SecurityFocus Newsletter #365

Peter Laborge <[email protected]> Tue, 29 Aug 2006 15:43:23 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #365
----------------------------------------

This issue is Sponsored by: SPI Dynamics

FREE Webcast: "Building a Web Application Assessment Program"
During this Webcast, you will learn; key challenges to implementing a Web application assessment program, how to limit false positives and increase  accuracy and why engaging developers is critical to the security process.

https://download.spidynamics.com/1/ad/AMPw.asp?Campaign_ID=70160000000CaZH

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Anonymous No More
        2. Microsoft Office security, part two
II.   BUGTRAQ SUMMARY
        1. 8Pixel.net SimpleBlog Comments.ASP SQL Injection Vulnerability
        2. LBlog Comments.ASP SQL Injection Vulnerability
        3. Mozilla Firefox Javascript Navigator Object Remote Code Execution Vulnerability
        4. Linux Kernel LSM ReadV/WriteV Security Restriction Bypass Vulnerability
        5. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
        6. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
        7. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
        8. Blackboard Products Multiple HTML Injection Vulnerabilities
        9. PHProjekt Multiple Remote File Include Vulnerabilities
        10. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
        11. Yukihiro Matsumoto Ruby XMLRPC Server Denial of Service Vulnerability
        12. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
        13. Linux Kernel IP ID Information Disclosure Weakness
        14. LibTIFF EstimateStripByteCounts() Denial of Service Vulnerability
        15. Linux Kernel NFS Client Denial of Service Vulnerability
        16. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
        17. Linux Kernel SDLA IOCTL Unauthorized Local Firmware Access Vulnerability
        18. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
        19. Linux Kernel IP6_Input_Finish Remote Denial Of Service Vulnerability
        20. Cisco Content Service Switch Management Port UDP Denial Of Service Vulnerability
        21. Cisco NAC Agent Installation Security Bypass Vulnerability
        22. LibTIFF Library Anonymous Field Merging Denial of Service Vulnerability
        23. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
        24. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
        25. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
        26. IrfanView ANI Image File Denial Of Service Vulnerability
        27. PHP Error_Log Safe_Mode Restriction-Bypass Vulnerability
        28. XennoBB Icon_Topic SQL Injection Vulnerability
        29. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
        30. PHP Multiple Security Bypass Vulnerabilities
        31. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
        32. MiniBill Config[Plugin_Dir] Parameter Multiple Remote File Include Vulnerabilities
        33. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
        34. GD Graphics Library Remote Integer Overflow Vulnerability
        35. Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
        36. Joomla Z00m Media Gallery Component mosConfig_absolute_path Remote File Include Vulnerability
        37. GD Graphics Library Multiple Unspecified Remote Buffer overflow Vulnerabilities
        38. RETIRED: Jupiter CMS Index.PHP Remote File Include Vulnerability
        39. RealVNC Clipboard Update Integer Overflow Vulnerability
        40. PHP Multiple Unspecified Vulnerabilities
        41. Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
        42. Sonium Enterprise Addressbook Multiple Remote File Include Vulnerabilities
        43.  Coppermine Gallery Component for Mambo cpg.PHP Remote File Include Vulnerability
        44. MamboWiki Component MamboLogin.PHP Remote File Include Vulnerability
        45. OpenOffice XML File Format Buffer Overflow Vulnerability
        46. OpenOffice Java Applet System Access Vulnerability
        47. Joomla Poll Component Multiple User Session Validation Vulnerability
        48. OpenOffice Arbitrary Macro Execution Vulnerability
        49. Joomla Kochsuite Component mosConfig_absolute_path Remote File Include Vulnerability
        50. Symantec Norton Personal Firewall SuiteOwners Registry Key Security Bypass Vulnerability
        51. ScriptsEZ Easy Ad-Manager Details.PHP Cross-Site Scripting Vulnerability
        52. IBM DB2 Multiple Denial of Service Vulnerabilities
        53. AOL Security Edition Local Privilege Escalation Vulnerability
        54. Mambo A6MamboCredits Component Remote File Include Vulnerability
        55. Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
        56. RETIRED: Jetbox CMS Search_function.PHP Remote File Include Vulnerability
        57. IBM AIX Setlocale Function Local Privilege Escalation Vulnerability
        58. Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
        59. Blog:CMS Dir_Plugins Parameter Multiple Remote File Include Vulnerabilities
        60. Mozilla Multiple Products Remote Vulnerabilities
        61. Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
        62. Mambo Jim Component Install.Jim.PHP Remote File Include Vulnerability
        63. Samba Internal Data Structures Denial of Service Vulnerability
        64. MambelFish Mambo Component Mambelfish.Class.PHP Remote File Include Vulnerability
        65. WTCom Web Torrent SQL Injection Vulnerability
        66. Wireshark Multiple Vulnerabilities
        67. KTools Remote Buffer Overflow Vulnerability
        68. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
        69. Powergap Multiple Remote File Include Vulnerabilities
        70. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
        71. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
        72. Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
        73. CliServ Web Community Multiple Remote File Include Vulnerabilities
        74. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
        75. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
        76. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
        77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
        78. Invisionix Roaming System Remote Pageheaderdefault.Inc.PHP Remote File Include Vulnerability
        79. IBM EGatherer ActiveX Remote Buffer Overflow Vulnerability
        80. Sendmail Malformed MIME Message Denial Of Service Vulnerability
        81. Perl SuidPerl Multiple Local Vulnerabilities
        82. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
        83. LessTif Debug Feature Local Arbitrary File Creation Vulnerability
        84. GNU BinUtils GAS Buffer Overflow Vulnerability
        85. GNU BinUtils Buffer Overflow Vulnerability
        86. ModuleBased CMS Multiple Remote File Include Vulnerabilities
        87. ExBB Italia UserStop.PHP Remote File Include Vulnerability
        88. PHPECard Functions.PHP Remote File Include Vulnerability
        89. PhpGroupWare Calendar Class.Holidaycalc.Inc.PHP Local File Include Vulnerability
        90. Mod_PHPAlbum Sommaire_Admin.PHP Remote File Include Vulnerability
        91. CJ Tag Board User-Agent PHP Code Injection Vulnerability
        92. PMWiki Table Markups HTML Injection Vulnerability
        93. HLstats Hlstats.PHP Cross Site Scripting Vulnerability
        94. SAP-DB/MaxDB WebDBM Remote Buffer Overflow Vulnerability
        95. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
        96. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
        97. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
        98. Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
        99. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
        100. Mozilla Foundation Products XPCOM Memory Corruption Vulnerability
III.  SECURITYFOCUS NEWS
        1. Linux update becomes terminal pain
        2. Microsoft patch opens users to attack
        3. Bot spreads using latest Windows flaw
        4. Covert channel tool hides data in IPv6
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Technical Support Engineer, Fredericton
        2. [SJ-JOB] Quality Assurance, Fredericton
        3. [SJ-JOB] Senior Software Engineer, Fredericton
        4. [SJ-JOB] Customer Support, San Antonio, TX
        5. [SJ-JOB] Developer, San  Antonio, TX
        6. [SJ-JOB] Security Consultant, San Antonio, TX
        7. [SJ-JOB] Management, San Francisco
        8. [SJ-JOB] Security Consultant, Remote
        9. [SJ-JOB] Security Consultant, Seattle
        10. [SJ-JOB] Security Consultant, Chicago, Il/San Francisco,    CA/Cambridge, MA/ Seattle, WA
        11. [SJ-JOB] Security Engineer, Beltsville
        12. [SJ-JOB] Threat Analyst, San Antonio, TX
        13. [SJ-JOB] Information Assurance Engineer, Eadontown
        14. [SJ-JOB] Manager, Information Security, San Antonio, TX
        15. [SJ-JOB] Security Engineer, Sydney
        16. [SJ-JOB] Director, Information Security, San Antonio, TX
        17. [SJ-JOB] Security Engineer, San Diego
        18. [SJ-JOB] Instructor, Basel
        19. [SJ-JOB] Threat Analyst, San Antonio, TX
        20. [SJ-JOB] Security Consultant, San Antonio
        21. [SJ-JOB] Security Consultant, San Antonio, TX
        22. [SJ-JOB] Security Engineer, New York
        23. [SJ-JOB] Sr. Security Engineer, Irvine
        24. [SJ-JOB] Sr. Security Analyst, Hampshire
        25. [SJ-JOB] Application Security Engineer, Anywhere
        26. [SJ-JOB] Security Engineer, Santa Monica
        27. [SJ-JOB] Security Director, Atlanta
        28. [SJ-JOB] Sales Representative, Austin
        29. [SJ-JOB] Security Engineer, Fort Collins
        30. [SJ-JOB] Sr. Product Manager, San Diego
        31. [SJ-JOB] Account Manager, Atlanta
        32. [SJ-JOB] Security Engineer, New York
        33. [SJ-JOB] Security Engineer, Washginton DC
        34. [SJ-JOB] Information Assurance Engineer, Camp Victory,  Baghdad
        35. [SJ-JOB] VP, Information Security, Any Major US City
        36. [SJ-JOB] Security Consultant, Any Major West Coast City
        37. [SJ-JOB] Security Engineer, Phoenix
        38. [SJ-JOB] Security Engineer, Zurich
        39. [SJ-JOB] Security Researcher, Bangalore
        40. [SJ-JOB] Security Engineer, Irving
        41. [SJ-JOB] Security Consultant, Anywhere
        42. [SJ-JOB] Security Consultant, Any Major US City
        43. [SJ-JOB] Sr. Security Engineer, Mountain View
        44. [SJ-JOB] Sr. Security Analyst, Calgary
        45. [SJ-JOB] Security Engineer, Phoenix
        46. [SJ-JOB] Security Architect, McLean
        47. [SJ-JOB] Security Engineer, New York
        48. [SJ-JOB] Security Consultant, Calgary
        49. [SJ-JOB] Security Consultant, Skokie
        50. [SJ-JOB] Security Researcher, Pamplona
        51. [SJ-JOB] Security Engineer, brussels
        52. [SJ-JOB] Information Assurance Analyst, San Antonio
        53. [SJ-JOB] Security System Administrator, San Antonio
V.    INCIDENTS LIST SUMMARY
        1. Odd traffic again...... internal --> 100.100.100.1 (137-udp)
        2. New malware names and updates to PowerPoint FAQ document
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. IP address assignment problem
        2. SecurityFocus Microsoft Newsletter #305
        3. User creation audit trail
        4. Workstation Shutdown / Logoff Policy
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. Write-protect sctors?
        2. Write-protect sctors?
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Anonymous No More
By Mark Rasch
In early August, officials at America Online released information about searches being conducted by AOL members and users of the AOL search tool.
http://www.securityfocus.com/columnists/414

2. Microsoft Office security, part two
By Khushbu Jithra
This article discusses Microsoft Office's OLE Structured Storage and the nature of recent dropper programs and other exploit agents, in an effort to scrutinize the workings of some of the recent MS Office exploits. Part two will then collates some forensic investigation avenues through different MS Office features. Parts of the article sample different MS Office vulnerabilities to discuss their nature and the method of exploitation.
http://www.securityfocus.com/infocus/1874


II.  BUGTRAQ SUMMARY
--------------------
1. 8Pixel.net SimpleBlog Comments.ASP SQL Injection Vulnerability
BugTraq ID: 19609
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19609
Summary:
SimpleBlog is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

SimpleBlog 2.0 and prior versions are affected by this issue.

2. LBlog Comments.ASP SQL Injection Vulnerability
BugTraq ID: 19607
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19607
Summary:
LBlog is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

LBlog 1.05 and prior versions are affected by this issue.

3. Mozilla Firefox Javascript Navigator Object Remote Code Execution Vulnerability
BugTraq ID: 19192
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19192
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability because the application fails to properly sanitize user-supplied input before using it to create new JavaScript objects.

Successful exploits may allow an attacker to crash the application or execute arbitrary machine code in the context of the affected application.

This issue was previously discussed in BID 19181 (Mozilla Multiple Products Remote Vulnerabilities).
It has been assigned a separate BID because new information has become available.

4. Linux Kernel LSM ReadV/WriteV Security Restriction Bypass Vulnerability
BugTraq ID: 18105
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/18105
Summary:
The Linux kernel is susceptible to a security-restriction-bypass vulnerability. This issue is due to the kernel's failure to properly enforce Linux Security Module security checks.

This issue allows local attackers to bypass security restrictions, allowing them to read and write to files they do not have permissions to access. This may aid them in further attacks.

This issue occurs during read and write calls that occur after files have been opened. During the open process, proper security checks are enforced. This means that this issue is exploitable only when access to files is revoked after they have already been opened by an attacker.

Linux kernel versions prior to 2.6.16.12 are vulnerable to this issue.

5. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
BugTraq ID: 17587
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17587
Summary:
The Linux kernel is prone to vulnerabilities regarding access to shared memory.

A local attacker could potentially gain read and write access to shared memory and write access to read-only tmpfs filesystems, bypassing security restrictions.

An attacker can exploit these issues to possibly corrupt applications and their data when the applications use temporary files or shared memory.

6. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.

Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.

Sendmail versions prior to 8.13.6 are vulnerable to this issue.

7. Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability
BugTraq ID: 18850
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/18850
Summary:
Ubuntu Linux passwd may allow local attackers to gain elevated privileges. A successful attack may lead to a complete compromise.

8. Blackboard Products Multiple HTML Injection Vulnerabilities
BugTraq ID: 19308
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19308
Summary:
Blackboard products are prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Blackboard Learning System (Release 6) and Blackboard Learning and Community Portal Suite (Release 6 build 6.2.3.23) are vulnerable; other version may also be affected.

Reports indicate this issue has been addressed in versions 7.0 and 7.1; this has not been confirmed by Symantec.

9. PHProjekt Multiple Remote File Include Vulnerabilities
BugTraq ID: 19541
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19541
Summary:
Multiple remote file-include vulnerabilities affect PHProjekt because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call.

An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process.

Version 5.1 of PHProjekt is vulnerable to this issue; previous versions may be affected as well.

Reports indicate that conficting details have been released about these issues.

10. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19450
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19450
Summary:
AlsaPlayer is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer.

An attacker can exploit these issues to execute arbitrary code within the context of the application or cause a denial-of-service condition.

AlsaPlayer 0.99.76, the CVS version as of 9 Aug 2006, and prior versions are vulnerable to this issue; other versions may also be affected.

11. Yukihiro Matsumoto Ruby XMLRPC Server Denial of Service Vulnerability
BugTraq ID: 17645
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17645
Summary:
Ruby is affected by a denial-of-service vulnerability in the WEBrick HTTP server. This issue is due to the use of blocking network operations. Ruby's implementation of XML/RPC is also affected, since it uses the vulnerable WEBrick server.

This issue allows remote attackers to cause affected webservers to fail to respond to further legitimate requests.

Ruby versions prior to 1.8.3 are affected by this issue.

12. Linux Kernel IP_ROUTE_INPUT Local Denial of Service Vulnerability
BugTraq ID: 17593
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17593
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'ip_route_input()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.8.

13. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is prone to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.

This issue allows remote attackers to use affected computers in stealth network port and trust scans.

The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.

14. LibTIFF EstimateStripByteCounts() Denial of Service Vulnerability
BugTraq ID: 19284
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19284
Summary:
LibTIFF is affected by a denial-of-service vulnerability.

An attacker can exploit this vulnerability to cause a denial of service in applications using the affected library.

15. Linux Kernel NFS Client Denial of Service Vulnerability
BugTraq ID: 16922
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/16922
Summary:
Linux kernel NFS client is prone to a denial-of-service vulnerability. An unprivileged local user can panic the NFS client and cause it to fail.

This issue was addressed in Linux kernel 2.6.15.5; earlier versions are vulnerable.

16. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
BugTraq ID: 19286
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19286
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial of service in applications using the affected library.

17. Linux Kernel SDLA IOCTL Unauthorized Local Firmware Access Vulnerability
BugTraq ID: 16304
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/16304
Summary:
The Linux kernel is susceptible to a local access-validation vulnerability in the SDLA driver.

This issue allows local users with the 'CAP_NET_ADMIN' capability, but without the 'CAP_SYS_RAWIO' capability, to read and write to the SDLA device firmware. This may cause a denial-of-service issue if attackers write an invalid firmware. Other attacks may also be possibly by writing modified firmware files.

18. Linux Kernel Sysctl_String Local Buffer Overflow Vulnerability
BugTraq ID: 16141
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/16141
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. This issue is due to an off-by-one error in the 'sysctl' subsystem.

A successful attack may result in a denial-of-service condition or possibly arbitrary code execution in the context of the local kernel.

Linux kernel versions prior to 2.6.15 in the 2.6 series are considered vulnerable to this issue.

19. Linux Kernel IP6_Input_Finish Remote Denial Of Service Vulnerability
BugTraq ID: 16043
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/16043
Summary:
Linux kernel is prone to a remote denial-of-service vulnerability.

Remote attackers can exploit this to leak kernel memory. Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.

Linux kernel versions 2.6.12.5 and prior in the 2.6 series are vulnerable to this issue.

20. Cisco Content Service Switch Management Port UDP Denial Of Service Vulnerability
BugTraq ID: 9806
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/9806
Summary:
A problem in the handling of some types of malformed UDP network traffic to the Cisco Content Service Switch management port has been identified.  Because of this, it may be possible for an attacker to deny service to legitimate users of vulnerable systems.

21. Cisco NAC Agent Installation Security Bypass Vulnerability
BugTraq ID: 19726
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19726
Summary:
The Cisco NAC Agent is prone to a security-bypass vulnerability. This issue is due to a design error in the application.

An attacker can exploit this issue to bypass security restrictions. This results in a false sense of security and may aid attackers in further attacks.

22. LibTIFF Library Anonymous Field Merging Denial of Service Vulnerability
BugTraq ID: 19287
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19287
Summary:
The libTIFF' library is prone to a denial-of-service vulnerability.

An attacker can exploit this issue by submitting malformed image files.

When the libTIFF library routines process a malicious TIFF file, this could result in abnormal behavior, cause the application to become unresponsive, or possibly allow malicious code to execute.

23. Linux Kernel ATM Module Inconsistent Reference Counts Denial of Service Vulnerability
BugTraq ID: 17078
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/17078
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

This vulnerability affects the ATM module and allows local users to panic the kernel by creating inconsistent reference counts, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.14.

24. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19290
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19290
Summary:
The PixarLog Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.

This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial-of-service.

25. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
BugTraq ID: 19288
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19288
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of applications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

26. IrfanView ANI Image File Denial Of Service Vulnerability
BugTraq ID: 19452
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19452
Summary:
IrfanView is prone to a denial-of-service vulnerability.

A remote attacker may crash the application, resulting in denial-of-service conditions to legitimate users.

This issue may potentially be exploited to execute arbitrary machine code, but this has not been
confirmed.

Version 3.98.0 is vulnerable to this issue; other versions may also be affected.

27. PHP Error_Log Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 18645
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18645
Summary:
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, with the 'safe_mode' and 'open_basedir' restrictions assumed to isolate the users from each other.

This issue is reported to affect PHP versions 4.4.2 and 5.1.4; other versions may also be vulnerable.

28. XennoBB Icon_Topic SQL Injection Vulnerability
BugTraq ID: 19606
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19606
Summary:
XennoBB is prone to an SQL-injection vulnerability that could allow an attacker to influence the structure or logic of SQL queries made by the application.

29. Mambo CropImage Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19605
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19605
Summary:
The Mambo CropImage component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

30. PHP Multiple Security Bypass Vulnerabilities
BugTraq ID: 16878
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/16878
Summary:
PHP is prone to multiple input-validation vulnerabilities that could allow 'safe_mode' and 'open_basedir' security settings to be bypassed. These issues reside in the 'mb_send_mail()' function, the 'mail()' function, and various PHP IMAP functions.

31. Mambo CatalogShop Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19604
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19604
Summary:
The Mambo CatalogShop component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

32. MiniBill Config[Plugin_Dir] Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19568
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19568
Summary:
MiniBill is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

33. Mambo AkoComment Module mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19602
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19602
Summary:
The Mambo AkoComment module is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

34. GD Graphics Library Remote Integer Overflow Vulnerability
BugTraq ID: 11523
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/11523
Summary:
The GD Graphics Library (gdlib) is affected by an integer overflow that facilitates a heap overflow. This issue is due to the library's failure to do proper sanity checking on size values contained within image-format files.

An attacker may leverage this issue to manipulate process heap memory, potentially leading to code execution and compromise of the computer running the affected library.

35. Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
BugTraq ID: 19707
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19707
Summary:
Streamripper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by forcing the application to parse malformed HTTP headers, with the privileges of the user running the application.

36. Joomla Z00m Media Gallery Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19601
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19601
Summary:
The Joomla Z00m Media Gallery component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

37. GD Graphics Library Multiple Unspecified Remote Buffer overflow Vulnerabilities
BugTraq ID: 11663
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/11663
Summary:
Multiple unspecified remote buffer-overflow vulnerabilities have been identified in the GD Graphics Library. These issues are due to the library's failure to do sufficient bounds-checking before processing user-specified strings.

An attacker may leverage these issues to remotely execute arbitrary code on a computer with the privileges of a user that views a malicious image file. This may facilitate unauthorized access or privilege escalation.

38. RETIRED: Jupiter CMS Index.PHP Remote File Include Vulnerability
BugTraq ID: 19721
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19721
Summary:
Jupiter CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 1.1.5 is vulnerable to this issue; other versions may also be affected.

This BID has been retired.

39. RealVNC Clipboard Update Integer Overflow Vulnerability
BugTraq ID: 19599
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19599
Summary:
An integer-overflow vulnerability occurs in RealVNC. This issue is related to clipboard updates that occur during an authenticated session. The attack may be initiated by a malicious server or client.

The researcher who discovered this issue has stated that the vulnerability will result in a denial of service.

40. PHP Multiple Unspecified Vulnerabilities
BugTraq ID: 17843
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/17843
Summary:
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.

The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.

Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.

41. Roxio Toast DejaVu Component PATH Variable Local Privilege Escalation Vulnerability
BugTraq ID: 19596
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19596
Summary:
Roxio Toast is prone to a local privilege-escalation vulnerability because it fails to properly sanitize user-supplied input. As a result, local users may set their own search path for external applications that are called by setuid programs that are included in Roxio Toast.

This issue allows local attackers to gain superuser privileges, resulting in a complete compromise of affected computers.

This issue affects the DejaVu component that is installed by default in a standard installation of the vulnerable application. DejaVu is a third-party component that is maintained by Propaganda Productions. Roxio Toast version 7 Titanium includes the vulnerable component; other versions may also be affected.

42. Sonium Enterprise Addressbook Multiple Remote File Include Vulnerabilities
BugTraq ID: 19597
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19597
Summary:
Sonium Enterprise Addressbook is prone multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.2 is vulnerable to this issue; other versions may also be affected.

43.  Coppermine Gallery Component for Mambo cpg.PHP Remote File Include Vulnerability
BugTraq ID: 19589
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19589
Summary:
The Coppermine Gallery for Mambo is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

44. MamboWiki Component MamboLogin.PHP Remote File Include Vulnerability
BugTraq ID: 19594
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19594
Summary:
MamboWiki is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

MamboWiki 0.9.4 and prior versions are vulnerable to this issue; other versions may also be affected.

45. OpenOffice XML File Format Buffer Overflow Vulnerability
BugTraq ID: 18739
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18739
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious XML documents to cause a buffer overflow leading to read/write privileges to local files on a vulnerable computer.

46. OpenOffice Java Applet System Access Vulnerability
BugTraq ID: 18737
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18737
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious Java applets to gain read/write privileges to local files on a vulnerable computer.

47. Joomla Poll Component Multiple User Session Validation Vulnerability
BugTraq ID: 19592
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19592
Summary:
The Joomla poll component is prone to multiple user-session-validation vulnerabilities.

An attacker can exploit these issues to bypass session validation; this may lead to other attacks.

Joomla 1.0.10 is vulnerable to this issue; other versions may also be affected.

48. OpenOffice Arbitrary Macro Execution Vulnerability
BugTraq ID: 18738
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18738
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious macros to gain read/write privileges to local files on a vulnerable computer.

49. Joomla Kochsuite Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 19590
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19590
Summary:
The Joomla Kochsuite component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

50. Symantec Norton Personal Firewall SuiteOwners Registry Key Security Bypass Vulnerability
BugTraq ID: 19585
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19585
Summary:
Symantec Norton Personal Firewall is prone to a security-bypass vulnerability, allowing an attacker to potentially bypass security measures that are used to prevent modification of registry keys that are related to the affected software.

An attacker may exploit this vulnerability to bypass Norton's registry protection mechanism and modify the 'SuiteOwners' registry entry to load an arbitrary library file. This will likely lead to further attacks.

The individual who discovered this issue claims to have tested it on Norton Personal Firewall 2006 version 9.1.0.33. Other versions could also be affected. Norton Internet Security products that include the vulnerable application may also be affected.

Symantec is currently investigating this issue. This BID will be updated when further details are available.

51. ScriptsEZ Easy Ad-Manager Details.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18339
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18339
Summary:
Easy Ad-Manager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

52. IBM DB2 Multiple Denial of Service Vulnerabilities
BugTraq ID: 19586
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19586
Summary:
DB2 Universal Database is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial-of-service condition in applications using the affected library.

53. AOL Security Edition Local Privilege Escalation Vulnerability
BugTraq ID: 19583
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19583
Summary:
AOL Security Edition is prone to a local privilege-escalation vulnerability.

This vulnerability arises because of insecure default permissions associated with directories, which can allow local attackers to place arbitrary executables in a directory that may be executed with elevated privileges.

AOL Security Edition 9.0 is reported vulnerable; other versions may be affected as well.

54. Mambo A6MamboCredits Component Remote File Include Vulnerability
BugTraq ID: 19581
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19581
Summary:
The Mambo a6MamboCredits component is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.0.0 and prior are vulnerable to this issue; other versions may also be affected.

55. Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
BugTraq ID: 19579
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19579
Summary:
Apple Xsan filesystem is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it into an insufficiently sized buffer.

This issue may allow remote attackers to execute arbitrary machine code with system privileges on computers directly attached to the vulnerable filesystem. Failed exploit attempts will likely crash the system, denying service to legitimate users.

56. RETIRED: Jetbox CMS Search_function.PHP Remote File Include Vulnerability
BugTraq ID: 19722
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19722
Summary:
Jetbox CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Jetbox CMS version 2.1 is reported vulnerable; other versions may also be affected.


Update: This BID is being retired because the 'search_function.php' file is not vulnerable as reported.

57. IBM AIX Setlocale Function Local Privilege Escalation Vulnerability
BugTraq ID: 19578
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19578
Summary:
IBM AIX is prone to a local privilege-escalation vulnerability.

A local attacker may be able to exploit this issue to gain elevated privileges on the affected system. This may lead to other attacks.

IBM AIX versions 5.1, 5.2, and 5.3 are vulnerable to this issue.

58. Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
BugTraq ID: 18923
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18923
Summary:
Microsoft Windows DHCP Client service is prone to a remote code-execution vulnerability because the service fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This vulnerability allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges on affected computers. This facilitates the complete compromise of affected computers.

59. Blog:CMS Dir_Plugins Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19577
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19577
Summary:
Blog:CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Version 4.1.0 is vulnerable; other versions may also be affected.

60. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

61. Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
BugTraq ID: 19572
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19572
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability that occurs when instantiating Visual Studio COM objects.

The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, but this has not been confirmed.

This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). Note, however, that this issue affects a different set of COM objects that were not addressed in the previous BIDs.

62. Mambo Jim Component Install.Jim.PHP Remote File Include Vulnerability
BugTraq ID: 19575
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19575
Summary:
The Mambo jim component is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.01 and prior are vulnerable to this issue; other versions may also be affected.

63. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.

This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.

64. MambelFish Mambo Component Mambelfish.Class.PHP Remote File Include Vulnerability
BugTraq ID: 19574
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19574
Summary:
MambelFish is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

MambelFish 1.1 and prior are vulnerable to this issue; other versions may also be affected.

65. WTCom Web Torrent SQL Injection Vulnerability
BugTraq ID: 19569
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19569
Summary:
WTCom Web Torrent is prone to an SQL-injection vulnerability that could allow an attacker to influence the structure or logic of SQL queries made by the application.

66. Wireshark Multiple Vulnerabilities
BugTraq ID: 19690
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19690
Summary:
Wireshark is prone to multiple vulnerabilities:

- Multiple denial-of-service vulnerabilities.
- Multiple off-by-one vulnerabilities.

These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.

67. KTools Remote Buffer Overflow Vulnerability
BugTraq ID: 15600
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/15600
Summary:
The ktools library is prone to a remote buffer-overflow vulnerability.

An attacker may execute arbitrary code with the privileges of the application and gain unauthorized remote access.

Version 0.3 (and prior) of ktools is vulnerable to this issue.

68. PHP SSCANF() Safe_Mode Restriction-Bypass Vulnerability
BugTraq ID: 19415
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19415
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successful exploits could allow an attacker to write files in unauthorized locations and potentially execute code.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, all assuming that the 'safe_mode' restriction will isolate the users from each other.

This issue is reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.

69. Powergap Multiple Remote File Include Vulnerabilities
BugTraq ID: 19565
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19565
Summary:
Powergap is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.

A successful exploit may allow an attacker to execute remote PHP code in the context of the webserver process. This may allow the attacker to compromise the application or to access the underlying system.

70. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 17439
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/17439
Summary:
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.

These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, when the 'safe_mode' and 'open_basedir' restrictions are expected to isolate the users from each other.

These issues are reported to affect PHP versions 4.4.2 and 5.1.2; other versions may also be vulnerable.

71. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.

72. Microsoft Internet Explorer TSUserEX.DLL ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 19570
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19570
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of the 'tsuserex.dll' COM object ActiveX control.

Attackers may exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. Exploitation attempts may lead to a denial-of-service condition as well. Attackers may also employ HTML email to carry out an attack.

73. CliServ Web Community Multiple Remote File Include Vulnerabilities
BugTraq ID: 19737
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19737
Summary:
CliServ Web Community is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

  Version 0.65 is reported vulnerable; other versions may also be affected.

74. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19697
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19697
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

75. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19699
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19699
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

76. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19507
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19507
Summary:
ImageMagick is prone to a remote heap buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.

77. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain elevated privileges, which may lead to a complete compromise.

Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be affected as well.

78. Invisionix Roaming System Remote Pageheaderdefault.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 19567
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19567
Summary:
Invisionix Roaming System Remote is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.2 and prior are vulnerable to this issue; other versions may also be affected.

79. IBM EGatherer ActiveX Remote Buffer Overflow Vulnerability
BugTraq ID: 19554
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19554
Summary:
IBM EGatherer ActiveX is prone to a stack-based buffer-overflow vulnerability.

This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would allow a remote attacker to execute code with the privileges of the currently logged-in user.

IBM EGatherer ActiveX versions prior to 3.20.0284.0 are vulnerable to this issue.

80. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

81. Perl SuidPerl Multiple Local Vulnerabilities
BugTraq ID: 12426
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/12426
Summary:
SuidPerl is reported prone to multiple vulnerabilities. The following individual issues are reported:

- the 'PERLIO_DEBUG' SuidPerl environment variable may be employed to corrupt arbitrary files. A local unprivileged attacker may exploit this vulnerability to corrupt arbitrary files with superuser privileges. This may ultimately lead to a denial of service for legitimate users or to privilege escalation.

- SuidPerl is prone to a local buffer-overflow vulnerability as well. A local attacker may exploit this buffer-overflow vulnerability to gain superuser privileges. This issue is also exploited through the 'PERLIO_DEBUG' variable.

82. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2

83. LessTif Debug Feature Local Arbitrary File Creation Vulnerability
BugTraq ID: 19430
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19430
Summary:
LessTif is prone to a local arbitrary file-creation vulnerability. This issue is exposed when an application using the affected library runs with setuid-privileges.

This issue presents itself only when the library is compiled without the 'LESSTIF_PRODUCTION' definition. This occurs when the '--enable-production' configuration option is not selected when the package is built.

When used in conjunction with the 'mtink' binary, exploiting this issue has been demonstrated to gain superuser privileges.

LessTif version 0.93.94 is vulnerable to this issue; other versions may also be affected.

84. GNU BinUtils GAS Buffer Overflow Vulnerability
BugTraq ID: 19555
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19555
Summary:
GNU binutils GAS (GNU assembler) is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Remote attackers may crash the application or execute arbitrary machine code in the context of the application.

85. GNU BinUtils Buffer Overflow Vulnerability
BugTraq ID: 17950
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/17950
Summary:
GNU binutils is susceptible to a buffer-overflow vulnerability because it fails to properly bounds check user-supplied input prior to copying it to an insufficiently-sized memory buffer.

Remote attackers may crash the strings utility, potentially making analysis of malicious binaries more difficult. Attackers may also execute arbitrary machine code in the context of applications that utilize the affected library.

86. ModuleBased CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 19754
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19754
Summary:
ModuleBased CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Version pre-alpha is vulnerable; other versions may also be affected.

87. ExBB Italia UserStop.PHP Remote File Include Vulnerability
BugTraq ID: 19753
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19753
Summary:
ExBB Italia is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

ExBB Italia version 0.2 is vulnerable to this issue; other versions may also be affected.

88. PHPECard Functions.PHP Remote File Include Vulnerability
BugTraq ID: 19752
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19752
Summary:
phpECard is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

  Versions 2.1.4 and prior are reported vulnerable; other versions may also be affected.

89. PhpGroupWare Calendar Class.Holidaycalc.Inc.PHP Local File Include Vulnerability
BugTraq ID: 19751
Remote: No
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19751
Summary:
phpGroupWare is prone to a local file-include vulnerability because the application fails to sufficiently sanitize user supplied-input. This issue may facilitate disclosure of sensitive data and could allow the execution of arbitrary local script code in the context of the application.

90. Mod_PHPAlbum Sommaire_Admin.PHP Remote File Include Vulnerability
BugTraq ID: 19750
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19750
Summary:
mod_phpalbum is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

  Versions 2.15 and prior are reported vulnerable; other versions may also be affected.

91. CJ Tag Board User-Agent PHP Code Injection Vulnerability
BugTraq ID: 19748
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19748
Summary:
CJ Tag Board is prone to a vulnerability that may allow remote attackers to inject arbitrary PHP code into scripts.

A successful attack may result in unauthorized access in the context of the server.

CJ Tag Board 3.0 is reported to be vulnerable.  Other versions may be affected as well.

92. PMWiki Table Markups HTML Injection Vulnerability
BugTraq ID: 19747
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19747
Summary:
PMWiki is prone to an HTML-injection vulnerability. An attacker may inject hostile HTML and script code into vulnerable sections of the application. When viewed, this code may be rendered in the browser of a user visiting the site in the context of the affected website.

93. HLstats Hlstats.PHP Cross Site Scripting Vulnerability
BugTraq ID: 19745
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19745
Summary:
HLstats is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.

This issue may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Version 1.34 is reported to be affected by this issue; other versions may also be affected.

94. SAP-DB/MaxDB WebDBM Remote Buffer Overflow Vulnerability
BugTraq ID: 19660
Remote: Yes
Last Updated: 2006-08-29
Relevant URL: http://www.securityfocus.com/bid/19660
Summary:
SAP-DB and MaxDB are prone to a remote buffer-overflow vulnerability because these applications fail to perform sufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code with privileges of the 'wahttp' process. Failed exploit attempts will likely crash the application, denying further service to legitimate users.

95. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.13.

96. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19282
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19282
Summary:
The Next RLE Decoder for libTIFF is prone to a remote heap buffer-overflow vulnerability.

This issue occurs because the application fails to check boundary conditions on certain RLE decoding operations.

This issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial of service.

97. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
BugTraq ID: 18099
Remote: No
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/18099
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'choose_new_parent' function.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.11.12.

98. Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
BugTraq ID: 12798
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/12798
Summary:
Mozilla Suite/Firefox and Thunderbird are reported prone to a URI obfuscation weakness. The issue is reported to manifest when 'Save Link As...' functionality is invoked on an malicious anchor tag.

This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present downloads to users that seem to originate from a trusted location. This may facilitate attacks based on this false sense of trust.

99. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
BugTraq ID: 19283
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19283
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

100. Mozilla Foundation Products XPCOM Memory Corruption Vulnerability
BugTraq ID: 19197
Remote: Yes
Last Updated: 2006-08-28
Relevant URL: http://www.securityfocus.com/bid/19197
Summary:
Various Mozilla Foundation products are prone to a memory-corruption vulnerability.

This issue occurs because the applications fail to handle simultaneous XPCOM events that would cause the deletion of the timer object.

An attacker can exploit this issue to execute arbitrary code.

This issue was previously discussed in BID 19181 (Mozilla Multiple Products Remote Vulnerabilities). It has been assigned a separate BID because new information has become available.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Linux update becomes terminal pain
By: Robert Lemos
Users of the increasingly popular Ubuntu distribution find themselves having to deal with the command-line terminal after an update breaks the graphical X Windows subsystem.
http://www.securityfocus.com/news/11409

2. Microsoft patch opens users to attack
By: Robert Lemos
UPDATE: The software giant rushes to fix a security hole introduced during its latest patch for Internet Explorer that opens Windows XP SP1 and Windows 2000 users to attack.
http://www.securityfocus.com/news/11408

3. Bot spreads using latest Windows flaw
By: Robert Lemos
Security firms advise companies and home users to patch their Windows systems after detecting a bot program using a recently fixed flaw to compromise computers.

http://www.securityfocus.com/news/11407

4. Covert channel tool hides data in IPv6
By: Robert Lemos
Announced at the DEFCON hacking conference, a tool dubbed VoodooNet hides a small amount of data in IPv6 error messages, where most security devices do not even look.
http://www.securityfocus.com/news/11406

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Technical Support Engineer, Fredericton
http://www.securityfocus.com/archive/77/444664

2. [SJ-JOB] Quality Assurance, Fredericton
http://www.securityfocus.com/archive/77/444674

3. [SJ-JOB] Senior Software Engineer, Fredericton
http://www.securityfocus.com/archive/77/444663

4. [SJ-JOB] Customer Support, San Antonio, TX
http://www.securityfocus.com/archive/77/444666

5. [SJ-JOB] Developer, San  Antonio, TX
http://www.securityfocus.com/archive/77/444667

6. [SJ-JOB] Security Consultant, San Antonio, TX
http://www.securityfocus.com/archive/77/444669

7. [SJ-JOB] Management, San Francisco
http://www.securityfocus.com/archive/77/444613

8. [SJ-JOB] Security Consultant, Remote
http://www.securityfocus.com/archive/77/444637

9. [SJ-JOB] Security Consultant, Seattle
http://www.securityfocus.com/archive/77/444657

10. [SJ-JOB] Security Consultant, Chicago, Il/San Francisco,    CA/Cambridge, MA/ Seattle, WA
http://www.securityfocus.com/archive/77/444634

11. [SJ-JOB] Security Engineer, Beltsville
http://www.securityfocus.com/archive/77/444564

12. [SJ-JOB] Threat Analyst, San Antonio, TX
http://www.securityfocus.com/archive/77/444565

13. [SJ-JOB] Information Assurance Engineer, Eadontown
http://www.securityfocus.com/archive/77/444538

14. [SJ-JOB] Manager, Information Security, San Antonio, TX
http://www.securityfocus.com/archive/77/444520

15. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/444521

16. [SJ-JOB] Director, Information Security, San Antonio, TX
http://www.securityfocus.com/archive/77/444528

17. [SJ-JOB] Security Engineer, San Diego
http://www.securityfocus.com/archive/77/444530

18. [SJ-JOB] Instructor, Basel
http://www.securityfocus.com/archive/77/444539

19. [SJ-JOB] Threat Analyst, San Antonio, TX
http://www.securityfocus.com/archive/77/444517

20. [SJ-JOB] Security Consultant, San Antonio
http://www.securityfocus.com/archive/77/444518

21. [SJ-JOB] Security Consultant, San Antonio, TX
http://www.securityfocus.com/archive/77/444519

22. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/444541

23. [SJ-JOB] Sr. Security Engineer, Irvine
http://www.securityfocus.com/archive/77/444511

24. [SJ-JOB] Sr. Security Analyst, Hampshire
http://www.securityfocus.com/archive/77/444512

25. [SJ-JOB] Application Security Engineer, Anywhere
http://www.securityfocus.com/archive/77/444515

26. [SJ-JOB] Security Engineer, Santa Monica
http://www.securityfocus.com/archive/77/444516

27. [SJ-JOB] Security Director, Atlanta
http://www.securityfocus.com/archive/77/444513

28. [SJ-JOB] Sales Representative, Austin
http://www.securityfocus.com/archive/77/444336

29. [SJ-JOB] Security Engineer, Fort Collins
http://www.securityfocus.com/archive/77/444333

30. [SJ-JOB] Sr. Product Manager, San Diego
http://www.securityfocus.com/archive/77/444334

31. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/444335

32. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/444352

33. [SJ-JOB] Security Engineer, Washginton DC
http://www.securityfocus.com/archive/77/444353

34. [SJ-JOB] Information Assurance Engineer, Camp Victory,  Baghdad
http://www.securityfocus.com/archive/77/444332

35. [SJ-JOB] VP, Information Security, Any Major US City
http://www.securityfocus.com/archive/77/444274

36. [SJ-JOB] Security Consultant, Any Major West Coast City
http://www.securityfocus.com/archive/77/444281

37. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/444273

38. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/444275

39. [SJ-JOB] Security Researcher, Bangalore
http://www.securityfocus.com/archive/77/444277

40. [SJ-JOB] Security Engineer, Irving
http://www.securityfocus.com/archive/77/444282

41. [SJ-JOB] Security Consultant, Anywhere
http://www.securityfocus.com/archive/77/444283

42. [SJ-JOB] Security Consultant, Any Major US City
http://www.securityfocus.com/archive/77/444264

43. [SJ-JOB] Sr. Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/444267

44. [SJ-JOB] Sr. Security Analyst, Calgary
http://www.securityfocus.com/archive/77/444276

45. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/444265

46. [SJ-JOB] Security Architect, McLean
http://www.securityfocus.com/archive/77/444266

47. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/444268

48. [SJ-JOB] Security Consultant, Calgary
http://www.securityfocus.com/archive/77/444128

49. [SJ-JOB] Security Consultant, Skokie
http://www.securityfocus.com/archive/77/444129

50. [SJ-JOB] Security Researcher, Pamplona
http://www.securityfocus.com/archive/77/444122

51. [SJ-JOB] Security Engineer, brussels
http://www.securityfocus.com/archive/77/444119

52. [SJ-JOB] Information Assurance Analyst, San Antonio
http://www.securityfocus.com/archive/77/444120

53. [SJ-JOB] Security System Administrator, San Antonio
http://www.securityfocus.com/archive/77/444121

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Odd traffic again...... internal --> 100.100.100.1 (137-udp)
http://www.securityfocus.com/archive/75/444209

2. New malware names and updates to PowerPoint FAQ document
http://www.securityfocus.com/archive/75/444197

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. IP address assignment problem
http://www.securityfocus.com/archive/88/444349

2. SecurityFocus Microsoft Newsletter #305
http://www.securityfocus.com/archive/88/444097

3. User creation audit trail
http://www.securityfocus.com/archive/88/444098

4. Workstation Shutdown / Logoff Policy
http://www.securityfocus.com/archive/88/443340

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Write-protect sctors?
http://www.securityfocus.com/archive/91/444603

2. Write-protect sctors?
http://www.securityfocus.com/archive/91/444500

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics

FREE Webcast: "Building a Web Application Assessment Program"
During this Webcast, you will learn; key challenges to implementing a Web application assessment program, how to limit false positives and increase  accuracy and why engaging developers is critical to the security process.

https://download.spidynamics.com/1/ad/AMPw.asp?Campaign_ID=70160000000CaZH