SecurityFocus Newsletter #359
Peter Laborge <[email protected]> Tue, 18 Jul 2006 16:04:15 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #359
----------------------------------------
This issue is Sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------
I. FRONT AND CENTER
1. Basic journey of a packet
2. Application-level virtualization for Windows
II. BUGTRAQ SUMMARY
1. FreeType TTF File Remote Denial of Service Vulnerability
2. Zope Docutils Information Disclosure Vulnerability
3. Microsoft ISA Server File Extension Filter Bypass Vulnerability
4. Microsoft Works Spreadsheet Multiple Remote Vulnerabilties
5. Sitemap Sitemap.XML.PHP Remote File Include Vulnerability
6. PHPBB 3 Memberlist.PHP SQL Injection Vulnerability
7. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
8. Subberz Lite UserFunc Remote File Include Vulnerability
9. Horde Application Framework CSV File Upload Code Execution Vulnerability
10. GNU WGet Multiple Remote Vulnerabilities
11. OpenOffice Arbitrary Macro Execution Vulnerability
12. Adobe Reader Multiple Unspecified Security Vulnerabilities
13. Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
14. LibPNG Graphics Library Chunk Error Processing Buffer Overflow Vulnerability
15. IBM Network Appliance Data ONTAP Security Restriction Bypass Vulnerability
16. Calendar Module For Mambo Com_Calendar.PHP Remote File Include Vulnerability
17. Plesk Control Panel File_Manager.PHP Cross-Site Scripting Vulnerability
18. Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
19. VisNetic Mail Server Multiple File Include Vulnerabilities
20. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
21. McAfee EPolicy Orchestrator Framework Service Directory Traversal Vulnerability
22. Apache HTTP Request Smuggling Vulnerability
23. Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
24. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
25. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
26. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
27. Horde Application Framework Input Validation Vulnerabilities
28. FreeType LWFN Files Buffer Overflow Vulnerability
29. FreeType TTF File Remote Buffer Overflow Vulnerability
30. Horde Nag Remote HTML Injection Vulnerabilities
31. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
32. MySQL Server Date_Format Denial Of Service Vulnerability
33. Microsoft Internet Explorer WebViewFolderIcon Denial Of Service Vulnerability
34. Horde Mnemo Remote HTML Injection Vulnerabilities
35. Microsoft Internet Explorer DXImageTransform Properties Denial Of Service Vulnerability
36. Horde Kronolith Multiple HTML Injection Vulnerabilities
37. Horde Turba Multiple HTML Injection Vulnerabilities
38. FlushCMS Class.Rich.PHP Remote File Include Vulnerability
39. UFO2000 SQL Injection Vulnerability
40. Multiple Vendor NIS Server YPSERV Denial Of Service Vulnerability
41. IlohaMail Email Message Remote HTML Injection Vulnerability
42. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
43. Agnitum Outpost Firewall FiltNT.SYS Local Denial of Service Vulnerability
44. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
45. Outpost Firewall PRO Local Privilege Escalation Vulnerability
46. Microsoft Powerpoint Remote Code Execution Vulnerability
47. Samba Internal Data Structures Denial of Service Vulnerability
48. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
49. Linux VServer Project CHRoot Breakout Vulnerability
50. Util-VServer Unknown Linux Capabilities Vulnerability
51. Lavasoft Personal Firewall Local Privilege Escalation Vulnerability
52. Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
53. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
54. Francisco Charrua Photo-Gallery Room.PHP SQL Injection Vulnerability
55. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
56. PHPLDAPAdmin Multiple Input Validation Vulnerabilities
57. Invision Power Board IPSClass.PHP SQL Injection Vulnerability
58. Professional Home Page Tools Guestbook Multiple SQL Injection Vulnerabilities
59. MySQL User-Defined Function Buffer Overflow Vulnerability
60. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
61. Zoho Virtual Office Message HTML Injection Vulnerability
62. Rabox WinLPD Remote Buffer Overflow Vulnerability
63. ListMessenger LM_Path Parameter Remote File Include Vulnerability
64. Asterisk IAX2 Request Flood Remote Denial of Service Vulnerability
65. OpenVMS Unspecified Local Denial of Service Vulnerability
66. IceWarp Web Mail Multiple File Include Vulnerabilities
67. Mercury Messenger Users Directory Information Disclosure Vulnerability
68. Pollxt Module For Mambo Conf.Pollxt.PHP Remote File Include Vulnerability
69. SimpleBoard SBP Parameter Multiple Remote File Include Vulnerabilities
70. Phorum Multiple Input Validation Vulnerabilities
71. Rocks Clusters Local Privilege Escalation Vulnerabilities
72. ExtCalendar ExtCalendar.php Remote File Include Vulnerability
73. OpenOffice Java Applet System Access Vulnerability
74. OpenOffice XML File Format Buffer Overflow Vulnerability
75. Microsoft Powerpoint Multiple Unspecified Vulnerabilities
76. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
77. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
78. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
79. LibWMF WMF File Handling Integer Overflow Vulnerability
80. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
81. Oracle July 2006 Security Update Multiple Vulnerabilities
82. Wireshark Protocol Dissectors Multiple Vulnerabilities
83. VideoDB Component Module For Mambo Xml_Domit_Lite_Include.PHP Remote File Include Vulnerability
84. HTMLArea3 Addon For Mambo Config.Inc.PHP Remote File Include Vulnerability
85. Eskolar CMS Multiple SQL Injection Vulnerabilities
86. LoudMouth Module For Mambo ABBC.Class.PHP Remote File Include Vulnerability
87. RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
88. ExtCalendar For Mambo ExtCalendar.php Remote File Include Vulnerability
89. Mail2Forum Multiple Remote File Include Vulnerabilities
90. UFO2000 Multiple Remote Vulnerabilities
91. OSDate Multiple HTML Injection Vulnerabilities
92. Lotus Notes Mail Recipient Information Disclosure Vulnerability
93. Debian GNU/Linux Rssh Security Bypass Vulnerability
94. Buddy Zone Multiple HTML Injection Vulnerabilities
95. MiniBB Multiple Remote File Include Vulnerabilities
96. Armagetron Advanced Invalid Values Multiple Remote Denial Of Service Vulnerabilities
97. MyBB Client-IP SQL Injection Vulnerability
98. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
99. Symantec Norton Personal Firewall Registry Access Denial of Service Vulnerability
100. Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
III. SECURITYFOCUS NEWS
1. Daily flaws ratchet up disclosure debate
2. Researchers look to predict software flaws
3. AT&T privacy policy overreaches, lawyers say
4. USB drives pose insider threat
IV. SECURITY JOBS LIST SUMMARY
V. INCIDENTS LIST SUMMARY
1. Preliminary CFP:The 2nd International Conference on Availability, Reliability and Security (ARES 07), Vienna, Austria, April 10-13, 2007
2. Suspicious 404's
VI. VULN-DEV RESEARCH LIST SUMMARY
1. RUXCON 2006 Final Call For Papers
2. ToorCon 2006 Call for Papers
3. PacSec 2006 CALL FOR PAPERS (Deadline Aug. 4; Event Nov. 27-30)
4. ms06-025
5. 23rd Chaos Communication Congress 2006: Call for Participation
VII. MICROSOFT FOCUS LIST SUMMARY
1. Questions about File deletion avoidance in Windows platform
2. SecurityFocus Microsoft Newsletter #299
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Basic journey of a packet
By Don Parker
The purpose of this introductory article is to look at basic look at the journey of a packet across the Internet, from packet creation to switches, routers, NAT, and so on. This topic is recommended for those who are new to the networking and security field and may not have a basic understanding of the underlying process.
http://www.securityfocus.com/infocus/1870
2. Application-level virtualization for Windows
By Federico Biancuzzi
Federico Biancuzzi interviews Eyal Dotan, who has developed application-level virtualization software that protects Windows hosts from malware. They discuss the architecture, advantages of this design, performance, and how this method could be applied to servers running Windows or be ported to other OSes.
http://www.securityfocus.com/columnists/410
II. BUGTRAQ SUMMARY
--------------------
1. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.
This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
2. Zope Docutils Information Disclosure Vulnerability
BugTraq ID: 18856
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18856
Summary:
Zope is prone to an information-disclosure vulnerability.
This issue is due to an error in the 'docutils' module when parsing and rendering text.
An attacker can exploit this issue by creating a web page with restructured text to access arbitrary files..
Versions 2.7.0 to 2.9.3 are vulnerable.
3. Microsoft ISA Server File Extension Filter Bypass Vulnerability
BugTraq ID: 18994
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18994
Summary:
Microsoft ISA (Internet Security and Acceleration) Server is prone to a vulnerability that may let users bypass rules for filtering file extensions. Attackers could exploit this vulnerability to bypass administrative policy and to access restricted content on the Internet.
This vulnerability is reported to affect Microsoft ISA Server 2004. Other versions may also be affected.
4. Microsoft Works Spreadsheet Multiple Remote Vulnerabilties
BugTraq ID: 18989
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18989
Summary:
The spreadsheet component of Microsoft Works is prone to multiple remote vulnerabilities, including buffer-overflow and denial-of service issues.
These issues occur because the application fails to handle specifically crafted spreadsheet documents when importing them into Microsoft Works.
These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected application. Attackers may also crash vulnerable applications, denying service to legitimate users.
Microsoft Works version 8.0 is vulnerable to these issues; other versions may also be affected.
5. Sitemap Sitemap.XML.PHP Remote File Include Vulnerability
BugTraq ID: 18991
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18991
Summary:
Sitemap is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Version 2.0 is vulnerable; other versions may also be affected.
6. PHPBB 3 Memberlist.PHP SQL Injection Vulnerability
BugTraq ID: 18969
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18969
Summary:
phpBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
7. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain elevated privileges, which may lead to a complete compromise.
Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be affected as well.
8. Subberz Lite UserFunc Remote File Include Vulnerability
BugTraq ID: 18990
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18990
Summary:
SubberZ[Lite] is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
9. Horde Application Framework CSV File Upload Code Execution Vulnerability
BugTraq ID: 15810
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/15810
Summary:
Horde Application Framework is prone to an arbitrary scriptcode-execution vulnerability when uploading CSV files. The application fails to properly sanitize user-supplied input.
Horde Application Framework 3.0.7 and earlier are affected by this issue.
10. GNU WGet Multiple Remote Vulnerabilities
BugTraq ID: 11871
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/11871
Summary:
Multiple remote vulnerabilities reportedly affect GNU wget. These issues are due to the application's failure to properly sanitize user-supplied input and to properly validate the presence of files before writing to them. The issues include:
- a potential directory-traversal issue
- an arbitrary file-overwriting vulnerability
- a weakness caused by the application's failure to filter potentially malicious characters from server-supplied input.
Via a malicious server, an attacker may exploit these issues to arbitrarily overwrite files within the current directory and potentially outside of it. This may let the attacker corrupt files, cause a denial of service, and possibly launch further attacks against the affected computer. Overwriting of files would take place with the privileges of the user that activates the vulnerable application.
11. OpenOffice Arbitrary Macro Execution Vulnerability
BugTraq ID: 18738
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18738
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows malicious macros to gain read/write privileges to local files on a vulnerable computer.
12. Adobe Reader Multiple Unspecified Security Vulnerabilities
BugTraq ID: 18445
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18445
Summary:
Adobe Reader is susceptible to multiple unspecified security vulnerabilities.
Due to the 'critical' rating given by the vendor, combined with their 'Severity rating system', at least one of these vulnerabilities may be exploited to execute arbitrary machine code in the context of the affected application. This is stated to occur in the Apple Macintosh version of the software.
Other vulnerabilities for the Microsoft Windows version of the software rate a 'low' on the vendor's scale, meaning that the vulnerabilities have minimal impact or are extremely difficult to exploit.
No further details are currently available. This BID will be updated as more information is disclosed.
Versions of Adobe Reader prior to 7.0.8 are vulnerable to these issues.
13. Horde Application Framework Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18436
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18436
Summary:
Horde is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
14. LibPNG Graphics Library Chunk Error Processing Buffer Overflow Vulnerability
BugTraq ID: 18698
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18698
Summary:
LibPNG is reported prone to a buffer-overflow vulnerability. The library fails to perform proper bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer.
This vulnerability may be exploited to execute attacker-supplied code in the context of an application that relies on the affected library.
15. IBM Network Appliance Data ONTAP Security Restriction Bypass Vulnerability
BugTraq ID: 18951
Remote: No
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18951
Summary:
The IBM Data ONTAP operating system is prone to a security-bypass vulnerability that may permit information disclosure.
Little is known with regards to this vulnerability; this BID will be updated when information becomes available.
It is conjectured that attackers may be able to execute SNMP-related commands, allowing them to gain access to potentially sensitive information.
Versions of IBM Data ONTAP in the 7.1 and 7.1.0.1 series, prior to version 7.1.1 are vulnerable to this issue.
16. Calendar Module For Mambo Com_Calendar.PHP Remote File Include Vulnerability
BugTraq ID: 19027
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19027
Summary:
Calendar Module for Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 1.5.7 and prior are affected
17. Plesk Control Panel File_Manager.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19017
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19017
Summary:
Plesk Control Panel is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 8.0.0 and prior are affected.
18. Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
BugTraq ID: 19006
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19006
Summary:
D-Link wired and wireless routers are prone to a buffer-overflow vulnerability. This issue is due because these devices fail to properly bounds-check user-supplied input before copying it to an insufficiently large memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected device.
19. VisNetic Mail Server Multiple File Include Vulnerabilities
BugTraq ID: 19002
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19002
Summary:
VisNetic Mail Server is prone to multiple local file-include vulnerabilities and a remote file includes vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files or local files containing malicious PHP code and execute it in the context of the web server process. This may allow the attacker to compromise the application and access the underlying system.
Version 8.3.5 is vulnerable to this issue; prior versions may also be affected.
20. Mutt BROWSE_GET_NAMESPACE IMAP Namespace Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 18642
Remote: Yes
Last Updated: 2006-07-15
Relevant URL: http://www.securityfocus.com/bid/18642
Summary:
Mutt is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
Mutt version 1.4.2.1 is reported to be vulnerable. Other versions may be affected as well.
21. McAfee EPolicy Orchestrator Framework Service Directory Traversal Vulnerability
BugTraq ID: 18979
Remote: Yes
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/18979
Summary:
The McAfee ePolicy Orchestrator framework service is prone to a directory-traversal vulnerability that can lead to complete system compromise..
The application fails to sanitize user input when accepting POST requests on the '/spipe/pkg' interface. Specifically, the script fails to sanitize input for proper directory and filename, allowing an attacker to conduct a directory-traversal attack that can overwrite existing files or place arbitrary files on a vulnerable computer.
A successful exploit may allow unauthorized remote users to overwrite existing files or place arbitrary files on a vulnerable computer.
22. Apache HTTP Request Smuggling Vulnerability
BugTraq ID: 14106
Remote: Yes
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/14106
Summary:
Apache is prone to an HTTP-request-smuggling attack.
A specially crafted request with a 'Transfer-Encoding: chunked' header and a 'Content-Length' header can cause the server to forward a reassembled request with the original 'Content-Length' header. As a result, the malicious request may piggyback on the valid HTTP request.
This attack may result in cache poisoning, cross-site scripting, session hijacking, and other attacks.
This issue was originally described in BID 13873 (Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities). Due to the availability of more details and vendor confirmation, the issue is now a new BID.
23. Apache Mod_SSL SSLVerifyClient Restriction Bypass Vulnerability
BugTraq ID: 14721
Remote: Yes
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/14721
Summary:
Apache 2.x mod_ssl is prone to a restriction-bypass vulnerability. This issue presents itself when mod_ssl is configured to be used with the 'SSLVerifyClient' directive.
This issue allows attackers to bypass security policies to gain access to locations that are configured to be forbidden for clients without a valid client certificate.
24. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
BugTraq ID: 18113
Remote: No
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/18113
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability.
This issue allows local attackers to gain access to potentially sensitive kernel memory, aiding them in further attacks. Failed exploit attempts may crash the kernel, denying service to legitimate users.
This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.
Linux kernel versions prior to 2.6.16.17 in the 2.6 series are affected by this issue.
25. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
BugTraq ID: 18978
Remote: Yes
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/18978
Summary:
KDE Konqueror is prone to a denial-of-service vulnerability.
This issue is triggered when an attacker convinces a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Konqueror, effectively denying service to legitimate users.
26. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 18057
Remote: No
Last Updated: 2006-07-14
Relevant URL: http://www.securityfocus.com/bid/18057
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability.
This issue arises because the software fails to handle exceptional conditions in a proper manner.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.
27. Horde Application Framework Input Validation Vulnerabilities
BugTraq ID: 15806
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/15806
Summary:
Horde Application Framework is prone to multiple input-validation vulnerabilities. Remote attackers could exploit these vulnerabilities to perform cross-site scripting attacks to execute arbitrary HTML and script code in the browser of a vulnerable user.
Horde Application Framework 3.0.7 and earlier are affected by these issues.
28. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
29. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
30. Horde Nag Remote HTML Injection Vulnerabilities
BugTraq ID: 15804
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/15804
Summary:
Nag is prone to multiple HTML-injection vulnerabilities.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Nag 2.0.3 and prior versions are affected by these issues.
31. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.
This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.27.
32. MySQL Server Date_Format Denial Of Service Vulnerability
BugTraq ID: 19032
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19032
Summary:
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.
33. Microsoft Internet Explorer WebViewFolderIcon Denial Of Service Vulnerability
BugTraq ID: 19030
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19030
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.
This issue is triggered when an attacker convinces a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
34. Horde Mnemo Remote HTML Injection Vulnerabilities
BugTraq ID: 15803
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/15803
Summary:
Mnemo is prone to multiple HTML-injection vulnerabilities.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
Mnemo 2.0.2 and prior versions are affected by these issues.
35. Microsoft Internet Explorer DXImageTransform Properties Denial Of Service Vulnerability
BugTraq ID: 19029
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19029
Summary:
Internet Explorer is prone to a denial-of-service vulnerability.
An attacker can exploit this vulnerability to crash Internet Explorer and deny service to users.
Internet Explorer 6 SP2 is prone to this issue; other versions may also be vulnerable.
36. Horde Kronolith Multiple HTML Injection Vulnerabilities
BugTraq ID: 15808
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/15808
Summary:
Kronolith is prone to multiple HTML-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
37. Horde Turba Multiple HTML Injection Vulnerabilities
BugTraq ID: 15802
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/15802
Summary:
Turba is prone to multiple HTML-injection vulnerabilities because the application fails to properly validate user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing attackers to steal cookie-based authentication credentials. An attacker could also exploit these issues to control how the site is rendered to the user; other attacks are also possible.
38. FlushCMS Class.Rich.PHP Remote File Include Vulnerability
BugTraq ID: 19023
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19023
Summary:
FlushCMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
The vulnerability has been reported in version 1.0.0-pre2; other versions may also be affected.
39. UFO2000 SQL Injection Vulnerability
BugTraq ID: 19028
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19028
Summary:
UFO2000 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
40. Multiple Vendor NIS Server YPSERV Denial Of Service Vulnerability
BugTraq ID: 8031
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/8031
Summary:
A vulnerability has been reported for ypserv that may result in a denial of service when certain TCP packets are processed.
41. IlohaMail Email Message Remote HTML Injection Vulnerability
BugTraq ID: 13175
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/13175
Summary:
IlohaMail is affected by an HTML-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
42. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19025
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19025
Summary:
A buffer-overflow vulnerability occurs in the DUMB application. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.
43. Agnitum Outpost Firewall FiltNT.SYS Local Denial of Service Vulnerability
BugTraq ID: 19026
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19026
Summary:
Outpost Firewall is prone to a local denial-of-service vulnerability.
An attacker can exploit this issue to crash the application, effectively denying service.
Outpost Firewall Pro version 3.5.631 is affected by this issue; other versions may also be vulnerable.
44. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.
These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1
45. Outpost Firewall PRO Local Privilege Escalation Vulnerability
BugTraq ID: 19024
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19024
Summary:
Outpost Firewall PRO will allow local attackers to gain elevated privileges, which may lead to a complete compromise.
Version 3.51.759.6511 (462) is reported vulnerable. Other versions may be affected as well.
46. Microsoft Powerpoint Remote Code Execution Vulnerability
BugTraq ID: 18957
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18957
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.
A malicious code named 'Trojan.PPDropper.B' is actively exploiting this vulnerability.
This issue affects PowerPoint 2003; other versions may also be vulnerable.
47. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.
This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.
48. MySQL Server Str_To_Date Remote Denial Of Service Vulnerability
BugTraq ID: 18439
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18439
Summary:
MySQL is susceptible to a remote denial-of-service vulnerability. This issue is due to the database server's failure to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.
49. Linux VServer Project CHRoot Breakout Vulnerability
BugTraq ID: 9596
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/9596
Summary:
VServer is reported prone to a breakout vulnerability that allows a malicious user to escape from the context of the chrooted root directory of the virtual server. This issue is due to the VServer application failing to secure itself against a "chroot-again" style vulnerability. Successful exploitation of this issue may allow an attacker to gain access to the filesystem outside of the chrooted root directory.
50. Util-VServer Unknown Linux Capabilities Vulnerability
BugTraq ID: 17180
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/17180
Summary:
The util-vserver package for the Linux-VServer project is susceptible to an unknown Linux capability vulnerability. The package fails to properly handle unknown Linux capabilities.
The exact consequences of this issue are currently unknown. They depend on the nature of the unknown capabilities and on the nature of the applications that use them. Hosted virtual servers may possibly gain inappropriate access to the hosting operating system.
51. Lavasoft Personal Firewall Local Privilege Escalation Vulnerability
BugTraq ID: 19018
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19018
Summary:
Lavasoft Personal Firewall will allow local attackers to gain elevated privileges, which may lead to a complete compromise.
Version 1.0.543.5722 (433) is reported vulnerable. Other versions may be affected as well.
52. Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
BugTraq ID: 19013
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19013
Summary:
Internet Explorer is prone to a denial-of-service vulnerability.
The problem occurs when the application is used to view a malicious URI or webpage consisting of a malformed MHTMLfile element.
An attacker can exploit this issue to crash Internet Explorer and deny service to the user.
Internet Explorer 6 SP2 is vulnerable to this issue; other versions may also be vulnerable.
53. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
BugTraq ID: 18604
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18604
Summary:
NSS is susceptible to a remote denial-of-service vulnerability. This issue is due to a memory leak in the library.
This issue allows remote attackers to consume excessive memory resources on affected computers. This may lead to computer hangs or panics, denying service to legitimate users.
NSS version 3.11 is affected by this issue.
54. Francisco Charrua Photo-Gallery Room.PHP SQL Injection Vulnerability
BugTraq ID: 19020
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19020
Summary:
Photo-Gallery is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Photo-Gallery version 1.0 is vulnerable to this issue; other versions may also be affected.
55. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is susceptible to a local privilege-escalation vulnerability. This issue is due to a race-condition in the 'proc' filesystem.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
The 2.6 series of the Linux kernel is vulnerable to this issue.
56. PHPLDAPAdmin Multiple Input Validation Vulnerabilities
BugTraq ID: 17643
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/17643
Summary:
PHPLDAPAdmin is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
57. Invision Power Board IPSClass.PHP SQL Injection Vulnerability
BugTraq ID: 18984
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18984
Summary:
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
58. Professional Home Page Tools Guestbook Multiple SQL Injection Vulnerabilities
BugTraq ID: 19019
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19019
Summary:
Professional PHP Tools Guestbook is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
59. MySQL User-Defined Function Buffer Overflow Vulnerability
BugTraq ID: 14509
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/14509
Summary:
MySQL is prone to a buffer-overflow vulnerability. The application fails to perform sufficient boundary checks on data supplied as an argument in a user-defined function.
A database user with sufficient access to create a user-defined function can exploit this issue. Attackers may also be able to exploit this issue through latent SQL-injection vulnerabilities in third-party applications that use the database as a backend.
Successful exploitation will result in the execution of arbitrary code in the context of the database server process.
60. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 17439
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/17439
Summary:
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.
These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, when the 'safe_mode' and 'open_basedir' restrictions are expected to isolate the users from each other.
These issues are reported to affect PHP versions 4.4.2 and 5.1.2; other versions may also be vulnerable.
61. Zoho Virtual Office Message HTML Injection Vulnerability
BugTraq ID: 19016
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19016
Summary:
Zoho Virtual Office is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects version 3.2 Build 3210; other versions may also be vulnerable.
62. Rabox WinLPD Remote Buffer Overflow Vulnerability
BugTraq ID: 19011
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19011
Summary:
Winlpd is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable application. Since this application listens on TCP port 515, it requires elevated privileges. Successfully exploiting this issue, therefore, likely facilitates the complete compromise of affected computers.
Winlpd version 1.2, build 1076 is vulnerable to this issue; other versions may also be affected.
63. ListMessenger LM_Path Parameter Remote File Include Vulnerability
BugTraq ID: 19014
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19014
Summary:
ListMessenger is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.9.3; other versions may also be vulnerable.
64. Asterisk IAX2 Request Flood Remote Denial of Service Vulnerability
BugTraq ID: 19009
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19009
Summary:
Asterisk is prone to a remote denial-of-service vulnerability because it fails to efficiently handle numerous remote requests.
This issue allows remote attackers to consume excessive CPU resources, denying service to legitimate users. The software will become unresponsive to further calls.
Asterisk versions prior to 1.2.10 are vulnerable to this issue.
65. OpenVMS Unspecified Local Denial of Service Vulnerability
BugTraq ID: 19008
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19008
Summary:
OpenVMS is prone to an unspecified local denial-of-service vulnerability.
A local unprivileged attacker can exploit this vulnerability to cause system crashes, denying service to legitimate users.
Very little information is currently available about this vulnerability; this BID will be updated as more information becomes available.
66. IceWarp Web Mail Multiple File Include Vulnerabilities
BugTraq ID: 19007
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19007
Summary:
IceWarp Web Mail is prone to multiple local file-include vulnerabilities and a remote file-include vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files or local files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and access the underlying system.
67. Mercury Messenger Users Directory Information Disclosure Vulnerability
BugTraq ID: 19005
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19005
Summary:
Mercury Messenger is prone to an information-disclosure vulnerability.
This issue is due to an error in the '/Users' directory of the application.
An attacker can exploit this issue by navigating to the affected directory and accessing arbitrary files.
This will lead to the disclosure of sensitive information that the attacker may use in other attacks.
68. Pollxt Module For Mambo Conf.Pollxt.PHP Remote File Include Vulnerability
BugTraq ID: 19037
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19037
Summary:
pollxt Module for Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 1.22.07 and prior are affected.
69. SimpleBoard SBP Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 18917
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18917
Summary:
SimpleBoard is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Update (Junly 14, 2006): Reports indicate that a worm named 'Perl.Raumoni' is known to be exploiting these issues in the wild.
70. Phorum Multiple Input Validation Vulnerabilities
BugTraq ID: 18941
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18941
Summary:
Phorum is prone to a cross-site scripting issue and an SQL-injection issue because the application fails to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Vendor reports indicate that the SQL-injection issue can only result in error messages rather than arbitrary SQL statement execution.
71. Rocks Clusters Local Privilege Escalation Vulnerabilities
BugTraq ID: 19003
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19003
Summary:
Rocks Clusters is prone to multiple local privilege-escalation vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input..
These issues allow local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
Rocks Clusters versions 4.1 and prior are vulnerable to these issues.
72. ExtCalendar ExtCalendar.php Remote File Include Vulnerability
BugTraq ID: 18876
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18876
Summary:
ExtCalendar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 2.0 is vulnerable to this issue; prior versions may also be affected.
73. OpenOffice Java Applet System Access Vulnerability
BugTraq ID: 18737
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18737
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows malicious Java applets to gain read/write privileges to local files on a vulnerable computer.
74. OpenOffice XML File Format Buffer Overflow Vulnerability
BugTraq ID: 18739
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18739
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows malicious XML documents to cause a buffer overflow leading to read/write privileges to local files on a vulnerable computer.
75. Microsoft Powerpoint Multiple Unspecified Vulnerabilities
BugTraq ID: 18993
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18993
Summary:
Microsoft PowerPoint is prone to multiple remote vulnerabilities.
Three proof-of-concept exploit files designed to trigger vulnerabilities in PowerPoint have been released.
It is currently unknown if these three exploit files pertain to newly discovered, unpublished vulnerabilities or if they exploit previously disclosed issues. These issues may allow remote attackers to cause crashes or to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
This BID will be updated and potentially split into individual records as further analysis is completed.
Microsoft PowerPoint 2003 is vulnerable to these issues; other versions may also be affected.
76. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
BugTraq ID: 18874
Remote: No
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18874
Summary:
Linux kernel is prone to a local privilege-escalation vulnerability.
A local attacker may gain elevated privileges by creating a coredump file in a directory that they do not have write access to.
A successful attack may result in a complete compromise.
Linux kernel versions prior to 2.6.17.4 are vulnerable.
77. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
BugTraq ID: 18877
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18877
Summary:
Gimp is prone to a buffer-overflow vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.
An attacker may cause malicious code to execute by forcing the application to read raw data from a malicious image file, with the privileges of the user running the GIMP application.
78. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
BugTraq ID: 14759
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/14759
Summary:
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.
This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.
79. LibWMF WMF File Handling Integer Overflow Vulnerability
BugTraq ID: 18751
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18751
Summary:
Applications using the libwmf library are prone to an integer-overflow vulnerability.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application that uses the affected library. Failed exploit attempts will likely cause denial-of-service conditions.
80. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.
81. Oracle July 2006 Security Update Multiple Vulnerabilities
BugTraq ID: 19054
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19054
Summary:
Various Oracle applications including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Pharmaceutical Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
Oracle has released a Critical Patch Update advisory for July 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well.
These issues will be split into individual records once further information has been disclosed.
82. Wireshark Protocol Dissectors Multiple Vulnerabilities
BugTraq ID: 19051
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19051
Summary:
Wireshark is prone to multiple vulnerabilities:
- A format string vulnerability.
- An off-by-one vulnerability.
- An infinite loop vulnerability.
- A memory allocation vulnerability.
These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.
83. VideoDB Component Module For Mambo Xml_Domit_Lite_Include.PHP Remote File Include Vulnerability
BugTraq ID: 19049
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19049
Summary:
VideoDB Component module For Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.3en and prior.
84. HTMLArea3 Addon For Mambo Config.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 19047
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19047
Summary:
HTMLArea3 addon for Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Versions 0.3en and prior are vulnerable to this issue.
85. Eskolar CMS Multiple SQL Injection Vulnerabilities
BugTraq ID: 19045
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19045
Summary:
Eskolar CMS is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
86. LoudMouth Module For Mambo ABBC.Class.PHP Remote File Include Vulnerability
BugTraq ID: 19044
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19044
Summary:
LoudMouth for Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 4.0j; other versions may also be affected.
87. RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
BugTraq ID: 19043
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19043
Summary:
WinRAR is susceptible to a remote buffer-overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input prior to copying it to an insufficiently-sized memory buffer.
This vulnerability allows attackers to execute arbitrary machine code in the context of the affected application.
Versions of WinRAR from 3.0 to 3.60 beta 6 are vulnerable to this issue.
88. ExtCalendar For Mambo ExtCalendar.php Remote File Include Vulnerability
BugTraq ID: 19042
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19042
Summary:
ExtCalendar for Mambo is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 2.0 and prior are vulnerable to this issue,
89. Mail2Forum Multiple Remote File Include Vulnerabilities
BugTraq ID: 19038
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19038
Summary:
Mail2Forum is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
90. UFO2000 Multiple Remote Vulnerabilities
BugTraq ID: 19035
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19035
Summary:
UFO2000 is affected by multiple remote vulnerabilities. These issues arise when the application handles malicious network data.
A remote attacker may execute arbitrary code to gain unauthorized access, or crash the application, effectively denying service to legitimate users.
Versions SVN 1057 and prior are vulnerable to these issues; other versions may also be affected.
91. OSDate Multiple HTML Injection Vulnerabilities
BugTraq ID: 19034
Remote: Yes
Last Updated: 2006-07-18
Relevant URL: http://www.securityfocus.com/bid/19034
Summary:
osDate is prone to multiple HTML-injection vulnerabilities. These vulnerability exists because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
Version 1.1.7 is vulnerable; other versions may also be affected.
92. Lotus Notes Mail Recipient Information Disclosure Vulnerability
BugTraq ID: 19022
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19022
Summary:
Lotus Notes is prone to an information-disclosure vulnerability.
The problem occurs because the 'SendTo/AltSendTo', 'CopyTo/AltCopyTo', and
'BlindCopyTo/AltBlindCopyTo' fields are not kept in sync when 'reply to all' is used.
This may result in unintended recipients receiving emails. This could result in the disclosure of sensitive information if an email containing sensitive or privileged information is sent to unintended readers.
93. Debian GNU/Linux Rssh Security Bypass Vulnerability
BugTraq ID: 18999
Remote: No
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18999
Summary:
A programming error in the 'util.c' file of the rssh package in Debian GNU/Linux allows rdist and rsync to bypass security.
This vulnerability may facilitate privilege escalation, because the error allows rssh's check for CVS to always succeed. An attacker could use this vulnerability to their advantage and bypass existing security limitations and access controls.
94. Buddy Zone Multiple HTML Injection Vulnerabilities
BugTraq ID: 18759
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18759
Summary:
Buddy Zone is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects version 1.0.1.
95. MiniBB Multiple Remote File Include Vulnerabilities
BugTraq ID: 18998
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18998
Summary:
MiniBB is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and access the underlying system.
96. Armagetron Advanced Invalid Values Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 19015
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/19015
Summary:
Multiple denial of service vulnerabilities affect Armagetron Advanced. These issues are due to a failure of the application to handle malformed network data.
An attacker may leverage these issues to cause a remote denial-of-service condition in affected applications.
97. MyBB Client-IP SQL Injection Vulnerability
BugTraq ID: 18997
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18997
Summary:
MyBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
98. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
99. Symantec Norton Personal Firewall Registry Access Denial of Service Vulnerability
BugTraq ID: 18995
Remote: No
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18995
Summary:
Symantec Norton Personal Firewall is prone to a denial-of-service vulnerability. This issue occurs when a program calls certain API calls for manipulating the Windows Registry on Norton service registry keys. This may crash the affected computer.
The individual who discovered this issue claims to have tested it on Norton Personal Firewall 2006 version 9.1.0.33. Other versions could also be affected.
Symantec is currently investigating this issue. This BID will be updated when further details are available.
100. Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
BugTraq ID: 18996
Remote: No
Last Updated: 2006-07-17
Relevant URL: http://www.securityfocus.com/bid/18996
Summary:
Sunbelt Kerio Personal Firewall is prone to a denial-of-service vulnerability. This issue can occur when a program calls the 'CreateRemoteThread' Windows API call.
Exploitation of this vulnerability could cause the firewall application to crash. This could expose the computer to further attacks.
The individual who discovered this vulnerability claims to have tested it on Sunbelt Kerio Personal Firewall versions 4.3.246 and 4.2.3.912. They were unable to reproduce the vulnerability on version 4.2.3.912, which is an older release. The vulnerable functionality may have been introduced at some point after the 4.2.3.912 release, but this has not been confirmed.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Daily flaws ratchet up disclosure debate
By: Robert Lemos
One researcher's promise to release a browser bug every day during the month of July escalates the debate over the degree of openness that helps security.
http://www.securityfocus.com/news/11400
2. Researchers look to predict software flaws
By: Robert Lemos
Want to know how many flaws will be in your next version? Using historical data, university researchers hope to be able to tell you.
http://www.securityfocus.com/news/11399
3. AT&T privacy policy overreaches, lawyers say
By: Robert Lemos
A recent change to AT&T's privacy policy for broadband and video users has been labeled overbroad by legal experts, and likely will leave the courts or Congress to decide whether the company's practices are standard or sinister.
http://www.securityfocus.com/news/11398
4. USB drives pose insider threat
By: Robert Lemos
Workers are more wary of putting giveaway CDs in their company's computers, but USB flash drives are another story.
http://www.securityfocus.com/news/11397
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
V. INCIDENTS LIST SUMMARY
---------------------------
1. Preliminary CFP:The 2nd International Conference on Availability, Reliability and Security (ARES 07), Vienna, Austria, April 10-13, 2007
http://www.securityfocus.com/archive/75/440076
2. Suspicious 404's
http://www.securityfocus.com/archive/75/439864
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. RUXCON 2006 Final Call For Papers
http://www.securityfocus.com/archive/82/440322
2. ToorCon 2006 Call for Papers
http://www.securityfocus.com/archive/82/440311
3. PacSec 2006 CALL FOR PAPERS (Deadline Aug. 4; Event Nov. 27-30)
http://www.securityfocus.com/archive/82/440310
4. ms06-025
http://www.securityfocus.com/archive/82/440309
5. 23rd Chaos Communication Congress 2006: Call for Participation
http://www.securityfocus.com/archive/82/440308
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Questions about File deletion avoidance in Windows platform
http://www.securityfocus.com/archive/88/440280
2. SecurityFocus Microsoft Newsletter #299
http://www.securityfocus.com/archive/88/439857
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus