SecurityFocus Newsletter #356
Peter Laborge <[email protected]> Tue, 27 Jun 2006 15:58:30 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #356
----------------------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000CY4R
------------------------------------------------------------------
I. FRONT AND CENTER
1. Strider URL Tracer with Typo Patrol
2. Phishing with Rachna Dhamija
II. BUGTRAQ SUMMARY
1. Phorum Read.PHP Cross-Site Scripting Vulnerability
2. Ralf Image Gallery Multiple Input Validation Vulnerabilities
3. ADOdb Tmssql.PHP Cross-Site Scripting Vulnerability
4. UebiMiau Multiple Cross-Site Scripting Vulnerabilities
5. DreamAccount Index.PHP Remote File Include Vulnerability
6. Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
7. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
8. DreamAccount Auth.api.PHP Remote File Include Vulnerability
9. Sun ONE and Sun Java System Application Server Unspecified Cross-Site Scripting Vulnerability
10. BitchX BX_Do_Hook Remote Denial of Service Vulnerability
11. PHPMySMS Gateway.PHP Remote File Include Vulnerability
12. XM Easy Personal FTP Server Remote Denial of Service Vulnerability
13. MailEnable SMTP HELO Command Remote Denial of Service Vulnerability
14. Winged Gallery Thumb.PHP Cross-Site Scripting Vulnerability
15. Cisco Secure ACS Authentication Bypass Vulnerability
16. Custom Dating Biz Multiple Input Validation Vulnerabilities
17. SmartSiteCMS Inc_Foot.PHP Remote File Include Vulnerability
18. Project Eros BBSEngine Multiple Input Validation Vulnerabilities
19. RealVNC Remote Authentication Bypass Vulnerability
20. Dig Config Parameter Cross-Site Scripting Vulnerability
21. YaBB SE Profile.php SQL Injection Vulnerability
22. Infinite Core Technologies ICT INDEX.PHP SQL Injection Vulnerability
23. THoRCMS Functions_cms.PHP Remote File Include Vulnerability
24. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
25. Linux Kernel POSIX-CPU-TIMERS.C Local Denial of Service Vulnerability
26. Linux Kernel Signal_32.C Local Denial of Service Vulnerability
27. Clam AntiVirus FreshClam Remote Buffer Overflow Vulnerability
28. Zorum Multiple SQL Injection Vulnerabilities
29. MF Piadas Admin.PHP Remote File Include Vulnerability
30. Spread Insecure Socket File Creation Denial Of Service Vulnerability
31. H-Sphere Multiple Cross-Site Scripting Vulnerabilities
32. MF Piadas Admin.PHP Cross-Site Scripting Vulnerability
33. FreeType TTF File Remote Denial of Service Vulnerability
34. Lotus Domino SMTP Meeting Request Remote Denial of Service Vulnerability
35. BlueDragon Server Error Page Cross-Site Scripting Vulnerability
36. BlueDragon Server .CFM Files Denial Of Service Vulnerability
37. FreeType TTF File Remote Buffer Overflow Vulnerability
38. FreeType LWFN Files Buffer Overflow Vulnerability
39. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
40. Ubuntu Linux Local Installation Password Disclosure Vulnerability
41. CrisoftRicette Cookbook.PHP Remote File Include Vulnerability
42. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
43. PHP Error_Log Safe_Mode Restriction-Bypass Vulnerability
44. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
45. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
46. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
47. Linux Kernel CIFS CHRoot Security Restriction Bypass Vulnerability
48. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
49. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
50. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
51. Linux Kernel RCU signal handling __group_complete_signal Function Unspecified Vulnerability
52. Linux Kernel RNDIS_Query_Response Remote Buffer Overflow Vulnerability
53. Linux Kernel IP ID Information Disclosure Weakness
54. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
55. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
56. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
57. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
58. Linux Kernel Perfmon.c Local Denial of Service Vulnerability
59. Linux Kernel sys_mbind System Call Local Denial of Service Vulnerability
60. Linux Kernel NFS Client Denial of Service Vulnerability
61. Linux Kernel XFS File System Local Information Disclosure Vulnerability
62. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
63. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
64. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
65. Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
66. Jaws Search Gadget Multiple Input Validation Vulnerabilities
67. ArGoSoft Mail Server POP3 Server Unspecified Remote Buffer Overflow Vulnerability
68. MVNForum Activatemember Cross-Site Scripting Vulnerability
69. Usenet Index.PHP Cross-Site Scripting Vulnerability
70. OpenGuestbook Multiple Input Validation Vulnerabilities
71. Claroline Multiple Unspecified Cross-Site Scripting Vulnerabilities
72. EnergyMech CTCP Notice Denial of Service Vulnerability
73. Hashcash Remote Heap Buffer Overflow Vulnerability
74. MyMail Login.PHP Cross-Site Scripting Vulnerability
75. Anthill Multiple SQL Injection Vulnerabilities
76. CBSMS Mambo Module Mod_CBSMS_Messages.PHP Remote File Include Vulnerability
77. phpQLAdmin Multiple Cross-Site Scripting Vulnerabilities
78. GNU Tar Invalid Headers Buffer Overflow Vulnerability
79. Bee-hive Multiple Remote File Include Vulnerabilities
80. Cpanel Select.HTML Cross-Site Scripting Vulnerability
81. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
82. Mantis Multiple Unspecified Remote Vulnerabilities
83. Mantis View_filters_page.PHP Cross-Site Scripting Vulnerability
84. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
85. eNpaper1 Root_Header.PHP Remote File Include Vulnerability
86. XennoBB Messages.PHP Cross-site Scripting Vulnerability
87. dotProject UI.Class.PHP Cross-Site Scripting Vulnerability
88. cURL / libcURL TFTP URL Parser Buffer Overflow Vulnerability
89. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
90. SiteBar Command.PHP Cross-Site Scripting Vulnerability
91. GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
92. IBM WebSphere Application Server Multiple Remote Vulnerabilities
93. cPanel OnMouseover Cross-Site Scripting Vulnerability
94. Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
95. DeluxeBB CP.PHP SQL Injection Vulnerability
96. GL-SH Deaf Forum Multiple Cross-Site Scripting Vulnerabilities
97. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
98. MPCS Comment.php Cross-Site Scripting Vulnerability
99. Squirrelmail Redirect.PHP Local File Include Vulnerability
100. Chatty Username HTML Injection Vulnerability
III. SECURITYFOCUS NEWS
1. USB drives pose insider threat
2. SCADA industry debates flaw disclosure
3. Researchers eye machines to analyze malware
4. Cybersecurity contests go national
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Sales Engineer, Washington
2. [SJ-JOB] Security Consultant, PA
3. [SJ-JOB] Sr. Security Analyst, Cleveland
4. [SJ-JOB] Sr. Security Analyst, Santa Clara
5. [SJ-JOB] Security Consultant, Atlanta
6. [SJ-JOB] Security Auditor, Atlanta
7. [SJ-JOB] Auditor, Miami
8. [SJ-JOB] Auditor, Detroit
9. [SJ-JOB] Security Auditor, Miami
10. [SJ-JOB] Security Consultant, Miami
11. [SJ-JOB] Security Consultant, NYC
12. [SJ-JOB] Security Auditor, NYC
13. [SJ-JOB] Auditor, NYC
14. [SJ-JOB] Security Consultant, Detroit
15. [SJ-JOB] Security Auditor, Detroit
V. INCIDENTS LIST SUMMARY
1. Excel 0-day FAQ updated with Microsoft advisory information
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Is Windows TCP/IP source routing PoC code available?
2. Suse Linux 10.0 and 10.1 (EIP Overflow Questions)
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #296
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Strider URL Tracer with Typo Patrol
By Tony Bradley, CISSP-ISSAP
This article looks at Microsoft's free Strider URL Tracer with Typo-Patrol to help fight typo-squatters and domain parking abuse. The tool can be used to protect children from seeing inappropriate or explicit sites that they should not see, and for companies or trademark owners to scan and investigate sites that may be typo-squatting their domain(s) so that they can be investigated and/or prosecuted.
http://www.securityfocus.com/infocus/1869
2. Phishing with Rachna Dhamija
By Federico Biancuzzi
Federico Biancuzzi interviews Rachna Dhamija, co-author of the paper "Why Phishing Works" and creator of Dynamic Security Skins. They discuss the human factor, how easy it is to recreate a credible browser window made with images, some new anti-phishing features included in the upcoming version of some popular browsers, and the power of letting a user personalize his interface.
http://www.securityfocus.com/columnists/407
II. BUGTRAQ SUMMARY
--------------------
1. Phorum Read.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18683
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18683
Summary:
Phorum is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Phorum version 5.1.13 is vulnerable; other versions may also be affected.
2. Ralf Image Gallery Multiple Input Validation Vulnerabilities
BugTraq ID: 18548
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18548
Summary:
Ralf Image Gallery is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit the directory-traversal vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the webserver process.
The cross-site scripting vulnerabilities allow an attacker to leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The remote file-include issues allow an attacker to include arbitrary remote files containing malicious PHP code and execute them in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
3. ADOdb Tmssql.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18638
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18638
Summary:
ADOdb is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. These may help the attacker steal cookie-based authentication credentials and launch other attacks.
4. UebiMiau Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18643
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18643
Summary:
UebiMiau is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize input before displaying it to users.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
5. DreamAccount Index.PHP Remote File Include Vulnerability
BugTraq ID: 18579
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18579
Summary:
DreamAccount is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
6. Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
BugTraq ID: 18639
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18639
Summary:
Microsoft Windows Live Messenger is reported prone to a remote denial-of-service vulnerability when handling malformed contact list (.ctt) files.
A successful attack can result in a denial of service condition by crashing the application.
Windows Live Messenger 8.0 is reported to be vulnerable. Other versions may be affected as well.
7. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 18642
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18642
Summary:
Mutt is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
Mutt version 1.4.2.1 is reported to be vulnerable. Other versions may be affected as well.
8. DreamAccount Auth.api.PHP Remote File Include Vulnerability
BugTraq ID: 18636
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18636
Summary:
DreamAccount is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.
Successful exploitation could facilitate unauthorized access; other attacks are also possible.
9. Sun ONE and Sun Java System Application Server Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 18635
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18635
Summary:
Sun One and Sun Java System Application Server are prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
10. BitchX BX_Do_Hook Remote Denial of Service Vulnerability
BugTraq ID: 18634
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18634
Summary:
BitchX is prone to a remote denial-of-service vulnerability because it fails to properly handle excessive data from malicious IRC servers.
This issue allows remote attackers to crash affected IRC clients, denying service to legitimate users. To exploit this issue, attackers must coerce users of affected clients to connect to a malicious server.
BitchX version 1.1-final is vulnerable to this issue; previous versions may also be affected.
11. PHPMySMS Gateway.PHP Remote File Include Vulnerability
BugTraq ID: 18633
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18633
Summary:
phpMySms is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 2.0 of phpMySms is vulnerable to this issue; other versions may also be affected.
12. XM Easy Personal FTP Server Remote Denial of Service Vulnerability
BugTraq ID: 18632
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18632
Summary:
XM Easy Personal FTP Server is prone to a remote denial-of-service vulnerability because it fails to properly handle excessive data.
This issue allows remote attackers to crash affected FTP servers, denying service to legitimate users. Attackers may potentially exploit this issue to execute arbitrary machine code in the context of affected servers, but this has not been confirmed.
XM Easy Personal FTP Server version 5.0.1 is vulnerable to this issue; other versions may also be affected.
13. MailEnable SMTP HELO Command Remote Denial of Service Vulnerability
BugTraq ID: 18630
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18630
Summary:
MailEnable is prone to a remote denial-of-service vulnerability.
This issue allows remote attackers to crash the application, denying further service to legitimate users.
The specific cause of this issue is currently unknown. This BID will be updated as further information is disclosed.
14. Winged Gallery Thumb.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18629
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18629
Summary:
Winged Gallery is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
15. Cisco Secure ACS Authentication Bypass Vulnerability
BugTraq ID: 18621
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18621
Summary:
Cisco Secure ACS is prone to an authentication-bypass vulnerability. This issue is due to the application's failure to properly ensure that remote web-based users are properly authenticated.
This issue allows remote attackers to gain administrative access to the web-based administrative interface of the affected application.
Cisco Secure ACS for Windows versions in the 4.x series were identified as vulnerable to this issue; other versions and platforms may also be affected.
This issue is being tracked by Cisco Bug IDs CSCse26754 and CSCse26719.
16. Custom Dating Biz Multiple Input Validation Vulnerabilities
BugTraq ID: 18626
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18626
Summary:
Custom Dating Biz is prone to multiple input-validation vulnerabilities because it fails to sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
17. SmartSiteCMS Inc_Foot.PHP Remote File Include Vulnerability
BugTraq ID: 18628
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18628
Summary:
SmartSiteCMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
18. Project Eros BBSEngine Multiple Input Validation Vulnerabilities
BugTraq ID: 18627
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18627
Summary:
Project Eros bbsengine is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
19. RealVNC Remote Authentication Bypass Vulnerability
BugTraq ID: 17978
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/17978
Summary:
RealVNC is susceptible to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.
Exploiting this issue allows attackers to gain unauthenticated, remote access to the VNC servers.
RealVNC version 4.1.1 is vulnerable to this issue; other versions may also be affected.
May 25, 2006 - Reports indicate that this issue is being actively exploited in the wild.
20. Dig Config Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 12442
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/12442
Summary:
ht://Dig is reported prone to a cross-site scripting vulnerability. This issue is due to the application's failure to properly sanitize user-supplied URI data before including it in dynamically generated web-page content.
All versions of ht://Dig are considered vulnerable at the moment.
21. YaBB SE Profile.php SQL Injection Vulnerability
BugTraq ID: 18625
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18625
Summary:
YaBB SE is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well
22. Infinite Core Technologies ICT INDEX.PHP SQL Injection Vulnerability
BugTraq ID: 18644
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18644
Summary:
Infinite Core Technologies ICT is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well
23. THoRCMS Functions_cms.PHP Remote File Include Vulnerability
BugTraq ID: 18637
Remote: Yes
Last Updated: 2006-06-25
Relevant URL: http://www.securityfocus.com/bid/18637
Summary:
THoRCMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
24. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
BugTraq ID: 17635
Remote: No
Last Updated: 2006-06-23
Relevant URL: http://www.securityfocus.com/bid/17635
Summary:
GDM is prone to an improper file-permissions vulnerability.
An attacker can exploit this issue to gain access to sensitive or privileged information that may facilitate a complete compromise of the vulnerable computer.
25. Linux Kernel POSIX-CPU-TIMERS.C Local Denial of Service Vulnerability
BugTraq ID: 18615
Remote: No
Last Updated: 2006-06-23
Relevant URL: http://www.securityfocus.com/bid/18615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a race condition arising in 'posix-cpu-timers.c'.
This vulnerability allows local users to crash the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.21.
26. Linux Kernel Signal_32.C Local Denial of Service Vulnerability
BugTraq ID: 18616
Remote: No
Last Updated: 2006-06-23
Relevant URL: http://www.securityfocus.com/bid/18616
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in 'signal_32.c'.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.21.
27. Clam AntiVirus FreshClam Remote Buffer Overflow Vulnerability
BugTraq ID: 17754
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17754
Summary:
ClamAV's freshclam utility is susceptible to a remote buffer-overflow vulnerability. The utility fails to perform sufficient boundary checks in server-supplied HTTP data before copying it to an insufficiently sized memory buffer.
To exploit this issue, attackers must subvert webservers in the ClamAV database server pool. Or, they would perform DNS-based attacks or man-in-the-middle attacks to cause affected freshclam applications to connect to attacker-controlled webservers.
This issue allows remote attackers to execute arbitrary machine code in the context of the freshclam utility. The affected utility may run with superuser privileges, aiding remote attackers in the complete compromise of affected computers.
ClamAV versions 0.88 and 0.88.1 are affected by this issue.
28. Zorum Multiple SQL Injection Vulnerabilities
BugTraq ID: 18681
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18681
Summary:
Zorum is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
29. MF Piadas Admin.PHP Remote File Include Vulnerability
BugTraq ID: 18679
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18679
Summary:
MF Piadas is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
30. Spread Insecure Socket File Creation Denial Of Service Vulnerability
BugTraq ID: 18675
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18675
Summary:
Spread creates temporary files in an insecure manner.
Successful exploits would most likely result in loss of data or a denial of service. Other attacks may also be possible.
31. H-Sphere Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18677
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18677
Summary:
H-Sphere is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 2.5.1 Beta 1; other versions may also be vulnerable.
32. MF Piadas Admin.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18676
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18676
Summary:
MF Piadas is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
33. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.
This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
34. Lotus Domino SMTP Meeting Request Remote Denial of Service Vulnerability
BugTraq ID: 18020
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18020
Summary:
Lotus Domino is prone to a remote denial-of-service vulnerability because it fails to properly handle malformed email.
This issue allows remote attackers to consume excessive CPU resources on affected computers and to block all email delivery until administrators manually remove the malicious message from the mail queue. This will deny further email service to legitimate users.
Restarting the affected service will not clear this problem, because the offending message will remain in the mail queue.
Lotus Domino versions prior to 6.5.4 FP1, 6.5.5, and 7.0 are vulnerable to this issue.
35. BlueDragon Server Error Page Cross-Site Scripting Vulnerability
BugTraq ID: 18623
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18623
Summary:
BlueDragon is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 6.2.1.286; other versions may also be vulnerable.
36. BlueDragon Server .CFM Files Denial Of Service Vulnerability
BugTraq ID: 18624
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18624
Summary:
BlueDragon is prone to a remote denial-of-service vulnerability. This issue is due to the application's failure to efficiently handle malformed GET requests.
An attacker can exploit this issue to cause the service to stop responding, effectively denying service to legitimate users.
This issue affects version 6.2.1.286; other versions may also be vulnerable.
37. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
38. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
39. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
BugTraq ID: 18439
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18439
Summary:
MySQL is susceptible to a remote denial-of-service vulnerability. This issue is due to the database server's failure to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.
40. Ubuntu Linux Local Installation Password Disclosure Vulnerability
BugTraq ID: 17086
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17086
Summary:
Ubuntu Linux is susceptible to a local password-disclosure vulnerability. This issue is due to the installation system improperly storing cleartext passwords in world-readable files.
This issue allows local attackers to gain access to the user account that was created during the initial installation of Ubuntu. Since this user is granted 'sudo' access to the superuser account, this potentially allows local attackers to completely compromise affected computers.
41. CrisoftRicette Cookbook.PHP Remote File Include Vulnerability
BugTraq ID: 18674
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18674
Summary:
CrisoftRicette is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
42. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
BugTraq ID: 18604
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18604
Summary:
NSS is susceptible to a remote denial-of-service vulnerability. This issue is due to a memory leak in the library.
This issue allows remote attackers to consume excessive memory resources on affected computers. This may lead to computer hangs or panics, denying service to legitimate users.
NSS version 3.11 is affected by this issue.
43. PHP Error_Log Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 18645
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18645
Summary:
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' and 'open_basedir' restrictions assumed to isolate the users from each other.
This issue is reported to affect PHP versions 4.4.2 and 5.1.4; other versions may also be vulnerable.
44. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17955
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17955
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel deadlock and infinite recursion, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
45. Linux Kernel Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17910
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17910
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
Note that a valid SCTP endpoint must be listening.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
46. Linux Kernel SMBFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 17735
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17735
Summary:
The Linux Kernel is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.
The problem affects chroot inside of an SMB-mounted filesystem ('smbfs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and gain unauthorized access to the filesystem.
47. Linux Kernel CIFS CHRoot Security Restriction Bypass Vulnerability
BugTraq ID: 17742
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17742
Summary:
The Linux Kernel is prone to a vulnerability that allows attackers to bypass a security restriction. This issue is due to a failure in the kernel to properly sanitize user-supplied data.
The problem affects chroot inside of an SMB-mounted filesystem ('cifs'). A local attacker who is bounded by the chroot can exploit this issue to bypass the chroot restriction and gain unauthorized access to the filesystem.
48. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
49. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
BugTraq ID: 17593
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17593
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'ip_route_input()' function.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.8.
50. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
BugTraq ID: 17587
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17587
Summary:
The Linux kernel is prone to vulnerabilities regarding access to shared memory.
A local attacker could potentially gain read and write access to shared memory and write access to read-only tmpfs filesystems, bypassing security restrictions.
An attacker can exploit these issues to possibly corrupt applications and their data when the applications use temporary files or shared memory.
51. Linux Kernel RCU signal handling __group_complete_signal Function Unspecified Vulnerability
BugTraq ID: 17640
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17640
Summary:
Linux Kernel is prone to a local unspecified vulnerability.
This issue exists in the '__group_complete_signal' function of the RCU signal-handling facility.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more details are available.
52. Linux Kernel RNDIS_Query_Response Remote Buffer Overflow Vulnerability
BugTraq ID: 17831
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17831
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to crash affected computers. Presumably, attackers could execute arbitrary machine code in the context of affected kernels, but this has not been confirmed.
Linux kernel versions in the 2.6 series prior to 2.6.16 are vulnerable to this issue.
53. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is susceptible to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.
This issue allows remote attackers to use affected computers in stealth network port and trust scans.
The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.
54. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
BugTraq ID: 17600
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17600
Summary:
Multiple vendors' operating systems are prone to a local information-disclosure vulnerability. This issue is due to a flaw in the operating systems that fail to properly use AMD CPUs.
Local attackers may exploit this vulnerability to gain access to potentially sensitive information regarding other processes executing on affected computers. This may aid attackers in retrieving information regarding cryptographic keys or other sensitive information.
This issue affects Linux and FreeBSD operating systems that use generations 7 and 8 AMD CPUs.
55. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
BugTraq ID: 17541
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17541
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue arises in Intel EM64T CPUs when returning program control using SYSRET.
This vulnerability allows local users to crash the kernel, denying further service to legitimate users.
56. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
BugTraq ID: 16993
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16993
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'die_if_kernel()' function.
This vulnerability allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.15.6 running on Itanium systems.
57. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
BugTraq ID: 16925
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16925
Summary:
Linux kernel is prone to a denial-of-service vulnerability when processing a malformed ELF file. This issue occurs only on Intel EM64T processors.
Linux kernel versions prior to 2.6.15.5 are affected by this issue.
58. Linux Kernel Perfmon.c Local Denial of Service Vulnerability
BugTraq ID: 17482
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17482
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue arises in 'perfmon.c' on ia64 platforms.
This vulnerability allows local users to crash the kernel, denying further service to legitimate users.
59. Linux Kernel sys_mbind System Call Local Denial of Service Vulnerability
BugTraq ID: 16924
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16924
Summary:
The Linux kernel 'sys_mbind' system call is prone to a local denial-of-service vulnerability. This issue is due to a lack of proper input sanitization in the system call's arguments.
This issue allows local users to panic the kernel, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.15.5.
60. Linux Kernel NFS Client Denial of Service Vulnerability
BugTraq ID: 16922
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16922
Summary:
Linux kernel NFS client is prone to a denial-of-service vulnerability. An unprivileged local user can panic the NFS client and cause it to fail.
This issue was addressed in Linux kernel 2.6.15.5; earlier versions are vulnerable.
61. Linux Kernel XFS File System Local Information Disclosure Vulnerability
BugTraq ID: 16921
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16921
Summary:
The Linux kernel's XFS filesystem is susceptible to a local information-disclosure vulnerablity. This issue is due to a flaw in the filesystem that may result in previously written data being returned to local users.
This issue allows local malicious users to gain access to potentially sensitive data, aiding them in further attacks.
Linux kernel versions prior to 2.6.15.5 are affected by this issue.
62. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
BugTraq ID: 18113
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18113
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability.
This issue allows local attackers to gain access to potentially sensitive kernel memory, aiding them in further attacks. Failed exploit attempts may crash the kernel, denying service to legitimate users.
This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.
Linux kernel versions prior to 2.6.16.17 in the 2.6 series are affected by this issue.
63. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
BugTraq ID: 17078
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17078
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.
This vulnerability affects the ATM module and allows local users to panic the kernel by creating inconsistent reference counts, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.14.
64. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
BugTraq ID: 17178
Remote: No
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17178
Summary:
The Linux kernel is susceptible to a local buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied input before using it in a memory copy operation.
This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.
This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.
Linux kernel versions prior to 2.6.16 in the 2.6 series are affected by this issue.
65. Algorithmic Research PrivateWire Online Registration Remote Buffer Overflow Vulnerability
BugTraq ID: 18647
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18647
Summary:
PrivateWire online registration is prone to a remote buffer-overflow vulnerability.
The application fails to properly check boundary conditions when handling GET requests.
This issue allows attackers to execute arbitrary machine code in the context of the affected application software.
Version 3.7 is vulnerable to this issue; previous versions may also be affected.
66. Jaws Search Gadget Multiple Input Validation Vulnerabilities
BugTraq ID: 18665
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18665
Summary:
Jaws is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, steal cookie-based authentication credentials, or exploit vulnerabilities in the underlying database implementation. Other attacks may also be possible.
67. ArGoSoft Mail Server POP3 Server Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 18668
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18668
Summary:
The ArGoSoft Mail Server POP3 service is prone to a remote buffer-overflow vulnerability.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected service. This service likely executes with SYSTEM-level privileges, so exploiting this issue will facilitate the complete compromise of affected computers.
More information, including affected versions, is not currently available. This BID will be updated as more information is disclosed.
68. MVNForum Activatemember Cross-Site Scripting Vulnerability
BugTraq ID: 18663
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18663
Summary:
mvnForum is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.0 GA; other versions may also be vulnerable.
69. Usenet Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18662
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18662
Summary:
Usenet is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
70. OpenGuestbook Multiple Input Validation Vulnerabilities
BugTraq ID: 18666
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18666
Summary:
OpenGuestbook is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection issues, because the application fails to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
71. Claroline Multiple Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 18667
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18667
Summary:
Claroline is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
72. EnergyMech CTCP Notice Denial of Service Vulnerability
BugTraq ID: 18664
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18664
Summary:
EnergyMech is prone to a denial-of-service vulnerability. Successful exploits will cause the application to crash, effectively denying service.
This issue affects versions prior to 3.0.2.
73. Hashcash Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 18659
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18659
Summary:
A buffer-overflow vulnerability exists in the generic C implementation of Hashcash. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow attackers to execute arbitrary machine code in the context of the affected application. This may facilitate the remote compromise of affected computers.
Hashcash versions prior to 1.21 are vulnerable to this issue.
74. MyMail Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18656
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18656
Summary:
MyMail is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
75. Anthill Multiple SQL Injection Vulnerabilities
BugTraq ID: 18661
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18661
Summary:
Anthill is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
76. CBSMS Mambo Module Mod_CBSMS_Messages.PHP Remote File Include Vulnerability
BugTraq ID: 18660
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18660
Summary:
CBSMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.
77. phpQLAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18658
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18658
Summary:
phpQLAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
78. GNU Tar Invalid Headers Buffer Overflow Vulnerability
BugTraq ID: 16764
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16764
Summary:
GNU Tar is prone to a buffer overflow when handling invalid headers. Successful exploitation could potentially lead to arbitrary code execution, but this has not been confirmed.
Tar versions 1.14 and above are vulnerable.
79. Bee-hive Multiple Remote File Include Vulnerabilities
BugTraq ID: 18654
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18654
Summary:
Bee-hive is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
These issues affect version 1.2; other versions may also be vulnerable.
80. Cpanel Select.HTML Cross-Site Scripting Vulnerability
BugTraq ID: 18655
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18655
Summary:
Cpanel is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 10; other versions may also be vulnerable.
81. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.
82. Mantis Multiple Unspecified Remote Vulnerabilities
BugTraq ID: 16046
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/16046
Summary:
Mantis is prone to multiple remote vulnerabilities.
These issues arise in Mantis versions prior to 0.19.4 and 1.0.0rc4.
These issues can allow attackers to access sensitive information and carry out cross-site scripting, HTML-injection, and SQL-injection attacks, and possibly execute arbitrary PHP script code. Other attacks may be possible as well.
This BID will be updated or split into individual records as further information is disclosed.
83. Mantis View_filters_page.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15842
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/15842
Summary:
Mantis is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
84. Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
BugTraq ID: 17372
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17372
Summary:
Kaffiene is reportedly affected by a remote buffer-overflow vulnerability because the application fails to perform sufficient boundary checks on user-supplied strings before copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
85. eNpaper1 Root_Header.PHP Remote File Include Vulnerability
BugTraq ID: 18649
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18649
Summary:
eNpaper1 is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage this issue to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
86. XennoBB Messages.PHP Cross-site Scripting Vulnerability
BugTraq ID: 18652
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18652
Summary:
XennoBB is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
87. dotProject UI.Class.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18650
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18650
Summary:
dotProject is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
88. cURL / libcURL TFTP URL Parser Buffer Overflow Vulnerability
BugTraq ID: 17154
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/17154
Summary:
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issue occurs when the URL parser handles an excessively long URL string with a TFTP protocol prefix 'tftp://'.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.
89. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
BugTraq ID: 18682
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18682
Summary:
Microsoft Internet Explorer is susceptible to an information disclosure vulnerability. This issue is due to a failure of the application to properly enforce cross-domain policies.
This issue may allow attackers to access arbitrary websites in the context of targeted users browser session. This may allow them to perform actions in web applications with the privileges of exploited users, or to gain access to potentially sensitive information. This may aid them in further attacks.
Microsoft Internet Explorer version 6.0 on Windows XP SP2 is vulnerable to this issue; other versions may also be affected.
90. SiteBar Command.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18680
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18680
Summary:
SiteBar is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
91. GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
BugTraq ID: 18678
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18678
Summary:
GraceNote CDDBControl ActiveX control is prone to a buffer-overflow vulnerability. The software fails to perform sufficient bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer.
Invoking the object from a malicious website or HTML email may trigger the condition. If the vulnerability were successfully exploited, this would corrupt process memory, resulting in arbitrary code execution. Arbitrary code would be executed in the context of the client application using the affected ActiveX control.
92. IBM WebSphere Application Server Multiple Remote Vulnerabilities
BugTraq ID: 18672
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18672
Summary:
IBM WebSphere Application Server is prone to multiple remote vulnerabilities. These include an unspecified vulnerability affecting the Core Console Plugin Module of the administrative console and an information-disclosure issue affecting the Web Container Implementation.
IBM WebSphere Application Server versions prior to 5.1.1 Cumulative Fix 11 for Windows are vulnerable.
93. cPanel OnMouseover Cross-Site Scripting Vulnerability
BugTraq ID: 18671
Remote: Yes
Last Updated: 2006-06-27
Relevant URL: http://www.securityfocus.com/bid/18671
Summary:
cPanel is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help attackers steal cookie-based authentication credentials and launch other attacks.
Successful exploitation may allow an attacker to gain unauthorized access to a cPanel user's account.
94. Qdig Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18653
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18653
Summary:
Qdig is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects version 1.2.9.2; earlier versions may also be vulnerable.
95. DeluxeBB CP.PHP SQL Injection Vulnerability
BugTraq ID: 18648
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18648
Summary:
DeluxeBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
96. GL-SH Deaf Forum Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18651
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18651
Summary:
GL-SH Deaf Forum is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize input before displaying it to users.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
97. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 17310
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/17310
Summary:
Dia is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the affected application to open attacker-supplied malicious XFig files.
98. MPCS Comment.php Cross-Site Scripting Vulnerability
BugTraq ID: 18470
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18470
Summary:
MPCS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
99. Squirrelmail Redirect.PHP Local File Include Vulnerability
BugTraq ID: 18231
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18231
Summary:
Squirrelmail is prone to a local file-include vulnerability. This is due to improper sanitization of user-supplied input.
A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.
100. Chatty Username HTML Injection Vulnerability
BugTraq ID: 18082
Remote: Yes
Last Updated: 2006-06-26
Relevant URL: http://www.securityfocus.com/bid/18082
Summary:
Chatty is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. USB drives pose insider threat
By: Robert Lemos
Workers are more wary of putting giveaway CDs in their company's computers, but USB flash drives are another story.
http://www.securityfocus.com/news/11397
2. SCADA industry debates flaw disclosure
By: Robert Lemos
Vulnerability researchers bring in US-CERT to referee the outing of an infrastructure bug, ruffling feathers as vendors and researchers clash over how disclosure should be handled. Sound familiar?
http://www.securityfocus.com/news/11396
3. Researchers eye machines to analyze malware
By: Robert Lemos
Automated classification of malicious software could make recognition of threats faster and names more consistent, but researchers cannot agree on what such a system should look like.
http://www.securityfocus.com/news/11395
4. Cybersecurity contests go national
By: Robert Lemos
America's heartland has become an incubator for competitions pitting high-school and college students against teams of hackers in defense of a corporate network.
http://www.securityfocus.com/news/11394
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sales Engineer, Washington
http://www.securityfocus.com/archive/77/438505
2. [SJ-JOB] Security Consultant, PA
http://www.securityfocus.com/archive/77/438506
3. [SJ-JOB] Sr. Security Analyst, Cleveland
http://www.securityfocus.com/archive/77/438507
4. [SJ-JOB] Sr. Security Analyst, Santa Clara
http://www.securityfocus.com/archive/77/438504
5. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/438467
6. [SJ-JOB] Security Auditor, Atlanta
http://www.securityfocus.com/archive/77/438470
7. [SJ-JOB] Auditor, Miami
http://www.securityfocus.com/archive/77/438493
8. [SJ-JOB] Auditor, Detroit
http://www.securityfocus.com/archive/77/438488
9. [SJ-JOB] Security Auditor, Miami
http://www.securityfocus.com/archive/77/438490
10. [SJ-JOB] Security Consultant, Miami
http://www.securityfocus.com/archive/77/438491
11. [SJ-JOB] Security Consultant, NYC
http://www.securityfocus.com/archive/77/438492
12. [SJ-JOB] Security Auditor, NYC
http://www.securityfocus.com/archive/77/438485
13. [SJ-JOB] Auditor, NYC
http://www.securityfocus.com/archive/77/438486
14. [SJ-JOB] Security Consultant, Detroit
http://www.securityfocus.com/archive/77/438487
15. [SJ-JOB] Security Auditor, Detroit
http://www.securityfocus.com/archive/77/438489
V. INCIDENTS LIST SUMMARY
---------------------------
1. Excel 0-day FAQ updated with Microsoft advisory information
http://www.securityfocus.com/archive/75/438076
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Is Windows TCP/IP source routing PoC code available?
http://www.securityfocus.com/archive/82/438398
2. Suse Linux 10.0 and 10.1 (EIP Overflow Questions)
http://www.securityfocus.com/archive/82/436453
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #296
http://www.securityfocus.com/archive/88/437908
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000CY4R