SecurityFocus Newsletter #366

Peter Laborge <[email protected]> Tue, 05 Sep 2006 16:37:22 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #366
----------------------------------------

This issue is Sponsored by: Watchfire

AppScan 6.5 is now available! New features for Web services testing, Advanced Automated Capabilities for Penetration Testers, PCI compliance reporting, Token Analysis, Authentication testing, Automated JavaScript execution and much more. Download a Free Trial of AppScan today!

https://www.watchfire.com/securearea/appscancamp.aspx?id=701500000008Vmd

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Disclosure survey
        2. Microsoft Office security, part two
II.   BUGTRAQ SUMMARY
        1. IntegraMOD PHPbb_Root_Path Multiple Remote File Include Vulnerabilities
        2. Linux Kernel Asynchronous Input/Output Local Denial Of Service Vulnerability
        3. Membrepass Multiple Cross-Site Scripting Vulnerabilities
        4. Evision CMS Path Parameter Multiple Remote File Include Vulnerabilities
        5. ExBB Home_Path Parameter Multiple Remote File Include Vulnerabilities
        6. X.Org X Window Server Local Privilege Escalation Vulnerability
        7. Joomla! Multiple Security Vulnerabilities
        8. PortailPHP Mod_PHPAlbum Sommaire_Admin.PHP Remote File Include Vulnerability
        9. OpenOffice Java Applet System Access Vulnerability
        10. FreeType TTF File Remote Buffer Overflow Vulnerability
        11. Lyris ListManager Unauthorized Administrative User Addition Vulnerability
        12. FreeType TTF File Remote Denial of Service Vulnerability
        13. Webmin and Usermin HTML Injection and Information Disclosure Vulnerability
        14. Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
        15. CubeCart Multiple Security Vulnerabilities
        16. HP OpenVMS Local Password Disclosure Vulnerability
        17.  MySQL MERGE Priviledge Revoke Bypass Vulnerability
        18. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
        19. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
        20. MySQL Privilege Elevation and Security Bypass Vulnerabilities
        21. Graphiks GrapAgenda Index.PHP Remote File Include Vulnerability
        22. ZixForum ReplyNew.ASP SQL Injection Vulnerability
        23. AnnoncesV Annonce.PHP Remote File Include Vulnerability
        24. J River Media Center Mediacenter.EXE Buffer Overflow Vulnerability
        25. DSocks Name Variable Buffer Overflow Vulnerability
        26. MySpeach JScript.PHP Remote File Include Vulnerability
        27. Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
        28. Gallery Stats Module Information Disclosure Vulnerability
        29. eIQNetworks Enterprise Security Analyzer Monitoring.EXE Multiple Buffer Overflow Vulnerabilities
        30. eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
        31. eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
        32. eIQnetworks Enterprise Security Analyzer License Manager Remote Buffer Overflow Vulnerability
        33. eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
        34. Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
        35. 3Com TippingPoint SMS Information Disclosure Vulnerability
        36. Debian hztty Multiple Buffer Overflow Vulnerabilities
        37. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
        38. ICBlogger Devam.ASP SQL Injection Vulnerability
        39. ToendaCMS Remote File Include Vulnerability
        40. Papoo CMS IBrowser Remote File Include Vulnerability
        41. SnapGear Multiple Unspecified Denial of Service Vulnerabilities
        42. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
        43. Sendmail Long Header Denial Of Service Vulnerability
        44. Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
        45. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
        46. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
        47. GTetrinet Index Out of Bounds Unspecified Remote Code Execution Vulnerability
        48. Ruby on Rails Routing Denial of Service Vulnerability
        49. Py2Play Object Unpickling Remote Python Code Execution Vulnerability
        50. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
        51. GDB DWARF Multiple Buffer Overflow Vulnerabilities
        52. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
        53. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
        54. Samba Internal Data Structures Denial of Service Vulnerability
        55. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
        56. VBZoom Profile.PHP Cross-Site Scripting Vulnerability
        57. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
        58. CAPI4Hylafax Remote Arbitrary Command Execution Vulnerability
        59. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
        60. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
        61. Rob Brown Net-Server Perl Module Logging Function Format String Vulnerability
        62. GD Graphics Library Remote Denial of Service Vulnerability
        63. Internet Security Systems BlackICE Local Denial of Service Vulnerability
        64. TIBCO Rendezvous HTTP Interface Remote Buffer Overflow Vulnerability
        65. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
        66. Cybozu Multiple Products Directory Traversal Vulnerability
        67. YACS Multiple Remote File Include Vulnerabilities
        68. GDB Multiple Vulnerabilities
        69. Cerberus Helpdesk Ticket Parameter Unauthorized Access Vulnerability
        70. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
        71. OpenSSH SCP Shell Command Execution Vulnerability
        72. Sun Solaris 10 Kernel Patches Denial of Service Vulnerability
        73. Sun Solaris Kernel Debugger KMDB(1) Local Denial of Service Vulnerability
        74. Sun Solaris SysInfo Local Information Disclosure Vulnerability
        75. Sun Solaris Event Port API Denial of Service Vulnerability
        76. Sun Internet Protocol Implementation Routing Table Bypass Vulnerability
        77. Sudo Python Environment Variable Handling Security Bypass Vulnerability
        78. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
        79. Multiple X.Org Products SetUID Local Privilege Escalation Vulnerability
        80. Compression Plus Zoo Format Stack Overflow Vulnerability
        81. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
        82. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
        83. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
        84. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
        85. IBM AIX Setlocale Function Local Privilege Escalation Vulnerability
        86. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
        87. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        88. OpenBSD Semaphore Allocation Denial Of Service Vulnerability
        89. Xoops Edituser.PHP SQL Injection Vulnerability
        90. MySQL Multiupdate and Subselects Denial Of Service Vulnerability
        91. Tor Multiple Buffer Overflow/Information Disclosure/Denial of Service Vulnerabilities
        92. PhpGroupWare Calendar Class.Holidaycalc.Inc.PHP Local File Include Vulnerability
        93. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
        94. MySQL User-Defined Function Buffer Overflow Vulnerability
        95. MySQL Query Logging Bypass Vulnerability
        96. LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
        97. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
        98.  Membrepass Recherchemembre.PHP SQL Injection Vulnerability
        99. Membrepass Variable.PHP Remote File Include Vulnerability
        100. IBM AIX Dtterm Local Privilege Escalation Vulnerability
III.  SECURITYFOCUS NEWS
        1. Trusted computing a shield against worst attacks?
        2. Linux update becomes terminal pain
        3. Microsoft patch opens users to attack
        4. Bot spreads using latest Windows flaw
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Information Assurance Engineer, Fort Belvoir
        2. [SJ-JOB] Information Assurance Engineer, Sterling
        3. [SJ-JOB] Security Engineer, Columbia
        4. [SJ-JOB] Security Engineer, Columbia
        5. [SJ-JOB] Security System Administrator, New York
        6. [SJ-JOB] Auditor, San Jose
        7. [SJ-JOB] Security System Administrator, New York
        8. [SJ-JOB] Security Engineer, Phoenix
        9. [SJ-JOB] Director, Information Security, Charlotte
        10. [SJ-JOB] Management, New York
        11. [SJ-JOB] Sr. Security Analyst, Atlanta
        12. [SJ-JOB] Security Engineer, London
        13. [SJ-JOB] Management, Sunnyvale
        14. [SJ-JOB] Security Engineer, Southfield
        15. [SJ-JOB] Sr. Security Analyst, Fort Worth
        16. [SJ-JOB] Security Engineer, Santa Monica
        17. [SJ-JOB] Forensics Engineer, Marietta
        18. [SJ-JOB] Security Consultant, New York/Northern NJ
        19. [SJ-JOB] Sales Representative, Kensington
        20. [SJ-JOB] Security Engineer, Fort Worth
        21. [SJ-JOB] Sr. Security Analyst, Miami
        22. [SJ-JOB] Application Security Architect, London
        23. [SJ-JOB] Security Architect, washington
        24. [SJ-JOB] Certification & Accreditation Engineer, Cambridge
        25. [SJ-JOB] Security Engineer, West Coast
V.    INCIDENTS LIST SUMMARY
        1. New NT4/Windows botnet reported
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Hackers to Hackers Conferece III - Call for Papers
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Disabling syskey on XP pro
        2. FW: MST transforms templates from sec persepctive?
        3. Fwd: Whole disk encryption
        4. SecurityFocus Microsoft Newsletter #306
        5. Workstation Shutdown / Logoff Policy
        6. Account Control: Running Windows Vista with Least Privilege
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Disclosure survey
By Federico Biancuzzi
Federico Biancuzzi surveys statements from some of the world's largest software companies about vulnerability disclosure, interviews two security companies who pay for vulnerabilities, and then talks with three prominent, independent researchers about their thoughts on choosing a responsible disclosure process. In three parts.
http://www.securityfocus.com/columnists/415

2. Microsoft Office security, part two
By Khushbu Jithra
This article discusses Microsoft Office's OLE Structured Storage and the nature of recent dropper programs and other exploit agents, in an effort to scrutinize the workings of some of the recent MS Office exploits. Part two will then collates some forensic investigation avenues through different MS Office features. Parts of the article sample different MS Office vulnerabilities to discuss their nature and the method of exploitation.
http://www.securityfocus.com/infocus/1874


II.  BUGTRAQ SUMMARY
--------------------
1. IntegraMOD PHPbb_Root_Path Multiple Remote File Include Vulnerabilities
BugTraq ID: 19809
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19809
Summary:
IntegraMOD is prone to multiple remote file-include vulnerabilities.

This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

IntegraMOD 2.0 rc2 and previous versions are affected by this issue.

2. Linux Kernel Asynchronous Input/Output Local Denial Of Service Vulnerability
BugTraq ID: 12987
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/12987
Summary:
A local denial-of-service vulnerability affects the Linux kernel because it fails to properly manage input/output resources.

A local attacker may leverage this issue to cause an affected Linux kernel to panic, effectively denying service to legitimate users.

3. Membrepass Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19789
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19789
Summary:
Membrepass is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

These issues affect version 1.5; other versions may also be vulnerable.

4. Evision CMS Path Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19788
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19788
Summary:
Evision CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

Version 1.0 is reported vulnerable; other versions may also be affected.

5. ExBB Home_Path Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 19787
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19787
Summary:
ExBB is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 1.9.1; other versions may also be vulnerable.

6. X.Org X Window Server Local Privilege Escalation Vulnerability
BugTraq ID: 17169
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/17169
Summary:
The X.Org X Window server is prone to a privilege-escalation vulnerability.

A local attacker can exploit this issue to load arbitrary modules and execute them or overwrite arbitrary files with superuser privileges. This may facilitate a complete compromise of the affected computer.

7. Joomla! Multiple Security Vulnerabilities
BugTraq ID: 19749
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19749
Summary:
Joomla! is prone to multiple security vulnerabilities, including varius cross-site scripting, code-injection, input-validation, and access-control-bypass issues. These issues are caused by design and configuration weaknesseses and by a failure in the application to properly sanitize user-supplied input in several cases.

A number of these issues may have already been documented in other BIDs.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, inject arbitrary hostile code, or even exploit vulnerabilities in the underlying system or database implementation. Presumably, some of these issues may facilitate remote unauthorized access. Other attacks are also possible.

All versions of Joomla! prior to version 1.0.11 are vulnerable to these issues. Updates are available.

8. PortailPHP Mod_PHPAlbum Sommaire_Admin.PHP Remote File Include Vulnerability
BugTraq ID: 19750
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19750
Summary:
PortailPHP mod_phpalbum is prone to a remote file-include vulnerability because the fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 2.15 and earlier are reported vulnerable; other versions may also be affected.

9. OpenOffice Java Applet System Access Vulnerability
BugTraq ID: 18737
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18737
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious Java applets to gain read/write privileges to local files on a vulnerable computer.

10. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

11. Lyris ListManager Unauthorized Administrative User Addition Vulnerability
BugTraq ID: 19784
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19784
Summary:
Lyris ListManager is prone to a design flaw that facilitates the addition of an unauthorized administrative user. The issue derives from the use of hidden form fields in the 'add administrator' form.

Attackers with administrative privileges to a Lyris list may exploit this vulnerability to add administrative users to arbitrary lists hosted on the same server. For example, an administrator for List-A can maliciously modify hidden form fields when conventionally adding an administrative user, causing that user to be added as an administrator to List-B.

Version 8.95 is vulnerable; other versions may also be affected.

12. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.

This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

13. Webmin and Usermin HTML Injection and Information Disclosure Vulnerability
BugTraq ID: 19820
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19820
Summary:
Webmin and Usermin are prone to a HTML-injection and information disclosure vulnerability.

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user and gain sensitive information.

Usermin versions prior to 1.226 and Webmin versions prior to 1.296 are vulnerable to this issue.

14. Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
BugTraq ID: 18108
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18108
Summary:
Vixie cron is susceptible to a local privilege-escalation vulnerability. This issue is due to the application's failure to properly drop superuser privileges in certain circumstances when executing jobs.

This issue allows local attackers that have been authorized to execute cron jobs to execute arbitrary commands with superuser privileges. This facilitates the complete compromise of affected computers.

Vixie cron version 4.1 is vulnerable to this issue when used in conjunction with pam_limits. Other versions may also be affected.

15. CubeCart Multiple Security Vulnerabilities
BugTraq ID: 19782
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19782
Summary:
CubeCart is prone to multiple security vulnerabilities, including cross-site scripting, remote file inclusion, and a SQL-injection issue, because the application fails to properly sanitize user-supplied input. The vendor has released updates that address these vulnerabilities.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

CubeCart 3.0.12 is vulnerable to these issues; other versions may also be affected.

16. HP OpenVMS Local Password Disclosure Vulnerability
BugTraq ID: 19783
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19783
Summary:
OpenVMS is prone to a local password-disclosure vulnerability.

This vulnerability may allow local attackers to access user passwords. Sensitive information gathered using this attack can lead to other attacks against the computer.

OpenVMS ALPHA V7.3-2 is reported vulnerable.

17.  MySQL MERGE Priviledge Revoke Bypass Vulnerability
BugTraq ID: 19279
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19279
Summary:
MySQL is prone to a vulnerability that allows users with revoked privileges to a particular table to access these tables without permission.

This issue allows attackers to gain access to data when access privileges have been revoked. The specific impact of this issue depends on the data that the attacker may retrieve.

18. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19699
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19699
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

19. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19697
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19697
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

20. MySQL Privilege Elevation and Security Bypass Vulnerabilities
BugTraq ID: 19559
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19559
Summary:
MySQL is prone to these vulnerabilities:

- A privilege-elevation vulnerability; a user with privileges to execute SUID routines may gain elevated privileges by executing certain commands and code with higher privileges.

- A security-bypass vulnerability; a user can bypass restrictions and create new databases.

MySQL 5.0.24 and prior versions are affected by these issues.

21. Graphiks GrapAgenda Index.PHP Remote File Include Vulnerability
BugTraq ID: 19857
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19857
Summary:
Graphiks GrapAgenda is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.1 is affected by this issue; other versions may also be vulnerable.

22. ZixForum ReplyNew.ASP SQL Injection Vulnerability
BugTraq ID: 19855
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19855
Summary:
ZixForum is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

ZixForum 1.12 and previous versions are affected by this issue.

23. AnnoncesV Annonce.PHP Remote File Include Vulnerability
BugTraq ID: 19854
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19854
Summary:
annoncesV is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 1.1; other versions may also be vulnerable.

24. J River Media Center Mediacenter.EXE Buffer Overflow Vulnerability
BugTraq ID: 19853
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19853
Summary:
Media Center and various Media Center plugins are prone to a buffer-overflow vulnerability.

This issue occurs because the application does not bounds check data before copying it into a finite-sized buffer.

This issue allows remote attackers to cause the application to crash, denying service to the legitimate user. Arbitrary code execution may be possible; this has not been confirmed.

Version 11.0.309 is vulnerable to this issue; other versions may also be affected.

25. DSocks Name Variable Buffer Overflow Vulnerability
BugTraq ID: 19852
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19852
Summary:
Dsocks is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

An attacker may exploit this vulnerability to execute arbitrary code in the context of the user running the application or to crash the application, resulting in denial-of-service conditions.

26. MySpeach JScript.PHP Remote File Include Vulnerability
BugTraq ID: 19851
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19851
Summary:
MySpeach is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 3.0.2 and prior are vulnerable to this issue; other versions may also be affected.

27. Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
BugTraq ID: 19297
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19297
Summary:
Novell GroupWise is prone to multiple HTML-injection vulnerabilities.

These issues occur because the application fails to sanitize user-input before using dynamically generated content.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

28. Gallery Stats Module Information Disclosure Vulnerability
BugTraq ID: 19453
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19453
Summary:
Gallery is prone to an information-disclosure vulnerability because it fails to protect sensitive information.

An attacker can exploit this issue to gain sensitive information, which could lead to other attacks.

29. eIQNetworks Enterprise Security Analyzer Monitoring.EXE Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19424
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19424
Summary:
eIQnetworks Enterprise Security Analyzer is prone to multiple remote buffer-overflow vulnerabilities.

These issues can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.

30. eIQNetworks Enterprise Security Analyzer Multiple Syslog Daemon Buffer Overflow Vulnerabilities
BugTraq ID: 19167
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19167
Summary:
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to multiple remote buffer-overflow vulnerabilities.

These issues can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.

31. eIQNetworks Enterprise Security Analyzer SyslogServer.EXE Buffer Overflow Vulnerability
BugTraq ID: 19165
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19165
Summary:
eIQnetworks Enterprise Security Analyzer Syslog daemon is prone to a remote buffer-overflow vulnerability.

This issue can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.

32. eIQnetworks Enterprise Security Analyzer License Manager Remote Buffer Overflow Vulnerability
BugTraq ID: 19163
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19163
Summary:
eIQnetworks Enterprise Security Analyzer License Manager is prone to a remote buffer-overflow vulnerability.

This issue can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable.

33. eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffer Overflow Vulnerability
BugTraq ID: 19164
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19164
Summary:
eIQnetworks Enterprise Security Analyzer Topology Server is prone to a remote buffer-overflow vulnerability.

This issue can facilitate a remote compromise due to arbitrary code execution.

Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable. OEM vendors' versions prior to 4.6 are also vulnerable.

34. Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
BugTraq ID: 10336
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/10336
Summary:
Various Symantec Client Firewall products are prone to a remote denial-of-service vulnerability because the applications fail to properly handle DNS response packets.

35. 3Com TippingPoint SMS Information Disclosure Vulnerability
BugTraq ID: 17935
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/17935
Summary:
TippingPoint SMS is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to retrieve potentially sensitive information.

36. Debian hztty Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 8656
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/8656
Summary:
Multiple buffer-overflow vulnerabilities occur in Debian's hztty program. These issues may allow an attacker to gain unauthorized access to a vulnerable host. The issues occur because the utility fails to do sufficient boundary checking.

Successful exploitation of these issue may allow an attacker to execute arbitrary code in the context of the user who is running the vulnerable software.

Version 2.0-5.2 of hztty has been reported vulnerable; other versions may be affected as well.

37. PHP Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 17439
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/17439
Summary:
PHP is prone to multiple 'safe_mode' and 'open_basedir' restriction-bypass vulnerabilities. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.

These vulnerabilities would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code, when the 'safe_mode' and 'open_basedir' restrictions are expected to isolate the users from each other.

These issues are reported to affect PHP versions 4.4.2 and 5.1.2; other versions may also be vulnerable.

38. ICBlogger Devam.ASP SQL Injection Vulnerability
BugTraq ID: 19808
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19808
Summary:
ICBlogger is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

ICBlogger 2.0 is vulnerable to this issue; other versions may be affected as well.

39. ToendaCMS Remote File Include Vulnerability
BugTraq ID: 19806
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19806
Summary:
ToendaCMS is prone a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects ToendaCMS 1.0.3 and prior; other versions may also be affected.

40. Papoo CMS IBrowser Remote File Include Vulnerability
BugTraq ID: 19807
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19807
Summary:
Papoo CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Papoo CMS 3.0.2 is reported vulnerable; other versions may also be affected.

41. SnapGear Multiple Unspecified Denial of Service Vulnerabilities
BugTraq ID: 19805
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19805
Summary:
SnapGear is prone to multiple unspecified remote denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to crash an affected device, effectively denying service to legitimate users.

This issue affects SnapGear firmware version 3 series.

42. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
BugTraq ID: 18092
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18092
Summary:
PostgreSQL is prone to SQL-injection vulnerabilities. These issues are due to a potential mismatch of multibyte character conversions between PostgreSQL servers and client applications.

A successful exploit could allow an attacker to execute arbitrary SQL statements on affected servers. This may allow the attacker to compromise the targeted computer, access or modify data, or exploit other latent vulnerabilities.

PostgreSQL versions prior to 7.3.15, 7.4.13, 8.0.8, and 8.1.4 are vulnerable to these issues.

43. Sendmail Long Header Denial Of Service Vulnerability
BugTraq ID: 19714
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19714
Summary:
Sendmail is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to crash the Sendmail process causing a denial-of-service.

44. Streamripper HTTP Header Parsing Buffer Overflow Vulnerability
BugTraq ID: 19707
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19707
Summary:
Streamripper is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by forcing the application to parse malformed HTTP headers, with the privileges of the user running the application.

45. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
BugTraq ID: 18944
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18944
Summary:
Ruby is prone to multiple vulnerabilities that let attackers bypass SAFE-level restrictions.

These issues allow attackers to bypass the expected SAFE-level restrictions, possibly allowing them to execute unauthorized script code in the context of affected applications. The specific impact of these issues depends on the implementation of scripts that use SAFE-level security checks.

46. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19450
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19450
Summary:
AlsaPlayer is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer.

An attacker can exploit these issues to execute arbitrary code within the context of the application or cause a denial-of-service condition.

AlsaPlayer 0.99.76, the CVS version as of 9 Aug 2006, and prior versions are vulnerable to this issue; other versions may also be affected.

47. GTetrinet Index Out of Bounds Unspecified Remote Code Execution Vulnerability
BugTraq ID: 19766
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19766
Summary:
GTetrinet is prone to an unspecified remote vulnerability. This issue is reportedly due to multiple out-of-bounds index-access flaws.

A remote attacker may exploit this issue to execute arbitrary machine code on the affected computer with the privileges of the user running the vulnerable application.

Very little information is currently available on this vulnerability. This BID will be updated as more information becomes available.

48. Ruby on Rails Routing Denial of Service Vulnerability
BugTraq ID: 19454
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19454
Summary:
Ruby on Rails is prone to a vulnerability in its routing functionality that may result in denial-of-service or data loss issues.

Attackers may exploit this issue by issuing HTTP GET requests to predictable URIs to affected webservers.

This issue affects Ruby on Rails versions 1.1.0, 1.1.1, 1.1.2, 1.1.4, and 1.1.5.

49. Py2Play Object Unpickling Remote Python Code Execution Vulnerability
BugTraq ID: 14864
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/14864
Summary:
Py2Play is prone to a vulnerability that may let remote attackers execute arbitrary Python code in the context of the program.

This issue could be exploited by remote peers.

50. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
BugTraq ID: 19666
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19666
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

A local attacker can exploit this issue to execute arbitrary code and potentially compromise the affected computer.

51. GDB DWARF Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19802
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19802
Summary:
GDB is prone to multiple buffer-overflow vulnerabilities because of  insufficient bounds checking when handling DWARF and DWARF2 data.

Attackers could leverage this issue to run arbitrary code outside of a restricted environment; this may lead to privilege escalation.

52. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

53. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

54. Samba Internal Data Structures Denial of Service Vulnerability
BugTraq ID: 18927
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18927
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.

This issue affects Samba versions 3.0.1 through 3.0.22 inclusive.

55. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability because of a race-condition in the 'proc' filesystem.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

The 2.6 series of the Linux kernel is vulnerable to this issue.

56. VBZoom Profile.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19803
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19803
Summary:
VBZooM is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

57. GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
BugTraq ID: 18554
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18554
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.

58. CAPI4Hylafax Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 19801
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19801
Summary:
CAP4Hylafax is prone to an arbitrary command-execution vulnerability.

An attacker can exploit this vulnerability to execute arbitrary commands in the context of the affected application.

59. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
BugTraq ID: 19661
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19661
Summary:
Apache HTTP server is prone to an HTTP request header security weakness.

An attacker may exploit this issue to  steal cookie-based authentication credentials and launch other attacks.

60. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is susceptible to a vulnerability that may allow an RSA signature to be forged. It is possible to forge a PKCS #1 v1.5 signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships which depend on these credentials. Possibly posing as a trusted party and signing a certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are affected by this vulnerability. Updates are available.

61. Rob Brown Net-Server Perl Module Logging Function Format String Vulnerability
BugTraq ID: 13193
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/13193
Summary:
Net-Server API is prone to a remote format-string vulnerability. The issue resides in the 'log' subroutine of the 'Server.pm' module.

This vulnerability may occur when an application uses the 'log' subroutine of the affected module to handle malicious data passed through a network request.

A successful attack may crash the server or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context the server.

62. GD Graphics Library Remote Denial of Service Vulnerability
BugTraq ID: 18294
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18294
Summary:
The GD Graphics Library is prone to a denial-of-service vulnerability. Attackers can trigger an infinite-loop condition when the library tries to handle malformed image files.

This issue allows attackers to consume excessive CPU resources on computers that use the affected software. This may deny service to legitimate users.

GD version 2.0.33 is vulnerable to this issue; other versions may also be affected.

63. Internet Security Systems BlackICE Local Denial of Service Vulnerability
BugTraq ID: 19800
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19800
Summary:
Internet Security Systems (ISS) BlackICE PC Protection is prone to a local denial-of-service vulnerability because the application fails to properly sanitize user-supplied input.

This vulnerability allows local attackers to crash affected systems, facilitating a denial-of-service condition on the local computer. Remote code execution may also be possible if the vulnerability is exploited in privileged kernel mode.

Versions 3.6.cpn, 3.6.cpj, and 3.6.cpiE are vulnerable to this issue; other versions may also be affected.

64. TIBCO Rendezvous HTTP Interface Remote Buffer Overflow Vulnerability
BugTraq ID: 18301
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18301
Summary:
TIBCO Rendezvous is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly check boundaries of user-supplied command-line argument data before copying it to an insufficiently sized memory buffer.

Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers. The affected component may be installed as a service with administrative privileges on Microsoft Windows computers.

TIBCO Hawk versions prior to 4.6.1, TIBCO Runtime Agent versions prior to 5.4, and TIBCO Rendezvous versions prior to 7.5.1 are vulnerable to this issue.

65. Gimp XCF_load_vector Function Buffer Overflow Vulnerability
BugTraq ID: 18877
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18877
Summary:
Gimp is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

An attacker may cause malicious code to execute by forcing the application to read raw data from a malicious image file, with the privileges of the user running the GIMP application.

66. Cybozu Multiple Products Directory Traversal Vulnerability
BugTraq ID: 19733
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19733
Summary:
Multiple Cybozu Products are prone to a directory-traversal vulnerability because they fail to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected applications. Information obtained may aid in further attacks.

67. YACS Multiple Remote File Include Vulnerabilities
BugTraq ID: 19799
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19799
Summary:
YACS is prone multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

YACS Version 6.6.1 is affected by this vulnerability; other versions may also be affected.

68. GDB Multiple Vulnerabilities
BugTraq ID: 13697
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/13697
Summary:
GDB is reportedly affected by multiple vulnerabilities. These issues can allow an attacker to execute arbitrary code and commands on an affected computer. A successful attack may allow the attacker to gain elevated privileges or unauthorized access.

The following specific issues were identified:

- a remote heap-overflow vulnerability when loading malformed object files.
- a local privilege-escalation vulnerability.

GDB 6.3 is reportedly affected by these issues; other versions are likely vulnerable as well. GNU binutils 2.14 and 2.15 are affected by the heap-overflow issue as well.

69. Cerberus Helpdesk Ticket Parameter Unauthorized Access Vulnerability
BugTraq ID: 19797
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19797
Summary:
Cerberus Helpdesk is prone to an unauthorized-access vulnerability because the application fails to verify the ticket parameter properly, resulting in an improper-access validation. An update that addresses this issue is available.

An attacker can exploit this vulnerability to retrieve arbitrary tickets of other users. Information obtained can lead to a compromise of other users' confidential information.

Version 3.2 Build 317 is affected by this issue; other versions may be vulnerable as well.

70. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
BugTraq ID: 7831
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/7831
Summary:
A vulnerability has been reported for OpenSSH that may allow unauthorized access to an OpenSSH server's login mechanism.

The vulnerability occurs because of the way OpenSSH restricts access. It's possible to configure OpenSSH to restrict access based on certain patterns. When a numeric IP address is provided as the host that is attempting a connection, an attacker can trick the OpenSSH server to allow access.

71. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because the application fails to properly sanitize user-supplied input before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.

72. Sun Solaris 10 Kernel Patches Denial of Service Vulnerability
BugTraq ID: 19064
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19064
Summary:
Sun Solaris 10 is vulnerable to a denial-of-service vulnerability.

The vendor has reported that local users on affected computers may trigger kernel panics, corrupt kernel memory, crash applications, or corrupt system files. This issue arises subsequent to the installation of certain kernel patches issued by the vendor.

A successful attack may allow attackers to trigger denial-of-service conditions.

73. Sun Solaris Kernel Debugger KMDB(1) Local Denial of Service Vulnerability
BugTraq ID: 19080
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19080
Summary:
Sun Solaris is prone to a local denial-of-service vulnerability.

An attacker can trigger a kernel panic by loading the kernel debugger 'kmdb(1)' on an x86 system.

74. Sun Solaris SysInfo Local Information Disclosure Vulnerability
BugTraq ID: 19104
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19104
Summary:
Sun Solaris is prone to a local information-disclosure vulnerability because the kernel fails to properly ensure that unintended memory is not disclosed to local users.

This issue allows local attackers to gain access to potentially sensitive kernel memory. Information harvested by exploiting this issue may aid attackers in further attacks.

75. Sun Solaris Event Port API Denial of Service Vulnerability
BugTraq ID: 19081
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19081
Summary:
Sun Solaris is prone to a local denial-of-service vulnerability.

An attacker can execute an application that calls the event-port API in a manner that causes a system panic.

76. Sun Internet Protocol Implementation Routing Table Bypass Vulnerability
BugTraq ID: 19108
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19108
Summary:
Sun's Internet Protocol implementation is prone to a routing-table-bypass vulnerability. This vulnerability occurs because the kernel fails to secure that network traffic is routed only to addresses configured in the system's routing table.

A successful exploit may allow an attacker to bypass the system's routing-table configuration to redirect traffic to unauthorized addresses. This may allow an attacker to access unauthorized hosts and services by bypassing firewalls.

77. Sudo Python Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 16184
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/16184
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.

A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. That attacker may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.

An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.

This issue is similar to BID 15394 (Sudo Perl Environment Variable Handling Security Bypass Vulnerability).

78. Sudo Perl Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 15394
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/15394
Summary:
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored.

An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.

  To exploit this vulnerability, an attacker must be able to run Perl scripts through Sudo.

79. Multiple X.Org Products SetUID Local Privilege Escalation Vulnerability
BugTraq ID: 19742
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19742
Summary:
Multiple X.org products are prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to gain superuser privileges. A successful exploit would lead to the complete compromise of the affected computer.

80. Compression Plus Zoo Format Stack Overflow Vulnerability
BugTraq ID: 19796
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19796
Summary:
Compression Plus is prone to a stack-based buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. The issue occurs when processing ZOO files.

This issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.

Compression Plus 5 and prior versions are reported vulnerable; other versions may also be affected. Other applications that import functions from the library component of the affected application may also be vulnerable to this issue.

81. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.

The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.

An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.

82. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

83. Apache Mod_SSL Custom Error Document Remote Denial Of Service Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service vulnerability. A flaw in the module results in a NULL-pointer dereference that causes the server to crash. This issue is present only when virtual hosts are configured with a custom 'ErrorDocument' statement for '400' errors or 'SSLEngine optional'.

Depending on the configuration of Apache, attackers may crash the entire webserver or individual child processes. Repeated attacks are required to deny service to legitimate users when Apache is configured for multiple child processes to handle connections.

This issue affects Apache 2.x versions.

84. DUMB Impulse Tracker Files Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19025
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19025
Summary:
A buffer-overflow vulnerability occurs in the DUMB application. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.

85. IBM AIX Setlocale Function Local Privilege Escalation Vulnerability
BugTraq ID: 19578
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19578
Summary:
IBM AIX is prone to a local privilege-escalation vulnerability.

A local attacker may be able to exploit this issue to gain elevated privileges on the affected computer. A successful exploit will lead to the complete compromise of the affected computer.

IBM AIX versions 5.1, 5.2, and 5.3 are vulnerable to this issue.

86. DieselScripts DieselPay Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19623
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19623
Summary:
DieselPay is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

87. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

88. OpenBSD Semaphore Allocation Denial Of Service Vulnerability
BugTraq ID: 19713
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19713
Summary:
OpenBSD is prone to a local denial-of-service vulnerability because of a flaw in affected kernels that results in a kernel crash when attempting to allocate more than a predefined number of semaphores.

This issue allows local attackers to crash affected kernels, denying further service to legitimate users.

89. Xoops Edituser.PHP SQL Injection Vulnerability
BugTraq ID: 19720
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19720
Summary:
Xoops is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.

Xoops version 2.0.14 is reported vulnerable; other versions may also be affected.

90. MySQL Multiupdate and Subselects Denial Of Service Vulnerability
BugTraq ID: 19794
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19794
Summary:
MySQL is prone to multiple local denial-of-service vulnerabilities.

An attacker can exploit these issues to crash the slave replication process.

Versions prior to 4.1.13 are reported vulnerable.

91. Tor Multiple Buffer Overflow/Information Disclosure/Denial of Service Vulnerabilities
BugTraq ID: 19795
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19795
Summary:
Tor is affected by multiple vulnerabilities, including an integer overflow, a denial of service, information disclosure, and a possible log-bypass vulnerability.

An attacker can exploit these issues to retrieve sensitive information, crash the affected application, and potentially gain remote access to the underlying computer.

92. PhpGroupWare Calendar Class.Holidaycalc.Inc.PHP Local File Include Vulnerability
BugTraq ID: 19751
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19751
Summary:
phpGroupWare is prone to a local file-include vulnerability because the application fails to sufficiently sanitize user supplied-input. This issue may facilitate disclosure of sensitive data and could allow the execution of arbitrary local script code in the context of the application.

Version 0.9.16.010 and prior are vulnerable to this issue; other versions may also be affected.

93. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
BugTraq ID: 17780
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/17780
Summary:
MySQL is susceptible to multiple remote vulnerabilities:

- A buffer-overflow vulnerability due to insufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue allows remote attackers to execute arbitrary machine code in the context of affected database servers. Failed exploit attempts will likely crash the server, denying further service to legitimate users.

- Two information-disclosure vulnerabilities due to insufficient input-sanitization and bounds-checking of user-supplied data. These issues allow remote users to gain access to potentially sensitive information that may aid them in further attacks.

94. MySQL User-Defined Function Buffer Overflow Vulnerability
BugTraq ID: 14509
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/14509
Summary:
MySQL is prone to a buffer-overflow vulnerability. The application fails to perform sufficient boundary checks on data supplied as an argument in a user-defined function.

A database user with sufficient access to create a user-defined function can exploit this issue. Attackers may also be able to exploit this issue through latent SQL-injection vulnerabilities in third-party applications that use the database as a backend.

Successful exploitation will result in the execution of arbitrary code in the context of the database server process.

95. MySQL Query Logging Bypass Vulnerability
BugTraq ID: 16850
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/16850
Summary:
MySQL is susceptible to a query-logging-bypass vulnerability. This issue is due to a discrepancy between the handling of NULL bytes in the 'mysql_real_query()' function and in the query-logging functionality.

This issue allows attackers to bypass the query-logging functionality of the database so they can cause malicious SQL queries to be improperly logged. This may help them hide the traces of their malicious activity from administrators.

This issue affects MySQL version 5.0.18; other versions may also be affected.

96. LibTIFF TIFFFindFieldInfo Remote Buffer Overflow Vulnerability
BugTraq ID: 19793
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19793
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library fails to do proper boundary checks before copying user-supplied data into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of appications using the affected library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

This issue is known to affect versions of LibTIFF included with Sony PSP devices running firmware versions 2.0 through 2.8.

Specific information regarding affected versions of LibTIFF is currently unavailable. This BID will be updated as more information is disclosed.

97. KDE Konqueror ReplaceChild Denial Of Service Vulnerability
BugTraq ID: 18978
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/18978
Summary:
KDE Konqueror is prone to a denial-of-service vulnerability.

This issue is triggered when an attacker convinces a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Konqueror, effectively denying service to legitimate users.

98.  Membrepass Recherchemembre.PHP SQL Injection Vulnerability
BugTraq ID: 19791
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19791
Summary:
Membrepass is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

99. Membrepass Variable.PHP Remote File Include Vulnerability
BugTraq ID: 19790
Remote: Yes
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19790
Summary:
Membrepass is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied data.

This may facilitate the compromise of the application and the underlying system; other attacks are also possible.

100. IBM AIX Dtterm Local Privilege Escalation Vulnerability
BugTraq ID: 19786
Remote: No
Last Updated: 2006-09-05
Relevant URL: http://www.securityfocus.com/bid/19786
Summary:
IBM AIX is prone to a privilege-escalation vulnerability in dtterm. This issue may allow an unprivileged user to execute arbitrary code with superuser privileges.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Trusted computing a shield against worst attacks?
By: Robert Lemos
A report funded by computer firmware developer Phoenix Technologies finds that the ability to identify users' computers, a key capability of trusted computing hardware, could eliminate the most damaging digital attacks.
http://www.securityfocus.com/news/11410

2. Linux update becomes terminal pain
By: Robert Lemos
Users of the increasingly popular Ubuntu distribution find themselves having to deal with the command-line terminal after an update breaks the graphical X Windows subsystem.
http://www.securityfocus.com/news/11409

3. Microsoft patch opens users to attack
By: Robert Lemos
UPDATE: The software giant rushes to fix a security hole introduced during its latest patch for Internet Explorer that opens Windows XP SP1 and Windows 2000 users to attack.
http://www.securityfocus.com/news/11408

4. Bot spreads using latest Windows flaw
By: Robert Lemos
Security firms advise companies and home users to patch their Windows systems after detecting a bot program using a recently fixed flaw to compromise computers.

http://www.securityfocus.com/news/11407

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Information Assurance Engineer, Fort Belvoir
http://www.securityfocus.com/archive/77/445163

2. [SJ-JOB] Information Assurance Engineer, Sterling
http://www.securityfocus.com/archive/77/445164

3. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/445167

4. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/445168

5. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/445171

6. [SJ-JOB] Auditor, San Jose
http://www.securityfocus.com/archive/77/444907

7. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/444909

8. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/444910

9. [SJ-JOB] Director, Information Security, Charlotte
http://www.securityfocus.com/archive/77/444911

10. [SJ-JOB] Management, New York
http://www.securityfocus.com/archive/77/444913

11. [SJ-JOB] Sr. Security Analyst, Atlanta
http://www.securityfocus.com/archive/77/444912

12. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/444774

13. [SJ-JOB] Management, Sunnyvale
http://www.securityfocus.com/archive/77/444775

14. [SJ-JOB] Security Engineer, Southfield
http://www.securityfocus.com/archive/77/444776

15. [SJ-JOB] Sr. Security Analyst, Fort Worth
http://www.securityfocus.com/archive/77/444768

16. [SJ-JOB] Security Engineer, Santa Monica
http://www.securityfocus.com/archive/77/444770

17. [SJ-JOB] Forensics Engineer, Marietta
http://www.securityfocus.com/archive/77/444771

18. [SJ-JOB] Security Consultant, New York/Northern NJ
http://www.securityfocus.com/archive/77/444773

19. [SJ-JOB] Sales Representative, Kensington
http://www.securityfocus.com/archive/77/444769

20. [SJ-JOB] Security Engineer, Fort Worth
http://www.securityfocus.com/archive/77/444772

21. [SJ-JOB] Sr. Security Analyst, Miami
http://www.securityfocus.com/archive/77/444765

22. [SJ-JOB] Application Security Architect, London
http://www.securityfocus.com/archive/77/444767

23. [SJ-JOB] Security Architect, washington
http://www.securityfocus.com/archive/77/444797

24. [SJ-JOB] Certification & Accreditation Engineer, Cambridge
http://www.securityfocus.com/archive/77/444763

25. [SJ-JOB] Security Engineer, West Coast
http://www.securityfocus.com/archive/77/444764

V.   INCIDENTS LIST SUMMARY
---------------------------
1. New NT4/Windows botnet reported
http://www.securityfocus.com/archive/75/444839

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Hackers to Hackers Conferece III - Call for Papers
http://www.securityfocus.com/archive/82/444956

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Disabling syskey on XP pro
http://www.securityfocus.com/archive/88/445136

2. FW: MST transforms templates from sec persepctive?
http://www.securityfocus.com/archive/88/445134

3. Fwd: Whole disk encryption
http://www.securityfocus.com/archive/88/444818

4. SecurityFocus Microsoft Newsletter #306
http://www.securityfocus.com/archive/88/444702

5. Workstation Shutdown / Logoff Policy
http://www.securityfocus.com/archive/88/443340

6. Account Control: Running Windows Vista with Least Privilege
http://www.securityfocus.com/archive/88/442279

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Watchfire

AppScan 6.5 is now available! New features for Web services testing, Advanced Automated Capabilities for Penetration Testers, PCI compliance reporting, Token Analysis, Authentication testing, Automated JavaScript execution and much more. Download a Free Trial of AppScan today!

https://www.watchfire.com/securearea/appscancamp.aspx?id=701500000008Vmd