SecurityFocus Newsletter #368

Peter Laborge <[email protected]> Tue, 19 Sep 2006 16:22:29 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #368
----------------------------------------

This issue is Sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Liar, Liar, and pretexting
        2. Beginner's guide to wireless auditing
II.   BUGTRAQ SUMMARY
        1. Freeciv Multiple Remote Denial of Service Vulnerabilities
        2. Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability
        3. Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
        4. Vikingboard Topic.PHP SQL Injection Vulnerability
        5. Vikingboard Multiple Cross-Site Scripting Vulnerabilities
        6. PHPQuiz Multiple Input Validation Vulnerabilities
        7. FreeType LWFN Files Buffer Overflow Vulnerability
        8. Mantis View_All_Set.PHP Multiple Cross-Site Scripting Vulnerabilities
        9. Artmedic Links Index.PHP Remote File Include Vulnerability
        10. Mantis Multiple Input Validation Vulnerabilities
        11. Aceboard Recherche.PHP Cross-Site Scripting Vulnerability
        12. ZilekPortal Haberdetay.ASP SQL Injection Vulnerability
        13. SiteBar Command.PHP Cross-Site Scripting Vulnerability
        14. PHP-Post Multiple Input Validation Vulnerabilities
        15. Plume CMS Multiple Remote File Include Vulnerabilities
        16. Nuked-Klan Query Parameter Cross-Site Scripting Vulnerability
        17. Claroline Claro_Init_Local.Inc.PHP Remote File Include Vulnerability
        18. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
        19. Linux Kernel Sendmsg() Local Buffer Overflow Vulnerability
        20. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        21. Linux Kernel Sysctl Unregistration Local Denial of Service Vulnerability
        22. Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
        23. Linux Orinoco Driver Remote Information Disclosure Vulnerability
        24. Site@School Multiple Input Validation Vulnerabilities
        25. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
        26. Linux Kernel 2.6.16.13 Multiple SCTP Remote Denial of Service Vulnerabilities
        27. AlstraSoft Efriends GetStartOptions.PHP Local File Include Vulnerability
        28. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
        29. EShoppingPro Search_Run.ASP SQL Injection Vulnerability
        30. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
        31. Linux Kernel Multiple Security Vulnerabilities
        32. HP-UX Trusted Mode Unspecified Local Denial of Service Vulnerability
        33. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
        34. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
        35. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
        36. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
        37. PhotoPost Pro Multiple Remote File Include Vulnerabilities
        38. Linux Kernel IP ID Information Disclosure Weakness
        39. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
        40. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
        41. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
        42. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
        43. NixieAffiliate Delete.PHP Authentication Bypass Vulnerability
        44. Linux Kernel SCTP SO_LINGER Local Denial of Service Vulnerability
        45. Retired: Hitweb REP_CLASS Multiple Remote File Include Vulnerabilities
        46. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
        47. Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
        48. Moodle Edit.PHP SQL Injection Vulnerability
        49. Linux Kernel ELF File Cross Region Mapping Local Denial of Service Vulnerability
        50. Osiris Logging.C Format String Vulnerability
        51. NixieAffiliate Lostpassword.PHP Cross-Site Scripting Vulnerability
        52. GNU GZip Archive Handling Multiple Remote Vulnerabilities
        53. PHP DocWriter Index.PHP Remote File Include Vulnerability
        54. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
        55. X.Org LibXfont CID Font File Multiple Integer Overflow Vulnerabilities
        56. ECardPro Search.ASP SQL Injection Vulnerability
        57. IDevSpot BizDirectory Multiple Cross-Site Scripting Vulnerabilities
        58. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
        59. Charon Cart Review.ASP SQL Injection Vulnerability
        60. MyBB Index.PHP Referrer Cookie SQL Injection Vulnerability
        61. MyBulletinBoard Generic_Error.PHP Multiple Cross-Site Scripting Vulnerabilities
        62. Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
        63. Microsoft PowerPoint Remote Code Execution Vulnerability
        64. MobilePublisherPHP Header.PHP Remote File Include Vulnerability
        65. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
        66. GNUTLS PKCS RSA Signature Forgery Vulnerability
        67. Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
        68. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
        69. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
        70. Bomberclone Multiple Remote Vulnerabilities
        71. Mambo Hotornot Component Uploadfile.PHP Arbitrary File Upload Vulnerability
        72. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer Overflow Vulnerability
        73. HP-UX ARPA Transport Software Local Denial of Service Vulnerability
        74. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
        75. Tagger LE Multiple PHP Code Injection Vulnerabilities
        76. GNU Mailman Multiple Security Vulnerabilities
        77. ZixForum ReplyNew.ASP SQL Injection Vulnerability
        78. Retired: TeamCal Pro Footer.html.inc.PHP Remote File Include Vulnerability
        79. Quadcomm Q-Shop Browse.ASP SQL Injection Vulnerability
        80. Techno Dreams FAQ Manager Package Faqview.ASP SQL Injection Vulnerability
        81. Techno Dreams Articles and Papers Package ArticlesTableview.ASP SQL Injection Vulnerability
        82. Mambo Extended Registration Component mosConfig_absolute_path Remote File Include Vulnerability
        83. GuanxiCRM Business Solution PHPXD.PHP Remote File Include Vulnerability
        84. UNAK-CMS Dirroot Parameter Remote File Include Vulnerability
        85. GNUTurk T_ID Parameter SQL Injection Vulnerability
        86. AEDating Dir[INC] Parameter Remote File Include Vulnerability
        87. BusyBox HTTPD Directory Traversal Vulnerability
        88. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
        89. NewsGator FeedDemon Active Script Code-Execution Vulnerability
        90. Exponent CMS Index.PHP Local File Include Vulnerability
        91. RSSOwl Atom Feed Script HTML Injection Vulnerability
        92. Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
        93. ESyndiCat Search.PHP Cross-Site Scripting Vulnerability
        94. MyReview Functions.PHP SQL Injection Vulnerability
        95. Innovate Portal Index.PHP Cross-Site Scripting Vulnerability
        96. Simple Discussion Board Multiple Remote File Include Vulnerabilities
        97. Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
        98. More.groupware Week.PHP SQL Injection Vulnerability
        99. OSU HTTP Server Multiple Information Disclosure Vulnerabilities
        100. Mantis Config_Defaults_Inc.PHP Cross-Site Scripting Vulnerability
III.  SECURITYFOCUS NEWS
        1. Web flaws race ahead in 2006
        2. HP's Dunn to step down amidst hacking scandal
        3. Security pro pleads guilty to USC breach
        4. Trusted computing a shield against worst attacks?
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Security Engineer, Columbia
        2. [SJ-JOB] Security Engineer, McLean
        3. [SJ-JOB] Forensics Engineer, Richmond
        4. [SJ-JOB] Forensics Engineer, Cardiff
        5. [SJ-JOB] Software Engineer, Los Angeles
        6. [SJ-JOB] Sales Engineer, San Francisco
        7. [SJ-JOB] Sr. Security Analyst, Parsippany
        8. [SJ-JOB] Manager, Information Security, Plantation
        9. [SJ-JOB] Security Engineer, London
        10. [SJ-JOB] Sales Representative, Atlanta
        11. [SJ-JOB] Security Consultant, Copenhagen
        12. [SJ-JOB] Security Consultant, Copenhagen
        13. [SJ-JOB] Manager, Information Security, Baltimore
        14. [SJ-JOB] Sr. Security Engineer, Baltimore/Owings Mills
        15. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
        16. [SJ-JOB] Security Consultant, London
        17. [SJ-JOB] Security Engineer, Research Triangle Park
        18. [SJ-JOB] Remediation Security Analyst, Charlotte
        19. [SJ-JOB] Sr. Security Engineer, San Francisco
        20. [SJ-JOB] Security Architect, Fort Lauderdale
        21. [SJ-JOB] Management, McLean
        22. [SJ-JOB] Manager, Information Security, Baltimore
        23. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
        24. [SJ-JOB] Sr. Security Engineer, Baltimore/Owings Mills
        25. [SJ-JOB] Security Consultant, London
        26. [SJ-JOB] Security Engineer, Research Triangle Park
        27. [SJ-JOB] Remediation Security Analyst, Charlotte
        28. [SJ-JOB] Management, McLean
        29. [SJ-JOB] Sr. Security Engineer, San Francisco
        30. [SJ-JOB] Security Architect, Fort Lauderdale
        31. [SJ-JOB] Security Researcher, Beijing
        32. [SJ-JOB] Software Engineer, Austin
        33. [SJ-JOB] Security Researcher, Beijing
        34. [SJ-JOB] Account Manager, Vienna
        35. [SJ-JOB] Sales Representative, Washington DC Metro Area
        36. [SJ-JOB] Senior Software Engineer, CAMBRIDGE
        37. [SJ-JOB] Security Engineer, Somerset
        38. [SJ-JOB] Security Auditor, Canberra
        39. [SJ-JOB] Quality Assurance, Somerset
        40. [SJ-JOB] Sr. Security Engineer, San Ramon
        41. [SJ-JOB] Sr. Security Analyst, Hunt Valley
        42. [SJ-JOB] Manager, Information Security, Brooklyn (Metrotech)
        43. [SJ-JOB] Security Engineer, Richland
        44. [SJ-JOB] Sr. Security Analyst, Hunt Valley
        45. [SJ-JOB] Quality Assurance, Minneapolis
        46. [SJ-JOB] Software Engineer, Columbia
        47. [SJ-JOB] Software Engineer, Columbia
        48. [SJ-JOB] Management, North Sydney
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. problem in bypassing stack randomization ("call *%edx" technique)
        2. ToorCon Pre-Registration Closing Friday!
        3. PAKCON III: Call for Papers (CfP 2006)
        4. PAKCON III: Announce (2006)
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Storing Images in SQL Server (2005)
        2. SecurityFocus Microsoft Newsletter #308
        3. Terminal Servers @ Datacenter
        4. Question about Sniffer in Windows
        5. windump on browsing of shared folders across vpn in winxp
        6. Don't Get Too Comfortable - Sept. '06 Patches
        7. IP address assignment problem
VIII. SUN FOCUS LIST SUMMARY
        1. root group in solaris
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Liar, Liar, and pretexting
By Mark Rasch
Mark Rasch details the legality of pretexting by putting it in context with how it used, comparing it with legal forms of lying, and by looking at previous court cases involving pretexting in the United States. Hewlett Packard's use of pretexting also brings up potential charges of criminal fraud, violations of consumer protection laws, issues of deception, and the use of spyware. Together these issues make for a very interesting legal situation at HP.
http://www.securityfocus.com/columnists/417

2. Beginner's guide to wireless auditing
By David Maynor
This article is designed as a beginner's guide to fuzzing wireless device drivers, starting with how to build an auditing environment, how to construct fuzzing tools and finally, how to interpret the results. This auditing environment can be used for WiFi as well as Bluetooth and infrared devices.
http://www.securityfocus.com/infocus/1877


II.  BUGTRAQ SUMMARY
--------------------
1. Freeciv Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 19117
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19117
Summary:
Freeciv server is prone to multiple remote denial-of-service vulnerabilities.

A remote attacker may exploit these issues to deny service to legitimate users by sending malicious packets to a server.

2.1.0-beta1 and prior versions are affected by these issues.

2. Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability
BugTraq ID: 20096
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20096
Summary:
Microsoft Internet Explorer is prone to a buffer-overflow vulnerability.

The vulnerability arises because of an error in the processing of Vector Markup Language documents.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. The method by which this vulnerability is currently being exploited will typically terminate Internet Explorer.

This vulnerability is currently being exploited in the wild as Trojan.Vimalov.

This vulnerability affects Internet Explorer version 6.0 on a fully patched system. Previous versions may also be affected.

3. Citrix Access Gateway AAC LDAP Authentication Bypass Vulnerability
BugTraq ID: 20066
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20066
Summary:
Citrix Access Gateway is prone to an authentication-bypass vulnerability.

An attacker can exploit this issue to bypass LDAP authentication and gain unauthorized access to the application.

4. Vikingboard Topic.PHP SQL Injection Vulnerability
BugTraq ID: 19919
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/19919
Summary:
Viking board is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 0.1b is vulnerable; other versions may also be affected.

5. Vikingboard Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 19916
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/19916
Summary:
Vikingboard is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 0.1b is vulnerable; other versions may also be affected.

6. PHPQuiz Multiple Input Validation Vulnerabilities
BugTraq ID: 20065
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20065
Summary:
PHPQuiz is prone to multiple input-validation vulnerabilities, including SQL-injection and arbitrary file-upload issues, because the application fails to sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database implementation, or execute arbitrary PHP code in the context of the webserver process; other attacks are also possible.

7. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.

This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.

FreeType versions prior to 2.2.1 are vulnerable to this issue.

8. Mantis View_All_Set.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17326
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/17326
Summary:
Mantis is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Mantis 1.0.1 and prior are considered vulnerable.

9. Artmedic Links Index.PHP Remote File Include Vulnerability
BugTraq ID: 20064
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20064
Summary:
The 'artmedic links' application is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 5.0; other versions may also be vulnerable.

10. Mantis Multiple Input Validation Vulnerabilities
BugTraq ID: 16657
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/16657
Summary:
Mantis is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

11. Aceboard Recherche.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20063
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20063
Summary:
Aceboard is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects version 5.3; other versions may also be vulnerable.

12. ZilekPortal Haberdetay.ASP SQL Injection Vulnerability
BugTraq ID: 20062
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20062
Summary:
ZilekPortal is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 1.0; other versions may also be vulnerable.

13. SiteBar Command.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18680
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/18680
Summary:
SiteBar is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

14. PHP-Post Multiple Input Validation Vulnerabilities
BugTraq ID: 20061
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20061
Summary:
PHP-Post is prone to multiple input-validation vulnerabilities, including multiple cross-site scripting, SQL-injection, and remote file-include issues, because the application fails to sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, exploit vulnerabilities in the underlying database implementation, or include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. Other attacks are also possible.

15. Plume CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 19629
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/19629
Summary:
Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

16. Nuked-Klan Query Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 20032
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20032
Summary:
Nuked-Klan is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 1.7 SP4.3 is vulnerable to this issue; other versions may also be affected.

17. Claroline Claro_Init_Local.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 20056
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20056
Summary:
Claroline is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.7.7 is affected by this issue; other versions may also be affected.

18. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.13.

19. Linux Kernel Sendmsg() Local Buffer Overflow Vulnerability
BugTraq ID: 14785
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/14785
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability.

The vulnerability affects 'sendmsg()' when malformed user-supplied data is copied from userland to kernel memory.

A successful attack can allow a local attacker to trigger an overflow, which may lead to a denial-of-service condition due to memory corruption. Arbitrary code execution resulting in privilege escalation is possible as well.

20. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

21. Linux Kernel Sysctl Unregistration Local Denial of Service Vulnerability
BugTraq ID: 15365
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/15365
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability. This issue arises from a failure to properly unregister kernel resources when network devices are removed.

This issue allows local attackers to deny service to legitimate users. Attackers may also be able to execute arbitrary code in the context of the kernel, but this has not been confirmed.

22. Linux Kernel SEARCH_BINARY_HANDLER Local Denial of Service Vulnerability
BugTraq ID: 16320
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/16320
Summary:
Linux kernel is susceptible to a local denial-of-service vulnerability.

This issue presents itself in the 'search_binary_handler' function of 'exec.c'.

This issue allows local users to crash the kernel due to a panic, denying service to legitimate users.

Linux kernel 2.4 versions on 64-bit x86 architectures prior to 2.4.33-pre1 are affected.

23. Linux Orinoco Driver Remote Information Disclosure Vulnerability
BugTraq ID: 15085
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/15085
Summary:
The Orinoco drivers for Linux kernels are susceptible to a remote information-disclosure vulnerability. This issue is due to the driver sending uninitialized kernel memory in small network packets.

Remote attackers may exploit this issue to access potentially sensitive kernel memory, aiding them in further attacks.

24. Site@School Multiple Input Validation Vulnerabilities
BugTraq ID: 20053
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/20053
Summary:
Site@School is prone to multiple input-validation vulnerabilities, including an arbitrary-file-upload issue, multiple remote file-include issues, and a directory-traversal issue, because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to upload an arbitrary PHP file, execute the file on the vulnerable computer in the context of the webserver process, and retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may lead to other attacks.

Site@School 2.4.02 and earlier versions are vulnerable to these issues.

25. Linux Kernel Shared Memory Security Restriction Bypass Vulnerabilities
BugTraq ID: 17587
Remote: No
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/17587
Summary:
The Linux kernel is prone to vulnerabilities regarding access to shared memory.

A local attacker could potentially gain read and write access to shared memory and write access to read-only tmpfs filesystems, bypassing security restrictions.

An attacker can exploit these issues to possibly corrupt applications and their data when the applications use temporary files or shared memory.

26. Linux Kernel 2.6.16.13 Multiple SCTP Remote Denial of Service Vulnerabilities
BugTraq ID: 17955
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/17955
Summary:
The Linux kernel SCTP module is susceptible to remote denial-of-service vulnerabilities. These issues are triggered when the kernel handles unexpected SCTP packets.

These issues allow remote attackers to trigger kernel deadlock and infinite recursion, denying further service to legitimate users.

The Linux kernel version 2.6.16 is vulnerable to these issues; prior versions may also be affected.

27. AlstraSoft Efriends GetStartOptions.PHP Local File Include Vulnerability
BugTraq ID: 20088
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20088
Summary:
AlstraSoft Efriends is prone to a local file include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to:

-  inject arbitrary PHP code into the webserver log files
-  include and execute arbitrary files from the vulnerable system in the context of the affected application.

Other attacks are possible.

This issue affects version 4.85; other versions may also be vulnerable.

28. Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities
BugTraq ID: 18944
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18944
Summary:
Ruby is prone to multiple vulnerabilities that let attackers bypass SAFE-level restrictions.

These issues allow attackers to bypass the expected SAFE-level restrictions, possibly allowing them to execute unauthorized script code in the context of affected applications. The specific impact of these issues depends on the implementation of scripts that use SAFE-level security checks.

29. EShoppingPro Search_Run.ASP SQL Injection Vulnerability
BugTraq ID: 20089
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20089
Summary:
EShoppingPro is prone to an SQL-injection vulnerability because  the application fails to properly sanitize user-supplied input before using it in an SQL query.

An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.

30. Linux Kernel USB Subsystem Local Denial Of Service Vulnerability
BugTraq ID: 14955
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/14955
Summary:
A local denial-of-service vulnerability affects the Linux kernel's USB subsystem. This issue is due to the kernel's failure to properly handle unexpected conditions when trying to handle URBs (USB Request Blocks).

Local attackers may exploit this vulnerability to trigger a kernel 'oops' on computers where the vulnerable USB subsystem is enabled. This would deny service to legitimate users.

31. Linux Kernel Multiple Security Vulnerabilities
BugTraq ID: 15049
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/15049
Summary:
Linux kernel is prone to multiple vulnerabilities. These issues may allow local and remote attackers to trigger denial-of-service conditions or to access sensitive kernel memory.

Linux kernel 2.6.x versions are known to be vulnerable at the moment. Other versions may be affected as well.

32. HP-UX Trusted Mode Unspecified Local Denial of Service Vulnerability
BugTraq ID: 19528
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19528
Summary:
HP-UX is prone to an unspecified local denial-of-service vulnerability because the application fails to properly handle exceptional conditions.

Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.

33. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
BugTraq ID: 16925
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/16925
Summary:
Linux kernel is prone to a denial-of-service vulnerability when processing a malformed ELF file. This issue occurs only on Intel EM64T processors.

Linux kernel versions prior to 2.6.15.5 are affected by this issue.

34. Linux Kernel Intel EM64T SYSRET Local Denial of Service Vulnerability
BugTraq ID: 17541
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/17541
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue arises in Intel EM64T CPUs when returning program control using SYSRET.

This vulnerability allows local users to crash the kernel, denying further service to legitimate users.

35. Linux Kernel die_if_kernel Local Denial of Service Vulnerability
BugTraq ID: 16993
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/16993
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'die_if_kernel()' function.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.15.6 running on Itanium systems.

36. Multiple Vendor AMD CPU Local FPU Information Disclosure Vulnerability
BugTraq ID: 17600
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/17600
Summary:
Multiple vendors' operating systems are prone to a local information-disclosure vulnerability. This issue is due to a flaw in the operating systems that fail to properly use AMD CPUs.

Local attackers may exploit this vulnerability to gain access to potentially sensitive information regarding other processes executing on affected computers. This may aid attackers in retrieving information regarding cryptographic keys or other sensitive information.

This issue affects Linux and FreeBSD operating systems that use generations 7 and 8 AMD CPUs.

37. PhotoPost Pro Multiple Remote File Include Vulnerabilities
BugTraq ID: 20028
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20028
Summary:
PhotoPost Pro is prone to multiple remote file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

PhotoPost Pro 4.6 and prior versions are vulnerable; other versions may also be affected.

38. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is prone to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.

This issue allows remote attackers to use affected computers in stealth network port and trust scans.

The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.

39. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

It has been reported that the Flock web browser version 0.7.4.1 and                          the K-Meleon web browser version 1.0.1 are also vulnerable.

40. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19488
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19488
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability. This issue is due to a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

41. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
BugTraq ID: 17203
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/17203
Summary:
The Linux kernel is affected by local memory-disclosure vulnerabilities. These issues are due to the kernel's failure to properly clear previously used kernel memory before returning it to local users.

These issues allow an attacker to read kernel memory and potentially gather information to use in further attacks.

42. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability.

This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users.

Kernel versions prior to 2.6.16.18 are vulnerable to this issue.

43. NixieAffiliate Delete.PHP Authentication Bypass Vulnerability
BugTraq ID: 20086
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20086
Summary:
NixieAffiliate is prone to an authentication-bypass vulnerability.

An attacker can exploit this issue to delete any user account, denying service to legitimate users.

44. Linux Kernel SCTP SO_LINGER Local Denial of Service Vulnerability
BugTraq ID: 20087
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20087
Summary:
The Linux kernel SCTP module is prone to a local denial-of-service vulnerability.

This issue allows local attackers to cause kernel crashes, denying service to legitimate users.

Specific information regarding affected versions of the Linux kernel is currently unavailable. This BID will be updated as further information is disclosed.

45. Retired: Hitweb REP_CLASS Multiple Remote File Include Vulnerabilities
BugTraq ID: 20060
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20060
Summary:
Hitweb is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This BID is being retired. The specified parameter is defined and can not contain an attacker specified value.

46. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are affected by this vulnerability. Updates are available.

47. Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
BugTraq ID: 20047
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20047
Summary:
Microsoft Internet Explorer is prone to a heap buffer-overflow vulnerability.

The vulnerability arises because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

This issue is similar to, but separate from, the one described in BID 19738 (Microsoft Internet Explorer Daxctle.OCX Spline Method Heap Buffer Overflow Vulnerability).

48. Moodle Edit.PHP SQL Injection Vulnerability
BugTraq ID: 20085
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20085
Summary:
Moodle is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Moodle 1.6.1 + is vulnerable; prior versions may also be affected.

49. Linux Kernel ELF File Cross Region Mapping Local Denial of Service Vulnerability
BugTraq ID: 19702
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19702
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue could cause an affected computer to crash.

50. Osiris Logging.C Format String Vulnerability
BugTraq ID: 19213
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19213
Summary:
Osiris is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before using it in a formatted-printing function.

A successful exploit could allow an attacker to execute arbitrary code or to crash the application.

Version 4.2.0 is vulnerable to this issue; other versions may also be affected.

51. NixieAffiliate Lostpassword.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20084
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20084
Summary:
NixieAffiliate is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

.

52. GNU GZip Archive Handling Multiple Remote Vulnerabilities
BugTraq ID: 20101
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20101
Summary:
The gzip utility is prone to multiple remote buffer-overflow and denial-of-service vulnerabilities when handling malicious archive files.

Successful exploits may allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise. Attackers may also trigger denial-of-service conditions by crashing or hanging the application.

Specific information regarding affected versions of gzip is currently unavailable. This BID will be updated as more information is released.

53. PHP DocWriter Index.PHP Remote File Include Vulnerability
BugTraq ID: 20041
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20041
Summary:
PHP DocWriter is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

DocWriter 0.3 and earlier versions are vulnerable; other versions may also be affected.

54. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
BugTraq ID: 20042
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20042
Summary:
The Mozilla Foundation has released six security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- supply malicious data through updates
- inject arbitrary content
- execute arbitrary JavaScript
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.7
- Mozilla Thunderbird version 1.5.0.7
- Mozilla SeaMonkey version 1.0.5

55. X.Org LibXfont CID Font File Multiple Integer Overflow Vulnerabilities
BugTraq ID: 19974
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19974
Summary:
The libXfont library is prone to multiple integer-overflow vulnerabilities.

Attackers can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial of service.

56. ECardPro Search.ASP SQL Injection Vulnerability
BugTraq ID: 20080
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20080
Summary:
ECardPro is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

This issue affects version 2.0; other versions may also be vulnerable.

57. IDevSpot BizDirectory Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20081
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20081
Summary:
IDevSpot BizDirectory is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker steal cookie-based authentication credentials and launch other attacks.

BizDirectory 1.9 and prior versions are vulnerable.

58. Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability
BugTraq ID: 18874
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18874
Summary:
Linux kernel is prone to a local privilege-escalation vulnerability.

A local attacker may gain elevated privileges by creating a coredump file in a directory that they do not have write access to.

A successful attack may result in a complete compromise.

Linux kernel versions prior to 2.6.17.4 are vulnerable.

59. Charon Cart Review.ASP SQL Injection Vulnerability
BugTraq ID: 20083
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20083
Summary:
Charon Cart is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 3 is vulnerable; other versions may also be affected.

60. MyBB Index.PHP Referrer Cookie SQL Injection Vulnerability
BugTraq ID: 16443
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/16443
Summary:
MyBB is prone to an SQL-injection vulnerability.

The vulnerability presents itself when user-supplied input via cookie data is passed to the 'index.php' script.

Successful exploitation can allow an attacker to bypass authentication and gain administrative access to a site. Other attacks may also be possible.

MyBB 1.1.2 and prior versions are reported vulnerable to this issue.

61. MyBulletinBoard Generic_Error.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20079
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20079
Summary:
MyBulletinBoard is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 1.2 is vulnerable to this issue; other versions may also be affected.

62. Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
BugTraq ID: 20076
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20076
Summary:
Ipswitch WS_FTP Server is prone to a number of stack-overflow vulnerabilities. Updates are available.

A successful exploit may lead to remote arbitrary code execution with administrative privileges, facilitating the complete compromise of affected computers.

Ipswitch WS_FTP Server 5.05 is vulnerable to this issue; other versions may also be affected.

63. Microsoft PowerPoint Remote Code Execution Vulnerability
BugTraq ID: 20059
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20059
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

This issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint document to a user. This issue is being actively exploited in the wild as Trojan.PPDropper.E.

This issue is currently known to affect only Office 2000 (Chinese version only) on Windows XP (Chinese edition).

64. MobilePublisherPHP Header.PHP Remote File Include Vulnerability
BugTraq ID: 20078
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20078
Summary:
MobilePublisherPHP is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.5 RC2 is vulnerable; other versions may also be affected.

65. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
BugTraq ID: 19980
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19980
Summary:
Adobe Flash Player is prone to multiple remote code-execution vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker could exploit this issue by creating a media file containing large, dynamically generated string data and submitting it to be processed by the media player.

These issues allow remote attackers to execute arbitrary machine code in the context of the user running the application. Other attacks are also possible.

Adobe Flash Player 8.0.24.0 and prior, Adobe Flash Professional 8, Flash Basic, Adobe Flash MX, and 2004Adobe Flex 1.5 are affected.

66. GNUTLS PKCS RSA Signature Forgery Vulnerability
BugTraq ID: 20027
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20027
Summary:
GnuTLS is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when verifying a X.509 certificate.

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key.

This vulnerability is a variant of the issue discussed in BID 19849 (OpenSSL PKCS Padding RSA Signature Forgery Vulnerability) and affects GnuTLS versions prior to version 1.4.3.

67. Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness
BugTraq ID: 18583
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18583
Summary:
Microsoft Office is prone to a weakness that may allow remote attackers to execute arbitrary script code contained in Shockwave Flash Objects without first requiring confirmation from users.

A successful attack may allow attackers to access sensitive information and potentially execute malicious commands on a vulnerable computer.

The researcher responsible for discovering this issue has indicated that it presents itself on Windows 2003 SP1, Windows XP Professional Edition SP1 and SP2 running Microsoft Office 2003, and Windows 2000 Professional running Microsoft Office 2003. Other versions may be vulnerable as well.

68. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
BugTraq ID: 18894
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18894
Summary:
The Macromedia Flash plug-in is prone to multiple remote vulnerabilities.

An attacker can exploit these vulnerabilities to execute arbitrary code or to crash the application hosting the Flash player (typically a web browser). Attackers exploit these issues through maliciously malformed SWF files that have been placed on a website or emailed to unsuspecting users.

Version 8.0.24.0 of Flash is vulnerable to these issues; other versions may also be affected.

69. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
BugTraq ID: 19661
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19661
Summary:
Apache HTTP server is prone to an HTTP request header security weakness.

An attacker may exploit this issue to  steal cookie-based authentication credentials and launch other attacks.

70. Bomberclone Multiple Remote Vulnerabilities
BugTraq ID: 19255
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19255
Summary:
Bomberclone is prone to remote information-disclosure and denial-of-service vulnerabilities because it fails to properly sanitize user-supplied input.

These issues allow remote attackers to access sensitive information and to crash the application, denying further service to legitimate users.

Version 0.11.6 is reported vulnerable; other versions may also be affected.

71. Mambo Hotornot Component Uploadfile.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 20077
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20077
Summary:
The Mambo Hotornot is prone to an arbitrary-file-upload vulnerability.

Exploiting this issue may allow an attacker to compromise the affected application; other attacks are also possible.

Version 1.2.2 is vulnerable; other versions may also be affected.

72. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer Overflow Vulnerability
BugTraq ID: 19905
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19905
Summary:
X.Org X Window Server libX11 library is prone to a local buffer-overflow vulnerability because it fails to properly validate the size of attacker-supplied data before copying it into a finite-sized buffer.

The issue allows local attackers to execute arbitrary machine code in the context of a user running an application that is dynamically linked against the library. Failed exploit attempts will likely crash the application, denying service to legitimate users.

X11R6 4.0 and prior versions are reported affected by this vulnerability.

73. HP-UX ARPA Transport Software Local Denial of Service Vulnerability
BugTraq ID: 19999
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19999
Summary:
HP-UX running the ARPA Transport Software is prone to an unspecified remote denial-of-service vulnerability.

A local authenticated attacker can exploit this issue to deny service to legitimate users.

74. Linux Kernel PROC Filesystem Local Privilege Escalation Vulnerability
BugTraq ID: 18992
Remote: No
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/18992
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability because of a race-condition in the 'proc' filesystem.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

The 2.6 series of the Linux kernel is vulnerable to this issue.

75. Tagger LE Multiple PHP Code Injection Vulnerabilities
BugTraq ID: 20023
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20023
Summary:
Tagger LE is prone to multiple PHP code-injection vulnerabilities that may allow remote attackers to inject arbitrary PHP code into scripts.

If the attacker is successful, the attacker-supplied code will run in a PHP 'eval()' function call with the privileges of the server process.

A successful attack may result in unauthorized access in the context of the server.

76. GNU Mailman Multiple Security Vulnerabilities
BugTraq ID: 19831
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19831
Summary:
Mailman is prone to multiple security vulnerabilities. The application fails to properly sanitize user-supplied input, and exhibits errors in MIME header handling and logging.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to cause a denial of service, and to inject spoofed log messages. This may help the attacker steal cookie-based authentication credentials, deny service to users, and launch other attacks.

These issues affect Mailman versions later than 2.0 and prior to 2.1.9rc1.

77. ZixForum ReplyNew.ASP SQL Injection Vulnerability
BugTraq ID: 19855
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19855
Summary:
ZixForum is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

ZixForum 1.12 and previous versions are affected by this issue.

78. Retired: TeamCal Pro Footer.html.inc.PHP Remote File Include Vulnerability
BugTraq ID: 20036
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20036
Summary:
TeamCal Pro is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 2.8.001 is vulnerable to this issue; other versions may also be affected.

This record is a duplicate of BID 20030 (TeamCal Pro Footer.HTML.Inc.PHP Remote File Include Vulnerability) and is therefore being retired.

79. Quadcomm Q-Shop Browse.ASP SQL Injection Vulnerability
BugTraq ID: 20075
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20075
Summary:
Quadcomm Q-Shop is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Quadcomm Q-Shop version 3.5 is reported vulnerable.

80. Techno Dreams FAQ Manager Package Faqview.ASP SQL Injection Vulnerability
BugTraq ID: 20074
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20074
Summary:
Techno Dreams FAQ Manager Package is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Techno Dreams FAQ Manager Package version 1.0 is reported vulnerable.

81. Techno Dreams Articles and Papers Package ArticlesTableview.ASP SQL Injection Vulnerability
BugTraq ID: 20073
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20073
Summary:
Techno Dreams Articles and Papers Package is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Techno Dreams Articles and Papers Package version 2 is reported vulnerable; previous versions may also be affected.

82. Mambo Extended Registration Component mosConfig_absolute_path Remote File Include Vulnerability
BugTraq ID: 20072
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20072
Summary:
The Mambo Extended Registration component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

83. GuanxiCRM Business Solution PHPXD.PHP Remote File Include Vulnerability
BugTraq ID: 20071
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20071
Summary:
guanxiCRM Business Solution is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 0.9.1; other versions may also be vulnerable.

84. UNAK-CMS Dirroot Parameter Remote File Include Vulnerability
BugTraq ID: 20070
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20070
Summary:
UNAK-CMS is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 1.5; other versions may also be vulnerable.

85. GNUTurk T_ID Parameter SQL Injection Vulnerability
BugTraq ID: 20069
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20069
Summary:
GNUTURK is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

86. AEDating Dir[INC] Parameter Remote File Include Vulnerability
BugTraq ID: 20068
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20068
Summary:
aeDating is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

87. BusyBox HTTPD Directory Traversal Vulnerability
BugTraq ID: 20067
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20067
Summary:
The httpd daemon of BusyBox is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.

This issue affects version 1.01; other versions may also be vulnerable.

88. AlsaPlayer Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19450
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/19450
Summary:
AlsaPlayer is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer.

An attacker can exploit these issues to execute arbitrary code within the context of the application or cause a denial-of-service condition.

AlsaPlayer 0.99.76, the CVS version as of 9 Aug 2006, and prior versions are vulnerable to this issue; other versions may also be affected.

89. NewsGator FeedDemon Active Script Code-Execution Vulnerability
BugTraq ID: 20114
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20114
Summary:
NewsGator FeedDemon is prone to an active script code-execution vulnerability because it fails to sufficiently sanitize Atom feed data prior to rendering the feed.

Successful exploits may result in active scripting content being executed in the context of the application. The 'Internet Zone' is utilized by the application to render the remote HTML content, lessening the impact of this issue.

90. Exponent CMS Index.PHP Local File Include Vulnerability
BugTraq ID: 20111
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20111
Summary:
Exponent CMS is prone to a local file include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to inject arbitrary PHP code into the application temp files, and to  include and execute arbitrary files from the vulnerable system in the context of the affected application. Other attacks are possible.

This issue affects version 0.96.3 stable; other versions may also be vulnerable.

91. RSSOwl Atom Feed Script HTML Injection Vulnerability
BugTraq ID: 20110
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20110
Summary:
RSSOwl is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the My Computer, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Versions 1.2.1 and 1.2.2 are vulnerable to this issue; other versions may also be affected.

92. Qualiteam X-Cart CMPI.PHP Arbitrary Variable Overwrite Vulnerability
BugTraq ID: 20108
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20108
Summary:
Qualiteam X-Cart is prone to a vulnerability that permits an attacker to overwrite arbitrary variables. This issue is due to a design flaw in handling HTTP POST variables.

An attacker can exploit this issue to overwrite the arbitrary variables with arbitrary input. Through control of the global variables, the attacker may be able to perform remote and local file-include, cross-site scripting, SQL-injection, and other attacks. This may facilitate a complete remote compromise of the application.

93. ESyndiCat Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20106
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20106
Summary:
eSyndiCat is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 1.5 is vulnerable; other versions may also be affected.

94. MyReview Functions.PHP SQL Injection Vulnerability
BugTraq ID: 20105
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20105
Summary:
MyReview is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 1.9.4 is vulnerable to this issue; other versions mays also be affected.

95. Innovate Portal Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20104
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20104
Summary:
Innovate Portal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

96. Simple Discussion Board Multiple Remote File Include Vulnerabilities
BugTraq ID: 20103
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20103
Summary:
Simple Discussion Board is prone multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

97. Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
BugTraq ID: 20102
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20102
Summary:
Tekman Portal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

98. More.groupware Week.PHP SQL Injection Vulnerability
BugTraq ID: 20100
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20100
Summary:
more.groupware is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 0.7.4 is vulnerable; other versions may also be affected.

99. OSU HTTP Server Multiple Information Disclosure Vulnerabilities
BugTraq ID: 20098
Remote: Yes
Last Updated: 2006-09-19
Relevant URL: http://www.securityfocus.com/bid/20098
Summary:
OSU (Ohio State University) HTTP server is prone to multiple information-disclosure vulnerabilities.

This may allow a malicious user to gain access to sensitive data; information gained may aid in further attacks.

Versions 3.11a and 3.10a are vulnerable; other versions may also be affected.

100. Mantis Config_Defaults_Inc.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16561
Remote: Yes
Last Updated: 2006-09-18
Relevant URL: http://www.securityfocus.com/bid/16561
Summary:
Mantis is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


Mantis is also prone to an unknown error in the 'query_store.php' and 'manage_proj_create.php' scripts. The exact nature and possible impact of these issues is currently unknown.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Web flaws race ahead in 2006
By: Robert Lemos
Less rigor in Web programming, a growing number of software projects, and restrictions on Web security testing are combining to make Web-site vulnerabilities the most common class of security issues this year.
http://www.securityfocus.com/news/11413

2. HP's Dunn to step down amidst hacking scandal
By: Robert Lemos
Hewlett-Packard announces that the chairwoman will resign in January, while California's Attorney General and civil lawsuits aim to use cybercrime laws to reign in investigators that abused computer access to "pretext" the phone records of reporters and directors.
http://www.securityfocus.com/news/11412

3. Security pro pleads guilty to USC breach
By: Robert Lemos
Eric McCarty agrees to a single felony charge of exploiting a flaw in the University of Southern California's online student application site and accessing confidential information.
http://www.securityfocus.com/news/11411

4. Trusted computing a shield against worst attacks?
By: Robert Lemos
A report funded by computer firmware developer Phoenix Technologies finds that the ability to identify users' computers, a key capability of trusted computing hardware, could eliminate the most damaging digital attacks.
http://www.securityfocus.com/news/11410

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/446432

2. [SJ-JOB] Security Engineer, McLean
http://www.securityfocus.com/archive/77/446431

3. [SJ-JOB] Forensics Engineer, Richmond
http://www.securityfocus.com/archive/77/446388

4. [SJ-JOB] Forensics Engineer, Cardiff
http://www.securityfocus.com/archive/77/446390

5. [SJ-JOB] Software Engineer, Los Angeles
http://www.securityfocus.com/archive/77/446392

6. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/446380

7. [SJ-JOB] Sr. Security Analyst, Parsippany
http://www.securityfocus.com/archive/77/446387

8. [SJ-JOB] Manager, Information Security, Plantation
http://www.securityfocus.com/archive/77/446389

9. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/446381

10. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/446385

11. [SJ-JOB] Security Consultant, Copenhagen
http://www.securityfocus.com/archive/77/446383

12. [SJ-JOB] Security Consultant, Copenhagen
http://www.securityfocus.com/archive/77/446382

13. [SJ-JOB] Manager, Information Security, Baltimore
http://www.securityfocus.com/archive/77/446288

14. [SJ-JOB] Sr. Security Engineer, Baltimore/Owings Mills
http://www.securityfocus.com/archive/77/446289

15. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
http://www.securityfocus.com/archive/77/446276

16. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/446286

17. [SJ-JOB] Security Engineer, Research Triangle Park
http://www.securityfocus.com/archive/77/446287

18. [SJ-JOB] Remediation Security Analyst, Charlotte
http://www.securityfocus.com/archive/77/446263

19. [SJ-JOB] Sr. Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/446270

20. [SJ-JOB] Security Architect, Fort Lauderdale
http://www.securityfocus.com/archive/77/446272

21. [SJ-JOB] Management, McLean
http://www.securityfocus.com/archive/77/446283

22. [SJ-JOB] Manager, Information Security, Baltimore
http://www.securityfocus.com/archive/77/446245

23. [SJ-JOB] Sr. Security Engineer, Sterling/Dulles
http://www.securityfocus.com/archive/77/446251

24. [SJ-JOB] Sr. Security Engineer, Baltimore/Owings Mills
http://www.securityfocus.com/archive/77/446260

25. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/446261

26. [SJ-JOB] Security Engineer, Research Triangle Park
http://www.securityfocus.com/archive/77/446264

27. [SJ-JOB] Remediation Security Analyst, Charlotte
http://www.securityfocus.com/archive/77/446247

28. [SJ-JOB] Management, McLean
http://www.securityfocus.com/archive/77/446249

29. [SJ-JOB] Sr. Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/446262

30. [SJ-JOB] Security Architect, Fort Lauderdale
http://www.securityfocus.com/archive/77/446248

31. [SJ-JOB] Security Researcher, Beijing
http://www.securityfocus.com/archive/77/446082

32. [SJ-JOB] Software Engineer, Austin
http://www.securityfocus.com/archive/77/446079

33. [SJ-JOB] Security Researcher, Beijing
http://www.securityfocus.com/archive/77/446080

34. [SJ-JOB] Account Manager, Vienna
http://www.securityfocus.com/archive/77/446081

35. [SJ-JOB] Sales Representative, Washington DC Metro Area
http://www.securityfocus.com/archive/77/446105

36. [SJ-JOB] Senior Software Engineer, CAMBRIDGE
http://www.securityfocus.com/archive/77/446135

37. [SJ-JOB] Security Engineer, Somerset
http://www.securityfocus.com/archive/77/446098

38. [SJ-JOB] Security Auditor, Canberra
http://www.securityfocus.com/archive/77/446103

39. [SJ-JOB] Quality Assurance, Somerset
http://www.securityfocus.com/archive/77/446104

40. [SJ-JOB] Sr. Security Engineer, San Ramon
http://www.securityfocus.com/archive/77/445885

41. [SJ-JOB] Sr. Security Analyst, Hunt Valley
http://www.securityfocus.com/archive/77/445886

42. [SJ-JOB] Manager, Information Security, Brooklyn (Metrotech)
http://www.securityfocus.com/archive/77/445869

43. [SJ-JOB] Security Engineer, Richland
http://www.securityfocus.com/archive/77/445870

44. [SJ-JOB] Sr. Security Analyst, Hunt Valley
http://www.securityfocus.com/archive/77/445887

45. [SJ-JOB] Quality Assurance, Minneapolis
http://www.securityfocus.com/archive/77/445866

46. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/445867

47. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/445868

48. [SJ-JOB] Management, North Sydney
http://www.securityfocus.com/archive/77/445884

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. problem in bypassing stack randomization ("call *%edx" technique)
http://www.securityfocus.com/archive/82/446330

2. ToorCon Pre-Registration Closing Friday!
http://www.securityfocus.com/archive/82/445956

3. PAKCON III: Call for Papers (CfP 2006)
http://www.securityfocus.com/archive/82/445957

4. PAKCON III: Announce (2006)
http://www.securityfocus.com/archive/82/445958

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Storing Images in SQL Server (2005)
http://www.securityfocus.com/archive/88/446413

2. SecurityFocus Microsoft Newsletter #308
http://www.securityfocus.com/archive/88/446218

3. Terminal Servers @ Datacenter
http://www.securityfocus.com/archive/88/446210

4. Question about Sniffer in Windows
http://www.securityfocus.com/archive/88/446136

5. windump on browsing of shared folders across vpn in winxp
http://www.securityfocus.com/archive/88/446048

6. Don't Get Too Comfortable - Sept. '06 Patches
http://www.securityfocus.com/archive/88/445921

7. IP address assignment problem
http://www.securityfocus.com/archive/88/444349

VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. root group in solaris
http://www.securityfocus.com/archive/92/446233

IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus