SecurityFocus Newsletter #360

Peter Laborge <[email protected]> Tue, 25 Jul 2006 16:02:54 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #360
----------------------------------------

This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. A month of browser bugs
        2. After an Exploit: mitigation and remediation
II.   BUGTRAQ SUMMARY
        1. AGEphone SIP Packet Handling Buffer Overflow Vulnerability
        2. MyBB Usercp.PHP HTML Injection Vulnerability
        3. Hiki Diff Denial Of Service Vulnerability
        4. Sun Solaris SysInfo Local Information Disclosure Vulnerability
        5. Microsoft Internet Explorer Internet.HHCtrl Click Denial Of Service Vulnerability
        6. Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
        7. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
        8. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
        9. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
        10. Chameleon LE Index.PHP Directory Traversal Vulnerability
        11. PHP Live Css_Path Remote File Include Vulnerability
        12. Sun Internet Protocol Implementation Routing Table Bypass Vulnerability
        13. Apache Tomcat Information Disclosure Vulnerability
        14. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
        15. Microsoft Internet Explorer Address Bar Spoofing Vulnerability
        16. MySQL Server Date_Format Denial Of Service Vulnerability
        17. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
        18. Advanced Poll Common.Inc.PHP Remote File Include Vulnerability
        19. GD Graphics Library Remote Denial of Service Vulnerability
        20. GnuPG Detached Signature Verification Bypass Vulnerability
        21. AWStats Remote Arbitrary Command Execution Vulnerability
        22. Farsinews Tiny_mce_gzip.PHP Directory Traversal Vulnerability
        23. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
        24. FreeType TTF File Remote Denial of Service Vulnerability
        25. FreeType TTF File Remote Buffer Overflow Vulnerability
        26. FreeType LWFN Files Buffer Overflow Vulnerability
        27. Microsoft Internet Explorer Native Function Iterator Denial Of Service Vulnerability
        28. PHP Forge Cfg_Racine Remote File Include Vulnerability
        29. Prince Clan Chess Club Include.PCchess.PHP Remote File Include Vulnerability
        30. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
        31. Checkpoint FireWall-1 Webserver Directory Traversal Vulnerability
        32. SQuery LibPath Parameter Multiple Remote File Include Vulnerabilities
        33. Samba Internal Data Structures Denial of Service Vulnerability
        34. Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
        35. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
        36. Squirrelmail Redirect.PHP Local File Include Vulnerability
        37. RETIRED: DoubleSpeak Multiple Remote File Include Vulnerabilities
        38. FBGS PostScript Filter Bypass Vulnerability
        39. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
        40. Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
        41. OpenOffice Arbitrary Macro Execution Vulnerability
        42. Microsoft Windows Remote Denial of Service Vulnerability
        43. Microsoft IIS ASP Remote Code Execution Vulnerability
        44. Multiple RadScript Products Authentication Bypass Vulnerability
        45. Finjan Appliance Plaintext Password Storage Information Disclosure Vulnerability
        46. ActionApps Multiple Remote File Include Vulnerabilities
        47. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
        48. IP Calculator Cross-Site Scripting Vulnerability
        49. Rob Brown Net-Server Perl Module Logging Function Format String Vulnerability
        50. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
        51. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
        52. Siemens SpeedStream Wireless Router Denial of Service Vulnerability
        53. Password Safe Local Insecure Idle Timeout Lock Vulnerability
        54. Wireshark Protocol Dissectors Multiple Vulnerabilities
        55. MusicBox Page Parameter SQL Injection Vulnerability
        56. ExtCalendar ExtCalendar.php Remote File Include Vulnerability
        57. Multiple TippingPoint IPS Malformed Packet Detection Bypass Vulnerability
        58. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
        59. InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
        60. PHP Pro Bid Multiple Input Validation Vulnerabilities
        61. Etomite CMS Rfiles.PHP Arbitrary File Upload Vulnerability
        62. SNews Search_Query Cross-Site Scripting Vulnerability
        63. Game Networking Engine ConsoleStreamBuf.CPP Format String Vulnerability
        64. Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
        65. KDE Desktop Screensaver Lock Activation Failure Vulnerability
        66. PHPSavant Savant2 Multiple Remote File Include Vulnerabilities
        67. Etomite Index.PHP SQL Injection Vulnerability
        68. LinksCaffe Multiple Input Validation Vulnerabilities
        69. Tumbleweed MailGate Email Firewall Multiple LHA Buffer Overflow Vulnerabilities
        70. Opsware NAS Root Password Information Disclosure Vulnerability
        71. MusicBox Multiple Input Validation Vulnerabilities
        72. Lussumo Vanilla RootDirectory Remote File Include Vulnerability
        73. MusicBox Multiple Input Validation Vulnerabilities
        74. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
        75. Quagga Information Disclosure and Route Injection Vulnerabilities
        76. RETIRED: Stud.IP Multiple Remote File Include Vulnerabilities
        77. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
        78. Outpost Firewall PRO Local Privilege Escalation Vulnerability
        79. Oracle July 2006 Security Update Multiple Vulnerabilities
        80. Microsoft Windows Server Driver Mailslot Remote Heap Buffer Overflow Vulnerability
        81. QontentOne CMS Search.PHP Cross-Site Scripting Vulnerability
        82. Moodle Moodle.PHP Remote File Include Vulnerability
        83. X7 Chat Upgradev1.PHP SQL Injection Vulnerability
        84. Intervations FileCopa LIST Command Remote Buffer Overflow Vulnerability
        85. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
        86. MoSpray Component Multiple Remote File Include Vulnerabilities
        87. Warzone Resurrection Multiple Buffer Overflow Vulnerabilities
        88. Fire-Mouse TopList Add.PHP HTML Injection Vulnerability
        89. Micro Guestbook Add.PHP HTML Injection Vulnerability
        90. Freeciv Multiple Remote Denial of Service Vulnerabilities
        91. Cheese Tracker XM Loader Buffer Overflow Vulnerability
        92. Microsoft Internet Explorer NMSA.ASFSourceMediaDescription Stack Overflow Vulnerability
        93. Sendmail Malformed MIME Message Denial Of Service Vulnerability
        94. Microsoft Internet Explorer Multiple Object ListWidth Property Denial Of Service Vulnerability
        95. Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities
        96. Advanced Guestbook Index.PHP Entry Parameter SQL Injection Vulnerability
        97. BLOG:CMS ID Parameter Cross-Site Scripting Vulnerability
        98. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
        99. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
        100. Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
III.  SECURITYFOCUS NEWS
        1. Flaw finders lay siege to Microsoft Office
        2. Daily flaws ratchet up disclosure debate
        3. Researchers look to predict software flaws
        4. AT&T privacy policy overreaches, lawyers say
IV.   SECURITY JOBS LIST SUMMARY
V.    INCIDENTS LIST SUMMARY
        1. New PowerPoint Trojan installs itself as LSP
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Fortigate Bypass
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Co-Hosting SQL with IIS FTP service
        2. SCHANNEL CSP SSL
        3. Free encryption and credential management tools for Windows
        4. SecurityFocus Microsoft Newsletter #300
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. A month of browser bugs
By Scott Granneman
Scott Granneman looks at the virtues and pitfalls of browser fuzzing and the overwhelmingly positive impact it has on the security community.
http://www.securityfocus.com/columnists/411

2. After an Exploit: mitigation and remediation
By Jamie Riden
This article describes a few hardening and alerting methods for Unix servers that help block vectors for various attacks, including two web-based application attacks, DNS issues, and the brute-forcing of SSH passwords. The article then looks at steps to take and lessons learned post-compromise.
http://www.securityfocus.com/infocus/1871


II.  BUGTRAQ SUMMARY
--------------------
1. AGEphone SIP Packet Handling Buffer Overflow Vulnerability
BugTraq ID: 19148
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19148
Summary:
AGEphone is prone to a remote buffer-overflow vulnerability.

Specifically, this issue presents itself when the application handles a malicious SIP (Session Initiation Protocol) packet.

AGEphone versions 1.24 and 1.38.1 are reported vulnerable; other versions may be affected as well.

2. MyBB Usercp.PHP HTML Injection Vulnerability
BugTraq ID: 19141
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19141
Summary:
MyBB is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Version 1.1.6 is vulnerable; other versions may also be affected.

3. Hiki Diff Denial Of Service Vulnerability
BugTraq ID: 18785
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18785
Summary:
Hiki is prone to a denial-of-service vulnerability. This vulnerability exists due to an error when processing a comparison between two pages.

An attacker can exploit this vulnerability to cause the application to stop responding due to excessive use of system resources, denying service to legitimate users.

4. Sun Solaris SysInfo Local Information Disclosure Vulnerability
BugTraq ID: 19104
Remote: No
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19104
Summary:
Sun Solaris is prone to a local information-disclosure vulnerability because the kernel fails to properly ensure that unintended memory is not disclosed to local users.

This issue allows local attackers to gain access to potentially sensitive kernel memory. Information harvested by exploiting this issue may aid attackers in further attacks.

5. Microsoft Internet Explorer Internet.HHCtrl Click Denial Of Service Vulnerability
BugTraq ID: 19109
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19109
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.

This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

6. Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
BugTraq ID: 18923
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18923
Summary:
Microsoft Windows DHCP Client service is prone to a remote code-execution vulnerability because the service fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges on affected computers. This facilitates the complete compromise of affected computers.

7. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 17462
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17462
Summary:
The Microsoft MDAC RDS.Dataspace ActiveX control is vulnerable to remote code execution.  An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

8. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
BugTraq ID: 18056
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18056
Summary:
Cyrus IMAPD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly verify user-supplied input before copying it into a finite-sized buffer.

Successful exploits may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.

Cyrus IMAPD version 2.3.2 is reported to be vulnerable. Other versions may be affected as well.

9. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.

Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.

Sendmail versions prior to 8.13.6 are vulnerable to this issue.

10. Chameleon LE Index.PHP Directory Traversal Vulnerability
BugTraq ID: 19107
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19107
Summary:
Chameleon LE  is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.

Chameleon LE is reported vulnerable; other versions may also be affected.

11. PHP Live Css_Path Remote File Include Vulnerability
BugTraq ID: 19116
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19116
Summary:
PHP Live is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

12. Sun Internet Protocol Implementation Routing Table Bypass Vulnerability
BugTraq ID: 19108
Remote: No
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19108
Summary:
Sun's Internet Protocol implementation is prone to a routing-table-bypass vulnerability. This vulnerability occurs because the kernel fails to secure that network traffic is routed only to addresses configured in the system's routing table.

A successful exploit may allow an attacker to bypass the system's routing-table configuration to redirect traffic to unauthorized addresses. This may allow an attacker to access unauthorized hosts and services by bypassing firewalls.

13. Apache Tomcat Information Disclosure Vulnerability
BugTraq ID: 19106
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19106
Summary:
Apache Tomcat is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to reveal a complete directory listing from any directory. Information obtained may aid in further attacks.

Versions 5.028, 5.5.23, 5.5.9, and 5.5.7 are vulnerable to this issue; other versions of Apache Tomcat 5 may also be affected.

14. Webmin/Usermin Unspecifed Information Disclosure Vulnerability
BugTraq ID: 18744
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18744
Summary:
Webmin and Usermin are prone to an unspecified information-disclosure vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.

An attacker can exploit this issue to retrieve potentially sensitive information.

This issue affects Webmin versions prior to 1.290 and Usermin versions prior to 1.220.

Unconfirmed reports suggest that this issue is the same as the one discussed in BID 18613 (Webmin Remote Directory Traversal Vulnerability). However, the fixes associated with that issue did not completely solve the vulnerability.

15. Microsoft Internet Explorer Address Bar Spoofing Vulnerability
BugTraq ID: 17404
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/17404
Summary:
Internet Explorer is prone to address-bar spoofing.

An attacker can exploit this issue to display the URI of a trusted and known site in the address bar, while running an attacker-supplied Macromedia Flash application. This may aid in phishing-style attacks and possibly allow access to properties of the trusted domain.

16. MySQL Server Date_Format Denial Of Service Vulnerability
BugTraq ID: 19032
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/19032
Summary:
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.

This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.

Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.

Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.

17. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

18. Advanced Poll Common.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 19105
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/19105
Summary:
Advanced Poll is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage this issue to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

Version 2.02 is reported vulnerable; other versions may also be affected.

19. GD Graphics Library Remote Denial of Service Vulnerability
BugTraq ID: 18294
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18294
Summary:
The GD Graphics Library is prone to a denial-of-service vulnerability. Attackers can trigger an infinite-loop condition when the library tries to handle malformed image files.

This issue allows attackers to consume excessive CPU resources on computers that use the affected software. This may deny service to legitimate users.

GD version 2.0.33 is vulnerable to this issue; other versions may also be affected.

20. GnuPG Detached Signature Verification Bypass Vulnerability
BugTraq ID: 16663
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/16663
Summary:
GnuPG is affected by a detached signature verification-bypass vulnerability. This issue is due to the application's failure to properly notify scripts that an invalid detached signature was presented and that the verification process has failed.

This issue allows attackers to bypass the signature-verification process used in some automated scripts. Depending on the use of GnuPG, this may result in a false sense of security, the installation of malicious packages, the execution of attacker-supplied code, or other attacks.

21. AWStats Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 17844
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/17844
Summary:
AWStats is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.

22. Farsinews Tiny_mce_gzip.PHP Directory Traversal Vulnerability
BugTraq ID: 18925
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18925
Summary:
Farsinews is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.

Farsinews 3.0BETA1 is reported vulnerable; other versions may also be affected.

23. HP-UX Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 18057
Remote: No
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18057
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability.

This issue arises because the software fails to handle exceptional conditions in a proper manner.

Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.

24. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.

This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

25. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

26. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-07-21
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

27. Microsoft Internet Explorer Native Function Iterator Denial Of Service Vulnerability
BugTraq ID: 19140
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19140
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability. This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

28. PHP Forge Cfg_Racine Remote File Include Vulnerability
BugTraq ID: 19139
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19139
Summary:
PHP Forge is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Versions 0.3 beta 2 and prior are vulnerable; other versions may also be affected.

29. Prince Clan Chess Club Include.PCchess.PHP Remote File Include Vulnerability
BugTraq ID: 19138
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19138
Summary:
Prince Clan Chess Club for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

30. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability because of a race-condition in the 'proc' filesystem.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

The 2.6 series of the Linux kernel is vulnerable to this issue.

31. Checkpoint FireWall-1 Webserver Directory Traversal Vulnerability
BugTraq ID: 19136
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19136
Summary:
Checkpoint FireWall-1 is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.

R55W HFA3 and prior versions are vulnerable to this issue.

32. SQuery LibPath Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 17434
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/17434
Summary:
SQuery is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 4.5 and prior are affected.

33. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.

This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.

34. Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service Vulnerability
BugTraq ID: 11258
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/11258
Summary:
Multiple vendor implementations of the TCP stack are reported prone to a remote denial-of-service vulnerability.

The issue is reported to present itself due to inefficiencies present when handling fragmented TCP packets.

The discoverer of this issue has dubbed the attack style the "New Dawn attack"; it is a variation of a previously reported attack that was named the "Rose Attack".

A remote attacker may exploit this vulnerability to deny service to an affected computer.

Microsoft Windows 2000/XP, Linux kernel 2.4 tree, and undisclosed Cisco systems are reported prone to this vulnerability; other products may also be affected.

35. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
BugTraq ID: 18874
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18874
Summary:
Linux kernel is prone to a local privilege-escalation vulnerability.

A local attacker may gain elevated privileges by creating a coredump file in a directory that they do not have write access to.

A successful attack may result in a complete compromise.

Linux kernel versions prior to 2.6.17.4 are vulnerable.

36. Squirrelmail Redirect.PHP Local File Include Vulnerability
BugTraq ID: 18231
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18231
Summary:
SquirrelMail is prone to a local file-include vulnerability. This is due to improper sanitization of user-supplied input.

A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.

37. RETIRED: DoubleSpeak Multiple Remote File Include Vulnerabilities
BugTraq ID: 18401
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18401
Summary:
DoubleSpeak is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect versions 0.1 and prior; other versions may also be vulnerable.

This BID has been retired.

38. FBGS PostScript Filter Bypass Vulnerability
BugTraq ID: 19131
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19131
Summary:
The 'fbgs' utility is prone to a filter-bypass vulnerability. This issue occurs because the application fails to filter malicious PostScript commands properly.

An attacker can exploit this issue by deleting user data while displaying a PostScript file.

39. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2

40. Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19134
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19134
Summary:
A buffer-overflow vulnerability occurs in the libmikmod library. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.

Versions 3.2.2 and prior are vulnerable; versions 2.x (which do not support the GT2 file format) are not vulnerable.

41. OpenOffice Arbitrary Macro Execution Vulnerability
BugTraq ID: 18738
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18738
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious macros to gain read/write privileges to local files on a vulnerable computer.

42. Microsoft Windows Remote Denial of Service Vulnerability
BugTraq ID: 19135
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19135
Summary:
Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability. This issue may be due to the operating system's failure to properly handle unexpected network traffic.

This issue may cause affected computers to crash, denying service to legitimate users.

Note that Microsoft has not been able to reproduce this issue. This BID will be updated as further analysis is performed.

43. Microsoft IIS ASP Remote Code Execution Vulnerability
BugTraq ID: 18858
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18858
Summary:
Microsoft Internet Information Server (IIS) is prone to a remote code-execution vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

To exploit this issue, attackers must be able to place and execute malicious ASP pages on computers running the affected ASP server software. This may be an issue in shared-hosting environments.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected webserver software.

44. Multiple RadScript Products Authentication Bypass Vulnerability
BugTraq ID: 19128
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19128
Summary:
Multiple Rad Scripts products are prone to an authentication-bypass vulnerability. These issues occur because the applications fail to prevent an attacker from accessing admin scripts directly without requiring authentication.

A remote attacker can exploit these issues to perform administrative functions without requiring authentication. For example, the attacker may be able to overwrite existing files on the vulnerable computer in the context of the webserver process.

45. Finjan Appliance Plaintext Password Storage Information Disclosure Vulnerability
BugTraq ID: 18940
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18940
Summary:
Finjan Appliance is prone to a vulnerability that may permit information disclosure.

The problem occurs because the device stores username and password pairs in plain text in backup files. A local authenticated attacker could exploit this issue to retrieve the username and password of other users; this may facilitate the disclosure of sensitive information.

46. ActionApps Multiple Remote File Include Vulnerabilities
BugTraq ID: 19133
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19133
Summary:
ActionApps is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 2.8.1; other versions may also be vulnerable.

47. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

48. IP Calculator Cross-Site Scripting Vulnerability
BugTraq ID: 19130
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19130
Summary:
IP Calculator is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 0.40 is vulnerable to this issue; prior versions may also be affected.

49. Rob Brown Net-Server Perl Module Logging Function Format String Vulnerability
BugTraq ID: 13193
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/13193
Summary:
Net-Server API is prone to a remote format-string vulnerability. The issue resides in the 'log' subroutine of the 'Server.pm' module.

This vulnerability may occur when an application uses the 'log' subroutine of the affected module to handle malicious data passed through a network request.

A successful attack may crash the server or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context the server.

50. Mozilla Network Security Services Library Remote Denial of Service Vulnerability
BugTraq ID: 18604
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18604
Summary:
NSS is susceptible to a remote denial-of-service vulnerability. This issue is due to a memory leak in the library.

This issue allows remote attackers to consume excessive memory resources on affected computers. This may lead to computer hangs or panics, denying service to legitimate users.

NSS version 3.11 is affected by this issue.

51. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
BugTraq ID: 18978
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18978
Summary:
KDE Konqueror is prone to a denial-of-service vulnerability.

This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Konqueror, effectively denying service to legitimate users.

52. Siemens SpeedStream Wireless Router Denial of Service Vulnerability
BugTraq ID: 19132
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19132
Summary:
Siemens SpeedStream Wireless Routers are prone to a remote denial-of-service vulnerability.

This may permit an attacker to crash affected devices, denying further network services to legitimate users.

Firmware version 2624 is vulnerable; other versions may also be affected.

53. Password Safe Local Insecure Idle Timeout Lock Vulnerability
BugTraq ID: 19078
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19078
Summary:
Password Safe is prone to a vulnerability that may result in information disclosure. This issue is due to a flaw in the implementation of the inactivity timer, which is designed to lock the database when it is not in use.

This issue may allow local attackers to gain access to the contents of the Password Safe database, since the database-locking feature may not function correctly under certain circumstances.

Versions 2.11, 2.16, and 3.0 beta 1 are vulnerable to this issue. Other versions may also be affected.

54. Wireshark Protocol Dissectors Multiple Vulnerabilities
BugTraq ID: 19051
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19051
Summary:
Wireshark is prone to multiple vulnerabilities:

- A format string vulnerability.
- An off-by-one vulnerability.
- An infinite loop vulnerability.
- A memory allocation vulnerability.

These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.

55. MusicBox Page Parameter SQL Injection Vulnerability
BugTraq ID: 19129
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19129
Summary:
MusicBox is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 2.3.4; earlier versions may also be vulnerable.

56. ExtCalendar ExtCalendar.php Remote File Include Vulnerability
BugTraq ID: 18876
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/18876
Summary:
ExtCalendar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 2.0 is vulnerable to this issue; prior versions may also be affected.

57. Multiple TippingPoint IPS Malformed Packet Detection Bypass Vulnerability
BugTraq ID: 19125
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19125
Summary:
TippingPoint IPSs are prone to a detection-bypass vulnerability because these appliances fail to properly handle malformed network packets.

A successful exploit of this issue may allow an attacker to bypass the filter and detection system of vulnerable appliances, allowing all traffic through without inspection. This will likely aid in further attacks.

Reports indicate that TippingPoint IPSs with TOS version 2.2.3.6514 and prior are vulnerable.

58. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19025
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19025
Summary:
A buffer-overflow vulnerability occurs in the DUMB application. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.

59. InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19143
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19143
Summary:
DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.

These vulnerabilities affect DynaZip Max with DZIP32.DLL version 5.0.0.7 and DynaZip Max Secure with DZIPS32.DLL version 6.0.0.4. Other versions may be vulnerable as well.

TurboZIP version 6.0 Build 002021004 is also affected by the first issue as it uses the DynaZip library.

60. PHP Pro Bid Multiple Input Validation Vulnerabilities
BugTraq ID: 19158
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19158
Summary:
PHP Pro Bid is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

Version 5.24 is vulnerable to this issue; other versions may also be affected.

61. Etomite CMS Rfiles.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 19157
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19157
Summary:
Etomite CMS is prone to an arbitrary file-upload vulnerability.

The issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and to execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system.

62. SNews Search_Query Cross-Site Scripting Vulnerability
BugTraq ID: 19156
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19156
Summary:
sNews is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

63. Game Networking Engine ConsoleStreamBuf.CPP Format String Vulnerability
BugTraq ID: 19154
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19154
Summary:
Game Networking Engine is prone to a remote format-string vulnerability.

This issue arises when the application displays a text string on the client screen during a multiplayer game. The application fails to properly sanitize user-supplied data prior to utilizing it in the format-specification argument of a formatted-printing function.

A successful attack may crash the application or lead to arbitrary code execution within the context of the game server.

Version 0.70, CVS 23 July 2006 and prior are vulnerable to this issue.

64. Intervations FileCopa Directory Arguments Mutiple Buffer Overflow Vulnerabilities
BugTraq ID: 19153
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19153
Summary:
FileCopa is prone to multiple buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.

Successful exploits may allow remote attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.


FileCOPA 1.01 version 2006-07-18 is vulnerable; other versions may also be affected.

65. KDE Desktop Screensaver Lock Activation Failure Vulnerability
BugTraq ID: 19152
Remote: No
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19152
Summary:
The KDE desktop is prone to a vulnerability that can cause the manual locking of the desktop to fail, or stop the screensaver from activating.

These issues could have a security impact if the user depends on the locking mechanism to secure the desktop.

66. PHPSavant Savant2 Multiple Remote File Include Vulnerabilities
BugTraq ID: 19151
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19151
Summary:
Savant2 is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

67. Etomite Index.PHP SQL Injection Vulnerability
BugTraq ID: 19150
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19150
Summary:
Etomite is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Versions 0.6.1 and prior are vulnerable to this issue.

68. LinksCaffe Multiple Input Validation Vulnerabilities
BugTraq ID: 19149
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19149
Summary:
LinksCaffe is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

69. Tumbleweed MailGate Email Firewall Multiple LHA Buffer Overflow Vulnerabilities
BugTraq ID: 19146
Remote: Yes
Last Updated: 2006-07-25
Relevant URL: http://www.securityfocus.com/bid/19146
Summary:
Tumbleweed MailGate Email Firewall is prone to multiple buffer-overflow vulnerabilities in its LHA processing routines.

A successful attack can allow a remote attacker to corrupt process memory by triggering various overflow conditions in the LHA processing engine. This may lead to arbitrary code execution in the context of the MMSDecompose, a process of the EMF Decomposer component, resulting in a full compromise.

These vulnerabilities reportedly affect all versions of the Tumbleweed MailGate Email Firewall.

70. Opsware NAS Root Password Information Disclosure Vulnerability
BugTraq ID: 19126
Remote: No
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19126
Summary:
Opsware NAS is prone to a local information-disclosure vulnerability. This issue occurs because the application fails to protect sensitive information to unprivileged users.

An attacker can exploit this issue by gaining access to the root MySQL account and reveal authentication credentials for network devices. This issue could also lead to other attacks.

Opsware NAS 6.0 is vulnerable to this issue; other versions may also be affected.

71. MusicBox Multiple Input Validation Vulnerabilities
BugTraq ID: 17149
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17149
Summary:
MusicBox is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

72. Lussumo Vanilla RootDirectory Remote File Include Vulnerability
BugTraq ID: 19127
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19127
Summary:
Vanilla is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 1.0.1; earlier versions may also be vulnerable.

73. MusicBox Multiple Input Validation Vulnerabilities
BugTraq ID: 17545
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17545
Summary:
MusicBox is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

74. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
BugTraq ID: 18877
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18877
Summary:
Gimp is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by forcing the application to read raw data from a malicious image file, with the privileges of the user running the GIMP application.

75. Quagga Information Disclosure and Route Injection Vulnerabilities
BugTraq ID: 17808
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17808
Summary:
Quagga is susceptible to remote information-disclosure and route-injection vulnerabilities. The application fails to properly ensure that required authentication and protocol configuration options are enforced.

These issues allow remote attackers to gain access to potentially sensitive network-routing configuration information and to inject arbitrary routes into the RIP routing table. This may aid malicious users in further attacks against targeted networks.

Quagga versions 0.98.5 and 0.99.3 are vulnerable to these issues; other versions may also be affected.

76. RETIRED: Stud.IP Multiple Remote File Include Vulnerabilities
BugTraq ID: 18741
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18741
Summary:
Stud.IP is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

These issues affect version 1.3.0-2; earlier versions may also be vulnerable.

This BID is being retired because of a retraction from [email protected].

77. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
BugTraq ID: 18906
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18906
Summary:
The sipXtapi product is reported to be prone to a remote buffer-overflow vulnerability. This issue presents itself when the application handles a specially crafted 'CSeq' value.

A successful attack may lead to unauthorized remote access in the context of a user running an affected application that uses the vulnerable library.

Reports indicate that sipXtapi versions that were released prior to March 24, 2006 are vulnerable to this issue. Certain PingTel products and versions of AOL Triton may be affected because they employ the vulnerable library.

78. Outpost Firewall PRO Local Privilege Escalation Vulnerability
BugTraq ID: 19024
Remote: No
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19024
Summary:
Outpost Firewall PRO will allow local attackers to gain elevated privileges, which may lead to a complete compromise.

Version 3.51.759.6511 (462) is reported vulnerable. Other versions may be affected as well.

79. Oracle July 2006 Security Update Multiple Vulnerabilities
BugTraq ID: 19054
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19054
Summary:
Various Oracle applications including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Pharmaceutical Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.

Oracle has released a Critical Patch Update advisory for July 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well.

These issues will be split into individual records when more information has been disclosed.

80. Microsoft Windows Server Driver Mailslot Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 18863
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18863
Summary:
Microsoft Windows Server driver is prone to a remote heap buffer-overflow vulnerability. This issue is due to a failure of the software to properly bounds check user-supplied input prior to copying it to an insufficiently-sized memory buffer.

Exploiting this issue allows anonymous, remote attackers to execute arbitrary machine code in the context of the affected driver. This facilitates the complete compromise of affected computers.

Microsoft Windows XP SP2 and Microsoft Windows Server 2003 SP1 are not vulnerable to this issue in their default configuration.

81. QontentOne CMS Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18209
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18209
Summary:
QontentOne CMS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

82. Moodle Moodle.PHP Remote File Include Vulnerability
BugTraq ID: 19124
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19124
Summary:
Moodle for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

83. X7 Chat Upgradev1.PHP SQL Injection Vulnerability
BugTraq ID: 19123
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19123
Summary:
X7 Chat is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Versions 2.0.4 and prior are affected; other versions may also be vulnerable.

84. Intervations FileCopa LIST Command Remote Buffer Overflow Vulnerability
BugTraq ID: 19065
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19065
Summary:
FileCopa is prone to a buffer-overflow vulnerability when handling data through the LIST command.

Reportedly, passing excessive data may overflow a finite-sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data.

This issue may lead to a denial-of-service condition or allow arbitrary code to run.

85. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
BugTraq ID: 17058
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/17058
Summary:
GnuPG is prone to a vulnerability involving incorrect verification of non-detached signatures.

A successful attack can allow an attacker to simply take a signed message, inject arbitrary data into it, and bypass verification.

Note that this issue also affects verification of signatures embedded in encrypted messages. Scripts and applications using gpg are affected, as are applications using the GPGME library.

GnuPG versions prior to 1.4.2.2 are vulnerable to this issue.

86. MoSpray Component Multiple Remote File Include Vulnerabilities
BugTraq ID: 19122
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19122
Summary:
MoSpray is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 1.8 RC1 is vulnerable to these issues; other versions may also be affected.

87. Warzone Resurrection Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19118
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19118
Summary:
Warzone Resurrection is prone to multiple remote buffer-overflow vulnerabilities.

A remote attacker may exploit these issues to corrupt memory and execute arbitrary code on vulnerable systems. Attack attempts may crash the client or server, depending on which vulnerability is targeted.

Versions prior to 2.0.3 and SVN 127 are affected by these issues.

88. Fire-Mouse TopList Add.PHP HTML Injection Vulnerability
BugTraq ID: 19120
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19120
Summary:
Fire-Mouse TopList is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.1; other versions may also be vulnerable.

89. Micro Guestbook Add.PHP HTML Injection Vulnerability
BugTraq ID: 19119
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19119
Summary:
Micro Guestbook is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

90. Freeciv Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 19117
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19117
Summary:
Freeciv server is prone to multiple remote denial-of-service vulnerabilities.

A remote attacker may exploit these issues to deny service to legitimate users by sending malicious packets to a server.

2.1.0-beta1 and prior versions are affected by these issues.

91. Cheese Tracker XM Loader Buffer Overflow Vulnerability
BugTraq ID: 19115
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19115
Summary:
Cheese Tracker is prone to a buffer-overflow vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by supplying a malicious XM file.  This may facilitate unauthorized remote access with the privileges of the user running the vulnerable application.

92. Microsoft Internet Explorer NMSA.ASFSourceMediaDescription Stack Overflow Vulnerability
BugTraq ID: 19114
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19114
Summary:
Microsoft Internet Explorer is prone to a stack-overflow vulnerability.

This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

93. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

94. Microsoft Internet Explorer Multiple Object ListWidth Property Denial Of Service Vulnerability
BugTraq ID: 19113
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19113
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.

This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

95. Advanced Guestbook Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15927
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/15927
Summary:
Advanced Guestbook is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

96. Advanced Guestbook Index.PHP Entry Parameter SQL Injection Vulnerability
BugTraq ID: 13548
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/13548
Summary:
Advanced Guestbook is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue reportedly affects Advanced Guestbook version 2.3.1; other versions may also be vulnerable.

97. BLOG:CMS ID Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 19111
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19111
Summary:
BLOG:CMS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 4.0.0j of BLOG:CMS is vulnerable to this issue; prior versions may also be affected.

98. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG version 1.4.4 is vulnerable to this issue; previous versions may also be affected.

99. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.

100. Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
BugTraq ID: 19006
Remote: Yes
Last Updated: 2006-07-24
Relevant URL: http://www.securityfocus.com/bid/19006
Summary:
D-Link wired and wireless routers are prone to a buffer-overflow vulnerability because these devices fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected device.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Flaw finders lay siege to Microsoft Office
By: Robert Lemos
Vulnerability researchers and hacker groups are inundating the software giant with flaws in its Office productivity suite, putting the product team on alert for almost an entire summer.
http://www.securityfocus.com/news/11401

2. Daily flaws ratchet up disclosure debate
By: Robert Lemos
One researcher's promise to release a browser bug every day during the month of July escalates the debate over the degree of openness that helps security.
http://www.securityfocus.com/news/11400

3. Researchers look to predict software flaws
By: Robert Lemos
Want to know how many flaws will be in your next version? Using historical data, university researchers hope to be able to tell you.
http://www.securityfocus.com/news/11399

4. AT&T privacy policy overreaches, lawyers say
By: Robert Lemos
A recent change to AT&T's privacy policy for broadband and video users has been labeled overbroad by legal experts, and likely will leave the courts or Congress to decide whether the company's practices are standard or sinister.
http://www.securityfocus.com/news/11398

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
V.   INCIDENTS LIST SUMMARY
---------------------------
1. New PowerPoint Trojan installs itself as LSP
http://www.securityfocus.com/archive/75/440465

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Fortigate Bypass
http://www.securityfocus.com/archive/82/440598

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Co-Hosting SQL with IIS FTP service
http://www.securityfocus.com/archive/88/441077

2. SCHANNEL CSP SSL
http://www.securityfocus.com/archive/88/441067

3. Free encryption and credential management tools for Windows
http://www.securityfocus.com/archive/88/441066

4. SecurityFocus Microsoft Newsletter #300
http://www.securityfocus.com/archive/88/440570

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat

Attend the Black Hat Briefings & Training USA, July 29-August 3 in Las Vegas.
World renowned security experts reveal tomorrow's threats today. Free of vendor pitches, the Briefings are designed to be pragmatic regardless of your security environment. Featuring 36 hands-on training courses and 10 conference tracks, networking opportunities with over 2,500 delegates from 40+ nations.

http://www.blackhat.com