SecurityFocus Newsletter #347
Peter Laborge <[email protected]> Tue, 25 Apr 2006 17:11:47 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #347
----------------------------------------
This Issue is Sponsored By: SPI Dynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step!" - White Paper
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000CGKl
------------------------------------------------------------------
I. FRONT AND CENTER
1. Forensic felonies
2. Lessons learned from Microsoft's MS06-013 patch
II. BUGTRAQ SUMMARY
1. Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
2. Mozilla Suite/Firefox JavaScript Lambda Replace Heap Memory Disclosure Vulnerability
3. TotalCalendar Multiple Remote File Include Vulnerabilities
4. OpenTTD Multiple Denial Of Service Vulnerabilities
5. DNSmasq Broadcast Reply Denial Of Service Vulnerability
6. Blender BlenLoader File Processing Integer Overflow Vulnerability
7. Mozilla Firefox Large History File Buffer Overflow Vulnerability
8. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
9. Skulltag Remote Format String Vulnerability
10. Clansys Index.PHP Remote Code Execution Vulnerability
11. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
12. Fbida FBGS Insecure Temporary File Creation Vulnerability
13. Microsoft Internet Explorer Nested OBJECT Tag Memory Corruption Vulnerability
14. My Gaming Ladder Stats.PHP Remote File Include Vulnerability
15. iOpus Secure Email Attachments Encryption Weakness
16. CrossFire Denial Of Service Vulnerability
17. CoreNews Multiple Input Validation Vulnerabilities
18. RI Blog Multiple SQL Injection Vulnerabilities
19. VWar Admin.PHP Remote File Include Vulnerability
20. XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
21. Simplog ImageList.PHP Cross-Site Scripting Vulnerability
22. MKPortal Multiple Input Validation Vulnerabilities
23. dForum Multiple Remote File Include Vulnerabilities
24. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
25. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
26. GhostScript Insecure Temporary File Creation Vulnerability
27. Mike Neuman OSH Environment Variable Buffer Overflow Vulnerability
28. IP3 Networks IP3 NetAccess Appliance SQL Injection Vulnerability
29. Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
30. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
31. Mozilla Suite Multiple Remote Vulnerabilities
32. OpenSSH GSSAPI Credential Disclosure Vulnerability
33. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
34. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
35. Fenice Remote Buffer Overflow and Denial Of Service Vulnerabilities
36. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
37. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
38. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
39. Mozilla Firefox Drag And Drop Security Policy Bypass Vulnerability
40. Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
41. cURL / libcURL URL Parser Buffer Overflow Vulnerability
42. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
43. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
44. Mozilla Temporary File Insecure Permissions Information Disclosure Vulnerability
45. MyDNS DNS Query Denial Of Service Vulnerability
46. Cisco IOS EIGRP Goodbye Message Denial Of Service and Unauthorized Access Vulnerability
47. Mozilla Browser Network News Transport Protocol Remote Heap Overflow Vulnerability
48. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
49. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
50. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
51. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
52. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
53. Mozilla Thunderbird IFRAME JavaScript Execution Vulnerability
54. Mozilla Browser/Firefox Chrome Window Spoofing Vulnerability
55. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
56. Mozilla Browser/Firefox Chrome Page Loading Restriction Bypass Privilege Escalation Weakness
57. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
58. Mozilla Suite And Firefox DOM Property Overrides Code Execution Vulnerability
59. Mozilla Suite And Firefox Document Object Model Nodes Code Execution Vulnerability
60. Pablo Software Solutions Quick 'n Easy FTP Server Logging Buffer Overflow Vulnerability
61. Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
62. DCForumLite DCBoard.CGI Multiple Input Validation Vulnerabilities
63. Instant Photo Gallery Multiple Cross-Site Scripting Vulnerabilities
64. Invision Power Board Search.PHP Script Injection Vulnerability
65. Paul A. Rombouts PDNSD DNS Query Denial Of Service Vulnerability
66. Juniper JUNOSe DNS Client Denial Of Service Vulnerability
67. ISC BIND TSIG Zone Transfer Denial Of Service Vulnerability
68. DeleGate DNS Response Denial Of Service Vulnerability
69. Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
70. ABC2PS ABC Music Files Remote Buffer Overflow Vulnerability
71. PHPWebFTP Multiple Cross-Site Scripting Vulnerabilities
72. Sun Solaris PKCS#11 Library Local Privilege Escalation Vulnerability
73. 3Com Baseline Switch 2848-SFP Plus Remote Denial Of Service Vulnerability
74. NextAge Shopping Cart Multiple HTML Injection Vulnerabilities
75. Photokorn Multiple SQL Injection Vulnerabilities
76. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
77. Apple Safari Web Browser Rowspan Denial Of Service Vulnerability
78. vBulletin Calendar Script SQL Injection Vulnerability
79. RateIt Rateit.PHP SQL Injection Vulnerability
80. Built2go Movie Review Movie_CLS.PHP3 Remote File Include Vulnerability
81. Multiple Vendor DNS Message Decompression Remote Denial of Service Vulnerability
82. Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
83. Sybase Pylon Anywhere Unauthorized Access Vulnerability
84. FlexBB Multiple Input Validation Vulnerabilities
85. IBM AIX RM_MLCache_File Insecure Temporary File Creation Vulnerability
86. Mozilla Firefox iframe.contentWindow.focus Buffer Overflow Vulnerability
87. LogMethods A2Z.JSP Cross-Site Scripting Vulnerability
88. SL_site Gallerie.PHP Information Disclosure Vulnerability
89. IBM AIX MKLVCopy Local Privilege Escalation Vulnerability
90. Winny File Transfer Heap Overflow Vulnerability
91. Lotus Domino Unspecified LDAP Denial of Service Vulnerability
92. PHPMyAgenda Agenda.PHP3 Remote File Include Vulnerability
93. Cisco Security Agent Crafted IP Packet Denial Of Service Vulnerability
94. SL_site Multiple Input Validation Vulnerabilities
95. Tcpick Write.C Remote Denial of Service Vulnerability
96. Scry Gallery Index.PHP Cross-Site Scripting Vulnerability
97. Evo-Dev evoBlog Comment Post HTML Injection Vulnerability
98. IZArc Hostile Destination Path Vulnerability
99. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
100. Blender BVF File Import Python Code Execution Vulnerability
III. SECURITYFOCUS NEWS
1. E-mail authentication gaining steam
2. Browsers feel the fuzz
3. Groups argue over merits of flaw bounties
4. Seven arrested in online fraud crackdown
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Principal Software Engineer, Calgary
2. [SJ-JOB] Senior Software Engineer, Calgary
3. [SJ-JOB] Sr. Security Engineer, Red Bank
4. [SJ-JOB] Information Assurance Engineer, El Segundo
5. [SJ-JOB] Auditor, London
6. [SJ-JOB] Auditor, Charlotte
7. [SJ-JOB] Security Director, East Coast Preferred
8. [SJ-JOB] Sr. Security Engineer, London / Birmingham
9. [SJ-JOB] Technology Risk Consultant, Baltimore
10. [SJ-JOB] Quality Assurance, Columbia
11. [SJ-JOB] Security Engineer, Fort Lauderdale
12. [SJ-JOB] Jr. Security Analyst, Washington DC (Downtown)
13. [SJ-JOB] Director, Information Security, Columbus
14. [SJ-JOB] Sales Engineer, Chicago
15. [SJ-JOB] Sales Engineer, Atlanta
16. [SJ-JOB] Sales Engineer, Baltimore
17. [SJ-JOB] Sales Engineer, Nashville
18. [SJ-JOB] Director of Privacy and Security, King of Prussia
19. [SJ-JOB] Sales Engineer, Philadelphia
20. [SJ-JOB] Security Consultant, New York
21. [SJ-JOB] Security Consultant, Boston
22. [SJ-JOB] Sales Representative, Atlanta
23. [SJ-JOB] Security Consultant, New York
24. [SJ-JOB] Evangelist, Anywhere on the West Coast
25. [SJ-JOB] Application Security Engineer, Ashburn
26. [SJ-JOB] Sales Representative, Minneapolis
27. [SJ-JOB] Sr. Security Engineer, Roseland
28. [SJ-JOB] Sr. Security Analyst, Framingham
29. [SJ-JOB] Sales Representative, Chicago
30. [SJ-JOB] Security Consultant, Birmingham/London
31. [SJ-JOB] Application Security Engineer, North Denver
32. [SJ-JOB] Sr. Security Analyst, Waukegan
33. [SJ-JOB] Information Assurance Analyst, Tyson's Corner
34. [SJ-JOB] Sales Representative, Dulles
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. 0DAY Firefox Remote Code Execution and Denial of Service Vulnerability <=1.5.0.2 iframe.contentWindow.focus()
VII. MICROSOFT FOCUS LIST SUMMARY
1. File/Directory Permission Setting in Windows 2k/2003 Security Template
2. SecurityFocus Microsoft Newsletter #287
3. Internet security on "hotspots"
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Content management solution w/ linux server?
2. Syncing iptables rules between two servers
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Forensic felonies
By Mark Rasch
A new law in Georgia on private investigators extends to computer forensics and computer incident response, meaning that forensics experts who testify in court without a PI license may be committing a felony.
http://www.securityfocus.com/columnists/399
2. Lessons learned from Microsoft's MS06-013 patch
By Bob Rudis
This article takes a quick look at the functionality changes in MS06-013, and then discusses the new types of deployment decisions that are being made within enterprise environments in light of this critical Microsoft security patch.
http://www.securityfocus.com/infocus/1863
II. BUGTRAQ SUMMARY
--------------------
1. Mike Neuman OSH Command Line Argument Buffer Overflow Vulnerability
BugTraq ID: 12455
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12455
Summary:
A buffer overflow vulnerability is reported for osh when processing superfluous command line arguments. The problem likely occurs due to insufficient bounds checking when copying command line argument data into an internal memory buffer.
This buffer overflow may be exploited to execute arbitrary code with superuser privileges.
2. Mozilla Suite/Firefox JavaScript Lambda Replace Heap Memory Disclosure Vulnerability
BugTraq ID: 12988
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12988
Summary:
Mozilla Suite/Firefox are reported prone to a memory-disclosure vulnerability. This issue can allow a remote attacker to access arbitrary heap memory.
Due to an error in the way 'replace()' handles lambda expressions, a remote attacker can access arbitrary heap memory from a vulnerable client.
Information harvested in this manner could then aid in further attacks launched against the vulnerable computer (such as memory-corruption exploits).
Firefox versions 1.0.1 and 1.0.2 are reported vulnerable. Mozilla 1.7.6 is vulnerable as well. Other versions may also be affected.
K-Meleon 0.9 is vulnerable to this issue. Older versions may be affected as well.
Camino 0.8.3 is affected by this issue. Other versions of Camino may be affected as well.
3. TotalCalendar Multiple Remote File Include Vulnerabilities
BugTraq ID: 17618
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17618
Summary:
TotalCalendar is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
4. OpenTTD Multiple Denial Of Service Vulnerabilities
BugTraq ID: 17661
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17661
Summary:
OpenTTD is prone to multiple remote denial-of-service vulnerabilities.
An attacker can cause the application to crash or fail to function properly, thus denying service to legitimate users.
5. DNSmasq Broadcast Reply Denial Of Service Vulnerability
BugTraq ID: 17662
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17662
Summary:
Dnsmasq is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to crash by sending a 'broadcast reply' request to the server application.
By causing the application to crash, the attacker can deny service to legitimate users.
6. Blender BlenLoader File Processing Integer Overflow Vulnerability
BugTraq ID: 15981
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/15981
Summary:
Blender is susceptible to an integer-overflow vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a memory allocation and copy operation.
This issue allows attackers to execute arbitrary machine code in the context of the user running the affected application.
7. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.
This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.
This may cause a denial-of-service condition.
**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.
8. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
BugTraq ID: 17635
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17635
Summary:
GDM is prone to an improper file-permissions vulnerability.
An attacker can exploit this issue to gain access to sensitive or privileged information that may facilitate a complete compromise of the vulnerable computer.
9. Skulltag Remote Format String Vulnerability
BugTraq ID: 17659
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17659
Summary:
Skulltag is reported prone to a remote format-string vulnerability.
As a result of this issue, malicious data containing format specifiers may be interpreted literally by the application, which may cause attacker-specified memory to be disclosed or corrupted, leading to arbitrary code execution.
A successful exploit could cause the application to fail or arbitrary code to run in the context of the application.
10. Clansys Index.PHP Remote Code Execution Vulnerability
BugTraq ID: 17660
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17660
Summary:
Clansys is prone to an arbitrary code-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary malicious PHP code in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
11. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 17310
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17310
Summary:
Dia is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the affected application to open attacker-supplied malicious XFig files.
12. Fbida FBGS Insecure Temporary File Creation Vulnerability
BugTraq ID: 17436
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17436
Summary:
The 'fbida' utilities create temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
A successful attack would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive files. This may result in a denial of service; other attacks may also be possible.
13. Microsoft Internet Explorer Nested OBJECT Tag Memory Corruption Vulnerability
BugTraq ID: 17658
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17658
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This issue is due to a flaw in the application in handling nested OBJECT tags in HTML content.
An attacker could exploit this issue via a malicious web page to potentially execute arbitrary code in the context of the currently logged-in user, but this has not been confirmed. Exploit attempts likely result in crashing the affected application. Attackers could exploit this issue through HTML email/newsgroup postings or through other applications that employ the affected component.
Microsoft Internet Explorer 6 for Microsoft Windows XP SP2 is reportedly vulnerable to this issue; other versions may also be affected.
14. My Gaming Ladder Stats.PHP Remote File Include Vulnerability
BugTraq ID: 17657
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17657
Summary:
My Gaming Ladder is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 7.0 of My Gaming Ladder is vulnerable to this issue; other versions may also be affected.
15. iOpus Secure Email Attachments Encryption Weakness
BugTraq ID: 17656
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17656
Summary:
iOpus Secure Email Attachments is susceptible to an insecure-encryption weakness. This issue is due to a design flaw in the encryption algorithm used in the application.
The insecure method of encrypting attachments may result in a substantially less than brute-force attack against certain passwords used to encrypt attachments.
16. CrossFire Denial Of Service Vulnerability
BugTraq ID: 16883
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/16883
Summary:
CrossFire is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the application to crash by activating the 'oldsocketmode' option, and then sending an overly large request to the server application.
An attacker may cause the application to crash, thus denying service to legitimate users; remote code execution may also be possible.
17. CoreNews Multiple Input Validation Vulnerabilities
BugTraq ID: 17655
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17655
Summary:
CoreNews is prone to multiple input-validation vulnerabilities. The issues include remote file-include and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successfully exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
CoreNews version 2.0.1 is vulnerable to these issues; other versions may also be affected.
18. RI Blog Multiple SQL Injection Vulnerabilities
BugTraq ID: 17654
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17654
Summary:
RI Blog is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
19. VWar Admin.PHP Remote File Include Vulnerability
BugTraq ID: 17443
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17443
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
20. XZGV Image Viewer JPEG File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 17409
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17409
Summary:
The 'xzgv' viewer is reported prone to a remote heap-overflow vulnerability.
This issue is reported to present itself when the application handles a specially crafted JPEG image. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue affects 'xzgv' 0.8 and prior. 'zgv' image viewer is vulnerable to this issue as well.
21. Simplog ImageList.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17653
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17653
Summary:
Simplog is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Simplog version 0.9.3 is vulnerable to this issue; other versions may also be affected.
22. MKPortal Multiple Input Validation Vulnerabilities
BugTraq ID: 17651
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17651
Summary:
MKPortal is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successfully exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
MKPortal version 1.1 in conjunction with vBulletin 3.5.4 is vulnerable to these issues; other versions may also be affected.
23. dForum Multiple Remote File Include Vulnerabilities
BugTraq ID: 17650
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17650
Summary:
dForum is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
24. XFree86 Pixmap Allocation Local Privilege Escalation Vulnerability
BugTraq ID: 14807
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/14807
Summary:
XFree86 is prone to a buffer overrun in its pixmap-processing code.
This issue can potentially allow an attacker to execute arbitrary code and to escalate privileges. An attacker may possibly gain superuser privileges by exploiting this issue.
25. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
26. GhostScript Insecure Temporary File Creation Vulnerability
BugTraq ID: 11285
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/11285
Summary:
Ghostscript creates temporary files in an insecure manor. This issue is likely due to a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation.
27. Mike Neuman OSH Environment Variable Buffer Overflow Vulnerability
BugTraq ID: 15370
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15370
Summary:
Osh is susceptible to a buffer overflow vulnerability when processing environment variables. This issue is due to a flaw in the application that results in overwriting adjacent environment variables with user-supplied contents.
This issue may be exploited to execute arbitrary code with superuser privileges.
28. IP3 Networks IP3 NetAccess Appliance SQL Injection Vulnerability
BugTraq ID: 9858
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/9858
Summary:
It has been reported that the IP3 NetAccess Appliance is prone to a remote SQL injection vulnerability. This issue is due to a failure of the appliance to properly sanitize user input.
This issue may allow an attacker to gain full control of the appliance through the network administration interface. It may also be possible for a malicious user to influence database queries in order to view or modify sensitive information potentially compromising the system or the database.
29. Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
BugTraq ID: 12881
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12881
Summary:
Multiple Mozilla products are affected by a remote heap-overflow vulnerability. This issue affects the GIF image processing library used by Mozilla Firefox, Mozilla Browser, and Mozilla Thunderbird Mail client.
A successful attack can result in arbitrary code execution and in unauthorized access to the affected computer. Arbitrary code execution will take place in the context of a user running a vulnerable application.
*Update: K-Meleon, which is based on the Mozilla Gecko-code base, is also prone to this issue.
30. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
31. Mozilla Suite Multiple Remote Vulnerabilities
BugTraq ID: 12659
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12659
Summary:
Multiple remote vulnerabilities affect Mozilla Suite, Firefox, and Thunderbird, as reported in several Mozilla Foundation Security Advisories:
- 2005-28: An issue affecting the plugin functionality; temporary directories are created in an insecure manner.
- 2005-22: A dialog-spoofing vulnerability.
- 2005-21: A '.lnk' link file arbitrary file-overwrite vulnerability.
- 2005-20: An XSLT stylesheet information-disclosure vulnerability.
- 2005-19: An information-disclosure issue affecting the form auto-complete functionality.
- 2005-18: A buffer-overflow vulnerability.
- 2005-17: A dialog-spoofing vulnerability affecting installation confirmation.
- 2005-15: A heap-overflow vulnerability in UTF8 encoding.
- 2005-15: Multiple spoofing vulnerabilities affecting the SSL 'secure site' lock icon.
An attacker may leverage these issues to spoof dialog boxes and SSL 'secure site' icons, to carry out symbolic-link attacks, to execute arbitrary code, and to access potentially sensitive information.
Please note that this BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed, at which time this 'umbrella' BID will be retired.
32. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability.
Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user employs authentication methods other than GSSAPI to connect, which is not usually expected.
This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use those credentials to access resources granted to the original principal.
This issue affects versions of OpenSSH prior to 4.2.
33. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
BugTraq ID: 14727
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14727
Summary:
OpenSSH is susceptible to a vulnerability that causes improper activation of the 'GatewayPorts' option, allowing unintended hosts to use the SSH SOCKS proxy.
Specifically, if the 'DynamicForward' option is activated, 'GatewayPorts' is also unconditionally enabled.
This vulnerability allows remote attackers to use the SOCKS proxy to make arbitrary TCP connections through the configured SSH session, allowing them to attack computers and services through a connection that was wrongly thought to be secure.
This issue affects OpenSSH 4.0, and 4.1.
34. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash.
This issue allows local users to crash the kernel, denying service to legitimate users.
Kernel versions prior to 2.6.15 are vulnerable to this issue.
35. Fenice Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17678
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17678
Summary:
Fenice is susceptible to multiple remote vulnerabilities:
- A buffer-overflow vulnerability. The application fails to perform sufficient bounds checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue potentially allows remote attackers to execute arbitrary machine code in the context of the affected server process. Failed exploit attempts will likely crash the application, denying service to legitimate users.
- A denial-of-service vulnerability due to an integer-overflow flaw. This issue allows remote attackers to crash the affected application, denying service to legitimate users.
Version 1.10 of Fenice is vulnerable to these issues; other versions may also be affected.
36. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
BugTraq ID: 15745
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15745
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
This issue is triggered when excessive kernel memory is consumed by numerous file-lock leases. This problem stems from a memory leak in the kernel's file-lock lease code.
This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and ultimately to a denial of service for legitimate users.
Kernel versions from 2.6.10 through to 2.6.14.2 are vulnerable to this issue.
37. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
BugTraq ID: 15627
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15627
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.
Local attackers may trigger this issue by obtaining numerous file-lock leases, which will consume excessive kernel log memory. Once the leases timeout, the event will be logged, and kernel memory will be consumed.
This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and a denial of service for legitimate users.
Kernel versions prior to 2.6.15-rc3 are vulnerable to this issue.
38. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
BugTraq ID: 15629
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15629
Summary:
Perl is susceptible to a format-string vulnerability. This issue is due to the programming language's failure to properly handle format specifiers in formatted-printing functions.
An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.
Developers should treat the formatted printing functions in Perl as equivalently vulnerable to exploitation as the C library versions, and should properly sanitize all data passed in the format-specifier argument.
All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.
39. Mozilla Firefox Drag And Drop Security Policy Bypass Vulnerability
BugTraq ID: 12468
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12468
Summary:
Mozilla Firefox is reported prone to a security vulnerability that could allow a malicious website to bypass drag-and-drop functionality security policies.
A user can exploit this vulnerability with an image that renders correctly in the Firefox browser, but is saved with a '.bat' file extension when dragged and dropped onto the local filesystem.
Since the batch file interpreter on Microsoft Windows is particularly lenient when it comes to syntax, batch commands appended to the image file will be executed if the image that was dragged and dropped is invoked.
Update: Netscape 7.2 is reported vulnerable to this issue as well. Other versions may also be affected.
40. Multiple Mozilla/Firefox/Thunderbird Vulnerabilities
BugTraq ID: 12407
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12407
Summary:
Mozilla, Firefox, and Thunderbird applications are reported prone to multiple vulnerabilities. The following specific issues are reported:
- Access-control bypass (Mozilla and Firefox browsers). Although unconfirmed, this vulnerability presumably may be exploited to access information pertaining to a target filesystem. For example, an attacker may be able to determine whether a file exists or not.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Status-bar misrepresentation (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional status-bar misrepresentation (Mozilla and Firefox browsers). Using JavaScript to automate the process, a remote attacker may exploit this vulnerability to aid in phishing-style attacks (e.g. to make a malicious site appear authentic).
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla and Firefox browsers provide functionality (Alt-Click) to download files that are linked by URIs to the default download location without requiring a user prompt. Reports indicate that a malicious site may exploit this functionality to download a file to the default download location without user interaction.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Clipboard information-disclosure vulnerability (Mozilla and Firefox browsers). A remote attacker may exploit this vulnerability to steal clipboard contents, which may reveal potentially sensitive information to a remote attacker.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Additional information-disclosure vulnerability (Mozilla and Firefox browsers). A remote malicious server may invoke a request against a vulnerable browser and the browser will respond with proxy-authentication credentials.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0 and Mozilla Suite versions prior to 1.7.5.
- Mozilla Thunderbird erroneously responds to cookie requests that are contained in HTML-based email. Reportedly, a remote attacker may exploit this vulnerability to track emails to victim users.
This vulnerability is reported to affect Thunderbird versions 0.6 to 0.9 and Mozilla Suite 1.7 to 1.7.3.
- Local code-execution vulnerability (Mozilla Firefox). The vulnerability exists in the Livefeed bookmark functionality. If, for example, 'about:config' is displayed when the Livefeed is updated, then arbitrary code execution may reportedly occur on the affected computer.
This vulnerability is reported to affect Mozilla Firefox versions prior to 1.0.
- Mozilla Thunderbird reportedly fails to handle 'javascript:' URI links. The affected application employs the default handler for 'javascript:' URIs that is registered on the host operating system. This is incorrect behavior and may result in exposure to latent vulnerabilities due to a false sense of security.
This vulnerability is reported to affect Mozilla Thunderbird versions prior to 0.9.
This BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed.
41. cURL / libcURL URL Parser Buffer Overflow Vulnerability
BugTraq ID: 15756
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15756
Summary:
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issues occur when the URL parser function handles an excessively long URL string.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.
42. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.
These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1
43. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
BugTraq ID: 17446
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17446
Summary:
Cyrus SASL is affected by a remote denial-of-service vulnerability. This issue occurs before successful authentication, allowing anonymous remote attackers to trigger it.
This vulnerability allows remote attackers to crash services using the affected SASL library, denying service to legitimate users.
This issue reportedly affects version 2.1.18 of Cyrus SASL; other versions may also be affected.
44. Mozilla Temporary File Insecure Permissions Information Disclosure Vulnerability
BugTraq ID: 11522
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/11522
Summary:
Mozilla, Mozilla Firefox, and Mozilla Thunderbird are all reported susceptible to an information-disclosure vulnerability. The applications fail to properly ensure secure file permissions on temporary files located in world-accessible locations.
This vulnerability allows local attackers to access the contents of potentially sensitive files, which may aid them in further attacks.
45. MyDNS DNS Query Denial Of Service Vulnerability
BugTraq ID: 16431
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/16431
Summary:
MyDNS is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle DNS queries.
An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.
The vendor has addressed this issue in version 1.1.0; earlier versions are reportedly vulnerable.
46. Cisco IOS EIGRP Goodbye Message Denial Of Service and Unauthorized Access Vulnerability
BugTraq ID: 14877
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14877
Summary:
Cisco IOS is vulnerable to a denial-of-service and unauthorized access vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions in the EIGRP implementation of selective neighbors and potentially intercept, modify and redirect messages.
Cisco is tracking this vulnerability as bug id CSCsc13698.
47. Mozilla Browser Network News Transport Protocol Remote Heap Overflow Vulnerability
BugTraq ID: 12131
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/12131
Summary:
A remote heap-overflow vulnerability affects Mozilla Browser's network news transport protocol (NNTP) functionality. This issue is due to the application's failure to properly validate the length of user-supplied strings before copying them into dynamically allocated process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
48. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
BugTraq ID: 17682
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17682
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.
These issues include:
- Buffer-overflow vulnerabilities
- Denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
- Off-by-one overflow vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect different versions of Ethereal, from 0.8.5 through to 0.10.14.
49. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
50. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
51. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 17439
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17439
Summary:
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.
These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, when the 'safe_mode' and 'open_basedir' restrictions are expected to isolate the users from each other.
These issues are reported to affect PHP versions 4.4.2 and 5.1.2; other versions may also be vulnerable.
52. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
BugTraq ID: 16881
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/16881
Summary:
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.
These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.
Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.
53. Mozilla Thunderbird IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Mozilla Thunderbird is prone to a script-execution vulnerability.
The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.
Mozilla Thunderbird 1.0.7 and prior versions are reportedly affected.
54. Mozilla Browser/Firefox Chrome Window Spoofing Vulnerability
BugTraq ID: 14919
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14919
Summary:
Mozilla and Firefox browsers are prone to a window-spoofing vulnerability.
An attacker can exploit this vulnerability to enhance phishing-style attacks.
55. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.
Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.
56. Mozilla Browser/Firefox Chrome Page Loading Restriction Bypass Privilege Escalation Weakness
BugTraq ID: 14920
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14920
Summary:
Mozilla Browser/Firefox are prone to a potential arbitrary code-execution weakness.
Specifically, an attacker can load privileged 'chrome' pages from an unprivileged 'about:' page. This issue does not pose a threat unless it is combined with a same-origin violation issue.
If successfully exploited, this issue may allow a remote attacker to execute arbitrary code and gain unauthorized remote access to a computer. This would occur in the context of the user running the browser.
57. Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities
BugTraq ID: 14242
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/14242
Summary:
The Mozilla Foundation has released 12 security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, and Thunderbird.
These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, to bypass security checks, and to execute script code in the context of targeted websites to disclose confidential information; other attacks are also possible.
These vulnerabilities have been addressed in Firefox version 1.0.5 and in Mozilla Suite 1.7.9. At this time, Mozilla Thunderbird has not been fixed.
The issues described here will be split into individual BIDs as further analysis is completed. This BID will then be retired.
Reportedly, Netscape is also vulnerable to the issue described in MFSA 2005-47. Due to the nature of Netscape's fork from the Mozilla codebase, Netscape is also likely affected by most if not all of the issues that affect Mozilla Firefox. This has not been confirmed at this time.
58. Mozilla Suite And Firefox DOM Property Overrides Code Execution Vulnerability
BugTraq ID: 13645
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/13645
Summary:
Mozilla Suite and Mozilla Firefox are affected by a code execution vulnerability. This issue is due to a failure in the application to properly verify Document Object Model (DOM) property values.
An attacker may leverage this issue to execute arbitrary code with the privileges of the user that activated the vulnerable Web browser, ultimately facilitating a compromise of the affected computer.
This issue is reportedly a variant of BID 13233. Further details are scheduled to be released in the future, and this BID will be updated accordingly.
59. Mozilla Suite And Firefox Document Object Model Nodes Code Execution Vulnerability
BugTraq ID: 13233
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/13233
Summary:
Mozilla Suite and Mozilla Firefox are affected by a code execution vulnerability. This issue is due to a failure in the application to properly verify Document Object Model (DOM) property values.
An attacker may leverage this issue to execute arbitrary code with the privileges of the user that activated the vulnerable Web browser, ultimately facilitating a compromise of the affected computer.
It should be noted that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
60. Pablo Software Solutions Quick 'n Easy FTP Server Logging Buffer Overflow Vulnerability
BugTraq ID: 17681
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17681
Summary:
Quick 'n Easy FTP Server is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected server application. This likely occurs with SYSTEM-level privileges.
61. Mozilla Suite And Firefox XPInstall JavaScript Object Instance Validation Vulnerability
BugTraq ID: 13232
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/13232
Summary:
Mozilla Suite and Mozilla Firefox are affected by an input validation vulnerability. This issue is due to a failure in the application to verify input passed to installation objects.
An attacker may be able to exploit this issue to execute malicious code in the context of the affected browser, subsequently facilitating unauthorized access.
It should be noted that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
62. DCForumLite DCBoard.CGI Multiple Input Validation Vulnerabilities
BugTraq ID: 17697
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17697
Summary:
DCForumLite is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
63. Instant Photo Gallery Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17696
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17696
Summary:
Instant Photo Gallery is prone to multiple cross-site scripting vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
64. Invision Power Board Search.PHP Script Injection Vulnerability
BugTraq ID: 17695
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17695
Summary:
Invision Power Board is prone to a script-injection vulnerability. A malicious user can exploit this vulnerability to execute arbitrary, malicious PHP code.
Script code would be executed with the privileges of the webserver process.
65. Paul A. Rombouts PDNSD DNS Query Denial Of Service Vulnerability
BugTraq ID: 17694
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17694
Summary:
The pdnsd DNS server is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle DNS queries.
An attacker can exploit this issue to consume excessive memory, and then to crash the affected service, effectively denying service to legitimate users.
The vendor has addressed this issue in version 1.2.4-par; earlier versions are reportedly vulnerable.
66. Juniper JUNOSe DNS Client Denial Of Service Vulnerability
BugTraq ID: 17693
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17693
Summary:
Juniper JUNOSe is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle DNS datagrams.
An attacker can exploit this issue to crash the affected DNS client service, effectively denying service to legitimate users.
67. ISC BIND TSIG Zone Transfer Denial Of Service Vulnerability
BugTraq ID: 17692
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17692
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed TSIG (Secret Key Transaction Authentication for DNS) replies.
To exploit this issue, attackers must be able to send messages with a correct TSIG during a zone transfer, limiting the potential for remote exploits significantly.
An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.
68. DeleGate DNS Response Denial Of Service Vulnerability
BugTraq ID: 17691
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17691
Summary:
DeleGate is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed DNS responses.
An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.
The vendor has addressed this issue in versions 8.11.6 and 9.0.6; earlier versions are vulnerable.
69. Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
BugTraq ID: 17690
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17690
Summary:
Invision Power Board is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
70. ABC2PS ABC Music Files Remote Buffer Overflow Vulnerability
BugTraq ID: 17689
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17689
Summary:
abc2ps is prone to a remote buffer-overflow vulnerability.
A remote attacker can exploit this issue to execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
71. PHPWebFTP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17688
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17688
Summary:
PhpWebFtp is prone to multiple cross-site scripting vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input using the HTTP 'POST' method when submitting a malicious URI.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
72. Sun Solaris PKCS#11 Library Local Privilege Escalation Vulnerability
BugTraq ID: 17687
Remote: No
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17687
Summary:
Sun Solaris is susceptible to a local privilege-escalation vulnerability. This issue is due to a failure of the PKCS#11 library to properly utilize non-reentrant functions.
This issue allows local attackers to gain elevated privileges, potentially aiding them in the complete compromise of affected computers. This issue only affects certain applications that run with elevated privileges, as they have to utilize the affected functions in a very specific manner.
73. 3Com Baseline Switch 2848-SFP Plus Remote Denial Of Service Vulnerability
BugTraq ID: 17686
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17686
Summary:
3Com Baseline Switch 2848-SFP Plus is susceptible to a remote denial of service vulnerability. This issue is reportedly due to certain malformed traffic that results in a denial of service condition.
It is reported that this issue may result in the crash of the device, denying further network services to legitimate users. The vendor states that this issue results in the device becoming unstable.
3Com Baseline Switch 2848-SFP Plus firmware versions prior to 1.0.2.0 are vulnerable.
74. NextAge Shopping Cart Multiple HTML Injection Vulnerabilities
BugTraq ID: 17685
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17685
Summary:
NextAge Shopping Cart is prone to multiple HTML-injection vulnerabilities; the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
75. Photokorn Multiple SQL Injection Vulnerabilities
BugTraq ID: 17683
Remote: Yes
Last Updated: 2006-04-25
Relevant URL: http://www.securityfocus.com/bid/17683
Summary:
Photokorn is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
76. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
77. Apple Safari Web Browser Rowspan Denial Of Service Vulnerability
BugTraq ID: 17674
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17674
Summary:
Apple Safari web browser is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume excessive system resources and eventually crash an affected browser.
78. vBulletin Calendar Script SQL Injection Vulnerability
BugTraq ID: 9360
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/9360
Summary:
vBulletin is prone to an SQL injection vulnerability. As a result, remote attackers may influence the logic and structure of database queries made by the software. This could potentially be exploited to compromise the bulletin board installation, disclose sensitive information from within the database or even to launch attacks against the database implementation.
79. RateIt Rateit.PHP SQL Injection Vulnerability
BugTraq ID: 17518
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17518
Summary:
RateIt is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
RateIt version 2.2 is reported vulnerable. Other versions may be affected as well.
80. Built2go Movie Review Movie_CLS.PHP3 Remote File Include Vulnerability
BugTraq ID: 17679
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17679
Summary:
Built2Go Movie Review is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 2B and prior versions are affected.
81. Multiple Vendor DNS Message Decompression Remote Denial of Service Vulnerability
BugTraq ID: 13729
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/13729
Summary:
Multiple DNS vendors are susceptible to a remote denial-of-service vulnerability. This issue affects both DNS servers and clients.
This issue arises when an affected application handles a specially crafted DNS message.
A successful attack would crash the affected client or server.
82. Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
BugTraq ID: 17676
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17676
Summary:
Help Center Live is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
83. Sybase Pylon Anywhere Unauthorized Access Vulnerability
BugTraq ID: 17677
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17677
Summary:
Sybase Pylon Anywhere is prone to an access-validation vulnerability. This issue could allow an authenticated attacker to access other users' data.
Pylon Anywhere versions prior to 7.0 are vulnerable.
84. FlexBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17574
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17574
Summary:
FlexBB is prone to multiple input-validation vulnerabilities. The issues include HTML- and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successfully exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Version 0.5.5 of FlexBB is vulnerable to these issues; other versions may also be affected.
85. IBM AIX RM_MLCache_File Insecure Temporary File Creation Vulnerability
BugTraq ID: 17576
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17576
Summary:
The IBM AIX 'rm_mlcache_file' command may let local attackers overwrite arbitrary files.
This could lead to the destruction of sensitive data and a denial of service because the application creates temporary files in an insecure manner.
86. Mozilla Firefox iframe.contentWindow.focus Buffer Overflow Vulnerability
BugTraq ID: 17671
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17671
Summary:
Mozilla Firefox is prone to a buffer-overflow vulnerability when rendering malformed JavaScript content. An attacker could exploit this issue to cause the browser to fail or potentially execute arbitrary code.
Firefox version 1.5.0.2 and earlier versions running on Windows and Linux platforms are affected.
87. LogMethods A2Z.JSP Cross-Site Scripting Vulnerability
BugTraq ID: 17675
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17675
Summary:
LogMethods is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
LogMethods versions 0.9 and prior are vulnerable to this issue; other versions may also be affected.
88. SL_site Gallerie.PHP Information Disclosure Vulnerability
BugTraq ID: 17672
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17672
Summary:
SL_site is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary image files. This may be done by using directory-traversal sequences ('../') from the vulnerable system in the context of the application.
Information obtained by exploiting this issue may aid malicious users in further attacks.
89. IBM AIX MKLVCopy Local Privilege Escalation Vulnerability
BugTraq ID: 17115
Remote: No
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17115
Summary:
IBM AIX is susceptible to a local privilege-escalation vulnerability in the 'mklvcopy' command.
IBM AIX version 5.3 is affected by this issue.
90. Winny File Transfer Heap Overflow Vulnerability
BugTraq ID: 17666
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17666
Summary:
Winny is prone to a heap-overflow vulnerability. This issue is due to improper boundary checks on data supplied to the file-transfer port. An attacker could exploit this to execute arbitrary code in the context of the user that launched the application.
Winny 2.0 b7.1 and earlier are vulnerable.
91. Lotus Domino Unspecified LDAP Denial of Service Vulnerability
BugTraq ID: 17669
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17669
Summary:
Lotus Domino LDAP server is prone to an unspecified denial-of-service vulnerability when handling malformed requests.
Lotus Domino version 7.0 is vulnerable; earlier versions may also be affected.
This issue may be related to the one described in BID 16523 (Lotus Domino LDAP Denial of Service Vulnerability), but insufficient details are currently available to make a proper determination.
92. PHPMyAgenda Agenda.PHP3 Remote File Include Vulnerability
BugTraq ID: 17670
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17670
Summary:
phpMyAgenda is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
phpMyAgenda 3.0 Final and prior versions are affected.
93. Cisco Security Agent Crafted IP Packet Denial Of Service Vulnerability
BugTraq ID: 14247
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/14247
Summary:
A denial-of-service vulnerability has been reported in Cisco Security Agent (CSA). This issue may be triggered by a maliciously crafted IP packet.
Successful exploitation will crash the Microsoft Windows operating system hosting the Cisco Security Agent software. This vulnerability affects only CSA 4.5 on Windows operating systems other than Windows XP.
94. SL_site Multiple Input Validation Vulnerabilities
BugTraq ID: 17667
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17667
Summary:
SL_site is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
95. Tcpick Write.C Remote Denial of Service Vulnerability
BugTraq ID: 17665
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17665
Summary:
Tcpick is susceptible to a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed input.
This vulnerability allows remote attackers to crash the application, denying service to legitimate users.
96. Scry Gallery Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17668
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17668
Summary:
Scry Gallery is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Scry Gallery version 1.1 is vulnerable to this issue; other versions may also be affected.
97. Evo-Dev evoBlog Comment Post HTML Injection Vulnerability
BugTraq ID: 16983
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/16983
Summary:
Evo-Dev's evoBlog is prone to an HTML-injection vulnerability.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
98. IZArc Hostile Destination Path Vulnerability
BugTraq ID: 17664
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17664
Summary:
IZArc contains a vulnerability in the handling of pathnames for archived files.
By specifying a path for an archived item that points outside the expected destination directory, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem, possibly including paths containing system binaries and other sensitive or confidential information.
Presumably, an attacker could use this to create or overwrite binaries in any desired location, using the privileges of the invoking user.
Version 3.5 beta 3 is vulnerable; other versions may also be affected.
99. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
100. Blender BVF File Import Python Code Execution Vulnerability
BugTraq ID: 17663
Remote: Yes
Last Updated: 2006-04-24
Relevant URL: http://www.securityfocus.com/bid/17663
Summary:
Blender is susceptible to a Python code-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a Python 'eval' statement.
This issue allows attackers to execute arbitrary Python code in the context of the user running the affected application.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. E-mail authentication gaining steam
By: Robert Lemos
A host of software companies, security firms and Internet service providers meet in Chicago to urge corporations and bulk e-mail senders to adopt authentication technologies.
http://www.securityfocus.com/news/11388
2. Browsers feel the fuzz
By: Robert Lemos
Security researchers are starting to aim network fuzzers away from servers and toward browsers, finding that dozens of flaws have been missed.
http://www.securityfocus.com/news/11387
3. Groups argue over merits of flaw bounties
By: Robert Lemos
Vulnerability researchers like getting paid for their research, but software companies criticize the programs. Do vulnerability-purchasing initiatives make sense?
http://www.securityfocus.com/news/11386
4. Seven arrested in online fraud crackdown
By: Robert Lemos
An ongoing investigation, dubbed Operation Rolling Stone by the U.S. Secret Service, has turned up links to the massive debit-card breaches that have worried banks and consumers.
http://www.securityfocus.com/news/11385
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Principal Software Engineer, Calgary
http://www.securityfocus.com/archive/77/431919
2. [SJ-JOB] Senior Software Engineer, Calgary
http://www.securityfocus.com/archive/77/431918
3. [SJ-JOB] Sr. Security Engineer, Red Bank
http://www.securityfocus.com/archive/77/431882
4. [SJ-JOB] Information Assurance Engineer, El Segundo
http://www.securityfocus.com/archive/77/431880
5. [SJ-JOB] Auditor, London
http://www.securityfocus.com/archive/77/431881
6. [SJ-JOB] Auditor, Charlotte
http://www.securityfocus.com/archive/77/431883
7. [SJ-JOB] Security Director, East Coast Preferred
http://www.securityfocus.com/archive/77/431879
8. [SJ-JOB] Sr. Security Engineer, London / Birmingham
http://www.securityfocus.com/archive/77/431527
9. [SJ-JOB] Technology Risk Consultant, Baltimore
http://www.securityfocus.com/archive/77/431529
10. [SJ-JOB] Quality Assurance, Columbia
http://www.securityfocus.com/archive/77/431525
11. [SJ-JOB] Security Engineer, Fort Lauderdale
http://www.securityfocus.com/archive/77/431522
12. [SJ-JOB] Jr. Security Analyst, Washington DC (Downtown)
http://www.securityfocus.com/archive/77/431524
13. [SJ-JOB] Director, Information Security, Columbus
http://www.securityfocus.com/archive/77/431526
14. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/431523
15. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/431521
16. [SJ-JOB] Sales Engineer, Baltimore
http://www.securityfocus.com/archive/77/431366
17. [SJ-JOB] Sales Engineer, Nashville
http://www.securityfocus.com/archive/77/431419
18. [SJ-JOB] Director of Privacy and Security, King of Prussia
http://www.securityfocus.com/archive/77/431454
19. [SJ-JOB] Sales Engineer, Philadelphia
http://www.securityfocus.com/archive/77/431372
20. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/431374
21. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/431378
22. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/431451
23. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/431364
24. [SJ-JOB] Evangelist, Anywhere on the West Coast
http://www.securityfocus.com/archive/77/431375
25. [SJ-JOB] Application Security Engineer, Ashburn
http://www.securityfocus.com/archive/77/431382
26. [SJ-JOB] Sales Representative, Minneapolis
http://www.securityfocus.com/archive/77/431376
27. [SJ-JOB] Sr. Security Engineer, Roseland
http://www.securityfocus.com/archive/77/431381
28. [SJ-JOB] Sr. Security Analyst, Framingham
http://www.securityfocus.com/archive/77/431456
29. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/431377
30. [SJ-JOB] Security Consultant, Birmingham/London
http://www.securityfocus.com/archive/77/431385
31. [SJ-JOB] Application Security Engineer, North Denver
http://www.securityfocus.com/archive/77/431438
32. [SJ-JOB] Sr. Security Analyst, Waukegan
http://www.securityfocus.com/archive/77/431362
33. [SJ-JOB] Information Assurance Analyst, Tyson's Corner
http://www.securityfocus.com/archive/77/431363
34. [SJ-JOB] Sales Representative, Dulles
http://www.securityfocus.com/archive/77/431431
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. 0DAY Firefox Remote Code Execution and Denial of Service Vulnerability <=1.5.0.2 iframe.contentWindow.focus()
http://www.securityfocus.com/archive/82/431950
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. File/Directory Permission Setting in Windows 2k/2003 Security Template
http://www.securityfocus.com/archive/88/431867
2. SecurityFocus Microsoft Newsletter #287
http://www.securityfocus.com/archive/88/431339
3. Internet security on "hotspots"
http://www.securityfocus.com/archive/88/431338
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Content management solution w/ linux server?
http://www.securityfocus.com/archive/91/431513
2. Syncing iptables rules between two servers
http://www.securityfocus.com/archive/91/430423
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SPI Dynamics
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step!" - White Paper
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70130000000CGKl