SecurityFocus Newsletter #364
Peter Laborge <[email protected]> Tue, 22 Aug 2006 17:19:12 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #364
----------------------------------------
This issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Feed Injection Attack!" - SPI Dynamics White Paper
Learn the risks associated with Feed Injection of Atom and RSS feeds, including Cross-Site Scripting, Cross-Site Request Forgery, and Keystroke Logging.
Download *FREE* white paper from SPI Dynamics.
https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CaO4
------------------------------------------------------------------
I. FRONT AND CENTER
1. LinuxWorld, virtually speaking
2. Microsoft Office security, part one
II. BUGTRAQ SUMMARY
1. Modernbill Config.PHP Remote File Include Vulnerability
2. Symantec Enterprise Security Manager Denial of Service Vulnerability
3. DieselScript Smart Traffic Index.PHP Remote File Include Vulnerability
4. Plume CMS Multiple Remote File Include Vulnerabilities
5. Eichhorn Portal Multiple Input Validation Vulnerabilities
6. ToendaCMS TCMS_Administer Parameter Remote File Include Vulnerability
7. Mambo EstateAgent Component mosConfig_absolute_path Remote File Include Vulnerability
8. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
9. DieselScripts Job Site Forgot.PHP Multiple Cross-Site Scripting Vulnerabilities
10. Mambo Display MOSBot Manager Component mosConfig_absolute_path Remote File Include Vulnerability
11. WebAdmin Module for MDaemon Information Disclosure Vulnerability
12. PHPCodeGenie Core.PHP Remote File Include Vulnerability
13. WFTPD Server Multiple Buffer Overflow Vulnerabilities
14. Mambo BigAPE-Backup Component Remote File Include Vulnerability
15. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
16. Fantastic Scripts Fantastic News Remote File Include Vulnerability
17. Tutti Nova Multiple Remote File Include Vulnerabilities
18. NES Game and NES System Multiple Remote File Include Vulnerabilities
19. SportsPHool Remote File Include Vulnerability
20. Shadows Rising RPG Multiple Remote File Include Vulnerabilities
21. LBlog Comments.ASP SQL Injection Vulnerability
22. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
23. XennoBB Icon_Topic SQL Injection Vulnerability
24. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
25. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
26. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
27. PHP Multiple Unspecified Vulnerabilities
28. SquirrelMail Search.PHP Cross-Site Scripting Vulnerability
29. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
30. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
31. Mozilla Firefox Large History File Buffer Overflow Vulnerability
32. Linux Kernel UDF Denial of Service Vulnerability
33. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
34. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
35. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
36. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
37. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
38. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
39. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
40. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
41. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
42. GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability
43. Sun Solaris SysInfo Local Information Disclosure Vulnerability
44. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
45. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
46. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
47. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
48. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
49. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
50. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
51. CPanel Multiple Cross-Site Scripting Vulnerabilities
52. OScommerce Shopping_cart.PHP SQL Injection Vulnerability
53. FreeType LWFN Files Buffer Overflow Vulnerability
54. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
55. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
56. Mozilla Multiple Products Remote Vulnerabilities
57. OpenSSH SCP Shell Command Execution Vulnerability
58. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
60. Linux Kernel s/io.c/IO.C Local Denial of Service Vulnerability
61. Linux Kernel Non-Hugemem Support Local Denial of Service Vulnerability
62. AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
63. RedBlog Index.PHP Remote File Include Vulnerability
64. Doika Guestbook GBook.PHP HTML Injection Vulnerability
65. Empire CMS Checklevel.PHP Remote File Include Vulnerability
66. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
67. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
68. Business Management Systems Dolphin Remote File Include Vulnerability
69. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
70. RETIRED: SPAW PHP Editor Multiple Remote File Include Vulnerabilities
71. Sendmail Malformed MIME Message Denial Of Service Vulnerability
72. PHProjekt Content Management Module Multiple Remote File Include Vulnerabilities
73. PHP 5 User-Supplied Session ID Input Validation Vulnerability
74. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
75. Multiple Docebo Products Multiple Remote File Include Vulnerabilities
76. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
78. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
79. Mobotix IP Camera Multiple Cross-Site Scripting Vulnerabilities
80. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
81. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
82. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
83. PHP Error Message Cross-Site Scripting Vulnerability
84. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
85. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
86. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities
87. Headline Portal Engine HPEInc Parameter Multiple Remote File Include Vulnerabilities
88. Sun Solaris Format(1M) Buffer Overflow Vulnerability
89. TikiWiki Highlight Cross-Site Scripting Vulnerability
90. CityForFree Indexcity List.PHP SQL Injection Vulnerability
91. CityForFree Indexcity Cross-Site Scripting Vulnerability
92. Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
93. Sun Solaris Format(1M) Local Privilege Escalation Vulnerability
94. DieselScripts Diesel Paid Mail Getad.PHP Cross-Site Scripting Vulnerability
95. Sun Solaris File System Management RBAC Profile Arbitrary Command Execution Vulnerability
96. Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
97. Woltlab Burning Board Attachment.php HTML Injection Vulnerability
98. Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
99. 2wire Modems and Routers CRLF Denial of Service Vulnerability
100. WebAdmin Module for MDaemon Unspecified Privilege Escalation Vulnerability
III. SECURITYFOCUS NEWS
1. Microsoft patch opens users to attack
2. Bot spreads using latest Windows flaw
3. Covert channel tool hides data in IPv6
4. Researchers warn over Web worms
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Consultant, Middletown, Bedminster
2. [SJ-JOB] Quality Assurance, Cupertino
3. [SJ-JOB] Security Engineer, Kirkland
4. [SJ-JOB] Technical Support Engineer, Cupertino
5. [SJ-JOB] Software Engineer, Columbia
6. [SJ-JOB] Principal Software Engineer, Columbia
7. [SJ-JOB] Software Engineer, Columbia
8. [SJ-JOB] Security Engineer, Schaumburg
9. [SJ-JOB] Sales Representative, Boston
10. [SJ-JOB] Database Security Engineer, New York
11. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
12. [SJ-JOB] Sales Engineer, New York City
13. [SJ-JOB] Security Architect, Schaumburg
14. [SJ-JOB] Security System Administrator, Toronto
15. [SJ-JOB] Security Researcher, Bay Area
16. [SJ-JOB] Database Security Architect, New York
17. [SJ-JOB] Security System Administrator, Schaumburg
18. [SJ-JOB] Auditor, New York
19. [SJ-JOB] Security Engineer, Kirkland
20. [SJ-JOB] Software Engineer, Redwood Shores
21. [SJ-JOB] Software Engineer, Burlington
22. [SJ-JOB] Security Engineer, Tampa
23. [SJ-JOB] Sales Engineer, Plano
24. [SJ-JOB] Security Engineer, Reston
25. [SJ-JOB] Security Engineer, Nashville
26. [SJ-JOB] Sales Engineer, Boston
27. [SJ-JOB] Security Engineer, miami
28. [SJ-JOB] Sales Engineer, Herndon
29. [SJ-JOB] Sales Engineer, Atlanta
30. [SJ-JOB] Senior Software Engineer, Bethesda
31. [SJ-JOB] Sales Engineer, New York
32. [SJ-JOB] Channel / Business Development, San Francisco
33. [SJ-JOB] Sales Engineer, New York
34. [SJ-JOB] Sales Engineer, Chicago
35. [SJ-JOB] Security Director, Dallas area
36. [SJ-JOB] Manager, Information Security, New York
37. [SJ-JOB] Security System Administrator, Jersey City
38. [SJ-JOB] Principal Software Engineer, San Francisco
39. [SJ-JOB] Software Engineer, New York City
40. [SJ-JOB] Account Manager, Orlando
41. [SJ-JOB] Security System Administrator, New York
42. [SJ-JOB] Jr. Security Analyst, Bangalore
43. [SJ-JOB] Quality Assurance, Redwood Shores
44. [SJ-JOB] Security Consultant, Houston
45. [SJ-JOB] Security Engineer, Jersey City
46. [SJ-JOB] Management, Alameda
47. [SJ-JOB] Technical Support Engineer, Burlington
48. [SJ-JOB] Penetration Engineer, McLean
49. [SJ-JOB] Principal Software Engineer, Crystal Lake
50. [SJ-JOB] Senior Software Engineer, Barcelona
51. [SJ-JOB] Security Consultant, Houston
52. [SJ-JOB] Security System Administrator, Plymouth or London
53. [SJ-JOB] Security Consultant, Houston
54. [SJ-JOB] Account Manager, San Diego
55. [SJ-JOB] Management, Tampa
56. [SJ-JOB] Security Architect, Richmond
57. [SJ-JOB] Security Researcher, Renton
58. [SJ-JOB] Developer, Cupertino
59. [SJ-JOB] Forensics Engineer, washington
60. [SJ-JOB] Developer, Cupertino
61. [SJ-JOB] Developer, Cupertino
62. [SJ-JOB] Jr. Security Analyst, Cupertino
63. [SJ-JOB] Sr. Security Analyst, Cupertino
64. [SJ-JOB] Security Auditor, Lanham
65. [SJ-JOB] Security Engineer, Lanham
66. [SJ-JOB] Security Consultant, Any Major U.S. City
67. [SJ-JOB] Security Consultant, Any Major U.S. City
68. [SJ-JOB] Security Auditor, Cupertino
69. [SJ-JOB] Principal Software Engineer, San Diego
70. [SJ-JOB] Penetration Engineer, Napa
71. [SJ-JOB] Security Engineer, Cupertino
72. [SJ-JOB] Technology Risk Consultant, Herndon
73. [SJ-JOB] Incident Handler, Arlington
74. [SJ-JOB] Security Consultant, Denver
75. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
76. [SJ-JOB] Security Consultant, philadelphia
77. [SJ-JOB] Security Engineer, Raleigh
78. [SJ-JOB] Sales Engineer, Boston
V. INCIDENTS LIST SUMMARY
1. Major updates in PowerPoint FAQ document - not a 0-day issue
2. New PowerPoint 0-day and Trojan - FAQ document available
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Skype API Ap2Ap Stream Creation Flaw
2. ToorCon 8 Call for Papers Closing Tomorrow & Workshops/Seminars Added
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #304
2. Licensed Software Audit
3. Workstation Shutdown / Logoff Policy
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Linux Audit
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. LinuxWorld, virtually speaking
By Scott Granneman
With all the free virtual machines out there running security software or acting as virtual security appliances, you'd think VMWare is on everyone's mind. Scott Granneman offers some thoughts at the close of this year's LinuxWorld.
http://www.securityfocus.com/columnists/413
2. Microsoft Office security, part one
By Khushbu Jithra
This article discusses Microsoft Office's OLE Structured Storage and the nature of recent dropper programs and other exploit agents, in an effort to scrutinize the workings of some of the recent MS Office exploits. Part two will then collates some forensic investigation avenues through different MS Office features. Parts of the article sample different MS Office vulnerabilities to discuss their nature and the method of exploitation.
http://www.securityfocus.com/infocus/1874
II. BUGTRAQ SUMMARY
--------------------
1. Modernbill Config.PHP Remote File Include Vulnerability
BugTraq ID: 19335
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19335
Summary:
Modernbill is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
Version 1.6 is vulnerable to this issue; other versions may also be affected.
2. Symantec Enterprise Security Manager Denial of Service Vulnerability
BugTraq ID: 19580
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19580
Summary:
Symantec Enterprise Security Manager is prone to a denial-of-service vulnerability; fixes are available.
Symantec Enterprise Security Manager is susceptible to a race condition that can cause the application to lock up, resulting in a denial-of-service.
ESM Agent and Manager Platforms 6.0-6.5x are affected by this vulnerability.
3. DieselScript Smart Traffic Index.PHP Remote File Include Vulnerability
BugTraq ID: 19630
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19630
Summary:
Smart Traffic is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
4. Plume CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 19629
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19629
Summary:
Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
5. Eichhorn Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 19627
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19627
Summary:
Eichhorn Portal is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
6. ToendaCMS TCMS_Administer Parameter Remote File Include Vulnerability
BugTraq ID: 19626
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19626
Summary:
ToendaCMS is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects ToendaCMS 1.0.3 and prior; other versions may also be affected.
7. Mambo EstateAgent Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19625
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19625
Summary:
The Mambo EstateAgent component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
8. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19623
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19623
Summary:
DieselPay is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
9. DieselScripts Job Site Forgot.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19622
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19622
Summary:
Multiple cross-site scripting vulnerabilities affect Job Site because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
10. Mambo Display MOSBot Manager Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19621
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19621
Summary:
The Mambo Display MOSBot Manager component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
11. WebAdmin Module for MDaemon Information Disclosure Vulnerability
BugTraq ID: 19620
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19620
Summary:
The WebAdmin Module for MDaemon is prone to an information-disclosure vulnerability because it fails to sanitize user-supplied input.
An attacker can exploit this issue to disclose sensitive information, which could lead to other attacks.
Versions 3.00 to 3.24 are reported vulnerable; other versions may also be affected.
12. PHPCodeGenie Core.PHP Remote File Include Vulnerability
BugTraq ID: 19618
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19618
Summary:
phpCodeGenie is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Version 3.0.2 is vulnerable to this issue; other versions may also be affected.
13. WFTPD Server Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19617
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19617
Summary:
WFTPD is prone to multiple buffer-overflow vulnerabilities. These issues are due to a failure in the application to do proper bounds checking on user-supplied data before storing it in finite sized buffers.
An attacker can exploit these issues to execute arbitrary code and gain unauthorized remote access to a computer. Denial-of-service conditions due to attack attempts may arise as well.
WFTPD 3.23 is reported to be vulnerable. Other versions may also be affected.
14. Mambo BigAPE-Backup Component Remote File Include Vulnerability
BugTraq ID: 19616
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19616
Summary:
The Mambo bigAPE-Backup component is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Versions 1.x and prior are vulnerable to this issue; other versions may also be affected.
15. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service.
An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.
16. Fantastic Scripts Fantastic News Remote File Include Vulnerability
BugTraq ID: 19613
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19613
Summary:
Fantastic News is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Fantastic News 2.1.3 is vulnerable; other versions may also be affected.
17. Tutti Nova Multiple Remote File Include Vulnerabilities
BugTraq ID: 19612
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19612
Summary:
Tutti Nova is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Tutti Nova 1.6 is vulnerable; other versions may also be affected.
18. NES Game and NES System Multiple Remote File Include Vulnerabilities
BugTraq ID: 19611
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19611
Summary:
NES Game and NES System is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
NES Game and NES System version c108122 is vulnerable; other versions may also be affected.
19. SportsPHool Remote File Include Vulnerability
BugTraq ID: 19610
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19610
Summary:
SportsPHool is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SportsPHool version 1.0 is vulnerable; other versions may also be affected.
20. Shadows Rising RPG Multiple Remote File Include Vulnerabilities
BugTraq ID: 19608
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19608
Summary:
Shadows Rising RPG is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Shadows Rising RPG (Pre-Alpha) 0.0.5b is vulnerable; other versions may also be affected.
21. LBlog Comments.ASP SQL Injection Vulnerability
BugTraq ID: 19607
Remote: Yes
Last Updated: 2006-08-20
Relevant URL: http://www.securityfocus.com/bid/19607
Summary:
LBlog is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
LBlog 1.05 and prior versions are affected by this issue.
22. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.
Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.
Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.
It has been reported that the Flock web browser version 0.7.4.1 and the K-Meleon web browser version 1.0.1 are also vulnerable.
23. XennoBB Icon_Topic SQL Injection Vulnerability
BugTraq ID: 19606
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19606
Summary:
XennoBB is prone to an SQL injection vulnerability which could allow an attacker to influence the structure or logic of SQL queries made by the application.
24. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19605
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19605
Summary:
The Mambo CropImage component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
25. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19604
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19604
Summary:
The Mambo CatalogShop component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
26. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19602
Remote: Yes
Last Updated: 2006-08-19
Relevant URL: http://www.securityfocus.com/bid/19602
Summary:
The Mambo AkoComment module is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
27. PHP Multiple Unspecified Vulnerabilities
BugTraq ID: 17843
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17843
Summary:
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.
The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.
Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.
28. SquirrelMail Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18700
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18700
Summary:
SquirrelMail is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
29. IPSec-Tools IKE Message Handling Denial of Service Vulnerability
BugTraq ID: 15523
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15523
Summary:
IPsec-Tools is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to handle exceptional conditions when in 'AGGRESSIVE' mode.
An attacker can exploit this issue to crash the application, thus denying service to legitimate users.
These vulnerabilities were discovered by, and may be reproduced by, the University of Oulu Secure Programming Group PROTOS IPSec Test Suite.
30. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 17000
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17000
Summary:
Microsoft Office is prone to a remote buffer-overflow vulnerability.
This vulnerability occurs when the application handles a specially crafted document. A successful attack can result in a remote compromise in the context of an affected user.
Update: This issue is known to be exploited in the wild by malware. In particular, 'Trojan.PPDropper' is known to exploit this issue.
31. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability.
This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file.
This may cause a denial-of-service condition.
**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.
32. Linux Kernel UDF Denial of Service Vulnerability
BugTraq ID: 19562
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19562
Summary:
The Linux kernel UDF file module is prone to a denial-of-service.
An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.
33. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Multiple Mozilla products are prone to a script-execution vulnerability.
The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client.
The following mozilla products are vulnerable to this issue:
- Mozilla Thunderbird, versions prior to 1.5.0.2, and prior to 1.0.8
- Mozilla SeaMonkey, versions prior to 1.0.1
- Mozilla Suite, versions prior to 1.7.13
34. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.
Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.
35. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.
This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.27.
36. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is prone to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.
These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.
The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.
37. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability.
This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users.
Kernel versions prior to 2.6.16.18 are vulnerable to this issue.
38. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.
This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.
Linux kernel versions 2.6.17.3 and prior are affected by this issue.
39. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability because of a race-condition in the 'proc' filesystem.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
The 2.6 series of the Linux kernel is vulnerable to this issue.
40. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.
Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.
Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.
41. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.
These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1
42. GNU Troff (Groff) Groffer Script Insecure Temporary File Creation Vulnerability
BugTraq ID: 11287
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/11287
Summary:
GNU Troff ('groff') is affected by an insecure temporary file-creation vulnerability. This issue is due to a design error that causes the application to fail to verify the presence of a file before writing to it.
An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Reportedly, this issue is unlikely to facilitate privilege escalation.
43. Sun Solaris SysInfo Local Information Disclosure Vulnerability
BugTraq ID: 19104
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19104
Summary:
Sun Solaris is prone to a local information-disclosure vulnerability because the kernel fails to properly ensure that unintended memory is not disclosed to local users.
This issue allows local attackers to gain access to potentially sensitive kernel memory. Information harvested by exploiting this issue may aid attackers in further attacks.
44. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.
Specific details of these issues are not currently available. This record will be updated when more information becomes available.
The following are vulnerable:
- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier
45. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
46. Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
BugTraq ID: 19520
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19520
Summary:
Microsoft Windows is reportedly prone to a remote denial-of-service vulnerability because the PNG-rendering portion of the operating system fails to handle malicious PNG (Portable Network Graphics) files.
This issue may cause Windows Explorer to consume excessive resources and crash, denying service to legitimate users.
47. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
48. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
49. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
50. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
BugTraq ID: 19215
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19215
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability because the operating system fails to properly handle network traffic.
This issue may cause affected computers to crash, denying service to legitimate users.
Reports indicate that this issue may be currently exploited in the wild, but this has not been confirmed.
51. CPanel Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19624
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19624
Summary:
cPanel is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
52. OScommerce Shopping_cart.PHP SQL Injection Vulnerability
BugTraq ID: 19644
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19644
Summary:
OSCommerce is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before being used as input to SQL queries.
A successful exploit could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
53. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
54. Multiple Vendor Web Browser JavaScript Key Filtering Vulnerability
BugTraq ID: 18308
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18308
Summary:
Multiple web browsers are prone to a JavaScript key-filtering vulnerability. This issue is due to the failure of the browsers to securely handle keystroke input from users.
This issue is demonstrated to allow attackers to divert keystrokes from one input form in a webpage to a hidden file-upload dialog in the same page. This may allow remote attackers to initiate file uploads from unsuspecting users. Other attacks may also be possible.
Exploiting this issue requires that users manually type the full path of files that attackers wish to download. This may require substantial typing from targeted users, so attackers will likely use keyboard-based games, blogs, or other similar pages to entice users to enter the required keyboard input to exploit this issue.
Reportedly, Mozilla Suite, Mozilla Firefox, Mozilla SeaMonkey, Netscape Navigator, and Microsoft Internet Explorer are all vulnerable to this issue.
55. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code
- gain access to potentially sensitive information.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as further information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2
56. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as more information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3
57. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because the application fails to properly sanitize user-supplied input before using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.
58. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
BugTraq ID: 19667
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19667
Summary:
Microsoft Internet Explorer is prone to a remote buffer-overflow vulnerability. A successful exploit may result in arbitrary code-execution in the context of the user running the browser.
This issue was introduced with the patches released with Microsoft advisory MS06-042.
Internet Explorer 6 SP1 running on Microsoft Windows 2000 and Windows XP SP1 is vulnerable to this issue.
59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
BugTraq ID: 19666
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19666
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability. This issue is due to the kernel's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary codel. Successfully exploiting this issue would cause the complete compromise of the affected computer.
Versions prior to 2.6.17.10 of the 2.6 series and versions prior to 2.4.33.2 of the 2.4 series are vulnerable to this issue.
60. Linux Kernel s/io.c/IO.C Local Denial of Service Vulnerability
BugTraq ID: 19665
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19665
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the direct IO driver.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects the Linux kernel 2.6 series prior to 2.6.10.
61. Linux Kernel Non-Hugemem Support Local Denial of Service Vulnerability
BugTraq ID: 19664
Remote: No
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19664
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the code which handles support for 'non-hugemem' kernels.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
62. AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
BugTraq ID: 19659
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19659
Summary:
AK-Systems Windows Terminals are prone to a remote unauthorized administrative access vulnerability. This issue is due to a lack of authentication requirements for remote administrative access to affected devices.
This issue allows remote attackers to gain administrative access on affected devices without requiring authentication. This allows attackers to compromise affected devices, and monitor or access RDP and Citrix sessions on targeted devices.
Devices with firmware version 1.2.5 ExVLP are vulnerable to this issue. Other versions may also be affected.
63. RedBlog Index.PHP Remote File Include Vulnerability
BugTraq ID: 19658
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19658
Summary:
RedBLoG is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.5; other versions may also be vulnerable.
64. Doika Guestbook GBook.PHP HTML Injection Vulnerability
BugTraq ID: 19656
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19656
Summary:
Doika Guestbook is prone to an HTML-injection vulnerability. An attacker may inject hostile HTML and script code into vulnerable sections of the application. When viewed, this code may be rendered in the browser of a user visiting the site in the context of the affected website.
65. Empire CMS Checklevel.PHP Remote File Include Vulnerability
BugTraq ID: 19655
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19655
Summary:
Empire CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Versions 3.7 and prior are vulnerable to this issue; other versions may also be affected.
66. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19650
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19650
Summary:
Links Manager is prone to multiple cross-site scripting vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
67. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
BugTraq ID: 19649
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19649
Summary:
Links Manager is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before being used as input to SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
68. Business Management Systems Dolphin Remote File Include Vulnerability
BugTraq ID: 19648
Remote: Yes
Last Updated: 2006-08-22
Relevant URL: http://www.securityfocus.com/bid/19648
Summary:
Business Management Systems Dolphin is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Version 5.2 is vulnerable to this issue; other versions may also be affected.
69. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 19415
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19415
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations and potentially execute code.
This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, all assuming that the 'safe_mode' restriction will isolate the users from each other.
This issue is reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.
70. RETIRED: SPAW PHP Editor Multiple Remote File Include Vulnerabilities
BugTraq ID: 19603
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19603
Summary:
SPAW PHP Editor is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to execute remote PHP code in the context of the web server process. This may allow the attacker to compromise the application or to gain access to the underlying system.
This BID has been retired.
71. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.
An attacker can exploit this issue to crash the sendmail process during delivery.
72. PHProjekt Content Management Module Multiple Remote File Include Vulnerabilities
BugTraq ID: 19628
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19628
Summary:
Multiple remote file-include vulnerabilities affect the Content Management module for PHProjekt because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call.
An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process.
These issues affect version 0.6.1; earlier versions may also be vulnerable.
73. PHP 5 User-Supplied Session ID Input Validation Vulnerability
BugTraq ID: 16220
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/16220
Summary:
PHP 5 is prone to an input-validation vulnerability. This is due to a lack of proper sanitization of user-supplied input of PHP session IDs, transmitted by way of HTTP headers.
An attacker may use this vulnerability to perform HTTP response splitting, often resulting in content spoofing and cross-site scripting attacks.
PHP 5 version 5.1.1 and prior are affected.
74. Taskjitsu Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 19251
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19251
Summary:
Taskjitsu is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Taskjitsu 2.03 and earlier are vulnerable to this issue.
75. Multiple Docebo Products Multiple Remote File Include Vulnerabilities
BugTraq ID: 18109
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18109
Summary:
Docebo is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Docebo versions 3.0.4 and prior are vulnerable to these issues.
76. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
BugTraq ID: 18850
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18850
Summary:
Ubuntu Linux passwd may allow local attackers to gain elevated privileges. A successful attack may lead to a complete compromise.
77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain elevated privileges, which may lead to a complete compromise.
Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be affected as well.
78. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.
The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.
An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.
79. Mobotix IP Camera Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18022
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18022
Summary:
The Mobotix IP camera is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the device to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
80. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.
This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.13.
81. University Of Washington IMAP Mailbox Name Buffer Overflow Vulnerability
BugTraq ID: 15009
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/15009
Summary:
University of Washington IMAP is prone to a buffer-overflow vulnerability. This issue is exposed when the application parses mailbox names.
If successful, an attacker may execute arbitrary code in the context of the server process. Note that to exploit this issue, the attacker must first authenticate to the service.
82. PHP PHPInfo Large Input Cross-Site Scripting Vulnerability
BugTraq ID: 17362
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/17362
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
83. PHP Error Message Cross-Site Scripting Vulnerability
BugTraq ID: 16803
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/16803
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploitation of this issue requires PHP to be configured with 'display_errors' and 'html_errors' enabled in the local site configuration.
84. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.
85. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
BugTraq ID: 19409
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19409
Summary:
Microsoft Windows Server Service is prone to a remote buffer-overflow vulnerability.
This vulnerability arises when the service processes a malicious message in RPC communications.
A successful attack may result in arbitrary code execution with SYSTEM privileges leading to a full compromise. Attack attempts may result in denial-of-service conditions as well.
Microsoft has reported that this issue is being exploited in the wild.
Update (August 14, 2006): A worm named 'W32.Wargbot' that exploits this issue to spread is currently in the wild.
86. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities
BugTraq ID: 19486
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and data-modification vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits may allow an authenticated remote attacker to read and write email attachments or preferences from other users. This may lead to other attacks.
87. Headline Portal Engine HPEInc Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19663
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19663
Summary:
Multiple remote file-include vulnerabilities affect HPE because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call.
An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process.
These issues affect versions 1.0, 0.7.0, 0.6.5 and 0.6.1; other versions may also be vulnerable.
88. Sun Solaris Format(1M) Buffer Overflow Vulnerability
BugTraq ID: 19657
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19657
Summary:
The format command in Solaris is prone to a buffer-overflow execution vulnerability.
This issue occurs because the application fails to check the size of the data before copying it into an into a finite-sized buffer.
A local attacker can exploit this issue to execute arbitrary code with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
89. TikiWiki Highlight Cross-Site Scripting Vulnerability
BugTraq ID: 19654
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19654
Summary:
TikiWiki is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Version 1.9.4 is known to be vulnerable; prior versions may also be affected.
90. CityForFree Indexcity List.PHP SQL Injection Vulnerability
BugTraq ID: 19653
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19653
Summary:
CityForFree Indexcity is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
91. CityForFree Indexcity Cross-Site Scripting Vulnerability
BugTraq ID: 19652
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19652
Summary:
CityForFree Indexcity is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
92. Alt-N MDaemon Multiple Remote Pre-Authentication POP3 Buffer Overflow Vulnerabilities
BugTraq ID: 19651
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19651
Summary:
Alt-N MDaemon POP3 Server is susceptible to multiple remote buffer-overflow vulnerabilities. The issues are due to the application's failure to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
These issues allow remote, unauthenticated attackers to execute arbitrary machine code in the context of affected servers. This may facilitate the compromise of affected computers.
MDaemon versions 8 and 9 are reported to be vulnerable; previous versions may be affected as well.
93. Sun Solaris Format(1M) Local Privilege Escalation Vulnerability
BugTraq ID: 19647
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19647
Summary:
Sun Solaris is prone to a local privilege-escalation vulnerability.
A successful exploit would allow an to write device files to local disks with privileges of the superuser.
94. DieselScripts Diesel Paid Mail Getad.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19646
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19646
Summary:
Paid Mail is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
95. Sun Solaris File System Management RBAC Profile Arbitrary Command Execution Vulnerability
BugTraq ID: 19643
Remote: No
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19643
Summary:
Solaris is prone to an arbitrary command execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with superuser privileges. Exploiting this issue allows attackers to completely compromise affected computers.
96. Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
BugTraq ID: 19640
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19640
Summary:
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities. The vulnerabilities exists when instantiating COM objects.
The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, however this has not been confirmed.
This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). However, these issues affect a different set of COM objects that were not addressed in the previous BIDs.
97. Woltlab Burning Board Attachment.php HTML Injection Vulnerability
BugTraq ID: 19639
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19639
Summary:
Woltlab Burning Board is prone to an HTML-injection vulnerability.
This issue occurs because the application to properly sanitize user-supplied input before using it in dynamically generated content.
An attacker can exploit this issue to execute arbitrary HTML and script code in the context of the affected application, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible
Version 2.3.5 is vulnerable to this issue; other versions may also be affected.
98. Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
BugTraq ID: 19636
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19636
Summary:
Microsoft Windows 2000 is prone to multiple memory-corruption vulnerabilities that are related to the instantiation of COM objects. These issues may be remotely triggered through Internet Explorer.
The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in arbitrary code execution, but this has not been confirmed. The affected objects are not likely intended to be instantiated through Internet Explorer.
This BID may be related to the issues discussed in BID 17453 (Microsoft Internet Explorer COM Object Instantiation Code Execution Vulnerability). However, these issues affect a different set of COM objects that were not addressed in previous BIDs.
99. 2wire Modems and Routers CRLF Denial of Service Vulnerability
BugTraq ID: 19634
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19634
Summary:
2wire Modems and Routers are prone to a remote denial-of-service vulnerability.
This may permit an attacker to crash affected devices, denying further network services to legitimate users.
100. WebAdmin Module for MDaemon Unspecified Privilege Escalation Vulnerability
BugTraq ID: 19631
Remote: Yes
Last Updated: 2006-08-21
Relevant URL: http://www.securityfocus.com/bid/19631
Summary:
WebAdmin Module for MDaemon can allow remote authenticated users attackers to gain elevated system privileges.
Versions 3.00 to 3.24 are reported vulnerable; other versions may also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Microsoft patch opens users to attack
By: Robert Lemos
UPDATE: The software giant rushes to fix a security hole introduced during its latest patch for Internet Explorer that opens Windows XP SP1 and Windows 2000 users to attack.
http://www.securityfocus.com/news/11408
2. Bot spreads using latest Windows flaw
By: Robert Lemos
Security firms advise companies and home users to patch their Windows systems after detecting a bot program using a recently fixed flaw to compromise computers.
http://www.securityfocus.com/news/11407
3. Covert channel tool hides data in IPv6
By: Robert Lemos
Announced at the DEFCON hacking conference, a tool dubbed VoodooNet hides a small amount of data in IPv6 error messages, where most security devices do not even look.
http://www.securityfocus.com/news/11406
4. Researchers warn over Web worms
By: Robert Lemos
Exploiting a lack of security checks in browsers and Web servers, Web worms and viruses are likely to become a major threat to surfers.
http://www.securityfocus.com/news/11405
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Middletown, Bedminster
http://www.securityfocus.com/archive/77/444028
2. [SJ-JOB] Quality Assurance, Cupertino
http://www.securityfocus.com/archive/77/444030
3. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/444027
4. [SJ-JOB] Technical Support Engineer, Cupertino
http://www.securityfocus.com/archive/77/444032
5. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443925
6. [SJ-JOB] Principal Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443908
7. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/443912
8. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/443943
9. [SJ-JOB] Sales Representative, Boston
http://www.securityfocus.com/archive/77/443909
10. [SJ-JOB] Database Security Engineer, New York
http://www.securityfocus.com/archive/77/443910
11. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
http://www.securityfocus.com/archive/77/443942
12. [SJ-JOB] Sales Engineer, New York City
http://www.securityfocus.com/archive/77/443944
13. [SJ-JOB] Security Architect, Schaumburg
http://www.securityfocus.com/archive/77/443945
14. [SJ-JOB] Security System Administrator, Toronto
http://www.securityfocus.com/archive/77/443946
15. [SJ-JOB] Security Researcher, Bay Area
http://www.securityfocus.com/archive/77/443643
16. [SJ-JOB] Database Security Architect, New York
http://www.securityfocus.com/archive/77/443653
17. [SJ-JOB] Security System Administrator, Schaumburg
http://www.securityfocus.com/archive/77/443700
18. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/443649
19. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/443698
20. [SJ-JOB] Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/443642
21. [SJ-JOB] Software Engineer, Burlington
http://www.securityfocus.com/archive/77/443650
22. [SJ-JOB] Security Engineer, Tampa
http://www.securityfocus.com/archive/77/443554
23. [SJ-JOB] Sales Engineer, Plano
http://www.securityfocus.com/archive/77/443555
24. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/443556
25. [SJ-JOB] Security Engineer, Nashville
http://www.securityfocus.com/archive/77/443557
26. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/443531
27. [SJ-JOB] Security Engineer, miami
http://www.securityfocus.com/archive/77/443541
28. [SJ-JOB] Sales Engineer, Herndon
http://www.securityfocus.com/archive/77/443544
29. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/443545
30. [SJ-JOB] Senior Software Engineer, Bethesda
http://www.securityfocus.com/archive/77/443529
31. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/443530
32. [SJ-JOB] Channel / Business Development, San Francisco
http://www.securityfocus.com/archive/77/443532
33. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/443534
34. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/443546
35. [SJ-JOB] Security Director, Dallas area
http://www.securityfocus.com/archive/77/443524
36. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/443523
37. [SJ-JOB] Security System Administrator, Jersey City
http://www.securityfocus.com/archive/77/443526
38. [SJ-JOB] Principal Software Engineer, San Francisco
http://www.securityfocus.com/archive/77/443527
39. [SJ-JOB] Software Engineer, New York City
http://www.securityfocus.com/archive/77/443507
40. [SJ-JOB] Account Manager, Orlando
http://www.securityfocus.com/archive/77/443510
41. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/443525
42. [SJ-JOB] Jr. Security Analyst, Bangalore
http://www.securityfocus.com/archive/77/443503
43. [SJ-JOB] Quality Assurance, Redwood Shores
http://www.securityfocus.com/archive/77/443504
44. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443505
45. [SJ-JOB] Security Engineer, Jersey City
http://www.securityfocus.com/archive/77/443480
46. [SJ-JOB] Management, Alameda
http://www.securityfocus.com/archive/77/443486
47. [SJ-JOB] Technical Support Engineer, Burlington
http://www.securityfocus.com/archive/77/443489
48. [SJ-JOB] Penetration Engineer, McLean
http://www.securityfocus.com/archive/77/443560
49. [SJ-JOB] Principal Software Engineer, Crystal Lake
http://www.securityfocus.com/archive/77/443477
50. [SJ-JOB] Senior Software Engineer, Barcelona
http://www.securityfocus.com/archive/77/443478
51. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443404
52. [SJ-JOB] Security System Administrator, Plymouth or London
http://www.securityfocus.com/archive/77/443410
53. [SJ-JOB] Security Consultant, Houston
http://www.securityfocus.com/archive/77/443406
54. [SJ-JOB] Account Manager, San Diego
http://www.securityfocus.com/archive/77/443412
55. [SJ-JOB] Management, Tampa
http://www.securityfocus.com/archive/77/443417
56. [SJ-JOB] Security Architect, Richmond
http://www.securityfocus.com/archive/77/443421
57. [SJ-JOB] Security Researcher, Renton
http://www.securityfocus.com/archive/77/443392
58. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443393
59. [SJ-JOB] Forensics Engineer, washington
http://www.securityfocus.com/archive/77/443432
60. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443394
61. [SJ-JOB] Developer, Cupertino
http://www.securityfocus.com/archive/77/443398
62. [SJ-JOB] Jr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/443399
63. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/443409
64. [SJ-JOB] Security Auditor, Lanham
http://www.securityfocus.com/archive/77/443422
65. [SJ-JOB] Security Engineer, Lanham
http://www.securityfocus.com/archive/77/443382
66. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443368
67. [SJ-JOB] Security Consultant, Any Major U.S. City
http://www.securityfocus.com/archive/77/443371
68. [SJ-JOB] Security Auditor, Cupertino
http://www.securityfocus.com/archive/77/443374
69. [SJ-JOB] Principal Software Engineer, San Diego
http://www.securityfocus.com/archive/77/443375
70. [SJ-JOB] Penetration Engineer, Napa
http://www.securityfocus.com/archive/77/443408
71. [SJ-JOB] Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/443365
72. [SJ-JOB] Technology Risk Consultant, Herndon
http://www.securityfocus.com/archive/77/443366
73. [SJ-JOB] Incident Handler, Arlington
http://www.securityfocus.com/archive/77/443370
74. [SJ-JOB] Security Consultant, Denver
http://www.securityfocus.com/archive/77/443349
75. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/443350
76. [SJ-JOB] Security Consultant, philadelphia
http://www.securityfocus.com/archive/77/443348
77. [SJ-JOB] Security Engineer, Raleigh
http://www.securityfocus.com/archive/77/443351
78. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/443347
V. INCIDENTS LIST SUMMARY
---------------------------
1. Major updates in PowerPoint FAQ document - not a 0-day issue
http://www.securityfocus.com/archive/75/444070
2. New PowerPoint 0-day and Trojan - FAQ document available
http://www.securityfocus.com/archive/75/443949
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Skype API Ap2Ap Stream Creation Flaw
http://www.securityfocus.com/archive/82/443877
2. ToorCon 8 Call for Papers Closing Tomorrow & Workshops/Seminars Added
http://www.securityfocus.com/archive/82/443685
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #304
http://www.securityfocus.com/archive/88/443459
2. Licensed Software Audit
http://www.securityfocus.com/archive/88/443369
3. Workstation Shutdown / Logoff Policy
http://www.securityfocus.com/archive/88/443340
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Linux Audit
http://www.securityfocus.com/archive/91/443621
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Feed Injection Attack!" - SPI Dynamics White Paper
Learn the risks associated with Feed Injection of Atom and RSS feeds, including Cross-Site Scripting, Cross-Site Request Forgery, and Keystroke Logging.
Download *FREE* white paper from SPI Dynamics.
https://download.spidynamics.com/1/ad/AJAX.asp?Campaign_ID=70160000000CaO4