SecurityFocus Newsletter #367

Peter Laborge <[email protected]> Fri, 15 Sep 2006 09:34:03 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #367
----------------------------------------

This issue is Sponsored by: SPI Dynamics

ALERT: Test and assess your Web Applications- FREE WebInspect Trial
Hackers are exploiting web apps with attacks such as; SQL Injection,XSS and Session Hijacking, all undetectable by Firewalls and IDS!
Are you vulnerable?   Run a FREE Test of your Web Apps via our FREE 15 Day Product Trial that delivers a comprehensive Vulnerability Report

https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cb6B

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Disclosure survey
        2. Analyzing malicious SSH login attempts
II.   BUGTRAQ SUMMARY
        1. Linux Kernel Lease_Init Local Denial of Service Vulnerability
        2. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
        3. Quicksilver Forums Activeutil.PHP Remote File Include Vulnerability
        4. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
        5. Ipswitch IMail Server and Collaboration Suite SMTP Daemon Stack Overflow Vulnerability
        6. ForumJBC Haut.PHP Cross-Site Scripting Vulnerability
        7. Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
        8. Verso NetPerformer Frame Relay Access Device Telnet Buffer Overflow Vulnerability
        9. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
        10. GNU Mailman Multiple Security Vulnerabilities
        11. Apple QuickTime Multiple Overflow and Exception Vulnerabilities
        12. Mozilla Multiple Products Remote Vulnerabilities
        13. WM-News Multiple Input Validation Vulnerabilities
        14. HP-UX LP Subsystem Denial of Service Vulnerability
        15. ColdFusion SandBox Security Bypass Vulnerability
        16. Dreameesoft Password Master Local Authentication Bypass Vulnerability
        17. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Variant Vulnerability
        18. Vitrax Premodded Functions_Portal.PHP Remote File Include Vulnerability
        19. Adobe ColdFusion Flash Remoting Gateway Denial of Service Vulnerability
        20. Adobe ColdFusion Error Page Cross-Site Scripting Vulnerability
        21. CCHost Index.PHP SQL Injection Vulnerability
        22. WebSPELL Database.PHP  Authentication Bypass Vulnerability
        23. NetGear DG834GT Long Username Denial Of Service Vulnerability
        24. AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
        25. Ractive Popper Childwindow.Inc.PHP Remote File Include Vulnerability
        26. Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
        27. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
        28. GNUTLS PKCS RSA Signature Forgery Vulnerability
        29. ISC BIND Multiple Remote Denial of Service Vulnerabilities
        30. TeamCal Pro Footer.html.inc.PHP Remote File Include Vulnerability
        31. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
        32. Mailman Multiple Input Validation Vulnerabilities
        33. Linux Kernel __SetLease Local Denial of Service Vulnerability
        34. DCP-Portal Multiple Input Validation Vulnerabilities
        35. Blojsom Cross-Site Scripting Vulnerability
        36. Tagger LE Multiple PHP Code Injection Vulnerabilities
        37. PHPATM Multiple Remote File Include Vulnerabilities
        38. Zope CSV_Table Information Disclosure Vulnerability
        39. PHPQuiz Index.PHP Remote File Include Vulnerability
        40. Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
        41. Mambo Serverstat Component Install.Serverstat.PHP Remote File Include Vulnerability
        42. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
        43. ActiveCampaign KnowledgeBuilder Remote File Include Vulnerability
        44. Iodine Unspecified Security Vulnerability
        45. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
        46. Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
        47. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
        48. Linux Kernel UDF Denial of Service Vulnerability
        49. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service Vulnerability
        50. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
        51. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        52. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
        53. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
        54. Jira ConfigureReleaseNote.JSPA Cross-Site Scripting Vulnerability
        55. Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
        56. Drupal Userreview Module Unspecified Cross-Site Scripting Vulnerability
        57. Reamday Enterprises Magic News Pro News_page.PHP Remote File Include Vulnerability
        58. EmuCMS Index.PHP Cross-Site Scripting Vulnerabilities
        59. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
        60. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
        61. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
        62. FFmpeg Image File Unspecified Multiple Buffer Overflow Vulnerabilities
        63. NX5Linkx Multiple SQL Injection Vulnerabilities
        64. NX5Linkx Links.PHP HTTP Response Splitting Vulnerability
        65. Vmist Downstat Remote File Include Vulnerabilities
        66. Nokia Phones Firmware MMC Local Authentication Bypass Vulnerability
        67. Shadowed Portal Bottom.PHP Remote File Include Vulnerability
        68. DokuWiki Multiple Input Validation Vulnerabilities
        69. NX5Linkx Link.PHP Directory Traversal Vulnerability
        70. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer Overflow Vulnerability
        71. Xine-Lib HTTP Response Buffer Overflow Vulnerability
        72. Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities
        73. Limbo CMS SQL.PHP Remote File Include Vulnerability
        74. HP OpenView Operations Denial of Service and Unauthorized Access Vulnerability
        75. e107 CMS Multiple Cross-Site Scripting Vulnerabilities
        76. CJ Tag Board Tag.PHP Cross-Site Scripting Vulnerability
        77. Telekorn Signkorn Guestbook Dir_Path Multiple Remote File Include Vulnerabilities
        78. CityForFree Indexcity Cross-Site Scripting Vulnerability
        79. TualBLOG Icerik.ASP SQL Injection Vulnerability
        80. Microsoft Internet Explorer COM Object Instantiation Daxctle.OCX Heap Buffer Overflow vulnerability.
        81. Snitz Forums 2000 Forum.ASP Cross-Site Scripting Vulnerability
        82. CityForFree Indexcity List.PHP SQL Injection Vulnerability
        83. PHP Event Calendar Index.PHP Multiple Cross Site Scripting Vulnerabilities
        84. Moodle Multiple Input Validation and Information Disclosure Vulnerabilities
        85. X.Org LibXfont CID Font File Multiple Integer Overflow Vulnerabilities
        86. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
        87. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
        88. OpenBSD ISAKMPD IPsec Replay Vulnerability
        89. HP-UX ARPA Transport Software Local Denial of Service Vulnerability
        90. AlphaMail Log File Information Disclosure Vulnerability
        91. K2News Management Ratings.PHP Cross-Site Scripting Vulnerability
        92. Avira AntiVir Shatter Local Buffer Overflow Vulnerability
        93. Apple Mac OS X KExtLoad Buffer Overflow Weakness
        94. ClickBlog! Default.ASP SQL Injection Vulnerability
        95. Apple Mac OS X KExtLoad Format String Weakness
        96. TeamCal Pro Footer.HTML.Inc.PHP Remote File Include Vulnerability
        97. HP-UX X.25 Transport Protocol Local Denial of Service Vulnerability
        98. PhotoPost Pro Zipndownload.PHP Remote File Include Vulnerability
        99. PHPUnity.Postcard PHPUnity-Postcard.PHP Remote File Include Vulnerability
        100. Verso NetPerformer Frame Relay Access Device ICMP Denial of Service Vulnerability
III.  SECURITYFOCUS NEWS
        1. HP's Dunn to step down amidst hacking scandal
        2. Security pro pleads guilty to USC breach
        3. Trusted computing a shield against worst attacks?
        4. Linux update becomes terminal pain
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Sr. Security Engineer, San Ramon
        2. [SJ-JOB] Sr. Security Analyst, Hunt Valley
        3. [SJ-JOB] Manager, Information Security, Brooklyn (Metrotech)
        4. [SJ-JOB] Security Engineer, Richland
        5. [SJ-JOB] Sr. Security Analyst, Hunt Valley
        6. [SJ-JOB] Quality Assurance, Minneapolis
        7. [SJ-JOB] Software Engineer, Columbia
        8. [SJ-JOB] Software Engineer, Columbia
        9. [SJ-JOB] Management, North Sydney
        10. [SJ-JOB] Sr. Security Analyst, Washington,DC
        11. [SJ-JOB] Security System Administrator, Arlington
        12. [SJ-JOB] Security Engineer, Louisville
        13. [SJ-JOB] Security Engineer, Bozeman
        14. [SJ-JOB] Security Engineer, London
        15. [SJ-JOB] Sr. Security Engineer, PARSIPPANNY
        16. [SJ-JOB] Security Engineer, London
        17. [SJ-JOB] Security System Administrator, Lanham
V.    INCIDENTS LIST SUMMARY
        1. softnyx install rootkits
        2. spoolss overflow attempt: unknow threat or false alert ?
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. ToorCon Pre-Registration Closing Friday!
        2. PAKCON III: Call for Papers (CfP 2006)
        3. PAKCON III: Announce (2006)
        4. Features in a Vulnerability Management System
        5. VirtueMart
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. windump on browsing of shared folders across vpn in winxp
        2. Don't Get Too Comfortable - Sept. '06 Patches
        3. IP address assignment problem
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Disclosure survey
By Federico Biancuzzi
Federico Biancuzzi surveys statements from some of the world's largest software companies about vulnerability disclosure, interviews two security companies who pay for vulnerabilities, and then talks with three prominent, independent researchers about their thoughts on choosing a responsible disclosure process. In three parts.
http://www.securityfocus.com/columnists/415

2. Analyzing malicious SSH login attempts
By Christian Seifert
Malicious SSH login attempts have been appearing in some administrators' logs for several years. This article takes a new look at the use of honeypots to analyze malicious SSH login attempts and see what can be learned about this activity. The article then offers recommendations on how to secure one's system against these attacks.
http://www.securityfocus.com/infocus/1876


II.  BUGTRAQ SUMMARY
--------------------
1. Linux Kernel Lease_Init Local Denial of Service Vulnerability
BugTraq ID: 17943
Remote: No
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/17943
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'lease_init' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.16.

2. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

It has been reported that the Flock web browser version 0.7.4.1 and                          the K-Meleon web browser version 1.0.1 are also vulnerable.

3. Quicksilver Forums Activeutil.PHP Remote File Include Vulnerability
BugTraq ID: 19991
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19991
Summary:
Quicksilver Forums is prone to a remote file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 1.2.0 and 1.2.1 are vulnerable; other versions may also be affected.

4. CloudNine Internet Solutions Links Manager SQL Injection Vulnerability
BugTraq ID: 19649
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19649
Summary:
Links Manager is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

5. Ipswitch IMail Server and Collaboration Suite SMTP Daemon Stack Overflow Vulnerability
BugTraq ID: 19885
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19885
Summary:
Ipswitch IMail Server and Collaboration Suite are prone to a stack-overflow vulnerability. Updates are available.

This vulnerability may lead to remote arbitrary code execution or denial-of-service conditions.

Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure are vulnerable.

6. ForumJBC Haut.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19992
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19992
Summary:
ForumJBC is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverge this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 4.0 is vulnerable; other versions may also be affected.

7. Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
BugTraq ID: 19388
Remote: No
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19388
Summary:
A local privilege-escalation vulnerability affects Microsoft Windows 2000.

This vulnerability affects the Windows kernel; local attackers may exploit it to completely compromise an affected computer.

8. Verso NetPerformer Frame Relay Access Device Telnet Buffer Overflow Vulnerability
BugTraq ID: 19989
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19989
Summary:
Verso NetPerformer Frame Relay Access Device (FRAD) is prone to a remotely exploitable buffer overflow in the telnet service.

A remote attacker can exploit this issue to execute arbitrary code on the affected device. Failed exploit attempts will likely crash the device, denying service to legitimate users.

9. Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
BugTraq ID: 19409
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19409
Summary:
Microsoft Windows Server Service is prone to a remote buffer-overflow vulnerability.

This vulnerability arises when the service processes a malicious message in RPC communications.

A successful attack may result in arbitrary code execution with SYSTEM privileges leading to a full compromise. Attack attempts may result in denial-of-service conditions as well.

Microsoft has reported that this issue is being exploited in the wild.

Update (August 14, 2006): A worm named 'W32.Wargbot' that exploits this issue to spread is currently in the wild.

10. GNU Mailman Multiple Security Vulnerabilities
BugTraq ID: 19831
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19831
Summary:
Mailman is prone to multiple security vulnerabilities. The application fails to properly sanitize user-supplied input, and exhibits errors in MIME header handling and logging.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to cause a denial of service, and to inject spoofed log messages. This may help the attacker steal cookie-based authentication credentials, deny service to users, and launch other attacks.

These issues affect Mailman versions later than 2.0 and prior to 2.1.9rc1.

11. Apple QuickTime Multiple Overflow and Exception Vulnerabilities
BugTraq ID: 19976
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19976
Summary:
Apple QuickTime is prone to multiple vulnerabilities because it fails to properly bounds-check and sanitize user-supplied data.

An attacker can exploit these issues to execute arbitrary code in the context of the victim user running the vulnerable application. Successful exploits may facilitate a remote compromise of affected computers.

12. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

13. WM-News Multiple Input Validation Vulnerabilities
BugTraq ID: 19988
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19988
Summary:
WM-News is prone to multiple vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.5 is vulnerable; other versions may also be affected.

14. HP-UX LP Subsystem Denial of Service Vulnerability
BugTraq ID: 19535
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19535
Summary:
HP-UX running the LP subsystem is prone to an unspecified remote denial-of-service vulnerability.

An attacker can exploit this issue to deny service to legitimate users.

This issue affects HP-UX versions B.11.00, B.11.04, B.11.11, and B.11.23.

15. ColdFusion SandBox Security Bypass Vulnerability
BugTraq ID: 19985
Remote: No
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19985
Summary:
ColdFusion is prone to a security-bypass vulnerability because the application fails to ensure that calls to ColdFusion Components (CFCs) are secure within a sandbox.

This issue allows local attackers to use the ColdFusion Markup Language (CFML) templates outside a sandbox to call CFCs within a sandbox.

The exact effects of exploiting this issue are currently unknown. Attackers may possibly exploit this issue to gain access to potentially sensitive information or to execute code that they are not intended to have access to. This may aid them in further attacks. Code execution has not been confirmed.

16. Dreameesoft Password Master Local Authentication Bypass Vulnerability
BugTraq ID: 19983
Remote: No
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19983
Summary:
Dreameesoft Password Master is prone to an authentication-bypass vulnerability due to a design error.

Setting a master password may lead to a false sense of security, since users may expect that this results in an encrypted database. This vulnerability implies that this is not the case, because an attacker may be able to remove the master password.

Successful exploits may allow an attacker with local access to a mobile device running the vulnerable software to bypass the application's authentication methods and retrieve sensitive information.

Version 1.0 is vulnerable to this issue; other versions may also be affected.

17. Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Variant Vulnerability
BugTraq ID: 19987
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19987
Summary:
Microsoft Internet Explorer is prone to a remote buffer-overflow vulnerability. A successful exploit may result in arbitrary code-execution in the context of the user running the browser.

This issue was introduced with the rereleased patches of Microsoft advisory MS06-042.

This issue is nearly identical to that discussed in BID 19667 (Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability), but is a separate vulnerability.

18. Vitrax Premodded Functions_Portal.PHP Remote File Include Vulnerability
BugTraq ID: 19979
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19979
Summary:
Vitrax Premodded is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

19. Adobe ColdFusion Flash Remoting Gateway Denial of Service Vulnerability
BugTraq ID: 19984
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19984
Summary:
Adobe ColdFusion is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

20. Adobe ColdFusion Error Page Cross-Site Scripting Vulnerability
BugTraq ID: 19982
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19982
Summary:
Adobe ColdFusion is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker could exploit this vulnerability to have arbitrary script code execute in the context of the affected website. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

21. CCHost Index.PHP SQL Injection Vulnerability
BugTraq ID: 19978
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19978
Summary:
ccHost is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

22. WebSPELL Database.PHP  Authentication Bypass Vulnerability
BugTraq ID: 19975
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19975
Summary:
webSPELL is prone to an authentication-bypass vulnerability because it fails to sufficiently sanitize user-supplied data.

This issue may allow an attacker to bypass the authentication mechanism and allow unauthorized access to the affected application. This may lead to other attacks.

webSPELL 4.01.01 and prior versions are affected by this issue.

23. NetGear DG834GT Long Username Denial Of Service Vulnerability
BugTraq ID: 19973
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19973
Summary:
The NetGear DG834GT device is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input.

This issue allows attackers to cause the device to stop responding to network requests, effectively denying service to legitimate users.

24. AdPlug Multiple Remote File Buffer Overflow Vulnerabilities
BugTraq ID: 18859
Remote: Yes
Last Updated: 2006-09-12
Relevant URL: http://www.securityfocus.com/bid/18859
Summary:
The AdPlug library is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the library's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.

These issues allow remote attackers to execute arbitrary machine code in the context of the user running applications that use the affected library to open attacker-supplied malicious files.

The AdPlug library version 2.0 is vulnerable to these issues; previous versions may also be affected.

25. Ractive Popper Childwindow.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 19972
Remote: Yes
Last Updated: 2006-09-12
Relevant URL: http://www.securityfocus.com/bid/19972
Summary:
Ractive Popper is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.41-r2 and prior are affected by this issue.

26. Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
BugTraq ID: 19951
Remote: Yes
Last Updated: 2006-09-12
Relevant URL: http://www.securityfocus.com/bid/19951
Summary:
Microsoft Publisher is prone to a code-execution vulnerability. This is due to a flaw when handling malformed PUB files.

Successfully exploiting this issue allows attackers to corrupt process memory and to execute arbitrary code in the context of targeted users.

27. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are affected by this vulnerability. Updates are available.

28. GNUTLS PKCS RSA Signature Forgery Vulnerability
BugTraq ID: 20027
Remote: Yes
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/20027
Summary:
GnuTLS is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when verifying a X.509 certificate.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key.

This vulnerability is a variant of the issue discussed in BID 19849 (OpenSSL PKCS Padding RSA Signature Forgery Vulnerability) and affects GnuTLS versions prior to version 1.4.3.

29. ISC BIND Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 19859
Remote: Yes
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/19859
Summary:
ISC BIND is prone to multiple denial-of-service vulnerabilities.

An attacker can exploit these issues to cause denial-of-service conditions, effectively denying service to legitimate users.

30. TeamCal Pro Footer.html.inc.PHP Remote File Include Vulnerability
BugTraq ID: 20036
Remote: Yes
Last Updated: 2006-09-15
Relevant URL: http://www.securityfocus.com/bid/20036
Summary:
TeamCal Pro is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 2.8.001 is vulnerable to this issue; other versions may also be affected.

31. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
BugTraq ID: 17541
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/17541
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue arises in Intel EM64T CPUs when returning program control using SYSRET.

This vulnerability allows local users to crash the kernel, denying further service to legitimate users.

32. Mailman Multiple Input Validation Vulnerabilities
BugTraq ID: 20021
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20021
Summary:
Mailman is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-input. These issues include multiple cross-site scripting vulnerabilities and a CRLF-injection vulnerability.

A successful exploit of these issues could allow an attacker to steal cookie-based authentication credentials, add additional content to the log file, possibly hide current attacks, or launch phishing-style attacks; other attacks may also be possible.

Versions between 2.1.0 and 2.1.8 are vulnerable to this issue; other versions prior to 2.1.0 may also be affected.

33. Linux Kernel __SetLease Local Denial of Service Vulnerability
BugTraq ID: 18033
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the '__setlease' function.

This vulnerability allows local users to leak kernel memory, potentially resulting in a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.16.

34. DCP-Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 20024
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20024
Summary:
DCP-Portal is prone to multiple input-validation vulnerabilities, including multiple cross-site scripting, SQL-injection, and remote file-include issues, because the application fails to sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, exploit vulnerabilities in the underlying database implementation, or include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. Other attacks are also possible.

Version 6.0 Standard Edition is vulnerable to these issues; other versions may also be affected.

35. Blojsom Cross-Site Scripting Vulnerability
BugTraq ID: 20026
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20026
Summary:
Blojsom is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

36. Tagger LE Multiple PHP Code Injection Vulnerabilities
BugTraq ID: 20023
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20023
Summary:
Tagger LE is prone to multiple PHP code-injection vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts.

If the attacker is successful, the attacker-supplied code will run in a PHP 'eval()' function call with the privileges of the server process.

A successful attack may result in unauthorized access in the context of the server.

37. PHPATM Multiple Remote File Include Vulnerabilities
BugTraq ID: 19765
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19765
Summary:
phpATM is prone multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

38. Zope CSV_Table Information Disclosure Vulnerability
BugTraq ID: 20022
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20022
Summary:
Zope is prone to an information-disclosure vulnerability because the application fails to properly secure potentially sensitive information.

A remote attacker can exploit this issue to retrieve potentially sensitive information that may aid the attacker in further attacks.

39. PHPQuiz Index.PHP Remote File Include Vulnerability
BugTraq ID: 20019
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20019
Summary:
phpQuiz is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.01 is vulnerable to this issue; other versions may also be affected.

40. Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
BugTraq ID: 19986
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19986
Summary:
Symantec AntiVirus Corporate Edition is prone to multiple format-string vulnerabilities because it fails to properly sanitize user-supplied input before using it in the format-specifier argument to a formatted-printing function.

Successfully exploiting these vulnerabilities may allow an attacker to execute arbitrary machine code with SYSTEM-level privileges. Attackers may also crash the Real Time Virus Scan service.

41. Mambo Serverstat Component Install.Serverstat.PHP Remote File Include Vulnerability
BugTraq ID: 20018
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20018
Summary:
The Mambo Serverstat component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.

Version 0.4.4 and earlier are vulnerable to this issue; other versions may also be affected.

42. Linux Kernel SCTP Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 18085
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18085
Summary:
The Linux kernel SCTP module is prone to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.

These issues allow remote attackers to trigger kernel panics, denying further service to legitimate users.

The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.

43. ActiveCampaign KnowledgeBuilder Remote File Include Vulnerability
BugTraq ID: 20020
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20020
Summary:
ActiveCampaign KnowledgeBuilder is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Reportedly, version 2.2 and earlier are vulnerable; other versions may also be affected.

44. Iodine Unspecified Security Vulnerability
BugTraq ID: 20017
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20017
Summary:
Iodine is prone to an unspecified security vulnerability.

Very little information is available on this issue; this BID will be updated as more information becomes available.

45. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

46. Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
BugTraq ID: 20016
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20016
Summary:
Novell Identity Manager is prone to a code-injection vulnerability.

A local attacker with administrative rights to the Identity Manager can exploit this issue to completely compromise an affected computer.

The vulnerability affects version 3.0.1; previous versions may be affected as well.

47. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
BugTraq ID: 19666
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19666
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

A local attacker can exploit this issue to execute arbitrary code and potentially compromise the affected computer.

48. Linux Kernel UDF Denial of Service Vulnerability
BugTraq ID: 19562
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19562
Summary:
The Linux kernel UDF file module is prone to a denial-of-service.

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

49. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service Vulnerability
BugTraq ID: 18755
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18755
Summary:
The Linux kernel 'netfilter' module is prone to a denial-of-service vulnerability.

Successful exploits of this vulnerability will cause the kernel to crash, effectively denying service to legitimate users.

50. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
BugTraq ID: 18099
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18099
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'choose_new_parent' function.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.11.12.

51. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

52. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

53. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

54. Jira ConfigureReleaseNote.JSPA Cross-Site Scripting Vulnerability
BugTraq ID: 18575
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18575
Summary:
Jira is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

55. Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
BugTraq ID: 19927
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19927
Summary:
Microsoft Indexing Service is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input before it is rendered to other users.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user, in the context of the victim's session. This could allow the attacker to perform actions on behalf of the victim, such as spoofing content or hijacking their session.

Microsoft Indexing Service is not installed or enabled by default. Even if installed, it is not accessible from Internet Information Services (IIS). This vulnerability affects only systems that have IIS and Indexing Service installed and that have the Indexing Service configured to be accessible from IIS through a web-based interface.

56. Drupal Userreview Module Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 20015
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20015
Summary:
Drupal Userrevew module is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Drupal 4.7 is affected by this issue. Versions lacking the following CVS $Id$ field are vulnerable:

  'Drupal 4.7 - // $Id: userreview.module,v 1.19 2006/09/12 18:12:21 killes Exp $'

57. Reamday Enterprises Magic News Pro News_page.PHP Remote File Include Vulnerability
BugTraq ID: 20014
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20014
Summary:
Magic News Pro is prone to a remote file-include vulnerability because the application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary local or remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This issue affects version 1.0.3; other versions may also be vulnerable.

58. EmuCMS Index.PHP Cross-Site Scripting Vulnerabilities
BugTraq ID: 20013
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20013
Summary:
emuCMS is prone to a cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Versions 0.21 and 0.3 are vulnerable; other versions may also be affected.

59. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
BugTraq ID: 15743
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/15743
Summary:
FFmpeg's 'libavcodec' is prone to a heap buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied data before using it in memory allocation and copy operations.

Attackers may exploit this vulnerability to execute arbitrary code in the context of applications that use an affected version of the libavcodec library.

An attacker can exploit this issue by enticing a user to open a malformed PNG file with an application that uses a vulnerable version of libavcodec. If the application is configured as the default handler for PNG files, this could present a viable web or email attack vector -- when the PNG is clicked from an appropriate client application, the application using the vulnerable library will automatically be invoked.

60. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
BugTraq ID: 18894
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18894
Summary:
The Macromedia Flash plug-in is prone to multiple remote vulnerabilities.

An attacker can exploit these vulnerabilities to execute arbitrary code or to crash the application hosting the Flash player (typically a web browser). Attackers exploit these issues through maliciously malformed SWF files that have been placed on a website or emailed to unsuspecting users.

Version 8.0.24.0 of Flash is vulnerable to these issues; other versions may also be affected.

61. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.13.

62. FFmpeg Image File Unspecified Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 20009
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20009
Summary:
FFmpeg is prone to multiple unspecified remote buffer-overflow vulnerabilities because the application using this library fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

These issues allow attackers to execute arbitrary machine code within the context of the affected application.

This BID will be updated as more information is disclosed.

Versions prior to 0.4.9_p20060530 are vulnerable to this issue.

63. NX5Linkx Multiple SQL Injection Vulnerabilities
BugTraq ID: 20010
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20010
Summary:
NX5Linkx is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.

An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.

64. NX5Linkx Links.PHP HTTP Response Splitting Vulnerability
BugTraq ID: 20011
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20011
Summary:
NX5Linkx is prone to an HTTP response-splitting vulnerability because the application fails to properly sanitize user-supplied input.

A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.

65. Vmist Downstat Remote File Include Vulnerabilities
BugTraq ID: 20007
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20007
Summary:
Vmist Downstat is prone to remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to execute arbitrary server-side script code on an affected computer in the context of the webserver process.

Version 1.8 and earlier are vulnerable; other versions may also be affected.

66. Nokia Phones Firmware MMC Local Authentication Bypass Vulnerability
BugTraq ID: 20003
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20003
Summary:
Nokia Mobile Phones are prone to an authentication-bypass vulnerability due to a design error.

Successful exploits may allow an attacker with local access to a vulnerable mobile device to bypass the application's authentication methods and gain full access to the affected device.

We currently have no information regarding specific details of the affected devices. This BID will be updated when more information becomes available.

67. Shadowed Portal Bottom.PHP Remote File Include Vulnerability
BugTraq ID: 20006
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20006
Summary:
Shadowed Porta is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 5.599 and earlier are vulnerable to this issue; other versions may also be affected.

68. DokuWiki Multiple Input Validation Vulnerabilities
BugTraq ID: 19911
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19911
Summary:
DokuWiki is prone to multiple input-validation vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts and to run it in the context of the webserver process.

A successful attack may result in unauthorized access.

69. NX5Linkx Link.PHP Directory Traversal Vulnerability
BugTraq ID: 20008
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20008
Summary:
NX5Linkx is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.

70. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer Overflow Vulnerability
BugTraq ID: 19905
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19905
Summary:
X.Org X Window Server libX11 library is prone to a local buffer-overflow vulnerability because it fails to properly validate the size of attacker-supplied data before copying it into a finite-sized buffer.

The issue allows local attackers to execute arbitrary machine code in the context of a user running an application that is dynamically linked against the library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

X11R6 4.0 and prior versions are reported affected by this vulnerability.

71. Xine-Lib HTTP Response Buffer Overflow Vulnerability
BugTraq ID: 18187
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/18187
Summary:
The xine-lib library is susceptible to a buffer-overflow vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer.

Successful exploits allow remote attackers to execute arbitrary machine code in the context of application using the affected library.

Versions of xine-lib greater than or equal to 1.0.1 are potentially affected by this issue, but information on specific affected versions is not currently available. Applications that use a vulnerable version of the library may also be affected. Version 0.5.6 of gxine is reportedly vulnerable to this issue.

72. Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities
BugTraq ID: 19998
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19998
Summary:
Cisco IOS is prone to multiple vulnerabilities when handling VLAN Trunking Protocol (VTP) packets.

These issues include two denial-of-service vulnerabilities and a buffer-overflow vulnerability.

Attackers require access to trunk ports on affected devices for VTP packets to be accepted. Attackers may reportedly use the Dynamic Trunk Protocol (DTP) to become a trunking peer to gain required access.

By exploiting these issues, attackers may crash affected routers, cause further VTP packets to be ignored, or potentially execute arbitrary machine code in the context of affected devices.

Cisco IOS 12.1(19) is vulnerable to these issues; other versions are also likely affected.

73. Limbo CMS SQL.PHP Remote File Include Vulnerability
BugTraq ID: 17760
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/17760
Summary:
Limbo CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 1.04; other versions may also be vulnerable.

74. HP OpenView Operations Denial of Service and Unauthorized Access Vulnerability
BugTraq ID: 20005
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20005
Summary:
HP OpenView Operations is prone to a denial-of-service and unauthorized-access vulnerability.

A remote attacker can exploit this issue to cause denial-of-service conditions or gain unauthorized access.

75. e107 CMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19997
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19997
Summary:
e107 CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to sanitize user-supplied input.

An attacker may levearge this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

Version 0.7.5 is vulnerable to this issue; other versions may also be affected.

76. CJ Tag Board Tag.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20000
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20000
Summary:
CJ Tag Board is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverge this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 3.0 is vulnerable; other versions may also be affected.

77. Telekorn Signkorn Guestbook Dir_Path Multiple Remote File Include Vulnerabilities
BugTraq ID: 19977
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19977
Summary:
Telekorn Signkorn Guestbook is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.

This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 1.3 and earlier are affected by this issue.

78. CityForFree Indexcity Cross-Site Scripting Vulnerability
BugTraq ID: 19652
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19652
Summary:
CityForFree Indexcity is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

79. TualBLOG Icerik.ASP SQL Injection Vulnerability
BugTraq ID: 20002
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20002
Summary:
TualBLOG is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

80. Microsoft Internet Explorer COM Object Instantiation Daxctle.OCX Heap Buffer Overflow vulnerability.
BugTraq ID: 19738
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19738
Summary:
Microsoft Internet Explorer is prone to a heap buffer-overflow vulnerability..

The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls.

An attacker can exploit this issue to execute arbitrary code within context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

81. Snitz Forums 2000 Forum.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 20004
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20004
Summary:
Snitz Forums 2000 is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

This could allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Version 3.4.06 is vulnerable; other versions may also be affected.

82. CityForFree Indexcity List.PHP SQL Injection Vulnerability
BugTraq ID: 19653
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19653
Summary:
CityForFree Indexcity is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

83. PHP Event Calendar Index.PHP Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 20001
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20001
Summary:
PHP Event Calendar is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 1.5.1 is vulnerable; other versions may also be affected.

84. Moodle Multiple Input Validation and Information Disclosure Vulnerabilities
BugTraq ID: 19995
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19995
Summary:
Moodle is prone to multiple cross-site scripting, SQL-injection, and information-disclosure vulnerabilities.

Exploiting these issues may allow an attacker to access or modify sensitive data, to execute arbitrary script code, or to steal cookie-based authentication credentials; other attacks are possible.

Versions 1.6.1 is vulnerable; other versions may also be affected.

85. X.Org LibXfont CID Font File Multiple Integer Overflow Vulnerabilities
BugTraq ID: 19974
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19974
Summary:
libXfont is prone to multiple integer-overflow vulnerabilities.

Attackers can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial of service.

86. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
BugTraq ID: 19980
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19980
Summary:
Adobe Flash Player is prone to multiple remote code-execution vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker could exploit this issue by creating a media file containing large, dynamically generated string data and submitting it to be processed by the media player.

These issues allow remote attackers to execute arbitrary machine code in the context of the user running the application. Other attacks are also possible.

Adobe Flash Player 8.0.24.0 and prior, Adobe Flash Professional 8, Flash Basic, Adobe Flash MX, and 2004Adobe Flex 1.5 are affected.

87. CloudNine Internet Solutions Links Manager Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19650
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19650
Summary:
Links Manager is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

88. OpenBSD ISAKMPD IPsec Replay Vulnerability
BugTraq ID: 19712
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19712
Summary:
OpenBSD's IPsec implementation is prone to remote replay attacks. This issue is due to the improper implementation of its replay window.

This issue allows remote attackers to replay IPsec traffic. The exact consequences of successful attacks depend on the nature of the traffic being replayed. This will likely affect only higher-level protocols such as UDP, since they don't provide their own anti-replay features.

89. HP-UX ARPA Transport Software Local Denial of Service Vulnerability
BugTraq ID: 19999
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19999
Summary:
HP-UX running the ARPA Transport Software is prone to an unspecified remote denial-of-service vulnerability.

A local authenticated attacker can exploit this issue to deny service to legitimate users.

90. AlphaMail Log File Information Disclosure Vulnerability
BugTraq ID: 19996
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19996
Summary:
AlphaMail is prone to a local information-disclosure vulnerability because the application fails to properly secure sensitive information.

This issue allows local attackers to gain access to administrative account-authentication credentials.

Versions prior to 1.0.16 are vulnerable.

91. K2News Management Ratings.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19994
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19994
Summary:
k2News Management is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

92. Avira AntiVir Shatter Local Buffer Overflow Vulnerability
BugTraq ID: 19843
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/19843
Summary:
Avira AntiVir is prone to a buffer-overflow vulnerability because the application fails to bounds-check data before copying it into a finite-sized buffer.

Attackers can exploit this issue to execute arbitrary machine code with SYSTEM-level privileges, resulting in the complete compromise of affected computers. Failed exploit attempts may result in crashes, denying service to legitimate users.

Currently we are not aware of the specific versions that are vulnerable. This BID will be updated as soon as more information is available. The free version is known to be affected by this issue.

93. Apple Mac OS X KExtLoad Buffer Overflow Weakness
BugTraq ID: 20034
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20034
Summary:
Apple Mac OS X kextload is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied data before copying it to a finite sized memory buffer.

This issue is not exploitable by itself, as kextload is not installed as a setuid-superuser application by default. This issue must be utilized in conjunction with another application running with elevated privileges that allows attackers to directly manipulate the arguments passed to kextload.

A malicious user can exploit this issue to execute arbitrary machine code with superuser privileges. A successful exploit may result in complete compromise of the affect computer.

94. ClickBlog! Default.ASP SQL Injection Vulnerability
BugTraq ID: 20033
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20033
Summary:
ClickBlog! is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Versions 2.0 and prior are reported vulnerable.

95. Apple Mac OS X KExtLoad Format String Weakness
BugTraq ID: 20031
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20031
Summary:
Apple Mac OS X kextload is prone to a format-string vulnerability because it fails to sufficiently sanitize user-supplied input data.

This issue is not exploitable by itself, as kextload is not installed as a setuid-superuser application by default. This issue must be utilized in conjunction with another application running with elevated privileges that allows attackers to directly manipulate the arguments passed to kextload.

A malicious user can exploit this issue to execute arbitrary machine code with superuser privileges. A successful exploit may result in complete compromise of the affect computer.

96. TeamCal Pro Footer.HTML.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 20030
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20030
Summary:
TeamCal Pro is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue is reported to affect version 2.8.001; other versions may also be vulnerable.

97. HP-UX X.25 Transport Protocol Local Denial of Service Vulnerability
BugTraq ID: 20029
Remote: No
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20029
Summary:
HP-UX running the X.25 transport protocol is prone to an unspecified remote denial-of-service vulnerability.

A local authenticated attacker can exploit this issue to deny service to legitimate users.

98. PhotoPost Pro Zipndownload.PHP Remote File Include Vulnerability
BugTraq ID: 20028
Remote: Yes
Last Updated: 2006-09-14
Relevant URL: http://www.securityfocus.com/bid/20028
Summary:
PhotoPost Pro is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 4.6 and prior are vulnerable; other versions may also be affected.

99. PHPUnity.Postcard PHPUnity-Postcard.PHP Remote File Include Vulnerability
BugTraq ID: 19993
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19993
Summary:
phpunity.postcard is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

100. Verso NetPerformer Frame Relay Access Device ICMP Denial of Service Vulnerability
BugTraq ID: 19990
Remote: Yes
Last Updated: 2006-09-13
Relevant URL: http://www.securityfocus.com/bid/19990
Summary:
Verso NetPerformer Frame Relay Access Device (FRAD) is prone to a denial-of-service vulnerability.

A remote attacker can exploit this issue to potentially crash the affected device, denying service to legitimate users. The atttacker may be able to terminate current TCP sessions being handled by the device, potentially without incurring a reboot.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. HP's Dunn to step down amidst hacking scandal
By: Robert Lemos
Hewlett-Packard announces that the chairwoman will resign in January, while California's Attorney General and civil lawsuits aim to use cybercrime laws to reign in investigators that abused computer access to "pretext" the phone records of reporters and directors.
http://www.securityfocus.com/news/11412

2. Security pro pleads guilty to USC breach
By: Robert Lemos
Eric McCarty agrees to a single felony charge of exploiting a flaw in the University of Southern California's online student application site and accessing confidential information.
http://www.securityfocus.com/news/11411

3. Trusted computing a shield against worst attacks?
By: Robert Lemos
A report funded by computer firmware developer Phoenix Technologies finds that the ability to identify users' computers, a key capability of trusted computing hardware, could eliminate the most damaging digital attacks.
http://www.securityfocus.com/news/11410

4. Linux update becomes terminal pain
By: Robert Lemos
Users of the increasingly popular Ubuntu distribution find themselves having to deal with the command-line terminal after an update breaks the graphical X Windows subsystem.
http://www.securityfocus.com/news/11409

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sr. Security Engineer, San Ramon
http://www.securityfocus.com/archive/77/445885

2. [SJ-JOB] Sr. Security Analyst, Hunt Valley
http://www.securityfocus.com/archive/77/445886

3. [SJ-JOB] Manager, Information Security, Brooklyn (Metrotech)
http://www.securityfocus.com/archive/77/445869

4. [SJ-JOB] Security Engineer, Richland
http://www.securityfocus.com/archive/77/445870

5. [SJ-JOB] Sr. Security Analyst, Hunt Valley
http://www.securityfocus.com/archive/77/445887

6. [SJ-JOB] Quality Assurance, Minneapolis
http://www.securityfocus.com/archive/77/445866

7. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/445867

8. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/445868

9. [SJ-JOB] Management, North Sydney
http://www.securityfocus.com/archive/77/445884

10. [SJ-JOB] Sr. Security Analyst, Washington,DC
http://www.securityfocus.com/archive/77/445746

11. [SJ-JOB] Security System Administrator, Arlington
http://www.securityfocus.com/archive/77/445773

12. [SJ-JOB] Security Engineer, Louisville
http://www.securityfocus.com/archive/77/445774

13. [SJ-JOB] Security Engineer, Bozeman
http://www.securityfocus.com/archive/77/445762

14. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/445775

15. [SJ-JOB] Sr. Security Engineer, PARSIPPANNY
http://www.securityfocus.com/archive/77/445776

16. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/445779

17. [SJ-JOB] Security System Administrator, Lanham
http://www.securityfocus.com/archive/77/445614

V.   INCIDENTS LIST SUMMARY
---------------------------
1. softnyx install rootkits
http://www.securityfocus.com/archive/75/445622

2. spoolss overflow attempt: unknow threat or false alert ?
http://www.securityfocus.com/archive/75/445546

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. ToorCon Pre-Registration Closing Friday!
http://www.securityfocus.com/archive/82/445956

2. PAKCON III: Call for Papers (CfP 2006)
http://www.securityfocus.com/archive/82/445957

3. PAKCON III: Announce (2006)
http://www.securityfocus.com/archive/82/445958

4. Features in a Vulnerability Management System
http://www.securityfocus.com/archive/82/445740

5. VirtueMart
http://www.securityfocus.com/archive/82/445739

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. windump on browsing of shared folders across vpn in winxp
http://www.securityfocus.com/archive/88/446048

2. Don't Get Too Comfortable - Sept. '06 Patches
http://www.securityfocus.com/archive/88/445921

3. IP address assignment problem
http://www.securityfocus.com/archive/88/444349

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics

ALERT: Test and assess your Web Applications- FREE WebInspect Trial
Hackers are exploiting web apps with attacks such as; SQL Injection,XSS and Session Hijacking, all undetectable by Firewalls and IDS!
Are you vulnerable?   Run a FREE Test of your Web Apps via our FREE 15 Day Product Trial that delivers a comprehensive Vulnerability Report

https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cb6B