SecurityFocus Newsletter #348

Peter Laborge <[email protected]> Tue, 02 May 2006 15:58:52 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #348
----------------------------------------

This Issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000007ka5

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Sendmail and secure design
        2. Five common Web application vulnerabilities
II.   BUGTRAQ SUMMARY
        1. Collaborative Portal Server POS Parameter Cross-Site Scripting Vulnerability
        2. Clam AntiVirus FreshClam Remote Buffer Overflow Vulnerability
        3. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
        4. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
        5. SWS Web Server Multiple Arbitrary Code Execution Vulnerabilities
        6. Mozilla Firefox Large History File Buffer Overflow Vulnerability
        7. Linux Kernel Multiple Security Vulnerabilities
        8. Linux Kernel CIFS CHRoot Security Restriction Bypass Vulnerability
        9. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
        10. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
        11. Linux Kernel Netfilter Ipt_recent Remote Denial of Service Vulnerability
        12. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
        13. Linux Kernel SCSI ProcFS Denial Of Service Vulnerability
        14. Artmedic Event Index.PHP Remote File Include Vulnerability
        15. LibTiff TIFFFetchData Integer Overflow Vulnerability
        16. Linux Kernel Raw_sendmsg() Kernel Memory Access Vulnerability
        17. LibTiff Double Free Memory Corruption Vulnerability
        18. Network Administration Visualized Multiple SQL Injection Vulnerabilities
        19. LibTiff Multiple Denial of Service Vulnerabilities
        20. Linux Kernel Sendmsg() Local Buffer Overflow Vulnerability
        21. Linux Kernel ZLib Local Null Pointer Dereference Denial of Service Vulnerability
        22. PHPWebSite Config.PHP File Include Vulnerability
        23. Linux Kernel ZLib Invalid Memory Access Local Denial of Service Vulnerability
        24. Linux Kernel ISO File System Denial Of Service Vulnerability
        25. Beagle Helper Applications Arbitrary Code Execution Vulnerability
        26. Linux Kernel Fib_Seq_Start Local Denial of Service Vulnerability
        27. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
        28. PHP MB_Send_Mail TO Argument Header Injection Vulnerability
        29. PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
        30. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
        31. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
        32. PHP File Upload GLOBAL Variable Overwrite Vulnerability
        33. PHP Parse_Str Register_Globals Activation Weakness
        34. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
        35. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
        36. Oracle 10g DBMS_EXPORT_EXTENSION SQL Injection Vulnerability
        37. CoolMenus Index.PHP Remote File Include Vulnerability
        38. Free-PHP.net Simple Poll Authentication Bypass Vulnerability
        39. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
        40. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
        41. Linux Kernel INVALIDATE_INODE_PAGES2 Local Integer Overflow Vulnerability
        42. Ruperts News Script Login.PHP SQL Injection Vulnerability
        43. DeltaScripts PHP Pro Publish Multiple SQL Injection Vulnerabilities
        44. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
        45. Limbo CMS SQL.PHP Remote File Include Vulnerability
        46. PHP Newsfeed Multiple SQL Injection Vulnerabilities
        47. ResMgr Unauthorized USB Device Access Vulnerability
        48. DMCounter Kopf.PHP Remote File Include Vulnerability
        49. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
        50. HB-NS Multiple Input Validation Vulnerabilities
        51. MPlayer Multiple Integer Overflow Vulnerabilities
        52. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
        53. EMC Dantz Retrospect Backup Server Local Privilege Escalation Vulnerability
        54. CmScout Multiple HTML Injection Vulnerabilities
        55. Pinnacle Cart Index.PHP Cross-Site Scripting Vulnerability
        56. Invision Gallery Post.PHP SQL Injection Vulnerability
        57. Fujitsu NetShelter Unspecified DNS Denial Of Service Vulnerability
        58. Virtual Hosting Control System Server_day_stats.PHP Multiple Cross-Site Scripting Vulnerabilities
        59. RSync Receive_XATTR Integer Overflow Vulnerability
        60. Russcom Network LoginPHP Open EMail Relay Vulnerability
        61. FileProtection Express Authentication Bypass Vulnerability
        62. Russcomm Network LoginPHP Username HTML Injection Vulnerability
        63. GeoBlog Viewcat.PHP Cross-Site Scripting Vulnerability
        64. SF-Users Username HTML Injection Vulnerability
        65. SBlog Search.PHP SQL Injection Vulnerability
        66. XDT Pro Stats.PHP Cross-Site Scripting Vulnerability
        67. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
        68. Zenphoto Multiple Cross-Site Scripting Vulnerabilities
        69. JSBoard Login.PHP Cross-Site Scripting Vulnerability
        70. X7 Chat Index.PHP Local File Include Vulnerability
        71. Cisco Unity Express Expired Password Privilege Escalation Vulnerability
        72. MKPortal Multiple Input Validation Vulnerabilities
        73. JMK Picture Gallery Admin_Gallery.PHP3 Authentication Bypass Vulnerability
        74. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
        75. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
        76. PlanetGallery Gallery_admin.PHP Authentication Bypass Vulnerability
        77. W-Agora BBCode Script Injection Vulnerability
        78. Linux Kernel IPV6 Local Denial of Service Vulnerability
        79. Asterisk Voicemail Unauthorized Access Vulnerability
        80. Asterisk JPEG File Handling Integer Overflow Vulnerability
        81. TextFileBB Multiple Tag Script Injection Vulnerabilities
        82. PHPNuke Downloads Module SQL Injection Vulnerability
        83. 4Images Multiple SQL Injection Vulnerabilities
        84. I-RATER Platinum Config_settings.TPL.PHP Remote File Include Vulnerability
        85. Thyme Search Page HTML Injection Vulnerability
        86. Advanced GuestBook Addentry.PHP Remote File Include Vulnerability
        87. Blog Mod Weblog_posting.PHP SQL Injection Vulnerability
        88. OpenPHPnuke Remote File Include Vulnerability
        89. SunShop Shopping Cart Multiple Cross-Site Scripting Vulnerabilities
        90. Xine Filename Handling Remote Format String Vulnerability
        91. Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
        92. OrbitHYIP Multiple Cross-Site Scripting Vulnerabilities
        93. MaxTrade Multiple SQL Injection Vulnerabilities
        94. phpBB Knowledge Base Mod KB_constants.PHP Remote File Include Vulnerability
        95. AZNEWS News.PHP SQL Injection Vulnerability
        96. Linux Orinoco Driver Remote Information Disclosure Vulnerability
        97. PostNuke Multiple Cross-Site Scripting Vulnerabilities
        98. Oracle Multiple Unspecified Vulnerabilities
        99. Trac Wiki Macro Remote HTML Injection Vulnerabilities
        100. Mozilla Thunderbird IFRAME JavaScript Execution Vulnerability
III.  SECURITYFOCUS NEWS
        1. Breach case could curtail Web flaw finders
        2. E-mail authentication gaining steam
        3. Browsers feel the fuzz
        4. Groups argue over merits of flaw bounties
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Account Manager, San Francisco
        2. [SJ-JOB] Account Manager, Chicago
        3. [SJ-JOB] Sales Engineer, Chicago
        4. [SJ-JOB] Sales Engineer, Detroit
        5. [SJ-JOB] Security Engineer, Elizabeth
        6. [SJ-JOB] Sr. Security Analyst, London, South East
        7. [SJ-JOB] Information Assurance Engineer, Arlington
        8. [SJ-JOB] Sales Representative, Houston
        9. [SJ-JOB] Security Researcher, San Francisco
        10. [SJ-JOB] Security Engineer, New York
        11. [SJ-JOB] Software Engineer, Ft. Huachuca
        12. [SJ-JOB] Account Manager, Los Angeles
        13. [SJ-JOB] Technology Risk Consultant, Jersey City
        14. [SJ-JOB] Account Manager, Any
        15. [SJ-JOB] Security Researcher, Mountain View
        16. [SJ-JOB] Sr. Security Engineer, Indian Head
        17. [SJ-JOB] Quality Assurance, Houston
        18. [SJ-JOB] Sr. Security Analyst, Santa Clara
        19. [SJ-JOB] Account Manager, New York
        20. [SJ-JOB] Security Engineer, Troy
        21. [SJ-JOB] Sales Engineer, Canberra
        22. [SJ-JOB] Security Consultant, Delhi
        23. [SJ-JOB] Security Researcher, Santa Clara
        24. [SJ-JOB] Security Engineer, Dallas / Richardson
        25. [SJ-JOB] Account Manager, San Francisco
        26. [SJ-JOB] Account Manager, Chicago
        27. [SJ-JOB] Sr. Security Engineer, Schaumburg
        28. [SJ-JOB] Security Engineer, Arlington
        29. [SJ-JOB] Disaster Recovery Coordinator, Miami
        30. [SJ-JOB] Sr. Security Analyst, Schaumburg
        31. [SJ-JOB] Account Manager, New York Metro - NE Territory
        32. [SJ-JOB] Security Engineer, Seattle
        33. [SJ-JOB] Security Engineer, Arlington
        34. [SJ-JOB] Sr. Security Analyst, Schaumburg
        35. [SJ-JOB] Penetration Engineer, Dallas
        36. [SJ-JOB] Penetration Engineer, Denver
        37. [SJ-JOB] Security Researcher, Kolkata
        38. [SJ-JOB] Security Engineer, Charlotte
        39. [SJ-JOB] Application Security Engineer, Santa Clara
        40. [SJ-JOB] Security Auditor, Houston
        41. [SJ-JOB] Penetration Engineer, New York
        42. [SJ-JOB] Threat Analyst, Boulder
        43. [SJ-JOB] Sr. Security Engineer, Sunnvale
        44. [SJ-JOB] Account Manager, Silicon Valley - Bay Area
        45. [SJ-JOB] Developer, Newark
        46. [SJ-JOB] Manager, Information Security, Metarie/New Orleans/Baton    Rouge
        47. [SJ-JOB] VP, Information Security, Dallas
        48. [SJ-JOB] Security Consultant, Chicago
        49. [SJ-JOB] Security Consultant, Ottawa
        50. [SJ-JOB] Sales Engineer, New York
        51. [SJ-JOB] Sr. Security Analyst, Peterborough
        52. Summer Internships
        53. [SJ-JOB] Penetration Engineer, Ashburn, VA   (anywhere for the    Guru types)
        54. [SJ-JOB] Sales Representative, Austin
        55. [SJ-JOB] Technical Support Engineer, Ottawa
        56. [SJ-JOB] Account Manager, New York
        57. [SJ-JOB] Account Manager, Raleigh
        58. [SJ-JOB] Account Manager, Minneapolis
        59. [SJ-JOB] Account Manager, Miami
        60. [SJ-JOB] Account Manager, Dallas
        61. [SJ-JOB] Security Consultant, Dallas
        62. [SJ-JOB] Account Manager, Washington
        63. [SJ-JOB] Security Engineer, Columbia
        64. [SJ-JOB] Account Manager, Philadelphia
        65. [SJ-JOB] Channel / Business Development, Anywhere
        66. [SJ-JOB] Security Product Marketing Manager, Austin
        67. [SJ-JOB] Account Manager, Anywhere
        68. [SJ-JOB] Information Assurance Engineer, Dahlgren
        69. [SJ-JOB] Sales Engineer, Anywhere
        70. [SJ-JOB] Account Manager, Chicago
        71. [SJ-JOB] Sales Engineer, Herndon
        72. [SJ-JOB] Security Engineer, Dearborn
        73. [SJ-JOB] Security Architect, Delhi
        74. [SJ-JOB] Security Auditor, Parsippany
        75. [SJ-JOB] Security Engineer, Delhi
V.    INCIDENTS LIST SUMMARY
        1. National Secret Agency of Slovak Republic
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Googling or Google Hacking Security Conference slides
        2. Possible Overflow in MS Word 2003
        3. mpg123 DoS ... It receives a SIGSEGV.
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. EFS rollout using Active Directory
        2. SecurityFocus Microsoft Newsletter #288
        3. Laptop Encryption & Write Permissions
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Sendmail and secure design
By Jason Miller
Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.
http://www.securityfocus.com/columnists/400

2. Five common Web application vulnerabilities
By Sumit Siddharth, Pratiksha Doshi
This article looks at five common Web application attacks, primarily for PHP applications, and then presents a short case study of a vulnerable Website that was found using Google and easily exploited.
http://www.securityfocus.com/infocus/1864


II.  BUGTRAQ SUMMARY
--------------------
1. Collaborative Portal Server POS Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17774
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17774
Summary:
Collaborative Portal Server is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Collaborative Portal Server version 3.4.0 is vulnerable to this issue; other versions may also be affected.

2. Clam AntiVirus FreshClam Remote Buffer Overflow Vulnerability
BugTraq ID: 17754
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17754
Summary:
ClamAV's freshclam utility is susceptible to a remote buffer-overflow vulnerability. The utility fails to perform sufficient boundary checks in server-supplied HTTP data before copying it to an insufficiently sized memory buffer.

To exploit this issue, attackers must subvert webservers in the ClamAV database server pool. Or, they would perform DNS-based attacks or man-in-the-middle attacks to cause affected freshclam applications to connect to attacker-controlled webservers.

This issue allows remote attackers to execute arbitrary machine code in the context of the freshclam utility. The affected utility may run with superuser privileges, aiding remote attackers in the complete compromise of affected computers.

ClamAV versions 0.88 and 0.88.1 are affected by this issue.

3. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
BugTraq ID: 16881
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/16881
Summary:
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.

These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.

Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.

4. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

5. SWS Web Server Multiple Arbitrary Code Execution Vulnerabilities
BugTraq ID: 17737
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17737
Summary:

SWS Web Server is prone to multiple vulnerabilities permitting arbitrary code execution.

The application is prone to multiple format-string and buffer-overflow vulnerabilities that can attackers can exploit to execute arbitrary code. A successful exploit may facilitate a compromise of the affected computer.

6. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.

This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.

This may cause a denial-of-service condition.

**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.

7. Linux Kernel Multiple Security Vulnerabilities
BugTraq ID: 15049
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/15049
Summary:
Linux kernel is prone to multiple vulnerabilities. These issues may allow local and remote attackers to trigger denial-of-service conditions or to access sensitive kernel memory.

Linux kernel 2.6.x versions are known to be vulnerable at the moment. Other versions may be affected as well.

8. Linux Kernel CIFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 17742
Remote: No
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17742
Summary:
The Linux Kernel is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.

The problem affects chroot inside of an SMB-mounted filesystem ('cifs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and gain unauthorized access to the filesystem.

9. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
BugTraq ID: 14955
Remote: No
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/14955
Summary:
A local denial-of-service vulnerability affects the Linux kernel's USB subsystem. This issue is due to the kernel's failure to properly handle unexpected conditions when trying to handle URBs (USB Request Blocks).

Local attackers may exploit this vulnerability to trigger a kernel 'oops' on computers where the vulnerable USB subsystem is enabled. This would deny service to legitimate users.

10. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 17735
Remote: No
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17735
Summary:
The Linux Kernel is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.

The problem affects chroot inside of an SMB-mounted filesystem ('smbfs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and gain unauthorized access to the filesystem.

11. Linux Kernel Netfilter Ipt_recent Remote Denial of Service Vulnerability
BugTraq ID: 14791
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14791
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability.

An attacker can exploit this issue by sending specially crafted packets to a vulnerable computer employing the 'ipt_recent' module.

A successful attack can cause a denial-of-service condition.

12. Linux Kernel 64-Bit SMP Routing_ioctl() Local Denial of Service Vulnerability
BugTraq ID: 14902
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14902
Summary:
A local denial-of-service vulnerability affects the Linux kernel on 64-bit Symmetric Multi-Processor (SMP) platforms.

Specifically, the vulnerability presents itself due to an omitted call to the 'sockfd_put()' function in the 32-bit-compatible 'routing_ioctl()' function.

The 32-bit-compatible 'tiocgdev ioctl()' function on x86-64 platforms is affected by this issue as well.

13. Linux Kernel SCSI ProcFS Denial Of Service Vulnerability
BugTraq ID: 14790
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14790
Summary:
The Linux kernel is prone to a denial-of-service vulnerability. The kernel is affected by a memory leak, which eventually can result in a denial of service.

A local attacker can exploit this vulnerability by making repeated reads to the '/proc/scsi/sg/devices' file, which will exhaust kernel memory and lead to a denial of service.

14. Artmedic Event Index.PHP Remote File Include Vulnerability
BugTraq ID: 17736
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17736
Summary:
Artmedic Event is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

15. LibTiff TIFFFetchData Integer Overflow Vulnerability
BugTraq ID: 17732
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17732
Summary:
Applications using the LibTIFF library are prone to an integer-overflow vulnerability.

An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application that uses the affected library. Failed exploit attempts will likely cause denial-of-service conditions.

16. Linux Kernel Raw_sendmsg() Kernel Memory Access Vulnerability
BugTraq ID: 14787
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14787
Summary:
Linux Kernel is prone to a kernel memory-access vulnerability.

This issue affects the 'raw_sendmsg()' function and can allow a local attacker to access kernel memory or manipulate the hardware state due to unauthorized access to I/O ports.

Linux kernel 2.6.10 is reportedly vulnerable, but other versions are likely to be affected as well.

17. LibTiff Double Free Memory Corruption Vulnerability
BugTraq ID: 17733
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17733
Summary:
Applications using the LibTIFF library are prone to a double-free vulnerability; a fix is available.

Attackers may be able to exploit this issue to cause denial-of-service conditions in affected applications using a vulnerable version of the library; arbitrary code execution may also be possible.

18. Network Administration Visualized Multiple SQL Injection Vulnerabilities
BugTraq ID: 17734
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17734
Summary:
Network Administration Visualized is prone to multiple, unspecified SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

19. LibTiff Multiple Denial of Service Vulnerabilities
BugTraq ID: 17730
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17730
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial of service in applications using the affected library.

20. Linux Kernel Sendmsg() Local Buffer Overflow Vulnerability
BugTraq ID: 14785
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14785
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability.

The vulnerability affects 'sendmsg()' when malformed user-supplied data is copied from userland to kernel memory.

A successful attack can allow a local attacker to trigger an overflow, which may lead to a denial-of-service condition due to memory corruption. Arbitrary code execution resulting in privilege escalation is possible as well.

21. Linux Kernel ZLib Local Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 14720
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14720
Summary:
The Linux kernel is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed compressed files.

An attacker can exploit this vulnerability to cause a kernel crash, effectively denying service to legitimate users.

22. PHPWebSite Config.PHP File Include Vulnerability
BugTraq ID: 17521
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17521
Summary:
PHPWebSite is prone to a remote and local file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote and local PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

Versions 0.10.2 and prior are affected.

23. Linux Kernel ZLib Invalid Memory Access Local Denial of Service Vulnerability
BugTraq ID: 14719
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14719
Summary:
The Linux kernel is reported prone to a local denial-of-service vulnerability. This issue arises because the software fails to handle exceptional conditions in a proper manner.

This can allow a local attacker to deny service to legitimate users due to a kernel oops. Since the zlib library is used throughout the kernel, attackers may likely find various avenues to exploit this issue.

24. Linux Kernel ISO File System Denial Of Service Vulnerability
BugTraq ID: 14614
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/14614
Summary:
The kernel driver for compressed ISO filesystems is prone to a denial-of-service vulnerability. This issue is due to a failure in the driver to properly sanitize input data.

When attempting to mount a malicious compressed ISO image, the kernel crashes.

25. Beagle Helper Applications Arbitrary Code Execution Vulnerability
BugTraq ID: 17611
Remote: Yes
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/17611
Summary:
Beagle is susceptible to an insecure indexing issue when dealing with helper applications. This can lead to arbitrary code execution.

An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the vulnerable application.

26. Linux Kernel Fib_Seq_Start Local Denial of Service Vulnerability
BugTraq ID: 13267
Remote: No
Last Updated: 2006-04-28
Relevant URL: http://www.securityfocus.com/bid/13267
Summary:
A local denial-of-service vulnerability affects the Linux kernel.

A local attacker may leverage this issue to cause an affected Linux kernel to panic, effectively denying service to legitimate users.

Although only the Linux kernel version 2.6.9 is reported vulnerable, other versions are likely vulnerable as well.

27. Perl Perl_sv_vcatpvfn Format String Integer Wrap Vulnerability
BugTraq ID: 15629
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15629
Summary:
Perl is susceptible to a format-string vulnerability. This issue is due to the programming language's failure to properly handle format specifiers in formatted-printing functions.

An attacker may leverage this issue to write to arbitrary process memory, facilitating code execution in the context of the Perl interpreter process. This can result in unauthorized remote access.

Developers should treat the formatted printing functions in Perl as equivalently vulnerable to exploitation as the C library versions, and should properly sanitize all data passed in the format-specifier argument.

All applications that use formatted-printing functions in an unsafe manner should be considered exploitable.

28. PHP MB_Send_Mail TO Argument Header Injection Vulnerability
BugTraq ID: 15571
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15571
Summary:
PHP is susceptible to a header-injection vulnerability when sending email. This issue is due to the application's failure to properly sanitize user-supplied input.

This issue allows remote attackers to add arbitrary headers to generated email messages. The results of this vary depending on the meaning of the injected headers. This may allow attackers to use vulnerable web applications as an anonymous email proxy.

29. PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
BugTraq ID: 15413
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15413
Summary:
PHP on Apache 2 is prone to a restriction bypass vulnerability when calling 'virtual()'.  Successful exploitation could lead to disclosure of sensitive information.

This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.

30. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
BugTraq ID: 14759
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/14759
Summary:
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.

This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.

31. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 15411
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15411
Summary:
PHP cURL and GD are prone to multiple safe_mode and open_basedir restriction-bypass vulnerabilities. Successful exploitation could allow an attacker to access sensitive information.

This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.

32. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.

By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

33. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to reenable the 'register_globals' directive. This issue is due to the application's failure to handle a memory-limit exception.

The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the process's life. If PHP is being run as a CGI process, this issue is not likely exploitable.

By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.

34. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
BugTraq ID: 15358
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15358
Summary:
PHP is prone to a denial-of-service vulnerability.

This issue occurs when parsing EXIF image data in corrupt JPEG files.

An attacker can exploit this vulnerability to crash the system, effectively denying service to legitimate users.

35. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
BugTraq ID: 17682
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17682
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors. These issues include:

- Buffer-overflow vulnerabilities
- Denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
- Off-by-one overflow vulnerabilities

These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.

Various vulnerabilities affect different versions of Ethereal, from 0.8.5 through to 0.10.14.

36. Oracle 10g DBMS_EXPORT_EXTENSION SQL Injection Vulnerability
BugTraq ID: 17699
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17699
Summary:
Oracle 10g is prone to an SQL-injection vulnerability. An attacker could exploit this to gain DBA privileges.

This vulnerability was initially thought to have been fixed as part of the Oracle April 2006 Security Update (BID 17590), but this issue reportedly wasn't patched.

Further information indicates that this issue also affects the 'GET_DOMAIN_INDEX_TABLES' and "GET_V2_DOMAIN_INDEX_TABLES' functions.

37. CoolMenus Index.PHP Remote File Include Vulnerability
BugTraq ID: 17738
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17738
Summary:
CoolMenus is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This BID has been retired. The initial report included erroneous information about the application. Further information has been published indicating that the allegedly vulnerable code is not present in the application.

38. Free-PHP.net Simple Poll Authentication Bypass Vulnerability
BugTraq ID: 17771
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17771
Summary:
Simple Poll is prone to an authentication-bypass vulnerability. The issue occurs because the affected script fails to prompt for authentication credentials.

An attacker can exploit this issue to bypass authentication and gain access to the affected application's poll creation/modification functionality. This could aid in further attacks on the affected computer.

39. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

40. Linux Kernel File Lock Lease Local Denial of Service Vulnerability
BugTraq ID: 15745
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15745
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

This issue is triggered when excessive kernel memory is consumed by numerous file-lock leases. This problem stems from a memory leak in the kernel's file-lock lease code.

This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and ultimately to a denial of service for legitimate users.

Kernel versions from 2.6.10 through to 2.6.14.2 are vulnerable to this issue.

41. Linux Kernel INVALIDATE_INODE_PAGES2 Local Integer Overflow Vulnerability
BugTraq ID: 15846
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15846
Summary:
Linux kernel is prone to a local integer-overflow vulnerability.

A successful attack can result in a kernel crash. Arbitrary code execution may be possible as well, but this has not been confirmed.

All 2.6.x versions of the Linux kernel are considered vulnerable at the moment.

42. Ruperts News Script Login.PHP SQL Injection Vulnerability
BugTraq ID: 17758
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17758
Summary:
Ruperts News Script is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

43. DeltaScripts PHP Pro Publish Multiple SQL Injection Vulnerabilities
BugTraq ID: 17762
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17762
Summary:
PHP Pro Publish is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

44. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this vulnerability to corrupt kernel memory or free non-allocated memory. Successful exploitation will crash the kernel, effectively denying service to legitimate users.

45. Limbo CMS SQL.PHP Remote File Include Vulnerability
BugTraq ID: 17760
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17760
Summary:
Limbo CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 1.04; other versions may also be vulnerable.

46. PHP Newsfeed Multiple SQL Injection Vulnerabilities
BugTraq ID: 17757
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17757
Summary:
PHP Newsfeed is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

47. ResMgr Unauthorized USB Device Access Vulnerability
BugTraq ID: 17752
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17752
Summary:
The resmgr module is prone to a vulnerability that permits unauthorized access to USB devices.

A successful exploit of this issue would result in a bypass of access controls leading to a false sense of security and a possible loss of confidentiality if data is intercepted; other attacks are also possible.

48. DMCounter Kopf.PHP Remote File Include Vulnerability
BugTraq ID: 17756
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17756
Summary:
DMCounter is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 0.9.2-b; other versions may also be vulnerable.

49. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
BugTraq ID: 15722
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15722
Summary:
A local denial-of-service vulnerability affects the Linux kernel.

The vulnerability arises due to a race-condition error in the handling of POSIX timer cleanup routines.

A successful attack can result in a kernel crash.

Linux kernel versions 2.6.10 to 2.6.14 are vulnerable to this issue.

50. HB-NS Multiple Input Validation Vulnerabilities
BugTraq ID: 17759
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17759
Summary:
HB-NS is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, and exploit vulnerabilities in the underlying database implementation. Other attacks are possible as well.

51. MPlayer Multiple Integer Overflow Vulnerabilities
BugTraq ID: 17295
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17295
Summary:
MPlayer is susceptible to two integer-overflow vulnerabilities. An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may help the attacker gain unauthorized access or escalate privileges.

MPlayer version 1.0.20060329 is affected by these issues; other versions may also be affected.

52. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
BugTraq ID: 15642
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/15642
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

In instances where a process is created via the 'clone()' system call with the 'CLONE_THREAD' argument ptraced, the kernel fails to properly ensure that the ptracing process is not attempting to trace itself.

This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.14.2 are vulnerable to this issue.

53. EMC Dantz Retrospect Backup Server Local Privilege Escalation Vulnerability
BugTraq ID: 17798
Remote: No
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17798
Summary:
Dantz Retrospect Backup Server is prone to a local privilege-escalation vulnerability. This issue is due to a failure of the application to properly ensure that administrative privileges are dropped prior to executing applications.

This issue allows local users to gain administrative privileges, facilitating the complete compromise of affected computers.

54. CmScout Multiple HTML Injection Vulnerabilities
BugTraq ID: 17796
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17796
Summary:
CmScout is prone to multiple HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Versions 1.10 and prior are vulnerable; other version may also be affected.

55. Pinnacle Cart Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17794
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17794
Summary:
Pinnacle Cart is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

56. Invision Gallery Post.PHP SQL Injection Vulnerability
BugTraq ID: 17793
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17793
Summary:
Invision Gallery is prone to a SQL-injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

57. Fujitsu NetShelter Unspecified DNS Denial Of Service Vulnerability
BugTraq ID: 17791
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17791
Summary:
Fujitsu NetShelter is prone to an unspecified remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed DNS responses.

An attacker can exploit this issue to crash the affected service, effectively denying service to legitimate users.

58. Virtual Hosting Control System Server_day_stats.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17790
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17790
Summary:
Virtual Hosting Control System is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

59. RSync Receive_XATTR Integer Overflow Vulnerability
BugTraq ID: 17788
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17788
Summary:
The rsync utility is susceptible to a remote integer-overflow vulnerability. This issue is due to a failure of the application to properly ensure that user-supplied input does not result in the overflowing of integer values. This may result in user-supplied data being copied past the end of a memory buffer.

Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating in the compromise of affected computers.

Versions of rsync prior to 2.6.8 that have had the 'xattrs.diff' patch applied are vulnerable to this issue.

60. Russcom Network LoginPHP Open EMail Relay Vulnerability
BugTraq ID: 17787
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17787
Summary:
loginphp is susceptible to a remote open-email-relay vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it to generate email messages.

This issue allows remote attackers to use webservers that are hosting the vulnerable applicationt to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from a trusted mail server.

61. FileProtection Express Authentication Bypass Vulnerability
BugTraq ID: 17786
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17786
Summary:
FileProtection Express is prone to an authentication-bypass vulnerability. The issue occurs because the affected application fails to verify cookie-based authentication credentials.

An attacker can exploit this issue to bypass authentication and gain access to the affected application's administrative section. This could aid in further attacks on the affected computer.

62. Russcomm Network LoginPHP Username HTML Injection Vulnerability
BugTraq ID: 17785
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17785
Summary:
loginphp is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

63. GeoBlog Viewcat.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17784
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17784
Summary:
GeoBlog is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

64. SF-Users Username HTML Injection Vulnerability
BugTraq ID: 17783
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17783
Summary:
SF-Users is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

65. SBlog Search.PHP SQL Injection Vulnerability
BugTraq ID: 17782
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17782
Summary:
sBlog is prone to a SQL-injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

66. XDT Pro Stats.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17781
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17781
Summary:
XDT Pro is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

XDT Pro version 2.3 is vulnerable to this issue; other versions may also be affected.

67. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
BugTraq ID: 17780
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17780
Summary:
MySQL is susceptible to multiple remote vulnerabilities. The issues are:

- A buffer-overflow vulnerability due to insufficient bounds-checking of user-supplied data prior to copying it to an insufficiently sized memory-buffer. This issue allows remote attackers to execute arbitrary machine code in the context of affected database servers. Failed exploit attempts likely result in crashing the server and denying further service to legitimate users.

- Two information-disclosure vulnerabilities due to insufficient input-sanitization and bounds-checking of user-supplied data. These issues allow remote users to gain access to potentially sensitive information that may aid them in further attacks.

68. Zenphoto Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17779
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17779
Summary:

Zenphoto is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Zenphoto versions prior to 1.0.2 beta are vulnerable to this issue.

69. JSBoard Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17778
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17778
Summary:
JSBoard is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

70. X7 Chat Index.PHP Local File Include Vulnerability
BugTraq ID: 17777
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17777
Summary:
X7 Chat is prone to a local file-include vulnerability. This may allow unauthorized users to view files and to execute local scripts.

An attacker may also be able to execute arbitrary code by way of uploaded avatars.

Versions 2.0 and earlier are reported vulnerable to this issue.

71. Cisco Unity Express Expired Password Privilege Escalation Vulnerability
BugTraq ID: 17775
Remote: Yes
Last Updated: 2006-05-02
Relevant URL: http://www.securityfocus.com/bid/17775
Summary:

Cisco Unity Express (CUE) is prone to a privilege escalation vulnerability.  An attacker could reset the password of a privileged account with an expired password.

CUE Advanced Integration Module (AIM) or Network Module (NM) running CUE software versions prior to 2.3(1) are affected by this issue.

72. MKPortal Multiple Input Validation Vulnerabilities
BugTraq ID: 17651
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17651
Summary:
MKPortal is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successfully exploiting these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

MKPortal version 1.1 in conjunction with vBulletin 3.5.4 is vulnerable to these issues; other versions may also be affected.

73. JMK Picture Gallery Admin_Gallery.PHP3 Authentication Bypass Vulnerability
BugTraq ID: 17755
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17755
Summary:
JMK Picture Gallery is prone to an authentication-bypass vulnerability. The issue occurs because the affected script fails to prompt for authentication credentials.

An attacker can exploit this issue to bypass authentication and gain admin access to the affected application. This could aid in further attacks on the affected computer.

74. Linux Kernel NAT Handling Memory Corruption Denial of Service Vulnerability
BugTraq ID: 15531
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/15531
Summary:
Linux Kernel is reported prone to a denial-of-service vulnerability.

Due to a design error in the kernel, an attacker can cause a memory corruption that will ultimately crash the kernel, denying service to legitimate users.

75. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash.

This issue allows local users to crash the kernel, denying service to legitimate users.

Kernel versions prior to 2.6.15 are vulnerable to this issue.

76. PlanetGallery Gallery_admin.PHP Authentication Bypass Vulnerability
BugTraq ID: 17753
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17753
Summary:
PlanetGallery is prone to an authentication-bypass vulnerability. The issue occurs because the affected script fails to prompt for authentication credentials.

An attacker can exploit this issue to bypass authentication and gain admin access. This could aid in further attacks on the affected computer.

77. W-Agora BBCode Script Injection Vulnerability
BugTraq ID: 17751
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17751
Summary:
W-Agora is prone to a script-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before including it in dynamically generated content.

W-Agora can be configured to send all user information in session data; if this is the case, then attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing an attacker to steal cookie-based authentication credentials. Other attacks are also possible.

This issue is reported to affect version 4.20; other versions may also be vulnerable.

78. Linux Kernel IPV6 Local Denial of Service Vulnerability
BugTraq ID: 15156
Remote: No
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/15156
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability.

This issue arises from an infinite loop when binding IPv6 UDP ports.

79. Asterisk Voicemail Unauthorized Access Vulnerability
BugTraq ID: 15336
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/15336
Summary:
Asterisk is prone to an unauthorized-access vulnerability. This issue is due to a failure in the application to properly verify user-supplied input.

Successful exploitation will grant an attacker access to a victim user's voicemail and to any '.wav/.WAV' files currently on the affected system.

80. Asterisk JPEG File Handling Integer Overflow Vulnerability
BugTraq ID: 17561
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17561
Summary:

Asterisk is prone to an integer-overflow vulnerability.

This issue arises when the application handles a malformed JPEG file.

An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application.

81. TextFileBB Multiple Tag Script Injection Vulnerabilities
BugTraq ID: 17750
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17750
Summary:
TextFileBB is prone to multiple script-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before including it in dynamically generated content.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.

These issues are reported to affect version 1.0.16; other versions may also be vulnerable.

82. PHPNuke Downloads Module SQL Injection Vulnerability
BugTraq ID: 17749
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17749
Summary:
PHPNuke is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

83. 4Images Multiple SQL Injection Vulnerabilities
BugTraq ID: 17748
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17748
Summary:
4Images is prone to multiple, unspecified SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

84. I-RATER Platinum Config_settings.TPL.PHP Remote File Include Vulnerability
BugTraq ID: 17731
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17731
Summary:
I-RATER Platinum is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

85. Thyme Search Page HTML Injection Vulnerability
BugTraq ID: 17746
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17746
Summary:
Thyme is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

86. Advanced GuestBook Addentry.PHP Remote File Include Vulnerability
BugTraq ID: 17745
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17745
Summary:
Advanced GuestBook for phpBB is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 2.4.0 and prior are reported vulnerable.

87. Blog Mod Weblog_posting.PHP SQL Injection Vulnerability
BugTraq ID: 17744
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17744
Summary:
Blog Mod is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

88. OpenPHPnuke Remote File Include Vulnerability
BugTraq ID: 17772
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17772
Summary:
OpenPHPnuke is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 2.3.3; other versions may also be vulnerable.

89. SunShop Shopping Cart Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17770
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17770
Summary:
SunShop Shopping Cart is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

90. Xine Filename Handling Remote Format String Vulnerability
BugTraq ID: 17769
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17769
Summary:
The xine package is susceptible to a remote format-string vulnerability.

This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users to try to execute the affected application with the malicious filename as an argument.

A successful attack may crash the application or lead to arbitrary code execution.

Version 0.99.4 of xine is vulnerable to this issue; other versions may also be affected.

91. Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
BugTraq ID: 17768
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17768
Summary:
ImageIO is susceptible to a remote denial-of-service vulnerability. This issue is do to a failure to properly process malicious OpenEXR image files.

This issue allows remote users to crash applications that use the ImageIO API, denying further service to users.

92. OrbitHYIP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17766
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17766
Summary:
OrbitHYIP is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

93. MaxTrade Multiple SQL Injection Vulnerabilities
BugTraq ID: 17765
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17765
Summary:
MaxTrade is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

94. phpBB Knowledge Base Mod KB_constants.PHP Remote File Include Vulnerability
BugTraq ID: 17763
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17763
Summary:
Knowledge Base Mod for phpbb is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 2.0.2 and prior; other versions may also be vulnerable.

95. AZNEWS News.PHP SQL Injection Vulnerability
BugTraq ID: 17761
Remote: Yes
Last Updated: 2006-05-01
Relevant URL: http://www.securityfocus.com/bid/17761
Summary:
AZNEWS is prone to an SQL-injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

96. Linux Orinoco Driver Remote Information Disclosure Vulnerability
BugTraq ID: 15085
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/15085
Summary:
The Orinoco drivers for Linux kernels are susceptible to a remote information-disclosure vulnerability. This issue is due to the driver sending uninitialized kernel memory in small network packets.

Remote attackers may exploit this issue to access potentially sensitive kernel memory, aiding them in further attacks.

97. PostNuke Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17743
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17743
Summary:
PostNuke is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

98. Oracle Multiple Unspecified Vulnerabilities
BugTraq ID: 17739
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17739
Summary:

Oracle is prone to multiple unspecified vulnerabilities.

These issues affect Oracle Database, Oracle Secure Enterprise Search, Oracle HTMLDB, Oracle TNS Listener 10g, Oracle HTMLDB, Oracle HTMLDB, Oracle Import, Workflow, JDeveloper, Oracle Developer Tools for Visual Studio .NET, Oracle Discoverer, Oracle Reports, and Oracle XMLDB.

99. Trac Wiki Macro Remote HTML Injection Vulnerabilities
BugTraq ID: 17741
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/17741
Summary:
Trac is prone to multiple, unspecified HTML-injection vulnerabilities.

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.

Trac versions prior to 0.9.5. are affected by these issues.

100. Mozilla Thunderbird IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-04-29
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Mozilla Thunderbird is prone to a script-execution vulnerability.

The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.

Mozilla Thunderbird 1.0.7 and prior versions are reportedly affected.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Breach case could curtail Web flaw finders
By: Robert Lemos
Security researchers and legal experts voice concern over the prosecution of an information-technology professional for computer intrusion after he allegedly breached a university's online application system while researching a flaw without the school's permission.
http://www.securityfocus.com/news/11389

2. E-mail authentication gaining steam
By: Robert Lemos
A host of software companies, security firms and Internet service providers meet in  Chicago to urge corporations and bulk e-mail senders to adopt authentication technologies.
http://www.securityfocus.com/news/11388

3. Browsers feel the fuzz
By: Robert Lemos
Security researchers are starting to aim network fuzzers away from servers and toward browsers, finding that dozens of flaws have been missed.
http://www.securityfocus.com/news/11387

4. Groups argue over merits of flaw bounties
By: Robert Lemos
Vulnerability researchers like getting paid for their research, but software companies criticize the programs. Do vulnerability-purchasing initiatives make sense?
http://www.securityfocus.com/news/11386

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Account Manager, San Francisco
http://www.securityfocus.com/archive/77/432627

2. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/432628

3. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/432624

4. [SJ-JOB] Sales Engineer, Detroit
http://www.securityfocus.com/archive/77/432625

5. [SJ-JOB] Security Engineer, Elizabeth
http://www.securityfocus.com/archive/77/432626

6. [SJ-JOB] Sr. Security Analyst, London, South East
http://www.securityfocus.com/archive/77/432619

7. [SJ-JOB] Information Assurance Engineer, Arlington
http://www.securityfocus.com/archive/77/432620

8. [SJ-JOB] Sales Representative, Houston
http://www.securityfocus.com/archive/77/432621

9. [SJ-JOB] Security Researcher, San Francisco
http://www.securityfocus.com/archive/77/432622

10. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/432618

11. [SJ-JOB] Software Engineer, Ft. Huachuca
http://www.securityfocus.com/archive/77/432612

12. [SJ-JOB] Account Manager, Los Angeles
http://www.securityfocus.com/archive/77/432613

13. [SJ-JOB] Technology Risk Consultant, Jersey City
http://www.securityfocus.com/archive/77/432614

14. [SJ-JOB] Account Manager, Any
http://www.securityfocus.com/archive/77/432616

15. [SJ-JOB] Security Researcher, Mountain View
http://www.securityfocus.com/archive/77/432610

16. [SJ-JOB] Sr. Security Engineer, Indian Head
http://www.securityfocus.com/archive/77/432611

17. [SJ-JOB] Quality Assurance, Houston
http://www.securityfocus.com/archive/77/432606

18. [SJ-JOB] Sr. Security Analyst, Santa Clara
http://www.securityfocus.com/archive/77/432605

19. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/432607

20. [SJ-JOB] Security Engineer, Troy
http://www.securityfocus.com/archive/77/432603

21. [SJ-JOB] Sales Engineer, Canberra
http://www.securityfocus.com/archive/77/432604

22. [SJ-JOB] Security Consultant, Delhi
http://www.securityfocus.com/archive/77/432565

23. [SJ-JOB] Security Researcher, Santa Clara
http://www.securityfocus.com/archive/77/432567

24. [SJ-JOB] Security Engineer, Dallas / Richardson
http://www.securityfocus.com/archive/77/432564

25. [SJ-JOB] Account Manager, San Francisco
http://www.securityfocus.com/archive/77/432563

26. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/432566

27. [SJ-JOB] Sr. Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/432562

28. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/432295

29. [SJ-JOB] Disaster Recovery Coordinator, Miami
http://www.securityfocus.com/archive/77/432296

30. [SJ-JOB] Sr. Security Analyst, Schaumburg
http://www.securityfocus.com/archive/77/432297

31. [SJ-JOB] Account Manager, New York Metro - NE Territory
http://www.securityfocus.com/archive/77/432292

32. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/432293

33. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/432294

34. [SJ-JOB] Sr. Security Analyst, Schaumburg
http://www.securityfocus.com/archive/77/432291

35. [SJ-JOB] Penetration Engineer, Dallas
http://www.securityfocus.com/archive/77/432258

36. [SJ-JOB] Penetration Engineer, Denver
http://www.securityfocus.com/archive/77/432261

37. [SJ-JOB] Security Researcher, Kolkata
http://www.securityfocus.com/archive/77/432262

38. [SJ-JOB] Security Engineer, Charlotte
http://www.securityfocus.com/archive/77/432257

39. [SJ-JOB] Application Security Engineer, Santa Clara
http://www.securityfocus.com/archive/77/432263

40. [SJ-JOB] Security Auditor, Houston
http://www.securityfocus.com/archive/77/432254

41. [SJ-JOB] Penetration Engineer, New York
http://www.securityfocus.com/archive/77/432255

42. [SJ-JOB] Threat Analyst, Boulder
http://www.securityfocus.com/archive/77/432256

43. [SJ-JOB] Sr. Security Engineer, Sunnvale
http://www.securityfocus.com/archive/77/432259

44. [SJ-JOB] Account Manager, Silicon Valley - Bay Area
http://www.securityfocus.com/archive/77/432275

45. [SJ-JOB] Developer, Newark
http://www.securityfocus.com/archive/77/432244

46. [SJ-JOB] Manager, Information Security, Metarie/New Orleans/Baton    Rouge
http://www.securityfocus.com/archive/77/432249

47. [SJ-JOB] VP, Information Security, Dallas
http://www.securityfocus.com/archive/77/432264

48. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/432274

49. [SJ-JOB] Security Consultant, Ottawa
http://www.securityfocus.com/archive/77/432243

50. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/432246

51. [SJ-JOB] Sr. Security Analyst, Peterborough
http://www.securityfocus.com/archive/77/432247

52. Summer Internships
http://www.securityfocus.com/archive/77/432330

53. [SJ-JOB] Penetration Engineer, Ashburn, VA   (anywhere for the    Guru types)
http://www.securityfocus.com/archive/77/432121

54. [SJ-JOB] Sales Representative, Austin
http://www.securityfocus.com/archive/77/432125

55. [SJ-JOB] Technical Support Engineer, Ottawa
http://www.securityfocus.com/archive/77/432129

56. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/432122

57. [SJ-JOB] Account Manager, Raleigh
http://www.securityfocus.com/archive/77/432123

58. [SJ-JOB] Account Manager, Minneapolis
http://www.securityfocus.com/archive/77/432126

59. [SJ-JOB] Account Manager, Miami
http://www.securityfocus.com/archive/77/432127

60. [SJ-JOB] Account Manager, Dallas
http://www.securityfocus.com/archive/77/432128

61. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/432115

62. [SJ-JOB] Account Manager, Washington
http://www.securityfocus.com/archive/77/432118

63. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/432119

64. [SJ-JOB] Account Manager, Philadelphia
http://www.securityfocus.com/archive/77/432120

65. [SJ-JOB] Channel / Business Development, Anywhere
http://www.securityfocus.com/archive/77/432114

66. [SJ-JOB] Security Product Marketing Manager, Austin
http://www.securityfocus.com/archive/77/432116

67. [SJ-JOB] Account Manager, Anywhere
http://www.securityfocus.com/archive/77/432117

68. [SJ-JOB] Information Assurance Engineer, Dahlgren
http://www.securityfocus.com/archive/77/432111

69. [SJ-JOB] Sales Engineer, Anywhere
http://www.securityfocus.com/archive/77/432112

70. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/432113

71. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/432088

72. [SJ-JOB] Security Engineer, Dearborn
http://www.securityfocus.com/archive/77/432089

73. [SJ-JOB] Security Architect, Delhi
http://www.securityfocus.com/archive/77/432090

74. [SJ-JOB] Security Auditor, Parsippany
http://www.securityfocus.com/archive/77/432086

75. [SJ-JOB] Security Engineer, Delhi
http://www.securityfocus.com/archive/77/432087

V.   INCIDENTS LIST SUMMARY
---------------------------
1. National Secret Agency of Slovak Republic
http://www.securityfocus.com/archive/75/432202

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Googling or Google Hacking Security Conference slides
http://www.securityfocus.com/archive/82/432552

2. Possible Overflow in MS Word 2003
http://www.securityfocus.com/archive/82/432289

3. mpg123 DoS ... It receives a SIGSEGV.
http://www.securityfocus.com/archive/82/429713

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. EFS rollout using Active Directory
http://www.securityfocus.com/archive/88/432081

2. SecurityFocus Microsoft Newsletter #288
http://www.securityfocus.com/archive/88/432070

3. Laptop Encryption & Write Permissions
http://www.securityfocus.com/archive/88/430680

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? See for yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000007ka5