SecurityFocus Newsletter #351
Peter Laborge <[email protected]> Tue, 23 May 2006 15:24:58 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #351
----------------------------------------
This issue is sponsored by: Lancope
"Revolutionize the way you view your network security"
How do you protect what you can't see? Stop protecting while blind. Gain network visibility now. Learn how Cisco NetFlow gives visibility and enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
ALERT: Download FREE White Paper "Network Behavior Analysis (NBA) in the Enterprise."
http://www.lancope.com/resource/
------------------------------------------------------------------
I. FRONT AND CENTER
1. Protection from prying NSA eyes
2. Malicious cryptography, part two
II. BUGTRAQ SUMMARY
1. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
2. Awstats Remote Arbitrary Command Execution Vulnerability
3. Linux Kernel SMBFS Multiple Remote Vulnerabilities
4. Linux Kernel USB Driver Uninitialized Structure Information Disclosure Vulnerability
5. Linux Kernel Floating Point Register Contents Leak Vulnerability
6. Linux Kernel Unspecified Local Denial of Service Vulnerability
7. Linux Kernel Multiple Device Driver Vulnerabilities
8. Linux Kernel Panic Function Call Buffer Overflow Vulnerability
9. Linux kernel do_fork() Memory Leakage Vulnerability
10. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
11. Woltlab Burning Board Links.PHP SQL Injection Vulnerability
12. CaLogic Calendars Multiple Remote File Include Vulnerabilities
13. Sybase EAServer J2EE Application Clients and Java GUI Applications Password Disclosure Vulnerability
14. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
15. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
16. KPhone Local Information Disclosure Vulnerability
17. Artmedic Newsletter Log.PHP Remote Script Execution Vulnerability
18. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
19. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
20. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
21. YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
22. JemWeb DownloadControl DC.PHP SQL Injection Vulnerability
23. ZixForum Settings.ASP SQL Injection Vulnerability
24. POPFile Denial Of Service Vulnerability
25. Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
26. PHPRaid View.PHP Cross-Site Scripting Vulnerability
27. Another Image Gallery Gallery.PHP Cross-Site Scripting Vulnerability
28. Captivate Gallery.PHP Cross-Site Scripting Vulnerability
29. Destiney Links Script Multiple HTML Injection Vulnerabilities
30. Destiney Rated Images Addweblog.PHP HTML Injection Vulnerability
31. Hscripts HGB Index.PHP HTML Injection Vulnerability
32. Prodder Arbitrary Shell Command Execution Vulnerability
33. Perlpodder Arbitrary Shell Command Execution Vulnerability
34. NetPBM PSToPNM Arbitrary Code Execution Vulnerability
35. BitZipper Remote Directory Traversal Vulnerability
36. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
37. EMC Retrospect Client Buffer Overflow Vulnerability
38. Linux Kernel Lease_Init Local Denial of Service Vulnerability
39. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
40. PHPWCMS CNT6.INC.PHP Cross-Site Scripting Vulnerability
41. PHPWCMS Spaw_Control.Class.PHP Local File Include Vulnerability
42. XOOPS Mainfile.PHP Local File Include Vulnerability
43. Power Place PHP Easy Galerie Index.PHP Remote File Include Vulnerability
44. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
45. Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
46. Skype Technologies Skype URI Handling Remote File Download Vulnerability
47. Nagios Remote Content-Length Integer Overflow Vulnerability
48. Nagios Remote Negative Content-Length Buffer Overflow Vulnerability
49. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
50. LibXpm Image Decoding Multiple Remote Buffer Overflow Vulnerabilities
51. Website Baker User Display Name HTML Injection Vulnerability
52. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
53. Quagga BGPD Local Denial Of Service Vulnerability
54. Libextractor Multiple Heap Buffer Overflow Vulnerabilities
55. Quagga Information Disclosure and Route Injection Vulnerabilities
56. Xtreme Topsites Multiple Input Validation Vulnerabilities
57. ActualScripts ActualAnalyzer Direct.PHP Remote File Include Vulnerability
58. PHPBazar Admin.PHP Unauthorized Access Vulnerability
59. PHPBazar Classified_right.PHP Remote File Include Vulnerability
60. Blender BlenLoader File Processing Integer Overflow Vulnerability
61. Fbida FBGS Insecure Temporary File Creation Vulnerability
62. RunCMS Remote Code Execution Vulnerability
63. CScope Include Filename Buffer Overflow Vulnerability
64. Network Block Device Server Buffer Overflow Vulnerability
65. hostapd Invalid EAPOL Key Length Remote Denial Of Service Vulnerability
66. FUDforum Avatar Upload Arbitrary Script Upload Vulnerability
67. YourFreeWorld Short Url & Url Tracker Script Multiple HTML Injection Vulnerabilities
68. RealVNC Remote Authentication Bypass Vulnerability
69. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
70. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
71. GNU Strings Denial Of Service Vulnerability
72. Sun ONE Directory Server Remote Denial Of Service Vulnerability
73. Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
74. Multiple Vendor SSH Server Remote Buffer Overflow Vulnerability
75. TFTPD32 Long Filename Buffer Overflow Vulnerability
76. Beats Of Rage Multiple Format String Vulnerabilities
77. IPLogger Useragent HTML Injection Vulnerability
78. Multiple Browsers Exception Handling Information Disclosure Vulnerability
79. Dia Filename Remote Format String Vulnerability
80. UBB.threads Addpost_newpoll.PHP Remote File Include Vulnerability
81. MySQL Query Logging Bypass Vulnerability
82. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
83. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
84. DSChat HTML Injection Vulnerability
85. Chatty Username HTML Injection Vulnerability
86. Linux Kernel Unw_Unwind_To_User Local Denial of Service Vulnerability
87. Linux Kernel PPP Driver Unspecified Remote Denial Of Service Vulnerability
88. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow Vulnerabilities
89. Linux kernel Uselib() Local Privilege Escalation Vulnerability
90. Linux Kernel User Triggerable BUG() Unspecified Local Denial of Service Vulnerability
91. Linux Kernel ELF Binary Loading Denial Of Service Vulnerability
92. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
93. Linux Kernel Local Denial Of Service And Memory Disclosure Vulnerabilities
94. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
95. Linux Kernel 2.4 RTC Handling Routines Memory Disclosure Vulnerability
96. Linux Kernel Coda_Pioctl Local Buffer Overflow Vulnerability
97. Linux Kernel USB io_edgeport Driver Local Integer Overflow Vulnerability
98. Linux Kernel Multiple Local Vulnerabilities
99. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
100. Linux Kernel Symmetrical Multiprocessing Page Fault Local Privilege Escalation Vulnerability
III. SECURITYFOCUS NEWS
1. Veterans Affairs warns of massive privacy breach
2. Blue Security folds under spammer's wrath
3. Diebold voting systems critically flawed
4. Bot software looks to improve peerage
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] VP, Information Security, Bournmouth
2. [SJ-JOB] Sales Representative, NORTHWEST
3. [SJ-JOB] Sr. Security Analyst, Norfolk
4. [SJ-JOB] Penetration Engineer, London - UK Wide
5. [SJ-JOB] Sr. Security Analyst, McLean
6. [SJ-JOB] Security Researcher, Cambridge
7. [SJ-JOB] Security Engineer, Chicago
8. [SJ-JOB] Channel / Business Development, SAN DIEGO
9. [SJ-JOB] Penetration Engineer, Cambridge
10. [SJ-JOB] Security Architect, London
11. [SJ-JOB] Security Architect, San Jose
12. [SJ-JOB] Management, San Francisco
13. [SJ-JOB] Sr. Product Manager, San Francisco
14. [SJ-JOB] VP / Dir / Mgr engineering, San Francisco
15. [SJ-JOB] Quality Assurance, Mysore
16. [SJ-JOB] Security Engineer, Fairfax
17. [SJ-JOB] VP of Regional Sales, Pittsburgh
18. [SJ-JOB] Application Security Architect, Singapore
19. [SJ-JOB] Application Security Architect, Frankfurt or Munich
20. [SJ-JOB] Auditor, NY/NJ
21. [SJ-JOB] Security Architect, Edison
22. [SJ-JOB] Manager, Information Security, New York (Brooklyn Metrotech)
23. [SJ-JOB] Security Engineer, Bangalore, Hyderabad or Mumbai
24. [SJ-JOB] Sr. Security Engineer, Weehawkin
25. [SJ-JOB] Manager, Information Security, New York (Brooklyn Metrotech)
26. [SJ-JOB] Software Engineer, Austin
27. [SJ-JOB] Application Security Architect, London
28. [SJ-JOB] Senior Software Engineer, Austin
29. [SJ-JOB] Security Consultant, Charlotte
30. [SJ-JOB] Sr. Security Analyst, Bellevue
31. [SJ-JOB] Security System Administrator, Columbia
32. [SJ-JOB] Jr. Security Analyst, Milwaukee
33. [SJ-JOB] VP, Information Security, Centreville
34. [SJ-JOB] Associate Software Engineer, Sunnyvale
35. [SJ-JOB] Sr. Security Analyst, Edinburgh
36. [SJ-JOB] Information Assurance Analyst, Springfield
37. [SJ-JOB] Forensics Engineer, Columbia
38. [SJ-JOB] Security Engineer, Columbia
39. [SJ-JOB] Sr. Security Analyst, London/Edinburgh
40. [SJ-JOB] Channel / Business Development, Boston
41. [SJ-JOB] Security System Administrator, Santa Clara
42. [SJ-JOB] Jr. Security Analyst, Parsippany
43. [SJ-JOB] Security Consultant, Germany
44. [SJ-JOB] Security Researcher, North Sydney
45. [SJ-JOB] Threat Analyst, Springfield
46. [SJ-JOB] Quality Assurance, Pverland
47. [SJ-JOB] Jr. Security Analyst, Parsippany
48. [SJ-JOB] Technology Risk Consultant, Alpharetta
49. [SJ-JOB] Developer, Overland
50. [SJ-JOB] Jr. Security Analyst, Parsippany
51. [SJ-JOB] Technical Support Engineer, Superior
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Skype 2.0.0.97 Major BUG
2. Buffer overflow?
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #291
2. Restricting Remote Registry Access
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Protection from prying NSA eyes
By Mark Rasch
From the U.S. Fourth Amendment, the Stored Communications Act and U.S. wiretap laws to the Pen-register statute, Mark Rasch looks at legal protections available to the telecommunication companies and individual Americans in the wake of the NSA's massive spying program.
http://www.securityfocus.com/columnists/403
2. Malicious cryptography, part two
By Frederic Raynal
This two-part article series looks at how cryptography is a double-edged sword: it is used to make us safer, but it is also being used for malicious purposes within sophisticated viruses. Part two continues the discussion of armored viruses and then looks at a Bradley worm - a worm that uses cryptography in such a way that it cannot be analyzed. Then it is shown how Skype can be used for malicious purposes, with a crypto-virus that is very difficult to detect.
http://www.securityfocus.com/infocus/1866
II. BUGTRAQ SUMMARY
--------------------
1. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
2. Awstats Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 17844
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17844
Summary:
Awstats is prone to an arbitrary command-execution vulnerabilit. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.
3. Linux Kernel SMBFS Multiple Remote Vulnerabilities
BugTraq ID: 11695
Remote: Yes
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11695
Summary:
The Linux kernel is reported susceptible to multiple remote vulnerabilities in the SMBFS network file system.
These vulnerabilities may lead to the execution of attacker-supplied machine code, information disclosure of kernel memory, or kernel crashes, denying service to legitimate users.
Versions of the kernel in both the 2.4, and the 2.6 series are reported susceptible to various issues.
4. Linux Kernel USB Driver Uninitialized Structure Information Disclosure Vulnerability
BugTraq ID: 10892
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10892
Summary:
Certain Linux Kernel USB drivers are prone to a vulnerability that may permit a local attacker to gain unauthorized to contents of kernel memory. This could reportedly reveal sensitive information to a local user.
5. Linux Kernel Floating Point Register Contents Leak Vulnerability
BugTraq ID: 10687
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10687
Summary:
The Linux kernel is reported prone to a data disclosure vulnerability.
It is reported that this issue may permit a malicious executable to disclose the contents of Floating Point registers that belong to another process.
It is reported that this vulnerability will only affect ia64 systems.
6. Linux Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 10783
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10783
Summary:
Linux kernel is reported prone to an unspecified local denial of service vulnerability. It is reported that issue only affects ia64 systems. A local attacker can exploit this issue by dereferencing a NULL pointer and causing a kernel panic. Successful exploitation will lead to a denial of service condition in a vulnerable computer.
No further details are available at this time. This issue will be updated as more information becomes available.
7. Linux Kernel Multiple Device Driver Vulnerabilities
BugTraq ID: 10566
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10566
Summary:
It has been reported that the Linux kernel is vulnerable to multiple device driver issues. These issues were found during a recent audit of the Linux kernel source.
Drivers reportedly affected by these issues are: aironet, asus_acpi, decnet, mpu401, msnd, and pss.
These issues may reportedly allow attackers to gain access to kernel memory or gain escalated privileges on the affected computer.
8. Linux Kernel Panic Function Call Buffer Overflow Vulnerability
BugTraq ID: 10233
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10233
Summary:
The panic() function call of the Linux kernel has been reported prone to a buffer overflow vulnerability.
The vulnerability is reported to present itself when an unbounded vsprintf() call within panic() copies user-supplied data into a fixed buffer. It is reported that it is possible to overrun the bounds of the affected buffer and corrupt adjacent memory. Because this buffer resides in kernel memory space this issue may potentially be exploited to cause kernel memory corruption, revelation of kernel memory and although unconfirmed, arbitrary code execution. Some reports indicate that this
vulnerability is not exploitable to any means.
9. Linux kernel do_fork() Memory Leakage Vulnerability
BugTraq ID: 10221
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/10221
Summary:
It has been reported that the Linux kernel may be prone to a memory leakage vulnerability. The issue exists because memory is allocate for child processes but never freed.
This issue has been identified in kernel versions 2.4 and 2.6.
10. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Last Updated: 2006-05-20
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability.
This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users.
Kernel versions prior to 2.6.16.18 are vulnerable to this issue.
11. Woltlab Burning Board Links.PHP SQL Injection Vulnerability
BugTraq ID: 18077
Remote: Yes
Last Updated: 2006-05-20
Relevant URL: http://www.securityfocus.com/bid/18077
Summary:
Woltlab Burning Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Woltlab Burning Board 2.3.4 and prior versions may be affected by this issue.
12. CaLogic Calendars Multiple Remote File Include Vulnerabilities
BugTraq ID: 18076
Remote: Yes
Last Updated: 2006-05-20
Relevant URL: http://www.securityfocus.com/bid/18076
Summary:
CaLogic Calendars is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
CaLogic Calendars 1.2.2 is reported to be vulnerable. Other versions may be affected as well.
13. Sybase EAServer J2EE Application Clients and Java GUI Applications Password Disclosure Vulnerability
BugTraq ID: 18036
Remote: No
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18036
Summary:
Sybase EAServer may expose passwords through GUI applications. A local user could exploit this vulnerability to view another user's password.
EAServer versions 5.0, 5.2 and 5.3 are vulnerable to this issue.
This issue affects users who develop and deploy their own GUI applications using J2EE Application Clients and Java GUI applications with EAServer. GUI applications built by other vendors may also be affected.
14. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.
Specific details of these issues are not currently available. This record will be updated when more information becomes available.
The following are vulnerable:
- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier
15. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
16. KPhone Local Information Disclosure Vulnerability
BugTraq ID: 18049
Remote: No
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18049
Summary:
KPhone is susceptible to a local information-disclosure vulnerability. This issue is due to the application's failure to ensure that files containing sensitive information are properly secured.
This issue allows local attackers to gain access to potentially sensitive information, including SIP configuration and passwords. This may aid them in further attacks.
KPhone version 4.2 is vulnerable to this issue; other versions may also be affected.
17. Artmedic Newsletter Log.PHP Remote Script Execution Vulnerability
BugTraq ID: 18047
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18047
Summary:
Artmedic Newsletter is prone to a remote PHP code-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to create files containing arbitrary content that can include arbitrary malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible. Attackers may also remove arbitrary log files, assisting them in obscuring their actions.
Version 4.1 of the software is vulnerable to this issue; other versions may also be affected.
18. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
19. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
20. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
21. YourFreeWorld Stylish Text Ads Script Multiple HTML Injection Vulnerabilities
BugTraq ID: 18044
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18044
Summary:
Stylish Text Ads Script is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
22. JemWeb DownloadControl DC.PHP SQL Injection Vulnerability
BugTraq ID: 18041
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18041
Summary:
DownloadControl is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
DownloadControl 1.0 is reported vulnerable. Other versions may be affected as well.
23. ZixForum Settings.ASP SQL Injection Vulnerability
BugTraq ID: 18043
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18043
Summary:
ZixForum is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
ZixForum 1.12 and prior versions are affected.
24. POPFile Denial Of Service Vulnerability
BugTraq ID: 16792
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/16792
Summary:
A denial-of-service vulnerability has been reported in POPFile.
A remote attacker may cause a denial-of-service condition in the application, effectively halting service to legitimate users.
25. Linux-VServer Local Insecure Guest Context Capabilities Vulnerability
BugTraq ID: 17842
Remote: No
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/17842
Summary:
The Linux-VServer package is susceptible to a vulnerability regarding insecure guest-context capabilities. This issue is due to the kernel's failure to properly enforce security restrictions in guest hosts.
This issue allows unprivileged users in guest hosts to perform various operations that should be restricted to superusers. By exploiting this issue, attackers can launch various attacks in guest hosts.
Note that this issue allows attackers to execute privileged operations only in the guest context, not in the host context.
26. PHPRaid View.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18042
Remote: Yes
Last Updated: 2006-05-19
Relevant URL: http://www.securityfocus.com/bid/18042
Summary:
phpRaid is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects phpRaid version 2.9.5; other versions may also be vulnerable.
27. Another Image Gallery Gallery.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18073
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18073
Summary:
Another Image Gallery is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.1; other versions may also be vulnerable.
28. Captivate Gallery.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18072
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18072
Summary:
Captivate is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.0; other versions may also be vulnerable.
29. Destiney Links Script Multiple HTML Injection Vulnerabilities
BugTraq ID: 18071
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18071
Summary:
Destiney Links Script is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
These issues affect version 2.1.2; other versions may also be vulnerable.
30. Destiney Rated Images Addweblog.PHP HTML Injection Vulnerability
BugTraq ID: 18070
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18070
Summary:
Destiney Rated Images is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects version 0.5.0; other versions may also be vulnerable.
31. Hscripts HGB Index.PHP HTML Injection Vulnerability
BugTraq ID: 18069
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18069
Summary:
HGB from hscripts is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects HGB 3.1; other versions may also be vulnerable.
32. Prodder Arbitrary Shell Command Execution Vulnerability
BugTraq ID: 18068
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18068
Summary:
Prodder is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary shell commands on the vulnerable computer in the context of the running application.
33. Perlpodder Arbitrary Shell Command Execution Vulnerability
BugTraq ID: 18067
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18067
Summary:
Perlpodder is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary shell commands on the vulnerable computer in the context of the running application.
34. NetPBM PSToPNM Arbitrary Code Execution Vulnerability
BugTraq ID: 14379
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/14379
Summary:
The 'pstopnm' command is susceptible to an arbitrary command-execution vulnerability. This issue is due to the program's failure of to ensure that GhostScript is executed in a secure manner.
This issue allows attackers to create malicious PostScript files that allow arbitrary commands to be executed when the affected utility parses the files. This occurs in the context of the user running the affected utility.
This vulnerability was reported in version 10.0 of netpbm. Other versions may also be affected.
35. BitZipper Remote Directory Traversal Vulnerability
BugTraq ID: 18065
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18065
Summary:
Reportedly, an attacker can carry out attacks similar to directory traversals. These issues present themselves when the application processes malicious archives.
A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploits may aid in further attacks.
36. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17955
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17955
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel deadlock and infinite recursion, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
37. EMC Retrospect Client Buffer Overflow Vulnerability
BugTraq ID: 18064
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18064
Summary:
Retrospect Client for Windows is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly verify user-supplied input before copying it into a finite-sized buffer.
Successful exploits may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.
Retrospect 7.5 Client for Windows is reported vulnerable. Other versions may be affected as well.
38. Linux Kernel Lease_Init Local Denial of Service Vulnerability
BugTraq ID: 17943
Remote: No
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17943
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'lease_init' function.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.16.
39. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17910
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17910
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
Note that a valid SCTP endpoint must be listening.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
40. PHPWCMS CNT6.INC.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18063
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18063
Summary:
The phpwcms application is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.2.5-DEV; other versions may also be vulnerable.
41. PHPWCMS Spaw_Control.Class.PHP Local File Include Vulnerability
BugTraq ID: 18062
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18062
Summary:
The phpwcms application is prone to a local file-include vulnerability. This may allow unauthorized users to view files and to execute local scripts.
An attacker may also be able to execute arbitrary code by way of uploaded images.
Version 1.2.5-DEV is affected; earlier versions may also be vulnerable.
42. XOOPS Mainfile.PHP Local File Include Vulnerability
BugTraq ID: 18061
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18061
Summary:
XOOPS is prone to a local file-include vulnerability. This may allow unauthorized users to view files and to execute local scripts.
An attacker may also be able to execute arbitrary code by way of uploaded avatars.
Version 2.0.13.2 is vulnerable; earlier versions may also be affected.
43. Power Place PHP Easy Galerie Index.PHP Remote File Include Vulnerability
BugTraq ID: 18060
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18060
Summary:
PHP Easy Galerie is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
44. Ethereal IRC Protocol Dissector Denial of Service Vulnerability
BugTraq ID: 15219
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/15219
Summary:
The Ethereal IRC protocol dissector is prone to a remotely exploitable denial-of-service vulnerability.
An attacker may exploit this issue by causing Ethereal to process a malformed packet. Successful exploitation will cause a denial-of-service condition in the Ethereal application.
Further details are not currently available. This BID will be updated as more information is disclosed.
45. Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
BugTraq ID: 18058
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18058
Summary:
The Sun Java Runtime Environment is vulnerable to a denial-of-service vulnerability. This issue is due to the software's failure to handle exceptional conditions.
This issue is reported to affect Java Runtime Environment versions up to 1.4.2_11 and 1.5.0_06. This issue will crash Internet browsers running an affected Java plug-in.
An attacker may exploit this issue to cause a vulnerable application -- as well as all processes spawned from the application -- to crash, denying service to legitimate users. Due to the scope of the crash, data loss may occur.
46. Skype Technologies Skype URI Handling Remote File Download Vulnerability
BugTraq ID: 18038
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18038
Summary:
Skype is prone to an arbitrary file-download vulnerability. This issue is due to improper Skype URI handling.
This issue allows remote attackers to transfer files from one Skype user to another, provided the recipient user has previously approved downloads.
By exploiting this issue, attackers may retrieve an arbitrary file from the victim user's computer.
The following versions of Skype for Windows are vulnerable to this issue:
- prior to 2.0.*.104
- 2.5.*.0 through 2.5.*.78.
47. Nagios Remote Content-Length Integer Overflow Vulnerability
BugTraq ID: 18059
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18059
Summary:
Nagios is prone to a remote integer-overflow vulnerability. The application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3.1 are vulnerable to this issue.
This issue is very similar to BID 17879 (Nagios Remote Negative Content-Length Buffer Overflow Vulnerability), but is a separate issue.
48. Nagios Remote Negative Content-Length Buffer Overflow Vulnerability
BugTraq ID: 17879
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17879
Summary:
Nagios is susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3 in the 2.x series, and versions prior to 1.4 in the 1.x series are vulnerable to this issue.
49. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 18057
Remote: No
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18057
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability.
This issue arises because the software fails to handle exceptional conditions in a proper manner.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.
50. LibXpm Image Decoding Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 11196
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/11196
Summary:
Multiple vulnerabilities are reported to exist in the libXpm. These issues may be triggered when the library handles malformed XPM images. The vulnerabilities occur because the software fails to perform sufficient boundary checks. A successful attack may allow for unauthorized access to a vulnerable computer.
An attacker can exploit these issues by crafting a malicious XPM file and having unsuspecting users view the file through an application that uses the affected library.
LibXpm shipped with X.org X11R6 6.8.0 is reported vulnerable to this issue.
This BID will be divided and updated as more information becomes available.
51. Website Baker User Display Name HTML Injection Vulnerability
BugTraq ID: 17868
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17868
Summary:
Website Baker is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
52. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
BugTraq ID: 18056
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18056
Summary:
Cyrus IMAPD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly verify user-supplied input before copying it into a finite-sized buffer.
Successful exploits may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.
Cyrus IMAPD version 2.3.2 is reported to be vulnerable. Other versions may be affected as well.
53. Quagga BGPD Local Denial Of Service Vulnerability
BugTraq ID: 17979
Remote: No
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17979
Summary:
Quagga is prone to a local denial-of-service vulnerability.
An attacker can exploit this issue by using commands that cause the consumption of a large amount of CPU resources.
An attacker may cause the application to crash, thus denying service to legitimate users.
Version 0.98.3 is vulnerable; other versions may also be affected.
54. Libextractor Multiple Heap Buffer Overflow Vulnerabilities
BugTraq ID: 18021
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18021
Summary:
The libextractor library is affected by multiple buffer-overflow vulnerabilities. The software fails to perform sufficient boundary checks of user-supplied input before copying it to insufficiently sized memory buffers.
An attacker exploits these issues by enticing a vulnerable user to open a malformed file using an application that employs libextractor.
This issue allows attackers to execute arbitrary machine code in the context of applications that use the affected library, aiding them in the remote compromise of affected computers.
Version 0.5.13 of libextractor is vulnerable to these issues; other versions may also be affected.
55. Quagga Information Disclosure and Route Injection Vulnerabilities
BugTraq ID: 17808
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17808
Summary:
Quagga is susceptible to remote information-disclosure and route-injection vulnerabilities. The application fails to properly ensure that required authentication and protocol configuration options are enforced.
These issues allow remote attackers to gain access to potentially sensitive network-routing configuration information and to inject arbitrary routes into the RIP routing table. This may aid malicious users in further attacks against targeted networks.
Quagga versions 0.98.5 and 0.99.3 are vulnerable to these issues; other versions may also be affected.
56. Xtreme Topsites Multiple Input Validation Vulnerabilities
BugTraq ID: 18055
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18055
Summary:
Xtreme Topsites is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting, HTML-injection, and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
57. ActualScripts ActualAnalyzer Direct.PHP Remote File Include Vulnerability
BugTraq ID: 17597
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17597
Summary:
ActualAnalyzer is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
58. PHPBazar Admin.PHP Unauthorized Access Vulnerability
BugTraq ID: 18053
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18053
Summary:
phpBazar is prone to an unauthorized-access vulnerability. This issue is due to a failure in the application to properly validate credentials before granting access to sensitive scripts.
An attacker can exploit this issue to alter the administrator credentials, ultimately gaining administrative access.
59. PHPBazar Classified_right.PHP Remote File Include Vulnerability
BugTraq ID: 18052
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18052
Summary:
phpBazar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
60. Blender BlenLoader File Processing Integer Overflow Vulnerability
BugTraq ID: 15981
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/15981
Summary:
Blender is susceptible to an integer-overflow vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a memory allocation and copy operation.
This issue allows attackers to execute arbitrary machine code in the context of the user running the affected application.
61. Fbida FBGS Insecure Temporary File Creation Vulnerability
BugTraq ID: 17436
Remote: No
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17436
Summary:
The 'fbida' utilities create temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to view files and obtain privileged information. The attacker may also perform symlink attacks, overwriting arbitrary files in the context of the affected application.
A successful attack would most likely result in loss of confidentiality and theft of privileged information. Successful exploitation of a symlink attack may allow an attacker to overwrite sensitive files. This may result in a denial of service; other attacks may also be possible.
62. RunCMS Remote Code Execution Vulnerability
BugTraq ID: 16578
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/16578
Summary:
RunCMS is prone to a remote code-execution vulnerability. This issue exists because the application allows remote users to upload files and call a connector script to execute the files.
This issue affects RunCMS version 1.3a2 and earlier.
63. CScope Include Filename Buffer Overflow Vulnerability
BugTraq ID: 18050
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18050
Summary:
Cscope is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to properly validate the size of attacker-supplied data before copying it into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the user running the application. Failed exploit attempts will likely crash the application, denying service to legitimate users.
64. Network Block Device Server Buffer Overflow Vulnerability
BugTraq ID: 16029
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/16029
Summary:
NBD is prone to a remote buffer overflow vulnerability. This issue is due to a failure in the server to do proper bounds checking on user-supplied data before using it in finite sized buffers.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the underlying system.
65. hostapd Invalid EAPOL Key Length Remote Denial Of Service Vulnerability
BugTraq ID: 17846
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17846
Summary:
The hostapd application is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed EAPOL-Key packets.
This issue allows remote attackers to crash affected applications, denying further network service to legitimate users.
Version 0.3.7 of hostapd is vulnerable to this issue; previous versions may also be affected.
66. FUDforum Avatar Upload Arbitrary Script Upload Vulnerability
BugTraq ID: 14678
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/14678
Summary:
FUDforum is prone to a remote arbitrary PHP file-upload vulnerability.
An attacker can merge an image file with a script file and upload it to an affected server.
This issue can facilitate unauthorized remote access.
FUDforum versions prior to 2.7.1 are reported affected. Currently, Symantec cannot confirm if version 2.7.1 is affected as well.
67. YourFreeWorld Short Url & Url Tracker Script Multiple HTML Injection Vulnerabilities
BugTraq ID: 18046
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18046
Summary:
Short Url & Url Tracker Script is prone to multiple HTML-injection vulnerabilities because the software fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
68. RealVNC Remote Authentication Bypass Vulnerability
BugTraq ID: 17978
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17978
Summary:
RealVNC is susceptible to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.
Exploiting this issue allows attackers to gain unauthenticated, remote access to the VNC servers.
RealVNC version 4.1.1 is vulnerable to this issue; other versions may also be affected.
69. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.
Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.
This issue affects Apache 2.x versions.
70. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
71. GNU Strings Denial Of Service Vulnerability
BugTraq ID: 17950
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17950
Summary:
The strings utility is susceptible to a denial-of-service vulnerability because it fails to properly handle unexpected user-supplied input.
This issue allows attackers to crash the affected utility. This may aid attackers by making analysis of binary files more difficult.
72. Sun ONE Directory Server Remote Denial Of Service Vulnerability
BugTraq ID: 16550
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/16550
Summary:
Sun ONE Directory Server is prone to a remote denial-of-service vulnerability. This issue is due to the application's failure to handle malformed network traffic.
This issue allows remote attackers to crash the application, denying service to legitimate users.
73. Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
BugTraq ID: 18026
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18026
Summary:
The Novell eDirectory Server iMonitor is prone to a buffer-overflow vulnerability. Successfully exploiting this issue could allow arbitrary code execution with administrative privileges.
iMonitor version 2.4, which is included with eDirectory version 8.8, is vulnerable to this issue; other versions may also be affected.
74. Multiple Vendor SSH Server Remote Buffer Overflow Vulnerability
BugTraq ID: 17958
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/17958
Summary:
Multiple SSH server implementations are prone to a remote buffer-overflow vulnerability. The applications fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
A successful attack may facilitate arbitrary code execution. Exploiting this vulnerability may allow an attacker to gain administrative access on targeted computers.
75. TFTPD32 Long Filename Buffer Overflow Vulnerability
BugTraq ID: 6199
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/6199
Summary:
A buffer overflow vulnerability has been reported for Tftpd32. The vulnerability is due to insufficient checks on user supplied input.
A remote attacker is able to exploit this vulnerability by supplying a long string as a name of the file to retrieve. This will trigger the buffer overflow condition. Any malicious attacker-supplied code will be executed with the privileges of the Tftpd32 process.
76. Beats Of Rage Multiple Format String Vulnerabilities
BugTraq ID: 18088
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18088
Summary:
Beats of Rage is prone to multiple remote format-string vulnerabilities.
This issue arises when the application handles specially crafted mod files. An attacker can exploit this vulnerability by crafting a malicious mod file that contains format specifiers and then coercing unsuspecting users to use the malicious mod files when running the application.
A successful attack may crash the application or lead to arbitrary code execution.
77. IPLogger Useragent HTML Injection Vulnerability
BugTraq ID: 18086
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18086
Summary:
ipLogger is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects version 1.7; other versions may also be vulnerable.
78. Multiple Browsers Exception Handling Information Disclosure Vulnerability
BugTraq ID: 18083
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18083
Summary:
Multiple browsers are prone to an information-disclosure vulnerability.
An attacker can exploit this issue to retrieve the installation directory of affected applications, and potentially retrieve profile information in certain configurations. Information obtained may aid in further attacks.
79. Dia Filename Remote Format String Vulnerability
BugTraq ID: 18078
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18078
Summary:
Dia is prone to a remote format-string vulnerability.
This issue arises when the application handles specially crafted filenames. An attacker can exploit this vulnerability by crafting a malicious filename that contains format specifiers and then coercing unsuspecting users to open the malicious file with the affected application.
A successful attack may crash the application or lead to arbitrary code execution.
This issue affects Dia versions 0.95 and earlier.
80. UBB.threads Addpost_newpoll.PHP Remote File Include Vulnerability
BugTraq ID: 18075
Remote: Yes
Last Updated: 2006-05-23
Relevant URL: http://www.securityfocus.com/bid/18075
Summary:
UBB.threads is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
81. MySQL Query Logging Bypass Vulnerability
BugTraq ID: 16850
Remote: Yes
Last Updated: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/16850
Summary:
MySQL is susceptible to a query-logging-bypass vulnerability. This issue is due to a discrepancy between the handling of NULL bytes in the 'mysql_real_query()' function and in the query-logging functionality.
This issue allows attackers to bypass the query-logging functionality of the database so they can cause malicious SQL queries to be improperly logged. This may help them hide the traces of their malicious activity from administrators.
This issue affects MySQL version 5.0.18; other versions may also be affected.
82. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
BugTraq ID: 17780
Remote: Yes
Last Updated: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/17780
Summary:
MySQL is susceptible to multiple remote vulnerabilities:
- A buffer-overflow vulnerability due to insufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue allows remote attackers to execute arbitrary machine code in the context of affected database servers. Failed exploit attempts will likely crash the server, denying further service to legitimate users.
- Two information-disclosure vulnerabilities due to insufficient input-sanitization and bounds-checking of user-supplied data. These issues allow remote users to gain access to potentially sensitive information that may aid them in further attacks.
83. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
84. DSChat HTML Injection Vulnerability
BugTraq ID: 18084
Remote: Yes
Last Updated: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/18084
Summary:
DSChat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
85. Chatty Username HTML Injection Vulnerability
BugTraq ID: 18082
Remote: Yes
Last Updated: 2006-05-22
Relevant URL: http://www.securityfocus.com/bid/18082
Summary:
Chatty is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
86. Linux Kernel Unw_Unwind_To_User Local Denial of Service Vulnerability
BugTraq ID: 13266
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/13266
Summary:
A local denial of service vulnerability affects the Linux kernel.
A local attacker may leverage this issue to cause an affected Linux kernel to panic, effectively denying service to legitimate users.
87. Linux Kernel PPP Driver Unspecified Remote Denial Of Service Vulnerability
BugTraq ID: 12810
Remote: Yes
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12810
Summary:
Linux Kernel (Point-to-Point Protocol) PPP Driver is reported prone to an unspecified remote denial of service vulnerability.
A successful attack can cause a denial of service condition in the server and prevent access to legitimate users.
Linux Kernel 2.6.8 was reported vulnerable. It is possible that subsequent versions are affected as well.
Due to a lack of details, further information is not available at the moment. This BID will be updated when more information becomes available.
88. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow Vulnerabilities
BugTraq ID: 12195
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12195
Summary:
The MOXA serial port driver in the Linux kernel is reported susceptible to multiple buffer overflow vulnerabilities. These issues are due to a failure of the driver to perform proper bounds checks prior to copying user-supplied data to fixed-size memory buffers.
These vulnerabilities exist in the 'drivers/char/moxa.c' file.
The vulnerable functions perform a 'copy_from_user()' function call to copy user-supplied, user-space data to a fixed-size, static kernel memory buffer (moxaBuff) of 10240 bytes in length while utilizing the user-supplied length argument as passed from 'MoxaDriverIoctl()'. This reportedly results in improperly bounded operations, potentially resulting in locally exploitable buffer overflows.
Linux kernels from 2.2, through 2.4, and 2.6 are all reportedly susceptible to these vulnerabilities.
89. Linux kernel Uselib() Local Privilege Escalation Vulnerability
BugTraq ID: 12190
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12190
Summary:
Linux kernel is reported prone to a local privilege escalation vulnerability. This issue arises in the 'uselib()' functions of the Linux binary format loader as a result of a race condition. Successful exploitation of this vulnerability can allow a local attacker to gain elevated privileges on a vulnerable computer.
The ELF and a.out loaders are reportedly affected by this vulnerability.
90. Linux Kernel User Triggerable BUG() Unspecified Local Denial of Service Vulnerability
BugTraq ID: 12261
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12261
Summary:
Linux Kernel is reported prone to a local denial of service vulnerability.
It is reported that this issue presents itself when a large Virtual Memory Area (VMA) is created by a user that overlaps with arg pages during the exec() system call.
Successful exploitation will lead to a denial of service condition in a vulnerable computer.
No further details are available at this time. This issue will be updated as more information becomes available.
91. Linux Kernel ELF Binary Loading Denial Of Service Vulnerability
BugTraq ID: 12101
Remote: Yes
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12101
Summary:
The Linux kernel is affected by an ELF binary loading vulnerability. This issue is due to a failure of the affected kernel to properly handle malformed ELF binaries.
An attacker may leverage this issue to cause the affected kernel to crash, denying service to legitimate users.
92. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
BugTraq ID: 11715
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11715
Summary:
A serialization error is reported to exist in the AF_UNIX address family; the error creates a race condition. This race condition reportedly allows local users to repeatedly increment arbitrary kernel memory locations.
This vulnerability allows local users to modify arbitrary kernel memory, facilitating privilege escalation; it may possibly allow code execution in the context of the kernel.
Versions prior to 2.4.28 are reportedly affected by this vulnerability.
93. Linux Kernel Local Denial Of Service And Memory Disclosure Vulnerabilities
BugTraq ID: 11754
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11754
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities. The following issues are reported:
Reports indicate that a handcrafted 'a.out' file may be used to trigger a local denial of service condition.
A local attacker may exploit this vulnerability to trigger a system-wide denial of service, potentially resulting in a kernel panic.
A memory disclosure vulnerability is also reported to affect the Linux kernel. This issue reportedly only affects SMP computers with more than 4GB of memory.
A local attacker may exploit this vulnerability to disclose random pages of physical memory.
94. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
BugTraq ID: 11646
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11646
Summary:
Multiple vulnerabilities have been identified in the Linux ELF binary loader. These issues can allow local attackers to gain elevated privileges. The source of these issues resides in the 'load_elf_binary' function of the 'binfmt_elf.c' file.
The first issue results from an improper check performed on the return value of the 'kernel_read()' function. An attacker may gain control over execution flow of a setuid binary by modifying the memory layout of a binary.
The second issue results from improper error-handling when the 'mmap()' function fails.
The third vulnerability results from a bad return value when the program interpreter (linker) is mapped into memory. It is reported that this issue occurs only in the 2.4.x versions of the Linux kernel.
The fourth issue presents itself because a user can execute a binary with a malformed interpreter name string. This issue can lead to a system crash.
The final issue resides in the 'execve()' code. This issue may allow an attacker to disclose sensitive data that can potentially be used to gain elevated privileges.
These issues are currently undergoing further analysis. This BID will be updated and divided into separate BIDS in the future.
95. Linux Kernel 2.4 RTC Handling Routines Memory Disclosure Vulnerability
BugTraq ID: 9154
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/9154
Summary:
The Linux kernel 2.4 tree has been reported prone to a memory disclosure vulnerability. The issue is reported to present itself in kernel real time clock interface procedures, and may result in kernel memory stack data being leaked into user land. The source of the vulnerability is that an internal real time clock structure is not properly initialized with zeros before being read, potentially returning random contents of kernel stack memory when this operation occurs. This could expose
sensitive information such as credentials to unprivileged users.
96. Linux Kernel Coda_Pioctl Local Buffer Overflow Vulnerability
BugTraq ID: 14967
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/14967
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability.
Specifically, the vulnerability affects the 'coda_pioctl()' function of the 'pioctl.c' file.
A successful attack may result in a denial-of-service condition or arbitrary code execution with superuser privileges.
This issue may be related to the issues described in BID 12239 (Linux Kernel Multiple Unspecified Vulnerabilities).
97. Linux Kernel USB io_edgeport Driver Local Integer Overflow Vulnerability
BugTraq ID: 12102
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12102
Summary:
A local integer-overflow vulnerability affects the Linux kernel's 'io_edgeport' USB driver. This issue is due to the driver's failure to validate integer bounds.
An attacker may leverage this issue to execute arbitrary instructions or cause the affected kernel to crash.
98. Linux Kernel Multiple Local Vulnerabilities
BugTraq ID: 11956
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11956
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities. The following individual issues are reported:
- An integer overflow is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file. This vulnerability is reported to exist only in the 2.6 kernel tree. Although unconfirmed, due to its nature this issue presumably may be further leveraged to execute arbitrary code with ring-0 privileges.
A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.
- A second integer-overflow vulnerability is reported to exist in the 'vc_resize()' function of the Linux kernel. This vulnerability is reported to exist in the 2.6 and 2.4 kernel trees. Although unconfirmed, due to its nature this issue presumably may be further leveraged to execute arbitrary code with ring-0 privileges.
A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible.
- A memory leak is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file. This vulnerability is reported to exist in the 2.6, and 2.4 kernel tree.
A local attacker may exploit this vulnerability to consume kernel heap memory resources and in doing so may impact system performance, ultimately resulting in a denial of service to legitimate users.
99. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
BugTraq ID: 11921
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/11921
Summary:
Linux kernel is reported prone to a local denial of service vulnerability. This issue presents itself in the SCM logical sub layer of the socket API.
An unprivileged application can craft a malformed auxiliary message and send it to a socket, which results in the kernel invoking '__scm_send()' in a manner that leads to a crash. This issue can allow local attackers to cause a denial of service condition on a vulnerable computer. It is not confirmed if this vulnerability can be leveraged to gain elevated privileges.
100. Linux Kernel Symmetrical Multiprocessing Page Fault Local Privilege Escalation Vulnerability
BugTraq ID: 12244
Remote: No
Last Updated: 2006-05-21
Relevant URL: http://www.securityfocus.com/bid/12244
Summary:
A local privilege escalation vulnerability affects the page fault handler of the Linux Kernel on symmetric multiprocessor (SMP) computers. This issue is due to a race condition error that may allow an attacker to gain superuser privileges.
A malicious local attacker may exploit this issue to gain superuser privileges on an the affected computer.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Veterans Affairs warns of massive privacy breach
By: Robert Lemos
The records of nearly 26.5 million veterans--including names, social security numbers and dates of birth--were stolen from the home of a federal employee.
http://www.securityfocus.com/news/11393
2. Blue Security folds under spammer's wrath
By: Robert Lemos
Under threat of further attacks on its service and users, an Israeli anti-spam startup decides to shutter its service.
http://www.securityfocus.com/news/11392
3. Diebold voting systems critically flawed
By: Robert Lemos
Concerns raised by a rural county in Utah helped an electronic voting watchdog discover a critical vulnerability in Diebold Election Systems' touchscreen terminal--a flaw that state election officials and security experts warn could pose a risk to elections.
http://www.securityfocus.com/news/11391
4. Bot software looks to improve peerage
By: Robert Lemos
Threatened by investigators' ability to tap into chat-based command-and-control networks, bot masters increasingly look to peer-to-peer communications, encryption and other technologies to hide their tracks.
http://www.securityfocus.com/news/11390
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] VP, Information Security, Bournmouth
http://www.securityfocus.com/archive/77/434844
2. [SJ-JOB] Sales Representative, NORTHWEST
http://www.securityfocus.com/archive/77/434845
3. [SJ-JOB] Sr. Security Analyst, Norfolk
http://www.securityfocus.com/archive/77/434843
4. [SJ-JOB] Penetration Engineer, London - UK Wide
http://www.securityfocus.com/archive/77/434833
5. [SJ-JOB] Sr. Security Analyst, McLean
http://www.securityfocus.com/archive/77/434834
6. [SJ-JOB] Security Researcher, Cambridge
http://www.securityfocus.com/archive/77/434835
7. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/434839
8. [SJ-JOB] Channel / Business Development, SAN DIEGO
http://www.securityfocus.com/archive/77/434840
9. [SJ-JOB] Penetration Engineer, Cambridge
http://www.securityfocus.com/archive/77/434832
10. [SJ-JOB] Security Architect, London
http://www.securityfocus.com/archive/77/434836
11. [SJ-JOB] Security Architect, San Jose
http://www.securityfocus.com/archive/77/434435
12. [SJ-JOB] Management, San Francisco
http://www.securityfocus.com/archive/77/434436
13. [SJ-JOB] Sr. Product Manager, San Francisco
http://www.securityfocus.com/archive/77/434438
14. [SJ-JOB] VP / Dir / Mgr engineering, San Francisco
http://www.securityfocus.com/archive/77/434440
15. [SJ-JOB] Quality Assurance, Mysore
http://www.securityfocus.com/archive/77/434441
16. [SJ-JOB] Security Engineer, Fairfax
http://www.securityfocus.com/archive/77/434429
17. [SJ-JOB] VP of Regional Sales, Pittsburgh
http://www.securityfocus.com/archive/77/434432
18. [SJ-JOB] Application Security Architect, Singapore
http://www.securityfocus.com/archive/77/434433
19. [SJ-JOB] Application Security Architect, Frankfurt or Munich
http://www.securityfocus.com/archive/77/434434
20. [SJ-JOB] Auditor, NY/NJ
http://www.securityfocus.com/archive/77/434437
21. [SJ-JOB] Security Architect, Edison
http://www.securityfocus.com/archive/77/434364
22. [SJ-JOB] Manager, Information Security, New York (Brooklyn Metrotech)
http://www.securityfocus.com/archive/77/434359
23. [SJ-JOB] Security Engineer, Bangalore, Hyderabad or Mumbai
http://www.securityfocus.com/archive/77/434360
24. [SJ-JOB] Sr. Security Engineer, Weehawkin
http://www.securityfocus.com/archive/77/434362
25. [SJ-JOB] Manager, Information Security, New York (Brooklyn Metrotech)
http://www.securityfocus.com/archive/77/434358
26. [SJ-JOB] Software Engineer, Austin
http://www.securityfocus.com/archive/77/434353
27. [SJ-JOB] Application Security Architect, London
http://www.securityfocus.com/archive/77/434354
28. [SJ-JOB] Senior Software Engineer, Austin
http://www.securityfocus.com/archive/77/434355
29. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/434356
30. [SJ-JOB] Sr. Security Analyst, Bellevue
http://www.securityfocus.com/archive/77/434357
31. [SJ-JOB] Security System Administrator, Columbia
http://www.securityfocus.com/archive/77/434275
32. [SJ-JOB] Jr. Security Analyst, Milwaukee
http://www.securityfocus.com/archive/77/434276
33. [SJ-JOB] VP, Information Security, Centreville
http://www.securityfocus.com/archive/77/434277
34. [SJ-JOB] Associate Software Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/434281
35. [SJ-JOB] Sr. Security Analyst, Edinburgh
http://www.securityfocus.com/archive/77/434269
36. [SJ-JOB] Information Assurance Analyst, Springfield
http://www.securityfocus.com/archive/77/434270
37. [SJ-JOB] Forensics Engineer, Columbia
http://www.securityfocus.com/archive/77/434271
38. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/434274
39. [SJ-JOB] Sr. Security Analyst, London/Edinburgh
http://www.securityfocus.com/archive/77/434266
40. [SJ-JOB] Channel / Business Development, Boston
http://www.securityfocus.com/archive/77/434267
41. [SJ-JOB] Security System Administrator, Santa Clara
http://www.securityfocus.com/archive/77/434257
42. [SJ-JOB] Jr. Security Analyst, Parsippany
http://www.securityfocus.com/archive/77/434260
43. [SJ-JOB] Security Consultant, Germany
http://www.securityfocus.com/archive/77/434262
44. [SJ-JOB] Security Researcher, North Sydney
http://www.securityfocus.com/archive/77/434263
45. [SJ-JOB] Threat Analyst, Springfield
http://www.securityfocus.com/archive/77/434252
46. [SJ-JOB] Quality Assurance, Pverland
http://www.securityfocus.com/archive/77/434258
47. [SJ-JOB] Jr. Security Analyst, Parsippany
http://www.securityfocus.com/archive/77/434259
48. [SJ-JOB] Technology Risk Consultant, Alpharetta
http://www.securityfocus.com/archive/77/434250
49. [SJ-JOB] Developer, Overland
http://www.securityfocus.com/archive/77/434253
50. [SJ-JOB] Jr. Security Analyst, Parsippany
http://www.securityfocus.com/archive/77/434256
51. [SJ-JOB] Technical Support Engineer, Superior
http://www.securityfocus.com/archive/77/434251
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Skype 2.0.0.97 Major BUG
http://www.securityfocus.com/archive/82/434426
2. Buffer overflow?
http://www.securityfocus.com/archive/82/434324
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #291
http://www.securityfocus.com/archive/88/434273
2. Restricting Remote Registry Access
http://www.securityfocus.com/archive/88/433671
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is sponsored by: Lancope
"Revolutionize the way you view your network security"
How do you protect what you can't see? Stop protecting while blind. Gain network visibility now. Learn how Cisco NetFlow gives visibility and enables cost-effective security across distributed enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA) and Response solution, leverages Cisco NetFlow to provide scalable, internal network security.
ALERT: Download FREE White Paper "Network Behavior Analysis (NBA) in the Enterprise."
http://www.lancope.com/resource/