability
BugTraq ID: 17584
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17584
Summary:
axoverzicht.cgi is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
84. LinPHA Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17581
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17581
Summary:
LinPHA is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
LinPHA 1.1.0 is reported vulnerable. Other versions may be affected as well.
85. myEvent Multiple Input Validation Vulnerabilities
BugTraq ID: 17580
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17580
Summary:
myEvent is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
86. Xine Playlist Handling Remote Format String Vulnerability
BugTraq ID: 17579
Remote: Yes
Last Updated: 2006-04-18
Relevant URL: http://www.securityfocus.com/bid/17579
Summary:
xine is reported prone to a remote format-string vulnerability.
This issue arises when the application handles specially-crafted playlist files. An attacker can exploit this vulnerability by crafting a malicious file that contains format specifiers and sending the file to an unsuspecting user.
A successful attack may crash the application or lead to arbitrary code execution.
All versions of xine are considered vulnerable at the moment.
87. Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
BugTraq ID: 12837
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/12837
Summary:
The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines.
An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges.
These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11.
88. Linux Kernel SDLA_XFER Kernel Memory Disclosure Vulnerability
BugTraq ID: 16759
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16759
Summary:
The Linux kernel is affected by a local memory-disclosure vulnerability.
This issue allows an attacker to read kernel memory. Information gathered via exploitation may aid malicious users in further attacks.
This issue affects kernel versions 2.4.x up to 2.4.29-rc1, and 2.6.x up to 2.6.5.
89. Info-ZIP UnZip File Name Buffer Overflow Vulnerability
BugTraq ID: 15968
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/15968
Summary:
Info-ZIP 'unzip' is susceptible to a filename buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
90. Linux Kernel Multithreaded ITimer Leak Local Denial of Service Vulnerability
BugTraq ID: 15533
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/15533
Summary:
Linux Kernel is susceptible to a local denial-of-service vulnerability.
This issue allows local users to leak small amounts of kernel memory that won't be available again until the computer is restarted. By consuming as many POSIX timers as possible and by employing many different users to overcome resource limits, attackers may cause the kernel to crash.
Kernel versions 2.6.8 and prior are vulnerable to this issue.
91. OSCommerce Update.PHP Information Disclosure Vulnerability
BugTraq ID: 14294
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/14294
Summary:
osCommerce is prone to an information-disclosure vulnerability. An attacker could exploit this vulnerability to display the contents of any file normally readable by the webserver process.
Successful exploitation would result in information disclosure. Information obtained could aid the attacker in further attacks against the underlying system; other attacks are also possible.
This issue reportedly affects osCommerce version 2.2 milestone 2; other versions may also be vulnerable.
92. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
BugTraq ID: 14955
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/14955
Summary:
A local denial-of-service vulnerability affects the Linux kernel's USB subsystem. This issue is due to the kernel's failure to properly handle unexpected conditions when trying to handle URBs (USB Request Blocks).
Local attackers may exploit this vulnerability to trigger a kernel 'oops' on computers where the vulnerable USB subsystem is enabled. This would deny service to legitimate users.
93. BSD-Games Multiple Local Buffer Overflow Vulnerabilities
BugTraq ID: 17401
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17401
Summary:
Multiple games in the BSD-games package are prone to locally exploitable buffer-overflow vulnerabilities. These issues are due to insufficient bounds-checking when copying user-supplied input to insufficiently sized memory buffers.
Since these games are installed 'setgid games' on many operating systems, attackers may be able to exploit these issues to escalate privileges to this level.
94. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
BugTraq ID: 17541
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17541
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue arises in Intel EM64T CPUs when returning program control using SYSRET.
This vulnerability allows local users to crash the kernel, denying further service to legitimate users.
95. FlexBB Multiple HTML Injection Vulnerabilities
BugTraq ID: 17539
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17539
Summary:
FlexBB is prone to multiple HTML-injection vulnerabilities; the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Versions 0.5.7 BETA and prior are vulnerable.
96. PHPGuestbook HTML Injection Vulnerability
BugTraq ID: 17537
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17537
Summary:
phpGuestbook is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
Versions 1.0 and prior are vulnerable.
97. Tiny Web Gallery Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17536
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17536
Summary:
Tiny Web Gallery is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.4 and prior are vulnerable.
98. Avast! Linux Home Edition Insecure Temporary File Creation Vulnerability
BugTraq ID: 17535
Remote: No
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17535
Summary:
Avast! Linux Home Edition creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
A successful attack would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive files. This may result in a denial of service; other attacks may also be possible.
99. FarsiNews Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17534
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/17534
Summary:
FarsiNews is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
100. AOblogger Multiple Input Validation Vulnerabilities
BugTraq ID: 16286
Remote: Yes
Last Updated: 2006-04-17
Relevant URL: http://www.securityfocus.com/bid/16286
Summary:
AOblogger is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to:
- compromise the application
- access, modify, or create data
- steal cookie-based authentication credentials.
An attacker may also be able to exploit vulnerabilities in the underlying database implementation and to launch other attacks.
Version 2.3 is vulnerable; other versions may also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Browsers feel the fuzz
By: Robert Lemos
Security researchers are starting to aim network fuzzers away from servers and toward browsers, finding that dozens of flaws have been missed.
http://www.securityfocus.com/news/11387
2. Groups argue over merits of flaw bounties
By: Robert Lemos
Vulnerability researchers like getting paid for their research, but software companies criticize the programs. Do vulnerability-purchasing initiatives make sense?
http://www.securityfocus.com/news/11386
3. Seven arrested in online fraud crackdown
By: Robert Lemos
An ongoing investigation, dubbed Operation Rolling Stone by the U.S. Secret Service, has turned up links to the massive debit-card breaches that have worried banks and consumers.
http://www.securityfocus.com/news/11385
4. Patches released for zero-day IE threat
By: Robert Lemos
UPDATE: As hundreds of malicious Web sites attempt to exploit the most critical of two Internet Explorer flaws disclosed last week, two third-party firms release fixes to nix the threat.<br />
See also: <a href="http://www.securityfocus.com/brief/174">Thousands download third-party patches</a>
http://www.securityfocus.com/news/11384
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Analyst, London
http://www.securityfocus.com/archive/77/431290
2. [SJ-JOB] Security Consultant, Edinburgh
http://www.securityfocus.com/archive/77/431291
3. [SJ-JOB] Regional Channel Manager, San Francisco
http://www.securityfocus.com/archive/77/431293
4. [SJ-JOB] Security Consultant, san jose
http://www.securityfocus.com/archive/77/431294
5. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/431286
6. [SJ-JOB] Database Security Engineer, Hyderabad
http://www.securityfocus.com/archive/77/431292
7. [SJ-JOB] Security Architect, Seattle
http://www.securityfocus.com/archive/77/431149
8. [SJ-JOB] Information Assurance Engineer, Sierra Vista/Ft. Huachuca
http://www.securityfocus.com/archive/77/431144
9. [SJ-JOB] Information Assurance Engineer, Mumbai
http://www.securityfocus.com/archive/77/431145
10. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/431146
11. [SJ-JOB] Director, Information Security, London
http://www.securityfocus.com/archive/77/431148
12. [SJ-JOB] Security System Administrator, San Diego
http://www.securityfocus.com/archive/77/431141
13. [SJ-JOB] Sr. Security Analyst, Indian Head
http://www.securityfocus.com/archive/77/431143
14. [SJ-JOB] Technical Support Engineer, Brussels
http://www.securityfocus.com/archive/77/431147
15. [SJ-JOB] Disaster Recovery Coordinator, London
http://www.securityfocus.com/archive/77/431140
16. [SJ-JOB] Sr. Security Engineer, Indian Head
http://www.securityfocus.com/archive/77/431142
17. [SJ-JOB] Auditor, Miami
http://www.securityfocus.com/archive/77/430914
18. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/430915
19. [SJ-JOB] Security Auditor, Atlanta
http://www.securityfocus.com/archive/77/430910
20. [SJ-JOB] Security Consultant, Warrington and Durham
http://www.securityfocus.com/archive/77/430913
21. [SJ-JOB] Security Engineer, Saratoga Region
http://www.securityfocus.com/archive/77/430908
22. [SJ-JOB] Management, Dubai
http://www.securityfocus.com/archive/77/430909
V. INCIDENTS LIST SUMMARY
---------------------------
1. Someone scanning for new PHP issues?
http://www.securityfocus.com/archive/75/431077
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. New site about security conferences : www.security-briefings.com
http://www.securityfocus.com/archive/82/431307
2. IE Update Possible vulnerability
http://www.securityfocus.com/archive/82/431139
3. Recon 2006: speaker lineup announcement
http://www.securityfocus.com/archive/82/430946
4. vulnerability research approach
http://www.securityfocus.com/archive/82/430810
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Windows Update error
http://www.securityfocus.com/archive/88/431107
2. MS06-013 Cumulative IE Update (912812) Issues
http://www.securityfocus.com/archive/88/430939
3. Detecting PwDump
http://www.securityfocus.com/archive/88/430932
4. SecurityFocus Microsoft Newsletter #286
http://www.securityfocus.com/archive/88/430755
5. Laptop Encryption & Write Permissions
http://www.securityfocus.com/archive/88/430680
6. Adding Users via Web Interface
http://www.securityfocus.com/archive/88/430662
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. about /dev/shm?
http://www.securityfocus.com/archive/91/431111
2. Syncing iptables rules between two servers
http://www.securityfocus.com/archive/91/430423
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: Lancope
"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response Systems in the Enterprise."
http://www.lancope.com/resource/