SecurityFocus Newsletter #369

Conrad Schilbe <[email protected]> Wed, 27 Sep 2006 09:32:54 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #369
----------------------------------------

This issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper 
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! 

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70160000000CbYU

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Liar, Liar, and pretexting
       2. Beginner's guide to wireless auditing
II.   BUGTRAQ SUMMARY
       1. Woltlab Burning Board Multiple SQL Injection Vulnerabilities
       2. AckerTodo Index.PHP Cross-Site Scripting Vulnerability
       3. Call of Duty Server Callvote Map Command Remote Buffer Overflow Vulnerability
       4. WWWThreads Cat Parameter Multiple Cross-Site Scripting Vulnerabilities
       5. Opial AV Download Management Index.PHP Cross-Site Scripting Vulnerability
       6. HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
       7. Kietu Hit.PHP Directory Traversal Vulnerability
       8. MySource Multiple Vulnerabilities
       9. Photostore Multiple Cross-Site Scripting Vulnerabilities
       10. PhpBB XS BB_Usage_Stats.PHP Remote File Include Vulnerability
       11. Typo3 Indexed Search Cross-Site Scripting Vulnerability
       12. ToendaCMS Media.PHP Directory Traversal Vulnerability
       13. SyntaxCMS 0004_Init_Urls.PHP Multiple Remote File Include Vulnerability
       14. Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
       15. RETIRED: Coppermine Photo Gallery Theme.PHP Remote File Include Vulnerability
       16. Sendmail Long Header Denial Of Service Vulnerability
       17. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
       18. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
       19. Iyzi Forum Uye_Ayrinti.ASP SQL Injection Vulnerability
       20. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
       21. Web-News Template.PHP Remote File Include Vulnerability
       22. ZoomStats MySQL.PHP Remote File Include Vulnerability
       23. AVCX MCF.PHP Remote File Include Vulnerability
       24. Spidey Blog Script PID Parameter SQL Injection Vulnerability
       25. PHP Multiple Input Validation Vulnerabilities
       26. PHP Multiple Unspecified Vulnerabilities
       27. My-BIC Mybic_server.PHP Remote File Include Vulnerability
       28. Back-End CMS Multiple Remote File Include Vulnerabilities
       29. Exporia Common.PHP Remote File Include Vulnerability
       30. IBM AIX Xlock Local Buffer Overflow Vulnerability
       31. BBSNew Index2.PHP Remote File Include Vulnerability
       32. Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
       33. DanPHPSupport Multiple Cross-Site Scripting Vulnerabilities
       34. BirdBlog Multiple Cross-Site Scripting Vulnerabilities
       35. IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
       36. Sun Secure Global Desktop Unspecified Multiple Input Validation Vulnerabilities
       37. CPanel Unspecified Remote Privilege Escalation Vulnerability
       38. Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability
       39. IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
       40. IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
       41. Ipswitch WS_FTP PASV Response Remote Buffer Overflow Vulnerability
       42. Apple Remote Desktop Local Authentication Bypass Vulnerability
       43. Sun Solaris 10 Malformed IPV6 Packets Denial of Service Vulnerability
       44. IBM AIX Slip.Login Local Privilege Escalation Vulnerability
       45. FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
       46. BrudaNews/GrudaGB Index.PHP Remote File Include Vulnerability
       47. EvoBB Path Parameter Multiple Remote File Include Vulnerabilities
       48. OpenOffice XML File Format Buffer Overflow Vulnerability
       49. OpenOffice Arbitrary Macro Execution Vulnerability
       50. OpenOffice Java Applet System Access Vulnerability
       51. IBM AIX CFGMGR Local Privilege Escalation and Arbitrary File Overwrite Vulnerabilities
       52. TikiWiki Highlight Cross-Site Scripting Vulnerability
       53. Linux Kernel UDF Denial of Service Vulnerability
       54. TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
       55. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
       56. Linux Kernel SCTP SO_LINGER Local Denial of Service Vulnerability
       57. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
       58. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
       59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
       60. faceStones Personal Fs_Forms_Links.PHP Remote File Include Vulnerability
       61. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
       62. Integramod Portal Phpbb_Root_Path Remote File Include Vulnerabilities
       63. Minerva Admin_Topic_Action_Logging.PHP Remote File Include Vulnerability
       64. GNUTLS PKCS RSA Signature Forgery Vulnerability
       65. GNU GZip Archive Handling Multiple Remote Vulnerabilities
       66. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
       67. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
       68. IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
       69. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
       70. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
       71. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
       72. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
       73. Linux Kernel LSM ReadV/WriteV Security Restriction Bypass Vulnerability
       74. PBLang Lang_NL.PHP Remote File Include Vulnerability
       75. Innovate Portal Index.PHP Cross-Site Scripting Vulnerability
       76. IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
       77. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
       78. Linux Kernel NFS ReadLink Remote Denial of Service Vulnerability
       79. Linux Kernel Direct-IO.C Local Denial of Service Vulnerability
       80. Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
       81. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
       82. Polaring General.PHP Remote File Include Vulnerability
       83. WebspotBlogging Multiple Remote File Include Vulnerabilities
       84. Wireshark Protocol Dissectors Multiple Vulnerabilities
       85. MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
       86. PHPartenaire Dix.PHP3 Remote File Include Vulnerability
       87. Elog Log Entry HTML Injection Vulnerability
       88. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities 
       89. JAF CMS Multiple HTML-Injection Vulnerabilities
       90. Sun Solaris Kernel SSL Service Remote Denial of Service Vulnerability
       91. PABugs Class.MySQL.PHP Remote File Include Vulnerability
       92. PHP Invoice Home.PHP Cross-Site Scripting Vulnerability
       93. PHPMyChat Index.PHP Connected_Users.Lib.PHP3 Local File Include Vulnerability
       94. Skype Technologies Skype Unspecified Remote Format String Vulnerability
       95. Sugar Suite Unspecified Arbitrary Command Execution Vulnerability
       96. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
       97. CubeCart Multiple Input Validation Vulnerabilities
       98. VBulletin Global.PHP SQL Injection Vulnerability
       99. eyeOS Multiple Unspecified Cross-Site Scripting Vulnerabilities
       100. Phoenix Evolution CMS Multiple Cross-Site Scripting Vulnerabilities
III.  SECURITYFOCUS NEWS
       1. Tag-team attack exploits IE flaw
       2. HP chief apologizes, denies he knew of hacking
       3. Web flaws race ahead in 2006
       4. HP's Dunn to step down amidst hacking scandal
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Account Manager, Houston
       2. [SJ-JOB] Account Manager, Anywhere
       3. [SJ-JOB] Security Researcher, Atlanta
       4. [SJ-JOB] Account Manager, Louisville
       5. [SJ-JOB] Account Manager, Memphis or Nashville
       6. [SJ-JOB] Quality Assurance, Ann Arbor
       7. [SJ-JOB] Quality Assurance, Ann Arbor
       8. [SJ-JOB] Technical Writer, Austin
       9. [SJ-JOB] Penetration Engineer, Chantilly
       10. [SJ-JOB] Technical Support Engineer, Ottawa
       11. [SJ-JOB] Certification & Accreditation Engineer, Washington,DC
       12. [SJ-JOB] Technical Support Engineer, Westborough
       13. [SJ-JOB] Database Security Architect, Schaumburg
       14. [SJ-JOB] Sr. Security Engineer, Schaumburg
       15. [SJ-JOB] Penetration Engineer, Sydney
       16. [SJ-JOB] Instructor, Various US Citites
       17. [SJ-JOB] Sr. Security Engineer, Arlington
       18. [SJ-JOB] Security Engineer, Melbourne
       19. [SJ-JOB] Security Consultant, Any
       20. [SJ-JOB] Director, Information Security, White Plains
       21. [SJ-JOB] Security Engineer, Dublin
       22. [SJ-JOB] Sales Engineer, New York
       23. [SJ-JOB] Security Engineer, Staines
       24. [SJ-JOB] Jr. Security Analyst, Alexandria
       25. [SJ-JOB] Threat Analyst, Fort Lauderdale
       26. [SJ-JOB] Privacy Officer, Warren
       27. [SJ-JOB] VP, Information Security, Warren
       28. [SJ-JOB] Penetration Engineer, Tel-Aviv
       29. [SJ-JOB] Certification & Accreditation Engineer, Dumfries
       30. [SJ-JOB] Sr. Security Analyst, New York
       31. [SJ-JOB] Security Consultant, Boston Area
       32. [SJ-JOB] Security Consultant, Huntington Beach
       33. [SJ-JOB] Security Consultant, Huntington Beach
       34. [SJ-JOB] Technical Support Engineer, Jersey City
       35. [SJ-JOB] Security Engineer, Santa Clara
       36. [SJ-JOB] Security Architect, New York
       37. [SJ-JOB] Sr. Security Engineer, Washington
       38. [SJ-JOB] Manager, Information Security, Washington
       39. [SJ-JOB] Sr. Security Engineer, St. Petersburg
       40. [SJ-JOB] Sr. Security Analyst, Rockville/Gaithersburg
       41. [SJ-JOB] Security Consultant, Newport Beach
       42. [SJ-JOB] Technology Risk Consultant, Chicago
       43. [SJ-JOB] Sales Engineer, Reston
       44. [SJ-JOB] Senior Software Engineer, Calgary
       45. [SJ-JOB] Jr. Security Analyst, Wilmington
       46. [SJ-JOB] Security System Administrator, Baltimore Area
       47. [SJ-JOB] Security System Administrator, Baltimore Area
       48. [SJ-JOB] Software Engineer, Minneapolis
       49. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
       50. [SJ-JOB] Sr. Security Analyst, Austin
       51. [SJ-JOB] Jr. Security Analyst, Newton
       52. [SJ-JOB] Sr. Security Analyst, Milwaukee
       53. [SJ-JOB] Security Engineer, Pittsburgh
       54. [SJ-JOB] Penetration Engineer, London
       55. [SJ-JOB] Security Auditor, New York City
       56. [SJ-JOB] Sr. Security Analyst, Chicago
       57. [SJ-JOB] Security Engineer, Greenwood Village
       58. [SJ-JOB] Information Assurance Analyst, Richmond
       59. [SJ-JOB] VP / Dir / Mgr engineering, Ann Arbor
       60. [SJ-JOB] Sales Representative, Austin
       61. [SJ-JOB] Security System Administrator, Port St Lucie
       62. [SJ-JOB] Sr. Security Analyst, Atlanta
       63. [SJ-JOB] Security Engineer, London
       64. [SJ-JOB] Technical Support Engineer, Brussels
       65. [SJ-JOB] Security Engineer, San Jose
       66. [SJ-JOB] Manager, Information Security, Richmond
       67. [SJ-JOB] Instructor, North Canton
       68. [SJ-JOB] Sales Representative, Montvale
       69. [SJ-JOB] Training / Awareness Specialist, Cupertino
       70. [SJ-JOB] Security Architect, Atlanta
       71. [SJ-JOB] Channel / Business Development, Frederick
       72. [SJ-JOB] Security Engineer, Raleigh
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. bypassing randomized stack using linux-gate.so.1
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #309
       2. Microsoft Security Clamp
       3. Storing Images in SQL Server (2005)
VIII. SUN FOCUS LIST SUMMARY
       1. root group in solaris
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Liar, Liar, and pretexting
By Mark Rasch
Mark Rasch details the legality of pretexting by putting it in context with how it used, comparing it with legal forms of lying, and by looking at previous court cases involving pretexting in the United States. Hewlett Packard's use of pretexting also brings up potential charges of criminal fraud, violations of consumer protection laws, issues of deception, and the use of spyware. Together these issues make for a very interesting legal situation at HP.
http://www.securityfocus.com/columnists/417

2. Beginner's guide to wireless auditing
By David Maynor
This article is designed as a beginner's guide to fuzzing wireless device drivers, starting with how to build an auditing environment, how to construct fuzzing tools and finally, how to interpret the results. This auditing environment can be used for WiFi as well as Bluetooth and infrared devices.
http://www.securityfocus.com/infocus/1877


II.  BUGTRAQ SUMMARY
--------------------
1. Woltlab Burning Board Multiple SQL Injection Vulnerabilities
BugTraq ID: 18423
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18423
Summary:
Woltlab Burning Board is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

2. AckerTodo Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 19894
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19894
Summary:
AckerTodo is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue would allow an attacker to steal cookie-based credentials and to launch other attacks.

Version 4.0 is vulnerable; other versions may also be affected.

3. Call of Duty Server Callvote Map Command Remote Buffer Overflow Vulnerability
BugTraq ID: 20180
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20180
Summary:
Call of Duty server is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Exploiting this issue may allow remote attackers to execute arbitrary machine code in the context of the affected application.

4. WWWThreads Cat Parameter Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20178
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20178
Summary:
WWWThreads is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

WWWThreads 4.5.2 and earlier versions are reported vulnerable; other versions may also be affected.

5. Opial AV Download Management Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20174
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20174
Summary:
Opial Audio/Visual Download Management is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 1.0 is vulnerable; other versions may also be affected.

6. HP-UX CIFS Unspecified Security Restriction Bypass Vulnerability
BugTraq ID: 20179
Remote: No
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20179
Summary:
HP-UX CIFS (Samba) is prone to an unspecified vulnerability that allows attackers to bypass certain security restrictions. 

The problem affects SMB-mounted filesystems ('cifs'). A local attacker can exploit this issue to bypass the security restrictions and gain unauthorized access to the filesystem. This may allow the attacker to escalate their privileges and then conduct further exploits.

Versions of HP CIFS Server (Samba) up to and including A.02.02.01 are affected.

7. Kietu Hit.PHP Directory Traversal Vulnerability
BugTraq ID: 20175
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20175
Summary:
Kietu is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.

Exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.

8. MySource Multiple Vulnerabilities
BugTraq ID: 20153
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20153
Summary:
MySource products are prone to multiple input-validation vulnerabilities. Exploiting these issues will allow an attacker to manipulate the application into becoming an HTTP proxy and to conduct cross-site scripting attacks.

An attacker may leverage these issues to cause the application to consume excessive bandwidth and to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

These versions are vulnerable:

- MySource Matrix 3.8 and earlier
- MySource 2.x.

9. Photostore Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20172
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20172
Summary:
Photostore is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

10. PhpBB XS BB_Usage_Stats.PHP Remote File Include Vulnerability
BugTraq ID: 20046
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20046
Summary:
phpBB XS is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

11. Typo3 Indexed Search Cross-Site Scripting Vulnerability
BugTraq ID: 20173
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20173
Summary:
TYPO3 is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Versions 4.0 and 4.0.1 are vulnerable.

12. ToendaCMS Media.PHP Directory Traversal Vulnerability
BugTraq ID: 20170
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20170
Summary:
toendaCMS is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.

Exploiting this issue may allow an attacker to access sensitive information that could aid in further attacks.

Version 1.0.4 is vulnerable; other versions may also be affected.

13. SyntaxCMS 0004_Init_Urls.PHP Multiple Remote File Include Vulnerability
BugTraq ID: 20171
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20171
Summary:
SyntaxCMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

A successful exploit of this issue allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

14. Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
BugTraq ID: 10253
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/10253
Summary:
Coppermine Photo Gallery is reported prone to multiple input-validation vulnerabilities, some of which may lead to arbitrary command execution. These issues occur because the application fails to properly sanitize and validate user-supplied input before using it in dynamic content and in function calls that execute system commands. 

Attackers may exploit these issues to steal cookie-based authentication credentials, map the application root directory of the affected application, execute arbitrary commands, and include arbitrary files. Other attacks are also possible.

15. RETIRED: Coppermine Photo Gallery Theme.PHP Remote File Include Vulnerability
BugTraq ID: 19219
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19219
Summary:
Coppermine Photo Gallery is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.

This BID is being retired because this issue has already been addressed in 10253 (Coppermine Photo Gallery Multiple Input Validation Vulnerabilities).

16. Sendmail Long Header Denial Of Service Vulnerability
BugTraq ID: 19714
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19714
Summary:
Sendmail is prone to a denial-of-service vulnerability. 

An attacker can exploit this issue to crash the Sendmail process, causing a denial of service.

17. Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19534
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19534
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

The Flock browser version 0.7.4.1 and the K-Meleon browser version 1.0.1 are also reported vulnerable.

18. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability
BugTraq ID: 19488
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19488
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability. This issue is due to a race condition that may result in double-free or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other Mozilla products are also likely affected.

19. Iyzi Forum Uye_Ayrinti.ASP SQL Injection Vulnerability
BugTraq ID: 20168
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20168
Summary:
Iyzi Forum is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Iyzi Forum 1.0 beta 3 and prior versions are reported affected.

20. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
BugTraq ID: 20042
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20042
Summary:
The Mozilla Foundation has released six security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- supply malicious data through updates
- inject arbitrary content
- execute arbitrary JavaScript
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.7
- Mozilla Thunderbird version 1.5.0.7
- Mozilla SeaMonkey version 1.0.5

21. Web-News Template.PHP Remote File Include Vulnerability
BugTraq ID: 20166
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20166
Summary:
Web-News is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.6.3 is vulnerable to this issue. Previous versions may be affected as well.

22. ZoomStats MySQL.PHP Remote File Include Vulnerability
BugTraq ID: 20165
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20165
Summary:
ZoomStats is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 1.0.2 is vulnerable to this issue. Previous versions may be affected as well.

23. AVCX MCF.PHP Remote File Include Vulnerability
BugTraq ID: 20167
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/20167
Summary:
AVCX is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

AVCX 3.4 and earlier versions are vulnerable to this issue.

24. Spidey Blog Script PID Parameter SQL Injection Vulnerability
BugTraq ID: 19518
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19518
Summary:
Spidey Blog Script is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Spidey Blog Script 1.5 and prior versions are reported to be affected.

25. PHP Multiple Input Validation Vulnerabilities
BugTraq ID: 19582
Remote: No
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/19582
Summary:
PHP is prone to multiple input-validation vulnerabilities. Successful exploits could allow an attacker to write files in unauthorized locations, cause a denial-of-service condition, and potentially execute code.

These issues are reported to affect PHP versions 4.4.3 and 5.1.4; other versions may also be vulnerable.

26. PHP Multiple Unspecified Vulnerabilities
BugTraq ID: 17843
Remote: Yes
Last Updated: 2006-09-25
Relevant URL: http://www.securityfocus.com/bid/17843
Summary:
PHP is vulnerable to multiple unspecified vulnerabilities ranging from buffer-overflow to cross-site scripting issues.

The precise nature of these vulnerabilities is currently not known; this BID will be updated as more information becomes available.

Some of the issues discussed may be related to other BIDs regarding PHP vulnerabilities.

27. My-BIC Mybic_server.PHP Remote File Include Vulnerability
BugTraq ID: 20208
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20208
Summary:
My-BIC is prone to a remote file-include vulnerability because these applications fail to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

28. Back-End CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 20207
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20207
Summary:
Back-End CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
 
Back-End CMS version 0.4.5 is vulnerable to these issues.

29. Exporia Common.PHP Remote File Include Vulnerability
BugTraq ID: 20205
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20205
Summary:
Exporia is prone to a remote file-include vulnerability because the application fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

30. IBM AIX Xlock Local Buffer Overflow Vulnerability
BugTraq ID: 20201
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20201
Summary:
IBM AIX is prone to a local buffer-overflow vulnerability. 

An attacker can exploit this vulnerability to execute arbitrary code with superuser privileges. A successful exploit would lead to a complete compromise of affected computers. 

AIX versions 5.2 and 5.3 are vulnerable to this issue.

31. BBSNew Index2.PHP Remote File Include Vulnerability
BugTraq ID: 20204
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20204
Summary:
bbsNew is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

A successful exploit of this issue allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

32. Ipswitch WS_FTP Server XCRC XSHA1 and XMD5 Commands Buffer Overflow Vulnerabilities
BugTraq ID: 20076
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20076
Summary:
Ipswitch WS_FTP Server is prone to a number of stack-overflow vulnerabilities. Updates are available.

A successful exploit may lead to remote arbitrary code execution with administrative privileges, facilitating the complete compromise of affected computers.

Ipswitch WS_FTP Server versions 5.04 and 5.05 are vulnerable to these issues; other versions may also be affected.

33. DanPHPSupport Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20203
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20203
Summary:
DanPHPSupport is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
 
DanPHPSupport 0.5 is vulnerable to these issues.

34. BirdBlog Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20202
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20202
Summary:
BirdBlog is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.

BirdBlog 1.4.0 and prior versions are reported vulnerable.

35. IBM AIX Inventory Scout Local Arbitrary File Overwrite Vulnerability
BugTraq ID: 20199
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20199
Summary:
IBM AIX Inventory Scout is prone to a local arbitrary-file-overwrite vulnerability. 

A local attacker may be able to exploit this issue to overwrite arbitrary files and corrupt sensitive data, which could lead to denial-of-service conditions. Privilege-escalation attacks may be possible as well. 

IBM Inventory Scout 2.2 for AIX versions 5.2 and 5.3 is vulnerable to this issue.

36. Sun Secure Global Desktop Unspecified Multiple Input Validation Vulnerabilities
BugTraq ID: 20135
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20135
Summary:
Sun Secure Global Desktop is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site or to retrieve sensitive system information. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.

Sun Secure Global Desktop 4.2 and earlier versions are reported vulnerable.

37. CPanel Unspecified Remote Privilege Escalation Vulnerability
BugTraq ID: 20163
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20163
Summary:
cPanel is prone to an unspecified remote privilege-escalation vulnerability.

A remote attacker can exploit this issue to gain administrative access to the affected application. This may lead to other attacks.

38. Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability
BugTraq ID: 20096
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20096
Summary:
Microsoft Internet Explorer is prone to a buffer-overflow vulnerability. 

The vulnerability arises because of an error in the processing of Vector Markup Language documents.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. The method currently used to exploit this issue will typically terminate Internet Explorer.

This vulnerability is currently being exploited in the wild as 'Trojan.Vimalov'.

This vulnerability affects Internet Explorer version 6.0 on a fully patched system. Previous versions may also be affected.

Update: Microsoft Outlook 2003 is also an attack vector for this issue, since it uses Internet Explorer to render HTML email. Reportedly, attacks are possible even when active scripting has been disabled for email viewing.

39. IBM AIX Mkvg Command Local Privilege Escalation Vulnerability
BugTraq ID: 20197
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20197
Summary:
AIX is prone to a local privilege-escalation vulnerability

A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. To exploit this issue, the attacker must have 'system group' permissions.

AIX 5.2 and 5.3 are affected by this vulnerability.

40. IBM AIX Utape Command Local Privilege Escalation and Denial of Service Vulnerabilities
BugTraq ID: 20187
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20187
Summary:
AIX is prone to local privilege-escalation and denial-of-service vulnerabilities.

A local attacker can exploit these issues to execute arbitrary commands with root privileges or to overwrite arbitrary system files, resulting in denial-of-service conditions. To exploit this issue, an attacker must have both 'system group' and the diagnostics role.

AIX 5.2 and 5.3 are affected by this vulnerability.

41. Ipswitch WS_FTP PASV Response Remote Buffer Overflow Vulnerability
BugTraq ID: 20121
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20121
Summary:
A remote buffer-overflow vulnerability is reported in the Ipswitch WS_FTP client. This issue occurs because the application fails to properly validate the length of user-supplied strings prior to copying them into finite process buffers. 

An attacker may exploit this issue to cause the affected client to crash. Execution of arbitrary code in the context of the FTP client process may also be possible.

Version 5.08 of the affected software is vulnerable; other versions may be affected as well.

42. Apple Remote Desktop Local Authentication Bypass Vulnerability
BugTraq ID: 20092
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20092
Summary:
Apple Remote Desktop is prone to an authentication-bypass vulnerability.

A local attacker can exploit this issue to gain superuser privileges to a vulnerable computer.

43. Sun Solaris 10 Malformed IPV6 Packets Denial of Service Vulnerability
BugTraq ID: 20195
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20195
Summary:
Sun Solaris 10 is prone to a denial-of-service vulnerability. This issue arises on systems running Solaris 10 x64 without patch 118855-16.

The vendor has reported that local or remote users on affected computers may trigger a denial-of-service condition through malformed IPV6 network packets.

A successful exploit may allow attackers to crash the operating system, effectively denying
service.

44. IBM AIX Slip.Login Local Privilege Escalation Vulnerability
BugTraq ID: 20191
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20191
Summary:
IBM AIX is prone to a privilege-escalation vulnerability in '/etc/slip.login'. Exploiting this issue may allow an unprivileged user to execute arbitrary code with superuser privileges.

45. FreeBSD I386_Set_LDT() Multiple Local Denial of Service Vulnerabilities
BugTraq ID: 20158
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20158
Summary:
FreeBSD is prone to multiple local denial-of-service vulnerabilities. These issues occur because of input-validation flaws related to the handling of integers.

An attacker may leverage these issues to cause the affected computer to crash, denying service to legitimate users.

Versions 5.2 through 5.5 are vulnerable to these issues; other versions may also be affected.

46. BrudaNews/GrudaGB Index.PHP Remote File Include Vulnerability
BugTraq ID: 20192
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20192
Summary:
BrudaNews/GrudaGB are prone to a remote file-include vulnerability because these applications fail to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

47. EvoBB Path Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 20189
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20189
Summary:
EvoBB is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

EvoBB 0.3 and prior versions are vulnerable to these issues.

48. OpenOffice XML File Format Buffer Overflow Vulnerability
BugTraq ID: 18739
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18739
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious XML documents to cause a buffer overflow leading to read/write privileges to local files on a vulnerable computer.

49. OpenOffice Arbitrary Macro Execution Vulnerability
BugTraq ID: 18738
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18738
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious macros to gain read/write privileges to local files on a vulnerable computer.

50. OpenOffice Java Applet System Access Vulnerability
BugTraq ID: 18737
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18737
Summary:
OpenOffice is prone to a vulnerability that allows attackers to gain unauthorized access to a vulnerable computer.

The vendor has reported that this vulnerability allows malicious Java applets to gain read/write privileges to local files on a vulnerable computer.

51. IBM AIX CFGMGR Local Privilege Escalation and Arbitrary File Overwrite Vulnerabilities
BugTraq ID: 20190
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20190
Summary:
IBM AIX is prone to these locally exploitable vulnerabilities:

- a privilege-escalation issue
- an arbitrary-file-overwrite issue. 

A local attacker may be able to exploit these issues to gain elevated privileges on the affected computer. A successful exploit will lead to a complete compromise. Attackers may also overwrite arbitrary files, resulting in denial-of-service conditions.

Attackers require access to the 'system' group to execute the affected binary.

IBM AIX versions 5.2 and 5.3 are vulnerable to these issues.

52. TikiWiki Highlight Cross-Site Scripting Vulnerability
BugTraq ID: 19654
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19654
Summary:
TikiWiki is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

Version 1.9.4 is known to be vulnerable; prior versions may also be affected.

53. Linux Kernel UDF Denial of Service Vulnerability
BugTraq ID: 19562
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19562
Summary:
The Linux kernel UDF file module is prone to a denial-of-service. 

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

54. TikiWiki Configure Script JHot.PHP Remote Command Execution Vulnerability
BugTraq ID: 19819
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19819
Summary:
TikiWiki is prone to a remote command-execution vulnerability. 

Attackers can exploit this issue to execute arbitrary system commands with the privileges of the webserver process.

TikiWiki 1.9.4 and prior versions are vulnerable to these issues; other versions may also be affected.

55. Linux Kernel NFS and EXT3 Combination Remote Denial of Service Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the EXT3 filesystem code fails to properly handle unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams to affected computers that are configured as NFS servers, causing filesystem errors. Depending on the mount-time options of affected filesystems, this may result in remounting filesystems as read-only or cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to this issue; other versions in the 2.6 series are also likely affected.

56. Linux Kernel SCTP SO_LINGER Local Denial of Service Vulnerability
BugTraq ID: 20087
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20087
Summary:
The Linux kernel SCTP module is prone to a local denial-of-service vulnerability. 

This issue allows local attackers to cause kernel crashes, denying service to legitimate users.

Specific information regarding affected versions of the Linux kernel is currently unavailable. This BID will be updated as further information is disclosed.

57. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. 

An attacker can exploit this issue to crash the kernel, denying further service to legitimate users.

58. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

59. Linux Kernel SCTP_Make_Abort_User Function Buffer Overflow Vulnerability
BugTraq ID: 19666
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19666
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

A local attacker can exploit this issue to execute arbitrary code and potentially compromise the affected computer.

60. faceStones Personal Fs_Forms_Links.PHP Remote File Include Vulnerability
BugTraq ID: 20188
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20188
Summary:
faceStones Personal is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

faceStones Personal 2.0.42 and earlier versions are vulnerable; other versions may also be affected.

61. ImageMagick Sun Bitmap Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19699
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19699
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

62. Integramod Portal Phpbb_Root_Path Remote File Include Vulnerabilities
BugTraq ID: 19689
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19689
Summary:
A remote file-include vulnerability affects Integramod Portal because the application fails to properly sanitize user-supplied input before using it in a PHP 'include()' function call. 

An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. 

This issue affects version 2.x; other versions may also be vulnerable.

63. Minerva Admin_Topic_Action_Logging.PHP Remote File Include Vulnerability
BugTraq ID: 20185
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20185
Summary:
Minerva is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Minerva 2.0.21 build 238a and earlier versions are vulnerable; other versions may also be affected.

64. GNUTLS PKCS RSA Signature Forgery Vulnerability
BugTraq ID: 20027
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20027
Summary:
GnuTLS is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when verifying a X.509 certificate. 

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key.

This vulnerability is a variant of the issue discussed in BID 19849 (OpenSSL PKCS Padding RSA Signature Forgery Vulnerability) and affects GnuTLS versions prior to version 1.4.3.

65. GNU GZip Archive Handling Multiple Remote Vulnerabilities
BugTraq ID: 20101
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20101
Summary:
The gzip utility is prone to multiple remote buffer-overflow and denial-of-service vulnerabilities when handling malicious archive files.

Successful exploits may allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and may facilitate a remote compromise. Attackers may also trigger denial-of-service conditions by crashing or hanging the application.

Specific information regarding affected versions of gzip is currently unavailable. This BID will be updated as more information is released.

66. ImageMagick XCF Image File Remote Unspecified Buffer Overflow Vulnerability
BugTraq ID: 19697
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19697
Summary:
ImageMagick is prone to an unspecified remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

This BID will be updated as further information is disclosed.

Versions of ImageMagick prior to 6.2.9-2 are vulnerable to this issue.

67. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19507
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19507
Summary:
ImageMagick is prone to a remote heap buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.

68. IBM Snappd AIX Local Arbitrary Command Execution Vulnerability
BugTraq ID: 20193
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20193
Summary:
IBM AIX is prone to an arbitrary command-execution vulnerability. 

An attacker can exploit this vulnerability to execute arbitrary commands with superuser privileges. A successful exploit would lead to a complete compromise of affected computers. 

AIX versions 5.2 and 5.3 are vulnerable to this issue.

69. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

70. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
BugTraq ID: 19475
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19475
Summary:
The Linux kernel is prone to an unspecified remote denial-of-service vulnerability.

This issue allows remote attackers to cause kernel panics, denying service to legitimate users.

No further information is currently available. This BID will be updated as more information is released.

Specific version information is currently unavailable. Kernel versions in the 2.6 series are currently considered vulnerable.

71. Linux Kernel Choose_New_Parent Local Denial of Service Vulnerability
BugTraq ID: 18099
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18099
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the 'choose_new_parent' function.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.11.12.

72. Linux Kernel SNMP NAT Helper Remote Denial of Service Vulnerability
BugTraq ID: 18081
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18081
Summary:
The Linux SNMP NAT helper is susceptible to a remote denial-of-service vulnerability. 

This issue allows remote attackers to potentially corrupt memory and ultimately trigger a denial of service for legitimate users. 

Kernel versions prior to 2.6.16.18 are vulnerable to this issue.

73. Linux Kernel LSM ReadV/WriteV Security Restriction Bypass Vulnerability
BugTraq ID: 18105
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18105
Summary:
The Linux kernel is susceptible to a security-restriction-bypass vulnerability. This issue is due to the kernel's failure to properly enforce Linux Security Module security checks.

This issue allows local attackers to bypass security restrictions, allowing them to read and write to files they do not have permissions to access. This may aid them in further attacks.

This issue occurs during read and write calls that occur after files have been opened. During the open process, proper security checks are enforced. This means that this issue is exploitable only when access to files is revoked after they have already been opened by an attacker.

Linux kernel versions prior to 2.6.16.12 are vulnerable to this issue.

74. PBLang Lang_NL.PHP Remote File Include Vulnerability
BugTraq ID: 20184
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20184
Summary:
PBLang is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 4.66z and prior.

75. Innovate Portal Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20104
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20104
Summary:
Innovate Portal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

76. IBM AIX RDIST Local Arbitrary File Overwrite Vulnerability
BugTraq ID: 20194
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20194
Summary:
IBM AIX is prone to a local a local arbitrary file-overwrite vulnerability. 

A local attacker can exploit this issue to overwrite arbitrary files. This may result in denial-of-service conditions or permit an attacker to take complete control of a vulnerable computer.

This issue pertains only to '/usr/bin/rdist'; '/usr/sbin/rdist' is not affected.

IBM AIX versions 5.2 and 5.3 are vulnerable to this issue.

77. Linux Kernel Ssockaddr_In.Sin_Zero Kernel Memory Disclosure Vulnerabilities
BugTraq ID: 17203
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/17203
Summary:
The Linux kernel is affected by local memory-disclosure vulnerabilities. These issues are due to the kernel's failure to properly clear previously used kernel memory before returning it to local users.

These issues allow an attacker to read kernel memory and potentially gather information to use in further attacks.

78. Linux Kernel NFS ReadLink Remote Denial of Service Vulnerability
BugTraq ID: 20186
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20186
Summary:
The Linux kernel is susceptible to a remote denial-of-service vulnerability because the NFS client code fails to properly handle unexpected conditions.

Attackers controlling malicious NFS servers, or attackers that can perform man-in-the-middle attacks between NFS client and server computers may cause vulnerable NFS client computers to crash.

Linux kernel versions 2.4 through 2.4.31 are vulnerable to this issue.

79. Linux Kernel Direct-IO.C Local Denial of Service Vulnerability
BugTraq ID: 19665
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19665
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the direct IO driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects the Linux kernel 2.6 series prior to 2.6.10.

80. Linux Kernel SELinux_PTrace Local Denial of Service Vulnerability
BugTraq ID: 17830
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/17830
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error when SELinux is enabled and ptrace is used.

This vulnerability allows local users to panic the kernel, denying further service to legitimate users.

81. Linux Kernel SG Driver Direct IO Local Denial of Service Vulnerability
BugTraq ID: 18101
Remote: No
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18101
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the SG driver.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.13.

82. Polaring General.PHP Remote File Include Vulnerability
BugTraq ID: 20183
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20183
Summary:
Polaring is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 0.04.03 and prior.

83. WebspotBlogging Multiple Remote File Include Vulnerabilities
BugTraq ID: 18260
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/18260
Summary:
WebspotBlogging is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

84. Wireshark Protocol Dissectors Multiple Vulnerabilities
BugTraq ID: 19051
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19051
Summary:
Wireshark is prone to multiple vulnerabilities:

- A format-string vulnerability.
- An off-by-one vulnerability.
- An infinite-loop vulnerability. 
- A memory-allocation vulnerability.

These may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer or cause a denial-of-service condition to legitimate users of the application.

85. MIT Kerberos 5 KRB5_Recvauth Remote Pre-Authentication Double-Free Vulnerability
BugTraq ID: 14239
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/14239
Summary:
MIT Kerberos 5 is prone to a remote double-free vulnerability. Remote attackers can trigger this issue prior to any authentication whatsoever. The issue exists in the 'revcauth_common()' helper function. 

 Because of the code path taken in the vulnerable function, exploitation may be hindered. However, attackers may presumably leverage this issue to execute arbitrary code in the context of the affected service. 

Note that successful exploitation of this issue on a Kerberos Key Distribution Center (KDC) computer may result in the compromise of an entire Kerberos realm.

86. PHPartenaire Dix.PHP3 Remote File Include Vulnerability
BugTraq ID: 20182
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20182
Summary:
PHPartenaire is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the application and the underlying system; other attacks are also possible.

PHPartenaire 1.0 and earlier versions are vulnerable to this issue.

87. Elog Log Entry HTML Injection Vulnerability
BugTraq ID: 20181
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20181
Summary:
ELOG is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.

Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
 
Version 2.6.1 is vulnerable; other versions may also be affected.

88. SquirrelMail Compose.PHP Multiple Information Disclosure and Data Modification Vulnerabilities 
BugTraq ID: 19486
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and data-modification vulnerabilities because the application fails to properly sanitize user-supplied input.

Successful exploits may allow an authenticated remote attacker to read and write email attachments or preferences from other users. This may lead to other attacks.

89. JAF CMS Multiple HTML-Injection Vulnerabilities
BugTraq ID: 20225
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20225
Summary:
JAF CMS is prone to multiple HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

JAF CMS version 4.0RC1 is vulnerable to these issues; other versions may also be affected.

90. Sun Solaris Kernel SSL Service Remote Denial of Service Vulnerability
BugTraq ID: 20224
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20224
Summary:
Sun Solaris is vulnerable to a denial-of-service vulnerability.

A remote attacker may exploit this issue to cause kernel panic effectively denying service to legitimate users.

 This issue only affects Solaris 10.

91. PABugs Class.MySQL.PHP Remote File Include Vulnerability
BugTraq ID: 20222
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20222
Summary:
paBugs is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Versions 2.0 beta 3 and prior are vulnerable to this issue.

92. PHP Invoice Home.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20221
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20221
Summary:
PHP Invoice is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

Version 2.2 is reported vulnerable; other versions may also be affected.

93. PHPMyChat Index.PHP Connected_Users.Lib.PHP3 Local File Include Vulnerability
BugTraq ID: 20219
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20219
Summary:
phpMyChat is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. 

A successful exploit may allow an unauthorized user to view files and to execute local scripts.

This issue affects version 0.1; other versions may also be affected.

94. Skype Technologies Skype Unspecified Remote Format String Vulnerability
BugTraq ID: 20218
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20218
Summary:
Skype is susceptible to a remote format-string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to utilizing it in the format-specification argument of a formatted-printing function.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application, potentially facilitating the remote compromise of affected computers.

Skype version 1.5.0.79 for Apple Mac OS X is vulnerable to this issue; other versions and platforms may also be affected.

95. Sugar Suite Unspecified Arbitrary Command Execution Vulnerability
BugTraq ID: 20217
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20217
Summary:
Sugar Suite is prone to an unspecified vulnerability that may allow an attacker to execute arbitrary commands with the privileges of the webserver process. 

Very little information is known. This BID will be updated as soon as more information is known.

96. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
BugTraq ID: 20216
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20216
Summary:
OpenSSH is susceptible to a remote denial-of-service vulnerability. This issue is due to a failure of the application to properly handle incoming duplicate blocks.

This issue may be exploited by remote attackers to consume excessive CPU resources, potentially denying service to legitimate users.

This issue only occurs when OpenSSH is configured to accept SSH version one traffic.

97. CubeCart Multiple Input Validation Vulnerabilities
BugTraq ID: 20215
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20215
Summary:
CubeCart is prone to multiple input-validation vulnerabilities. The issues include information disclosure, cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

98. VBulletin Global.PHP SQL Injection Vulnerability
BugTraq ID: 20214
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20214
Summary:
VBulletin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 2.3 is vulnerable; other versions may also be affected.

99. eyeOS Multiple Unspecified Cross-Site Scripting Vulnerabilities
BugTraq ID: 20213
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20213
Summary:
eyeOS is prone to  multiple unspecified cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
 
eyeOS versions prior to 0.9.1 are vulnerable to these issues.

100. Phoenix Evolution CMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20212
Remote: Yes
Last Updated: 2006-09-26
Relevant URL: http://www.securityfocus.com/bid/20212
Summary:
Phoenix Evolution CMS is prone to multiple cross-site scripting vulnerabilities because the application fails to sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Tag-team attack exploits IE flaw
By: Robert Lemos
Attackers exploit a zero-day vulnerability to cause a large number of Web sites to send their visitors to rogue pages carrying a second attack, this time against Microsoft's Internet Explorer.
http://www.securityfocus.com/news/11415

2. HP chief apologizes, denies he knew of hacking
By: Robert Lemos
Hewlett-Packard's CEO Mark Hurd immediately replaces former chairperson Patricia Dunn as the company acknowledges it knew about the "pretexting" but not about the "hacking."
http://www.securityfocus.com/news/11414

3. Web flaws race ahead in 2006
By: Robert Lemos
Less rigor in Web programming, a growing number of software projects, and restrictions on Web security testing are combining to make Web-site vulnerabilities the most common class of security issues this year.
http://www.securityfocus.com/news/11413

4. HP's Dunn to step down amidst hacking scandal
By: Robert Lemos
Hewlett-Packard announces that the chairwoman will resign in January, while California's Attorney General and civil lawsuits aim to use cybercrime laws to reign in investigators that abused computer access to "pretext" the phone records of reporters and directors.
http://www.securityfocus.com/news/11412

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Account Manager, Houston
http://www.securityfocus.com/archive/77/447059

2. [SJ-JOB] Account Manager, Anywhere
http://www.securityfocus.com/archive/77/447064

3. [SJ-JOB] Security Researcher, Atlanta
http://www.securityfocus.com/archive/77/447060

4. [SJ-JOB] Account Manager, Louisville
http://www.securityfocus.com/archive/77/447061

5. [SJ-JOB] Account Manager, Memphis or Nashville
http://www.securityfocus.com/archive/77/447063

6. [SJ-JOB] Quality Assurance, Ann Arbor
http://www.securityfocus.com/archive/77/447073

7. [SJ-JOB] Quality Assurance, Ann Arbor
http://www.securityfocus.com/archive/77/447074

8. [SJ-JOB] Technical Writer, Austin
http://www.securityfocus.com/archive/77/447076

9. [SJ-JOB] Penetration Engineer, Chantilly
http://www.securityfocus.com/archive/77/447072

10. [SJ-JOB] Technical Support Engineer, Ottawa
http://www.securityfocus.com/archive/77/447075

11. [SJ-JOB] Certification & Accreditation Engineer, Washington,DC
http://www.securityfocus.com/archive/77/446898

12. [SJ-JOB] Technical Support Engineer, Westborough
http://www.securityfocus.com/archive/77/446899

13. [SJ-JOB] Database Security Architect, Schaumburg
http://www.securityfocus.com/archive/77/446900

14. [SJ-JOB] Sr. Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/446905

15. [SJ-JOB] Penetration Engineer, Sydney
http://www.securityfocus.com/archive/77/446901

16. [SJ-JOB] Instructor, Various US Citites
http://www.securityfocus.com/archive/77/446902

17. [SJ-JOB] Sr. Security Engineer, Arlington
http://www.securityfocus.com/archive/77/446906

18. [SJ-JOB] Security Engineer, Melbourne
http://www.securityfocus.com/archive/77/446907

19. [SJ-JOB] Security Consultant, Any
http://www.securityfocus.com/archive/77/446639

20. [SJ-JOB] Director, Information Security, White Plains
http://www.securityfocus.com/archive/77/446640

21. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/446644

22. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/446648

23. [SJ-JOB] Security Engineer, Staines
http://www.securityfocus.com/archive/77/446654

24. [SJ-JOB] Jr. Security Analyst, Alexandria
http://www.securityfocus.com/archive/77/446641

25. [SJ-JOB] Threat Analyst, Fort Lauderdale
http://www.securityfocus.com/archive/77/446645

26. [SJ-JOB] Privacy Officer, Warren
http://www.securityfocus.com/archive/77/446647

27. [SJ-JOB] VP, Information Security, Warren
http://www.securityfocus.com/archive/77/446649

28. [SJ-JOB] Penetration Engineer, Tel-Aviv
http://www.securityfocus.com/archive/77/446643

29. [SJ-JOB] Certification & Accreditation Engineer, Dumfries
http://www.securityfocus.com/archive/77/446625

30. [SJ-JOB] Sr. Security Analyst, New York
http://www.securityfocus.com/archive/77/446596

31. [SJ-JOB] Security Consultant, Boston Area
http://www.securityfocus.com/archive/77/446598

32. [SJ-JOB] Security Consultant, Huntington Beach
http://www.securityfocus.com/archive/77/446597

33. [SJ-JOB] Security Consultant, Huntington Beach
http://www.securityfocus.com/archive/77/446595

34. [SJ-JOB] Technical Support Engineer, Jersey City
http://www.securityfocus.com/archive/77/446577

35. [SJ-JOB] Security Engineer, Santa Clara
http://www.securityfocus.com/archive/77/446591

36. [SJ-JOB] Security Architect, New York
http://www.securityfocus.com/archive/77/446593

37. [SJ-JOB] Sr. Security Engineer, Washington
http://www.securityfocus.com/archive/77/446588

38. [SJ-JOB] Manager, Information Security, Washington
http://www.securityfocus.com/archive/77/446592

39. [SJ-JOB] Sr. Security Engineer, St. Petersburg
http://www.securityfocus.com/archive/77/446578

40. [SJ-JOB] Sr. Security Analyst, Rockville/Gaithersburg
http://www.securityfocus.com/archive/77/446586

41. [SJ-JOB] Security Consultant, Newport Beach
http://www.securityfocus.com/archive/77/446587

42. [SJ-JOB] Technology Risk Consultant, Chicago
http://www.securityfocus.com/archive/77/446589

43. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/446590

44. [SJ-JOB] Senior Software Engineer, Calgary
http://www.securityfocus.com/archive/77/446524

45. [SJ-JOB] Jr. Security Analyst, Wilmington
http://www.securityfocus.com/archive/77/446519

46. [SJ-JOB] Security System Administrator, Baltimore Area
http://www.securityfocus.com/archive/77/446526

47. [SJ-JOB] Security System Administrator, Baltimore Area
http://www.securityfocus.com/archive/77/446531

48. [SJ-JOB] Software Engineer, Minneapolis
http://www.securityfocus.com/archive/77/446513

49. [SJ-JOB] Sr. Security Analyst, Eastern Iowa
http://www.securityfocus.com/archive/77/446514

50. [SJ-JOB] Sr. Security Analyst, Austin
http://www.securityfocus.com/archive/77/446518

51. [SJ-JOB] Jr. Security Analyst, Newton
http://www.securityfocus.com/archive/77/446527

52. [SJ-JOB] Sr. Security Analyst, Milwaukee
http://www.securityfocus.com/archive/77/446510

53. [SJ-JOB] Security Engineer, Pittsburgh
http://www.securityfocus.com/archive/77/446515

54. [SJ-JOB] Penetration Engineer, London
http://www.securityfocus.com/archive/77/446509

55. [SJ-JOB] Security Auditor, New York City
http://www.securityfocus.com/archive/77/446501

56. [SJ-JOB] Sr. Security Analyst, Chicago
http://www.securityfocus.com/archive/77/446506

57. [SJ-JOB] Security Engineer, Greenwood Village
http://www.securityfocus.com/archive/77/446507

58. [SJ-JOB] Information Assurance Analyst, Richmond
http://www.securityfocus.com/archive/77/446502

59. [SJ-JOB] VP / Dir / Mgr engineering, Ann Arbor
http://www.securityfocus.com/archive/77/446503

60. [SJ-JOB] Sales Representative, Austin
http://www.securityfocus.com/archive/77/446504

61. [SJ-JOB] Security System Administrator, Port St Lucie
http://www.securityfocus.com/archive/77/446508

62. [SJ-JOB] Sr. Security Analyst, Atlanta
http://www.securityfocus.com/archive/77/446511

63. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/446498

64. [SJ-JOB] Technical Support Engineer, Brussels
http://www.securityfocus.com/archive/77/446496

65. [SJ-JOB] Security Engineer, San Jose
http://www.securityfocus.com/archive/77/446493

66. [SJ-JOB] Manager, Information Security, Richmond
http://www.securityfocus.com/archive/77/446497

67. [SJ-JOB] Instructor, North Canton
http://www.securityfocus.com/archive/77/446490

68. [SJ-JOB] Sales Representative, Montvale
http://www.securityfocus.com/archive/77/446495

69. [SJ-JOB] Training / Awareness Specialist, Cupertino
http://www.securityfocus.com/archive/77/446512

70. [SJ-JOB] Security Architect, Atlanta
http://www.securityfocus.com/archive/77/446485

71. [SJ-JOB] Channel / Business Development, Frederick
http://www.securityfocus.com/archive/77/446486

72. [SJ-JOB] Security Engineer, Raleigh
http://www.securityfocus.com/archive/77/446487

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. bypassing randomized stack using linux-gate.so.1
http://www.securityfocus.com/archive/82/446660

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #309
http://www.securityfocus.com/archive/88/446468

2. Microsoft Security Clamp
http://www.securityfocus.com/archive/88/446467

3. Storing Images in SQL Server (2005)
http://www.securityfocus.com/archive/88/446413

VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. root group in solaris
http://www.securityfocus.com/archive/92/446233

IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper 
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection! 

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=70160000000CbYU