SecurityFocus Newsletter #364

Peter Laborge <[email protected]> Tue, 22 Aug 2006 17:19:12 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #364
----------------------------------------

This issue is Sponsored by: SPI Dynamics

ALERT:  "How A Hacker Launches A Feed Injection Attack!" - SPI Dynamics White Paper
Learn the risks associated with Feed Injection of Atom and RSS feeds, including Cross-Site Scripting, Cross-Site Request Forgery, and Keystroke Logging.
Download *FREE* white paper from SPI Dynamics.

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CaO4

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. LinuxWorld, virtually speaking
        2. Microsoft Office security, part one
II.   BUGTRAQ SUMMARY
        1. Modernbill Config.PHP Remote File Include Vulnerability
        2. Symantec Enterprise Security Manager Denial of Service Vulnerability
        3. DieselScript Smart Traffic Index.PHP Remote File Include Vulnerability
        4. Plume CMS Multiple Remote File Include Vulnerabilities
        5. Eichhorn Portal Multiple Input Validation Vulnerabilities
        6. ToendaCMS TCMS_Administer Parameter Remote File Include Vulnerability
        7. Mambo EstateAgent Component mosConfig_absolute_path Remote File Include Vulnerability
        8. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
        9. DieselScripts Job Site Forgot.PHP Multiple Cross-Site Scripting Vulnerabilities
        10. Mambo Display MOSBot Manager Component mosConfig_absolute_path Remote File Include Vulnerability
        11. WebAdmin Module for MDaemon Information Disclosure Vulnerability
        12. PHPCodeGenie Core.PHP Remote File Include Vulnerability
        13. WFTPD Server Multiple Buffer Overflow Vulnerabilities
        14. Mambo BigAPE-Backup Component Remote File Include Vulnerability
        15. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
        16. Fantastic Scripts Fantastic News Remote File Include Vulnerability
        17. Tutti Nova Multiple Remote File Include Vulnerabilities
        18. NES Game and NES System Multiple Remote File Include Vulnerabilities
        19. SportsPHool Remote File Include Vulnerability
        20. Shadows Rising RPG Multiple Remote File Include Vulnerabilities
        21. LBlog Comments.ASP SQL Injection Vulnerability
        22. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
        23. XennoBB Icon_Topic SQL Injection Vulnerability
        24. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
        25. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
        26. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
        27. PHP Multiple Unspecified Vulnerabilities
        28. SquirrelMail Search.PHP Cross-Site Scripting Vulnerability
        29. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
        30. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
        31. Mozilla Firefox Large History File Buffer Overflow Vulnerability
        32. Linux Kernel UDF Denial of Service Vulnerability
        33. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
        34. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
        35. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
        36. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
        37. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
        38. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        39. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
        40. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
        41. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
        42. GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability
        43. Sun Solaris SysInfo Local Information Disclosure Vulnerability
        44. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
        45. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
        46. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
        47. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
        48. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
        49. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
        50. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
        51. CPanel Multiple Cross-Site Scripting Vulnerabilities
        52. OScommerce Shopping_cart.PHP SQL Injection Vulnerability
        53. FreeType LWFN Files Buffer Overflow Vulnerability
        54. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
        55. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
        56. Mozilla Multiple Products Remote Vulnerabilities
        57. OpenSSH SCP Shell Command Execution Vulnerability
        58. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
        59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
        60. Linux Kernel s/io.c/IO.C Local Denial of Service Vulnerability
        61. Linux Kernel Non-Hugemem Support Local Denial of Service Vulnerability
        62. AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
        63. RedBlog Index.PHP Remote File Include Vulnerability
        64. Doika Guestbook GBook.PHP HTML Injection Vulnerability
        65. Empire CMS Checklevel.PHP Remote File Include Vulnerability
        66. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
        67. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
        68. Business Management Systems Dolphin Remote File Include Vulnerability
        69. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
        70. RETIRED: SPAW PHP Editor Multiple Remote File Include Vulnerabilities
        71. Sendmail Malformed MIME Message Denial Of Service Vulnerability
        72. PHProjekt Content Management Module Multiple Remote File Include Vulnerabilities
        73. PHP 5 User-Supplied Session ID Input Validation Vulnerability
        74. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
        75. Multiple Docebo Products Multiple Remote File Include Vulnerabilities
        76. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
        77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
        78. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
        79. Mobotix IP Camera Multiple Cross-Site Scripting Vulnerabilities
        80. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
        81. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
        82. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
        83. PHP Error Message Cross-Site Scripting Vulnerability
        84. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
        85. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
        86. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities
        87. Headline Portal Engine HPEInc Parameter Multiple Remote File Include Vulnerabilities
        88. Sun Solaris Format(1M) Buffer Overflow Vulnerability
        89. TikiWiki Highlight Cross-Site Scripting Vulnerability
        90. CityForFree Indexcity List.PHP SQL Injection Vulnerability
        91. CityForFree Indexcity Cross-Site Scripting Vulnerability
        92. Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
        93. Sun Solaris Format(1M) Local Privilege Escalation Vulnerability
        94. DieselScripts Diesel Paid Mail Getad.PHP Cross-Site Scripting Vulnerability
        95. Sun Solaris File System Management RBAC Profile Arbitrary Command Execution Vulnerability
        96. Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
        97. Woltlab Burning Board Attachment.php HTML Injection Vulnerability
        98. Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
        99. 2wire Modems and Routers CRLF Denial of Service Vulnerability
        100. WebAdmin Module for MDaemon Unspecified Privilege Escalation Vulnerability
III.  SECURITYFOCUS NEWS
        1. Microsoft patch opens users to attack
        2. Bot spreads using latest Windows flaw
        3. Covert channel tool hides data in IPv6
        4. Researchers warn over Web worms
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Security Consultant, Middletown, Bedminster
        2. [SJ-JOB] Quality Assurance, Cupertino
        3. [SJ-JOB] Security Engineer, Kirkland
        4. [SJ-JOB] Technical Support Engineer, Cupertino
        5. [SJ-JOB] Software Engineer, Columbia
        6. [SJ-JOB] Principal Software Engineer, Columbia
        7. [SJ-JOB] Software Engineer, Columbia
        8. [SJ-JOB] Security Engineer, Schaumburg
        9. [SJ-JOB] Sales Representative, Boston
        10. [SJ-JOB] Database Security Engineer, New York
        11. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
        12. [SJ-JOB] Sales Engineer, New York City
        13. [SJ-JOB] Security Architect, Schaumburg
        14. [SJ-JOB] Security System Administrator, Toronto
        15. [SJ-JOB] Security Researcher, Bay Area
        16. [SJ-JOB] Database Security Architect, New York
        17. [SJ-JOB] Security System Administrator, Schaumburg
        18. [SJ-JOB] Auditor, New York
        19. [SJ-JOB] Security Engineer, Kirkland
        20. [SJ-JOB] Software Engineer, Redwood Shores
        21. [SJ-JOB] Software Engineer, Burlington
        22. [SJ-JOB] Security Engineer, Tampa
        23. [SJ-JOB] Sales Engineer, Plano
        24. [SJ-JOB] Security Engineer, Reston
        25. [SJ-JOB] Security Engineer, Nashville
        26. [SJ-JOB] Sales Engineer, Boston
        27. [SJ-JOB] Security Engineer, miami
        28. [SJ-JOB] Sales Engineer, Herndon
        29. [SJ-JOB] Sales Engineer, Atlanta
        30. [SJ-JOB] Senior Software Engineer, Bethesda
        31. [SJ-JOB] Sales Engineer, New York
        32. [SJ-JOB] Channel / Business Development, San Francisco
        33. [SJ-JOB] Sales Engineer, New York
        34. [SJ-JOB] Sales Engineer, Chicago
        35. [SJ-JOB] Security Director, Dallas area
        36. [SJ-JOB] Manager, Information Security, New York
        37. [SJ-JOB] Security System Administrator, Jersey City
        38. [SJ-JOB] Principal Software Engineer, San Francisco
        39. [SJ-JOB] Software Engineer, New York City
        40. [SJ-JOB] Account Manager, Orlando
        41. [SJ-JOB] Security System Administrator, New York
        42. [SJ-JOB] Jr. Security Analyst, Bangalore
        43. [SJ-JOB] Quality Assurance, Redwood Shores
        44. [SJ-JOB] Security Consultant, Houston
        45. [SJ-JOB] Security Engineer, Jersey City
        46. [SJ-JOB] Management, Alameda
        47. [SJ-JOB] Technical Support Engineer, Burlington
        48. [SJ-JOB] Penetration Engineer, McLean
        49. [SJ-JOB] Principal Software Engineer, Crystal Lake
        50. [SJ-JOB] Senior Software Engineer, Barcelona
        51. [SJ-JOB] Security Consultant, Houston
        52. [SJ-JOB] Security System Administrator, Plymouth or London
        53. [SJ-JOB] Security Consultant, Houston
        54. [SJ-JOB] Account Manager, San Diego
        55. [SJ-JOB] Management, Tampa
        56. [SJ-JOB] Security Architect, Richmond
        57. [SJ-JOB] Security Researcher, Renton
        58. [SJ-JOB] Developer, Cupertino
        59. [SJ-JOB] Forensics Engineer, washington
        60. [SJ-JOB] Developer, Cupertino
        61. [SJ-JOB] Developer, Cupertino
        62. [SJ-JOB] Jr. Security Analyst, Cupertino
        63. [SJ-JOB] Sr. Security Analyst, Cupertino
        64. [SJ-JOB] Security Auditor, Lanham
        65. [SJ-JOB] Security Engineer, Lanham
        66. [SJ-JOB] Security Consultant, Any Major U.S. City
        67. [SJ-JOB] Security Consultant, Any Major U.S. City
        68. [SJ-JOB] Security Auditor, Cupertino
        69. [SJ-JOB] Principal Software Engineer, San Diego
        70. [SJ-JOB] Penetration Engineer, Napa
        71. [SJ-JOB] Security Engineer, Cupertino
        72. [SJ-JOB] Technology Risk Consultant, Herndon
        73. [SJ-JOB] Incident Handler, Arlington
        74. [SJ-JOB] Security Consultant, Denver
        75. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
        76. [SJ-JOB] Security Consultant, philadelphia
        77. [SJ-JOB] Security Engineer, Raleigh
        78. [SJ-JOB] Sales Engineer, Boston
V.    INCIDENTS LIST SUMMARY
        1. Major updates in PowerPoint FAQ document - not a 0-day issue
        2. New PowerPoint 0-day and Trojan - FAQ document available
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Skype API Ap2Ap Stream Creation Flaw
        2. ToorCon 8 Call for Papers Closing Tomorrow & Workshops/Seminars Added
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. SecurityFocus Microsoft Newsletter #304
        2. Licensed Software Audit
        3. Workstation Shutdown / Logoff Policy
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. Linux Audit
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. LinuxWorld, virtually speaking
By Scott Granneman
With all the free virtual machines out there running security software or acting as virtual security appliances, you'd think VMWare is on everyone's mind. Scott Granneman offers some thoughts at the close of this year's LinuxWorld.
http://www.securityfocus.com/columnists/413

2. Microsoft Office security, part one
By Khushbu Jithra
This article discusses Microsoft Office's OLE Structured Storage and the nature of recent dropper programs and other exploit agents, in an effort to scrutinize the workings of some of the recent MS Office exploits. Part two will then collates some forensic investigation avenues through different MS Office features. Parts of the article sample different MS Office vulnerabilities to discuss their nature and the method of exploitation.
http://www.securityfocus.com/infocus/1874


II.  BUGTRAQ SUMMARY
--------------------
1. Modernbill Config.PHP Remote File Include Vulnerability
BugTraq ID: 19335
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19335
Summary:
Modernbill is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 1.6 is vulnerable to this issue; other versions may also be affected.

2. Symantec Enterprise Security Manager Denial of Service Vulnerability
BugTraq ID: 19580
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19580
Summary:
Symantec Enterprise Security Manager is prone to a denial-of-service vulnerability; fixes are available.

Symantec Enterprise Security Manager is susceptible to a race condition that can cause the application to lock up, resulting in a denial-of-service.

ESM Agent and Manager Platforms 6.0-6.5x are affected by this vulnerability.

3. DieselScript Smart Traffic Index.PHP Remote File Include Vulnerability
BugTraq ID: 19630
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19630
Summary:
Smart Traffic is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

4. Plume CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 19629
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19629
Summary:
Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

5. Eichhorn Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 19627
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19627
Summary:
Eichhorn Portal is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

6. ToendaCMS TCMS_Administer Parameter Remote File Include Vulnerability
BugTraq ID: 19626
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19626
Summary:
ToendaCMS is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects ToendaCMS 1.0.3 and prior; other versions may also be affected.

7. Mambo EstateAgent Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19625
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19625
Summary:
The Mambo EstateAgent component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

8. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19623
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19623
Summary:
DieselPay is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

9. DieselScripts Job Site Forgot.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19622
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19622
Summary:
Multiple cross-site scripting vulnerabilities affect Job Site because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

10. Mambo Display MOSBot Manager Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19621
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19621
Summary:
The Mambo Display MOSBot Manager component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

11. WebAdmin Module for MDaemon Information Disclosure Vulnerability
BugTraq ID: 19620
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19620
Summary:
The WebAdmin Module for MDaemon is prone to an information-disclosure vulnerability because it fails to sanitize user-supplied input.

An attacker can exploit this issue to disclose sensitive information, which could lead to other attacks.

Versions 3.00 to 3.24 are reported vulnerable; other versions may also be affected.

12. PHPCodeGenie Core.PHP Remote File Include Vulnerability
BugTraq ID: 19618
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19618
Summary:
phpCodeGenie is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Version 3.0.2 is vulnerable to this issue; other versions may also be affected.

13. WFTPD Server Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19617
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19617
Summary:
WFTPD is prone to multiple buffer-overflow vulnerabilities. These issues are due to a failure in the application to do proper bounds checking on user-supplied data before storing it in finite sized buffers.

An attacker can exploit these issues to execute arbitrary code and gain unauthorized remote access to a computer.  Denial-of-service conditions due to attack attempts may arise as well.

WFTPD 3.23 is reported to be vulnerable.  Other versions may also be affected.

14. Mambo BigAPE-Backup Component Remote File Include Vulnerability
BugTraq ID: 19616
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19616
Summary:
The Mambo bigAPE-Backup component is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 1.x and prior are vulnerable to this issue; other versions may also be affected.

15. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service.

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

16. Fantastic Scripts Fantastic News Remote File Include Vulnerability
BugTraq ID: 19613
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19613
Summary:
Fantastic News is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Fantastic News 2.1.3 is vulnerable; other versions may also be affected.

17. Tutti Nova Multiple Remote File Include Vulnerabilities
BugTraq ID: 19612
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19612
Summary:
Tutti Nova is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Tutti Nova 1.6 is vulnerable; other versions may also be affected.

18. NES Game and NES System Multiple Remote File Include Vulnerabilities
BugTraq ID: 19611
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19611
Summary:
NES Game and NES System is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

NES Game and NES System version c108122 is vulnerable; other versions may also be affected.

19. SportsPHool Remote File Include Vulnerability
BugTraq ID: 19610
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19610
Summary:
SportsPHool is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

SportsPHool version 1.0 is vulnerable; other versions may also be affected.

20. Shadows Rising RPG Multiple Remote File Include Vulnerabilities
BugTraq ID: 19608
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19608
Summary:
Shadows Rising RPG is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Shadows Rising RPG (Pre-Alpha) 0.0.5b is vulnerable; other versions may also be affected.

21. LBlog Comments.ASP SQL Injection Vulnerability
BugTraq ID: 19607
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19607
Summary:
LBlog is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

LBlog 1.05 and prior versions are affected by this issue.

22. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

It has been reported that the Flock web browser version 0.7.4.1 and                          the K-Meleon web browser version 1.0.1 are also vulnerable.

23. XennoBB Icon_Topic SQL Injection Vulnerability
BugTraq ID: 19606
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19606
Summary:
XennoBB is prone to an SQL injection vulnerability which could allow an attacker to influence the structure or logic of SQL queries made by the application.

24. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19605
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19605
Summary:
The Mambo CropImage component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

25. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19604
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19604
Summary:
The Mambo CatalogShop component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

26. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19602
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19602
Summary:
The Mambo AkoComment module is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

27. PHP Multiple Unspecified Vulnerabilities
BugTraq ID: 17843
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17843
Summary:
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.

The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.

Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.

28. SquirrelMail Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18700
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18700
Summary:
SquirrelMail is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

29. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
BugTraq ID: 15523
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15523
Summary:
IPsec-Tools is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions when in 'AGGRESSIVE' mode.

An attacker can exploit this issue to crash the application, thus denying service to legitimate users.

These vulnerabilities were discovered by, and may be reproduced by, the University of Oulu Secure Programming Group PROTOS IPSec Test Suite.

30. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 17000
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17000
Summary:
Microsoft Office is prone to a remote buffer-overflow vulnerability.

This vulnerability occurs when the application handles a specially crafted document. A successful attack can result in a remote compromise in the context of an affected user.

Update: This issue is known to be exploited in the wild by malware. In particular, 'Trojan.PPDropper' is known to exploit this issue.

31. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.

This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.

This may cause a denial-of-service condition.

**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.

32. Linux Kernel UDF Denial of Service Vulnerability
BugTraq ID: 19562
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19562
Summary:
The Linux kernel UDF file module is prone to a denial-of-service.

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

33. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Multiple Mozilla products are prone to a script-execution vulnerability.

The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.

The following mozilla products are vulnerable to this issue:
- Mozilla Thunderbird, versions prior to 1.5.0.2, and prior to 1.0.8
- Mozilla SeaMonkey, versions prior to 1.0.1
- Mozilla Suite, versions prior to 1.7.13

34. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

35. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

36. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is prone to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.

These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.

The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.

37. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability.

This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users.

Kernel versions prior to 2.6.16.18 are vulnerable to this issue.

38. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel versions 2.6.17.3 and prior are affected by this issue.

39. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability because of a race-condition in the 'proc' filesystem.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

The 2.6 series of the Linux kernel is vulnerable to this issue.

40. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

41. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

42. GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability
BugTraq ID: 11287
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/11287
Summary:
GNU Troff ('groff') is affected by an insecure temporary file-creation vulnerability. This issue is due to a design error that causes the application to fail to verify the presence of a file before writing to it.

An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation.

43. Sun Solaris SysInfo Local Information Disclosure Vulnerability
BugTraq ID: 19104
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19104
Summary:
Sun Solaris is prone to a local information-disclosure vulnerability because the kernel fails to properly ensure that unintended memory is not disclosed to local users.

This issue allows local attackers to gain access to potentially sensitive kernel memory. Information harvested by exploiting this issue may aid attackers in further attacks.

44. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.

Specific details of these issues are not currently available. This record will be updated when more information becomes available.

The following are vulnerable:

- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier

45. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

46. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
BugTraq ID: 19520
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19520
Summary:
Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability because the PNG-rendering portion of the operating system fails to handle malicious PNG (Portable Network Graphics) files.

This issue may cause Windows Explorer to consume excessive resources and crash, denying service to legitimate users.

47. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

48. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.

This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

49. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.

Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.

The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.

Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.

50. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
BugTraq ID: 19215
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19215
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability because the operating system fails to properly handle network traffic.

This issue may cause affected computers to crash, denying service to legitimate users.

Reports indicate that this issue may be currently exploited in the wild, but this has not been confirmed.

51. CPanel Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19624
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19624
Summary:
cPanel is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

52. OScommerce Shopping_cart.PHP SQL Injection Vulnerability
BugTraq ID: 19644
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19644
Summary:
OSCommerce is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before being used as input to SQL queries.

A  successful exploit could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

53. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

54. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
BugTraq ID: 18308
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18308
Summary:
Multiple web browsers are prone to a JavaScript key-filtering vulnerability. This issue is due to the failure of the browsers to securely handle keystroke input from users.

This issue is demonstrated to allow attackers to divert keystrokes from one input form in a webpage to a hidden file-upload dialog in the same page. This may allow remote attackers to initiate file uploads from unsuspecting users. Other attacks may also be possible.

Exploiting this issue requires that users manually type the full path of files that attackers wish to download. This may require substantial typing from targeted users, so attackers will likely use keyboard-based games, blogs, or other similar pages to entice users to enter the required keyboard input to exploit this issue.

Reportedly, Mozilla Suite, Mozilla Firefox, Mozilla SeaMonkey, Netscape Navigator, and Microsoft Internet Explorer are all vulnerable to this issue.

55. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2

56. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

57. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because the application fails to properly sanitize user-supplied input before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.

58. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
BugTraq ID: 19667
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19667
Summary:
Microsoft Internet Explorer is prone to a remote buffer-overflow vulnerability. A successful exploit may result in arbitrary code-execution in the context of the user running the browser.

This issue was introduced with the patches released with Microsoft advisory MS06-042.

Internet Explorer 6 SP1 running on Microsoft Windows 2000 and Windows XP SP1 is vulnerable to this issue.

59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
BugTraq ID: 19666
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19666
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

  An attacker can exploit this issue to execute arbitrary codel. Successfully exploiting this issue would cause the complete compromise of the affected computer.

Versions prior to 2.6.17.10 of the 2.6 series and versions prior to 2.4.33.2 of the 2.4 series are vulnerable to this issue.

60. Linux Kernel s/io.c/IO.C Local Denial of Service Vulnerability
BugTraq ID: 19665
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19665
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the direct IO driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects the Linux kernel 2.6 series prior to 2.6.10.

61. Linux Kernel Non-Hugemem Support Local Denial of Service Vulnerability
BugTraq ID: 19664
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19664
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the code which handles support for 'non-hugemem' kernels.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

62. AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
BugTraq ID: 19659
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19659
Summary:
AK-Systems Windows Terminals are prone to a remote unauthorized administrative access vulnerability. This issue is due to a lack of authentication requirements for remote administrative access to affected devices.

This issue allows remote attackers to gain administrative access on affected devices without requiring authentication. This allows attackers to compromise affected devices, and monitor or access RDP and Citrix sessions on targeted devices.

Devices with firmware version 1.2.5 ExVLP are vulnerable to this issue. Other versions may also be affected.

63. RedBlog Index.PHP Remote File Include Vulnerability
BugTraq ID: 19658
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19658
Summary:
RedBLoG is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 0.5; other versions may also be vulnerable.

64. Doika Guestbook GBook.PHP HTML Injection Vulnerability
BugTraq ID: 19656
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19656
Summary:
Doika Guestbook is prone to an HTML-injection vulnerability. An attacker may inject hostile HTML and script code into vulnerable sections of the application. When viewed, this code may be rendered in the browser of a user visiting the site in the context of the affected website.

65. Empire CMS Checklevel.PHP Remote File Include Vulnerability
BugTraq ID: 19655
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19655
Summary:
Empire CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Versions 3.7 and prior are vulnerable to this issue; other versions may also be affected.

66. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19650
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19650
Summary:
Links Manager is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

67. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
BugTraq ID: 19649
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19649
Summary:
Links Manager is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before being used as input to SQL queries.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

68. Business Management Systems Dolphin Remote File Include Vulnerability
BugTraq ID: 19648
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19648
Summary:
Business Management Systems Dolphin is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 5.2 is vulnerable to this issue; other versions may also be affected.

69. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 19415
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19415
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations and potentially execute code.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, all assuming that the 'safe_mode' restriction will isolate the users from each other.

This issue is reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.

70. RETIRED: SPAW PHP Editor Multiple Remote File Include Vulnerabilities
BugTraq ID: 19603
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19603
Summary:
SPAW PHP Editor is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.

A successful exploit may allow an attacker to execute remote PHP code in the context of the web server process. This may allow the attacker to compromise the application or to gain access to the underlying system.

This BID has been retired.

71. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

72. PHProjekt Content Management Module Multiple Remote File Include Vulnerabilities
BugTraq ID: 19628
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19628
Summary:
Multiple remote file-include vulnerabilities affect the Content Management module for PHProjekt because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call.

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process.

These issues affect version 0.6.1; earlier versions may also be vulnerable.

73. PHP 5 User-Supplied Session ID Input Validation Vulnerability
BugTraq ID: 16220
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/16220
Summary:
PHP 5 is prone to an input-validation vulnerability. This is due to a lack of proper sanitization of user-supplied input of PHP session IDs, transmitted by way of HTTP headers.

An attacker may use this vulnerability to perform HTTP response splitting, often resulting in content spoofing and cross-site scripting attacks.

PHP 5 version 5.1.1 and prior are affected.

74. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 19251
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19251
Summary:
Taskjitsu is prone to multiple cross-site scripting vulnerabilities.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Taskjitsu 2.03 and earlier are vulnerable to this issue.

75. Multiple Docebo Products Multiple Remote File Include Vulnerabilities
BugTraq ID: 18109
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18109
Summary:
Docebo is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Docebo versions 3.0.4 and prior are vulnerable to these issues.

76. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
BugTraq ID: 18850
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18850
Summary:
Ubuntu Linux passwd may allow local attackers to gain elevated privileges. A successful attack may lead to a complete compromise.

77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain elevated privileges, which may lead to a complete compromise.

Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be affected as well.

78. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.

The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.

An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.

79. Mobotix IP Camera Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18022
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18022
Summary:
The Mobotix IP camera is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the device to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

80. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.13.

81. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
BugTraq ID: 15009
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/15009
Summary:
University of Washington IMAP is prone to a buffer-overflow vulnerability. This issue is exposed when the application parses mailbox names.

If successful, an attacker may execute arbitrary code in the context of the server process. Note that to exploit this issue, the attacker must first authenticate to the service.

82. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

83. PHP Error Message Cross-Site Scripting Vulnerability
BugTraq ID: 16803
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/16803
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Exploitation of this issue requires PHP to be configured with 'display_errors' and 'html_errors' enabled in the local site configuration.

84. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.

85. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
BugTraq ID: 19409
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19409
Summary:
Microsoft Windows Server Service is prone to a remote buffer-overflow vulnerability.

This vulnerability arises when the service processes a malicious message in RPC communications.

A successful attack may result in arbitrary code execution with SYSTEM privileges leading to a full compromise. Attack attempts may result in denial-of-service conditions as well.

Microsoft has reported that this issue is being exploited in the wild.

Update (August 14, 2006): A worm named 'W32.Wargbot' that exploits this issue to spread is currently in the wild.

86. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities
BugTraq ID: 19486
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and data-modification vulnerabilities because the application fails to properly sanitize user-supplied input.

Successful exploits may allow an authenticated remote attacker to read and write email attachments or preferences from other users. This may lead to other attacks.

87. Headline Portal Engine HPEInc Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19663
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19663
Summary:
Multiple remote file-include vulnerabilities affect HPE because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call.

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process.

These issues affect versions 1.0, 0.7.0, 0.6.5 and 0.6.1; other versions may also be vulnerable.

88. Sun Solaris Format(1M) Buffer Overflow Vulnerability
BugTraq ID: 19657
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19657
Summary:
The format command in Solaris is prone to a buffer-overflow execution vulnerability.

This issue occurs because the application fails to check the size of the data before copying it into an into a finite-sized buffer.

A local attacker can exploit this issue to execute arbitrary code with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.

89. TikiWiki Highlight Cross-Site Scripting Vulnerability
BugTraq ID: 19654
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19654
Summary:
TikiWiki is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Version 1.9.4 is known to be vulnerable; prior versions may also be affected.

90. CityForFree Indexcity List.PHP SQL Injection Vulnerability
BugTraq ID: 19653
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19653
Summary:
CityForFree Indexcity is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

91. CityForFree Indexcity Cross-Site Scripting Vulnerability
BugTraq ID: 19652
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19652
Summary:
CityForFree Indexcity is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

92. Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
BugTraq ID: 19651
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19651
Summary:
Alt-N MDaemon POP3 Server is susceptible to multiple remote buffer-overflow vulnerabilities. The issues are due to the application's failure to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.

These issues allow remote, unauthenticated attackers to execute arbitrary machine code in the context of affected servers. This may facilitate the compromise of affected computers.

MDaemon versions 8 and 9 are reported to be vulnerable; previous versions may be affected as well.

93. Sun Solaris Format(1M) Local Privilege Escalation Vulnerability
BugTraq ID: 19647
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19647
Summary:
Sun Solaris is prone to a local privilege-escalation vulnerability.

A successful exploit would allow an to write device files to local disks with privileges of the superuser.

94. DieselScripts Diesel Paid Mail Getad.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19646
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19646
Summary:
Paid Mail is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

95. Sun Solaris File System Management RBAC Profile Arbitrary Command Execution Vulnerability
BugTraq ID: 19643
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19643
Summary:
Solaris is prone to an arbitrary command execution vulnerability.

A local attacker can exploit this issue to execute arbitrary commands with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.

96. Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
BugTraq ID: 19640
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19640
Summary:
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities. The vulnerabilities exists when instantiating COM objects.

The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, however this has not been confirmed.

This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). However, these issues affect a different set of COM objects that were not addressed in the previous BIDs.

97. Woltlab Burning Board Attachment.php HTML Injection Vulnerability
BugTraq ID: 19639
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19639
Summary:
Woltlab Burning Board is prone to an HTML-injection vulnerability.

This issue occurs because the application to properly sanitize user-supplied input before using it in dynamically generated content.

An attacker can exploit this issue to execute arbitrary HTML and script code in the context of the affected application, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible

Version 2.3.5 is vulnerable to this issue; other versions may also be affected.

98. Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
BugTraq ID: 19636
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19636
Summary:
Microsoft Windows 2000 is prone to multiple memory-corruption vulnerabilities that are related to the instantiation of COM objects. These issues may be remotely triggered through Internet Explorer.

The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution, but this has not been confirmed. The affected objects are not likely intended to be instantiated through Internet Explorer.

This BID may be related to the issues discussed in BID 17453 (Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability). However, these issues affect a different set of COM objects that were not addressed in previous BIDs.

99. 2wire Modems and Routers CRLF Denial of Service Vulnerability
BugTraq ID: 19634
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19634
Summary:
2wire Modems and Routers are prone to a remote denial-of-service vulnerability.

This may permit an attacker to crash affected devices, denying further network services to legitimate users.

100. WebAdmin Module for MDaemon Unspecified Privilege Escalation Vulnerability
BugTraq ID: 19631
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19631
Summary:
WebAdmin Module for MDaemon can allow remote authenticated users attackers to gain elevated system privileges.

Versions 3.00 to 3.24 are reported vulnerable; other versions may also be affected.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Microsoft patch opens users to attack
By: Robert Lemos
UPDATE: The software giant rushes to fix a security hole introduced during its latest patch for Internet Explorer that opens Windows XP SP1 and Windows 2000 users to attack.
http://www.securityfocus.com/news/11408

2. Bot spreads using latest Windows flaw
By: Robert Lemos
Security firms advise companies and home users to patch their Windows systems after detecting a bot program using a recently fixed flaw to compromise computers.

http://www.securityfocus.com/news/11407

3. Covert channel tool hides data in IPv6
By: Robert Lemos
Announced at the DEFCON hacking conference, a tool dubbed VoodooNet hides a small amount of data in IPv6 error messages, where most security devices do not even look.
http://www.securityfocus.com/news/11406

4. Researchers warn over Web worms
By: Robert Lemos
Exploiting a lack of security checks in browsers and Web servers, Web worms and viruses are likely to become a major threat to surfers.
http://www.securityfocus.com/news/11405

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Middletown, Bedminster
http://www.securityfocus.com/archive/77/444028

2. [SJ-JOB] Quality Assurance, Cupertino
http://www.securityfocus.com/archive/77/444030

3. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/444027

4. [SJ-JOB] Technical Support Engineer, Cupertino
http://www.securityfocus.com/archive/77/444032

5. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443925

6. [SJ-JOB] Principal Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443908

7. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443912

8. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/443943

9. [SJ-JOB] Sales Representative, Boston
http://www.securityfocus.com/archive/77/443909

10. [SJ-JOB] Database Security Engineer, New York
http://www.securityfocus.com/archive/77/443910

11. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
http://www.securityfocus.com/archive/77/443942

12. [SJ-JOB] Sales Engineer, New York City
http://www.securityfocus.com/archive/77/443944

13. [SJ-JOB] Security Architect, Schaumburg
http://www.securityfocus.com/archive/77/443945

14. [SJ-JOB] Security System Administrator, Toronto
http://www.securityfocus.com/archive/77/443946

15. [SJ-JOB] Security Researcher, Bay Area
http://www.securityfocus.com/archive/77/443643

16. [SJ-JOB] Database Security Architect, New York
http://www.securityfocus.com/archive/77/443653

17. [SJ-JOB] Security System Administrator, Schaumburg
http://www.securityfocus.com/archive/77/443700

18. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/443649

19. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/443698

20. [SJ-JOB] Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/443642

21. [SJ-JOB] Software Engineer, Burlington
http://www.securityfocus.com/archive/77/443650

22. [SJ-JOB] Security Engineer, Tampa
http://www.securityfocus.com/archive/77/443554

23. [SJ-JOB] Sales Engineer, Plano
http://www.securityfocus.com/archive/77/443555

24. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/443556

25. [SJ-JOB] Security Engineer, Nashville
http://www.securityfocus.com/archive/77/443557

26. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/443531

27. [SJ-JOB] Security Engineer, miami
http://www.securityfocus.com/archive/77/443541

28. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/443544

29. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/443545

30. [SJ-JOB] Senior Software Engineer, Bethesda
http://www.securityfocus.com/archive/77/443529

31. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/443530

32. [SJ-JOB] Channel / Business Development, San Francisco
http://www.securityfocus.com/archive/77/443532

33. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/443534

34. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/443546

35. [SJ-JOB] Security Director, Dallas area
http://www.securityfocus.com/archive/77/443524

36. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/443523

37. [SJ-JOB] Security System Administrator, Jersey City
http://www.securityfocus.com/archive/77/443526

38. [SJ-JOB] Principal Software Engineer, San Francisco
http://www.securityfocus.com/archive/77/443527

39. [SJ-JOB] Software Engineer, New York City
http://www.securityfocus.com/archive/77/443507

40. [SJ-JOB] Account Manager, Orlando
http://www.securityfocus.com/archive/77/443510

41. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/443525

42. [SJ-JOB] Jr. Security Analyst, Bangalore
http://www.securityfocus.com/archive/77/443503

43. [SJ-JOB] Quality Assurance, Redwood Shores
http://www.securityfocus.com/archive/77/443504

44. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443505

45. [SJ-JOB] Security Engineer, Jersey City
http://www.securityfocus.com/archive/77/443480

46. [SJ-JOB] Management, Alameda
http://www.securityfocus.com/archive/77/443486

47. [SJ-JOB] Technical Support Engineer, Burlington
http://www.securityfocus.com/archive/77/443489

48. [SJ-JOB] Penetration Engineer, McLean
http://www.securityfocus.com/archive/77/443560

49. [SJ-JOB] Principal Software Engineer, Crystal Lake
http://www.securityfocus.com/archive/77/443477

50. [SJ-JOB] Senior Software Engineer, Barcelona
http://www.securityfocus.com/archive/77/443478

51. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443404

52. [SJ-JOB] Security System Administrator, Plymouth or London
http://www.securityfocus.com/archive/77/443410

53. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443406

54. [SJ-JOB] Account Manager, San Diego
http://www.securityfocus.com/archive/77/443412

55. [SJ-JOB] Management, Tampa
http://www.securityfocus.com/archive/77/443417

56. [SJ-JOB] Security Architect, Richmond
http://www.securityfocus.com/archive/77/443421

57. [SJ-JOB] Security Researcher, Renton
http://www.securityfocus.com/archive/77/443392

58. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443393

59. [SJ-JOB] Forensics Engineer, washington
http://www.securityfocus.com/archive/77/443432

60. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443394

61. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443398

62. [SJ-JOB] Jr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/443399

63. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/443409

64. [SJ-JOB] Security Auditor, Lanham
http://www.securityfocus.com/archive/77/443422

65. [SJ-JOB] Security Engineer, Lanham
http://www.securityfocus.com/archive/77/443382

66. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443368

67. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443371

68. [SJ-JOB] Security Auditor, Cupertino
http://www.securityfocus.com/archive/77/443374

69. [SJ-JOB] Principal Software Engineer, San Diego
http://www.securityfocus.com/archive/77/443375

70. [SJ-JOB] Penetration Engineer, Napa
http://www.securityfocus.com/archive/77/443408

71. [SJ-JOB] Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/443365

72. [SJ-JOB] Technology Risk Consultant, Herndon
http://www.securityfocus.com/archive/77/443366

73. [SJ-JOB] Incident Handler, Arlington
http://www.securityfocus.com/archive/77/443370

74. [SJ-JOB] Security Consultant, Denver
http://www.securityfocus.com/archive/77/443349

75. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/443350

76. [SJ-JOB] Security Consultant, philadelphia
http://www.securityfocus.com/archive/77/443348

77. [SJ-JOB] Security Engineer, Raleigh
http://www.securityfocus.com/archive/77/443351

78. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/443347

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Major updates in PowerPoint FAQ document - not a 0-day issue
http://www.securityfocus.com/archive/75/444070

2. New PowerPoint 0-day and Trojan - FAQ document available
http://www.securityfocus.com/archive/75/443949

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Skype API Ap2Ap Stream Creation Flaw
http://www.securityfocus.com/archive/82/443877

2. ToorCon 8 Call for Papers Closing Tomorrow & Workshops/Seminars Added
http://www.securityfocus.com/archive/82/443685

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #304
http://www.securityfocus.com/archive/88/443459

2. Licensed Software Audit
http://www.securityfocus.com/archive/88/443369

3. Workstation Shutdown / Logoff Policy
http://www.securityfocus.com/archive/88/443340

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Linux Audit
http://www.securityfocus.com/archive/91/443621

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics

ALERT:  "How A Hacker Launches A Feed Injection Attack!" - SPI Dynamics White Paper
Learn the risks associated with Feed Injection of Atom and RSS feeds, including Cross-Site Scripting, Cross-Site Request Forgery, and Keystroke Logging.
Download *FREE* white paper from SPI Dynamics.

https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CaO4