SecurityFocus Newsletter #354

Conrad Schilbe <[email protected]> Thu, 15 Jun 2006 09:59:11 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #354
----------------------------------------

This issue is sponsored by: PortAuthority Technologies

ALERT: What Information Is Leaving Your Organization?
Effective information leak monitoring and prevention is all about ACCURACY. Download the industry's first independent leak prevention accuracy test results validating PortAuthority as having the lowest false positives (<1%). Review the Open Leak Prevention Test Criteria and Test Tool and you be the judge!
Visit http://www.portauthoritytech.com/datasecuritylabs/

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Retain or restrain access logs?
II.   BUGTRAQ SUMMARY
       1. Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
       2. Apache mod_include Local Buffer Overflow Vulnerability
       3. BoastMachine Vote.PHP Remote File Include Vulnerability
       4. Microsoft DXImageTransform.Microsoft.Light ActiveX Control Remote Code Execution Vulnerability
       5. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability Variant
       6. Somery Team.PHP Remote File Include Vulnerability
       7. aWebNews Visview.PHP Remote File Include Vulnerability
       8. Microsoft Windows Malformed ART Image Remote Code Execution Vulnerability
       9. Myscrapbook Singlepage.PHP HTML Injection Vulnerability
       10. ISPConfig Multiple Remote File Include Vulnerabilities
       11. PhpBlueDragon CMS Template.PHP Remote File Include Vulnerability
       12. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
       13.  Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
       14. Content-Builder Multiple Remote File Include Vulnerabilities
       15. DoubleSpeak Multiple Remote File Include Vulnerabilities
       16. Microsoft JScript Memory Corruption Vulnerability
       17. Microsoft Internet Explorer Multipart HTML File Handling Remote Code Execution Vulnerability
       18. Microsoft Windows TCP/IP Protocol Driver Remote Buffer Overflow Vulnerability
       19. Microsoft Windows RPC Mutual Authentication Service Spoofing Vulnerability
       20. Microsoft PowerPoint Malformed Record Remote Code Execution Vulnerability
       21. Microsoft Internet Explorer Persistent Modal Dialog Window Address Bar Spoofing Vulnerability
       22. Microsoft Internet Explorer HTML Decoding Remote Code Execution Vulnerability
       23. Microsoft Internet Explorer CSS Import Cross-Domain Restriction Bypass Vulnerability
       24. Microsoft Internet Explorer Address Bar Spoofing Vulnerability
       25. Microsoft Windows GDI WMF Handling Heap Overflow Vulnerability
       26. CEScripts Multiple Scripts Cross-Site Scripting Vulnerabilities
       27. Apache HTTP Request Smuggling Vulnerability
       28. wv2 Remote Buffer Overflow Vulnerability
       29. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
       30. Sendmail Malformed MIME Message Denial Of Service Vulnerability
       31. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
       32. Squirrelmail Redirect.PHP Local File Include Vulnerability
       33. W3C Libwww Multiple Vulnerabilities
       34. KDE KDM Session Type Symbolic Link Vulnerability
       35. IBM AIX LSMCode Local Privilege Escalation Vulnerability
       36. DokuWiki Remote PHP Script Code Injection Vulnerability
       37. Asterisk IAX2 Remote Buffer Overflow Vulnerability
       38. MPlayer Multiple Integer Overflow Vulnerabilities
       39. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
       40. ISPConfig Session.INC.PHP Remote File Include Vulnerability
       41. PhpBB BBRSS.PHP Remote File Include Vulnerability
       42. RahnemaCo Page.PHP Remote File Include Vulnerability
       43. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
       44. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
       45. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
       46. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
       47. Linux Kernel Shared Memory Security Restriction Bypass Vulnerability
       48. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
       49. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
       50. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
       51. Linux Kernel RNDIS_Query_Response Remote Buffer Overflow Vulnerability
       52. Linux Kernel IP ID Information Disclosure Weakness
       53. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
       54. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
       55. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
       56. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
       57. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
       58. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
       59. KDE ArtsWrapper Local Privilege Escalation Vulnerability
       60. My Photo Scrapbook Multiple Input Validation Vulnerabilities
       61. IBM DB2 Universal Database Multiple Denial of Service Vulnerabilities
       62. Confixx FTP_index.PHP Cross-Site Scripting Vulnerability
       63. Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
       64. Microsoft Exchange Server Outlook Web Access Script Injection Vulnerability
       65. PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
       66. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
       67. Microsoft Windows Routing and Remote Access Unspecified Remote Code Execution Vulnerability
       68. LibTiff TIFFToRGB Denial of Service Vulnerability
       69. Zoo Misc.c Buffer Overflow Vulnerability
       70. LibTiff Multiple Denial of Service Vulnerabilities
       71. LibTiff Double Free Memory Corruption Vulnerability
       72. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
       73. LibTiff TIFFFetchData Integer Overflow Vulnerability
       74. Vixie Cron Crontab File Disclosure Vulnerability
       75. Microsoft Windows Media Player Malformed PNG Remote Code Execution Vulnerability
       76. Woltlab Burning Board Multiple SQL Injection Vulnerabilities
       77. Microsoft Windows Routing and Remote Access RASMAN Registry Remote Code Execution Vulnerability
       78. Microsoft Windows Routing and Remote Access Remote Code Execution Vulnerability
       79. Wheatblog View_Links.PHP Remote File Include Vulnerability
       80. Hinton Design PHPHG Guestbook Signed.PHP Remote File Include Vulnerability
       81. CzarNews Remote File Include Vulnerability
       82. Retired - CzarNews Headlines.PHP Remote File Include Vulnerability
       83. TikiWiki Multiple Input Validation Vulnerabilities
       84. Microsoft Excel Unspecified Remote Code Execution Vulnerability
       85. Microsoft Internet Explorer Unspecified OBJECT Tag Memory Corruption Variant Vulnerability
       86. GD Graphics Library Remote Denial of Service Vulnerability
       87. Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
       88. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
       89. FreeType LWFN Files Buffer Overflow Vulnerability
       90. FreeType TTF File Remote Buffer Overflow Vulnerability
       91. FreeType TTF File Remote Denial of Service Vulnerability
       92. Symantec Security Information Manager Authentication Bypass Vulnerability
       93. Cisco VPN3K/ASA WebVPN Clientless Mode Cross-Site Scripting Vulnerability
       94. Microsoft Windows SMB Driver Local Privilege Escalation Vulnerability
       95. Microsoft SMB Driver Local Denial Of Service Vulnerability
       96. 35mmslidegallery Multiple Cross-Site Scripting Vulnerabilities
       97. G-Shout Shoutbox.PHP Remote File Include Vulnerability
       98. PHPSimpleChoose Multiple HTML Injection Vulnerabilities
       99. Simpnews Wap_short_news.PHP Remote File Include Vulnerability
       100. iFusion iFlance Multiple Input Validation Vulnerabilities
III.  SECURITYFOCUS NEWS
       1. Researchers eye machines to analyze malware
       2. Cybersecurity contests go national
       3. Veterans Affairs warns of massive privacy breach
       4. Blue Security folds under spammer's wrath
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Sr. Security Analyst, Cupertino
       2. [SJ-JOB] Sales Representative, Los Angeles
       3. [SJ-JOB] Security Architect, Santa Clara
       4. [SJ-JOB] Security Engineer, Cupertino
       5. [SJ-JOB] Security Consultant, Access to a Major Airport
       6. [SJ-JOB] Sr. Security Analyst, Minneapolis
       7. [SJ-JOB] Security Consultant, South San Francisco
       8. [SJ-JOB] Disaster Recovery Coordinator, Washington D.C.
       9. [SJ-JOB] Sales Representative, Indianapolis
       10. [SJ-JOB] Technical Support Engineer, karachi
       11. [SJ-JOB] Technical Marketing Engineer, Pittsburgh
       12. [SJ-JOB] Sales Representative, Herndon
       13. [SJ-JOB] Application Security Architect, Bangalore
       14. [SJ-JOB] Customer Service, Washington, D.C.
       15. [SJ-JOB] Account Manager, Herndon
       16. [SJ-JOB] Software Engineer, Columbia
       17. [SJ-JOB] Sr. Security Analyst, Austin
       18. [SJ-JOB] Senior Software Engineer, Palo Alto
       19. [SJ-JOB] Security Engineer, New York
       20. [SJ-JOB] Senior Software Engineer, Palo Alto
       21. [SJ-JOB] Sr. Security Analyst, Dallas
       22. [SJ-JOB] Senior Software Engineer, Palo Alto
       23. [SJ-JOB] Security Researcher, Las Vegas
       24. [SJ-JOB] Security System Administrator, Silver Spring
       25. [SJ-JOB] Security System Administrator, Dallas
       26. [SJ-JOB] Information Assurance Analyst, Austin
       27. [SJ-JOB] Quality Assurance, Fredericton
       28. [SJ-JOB] Sr. Security Engineer, Fredericton
       29. [SJ-JOB] Sales Representative, Tampa
       30. [SJ-JOB] Technical Writer, Germantown
       31. [SJ-JOB] Jr. Security Analyst, Chicago
       32. [SJ-JOB] Senior Software Engineer, Fredericton
       33. [SJ-JOB] Training / Awareness Specialist, San Jose
       34. [SJ-JOB] Security Engineer, Beaverton
       35. [SJ-JOB] CSO, Chicago
       36. [SJ-JOB] Senior Software Engineer, Calgary
       37. [SJ-JOB] Threat Analyst, Calgary
       38. [SJ-JOB] Sales Engineer, Herndon
       39. [SJ-JOB] Sales Engineer, Pittsburgh
       40. [SJ-JOB] Management, Herndon
       41. [SJ-JOB] Sales Engineer, San Francisco
       42. [SJ-JOB] Software Engineer, Columbia
       43. [SJ-JOB] Sales Representative, San Francisco
       44. [SJ-JOB] Management, Herndon
V.    INCIDENTS LIST SUMMARY
       1. 0day worm spreading through Yahoo webmail
       2. Website Defacement
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Yahoo Messenger 7.0.0.438 Crash Tested
       2. Black Hat Speakers + 2005 Content on-line
       3. InternetExplorer & Mozilla Firefox Local File Disclosure Vulnerability PoC Exploit (Reported by Symantec)
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Controlling specific USB devices on Windows XP
       2. Logon audit
       3. SecurityFocus Microsoft Newsletter #294
       4. Logon audit
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Retain or restrain access logs?
By Mark Rasch
A recent proposal by the U.S. Department of Justice that would mandate Internet Service Providers to retain certain records represents a dangerous trend of turning private companies into proxies for law enforcement or intelligence agencies against the interests of their clients or customers.
http://www.securityfocus.com/columnists/406


II.  BUGTRAQ SUMMARY
--------------------
1. Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
BugTraq ID: 14721
Remote: Yes
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/14721
Summary:
Apache 2.x mod_ssl is prone to a restriction-bypass vulnerability. This issue presents itself when mod_ssl is configured to be used with the 'SSLVerifyClient' directive. 

This issue allows attackers to bypass security policies to gain access to locations that are configured to be forbidden for clients without a valid client certificate.

2. Apache mod_include Local Buffer Overflow Vulnerability
BugTraq ID: 11471
Remote: No
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/11471
Summary:
The problem presents itself when the affected module attempts to parse mod_include-specific tag values. A failure to properly validate the lengths of user-supplied tag strings before copying them into finite buffers facilitates the overflow. 

A local attacker may leverage this issue to execute arbitrary code on the affected computer with the privileges of the affected Apache server.

3. BoastMachine Vote.PHP Remote File Include Vulnerability
BugTraq ID: 18415
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18415
Summary:
boastMachine is prone to a remote file-include vulnerability.
 
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

4. Microsoft DXImageTransform.Microsoft.Light ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 18303
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18303
Summary:
The DXImageTransform.Microsoft.Light ActiveX control is prone to remote code execution. 

An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

5. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability Variant
BugTraq ID: 18328
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18328
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability that is related to the instantiation of COM objects. This issue results from a design error.

The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution. The affected objects are not intended to be instantiated through Internet Explorer.

This BID is related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability), BID 15061 (Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability), and BID 17453 (Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability). However, this issue affects a different set of COM objects that were not addressed in the previous BIDs.

6. Somery Team.PHP Remote File Include Vulnerability
BugTraq ID: 18412
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18412
Summary:
Somery is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

7. aWebNews Visview.PHP Remote File Include Vulnerability
BugTraq ID: 18406
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18406
Summary:
aWebNews is prone to a remote file-include vulnerability.
 
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

8. Microsoft Windows Malformed ART Image Remote Code Execution Vulnerability
BugTraq ID: 18394
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18394
Summary:
Microsoft Windows is prone to remote code execution when processing malformed AOL ART images. 
This issue is exposed when the malicious images are processed by Internet Explorer or other applications that rely on Internet Explorer to display AOL ART images. If exploited, this vulnerability could let a remote attacker execute arbitrary code in the context of the victim user.

9. Myscrapbook Singlepage.PHP HTML Injection Vulnerability
BugTraq ID: 18398
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18398
Summary:
Myscrapbook is prone to an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application. This may let the attacker steal cookie-based authentication credentials or launch other attacks.

Version 3.1 is reported vulnerable; other versions may also be affected.

10. ISPConfig Multiple Remote File Include Vulnerabilities
BugTraq ID: 18441
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18441
Summary:
ISPConfig is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 2.2.3; other versions may also be vulnerable.

11. PhpBlueDragon CMS Template.PHP Remote File Include Vulnerability
BugTraq ID: 18440
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18440
Summary:
PhpBlueDragon CMS is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 2.9.1 is reported to be vulnerable; other versions may also be affected.

12. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
BugTraq ID: 18439
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18439
Summary:
MySQL is susceptible to a remote denial-of-service vulnerability. This issue is due to a failure of the database server to properly handle unexpected input.

This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.

Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.

Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.

13.  Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18436
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18436
Summary:
Horde is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

14. Content-Builder Multiple Remote File Include Vulnerabilities
BugTraq ID: 18404
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18404
Summary:
Content-Builder is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 0.7.5; other versions may also be vulnerable.

15. DoubleSpeak Multiple Remote File Include Vulnerabilities
BugTraq ID: 18401
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18401
Summary:
DoubleSpeak is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect versions 0.1 and prior; other versions may also be vulnerable.

16. Microsoft JScript Memory Corruption Vulnerability
BugTraq ID: 18359
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18359
Summary:
Microsoft JScript is prone to a remote memory-corruption vulnerability. This issue is due to the software's failure to properly execute certain HTML script content.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the JScript component to render attacker-supplied script code.

Microsoft Internet Explorer and Outlook both use the affected component, allowing attackers to exploit this issue by sending HTML email or by coercing unsuspecting users to visit malicious websites.

17. Microsoft Internet Explorer Multipart HTML File Handling Remote Code Execution Vulnerability
BugTraq ID: 18320
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18320
Summary:
Internet Explorer is prone to remote code execution. 

An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

18. Microsoft Windows TCP/IP Protocol Driver Remote Buffer Overflow Vulnerability
BugTraq ID: 18374
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18374
Summary:
Microsoft Windows is prone to a remote buffer-overflow vulnerability. 

The vulnerability arises in the Microsoft Windows TCP/IP protocol driver when IP Source Routing has been enabled.

A remote attacker may trigger a denial-of-service condition or may execute arbitrary code, leading to a complete compromise.

19. Microsoft Windows RPC Mutual Authentication Service Spoofing Vulnerability
BugTraq ID: 18389
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18389
Summary:
Microsoft Windows is susceptible to a vulnerability in the RPC component, specifically when using the mutual authentication mechanism with the SSL (Secure Socket Layer) protocol.

This issue is due to a flaw in the mutual authentication mechanism that can occur when it attempts to validate the identity of an RPC service. This can allow the attacker to spoof a valid RPC service that victims of the attack may inadvertently access.

Exploitation of this issue could potentially expose the victim to other attacks.

20. Microsoft PowerPoint Malformed Record Remote Code Execution Vulnerability
BugTraq ID: 18382
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18382
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability. The issue is related to how the application processes malformed record data in PowerPoint documents. 

To exploit this issue, an attacker must entice a victim to open a malicious PowerPoint file. If the exploit is successful, the attacker may execute arbitrary code with the privileges of the currently logged-in user.

21. Microsoft Internet Explorer Persistent Modal Dialog Window Address Bar Spoofing Vulnerability
BugTraq ID: 18321
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18321
Summary:
Microsoft Internet Explorer is prone to address-bar spoofing. Attackers may exploit this via a malicious web page to spoof the contents of a page that the victim may trust. This vulnerability may be useful in phishing or other attacks that rely on content spoofing.

22. Microsoft Internet Explorer HTML Decoding Remote Code Execution Vulnerability
BugTraq ID: 18309
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18309
Summary:
Internet Explorer is vulnerable to remote code execution.  

An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

23. Microsoft Internet Explorer CSS Import Cross-Domain Restriction Bypass Vulnerability
BugTraq ID: 15660
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/15660
Summary:
Microsoft Internet Explorer is prone to an issue that allows a violation of the cross-domain security model. 

The vulnerability arises because Internet Explorer fails to properly parse CSS files and facilitates importing of files that are not valid CSS files. 

This allows attackers to access HTML and script code from the remote site that was improperly imported as a CSS file. This site may reside in a domain other than the site that exploits the issue. 
An attacker may exploit this issue to steal sensitive information, which may aid in other attacks.

24. Microsoft Internet Explorer Address Bar Spoofing Vulnerability
BugTraq ID: 17404
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/17404
Summary:
Internet Explorer is prone to address-bar spoofing.

An attacker can exploit this issue to display the URI of a trusted and known site in the address bar, while running an attacker-supplied Macromedia Flash application. This may aid in phishing-style attacks and possibly allow access to properties of the trusted domain.

25. Microsoft Windows GDI WMF Handling Heap Overflow Vulnerability
BugTraq ID: 18322
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18322
Summary:
The Microsoft Windows GDI Graphics Rendering Engine is prone to a heap-overflow vulnerability. This issue is exposed when the component loads a specially crafted WMF (Windows Metafile) image.

If this issue is exploited, a malicious WMF or EMF file could potentially corrupt heap-based memory with attacker-supplied data. This could lead to the execution of arbitrary code and to a complete system compromise.

An attacker could exploit the issue by enticing the victim user to visit a malicious web page that contains the image or to open an email attachment that consists of the image.

This vulnerability is limited to Windows 98/98SE/ME systems.

26. CEScripts Multiple Scripts Cross-Site Scripting Vulnerabilities
BugTraq ID: 18402
Remote: Yes
Last Updated: 2006-06-13
Relevant URL: http://www.securityfocus.com/bid/18402
Summary:
CEScripts scripts are prone to multiple cross-site scripting vulnerabilities because they fail to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

These issues affect CEScripts Car Classifieds, Event Registration(all versions), Fast Menu Restaurant Ordering v1.0, and Home Rental Script (all versions); other scripts may also be vulnerable.

27. Apache HTTP Request Smuggling Vulnerability
BugTraq ID: 14106
Remote: Yes
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/14106
Summary:
Apache is prone to an HTTP-request-smuggling attack. 

A specially crafted request with a 'Transfer-Encoding: chunked' header and a 'Content-Length' header can cause the server to forward a reassembled request with the original 'Content-Length' header. As a result, the malicious request may piggyback on the valid HTTP request. 

This attack may result in cache poisoning, cross-site scripting, session hijacking, and other attacks. 

This issue was originally described in BID 13873 (Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities). Due to the availability of more details and vendor confirmation, the issue is now a new BID.

28. wv2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18437
Remote: Yes
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/18437
Summary:
The wv2 library is susceptible to a remote buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library to parse malicious Microsoft Word files.

Version 0.2.2 of the wv2 library is vulnerable to this issue; other versions may also be affected.

29. LibTIFF tiff2pdf Remote Buffer Overflow Vulnerability
BugTraq ID: 18331
Remote: Yes
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/18331
Summary:
The tiff2pdf utility is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying service to legitimate users.

30. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-06-15
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

31. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 16171
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/16171
Summary:
Multiple remote buffer-overflow vulnerabilities affect Bogofilter. These issues are due to the application's failure to properly handle invalid input sequences and to validate the length of user-supplied strings before copying them into static process buffers. 

An attacker may exploit these issue to cause a denial-of-service condition or possibly to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation. 

Note that successful exploitation requires that Bogofilter be used with a Unicode database.

32. Squirrelmail Redirect.PHP Local File Include Vulnerability
BugTraq ID: 18231
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18231
Summary:
Squirrelmail is prone to a local file-include vulnerability. This is due to improper sanitization of  user-supplied input.

A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.

33. W3C Libwww Multiple Vulnerabilities
BugTraq ID: 15035
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/15035
Summary:
W3C Libwww is prone to multiple vulnerabilities. 

These issues include a buffer-overflow vulnerability and some issues related to the handling of multipart/byteranges content. 

Libwww 5.4.0 is reported to be vulnerable. Other versions may be affected as well. These issues may also be exploited through other applications that implement the library.

34. KDE KDM Session Type Symbolic Link Vulnerability
BugTraq ID: 18431
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18431
Summary:
KDM is prone to a vulnerability that may permit symbolic-link attacks when processing the user's session type.

An attacker with local access could potentially exploit this issue to view files and obtain privileged information.

A successful attack would most likely result in the loss of confidentiality and the theft of privileged information.

35. IBM AIX LSMCode Local Privilege Escalation Vulnerability
BugTraq ID: 18114
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18114
Summary:
IBM AIX is susceptible to a local vulnerability in the 'lsmcode' command that allows attackers to execute arbitrary machine code with superuser privileges.

IBM AIX versions 5.1, 5.2, and 5.3 are affected by this issue.

36. DokuWiki Remote PHP Script Code Injection Vulnerability
BugTraq ID: 18289
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18289
Summary:
DokuWiki is prone to a remote PHP code-injection vulnerability. 

An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.

DokuWiki versions 2006-06-04 and prior are vulnerable; other versions may also be affected.

37. Asterisk IAX2 Remote Buffer Overflow Vulnerability
BugTraq ID: 18295
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18295
Summary:
Asterisk is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the server, denying further service to legitimate users.

38. MPlayer Multiple Integer Overflow Vulnerabilities
BugTraq ID: 17295
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17295
Summary:
MPlayer is susceptible to two integer-overflow vulnerabilities. An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may help the attacker gain unauthorized access or escalate privileges.

MPlayer version 1.0.20060329 is affected by these issues; other versions may also be affected.

39. SpamAssassin Vpopmail and Paranoid Switches Remote Command Execution Vulnerability
BugTraq ID: 18290
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18290
Summary:
SpamAssassin is prone to an arbitrary-command-execution vulnerability. This issue is due to an error in the application when processing a specially formatted input message when certain switches are set. 

An attacker can exploit this issue to execute arbitrary comannds on the vulnerable computer with the privileges of the affected application.

40. ISPConfig Session.INC.PHP Remote File Include Vulnerability
BugTraq ID: 17909
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17909
Summary:
ISPConfig is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 2.2.2; other versions may also be affected.

41. PhpBB BBRSS.PHP Remote File Include Vulnerability
BugTraq ID: 18432
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18432
Summary:
The bbrss plugin for PhpBB is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

42. RahnemaCo Page.PHP Remote File Include Vulnerability
BugTraq ID: 18435
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18435
Summary:
RahnemaCo is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

43. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17910
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17910
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.

These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users. 

Note that a valid SCTP endpoint must be listening.

The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.

44. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
BugTraq ID: 17203
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17203
Summary:
The Linux kernel is affected by local memory-disclosure vulnerabilities. These issues are due to the kernel's failure to properly clear previously used kernel memory before returning it to local users.

These issues allow an attacker to read kernel memory and potentially gather information to use in further attacks.

45. Linux Kernel Time_Out_Leases PrintK Local Denial of Service Vulnerability
BugTraq ID: 15627
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/15627
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability. 

Local attackers may trigger this issue by obtaining numerous file-lock leases, which will consume excessive kernel log memory. Once the leases timeout, the event will be logged, and kernel memory will be consumed. 

This issue allows local attackers to consume excessive kernel memory, eventually leading to an out-of-memory condition and a denial of service for legitimate users. 

Kernel versions prior to 2.6.15-rc3 are vulnerable to this issue.

46. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.

These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users. 

The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.

47. Linux Kernel Shared Memory Security Restriction Bypass Vulnerability
BugTraq ID: 17587
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17587
Summary:
The Linux kernel is prone to a vulnerability regarding access to shared memory.

A local attacker could potentially gain read and write access to shared memory and write access to read-only tmpfs filesystems, bypassing security restrictions.

An attacker can exploit this issue to possibly corrupt applications and their data when the applications use temporary files or shared memory.

48. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 17735
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17735
Summary:
The Linux Kernel is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.

The problem affects chroot inside of an SMB-mounted filesystem ('smbfs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and gain unauthorized access to the filesystem.

49. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
BugTraq ID: 17593
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17593
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'ip_route_input()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.8.

50. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
BugTraq ID: 16993
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/16993
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'die_if_kernel()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.15.6 running on Itanium systems.

51. Linux Kernel RNDIS_Query_Response Remote Buffer Overflow Vulnerability
BugTraq ID: 17831
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17831
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to crash affected computers. Presumably, attackers could execute arbitrary machine code in the context of affected kernels, but this has not been confirmed.

Linux kernel versions in the 2.6 series prior to 2.6.16 are vulnerable to this issue.

52. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is susceptible to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.

This issue allows remote attackers to use affected computers in stealth network port and trust scans.

The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.

53. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
BugTraq ID: 17178
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17178
Summary:
The Linux kernel is susceptible to a local buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.

Linux kernel versions prior to 2.6.16 in the 2.6 series are affected by this issue.

54. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
BugTraq ID: 18113
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18113
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability.

This issue allows local attackers to gain access to potentially sensitive kernel memory, aiding them in further attacks. Failed exploit attempts may crash the kernel, denying service to legitimate users.

This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.

Linux kernel versions prior to 2.6.16.17 in the 2.6 series are affected by this issue.

55. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
BugTraq ID: 16925
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/16925
Summary:
Linux kernel is prone to a denial-of-service vulnerability when processing a malformed ELF file. This issue occurs only on Intel EM64T processors.

Linux kernel versions prior to 2.6.15.5 are affected by this issue.

56. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
BugTraq ID: 17600
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17600
Summary:
Multiple vendors' operating systems are prone to a local information-disclosure vulnerability. This issue is due to a flaw in the operating systems that fail to properly use AMD CPUs.

Local attackers may exploit this vulnerability to gain access to potentially sensitive information regarding other processes executing on affected computers. This may aid attackers in retrieving information regarding cryptographic keys or other sensitive information.

This issue affects Linux and FreeBSD operating systems that use generations 7 and 8 AMD CPUs.

57. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability. 

The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash. 

This issue allows local users to crash the kernel, denying service to legitimate users. 

Kernel versions prior to 2.6.15 are vulnerable to this issue.

58. Linux Kernel PTrace CLONE_THREAD Local Denial of Service Vulnerability
BugTraq ID: 15642
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/15642
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability. 

In instances where a process is created via the 'clone()' system call with the 'CLONE_THREAD' argument ptraced, the kernel fails to properly ensure that the ptracing process is not attempting to trace itself. 

This issue allows local users to crash the kernel, denying service to legitimate users. 

Kernel versions prior to 2.6.14.2 are vulnerable to this issue.

59. KDE ArtsWrapper Local Privilege Escalation Vulnerability
BugTraq ID: 18429
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18429
Summary:
KDE's artswrapper utility is susceptible to a local privilege-escalation vulnerability because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

60. My Photo Scrapbook Multiple Input Validation Vulnerabilities
BugTraq ID: 18418
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18418
Summary:
My Photo Scrapbook is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to compromise the application, access or modify data, steal cookie-based authentication credentials, or exploit vulnerabilities in the underlying database implementation. Other attacks may also be possible.

These issues affect versions 1.0 and prior.

61. IBM DB2 Universal Database Multiple Denial of Service Vulnerabilities
BugTraq ID: 18428
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18428
Summary:
IBM DB2 Universal Database is prone to multiple denial-of-service vulnerabilities. 

An attacker may be able to exploit these issues to cause the database to crash or hang, effectively denying service to legitimate users.

These issues affect DB2 versions prior to 8 FixPak 12 also known as version 8.2 FixPak 5.

62. Confixx FTP_index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18426
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18426
Summary:
Confixx is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

63. Microsoft Word Malformed Object Pointer Remote Code Execution Vulnerability
BugTraq ID: 18037
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18037
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.  The issue arises because Word fails to properly handle malformed object pointers.

Reports indicate that this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious Word document to a user. This issue is being actively exploited in the wild to place a backdoor named Backdoor.Ginwui on targeted computers through a trojan named Trojan.Mdropper.H.

64. Microsoft Exchange Server Outlook Web Access Script Injection Vulnerability
BugTraq ID: 18381
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18381
Summary:
Microsoft Exchange Server Outlook Web Access is prone to a script-injection vulnerability.

A remote attacker can exploit this issue by sending a malicious email message to a vulnerable user.

65. PicoZip Zipinfo.DLL Buffer Overflow Vulnerability
BugTraq ID: 18425
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18425
Summary:
PicoZip is susceptible to a buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. 

This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.

Version 4.0.1 of PicoZip is vulnerable to this issue; prior versions may also be affected.

66. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer. 

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file. 

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

67. Microsoft Windows Routing and Remote Access Unspecified Remote Code Execution Vulnerability
BugTraq ID: 18424
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18424
Summary:
Microsoft Windows Routing and Remote Access is prone to an unspecified remote vulnerability. This issue is reportedly due to an integer-signedness error in the affected component.

This issue likely allows remote attackers to execute arbitrary machine code on affected computers with SYSTEM-level privileges. This facilitates the complete compromise of affected computers.

It is not currently known if remote, anonymous attacks are possible on all affected platforms.

This BID will be updated as further information is disclosed.

68. LibTiff TIFFToRGB Denial of Service Vulnerability
BugTraq ID: 17809
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17809
Summary:
LibTIFF is affected by a denial-of-service vulnerability.

An attacker can exploit this vulnerability to cause a denial of service in applications using the affected library.

69. Zoo Misc.c Buffer Overflow Vulnerability
BugTraq ID: 16790
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/16790
Summary:
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.

An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.

70. LibTiff Multiple Denial of Service Vulnerabilities
BugTraq ID: 17730
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17730
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial of service in applications using the affected library.

71. LibTiff Double Free Memory Corruption Vulnerability
BugTraq ID: 17733
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17733
Summary:
Applications using the LibTIFF library are prone to a double-free vulnerability; a fix is available.

Attackers may be able to exploit this issue to cause denial-of-service conditions in affected applications using a vulnerable version of the library; arbitrary code execution may also be possible.

72. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
BugTraq ID: 18092
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18092
Summary:
PostgreSQL is prone to SQL-injection vulnerabilities. These issues are due to a potential mismatch of multibyte character conversions between PostgreSQL servers and client applications.

A successful exploit could allow an attacker to execute arbitrary SQL statements on affected servers. This may allow the attacker to compromise the targeted computer, access or modify data, or exploit other latent vulnerabilities.

PostgreSQL versions prior to 7.3.15, 7.4.13, 8.0.8, and 8.1.4 are vulnerable to these issues.

73. LibTiff TIFFFetchData Integer Overflow Vulnerability
BugTraq ID: 17732
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17732
Summary:
Applications using the LibTIFF library are prone to an integer-overflow vulnerability.

An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application that uses the affected library. Failed exploit attempts will likely cause denial-of-service conditions.

74. Vixie Cron Crontab File Disclosure Vulnerability
BugTraq ID: 13024
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/13024
Summary:
Vixie cron crontab is reported prone to an information-disclosure vulnerability that may allow local attackers to access users' crontab files. 

Reportedly, this issue arises due to a design error resulting in the insecure creation of a temporary file in the '/tmp' directory. This occurs when crontab is executed with the '-e' option used for editing the current crontab. 

Attackers may leverage this issue to access potentially sensitive data, which they may use to carry out further attacks against a computer. 

Vixie cron 4.1-24_FC3 running on Fedora Core 3 is reported vulnerable. Other versions on different operating systems may be affected as well. 

This issue may be specific to Red Hat operating systems and may be related to BID 1845 (HP-UX crontab /tmp File Vulnerability).

75. Microsoft Windows Media Player Malformed PNG Remote Code Execution Vulnerability
BugTraq ID: 18385
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18385
Summary:
Microsoft Windows Media Player is prone to a remote code-execution vulnerability. This vulnerability is related to handling of malicious PNG images.

PNG images may be embedded in Windows Media Player skin files. Attackers may be able to exploit this issue by causing the application to load a malicious skin file, which could be hosted on an attacker-controlled web page or through email attachments. If successful, an attacker could execute arbitrary code in the context of the affected user.

Microsoft has stated that web-based attack scenarios are not possible with Media Player 7.1 on Windows 2000 SP4 and Media Player XP on Windows XP SP2. However, a victim may still be affected if they manually download and install a malicious skin file on these platforms.

76. Woltlab Burning Board Multiple SQL Injection Vulnerabilities
BugTraq ID: 18423
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18423
Summary:
Woltlab Burning Board is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

77. Microsoft Windows Routing and Remote Access RASMAN Registry Remote Code Execution Vulnerability
BugTraq ID: 18358
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18358
Summary:
Microsoft Windows Routing and Remote Access is prone to a memory-corruption vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied network data before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code on affected computers with SYSTEM-level privileges. This facilitates the complete compromise of affected computers.

Exploiting this issue on Microsoft Windows XP SP2 or Windows Server 2003 requires valid login credentials. Anonymous attacks are possible with Windows 2000 and Windows XP versions prior to SP2.

78. Microsoft Windows Routing and Remote Access Remote Code Execution Vulnerability
BugTraq ID: 18325
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18325
Summary:
Microsoft Windows Routing and Remote Access is prone to a memory-corruption vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied network data before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code on affected computers with SYSTEM-level privileges. This facilitates the complete compromise of affected computers.

Exploiting this issue on Microsoft Windows XP SP2 or Windows Server 2003 requires valid login credentials. Anonymous attacks are possible with Windows 2000 and Windows XP versions prior to SP2.

79. Wheatblog View_Links.PHP Remote File Include Vulnerability
BugTraq ID: 18416
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18416
Summary:
Wheatblog is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Further information from Steven M. Christey reports that this may not be an issue.

80. Hinton Design PHPHG Guestbook Signed.PHP Remote File Include Vulnerability
BugTraq ID: 18413
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18413
Summary:
The phphg Guestbook application is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Further information from Steven M. Christey reports that this may not be an issue.

81. CzarNews Remote File Include Vulnerability
BugTraq ID: 12857
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/12857
Summary:
CzarNews is prone to a remote file-include vulnerability. 

An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access. 

CzarNews 1.13b is reported vulnerable; other versions may be affected as well.

82. Retired - CzarNews Headlines.PHP Remote File Include Vulnerability
BugTraq ID: 18411
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18411
Summary:
CzarNews is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is a duplicate of BID 12857 (CzarNews Remote File Include Vulnerability) and is therefore being retired.

83. TikiWiki Multiple Input Validation Vulnerabilities
BugTraq ID: 18421
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18421
Summary:
TikiWiki is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

84. Microsoft Excel Unspecified Remote Code Execution Vulnerability
BugTraq ID: 18422
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18422
Summary:
Microsoft Excel is prone to an unspecified remote code-execution vulnerability. Insufficient details are currently available to elaborate further.

Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.

Attackers are actively exploiting this vulnerability in targeted attacks and to install malicious software.

This BID will be updated as further information becomes available.

85. Microsoft Internet Explorer Unspecified OBJECT Tag Memory Corruption Variant Vulnerability
BugTraq ID: 17820
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/17820
Summary:
Microsoft Internet Explorer is prone to an unspecified memory-corruption vulnerability.

An attacker could exploit this issue via a malicious web page to potentially execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely crash the affected application.

This issue is reportedly a variant of BID 17658 (Microsoft Internet Explorer Nested OBJECT Tag Memory Corruption Vulnerability). Further details are currently unavailable. This BID will be updated as more information is disclosed.

86. GD Graphics Library Remote Denial of Service Vulnerability
BugTraq ID: 18294
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18294
Summary:
The GD Graphics Library is prone to a denial-of-service vulnerability. Attackers can trigger an infinite-loop condition when the library tries to handle malformed image files.

This issue allows attackers to consume excessive CPU resources on computers that use the affected software. This may deny service to legitimate users.

GD version 2.0.33 is vulnerable to this issue; other versions may also be affected.

87. Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code 
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2

88. GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability
BugTraq ID: 18332
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18332
Summary:
GDM is susceptible to an authentication-bypass vulnerability when users try to access the 'Configure Login Manager' option.

This issue allows local attackers to execute the 'Configure Login Manager' option with superuser privileges without entering valid superuser credentials. This allows them to make unauthorized configuration changes, which in turn grants them administrative access to affected computers, facilitating their complete compromise.

89. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

90. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

91. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.

This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

92. Symantec Security Information Manager Authentication Bypass Vulnerability
BugTraq ID: 18420
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18420
Summary:
Symantec Security Information Manager is prone to a vulnerability that may let malicious users bypass authentication and gain unauthorized access. 

This issue is exposed when the application transforms raw rule definitions into Java code. A malicious user with sufficient access to create rules could exploit the issue by creating a specially crafted rule that will let them gain shell access under another user account.

93. Cisco VPN3K/ASA WebVPN Clientless Mode Cross-Site Scripting Vulnerability
BugTraq ID: 18419
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18419
Summary:
Cisco VPN 3000 Series Concentrators and ASA 5500 Series Adaptive Security Appliances (ASA) are prone to cross-site scripting attacks via the WebVPN Clientless Mode. 

The issue is due to insufficient sanitization of HTML and script code from error messages that are displayed to users. This vulnerability could result in the execution of attacker-supplied HTML and script code in the session of a victim user. In the worst-case scenario, the attacker could gain unauthorized access to the VPN by stealing the WebVPN session cookie.

94. Microsoft Windows SMB Driver Local Privilege Escalation Vulnerability
BugTraq ID: 18356
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18356
Summary:
The Microsoft SMB driver is susceptible to a local privilege-escalation vulnerability. This issue is due to a failure of the affected software to properly bounds-check user-supplied input prior to copying it to insufficiently-sized kernel memory.

A local attacker can exploit this issue to elevate privileges and gain complete control of an affected computer.

95. Microsoft SMB Driver Local Denial Of Service Vulnerability
BugTraq ID: 18357
Remote: No
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18357
Summary:
The Microsoft SMB driver is prone to a local denial-of-service vulnerability.

A local attacker can exploit this issue to create processes that cannot be killed in affected operating systems, potentially denying service to legitimate users and other software on affected computers. This may aid the attacker in further attacks.

96. 35mmslidegallery Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18414
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18414
Summary:
35mmslidegallery is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

These issues affect version 6; other versions may also be vulnerable.

97. G-Shout Shoutbox.PHP Remote File Include Vulnerability
BugTraq ID: 18417
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18417
Summary:
G-Shout is prone to a remote file-include vulnerability.
 
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

98. PHPSimpleChoose Multiple HTML Injection Vulnerabilities
BugTraq ID: 18408
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18408
Summary:
PHPSimpleChoose is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied HTML and script code before using it in dynamically generated content.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application or to control how the site is rendered; other attacks are also possible.

99. Simpnews Wap_short_news.PHP Remote File Include Vulnerability
BugTraq ID: 18410
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18410
Summary:
Simpnews is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Further information from Steven M. Christey reports this may not be an issue.

100. iFusion iFlance Multiple Input Validation Vulnerabilities
BugTraq ID: 18399
Remote: Yes
Last Updated: 2006-06-14
Relevant URL: http://www.securityfocus.com/bid/18399
Summary:
iFlance is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input to the application. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and launch other attacks.

This issue affects version 1.1; other versions may also be vulnerable.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Researchers eye machines to analyze malware
By: Robert Lemos
Automated classification of malicious software could make recognition of threats faster and names more consistent, but researchers cannot agree on what such a system should look like.
http://www.securityfocus.com/news/11395

2. Cybersecurity contests go national
By: Robert Lemos
America's heartland has become an incubator for competitions pitting high-school and college students against teams of hackers in defense of a corporate network.
http://www.securityfocus.com/news/11394

3. Veterans Affairs warns of massive privacy breach
By: Robert Lemos
The records of nearly 26.5 million veterans--including names, social security numbers and dates of birth--were stolen from the home of a federal employee.
http://www.securityfocus.com/news/11393

4. Blue Security folds under spammer's wrath
By: Robert Lemos
Under threat of further attacks on its service and users, an Israeli anti-spam startup decides to shutter its service.

http://www.securityfocus.com/news/11392

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/436854

2. [SJ-JOB] Sales Representative, Los Angeles
http://www.securityfocus.com/archive/77/436857

3. [SJ-JOB] Security Architect, Santa Clara
http://www.securityfocus.com/archive/77/436833

4. [SJ-JOB] Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/436834

5. [SJ-JOB] Security Consultant, Access to a Major Airport
http://www.securityfocus.com/archive/77/436840

6. [SJ-JOB] Sr. Security Analyst, Minneapolis
http://www.securityfocus.com/archive/77/436827

7. [SJ-JOB] Security Consultant, South San Francisco
http://www.securityfocus.com/archive/77/436841

8. [SJ-JOB] Disaster Recovery Coordinator, Washington D.C.
http://www.securityfocus.com/archive/77/436849

9. [SJ-JOB] Sales Representative, Indianapolis
http://www.securityfocus.com/archive/77/436800

10. [SJ-JOB] Technical Support Engineer, karachi
http://www.securityfocus.com/archive/77/436825

11. [SJ-JOB] Technical Marketing Engineer, Pittsburgh
http://www.securityfocus.com/archive/77/436855

12. [SJ-JOB] Sales Representative, Herndon
http://www.securityfocus.com/archive/77/436862

13. [SJ-JOB] Application Security Architect, Bangalore
http://www.securityfocus.com/archive/77/436866

14. [SJ-JOB] Customer Service, Washington, D.C.
http://www.securityfocus.com/archive/77/436869

15. [SJ-JOB] Account Manager, Herndon
http://www.securityfocus.com/archive/77/436798

16. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/436853

17. [SJ-JOB] Sr. Security Analyst, Austin
http://www.securityfocus.com/archive/77/436791

18. [SJ-JOB] Senior Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/436807

19. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/436819

20. [SJ-JOB] Senior Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/436794

21. [SJ-JOB] Sr. Security Analyst, Dallas
http://www.securityfocus.com/archive/77/436806

22. [SJ-JOB] Senior Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/436808

23. [SJ-JOB] Security Researcher, Las Vegas
http://www.securityfocus.com/archive/77/436816

24. [SJ-JOB] Security System Administrator, Silver Spring
http://www.securityfocus.com/archive/77/436822

25. [SJ-JOB] Security System Administrator, Dallas
http://www.securityfocus.com/archive/77/436802

26. [SJ-JOB] Information Assurance Analyst, Austin
http://www.securityfocus.com/archive/77/436821

27. [SJ-JOB] Quality Assurance, Fredericton
http://www.securityfocus.com/archive/77/436754

28. [SJ-JOB] Sr. Security Engineer, Fredericton
http://www.securityfocus.com/archive/77/436759

29. [SJ-JOB] Sales Representative, Tampa
http://www.securityfocus.com/archive/77/436752

30. [SJ-JOB] Technical Writer, Germantown
http://www.securityfocus.com/archive/77/436753

31. [SJ-JOB] Jr. Security Analyst, Chicago
http://www.securityfocus.com/archive/77/436755

32. [SJ-JOB] Senior Software Engineer, Fredericton
http://www.securityfocus.com/archive/77/436758

33. [SJ-JOB] Training / Awareness Specialist, San Jose
http://www.securityfocus.com/archive/77/436750

34. [SJ-JOB] Security Engineer, Beaverton
http://www.securityfocus.com/archive/77/436751

35. [SJ-JOB] CSO, Chicago
http://www.securityfocus.com/archive/77/436756

36. [SJ-JOB] Senior Software Engineer, Calgary
http://www.securityfocus.com/archive/77/436606

37. [SJ-JOB] Threat Analyst, Calgary
http://www.securityfocus.com/archive/77/436641

38. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/436590

39. [SJ-JOB] Sales Engineer, Pittsburgh
http://www.securityfocus.com/archive/77/436634

40. [SJ-JOB] Management, Herndon
http://www.securityfocus.com/archive/77/436555

41. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/436559

42. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/436600

43. [SJ-JOB] Sales Representative, San Francisco
http://www.securityfocus.com/archive/77/436553

44. [SJ-JOB] Management, Herndon
http://www.securityfocus.com/archive/77/436554

V.   INCIDENTS LIST SUMMARY
---------------------------
1. 0day worm spreading through Yahoo webmail
http://www.securityfocus.com/archive/75/436746

2. Website Defacement
http://www.securityfocus.com/archive/75/436335

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Yahoo Messenger 7.0.0.438 Crash Tested
http://www.securityfocus.com/archive/82/437094

2. Black Hat Speakers + 2005 Content on-line
http://www.securityfocus.com/archive/82/437093

3. InternetExplorer & Mozilla Firefox Local File Disclosure Vulnerability PoC Exploit (Reported by Symantec)
http://www.securityfocus.com/archive/82/436876

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Controlling specific USB devices on Windows XP
http://www.securityfocus.com/archive/88/437076

2. Logon audit
http://www.securityfocus.com/archive/88/436536

3. SecurityFocus Microsoft Newsletter #294
http://www.securityfocus.com/archive/88/436524

4. Logon audit
http://www.securityfocus.com/archive/88/436523

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is sponsored by: PortAuthority Technologies

ALERT: What Information Is Leaving Your Organization?
Effective information leak monitoring and prevention is all about ACCURACY. Download the industry's first independent leak prevention accuracy test results validating PortAuthority as having the lowest false positives (<1%). Review the Open Leak Prevention Test Criteria and Test Tool and you be the judge!
Visit http://www.portauthoritytech.com/datasecuritylabs/