SecurityFocus Newsletter #361
Peter Laborge <[email protected]> Tue, 01 Aug 2006 16:06:05 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #361
----------------------------------------
This issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of sensitive data - including personal, medical and financial information - are exchanged, and stored. This paper examines a few vulnerability detection methods - specifically comparing and contrasting manual penetration testing with automated scanning tools. Download Watchfire's "Web Application Security: Automated Scanning or Manual Penetration Testing?" whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008Vmc
------------------------------------------------------------------
I. FRONT AND CENTER
1. E-mail privacy in the workplace
2. After an Exploit: mitigation and remediation
II. BUGTRAQ SUMMARY
1. Knusperleicht ShoutBox SB_Include_Path Parameter Remote File Include Vulnerability
2. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
3. Ajax Chat Multiple Remote Vulnerabilities
4. X-Scripts X-Statistics X-Statistics.PHP SQL Injection Vulnerability
5. Liga Manager Online Joomla! Component Remote File Include Vulnerability
6. X-Scripts X-Poll Top.PHP SQL Injection Vulnerability
7. X-Scripts X-Protection Protect.PHP SQL Injection Vulnerability
8. Com_Bayesiannaivefilter Mambo Component Remote File Include Vulnerability
9. User Home Pages UHP_CONFIG.PHP Remote File Include Vulnerability
10. Microsoft PowerPoint Unspecified Code Execution Vulnerability
11. ATutor Multiple SQL Injection Vulnerabilities
12. Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
13. Microsoft Internet Explorer ADODB.Recordset NextRecordset Denial of Service Vulnerability
14. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
15. Mambo Gallery Manager MosConfig_Absolute_Path Remote File Include Vulnerability
16. Artlinks MosConfig_Absolute_Path Remote File Include Vulnerability
17. Mambatstaff MosConfig_Absolute_Path Remote File Include Vulnerability
18. Microsoft Windows Graphical Device Interface Plus Library Denial Of Service Vulnerability
19. AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
20. MyBulletinBoard UserCP.PHP Cross-Site Scripting Vulnerability
21. MyBulletinBoard UserCP.PHP Directory Traversal Vulnerability
22. eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
23. Coppermine Photo Gallery Theme.PHP Remote File Include Vulnerability
24. Sun Solaris N1 Grid Engine Multiple Local Vulnerabilities
25. SecurityImages Component Multiple Remote File Include Vulnerabilities
26. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
27. Knusperleicht FileManager DWL_Download Remote File Include Vulnerability
28. Knusperleicht Quickie Quick_Path Parameter Remote File Include Vulnerability
29. Multiple Browser Proxy Auto-Config Script Handling Remote Denial of Service Vulnerability
30. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
31. Advanced Webhost Billing System Contact.PHP Multiple Cross-Site Scripting Vulnerabilities
32. Mozilla/Netscape/Firefox Browsers Domain Name Remote Buffer Overflow Vulnerability
33. OpenForum Multiple Cross-Site Injection Vulnerabilities
34. SiteBar Command.PHP Cross-Site Scripting Vulnerability
35. Mozilla Browser/Firefox Chrome Window Spoofing Vulnerability
36. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
37. Mozilla Browser/Firefox Chrome Page Loading Restriction Bypass Privilege Escalation Weakness
38. Mozilla Browser/Firefox JavaScript Engine Integer Overflow Vulnerability
39. Mozilla Browser/Firefox DOM Objects Spoofing Vulnerability
40. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
41. Mozilla Browser/Firefox Arbitrary HTTP Request Injection Vulnerability
42. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
43. Mcafee Multiple Products Unspecified Remote Code Execution Vulnerability
44. OpenSSH SCP Shell Command Execution Vulnerability
45. GDB Multiple Vulnerabilities
46. Squirrelmail Redirect.PHP Local File Include Vulnerability
47. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
48. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
49. Samba Internal Data Structures Denial of Service Vulnerability
50. IBM Informix Dynamic Server Multiple Vulnerabilities
51. Freeciv Multiple Remote Denial of Service Vulnerabilities
52. MyNewsGroups Layersmenu.INC.PHP Remote File Include Vulnerability
53. Open Cubic Player Multiple Buffer Overflow Vulnerabilities
54. VBPortal Log Remote Code Execution Vulnerability
55. PHPReactor EditProfile.PHP Remote File Include Vulnerability
56. TinyPHPForum Multiple Cross-Site Scripting Vulnerabilities
57. Bomberclone Multiple Remote Vulnerabilities
58. Mozilla Browser/Firefox XBM Image Processing Heap Overflow Vulnerability
59. PHPAuction PHPAds_Path Variable Remote File Include Vulnerability
60. Help Center Live Module.PHP Directory Traversal Vulnerability
61. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
62. SQLiteWebAdmin Multiple Input Validation Vulnerabilities
63. 312Soft PhP-Gallery Multiple Input Validation Vulnerabilities
64. Colophon Component Admin.Colophon.PHP Remote File Include Vulnerability
65. Apple Safari KHTMLParser::popOneBlock Denial Of Service Vulnerability
66. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
67. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
68. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
69. Ethereal Multiple Protocol Dissector Vulnerabilities
70. Ethereal Multiple Remote Protocol Dissector Vulnerabilities
71. WordPress Multiple Unspecified Security Vulnerabilities
72. Mozilla Browser/Firefox Zero-Width Non-Joiner Stack Corruption Vulnerability
73. Mozilla Multiple Products Remote Vulnerabilities
74. VMware ESX Multiple Information Disclosure Vulnerabilities
75. Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability
76. Ethereal Etheric/GPRS-LLC/IAPP/JXTA/sFlow Dissector Vulnerabilities
77. XMB Forum U2UID SQL Injection Vulnerability
78. TinyPHPForum Error.PHP Information Disclosure Vulnerability
79. Voodoo Chat File_Path Parameter Remote File Include Vulnerability
80. Barracuda Networks Spam Firewall Multiple Vulnerabilities
81. Knusperleicht NewsPreporter News_include_path Remote File Include Vulnerability
82. Knusperleicht GuestBook GB_PATH Parameter Remote File Include Vulnerability
83. Knusperleicht FAQ Script Index.PHP Remote File Include Vulnerability
84. WoW Roster Multiple Remote File Include Vulnerabilities
85. TSEP Copyright.PHP Remote File Include Vulnerability
86. Knusperleicht NewsLetter Index.PHP Remote File Include Vulnerability
87. Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
88. Moskool Component Admin.Moskool.PHP Remote File Include Vulnerability
89. myEvent Myevent.PHP Remote File Include Vulnerability
90. Oracle 10g Alter Session Integer Overflow Vulnerability
91. Multiple Ethereal Unspecified Dissector Vulnerabilities
92. Banex PHP MySQL Banner Exchange Multiple Remote Vulnerabilities
93. Ethereal Multiple Unspecified Denial of Service and Potential Code Execution Vulnerabilities
94. Seir Anphin V666 Community Management System Multiple SQL Injection Vulnerabilities
95. Easy File Sharing FTP Server Pass Command Remote Buffer Overflow Vulnerability
96. Dig Config Parameter Cross-Site Scripting Vulnerability
97. MySQL Server Date_Format Denial Of Service Vulnerability
98. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
99. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
100. LibXPM Bitmap_unit Integer Overflow Vulnerability
III. SECURITYFOCUS NEWS
1. ActiveX security faces storm before calm
2. SCADA system makers pushed toward security
3. Flaw finders lay siege to Microsoft Office
4. Daily flaws ratchet up disclosure debate
IV. SECURITY JOBS LIST SUMMARY
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Exploiting Heap Overflows in W2K
2. Problem in IE's File Type Recognition
VII. MICROSOFT FOCUS LIST SUMMARY
1. Domain admin mailbox rights on Exchange 2003
2. username change best practices...
3. [Administrivia] Guest moderator
4. MS Exchange
5. Impact of removing administrative rights in an enterprise running XP
6. .Net Satisfies Security Compliance Satistactions or Not ???
7. API hooking
8. Co-Hosting SQL with IIS FTP service
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. E-mail privacy in the workplace
By Mark Rasch
Even with a well-heeled corporate privacy policy stating that all employee communications may be monitored in the workplace, the legality of e-mail monitoring is not as clear cut as one might think.
http://www.securityfocus.com/columnists/412
2. After an Exploit: mitigation and remediation
By Jamie Riden
This article describes a few hardening and alerting methods for Unix servers that help block vectors for various attacks, including two web-based application attacks, DNS issues, and the brute-forcing of SSH passwords. The article then looks at steps to take and lessons learned post-compromise.
http://www.securityfocus.com/infocus/1871
II. BUGTRAQ SUMMARY
--------------------
1. Knusperleicht ShoutBox SB_Include_Path Parameter Remote File Include Vulnerability
BugTraq ID: 19273
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19273
Summary:
ShoutBox is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This affects version 4.4; other versions may also be vulnerable.
2. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.
Specific details of these issues are not currently available. This record will be updated when more information becomes available.
The following are vulnerable:
- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier
3. Ajax Chat Multiple Remote Vulnerabilities
BugTraq ID: 19238
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19238
Summary:
Ajax Chat is prone to both a directory-traversal vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the directory-traversal issue to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
An attacker may also leverage the cross-site scripting issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 0.1 of the application is reportedly affected by these vulnerabilities.
4. X-Scripts X-Statistics X-Statistics.PHP SQL Injection Vulnerability
BugTraq ID: 19237
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19237
Summary:
X-Statistics is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
X-Statistics 1.20 is vulnerable to this issue.
5. Liga Manager Online Joomla! Component Remote File Include Vulnerability
BugTraq ID: 19234
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19234
Summary:
Liga Manager Online Joomla! Component is prone to a remote file-include vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input. An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process.
This may allow the attacker to compromise the application and gain access to the underlying system.
6. X-Scripts X-Poll Top.PHP SQL Injection Vulnerability
BugTraq ID: 19236
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19236
Summary:
X-Poll is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
X-Poll 1.10 is vulnerable to this issue.
7. X-Scripts X-Protection Protect.PHP SQL Injection Vulnerability
BugTraq ID: 19235
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19235
Summary:
X-Protection is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
X-Protection 1.10 is vulnerable to this issue.
8. Com_Bayesiannaivefilter Mambo Component Remote File Include Vulnerability
BugTraq ID: 19231
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19231
Summary:
The 'com_bayesiannaivefilter' Mambo Component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 1.1.
9. User Home Pages UHP_CONFIG.PHP Remote File Include Vulnerability
BugTraq ID: 19233
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19233
Summary:
User Home Pages for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
10. Microsoft PowerPoint Unspecified Code Execution Vulnerability
BugTraq ID: 19229
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19229
Summary:
Microsoft PowerPoint is prone to an unspecified code-execution vulnerability.
A proof-of-concept exploit file designed to trigger this vulnerability has been released. This issue arises when a vulnerable user opens a malicious read-only PowerPoint file and then closes it.
It is currently unknown if this exploit file pertains to a newly discovered, unpublished vulnerability or if this exploits a previously disclosed issue. This issue may be related to one of the vulnerabilities described in BID 18993 (Microsoft Powerpoint Multiple Unspecified Vulnerabilities). If further analysis reveals that this issue is related to an existing BID, this record will be retired.
Microsoft PowerPoint 2003 SP2 French Edition is reported vulnerable to this issue; other versions may also be affected.
11. ATutor Multiple SQL Injection Vulnerabilities
BugTraq ID: 19232
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19232
Summary:
ATutor is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.
A successful attack could allow an attacker to compromise the software, access or modify data, or exploit vulnerabilities in the underlying database implementation.
12. Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
BugTraq ID: 19228
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19228
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability. This issue is triggered when an attacker convinces a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
13. Microsoft Internet Explorer ADODB.Recordset NextRecordset Denial of Service Vulnerability
BugTraq ID: 19227
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19227
Summary:
Microsoft Internet Explorer is prone to a denial-of-service condition when processing the 'NextRecordset' method of the 'ADODB.Recordset' object.
A successful attack may cause the browser to fail.
14. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
15. Mambo Gallery Manager MosConfig_Absolute_Path Remote File Include Vulnerability
BugTraq ID: 19224
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19224
Summary:
Mambo Gallery Manager for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
16. Artlinks MosConfig_Absolute_Path Remote File Include Vulnerability
BugTraq ID: 19223
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19223
Summary:
Artlinks for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
17. Mambatstaff MosConfig_Absolute_Path Remote File Include Vulnerability
BugTraq ID: 19222
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19222
Summary:
Mambatstaff for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
18. Microsoft Windows Graphical Device Interface Plus Library Denial Of Service Vulnerability
BugTraq ID: 19221
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19221
Summary:
Reportedly, the Microsoft Windows GDI+ library 'gdiplus.dll' is prone to a denial-of-service vulnerability because the software fails to handle malformed image files properly.
An attacker may leverage this issue to trigger a denial-of-service condition in software implementing the vulnerable library. Other attacks may also be possible.
19. AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
BugTraq ID: 18859
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/18859
Summary:
The AdPlug library is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the library's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running applications that use the affected library to open attacker-supplied malicious files.
The AdPlug library version 2.0 is vulnerable to these issues; previous versions may also be affected.
20. MyBulletinBoard UserCP.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19193
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19193
Summary:
MyBulletinBoard is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
21. MyBulletinBoard UserCP.PHP Directory Traversal Vulnerability
BugTraq ID: 19195
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19195
Summary:
MyBulletinBoard is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
22. eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
BugTraq ID: 19164
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19164
Summary:
eIQnetworks Enterprise Security Analyzer Topology Server is prone to a remote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execution.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable. OEM vendors' versions prior to 4.6 are also vulnerable.
23. Coppermine Photo Gallery Theme.PHP Remote File Include Vulnerability
BugTraq ID: 19219
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19219
Summary:
Coppermine Photo Gallery is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
24. Sun Solaris N1 Grid Engine Multiple Local Vulnerabilities
BugTraq ID: 19218
Remote: No
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19218
Summary:
N1 Grid Engine is prone to a multiple local vulnerabilities.
An unprivileged local attacker may be able to trigger the following vulnerabilities:
- A denial-of-service condition by shutting down the grid service.
- An unspecified buffer-overflow vulnerability.
Successful exploits of these vulnerabilities may allow local attackers to execute arbitrary machine code resulting in privilege escalation or to deny service to legitimate users.
25. SecurityImages Component Multiple Remote File Include Vulnerabilities
BugTraq ID: 19217
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19217
Summary:
SecurityImages is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Versions 3.05 for Mambo and version 1.09 for Joomla are vulnerable to this issue; prior versions may also be affected.
26. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
BugTraq ID: 18944
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/18944
Summary:
Ruby is prone to multiple vulnerabilities that let attackers bypass SAFE-level restrictions.
These issues allow attackers to bypass the expected SAFE-level restrictions, possibly allowing them to execute unauthorized script code in the context of affected applications. The specific impact of these issues depends on the implementation of scripts that use SAFE-level security checks.
27. Knusperleicht FileManager DWL_Download Remote File Include Vulnerability
BugTraq ID: 19270
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19270
Summary:
FileManager is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
28. Knusperleicht Quickie Quick_Path Parameter Remote File Include Vulnerability
BugTraq ID: 19271
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19271
Summary:
Quickie is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
29. Multiple Browser Proxy Auto-Config Script Handling Remote Denial of Service Vulnerability
BugTraq ID: 14924
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14924
Summary:
Multiple browsers are affected by a remote denial-of-service vulnerability when handling proxy auto-config scripts. This can cause a crash in an instance of an affected browser.
Firefox 1.0.6 and prior versions, Netscape Browser 8.0.3.3, and Mozilla 1.7.11 and prior versions are affected by this issue.
30. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
31. Advanced Webhost Billing System Contact.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19226
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19226
Summary:
Advanced Webhost Billing System (AWBS) is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage any of these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 2.2.2 is vulnerable. Other versions may also be affected.
32. Mozilla/Netscape/Firefox Browsers Domain Name Remote Buffer Overflow Vulnerability
BugTraq ID: 14784
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14784
Summary:
Mozilla/Netscape/Firefox are reported prone to a remote buffer-overflow vulnerability when handling a malformed URI.
A successful attack may result in a crash of the application or the execution of arbitrary code.
Firefox 1.0.6 and 1.5 Beta 1 are vulnerable to this issue. Mozilla 1.7.11 and Netscape 8.0.3.3 and 7.2 are affected as well.
33. OpenForum Multiple Cross-Site Injection Vulnerabilities
BugTraq ID: 19266
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19266
Summary:
OpenForum is prone to multiple cross-site scripting vulnerability because the application fails to sanitize user input.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
These issues affect version 1.2 beta; other versions may also be vulnerable.
34. SiteBar Command.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18680
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/18680
Summary:
SiteBar is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
35. Mozilla Browser/Firefox Chrome Window Spoofing Vulnerability
BugTraq ID: 14919
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14919
Summary:
Mozilla and Firefox browsers are prone to a window-spoofing vulnerability.
An attacker can exploit this vulnerability to enhance phishing-style attacks.
36. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
37. Mozilla Browser/Firefox Chrome Page Loading Restriction Bypass Privilege Escalation Weakness
BugTraq ID: 14920
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14920
Summary:
Mozilla Browser/Firefox are prone to a potential arbitrary code-execution weakness.
Specifically, an attacker can load privileged 'chrome' pages from an unprivileged 'about:' page. This issue does not pose a threat unless it is combined with a same-origin violation issue.
If successfully exploited, this issue may allow a remote attacker to execute arbitrary code and gain unauthorized remote access to a computer. This would occur in the context of the user running the browser.
38. Mozilla Browser/Firefox JavaScript Engine Integer Overflow Vulnerability
BugTraq ID: 14917
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14917
Summary:
Mozilla Browser/Firefox are affected by an integer-overflow vulnerability in their JavaScript engine. A remote attacker may exploit this issue by creating a malicious site and enticing users to visit it.
A successful attack may facilitate unauthorized remote access to a vulnerable computer.
Netscape Browser 8.0.3.3, Netscape 7.2, and K-Meleon 0.9 are also vulnerable.
39. Mozilla Browser/Firefox DOM Objects Spoofing Vulnerability
BugTraq ID: 14921
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14921
Summary:
Mozilla and Firefox are prone to a DOM object spoofing vulnerability. Successful exploitation could allow a remote attacker to execute arbitrary script code with elevated privileges.
40. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
41. Mozilla Browser/Firefox Arbitrary HTTP Request Injection Vulnerability
BugTraq ID: 14923
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14923
Summary:
Mozilla and Firefox browsers are prone to a vulnerability that permits the injection of arbitrary HTTP requests. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can use this issue to exploit server or proxy flaws from the user's machine, or to fool a server or proxy into thinking a single request is a stream of separate requests.
42. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.
The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.
An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.
43. Mcafee Multiple Products Unspecified Remote Code Execution Vulnerability
BugTraq ID: 19265
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19265
Summary:
Multiple products by McAfee are prone to an unspecified remote code execution vulnerability.
A successful attack can result in a complete compromise.
Due to a lack of information, further details are not available at the moment. This BID will be updated when more information becomes available.
44. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because the application fails to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
45. GDB Multiple Vulnerabilities
BugTraq ID: 13697
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/13697
Summary:
GDB is reportedly affected by multiple vulnerabilities. These issues can allow an attacker to execute arbitrary code and commands on an affected computer. A successful attack may allow the attacker to gain elevated privileges or unauthorized access.
The following specific issues were identified:
- a remote heap-overflow vulnerability when loading malformed object files.
- a local privilege-escalation vulnerability.
GDB 6.3 is reportedly affected by these issues; other versions are likely vulnerable as well. GNU binutils 2.14 and 2.15 are affected by the heap-overflow issue as well.
46. Squirrelmail Redirect.PHP Local File Include Vulnerability
BugTraq ID: 18231
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/18231
Summary:
SquirrelMail is prone to a local file-include vulnerability. This is due to improper sanitization of user-supplied input.
A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.
47. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
BugTraq ID: 7831
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/7831
Summary:
A vulnerability has been reported for OpenSSH that may allow unauthorized access to an OpenSSH server's login mechanism.
The vulnerability occurs because of the way OpenSSH restricts access. It's possible to configure OpenSSH to restrict access based on certain patterns. When a numeric IP address is provided as the host that is attempting a connection, an attacker can trick the OpenSSH server to allow access.
48. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
49. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.
This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.
50. IBM Informix Dynamic Server Multiple Vulnerabilities
BugTraq ID: 19264
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19264
Summary:
IBM Informix Dynamic Server is prone to fourteen vulnerabilities. These issues can allow attackers to execute arbitrary code and compromise a vulnerable computer, gain elevated privileges, retrieve sensitive information, and trigger denial-of-service conditions.
Presumably, some of these issues are remote in nature, while others may present a local threat.
IBM Informix Dynamic Server versions 7.3, 9.4, 10.0 for Windows and Linux are reported vulnerable; other versions may be affected as well.
51. Freeciv Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 19117
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19117
Summary:
Freeciv server is prone to multiple remote denial-of-service vulnerabilities.
A remote attacker may exploit these issues to deny service to legitimate users by sending malicious packets to a server.
2.1.0-beta1 and prior versions are affected by these issues.
52. MyNewsGroups Layersmenu.INC.PHP Remote File Include Vulnerability
BugTraq ID: 19258
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19258
Summary:
MyNewsGroups is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This issue affects version 0.6b; other versions may also be vulnerable.
53. Open Cubic Player Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19262
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19262
Summary:
Open Cubic Player is affected by multiple remote buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the application.
54. VBPortal Log Remote Code Execution Vulnerability
BugTraq ID: 19257
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19257
Summary:
vbPortal is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code on the affected computer in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
vbPortal versions 3.0.2 to 3.6.0 are vulnerable; other versions may also be affected.
55. PHPReactor EditProfile.PHP Remote File Include Vulnerability
BugTraq ID: 19259
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19259
Summary:
PHPReactor is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Version 1.2.7pl1 is vulnerable to this issue; other versions may also be affected.
56. TinyPHPForum Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19260
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19260
Summary:
TinyPHPForum is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
57. Bomberclone Multiple Remote Vulnerabilities
BugTraq ID: 19255
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19255
Summary:
Bomberclone is prone to remote information-disclosure and denial-of-service vulnerabilities because it fails to properly sanitize user-supplied input.
These issues allow remote attackers to access sensitive information and to crash the application, denying further service to legitimate users.
Version 0.11.6 is reported vulnerable; other versions may also be affected.
58. Mozilla Browser/Firefox XBM Image Processing Heap Overflow Vulnerability
BugTraq ID: 14916
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14916
Summary:
Mozilla and Firefox browsers are prone to a heap overflow when processing malformed XBM images. Successful exploitation can result in arbitrary code execution.
59. PHPAuction PHPAds_Path Variable Remote File Include Vulnerability
BugTraq ID: 19254
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19254
Summary:
PHPAuction with phpAdsNew is prone to a remote file-include vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
PHPAuction version 2.1 with phpAdsNew 2.0.5 is vulnerable; other versions may also be affected.
60. Help Center Live Module.PHP Directory Traversal Vulnerability
BugTraq ID: 19256
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19256
Summary:
Help Center Live is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
This issue affects version 2.1.2; other versions may also be vulnerable.
61. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code
- gain access to potentially sensitive information.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as further information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2
62. SQLiteWebAdmin Multiple Input Validation Vulnerabilities
BugTraq ID: 19253
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19253
Summary:
SQLiteWebAdmin is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These issues include:
- A remote file-include vulnerability. A remote attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process.
- An SQL-injection vulnerability. A remote attacker can exploit this issue to access or modify data or to exploit vulnerabilities in the underlying database implementation.
- Multiple vulnerabilities affecting the HTTP response header. A remote attacker can exploit these issues to influence or misrepresent how web content is served.
63. 312Soft PhP-Gallery Multiple Input Validation Vulnerabilities
BugTraq ID: 17812
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/17812
Summary:
PhP-Gallery is prone to an information-disclosure vulnerability and a cross-site scripting vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the affected application or to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
64. Colophon Component Admin.Colophon.PHP Remote File Include Vulnerability
BugTraq ID: 19252
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19252
Summary:
The Colophon component for Joomla is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Colophon 1.2 and prior versions are vulnerable to this issue.
65. Apple Safari KHTMLParser::popOneBlock Denial Of Service Vulnerability
BugTraq ID: 19250
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19250
Summary:
Safari is prone to a denial-of-service vulnerability. This issue is triggered when an attacker entices a victim user to visit a malicious website or to open a malicious HTML file.
A remote attacker may exploit this issue to crash the application, effectively denying service to legitimate users. Remote code execution may be possible, but this has not been confirmed.
66. Ethereal Service Location Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15158
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15158
Summary:
A remote buffer-overflow vulnerability affects Ethereal. This issue is due to the application's failure to securely copy network-derived data into sensitive process buffers. The specific issue resides in the Service Location Protocol dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
This issue may be exploited by a single TCP packet to port 427, since Ethereal does not keep track of connection states. This allows malicious users to spoof the origin of attacks and to exploit this vulnerability when no services are actively listening on TCP port 427.
Note that this issue was originally disclosed in BID 15148 "Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13".
67. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 19251
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19251
Summary:
Taskjitsu is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Taskjitsu 2.03 and earlier are vulnerable to this issue.
68. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.10.13
BugTraq ID: 15148
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/15148
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.
These issues include:
- Buffer-overflow vulnerabilities
- Null-pointer dereference denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Memory exhaustion denial-of-service vulnerabilities
- Division by zero denial-of-service vulnerabilities
- Invalid pointer free() attempt denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect different versions of Ethereal, from 0.7.7 through to 0.10.12.
69. Ethereal Multiple Protocol Dissector Vulnerabilities
BugTraq ID: 14399
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14399
Summary:
Many vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.
These issues include:
- Buffer-overflow vulnerabilities
- Format-string vulnerabilities
- NULL-pointer dereference denial-of-service vulnerabilities
- Infinite-loop denial-of-service vulnerabilities
- Memory-exhaustion denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect several versions of Ethereal, from 0.8.5 through to 0.10.11.
70. Ethereal Multiple Remote Protocol Dissector Vulnerabilities
BugTraq ID: 13504
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/13504
Summary:
Many vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors.
These issues include:
- Buffer-overflow vulnerabilities
- Format-string vulnerabilities
- NULL-pointer dereference denial-of-service vulnerabilities
- Segmentation fault denial-of-service vulnerabilities
- Infinite-loop denial-of-service vulnerabilities
- Memory exhaustion denial-of-service vulnerabilities
- Double-free vulnerabilities
- Unspecified denial-of-service vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect several versions of Ethereal, from 0.8.14 through to 0.10.10.
This BID will be split into individual BIDs for each separate issue.
BID 13567 has been created for the DISTCC issue.
71. WordPress Multiple Unspecified Security Vulnerabilities
BugTraq ID: 19247
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19247
Summary:
WordPress is prone to multiple unspecified security vulnerabilities.
Very little information is available on this issue; this BID will be updated as more information becomes available.
WordPress 2.03 and earlier are vulnerable to this issue.
The vendor has released an update.
72. Mozilla Browser/Firefox Zero-Width Non-Joiner Stack Corruption Vulnerability
BugTraq ID: 14918
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/14918
Summary:
Mozilla and Firefox are prone to a stack-corruption vulnerability. Successful exploitation could potentially result in arbitrary code execution.
73. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information.
- carry out cross-domain scripting attacks
Other attacks may also be possible.
The issues described here will be split into individual BIDs as further information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3
74. VMware ESX Multiple Information Disclosure Vulnerabilities
BugTraq ID: 19249
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19249
Summary:
VMware ESX is prone to multiple information-disclosure vulnerabilities. These issues are due to a design error in the application. The following issues were reported:
1. An information disclosure vulnerability that could disclose the session ID, username, and password if an attacker can access session cookies used by the management interface.
2. An information disclosure vulnerability that could expose authentication credentials to local users on the computer hosting the VMWare ESX Server. This vulnerability occurs because authentication credentials are also handled insecurely by the VMWare ESX management interface.
VMware ESX server versions 2.5.3 P2, 2.1.3 P1, 2.0.2, 2.0.2 P1, and 2.5.2 P4 are reported to be vulnerable; other versions may also be affected.
75. Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability
BugTraq ID: 19263
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19263
Summary:
Lhaplus is prone to a buffer-overflow vulnerability in its LHA extended header handling routine.
A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition when Lhaplus reads the extended header in an LZH file.
This vulnerability reportedly affects version 1.52 (Japanese) of Lhaplus. Previous versions may also be vulnerable.
76. Ethereal Etheric/GPRS-LLC/IAPP/JXTA/sFlow Dissector Vulnerabilities
BugTraq ID: 12762
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/12762
Summary:
Multiple buffer-overflow and denial-of-service vulnerabilities affect various Ethereal protocol dissectors, including the Etheric, GPRS-LLC, IAPP, JXTA, and sFlow dissectors.
These issues may be triggered when the software is used to monitor live network traffic or when a dump is viewed. In the worst-case scenario, an attacker may be able to execute arbitrary code as the superuser. Exploiting the other vulnerabilities will cause the software to crash when an affected dissector processes live network traffic or a dump.
77. XMB Forum U2UID SQL Injection Vulnerability
BugTraq ID: 19280
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19280
Summary:
XMB Forum is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 1.9.6; earlier versions may also be vulnerable.
78. TinyPHPForum Error.PHP Information Disclosure Vulnerability
BugTraq ID: 19278
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19278
Summary:
TinyPHPForum is prone to an information-disclosure vulnerability. This issue arises when a script allows a remote untrusted source to change a victim user's email address, and have their login credentials returned to an attacker.
Information that the attacker gathers by exploiting this vulnerability may aid in other attacks.
79. Voodoo Chat File_Path Parameter Remote File Include Vulnerability
BugTraq ID: 19277
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19277
Summary:
Voodoo Chat is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This affects version 1.0RC1b; other versions may also be vulnerable.
80. Barracuda Networks Spam Firewall Multiple Vulnerabilities
BugTraq ID: 19276
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19276
Summary:
Spam Firewall is prone to multiple vulnerabilities. The issues include a directory-traversal vulnerability and a access-validation vulnerability.
An attacker can exploit these issues to gain access to potentially sensitive information. Information obtained may aid in further attacks.
Versions 3.3.01.0001 to 3.3.03.053 are vulnerable to this issue.
81. Knusperleicht NewsPreporter News_include_path Remote File Include Vulnerability
BugTraq ID: 19275
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19275
Summary:
NewsPreporter is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
82. Knusperleicht GuestBook GB_PATH Parameter Remote File Include Vulnerability
BugTraq ID: 19274
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19274
Summary:
GuestBook is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
83. Knusperleicht FAQ Script Index.PHP Remote File Include Vulnerability
BugTraq ID: 19272
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19272
Summary:
FAQ Script is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This issue affects version 1.0; other versions may also be vulnerable.
84. WoW Roster Multiple Remote File Include Vulnerabilities
BugTraq ID: 19269
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19269
Summary:
WoW Roster is prone to multiple remote file-include vulnerabilities. These issues are due to improper sanitization of user-supplied input.
A successful exploit may allow unauthorized users to execute remote PHP scripts; other attacks are also possible.
85. TSEP Copyright.PHP Remote File Include Vulnerability
BugTraq ID: 19268
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19268
Summary:
TSEP is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
86. Knusperleicht NewsLetter Index.PHP Remote File Include Vulnerability
BugTraq ID: 19267
Remote: Yes
Last Updated: 2006-08-01
Relevant URL: http://www.securityfocus.com/bid/19267
Summary:
NewsLetter is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Versions 3.5 and prior are vulnerable to this issue; others versions may also be affected.
87. Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
BugTraq ID: 12759
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/12759
Summary:
A remote buffer-overflow vulnerability reportedly affects Ethereal because it fails to securely copy network-derived data into sensitive process buffers. The specific issue resides in the 3GPP2 A11 dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
88. Moskool Component Admin.Moskool.PHP Remote File Include Vulnerability
BugTraq ID: 19245
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19245
Summary:
Moskool is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 1.5 is vulnerable to this issue; other versions may also be affected.
89. myEvent Myevent.PHP Remote File Include Vulnerability
BugTraq ID: 19246
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19246
Summary:
myEvent is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
90. Oracle 10g Alter Session Integer Overflow Vulnerability
BugTraq ID: 19201
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19201
Summary:
Oracle 10g is reportedly prone to a integer-overflow vulnerability because the application fails to allocate a large enough data type to accommodate user-supplied input before using it in a query. This issue has not been confirmed.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely cause denial-of-service conditions.
Reports indicate that Oracle 10g R2 is vulnerable; other versions may also be affected.
91. Multiple Ethereal Unspecified Dissector Vulnerabilities
BugTraq ID: 12326
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/12326
Summary:
Ethereal is prone to multiple vulnerabilities ranging from denial of service to arbitrary code execution:
- The COPS dissector may go into an infinite loop.
- The DLSw dissector may force Ethereal to exit prematurely.
- The DNP dissector may corrupt memory.
- The Gnutella dissector may force Ethereal to exit prematurely.
- The MMSE dissector may free statically allocated memory.
- A buffer overflow may occur in the X11 dissector.
92. Banex PHP MySQL Banner Exchange Multiple Remote Vulnerabilities
BugTraq ID: 19240
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19240
Summary:
PHP MySQL Banner Exchange is prone to multiple SQL-injection vulnerabilities and a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
An attacker may also leverage the remote file-include issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process.
Version 2.1 of the application is affected by these vulnerabilities; other versions may also be affected.
93. Ethereal Multiple Unspecified Denial of Service and Potential Code Execution Vulnerabilities
BugTraq ID: 11943
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/11943
Summary:
Ethereal 0.10.8 has been released to address multiple vulnerabilities. These issues are reported to cause denial-of-service conditions in the application; some issues may allow arbitrary code execution.
The following specific issues were specified:
- A denial-of-service vulnerability presents itself in the DICOM dissector.
- Another denial-of-service vulnerability occurs when handling a malformed RTP timestamp.
- Another denial of service arises when Ethereal processes a specially crafted SMB packet.
- The HTTP dissector may allow a remote attacker to access memory that was previously freed.
This BID will be updated as more information becomes available.
94. Seir Anphin V666 Community Management System Multiple SQL Injection Vulnerabilities
BugTraq ID: 19244
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19244
Summary:
Seir Anphin V666 Community Management System is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.
A successful attack could allow an attacker to compromise the software, access or modify data, or exploit vulnerabilities in the underlying database implementation.
95. Easy File Sharing FTP Server Pass Command Remote Buffer Overflow Vulnerability
BugTraq ID: 19243
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19243
Summary:
Easy File Sharing FTP Server is prone to a buffer-overflow vulnerability because the application fails to do proper bounds checking on user-supplied data before storing it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected server application.
Version 2.0 is vulnerable to this issue; other versions may also be affected.
96. Dig Config Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 12442
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/12442
Summary:
ht://Dig is reported prone to a cross-site scripting vulnerability. This issue is due to the application's failure to properly sanitize user-supplied URI data before including it in dynamically generated web-page content.
All versions of ht://Dig are considered vulnerable at the moment.
97. MySQL Server Date_Format Denial Of Service Vulnerability
BugTraq ID: 19032
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/19032
Summary:
MySQL is prone to a remote denial-of-service vulnerability because the database server fails to properly handle unexpected input.
This issue allows remote attackers to crash affected database servers, denying service to legitimate users. Attackers must be able to execute arbitrary SQL statements on affected servers, which requires valid credentials to connect to affected servers.
Attackers may exploit this issue in conjunction with latent SQL-injection vulnerabilities in other applications.
Versions of MySQL prior to 4.1.18, 5.0.19, and 5.1.6 are vulnerable to this issue.
98. SIPfoundry SIPXtapi CSeq Processing Remote Buffer-Overflow Vulnerability
BugTraq ID: 18906
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/18906
Summary:
The sipXtapi product is reported to be prone to a remote buffer-overflow vulnerability. This issue presents itself when the application handles a specially crafted 'CSeq' value.
A successful attack may lead to unauthorized remote access in the context of a user running an affected application that uses the vulnerable library.
Reports indicate that sipXtapi versions that were released prior to March 24, 2006 are vulnerable to this issue. Certain PingTel products and versions of AOL Triton may be affected because they employ the vulnerable library.
99. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.
100. LibXPM Bitmap_unit Integer Overflow Vulnerability
BugTraq ID: 12714
Remote: Yes
Last Updated: 2006-07-31
Relevant URL: http://www.securityfocus.com/bid/12714
Summary:
An integer-overflow vulnerability is reported to affect libXpm. Reportedly, this vulnerability occurs in the 'scan.c' source file and is due to a lack of sanity checks performed on the 'bitmap_unit' value.
A remote attacker may exploit this condition to execute arbitrary code in the context of the application that is linked to the affected library.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. ActiveX security faces storm before calm
By: Robert Lemos
A security researcher informs Microsoft of more than 100 flaws in ActiveX controls included with a default installation of Windows XP. Another reason to install Internet Explorer 7?
http://www.securityfocus.com/news/11403
2. SCADA system makers pushed toward security
By: Robert Lemos
Companies that make distributed, real-time control systems--a key part of many nations' critical infrastructure--may be forced by their customers to provide better security.
http://www.securityfocus.com/news/11402
3. Flaw finders lay siege to Microsoft Office
By: Robert Lemos
Vulnerability researchers and hacker groups are inundating the software giant with flaws in its Office productivity suite, putting the product team on alert for almost an entire summer.
http://www.securityfocus.com/news/11401
4. Daily flaws ratchet up disclosure debate
By: Robert Lemos
One researcher's promise to release a browser bug every day during the month of July escalates the debate over the degree of openness that helps security.
http://www.securityfocus.com/news/11400
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Exploiting Heap Overflows in W2K
http://www.securityfocus.com/archive/82/441851
2. Problem in IE's File Type Recognition
http://www.securityfocus.com/archive/82/441117
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Domain admin mailbox rights on Exchange 2003
http://www.securityfocus.com/archive/88/441811
2. username change best practices...
http://www.securityfocus.com/archive/88/441749
3. [Administrivia] Guest moderator
http://www.securityfocus.com/archive/88/441537
4. MS Exchange
http://www.securityfocus.com/archive/88/441417
5. Impact of removing administrative rights in an enterprise running XP
http://www.securityfocus.com/archive/88/441275
6. .Net Satisfies Security Compliance Satistactions or Not ???
http://www.securityfocus.com/archive/88/441276
7. API hooking
http://www.securityfocus.com/archive/88/441274
8. Co-Hosting SQL with IIS FTP service
http://www.securityfocus.com/archive/88/441077
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of sensitive data - including personal, medical and financial information - are exchanged, and stored. This paper examines a few vulnerability detection methods - specifically comparing and contrasting manual penetration testing with automated scanning tools. Download Watchfire's "Web Application Security: Automated Scanning or Manual Penetration Testing?" whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008Vmc