SecurityFocus Newsletter #363
Conrad Schilbe <[email protected]> Wed, 16 Aug 2006 12:14:05 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #363
----------------------------------------
This issue is Sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------
I. FRONT AND CENTER
1. Dynamic Linking in Linux and Windows, part two
II. BUGTRAQ SUMMARY
1. Mensajeitor HTTP CLIENT IP HTML Injection Vulnerability
2. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
3. Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
4. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
5. WP-DB Backup For Wordpress Edit.PHP Directory Traversal Vulnerability
6. Clam Anti-Virus ClamAV UPX Compressed File Heap Buffer Overflow Vulnerability
7. RETIRED: Panda ActiveScan Ascan_6.ASP ActiveX Control Cross-Site Scripting Vulnerability
8. Albatross Remote Arbitrary Code Execution Vulnerability
9. IBM Informix Dynamic Server Multiple Vulnerabilities
10. Mambo Peoplebook Component Param.PeopleBook.PHP Remote File Include Vulnerability
11. RETIRED: Microsoft Windows Help Multiple Remote Vulnerabilities
12. Zen Cart Multiple SQL Injection Vulnerabilities
13. ProjectButler RootDIR Parameter Multiple Remote File Include Vulnerabilities
14. OSDate Multiple HTML Injection Vulnerabilities
15. Extreme Media Board MemCP.PHP Local File Include Vulnerability
16. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
17. Symantec Backup Exec Multiple Heap Overflow Vulnerabilities
18. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
19. Microsoft Windows Server Driver Mailslot Remote Heap Buffer Overflow Vulnerability
20. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
21. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
22. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
23. Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
24. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
25. YaBBSE Index.PHP Cross-Site Scripting Vulnerability
26. Novell eDirectory Unspecified Nessus Denial of Service Vulnerability
27. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
28. MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities
29. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
30. WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
31. HP-UX Support Tools Manager Unspecified Local Denial of Service Vulnerability
32. Opera Document Stylesheet Denial Of Service Vulnerability
33. HP-UX LP Subsystem Denial of Service Vulnerability
34. Cisco PIX SIP Implementation Unauthorized UDP Port Forwarding Vulnerability
35. SmartLine DeviceLock Unauthorized Access Vulnerability
36. NFS-SERVER Remote Buffer Overflow Vulnerability
37. Opera Web Browser CSS Background URI Memory Corruption Vulnerability
38. Lizge Index.PHP Multiple Remote File Include Vulnerabilities
39. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
40. ImageMagick File Name Handling Remote Format String Vulnerability
41. ImageMagick Image Filename Remote Command Execution Vulnerability
42. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
43. Apache HTTP Request Smuggling Vulnerability
44. Apache mod_include Local Buffer Overflow Vulnerability
45. LSH Seed File File Descriptor Leakage Vulnerability
46. Discloser Multiple Remote File Include Vulnerabilities
47. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
48. HP-UX Trusted Mode Unspecified Local Denial of Service Vulnerability
49. Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
50. Linux-HA Heartbeat Remote Denial of Service Vulnerability
51. OpenLDAP TLS Plaintext Password Vulnerability
52. OpenLDAP Ambiguous Password Attribute Weakness
53. Multiple Vendor Dump File Locking Denial Of Service Vulnerability
54. PCRE Regular Expression Heap Overflow Vulnerability
55. HP-UX Mkdir Local Unauthorized Access Vulnerability
56. OpenSSH SCP Shell Command Execution Vulnerability
57. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
58. Horde Products Search.PHP Cross-Site Scripting Vulnerability
59. PHProjekt Multiple Remote File Include Vulnerabilities
60. BusyBox Insecure Password Hash Weakness
61. Microsoft Internet Explorer CHTSKDIC.DLL Denial Of Service Vulnerability
62. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
63. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
64. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
65. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
66. PHP-Nuke AutoHTML Module Local File Include Vulnerability
67. WEBInsta Mailing List Manager InitDB.PHP Remote File Include Vulnerability
68. Microsoft Internet Explorer IMSKDIC.DLL Denial Of Service Vulnerability
69. Linux Kernel do_coredump Denial of Service Vulnerability
70. IBM WebSphere Application Server Prior to 6.0.2.13 Multiple Vulnerabilities
71. Microsoft Winsock Gethostbyname Buffer Overflow Vulnerability
72. Microsoft Windows DNS Client Buffer Overrun Vulnerability
73. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
74. Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
75. NCompress Decompress Buffer Underflow Vulnerability
76. Wireshark Protocol Dissectors Multiple Vulnerabilities
77. Spidey Blog Script PID Parameter SQL Injection Vulnerability
78. Ruby on Rails Routing Denial of Service Vulnerability
79. phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
80. Microsoft Windows HTML Help HHCtrl ActiveX Control Memory Corruption Vulnerability
81. Joomla Webring Component Admin.Webring.Docs.PHP SQL Injection Vulnerability
82. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
83. BlaBla 4U Multiple Cross-Site Scripting Vulnerabilities
84. Apache MPM Worker.C Denial Of Service Vulnerability
85. Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
86. VWar Multiple Input Validation Vulnerabilities
87. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
88. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
89. Mambo Email Publisher Help.MMP.PHP Remote File Include Vulnerability
90. Microsoft Management Console Zone Bypass Vulnerability
91. Libmusicbrainz Multiple Buffer Overflow Vulnerabilities
92. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
93. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
94. GNU Mailman Large Date Data Denial Of Service Vulnerability
95. Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
96. Microsoft Internet Explorer Window Location Cross-Domain Information Disclosure Vulnerability
97. Microsoft Internet Explorer Frameset Memory Corruption Vulnerability
98. Microsoft Internet Explorer Source Element Cross-Domain Information Disclosure Vulnerability
99. Microsoft Internet Explorer Chained Cascading Style Sheets Remote Code Execution Vulnerability
100. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
III. SECURITYFOCUS NEWS
1. Bot spreads using latest Windows flaw
2. Covert channel tool hides data in IPv6
3. Researchers warn over Web worms
4. Attackers pass on OS, aim for drivers and apps
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Consultant, Any Major U.S. City
2. [SJ-JOB] Security Consultant, Any Major U.S. City
3. [SJ-JOB] Security Engineer, Cupertino
4. [SJ-JOB] Technology Risk Consultant, Herndon
5. [SJ-JOB] Incident Handler, Arlington
6. [SJ-JOB] Security Consultant, Denver
7. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
8. [SJ-JOB] Security Consultant, philadelphia
9. [SJ-JOB] Security Engineer, Raleigh
10. [SJ-JOB] Sales Engineer, Boston
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Security contact from Critical Path Inc
VII. MICROSOFT FOCUS LIST SUMMARY
1. Licensed Software Audit
2. Workstation Shutdown / Logoff Policy
3. Local Security Policy screen can't retrieve sec policy information
4. Impact of removing administrative rights in an enterprise running XP
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Dynamic Linking in Linux and Windows, part two
By Reji Thomas and Bhasker Reddy
This article discusses the shared libraries concept in both Windows and Linux, and offers a walk through various data structures to explain how dynamic linking is done in these operating systems.
http://www.securityfocus.com/infocus/1873
II. BUGTRAQ SUMMARY
--------------------
1. Mensajeitor HTTP CLIENT IP HTML Injection Vulnerability
BugTraq ID: 19539
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19539
Summary:
Mensajeitor is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Mensajeitor v1.8.9 r3 is reported vulnerable; previous versions may be affected as well.
2. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 19415
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19415
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations and potentially execute code.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, all assuming that the 'safe_mode' restriction will isolate the users from each other.
This issue is reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.
3. Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
BugTraq ID: 19312
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19312
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
This vulnerability is related to how the browser renders HTML with certain layout and positioning combinations. An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.
This issue affects Internet Explorer on Windows 2000, Windows XP, and Windows Server 2003.
4. Microsoft Internet Explorer OuterHTML Redirection Handling Information Disclosure Vulnerability
BugTraq ID: 18682
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/18682
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.
This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.
5. WP-DB Backup For Wordpress Edit.PHP Directory Traversal Vulnerability
BugTraq ID: 19504
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19504
Summary:
WP-DB Backup For Wordpress is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
6. Clam Anti-Virus ClamAV UPX Compressed File Heap Buffer Overflow Vulnerability
BugTraq ID: 16191
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/16191
Summary:
ClamAV is prone to a heap buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue occurs when the application attempts to handle compressed UPX files.
Exploitation of this issue could allow attacker-supplied machine code to be executed in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.
7. RETIRED: Panda ActiveScan Ascan_6.ASP ActiveX Control Cross-Site Scripting Vulnerability
BugTraq ID: 19471
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19471
Summary:
Panda ActiveScan is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Panda ActiveScan version 5.53.00 is affected by this issue; other versions may also be affected.
This BID is being retired because the application is a service and cannot be downloaded.
8. Albatross Remote Arbitrary Code Execution Vulnerability
BugTraq ID: 16252
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/16252
Summary:
Albatross is prone to an arbitrary code-execution vulnerability.
Reports indicate that malicious user-supplied data may be insecurely used as part of a template, which may lead to arbitrary code execution.
A remote attacker may exploit this issue to gain unauthorized access to an affected computer. Other attacks may be possible as well.
9. IBM Informix Dynamic Server Multiple Vulnerabilities
BugTraq ID: 19264
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19264
Summary:
IBM Informix Dynamic Server is prone to multiple vulnerabilities. These issues can allow attackers to execute arbitrary code and compromise a vulnerable computer, gain elevated privileges, retrieve sensitive information, and trigger denial-of-service conditions.
Some of these issues are remote in nature, while others present a local threat.
10. Mambo Peoplebook Component Param.PeopleBook.PHP Remote File Include Vulnerability
BugTraq ID: 19505
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19505
Summary:
Mambo PeopleBook component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to access the underlying system.
Version 1.0 is vulnerable to this issue; other versions may also be affected.
11. RETIRED: Microsoft Windows Help Multiple Remote Vulnerabilities
BugTraq ID: 19490
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19490
Summary:
The Microsoft Windows Help File viewer (winhlp32.exe) is prone to multiple remote vulnerabilities.
These vulnerabilities present themselves when the application handles specially crafted Windows Help (.hlp) files.
A successful attack may let the attacker crash the application or execute arbitrary code in the context of a vulnerable user who opens a malicious file.
Specific information regarding affected versions of Microsoft Windows is currently unavailable.
Update: Since help files can inherently execute arbitrary malicious code, this BID is being retired.
12. Zen Cart Multiple SQL Injection Vulnerabilities
BugTraq ID: 19542
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19542
Summary:
Zen Cart is prone to multiple SQL injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
These issues affect version 1.3.0.2; earlier versions may also be vulnerable.
13. ProjectButler RootDIR Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19503
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19503
Summary:
ProjectButler is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 0.8.4 is vulnerable to this issue; other versions may also be affected.
14. OSDate Multiple HTML Injection Vulnerabilities
BugTraq ID: 19034
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19034
Summary:
osDate is prone to multiple HTML-injection vulnerabilities. These vulnerabilities occur because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
Version 1.1.7 is vulnerable; other versions may also be affected.
15. Extreme Media Board MemCP.PHP Local File Include Vulnerability
BugTraq ID: 19501
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19501
Summary:
Extreme Media Board is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to execute arbitrary local scripts within the context of the affected application.
Extreme Media Board 1.96 and prior versions are vulnerable to this issue; other versions may also be affected.
16. Linux Kernel DM-Crypt Local Information Disclosure Vulnerability
BugTraq ID: 16301
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/16301
Summary:
The Linux kernel 'dm-crypt' module is susceptible to a local information-disclosure vulnerability. This issue is due to the module's failure to properly zero-sensitive memory buffers before freeing the memory.
This issue may allow local attackers to gain access to potentially sensitive memory that contains information on the cryptographic key used for the encrypted storage. This may aid attackers in further attacks.
This issue affects the 2.6 series of the Linux kernel.
17. Symantec Backup Exec Multiple Heap Overflow Vulnerabilities
BugTraq ID: 19479
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19479
Summary:
Symantec Backup Exec for Windows Servers and Remote Agents, Continuous Protection Server, and Backup Exec for Netware Servers are prone to multiple heap-overflow vulnerabilities.
A remote, authenticated attacker may exploit these vulnerabilities to execute arbitrary code and gain administrative privileges on vulnerable computers. Failed exploit attempts may result in denial-of-service conditions.
18. Linux Kernel DVB Driver Local Buffer Overflow Vulnerability
BugTraq ID: 16142
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/16142
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. This issue is due to a flaw in the DVB (Digital Video Broadcasting) driver subsystem. This issue is exploitable only on computers with the affected DVB module compiled, enabled, and accessible to local malicious users.
A successful attack may result in a denial-of-service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
19. Microsoft Windows Server Driver Mailslot Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 18863
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/18863
Summary:
Microsoft Windows Server driver is prone to a remote heap buffer-overflow vulnerability. This issue is due to a failure of the software to properly bounds check user-supplied input prior to copying it to an insufficiently-sized memory buffer.
Exploiting this issue allows anonymous, remote attackers to execute arbitrary machine code in the context of the affected driver. This facilitates the complete compromise of affected computers.
Microsoft Windows XP SP2 and Microsoft Windows Server 2003 SP1 are not vulnerable to this issue in their default configuration.
20. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
BugTraq ID: 16141
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/16141
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. This issue is due to an off-by-one error in the 'sysctl' subsystem.
A successful attack may result in a denial-of-service condition or possibly arbitrary code execution in the context of the local kernel.
Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.
21. Linux Kernel ProcFS Kernel Memory Disclosure Vulnerability
BugTraq ID: 16284
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/16284
Summary:
The Linux kernel is affected by a local memory-disclosure vulnerability.
This issue allows an attacker to read kernel memory. Information gathered via exploitation may aid malicious users in further attacks.
This issue affects the 2.6 series of the Linux kernel, prior to 2.6.15.
22. Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
BugTraq ID: 18056
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/18056
Summary:
Cyrus IMAPD is prone to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly verify user-supplied input before copying it into a finite-sized buffer.
Successful exploits may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.
Cyrus IMAPD version 2.3.2 is reported to be vulnerable. Other versions may be affected as well.
23. Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
BugTraq ID: 19499
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19499
Summary:
The Novell eDirectory Server is prone to an information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.
24. Linux Kernel mq_open System Call Unspecified Denial of Service Vulnerability
BugTraq ID: 16283
Remote: No
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/16283
Summary:
Linux kernel 'mq_open()' system call is prone to a local denial-of-service vulnerability. Further information is not currently available. This record will be updated when more details are disclosed.
This issue affects Linux kernel 2.6.9. Earlier kernel versions may be affected.
25. YaBBSE Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19460
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19460
Summary:
A cross-site scripting vulnerability affects YaBBSE because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
26. Novell eDirectory Unspecified Nessus Denial of Service Vulnerability
BugTraq ID: 19498
Remote: Yes
Last Updated: 2006-08-14
Relevant URL: http://www.securityfocus.com/bid/19498
Summary:
The Novell eDirectory Server is prone to an unspecified denial-of-service vulnerability. The system experiences high CPU usage when it is subjected to a Nessus scan.
The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.
27. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
BugTraq ID: 16177
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/16177
Summary:
Dave Carrigan's auth_ldap is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in the format-specifier of a formatted printing function.
This issue likely arises only if auth_ldap has been enabled and is used for user authentication.
This issue allows remote attackers to execute arbitrary machine code in the context of Apache webservers that use the affected module. This may facilitate the compromise of affected computers.
28. MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities
BugTraq ID: 19427
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19427
Summary:
MIT Kerberos 5 is prone to multiple local privilege-escalation vulnerabilities because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels or with AIX operating systems.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
29. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
BugTraq ID: 19409
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19409
Summary:
Microsoft Windows Server Service is prone to a remote buffer-overflow vulnerability.
This vulnerability arises when the service processes a malicious message in RPC communications.
A successful attack may result in arbitrary code execution with SYSTEM privileges leading to a full compromise. Attack attempts may result in denial-of-service conditions as well.
Microsoft has reported that this issue is being exploited in the wild.
Update (August 14, 2006): A worm named 'W32.Wargbot' that exploits this issue to spread is currently in the wild.
30. WikiWebWeaver Index.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 19537
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19537
Summary:
WikiWebWeaver is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload malicious script code that will run in the context of the webserver process.
An attacker can exploit this issue by uploading and executing malicious PHP scripts.
31. HP-UX Support Tools Manager Unspecified Local Denial of Service Vulnerability
BugTraq ID: 18457
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/18457
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability when running Support Tools Manager.
This issue arises because the software fails to handle exceptional conditions in a proper manner.
A local attacker can exploit this issue to cause denial-of-service conditions.
Very little information is currently available on this issue; this BID will be updated as further information becomes available.
32. Opera Document Stylesheet Denial Of Service Vulnerability
BugTraq ID: 18758
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/18758
Summary:
Opera is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle user-supplied input.
An attacker can exploit this issue to crash an affected browser, effectively denying service.
33. HP-UX LP Subsystem Denial of Service Vulnerability
BugTraq ID: 19535
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19535
Summary:
HP-UX running the LP subsystem is prone to an unspecified remote denial-of-service vulnerability.
An attacker can exploit this issue to deny service to legitimate users.
This issue affects HP-UX versions B.11.00, B.11.04, B.11.11, and B.11.23.
34. Cisco PIX SIP Implementation Unauthorized UDP Port Forwarding Vulnerability
BugTraq ID: 19536
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19536
Summary:
Cisco PIX is reportedly prone to an unauthorized UDP port-forwarding vulnerability.
Attackers may exploit this issue to forward UDP datagrams to arbitrary hosts protected by affected firewall devices, potentially bypassing firewall rules. This may aid attackers in further attacks against computers protected by affected firewall devices.
Note that Cisco is investigating the vulnerability and so far has not been able to reproduce this issue.
This BID will be updated as further information becomes available.
35. SmartLine DeviceLock Unauthorized Access Vulnerability
BugTraq ID: 19500
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19500
Summary:
SmartLine DeviceLock is prone to an unauthorized access vulnerability because the application fails to apply proper access-control restrictions to various devices.
An attacker can exploit this issue to gain administrative privileges; other attacks are also possible.
Version 5.73 is vulnerable to this issue; other versions may also be affected.
36. NFS-SERVER Remote Buffer Overflow Vulnerability
BugTraq ID: 16388
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/16388
Summary:
The 'nfs-server' package is prone to a remote buffer-overflow vulnerability.
A remote attacker with the ability to create symlinks on any of the filesystems on an affected computer running 'rpc.mountd' can exploit this issue to execute arbitrary code. Attackers without filesystem access may also be able to execute arbitrary code, but this has not been confirmed.
Note that the 'nfs-server' package is obsolete. The 'nfs-utils' package is not affected by this issue.
37. Opera Web Browser CSS Background URI Memory Corruption Vulnerability
BugTraq ID: 19166
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19166
Summary:
Opera Web Browser is prone to a memory-corruption vulnerability.
A remote attacker may trigger this issue by enticing a user to visit a malicious website.
This issue has been reported in Opera 9. Other versions may be vulnerable as well.
38. Lizge Index.PHP Multiple Remote File Include Vulnerabilities
BugTraq ID: 19533
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19533
Summary:
Lizge is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version V.20 is vulnerable to these issues; other versions may also be affected.
39. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG version 1.4.4 is vulnerable to this issue; previous versions may also be affected.
40. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.
Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.
Note that there are other attack vectors that may not require user interaction, since the application can be used with custom printing systems and web applications.
A successful attack may crash the application or lead to arbitrary code execution.
All versions of ImageMagick are considered vulnerable at the moment.
41. ImageMagick Image Filename Remote Command Execution Vulnerability
BugTraq ID: 16093
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/16093
Summary:
ImageMagick is prone to a remote shell command-execution vulnerability.
Successful exploitation can allow arbitrary commands to be executed in the context of the affected user. Note that attackers could exploit this issue through other applications that use ImageMagick as the default image viewer.
ImageMagick 6.2.4.5 is reportedly vulnerable. Other versions may be affected as well.
42. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.
Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.
Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.
43. Apache HTTP Request Smuggling Vulnerability
BugTraq ID: 14106
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/14106
Summary:
Apache is prone to an HTTP-request-smuggling attack.
A specially crafted request with a 'Transfer-Encoding: chunked' header and a 'Content-Length' header can cause the server to forward a reassembled request with the original 'Content-Length' header. As a result, the malicious request may piggyback on the valid HTTP request.
This attack may result in cache poisoning, cross-site scripting, session hijacking, and other attacks.
This issue was originally described in BID 13873 (Multiple Vendor Multiple HTTP Request Smuggling Vulnerabilities). Since vendor confirmation and more details are available, the issue has now been assigned a new BID.
44. Apache mod_include Local Buffer Overflow Vulnerability
BugTraq ID: 11471
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/11471
Summary:
The problem presents itself when the affected module attempts to parse mod_include-specific tag values. A failure to properly validate the lengths of user-supplied tag strings before copying them into finite buffers facilitates the overflow.
A local attacker may leverage this issue to execute arbitrary code on the affected computer with the privileges of the affected Apache server.
45. LSH Seed File File Descriptor Leakage Vulnerability
BugTraq ID: 16357
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/16357
Summary:
lsh may leak file descriptors that may allow a local attacker to access sensitive information or to cause a denial-of-service condition.
lsh 2.0.1 is reportedly vulnerable. Other versions may be affected as well.
46. Discloser Multiple Remote File Include Vulnerabilities
BugTraq ID: 19532
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19532
Summary:
Discloser is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 0.0.4 is vulnerable to these issues; other versions may also be affected.
47. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
BugTraq ID: 19215
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19215
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability because the operating system fails to properly handle network traffic.
This issue may cause affected computers to crash, denying service to legitimate users.
Reports indicate that this issue may be currently exploited in the wild, but this has not been confirmed.
48. HP-UX Trusted Mode Unspecified Local Denial of Service Vulnerability
BugTraq ID: 19528
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19528
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability because the application fails to properly handle exceptional conditions.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.
49. Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
BugTraq ID: 19530
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19530
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users, and may cause arbitrary code to run within the context of the application.
50. Linux-HA Heartbeat Remote Denial of Service Vulnerability
BugTraq ID: 19516
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19516
Summary:
Linux-HA Heartbeat is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue results in crashing the master control process. This may result in the failure of services depending on the application's functionality.
51. OpenLDAP TLS Plaintext Password Vulnerability
BugTraq ID: 14125
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/14125
Summary:
OpenLDAP is affected by a password-disclosure vulnerability when used with TLS.
This issue arises when a connection to a slave is established using TLS and the client is referred to a master. TLS is not used with this connection, which can allow an attacker to sniff network traffic and obtain user credentials.
OpenLDAP 2.1.25 is known to be vulnerable at the moment. Other versions may be affected as well.
52. OpenLDAP Ambiguous Password Attribute Weakness
BugTraq ID: 11137
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/11137
Summary:
It is reported that in certain undisclosed cases, OpenLDAP is susceptible to an ambiguous password attribute weakness.
If an attacker is able to retrieve a password hash as contained in the OpenLDAP database, they are possibly able to directly authenticate to the LDAP database. An attacker is able to gain unauthorized access if they can sniff password hashes from the network, or retrieve the contents of the 'userPassword' attribute from a database backup, or through weak permissions on the database.
The OpenLDAP that is included with Apple Mac OS X, versions 10.3.4 and 10.3.5 is reported to be affected. Versions of OpenLDAP included in other operating systems are also possibly affected.
53. Multiple Vendor Dump File Locking Denial Of Service Vulnerability
BugTraq ID: 5264
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/5264
Summary:
It is possible for local attackers to create a denial of service by creating a file lock on files that the dump utility requires for normal operation. This may be exploited to effectively prevent dump from backing up files.
The process holding the file lock must be killed to resume normal operation.
54. PCRE Regular Expression Heap Overflow Vulnerability
BugTraq ID: 14620
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/14620
Summary:
PCRE is prone to a heap-overflow vulnerability. This issue is due to the library's failure to properly perform boundary checks on user-supplied input before copying data to an internal memory buffer.
The impact of successful exploitation of this vulnerability depends on the application and the user credentials using the vulnerable library. A successful attack may ultimately permit an attacker to control the contents of critical memory control structures and write arbitrary data to arbitrary memory locations.
55. HP-UX Mkdir Local Unauthorized Access Vulnerability
BugTraq ID: 18748
Remote: No
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/18748
Summary:
HP-UX mkdir is prone to a local unauthorized-access vulnerability.
This may facilitate various attacks, including information disclosure and potential code execution, leading to privilege escalation.
56. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because the application fails to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
57. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.
The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.
An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.
58. Horde Products Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19544
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19544
Summary:
Various Horde products are prone to a cross-site scripting vulnerability. This issue is due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
59. PHProjekt Multiple Remote File Include Vulnerabilities
BugTraq ID: 19541
Remote: Yes
Last Updated: 2006-08-16
Relevant URL: http://www.securityfocus.com/bid/19541
Summary:
Multiple remote file include vulnerabilities affect PHProjekt. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in a PHP 'include()' function call.
An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process.
Version 5.1 of PHProjekt is vulnerable to this issue; previous versions may be affected as well.
60. BusyBox Insecure Password Hash Weakness
BugTraq ID: 17330
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/17330
Summary:
BusyBox is prone to an insecure password-hash weakness. This issue is due to a design flaw that results in password hashes being created in an insecure manner.
This issue allows attackers to use precomputed password hashes in brute-force attacks if they can gain access to password hashes by some means (such as exploiting another vulnerability).
61. Microsoft Internet Explorer CHTSKDIC.DLL Denial Of Service Vulnerability
BugTraq ID: 19529
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19529
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users and may cause arbitrary code to run within the context of the user running the application.
62. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial-of-service vulnerability.
Local attackers can exploit this vulnerability to corrupt kernel memory or free non-allocated memory. Successful exploitation will crash the kernel, effectively denying service to legitimate users.
63. Linux Kernel POSIX Timer Cleanup Handling Local Denial of Service Vulnerability
BugTraq ID: 15722
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15722
Summary:
A local denial-of-service vulnerability affects the Linux kernel.
The vulnerability arises due to a race-condition error in the handling of POSIX timer cleanup routines.
A successful attack can result in a kernel crash.
Linux kernel versions 2.6.10 to 2.6.14 are vulnerable to this issue.
64. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
BugTraq ID: 19520
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19520
Summary:
Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability because the PNG-rendering portion of the operating system fails to handle malicious PNG (Portable Network Graphics) files.
This issue may cause Windows Explorer to consume excessive resources and crash, denying service to legitimate users.
65. Linux Kernel PTraced Child Auto-Reap Local Denial of Service Vulnerability
BugTraq ID: 15625
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15625
Summary:
Linux kernel is prone to a local denial-of-service vulnerability. The kernel improperly auto-reaps processes when they are being ptraced, leading to an invalid pointer. Further operations on this pointer result in a kernel crash.
This issue allows local users to crash the kernel, denying service to legitimate users.
A complete compromise of the affected computer has also been reported, but this has not been confirmed.
Kernel versions prior to 2.6.15 are vulnerable to this issue.
66. PHP-Nuke AutoHTML Module Local File Include Vulnerability
BugTraq ID: 19525
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19525
Summary:
PHP-Nuke AutoHTML Module is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to execute arbitrary local scripts within the context of the affected application.
67. WEBInsta Mailing List Manager InitDB.PHP Remote File Include Vulnerability
BugTraq ID: 19526
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19526
Summary:
WEBInsta Mailing List Manager is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
WEBInsta Mailing List Manager 1.3e and prior versions are reported vulnerable; other versions may also be affected.
68. Microsoft Internet Explorer IMSKDIC.DLL Denial Of Service Vulnerability
BugTraq ID: 19521
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19521
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users and may cause arbitrary code to run within the context of the application.
69. Linux Kernel do_coredump Denial of Service Vulnerability
BugTraq ID: 15723
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15723
Summary:
Linux kernel is prone to a denial-of-service vulnerability caused by a race condition in 'do_coredump()'.
Successful exploitation can cause the system to stop responding to legitimate requests.
70. IBM WebSphere Application Server Prior to 6.0.2.13 Multiple Vulnerabilities
BugTraq ID: 19527
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19527
Summary:
IBM WebSphere Application Server is prone to multiple unspecified vulnerabilities, including:
- multiple information-disclosure issues
- multiple security exposures of unknown impact
- a potential authority issue.
IBM WebSphere Application Server versions in the 6.0.2 series (prior to 6.0.2.13) are vulnerable to these issues.
71. Microsoft Winsock Gethostbyname Buffer Overflow Vulnerability
BugTraq ID: 19319
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19319
Summary:
The Microsoft Winsock API is prone to a buffer-overflow vulnerability.
This issue can occur when the API is invoked via a malicious file or web page that is sufficient to trigger the vulnerability. If the exploit is successful, attacker-supplied code will execute, completely compromising the affected computer.
72. Microsoft Windows DNS Client Buffer Overrun Vulnerability
BugTraq ID: 19404
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19404
Summary:
Microsoft Windows is prone to a remotely exploitable buffer overrun condition in the DNS client.
This issue is exposed when a client handles a malicious response from a DNS server. Attackers may leverage this to execute arbitrary code and launch a complete compromise of the affected computer.
73. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19488
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19488
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability. This issue is due to a race condition that may result in double-free or other memory-corruption issues.
Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.
Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.
74. Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability
BugTraq ID: 19414
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19414
Summary:
A vulnerability has been discovered in Microsoft Visual Basic for Applications. The vulnerability occurs due to insufficient bounds checking when checking the properties of malicious documents. As a result, a malformed document may be able to trigger a buffer-overflow within the affected application, effectively allowing for the execution of arbitrary code.
Microsoft Office, Access, Visio, Word, and Works are also reportedly attack vectors, since they employ VBA when handling certain document types. Email is another potential attack vector for this vulnerability, but merely opening an email would not trigger the issue; replying or forwarding the message could potentially trigger it.
Microsoft has reported that this issue is being exploited in the wild.
75. NCompress Decompress Buffer Underflow Vulnerability
BugTraq ID: 19455
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19455
Summary:
The ncompress utility is prone to a buffer-underflow vulnerability. When ncompress decompresses data, it fails to perform appropriate bounds checking, which may allow certain decompress operations to underflow an internal buffer. This may cause unpredictable effects on vulnerable systems.
Version 4.2.4 is reportedly vulnerable to this issue; earlier versions may be affected as well.
76. Wireshark Protocol Dissectors Multiple Vulnerabilities
BugTraq ID: 19051
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19051
Summary:
Wireshark is prone to multiple vulnerabilities:
- A format-string vulnerability.
- An off-by-one vulnerability.
- An infinite-loop vulnerability.
- A memory-allocation vulnerability.
These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.
77. Spidey Blog Script PID Parameter SQL Injection Vulnerability
BugTraq ID: 19518
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19518
Summary:
Spidey Blog Script is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Spidey Blog Script 1.5 and prior versions are reported to be affected.
78. Ruby on Rails Routing Denial of Service Vulnerability
BugTraq ID: 19454
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19454
Summary:
Ruby on Rails is prone to a vulnerability in its routing functionality that may result in denial-of-service or data loss issues.
Attackers may exploit this issue by issuing HTTP GET requests to predictable URIs to affected webservers.
This issue affects Ruby on Rails versions 1.1.0, 1.1.1, 1.1.2, 1.1.4, and 1.1.5.
79. phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
BugTraq ID: 19517
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19517
Summary:
phPay is prone to a remote open-mail-relay vulnerability because the application fails to properly sanitize user-supplied input before using it to generate email messages.
An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from trusted mail servers.
80. Microsoft Windows HTML Help HHCtrl ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 18769
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/18769
Summary:
Microsoft Windows HTML Help is prone to a memory-corruption vulnerability. This is related to the handling of the HHCtrl ActiveX control.
Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.
81. Joomla Webring Component Admin.Webring.Docs.PHP SQL Injection Vulnerability
BugTraq ID: 19511
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19511
Summary:
The Joomla Webring component is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.0 is vulnerable to this issue; other versions may also be affected.
82. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.
Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.
This issue affects Apache 2.x versions.
83. BlaBla 4U Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19513
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19513
Summary:
Multiple cross-site scripting vulnerabilities affect BlaBla 4U because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
84. Apache MPM Worker.C Denial Of Service Vulnerability
BugTraq ID: 15762
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15762
Summary:
Apache is prone to a memory leak that may cause a denial-of-service condition.
An attacker may consume excessive memory resources, resulting in a denial of service for legitimate users.
Apache 2.x versions are vulnerable; other versions may also be affected.
85. Linux-HA Heartbeat Insecure Default Permissions on Shared Memory Vulnerability
BugTraq ID: 19186
Remote: No
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19186
Summary:
Since Linux-HA Heartbeat has insecure default permissions set on shared memory, local attackers may be able to cause a denial of service.
Exploitation would most likely result in a system crash, loss of data, and resource exhaustion, leading to a denial of service if critical files are accessed improperly or overwritten in the attack. Other attacks may be possible as well.
86. VWar Multiple Input Validation Vulnerabilities
BugTraq ID: 19327
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19327
Summary:
Vwar is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection issues. These issues occur because the application fails to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
87. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 16389
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/16389
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
88. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
BugTraq ID: 15761
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15761
Summary:
phpMyAdmin is prone to a vulnerability that permits an attacker to overwrite global variables.
An attacker can exploit this issue to overwrite the global variables with arbitrary input. Through control of the global variables, the attacker may be able to include arbitrary remote and local files depending on the current PHP version. Various other attacks are also possible.
89. Mambo Email Publisher Help.MMP.PHP Remote File Include Vulnerability
BugTraq ID: 19502
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19502
Summary:
Mambo eMail Publisher is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 1.2 is vulnerable to this issue; other versions may also be affected.
90. Microsoft Management Console Zone Bypass Vulnerability
BugTraq ID: 19417
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19417
Summary:
Microsoft Management Console (MMC) is prone to a cross-zone scripting vulnerability because the operating system fails to properly restrict access to MMC components, allowing the MMC files to be referenced from the Internet Zone in some cases.
This vulnerability could let an attacker execute arbitrary code, completely compromising the computer.
91. Libmusicbrainz Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19508
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19508
Summary:
The libmusicbrainz library is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer.
An attacker can exploit these issues to execute arbitrary code within the context of the application or to cause a denial-of-service condition.
Versions 2.1.2, SVN 8406, and prior are vulnerable to this issue; other versions may also be affected.
92. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15735
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/15735
Summary:
The phpMyAdmin tool is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
93. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19507
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19507
Summary:
ImageMagick is prone to a remote heap buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.
ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.
94. GNU Mailman Large Date Data Denial Of Service Vulnerability
BugTraq ID: 16248
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/16248
Summary:
GNU Mailman is prone to a denial-of-service attack. This issue affects Mailman's email date parsing.
The vulnerability could be triggered by mailing-list posts and will impact the availability of mailing lists hosted by the application.
95. Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability
BugTraq ID: 11826
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/11826
Summary:
Microsoft Internet Explorer is reported prone to an arbitrary FTP server command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied URI input before using it to execute FTP commands on remote servers.
This vulnerability allows attackers to embed arbitrary FTP server commands in malicious URIs. Upon following this malicious URI, the victim user's browser will reportedly connect to the attacker-specified FTP server, and the malicious commands will be sent to the server. This may allow malicious files to be downloaded to the victim's computer without their knowledge. Other attacks are also likely possible.
Note: Reportedly, this issue can be leveraged to send email to arbitrary addresses without user interaction.
96. Microsoft Internet Explorer Window Location Cross-Domain Information Disclosure Vulnerability
BugTraq ID: 19339
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19339
Summary:
Microsoft Internet Explorer is prone to a cross-domain information-disclosure vulnerability.
This vulnerability may let a malicious website access properties of a site in an arbitrary external domain. Attackers could exploit this issue to gain access to sensitive information that is associated with the external domain.
97. Microsoft Internet Explorer Frameset Memory Corruption Vulnerability
BugTraq ID: 18277
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/18277
Summary:
Microsoft Internet Explorer is affected by a memory-corruption vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner.
An attacker may exploit this issue by enticing a user to visit a malicious site and then to click anywhere on the page. This results in a denial-of-service condition in the application.
The vendor reports this issue may also be exploited to execute arbitrary code in the context of the victim user.
98. Microsoft Internet Explorer Source Element Cross-Domain Information Disclosure Vulnerability
BugTraq ID: 19400
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19400
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain policies.
This issue may allow attackers to access arbitrary websites in the context of a targeted user's browser session. This may allow attackers to perform actions in web applications with the privileges of exploited users or to gain access to potentially sensitive information. This may aid attackers in further attacks.
99. Microsoft Internet Explorer Chained Cascading Style Sheets Remote Code Execution Vulnerability
BugTraq ID: 19316
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19316
Summary:
Microsoft Internet Explorer is prone to remote code-execution vulnerability.
This issue is related to how the browser handles chained CSS (Cascading Style Sheets). An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.
This issue affects Internet Explorer on Windows 2000, Windows XP (excluding XP SP2), and Windows Server 2003.
100. Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability
BugTraq ID: 19340
Remote: Yes
Last Updated: 2006-08-15
Relevant URL: http://www.securityfocus.com/bid/19340
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability that is related to the instantiation of COM objects. This issue stems from a design error.
The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution. The affected objects are not intended to be instantiated through Internet Explorer.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Bot spreads using latest Windows flaw
By: Robert Lemos
Security firms advise companies and home users to patch their Windows systems after detecting a bot program using a recently fixed flaw to compromise computers.
http://www.securityfocus.com/news/11407
2. Covert channel tool hides data in IPv6
By: Robert Lemos
Announced at the DEFCON hacking conference, a tool dubbed VoodooNet hides a small amount of data in IPv6 error messages, where most security devices do not even look.
http://www.securityfocus.com/news/11406
3. Researchers warn over Web worms
By: Robert Lemos
Exploiting a lack of security checks in browsers and Web servers, Web worms and viruses are likely to become a major threat to surfers.
http://www.securityfocus.com/news/11405
4. Attackers pass on OS, aim for drivers and apps
By: Robert Lemos
The low hanging fruit for vulnerability researchers is no longer found in the operating system, but among common applications and device drivers, say flaw finders.
http://www.securityfocus.com/news/11404
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443368
2. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443371
3. [SJ-JOB] Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/443365
4. [SJ-JOB] Technology Risk Consultant, Herndon
http://www.securityfocus.com/archive/77/443366
5. [SJ-JOB] Incident Handler, Arlington
http://www.securityfocus.com/archive/77/443370
6. [SJ-JOB] Security Consultant, Denver
http://www.securityfocus.com/archive/77/443349
7. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/443350
8. [SJ-JOB] Security Consultant, philadelphia
http://www.securityfocus.com/archive/77/443348
9. [SJ-JOB] Security Engineer, Raleigh
http://www.securityfocus.com/archive/77/443351
10. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/443347
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Security contact from Critical Path Inc
http://www.securityfocus.com/archive/82/443223
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Licensed Software Audit
http://www.securityfocus.com/archive/88/443369
2. Workstation Shutdown / Logoff Policy
http://www.securityfocus.com/archive/88/443340
3. Local Security Policy screen can't retrieve sec policy information
http://www.securityfocus.com/archive/88/443100
4. Impact of removing administrative rights in an enterprise running XP
http://www.securityfocus.com/archive/88/441275
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus