SecurityFocus Newsletter #370
Peter Laborge <[email protected]> Tue, 03 Oct 2006 16:52:43 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #370
----------------------------------------
This Issue is Sponsored by: Watchfire
Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web
application security assessments should be considered a crucial phase in
the development of any web application. What methodology should be
followed? What tools can accelerate the assessment process? See for
yourself. Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008YSf
------------------------------------------------------------------
I. FRONT AND CENTER
1. Recent Security Enhancements in NetBSD
2. Beginner's guide to wireless auditing
II. BUGTRAQ SUMMARY
1. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
2. Travelsized CMS Frontpage.PHP Remote File Include Vulnerability
3. phpMyWebmin Multiple Remote File Include Vulnerabilities
4. Yblog Multiple Cross-Site Scripting Vulnerabilities
5. PADL Software MigtrationTools Insecure Temporary File
Creation Vulnerability
6. CScope Cscope.Lists Multiple Buffer Overflow Vulnerabilities
7. PowerPortal Register User Cross-Site Scripting Vulnerability
8. OlateDownload Multiple Input Validation Vulnerabilities
9. PhpBB XS Multiple Remote File Include Vulnerabilities
10. Sun Secure Global Desktop Multiple Unspecified Cross-Site
Scripting Vulnerabilities
11. OpenLDAP SLAPD Access Control Circumvention Vulnerability
12. Newswriter Editfunc.inc..PHP Remote File Include Vulnerability
13. ConPresso CMS Multiple Input Validation Vulnerabilities
14. Mercury SiteScope Unspecified HTML Injection Vulnerability
15. Apple Safari KHTMLParser::popOneBlock Buffer Overflow
Vulnerability
16. Geotarget Script.PHP Remote File Include Vulnerability
17. Les Visiteurs Multiple Remote File Include Vulnerabilities
18. UBB.threads Multiple Input Validation Vulnerabilities
19. HP-UX Ignite-UX Remote Unauthorized Access and Privilege
Escalation Vulnerabilities
20. PHP Krazy Image Host Script Display.PHP SQL Injection
Vulnerability
21. Zen Cart Multiple Cross-Site Scripting Vulnerabilities
22. PHProjekt Include Path Multiple Remote File Include
Vulnerabilities
23. PHPSecurePages cfpProgDir File Include Vulnerability
24. Linux Kernel PPC970 Systems Local Denial of Service
Vulnerability
25. BSQ Sitestats Joomla Component Multiple Input Validation
Vulnerabilities
26. Linux Kernel NFS and EXT3 Combination Remote Denial of
Service Vulnerability
27. PHPMyProfiler Functions.PHP Remote File Include Vulnerability
28. Klinza Professional CMS Show_Hlp.PHP Remote File Include
Vulnerability
29. Drupal IMCE Module Arbitrary File Deletion Vulnerability
30. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
31. Novell GroupWise Messenger Server Nmma.EXE Denial of Service
Vulnerability
32. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of
Service Vulnerability
33. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
34. Linux Kernel USB Driver Data Queue Local Denial of Service
Vulnerability
35. PostNuke Admin.PHP SQL Injection Vulnerability
36. Jetty Directory Traversal Vulnerability
37. Net2FTP Index.PHP Cross-Site Scripting Vulnerability
38. HAMweather Template.PHP Script Code Injection Vulnerability
39. JAF CMS Forum.PHP Remote File Include Vulnerability
40. Motorola SB4200 Remote Denial of Service Vulnerability
41. WebspotBlogging Multiple Remote File Include Vulnerabilities
42. IBM Client Security Password Manager Design Error Vulnerability
43. RETIRED: Mozilla Firefox Multiple Unspecified Javascript
Vulnerabilities
44. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow
Vulnerability
45. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
46. Adobe Flash Player Multiple Remote Code Execution
Vulnerabilities
47. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
48. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
49. Apple Mac OS X Pre 10.4.8 Multiple Security Vulnerabilities
50. OpenSSL ASN.1 Structures Denial of Service Vulnerability
51. OpenSSL SSLv2 Null Pointer Dereference Client Denial of
Service Vulnerability
52. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
53. WheatBlog Multiple HTML Injection Vulnerabilities
54. OpenBiblio Multiple Input Validation Vulnerabilities
55. AllMyGuests SignIn.PHP Remote File Include Vulnerability
56. Pebble Search Functionality HTML Injection Vulnerability
57. Multiple Vendor gethostbyname() Buffer Overflow Vulnerability
58. BBaCE Functions.PHP Remote File Include Vulnerability
59. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow
Vulnerability
60. IBM Informix Dynamic Server Installer Insecure Temporary
File Creation Vulnerability
61. Sunbelt Kerio Personal Firewall Multiple Local Denial of
Service Vulnerabilities
62. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
63. LibTIFF EstimateStripByteCounts() Denial of Service
Vulnerability
64. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
65. LibTIFF Library Anonymous Field Merging Denial of Service
Vulnerability
66. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
67. Digishop Cart.PHP Cross-Site Scripting Vulnerability
68. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow
Vulnerability
69. McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server
Remote Buffer Overflow Vulnerability
70. OpenSSL Public Key Processing Denial of Service Vulnerability
71. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
72. ProRat Remote Login Authentication Bypass Vulnerability
73. DeluxeBB Sig.PHP Remote File Include Vulnerability
74. Loudblog Message Comment HTML Injection Vulnerability
75. PHP Web Scripts Easy Banner Functions.PHP Remote File
Include Vulnerability
76. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote
Vulnerabilities
77. Mozilla Firefox JavaScript Handler Race Condition Memory
Corruption Vulnerability
78. Mozilla Firefox Javascript Navigator Object Remote Code
Execution Vulnerability
79. Mozilla Foundation Products XPCOM Memory Corruption
Vulnerability
80. Forum82 Multiple Remote File Include Vulnerabilities
81. Mozilla Multiple Products Remote Vulnerabilities
82. Microsoft Indexing Service Query Validation Cross-Site
Scripting Vulnerability
83. BisonFTP Remote Denial Of Service Vulnerability
84. GDB DWARF Multiple Buffer Overflow Vulnerabilities
85. CPanel SUID Wrapper Remote Privilege Escalation Vulnerability
86. PHP Download Download.PHP Directory Traversal Vulnerability
87. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
88. OpenSSH SCP Shell Command Execution Vulnerability
89. MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
90. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
91. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
92. Apache HTTP Server Arbitrary HTTP Request Headers Security
Weakness
93. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
94. VAMP Webmail Yesno.PHTML Remote File Include Vulnerability
95. BasiliX Multiple Remote File Include Vulnerabilities
96. Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format
String Vulnerability
97. FFmpeg Image File Multiple Buffer Overflow Vulnerabilities
98. SquirrelMail Compose.PHP Multiple Information Disclosure and
Data Modification Vulnerabilities
99. Mozilla Firefox Unspecified Javascript Remote Code Execution
Vulnerability
100. SiteDepth CMS Constants.PHP Remote File Include Vulnerability
III. SECURITYFOCUS NEWS
1. Mozilla flaws more joke than jeopardy
2. Tag-team attack exploits IE flaw
3. HP chief apologizes, denies he knew of hacking
4. Web flaws race ahead in 2006
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Information Assurance Engineer, Clarksburg
2. [SJ-JOB] Sr. Security Engineer, Hyderabad
3. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
4. [SJ-JOB] Management, Charlotte
5. [SJ-JOB] Security Engineer, Schaumburg
6. [SJ-JOB] Software Engineer, San Francisco
7. [SJ-JOB] Developer, Columbia
8. [SJ-JOB] Security Engineer, Burlington
9. [SJ-JOB] Manager, Information Security, Columbia
10. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
11. [SJ-JOB] Security Consultant, Newport Beach
12. [SJ-JOB] Developer, Broomfield
13. [SJ-JOB] Information Assurance Analyst, Broomfield
14. [SJ-JOB] Security Engineer, Broomfield
15. [SJ-JOB] Jr. Security Analyst, LOS ANGELES
16. [SJ-JOB] Security Consultant, berkshire
17. [SJ-JOB] Security Architect, Broomfield
18. [SJ-JOB] Security Engineer, berkshire
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
1. Allow regular user to unlock screensaver locked computer
2. a question of usb token
3. How can this happen with Windows Vista?
4. Security Policy Anomaly
5. SecurityFocus Microsoft Newsletter #310
6. Microsoft Security Clamp
VIII. SUN FOCUS LIST SUMMARY
1. LDAP in Unix
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Recent Security Enhancements in NetBSD
By Elad Efrat
NetBSD is renowned for its focus on portability, but great care is also
given to security. This paper presents the NetBSD philosophy on
security, major design decisions, and its current security features.
Following the discussion, current and future research is presented to
provide a good look at NetBSD's direction.
http://www.securityfocus.com/infocus/1878
2. Beginner's guide to wireless auditing
By David Maynor
This article is designed as a beginner's guide to fuzzing wireless
device drivers, starting with how to build an auditing environment, how
to construct fuzzing tools and finally, how to interpret the results.
This auditing environment can be used for WiFi as well as Bluetooth and
infrared devices.
http://www.securityfocus.com/infocus/1877
II. BUGTRAQ SUMMARY
--------------------
1. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it
fails to properly bounds-check user-supplied input before copying it to
an insufficiently sized memory buffer.
This issue may allow remote attackers to execute arbitrary machine code
in the context of the affected application, but this has not been confirmed.
GnuPG version 1.4.4 is vulnerable to this issue; previous versions may
also be affected.
2. Travelsized CMS Frontpage.PHP Remote File Include Vulnerability
BugTraq ID: 20321
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20321
Summary:
Travelsized CMS is prone to a remote file-include vulnerability because
the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
This issue affects version 0.4 and earlier.
3. phpMyWebmin Multiple Remote File Include Vulnerabilities
BugTraq ID: 20281
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20281
Summary:
phpMyWebmin is affected by multiple remote file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code
on an affected computer with the privileges of the webserver process.
This may potentially facilitate unauthorized access.
phpMyWebmin 1.0 and prior versions are vulnerable.
4. Yblog Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20280
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20280
Summary:
Yblog is prone to multiple cross-site scripting vulnerabilities because
it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage these issues to have arbitrary script code
execute in the browser of an unsuspecting user in the context of the
affected site. This may allow the attacker to steal cookie-based
authentication credentials and to launch other attacks.
5. PADL Software MigtrationTools Insecure Temporary File Creation
Vulnerability
BugTraq ID: 15431
Remote: No
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/15431
Summary:
PADL Software MigrationTools creates temporary files in an insecure
manner. An attacker with local access could potentially exploit this
issue to obtain sensitive information in the context of the affected
computer.
Exploitation would most likely result in loss of confidentiality or
data. A denial of service could occur if critical files are overwritten
in the attack. Other attacks may be possible as well.
MigrationTools version 46 is reported affected by this issue; other
versions may also be affected.
6. CScope Cscope.Lists Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19686
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19686
Summary:
Cscope is prone to multiple buffer-overflow vulnerabilities because it
fails to properly validate the size of attacker-supplied data before
copying it into a finite-sized buffer.
These issues allow remote attackers to execute arbitrary machine code in
the context of the user running the application. Failed exploit attempts
will likely crash the application, denying service to legitimate users.
Cscope 15.x is affected by these vulnerabilities; previous versions may
be affected as well.
7. PowerPortal Register User Cross-Site Scripting Vulnerability
BugTraq ID: 20279
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20279
Summary:
PowerPortal is prone to a cross-site scripting vulnerability because it
fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code
execute in the browser of an unsuspecting user in the context of the
affected site. This may help the attacker steal cookie-based
authentication credentials and launch other attacks.
PowerPortal 1.1 is vulnerable; other versions may also be affected.
8. OlateDownload Multiple Input Validation Vulnerabilities
BugTraq ID: 20278
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20278
Summary:
OlateDownload is prone to multiple input-validation vulnerabilities,
including HTML-injection and SQL-injection issues, because the
application fails to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to
inject hostile HTML and script code into vulnerable sections of the
application, steal cookie-based authentication credentials from
legitimate users of the site, or even exploit vulnerabilities in the
underlying database implementation. Other attacks are also possible.
OlateDownload version 3.4.0 is vulnerable.
9. PhpBB XS Multiple Remote File Include Vulnerabilities
BugTraq ID: 20277
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20277
Summary:
phpBB XS is prone to multiple remote file-include vulnerabilities
because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
phpBB XS 0.58 and prior versions are affected by these issues.
10. Sun Secure Global Desktop Multiple Unspecified Cross-Site Scripting
Vulnerabilities
BugTraq ID: 20276
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20276
Summary:
Sun Secure Global Desktop is prone to multiple unspecified cross-site
scripting vulnerabilities because it fails to sufficiently sanitize
user-supplied input data.
An attacker could exploit this vulnerability to have arbitrary script
code execute in the context of the affected webserver. This may allow an
attacker to steal cookie-based authentication credentials and to launch
other attacks.
11. OpenLDAP SLAPD Access Control Circumvention Vulnerability
BugTraq ID: 19832
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19832
Summary:
OpenLDAP slapd is prone to a vulnerability that allows attackers to
circumvent access controls.
An attacker may be able to modify any domain name regardless of the owner.
Versions prior to 2.3.25 are vulnerable.
12. Newswriter Editfunc.inc..PHP Remote File Include Vulnerability
BugTraq ID: 20237
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20237
Summary:
Newswriter is prone to a remote file-include vulnerability because it
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
Newswriter 1.42 and prior versions are vulnerable; other versions may
also be affected.
13. ConPresso CMS Multiple Input Validation Vulnerabilities
BugTraq ID: 20273
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20273
Summary:
ConPresso CMS is prone to multiple input-validation vulnerabilities,
including cross-site scripting and SQL-injection issues, because the
application fails to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to
compromise the application, access or modify data, steal cookie-based
authentication credentials, or even exploit vulnerabilities in the
underlying database implementation. Other attacks are also possible.
14. Mercury SiteScope Unspecified HTML Injection Vulnerability
BugTraq ID: 20275
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20275
Summary:
Mercury SiteScope is prone to an HTML-injection vulnerability because it
fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script
code in the context of the affected site, to steal cookie-based
authentication credentials, or to control how the site is rendered to
the user; other attacks are also possible.
Note that authenticated access to the affected application is required
to exploit this vulnerability.
Version 8.2 is vulnerable; other versions may also be affected.
15. Apple Safari KHTMLParser::popOneBlock Buffer Overflow Vulnerability
BugTraq ID: 19250
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19250
Summary:
Safari is prone to a buffer-overflow vulnerability. This issue is
triggered when an attacker entices a victim user to visit a malicious
website or to open a malicious HTML file.
A remote attacker may exploit this issue to execute arbitrary machine
code in the context of the affected application. Failed exploit attempts
result in crashing the application, effectively denying service to
legitimate users.
16. Geotarget Script.PHP Remote File Include Vulnerability
BugTraq ID: 20272
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20272
Summary:
Geotarget is prone to a remote file-include vulnerability because it
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
17. Les Visiteurs Multiple Remote File Include Vulnerabilities
BugTraq ID: 20259
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20259
Summary:
Les Visiteurs is prone to multiple remote file-include vulnerabilities
because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
Les Visiteurs 2.0 and earlier versions are vulnerable; other versions
may also be affected.
18. UBB.threads Multiple Input Validation Vulnerabilities
BugTraq ID: 20266
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20266
Summary:
UBB.threads is prone to multiple input-validation vulnerabilities
because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include and overwrite arbitrary
files. These files could contain malicious PHP code and could run it in
the context of the webserver process. This may allow the attacker to
compromise the application and the underlying system; other attacks are
also possible.
Version 6 (6.5.1.1) is vulnerable; other versions may also be affected.
19. HP-UX Ignite-UX Remote Unauthorized Access and Privilege Escalation
Vulnerabilities
BugTraq ID: 20269
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20269
Summary:
HP-UX is prone to a remote unauthorized access and privilege-escalation
vulnerabilities.
Exploiting this issue allows remote attackers to access restricted
information or to gain administrative privileges on affected computers.
This facilitates the complete compromise of affected computers.
Further information is currently unavailable. This BID will be updated
as more information is disclosed.
20. PHP Krazy Image Host Script Display.PHP SQL Injection Vulnerability
BugTraq ID: 20270
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20270
Summary:
PHP Krazy Image Host Script is prone to an SQL-injection vulnerability
because it fails to sufficiently sanitize user-supplied data before
using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the
application, access or modify data, or exploit latent vulnerabilities in
the underlying database implementation.
21. Zen Cart Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20242
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20242
Summary:
Zen Cart is prone to multiple cross-site scripting vulnerabilities
because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage these issues to have arbitrary script code
execute in the browser of an unsuspecting user in the context of the
affected site. This may allow the attacker to steal cookie-based
authentication credentials and to launch other attacks.
Zen Cart 1.3.5 is vulnerable to these issues.
22. PHProjekt Include Path Multiple Remote File Include Vulnerabilities
BugTraq ID: 20268
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20268
Summary:
Multiple remote file-include vulnerabilities affect PHProjekt because
the application fails to properly sanitize user-supplied input before
using it in a PHP 'include()' function call.
An attacker may leverage these issues to execute arbitrary server-side
script code on an affected computer with the privileges of the webserver
process.
Version 5.1.1 of PHProjekt is vulnerable to these issues; previous
versions may be affected as well.
23. PHPSecurePages cfpProgDir File Include Vulnerability
BugTraq ID: 14201
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/14201
Summary:
phpSecurePages is prone to a remote file-include vulnerability because
the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side
script code on an affected computer with the privileges of the webserver
process. This may facilitate unauthorized access.
This issue affects PHPSecurePages 0.28beta; earlier versions may also be
vulnerable.
24. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.
An attacker can exploit this issue to crash the kernel, denying further
service to legitimate users.
25. BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities
BugTraq ID: 20267
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20267
Summary:
BSQ Sitestats is prone to multiple input-validation vulnerabilities
because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to steal cookie-based
authentication credentials, compromise the application, access or modify
data, or exploit latent vulnerabilities in the underlying database
implementation; other attacks are possible.
Version 1.8.0 is vulnerable; other versions may also be affected.
26. Linux Kernel NFS and EXT3 Combination Remote Denial of Service
Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service
vulnerability because the EXT3 filesystem code fails to properly handle
unexpected conditions.
Remote attackers may trigger this issue by sending crafted UDP datagrams
to affected computers that are configured as NFS servers, causing
filesystem errors. Depending on the mount-time options of affected
filesystems, this may result in remounting filesystems as read-only or
cause a kernel panic.
Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to
this issue; other versions in the 2.6 series are also likely affected.
27. PHPMyProfiler Functions.PHP Remote File Include Vulnerability
BugTraq ID: 20324
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20324
Summary:
phpMyProfiler is prone to a remote file-include vulnerability because
the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
phpMyProfiler version 0.9.6 is vulnerable; other versions may also be
affected.
28. Klinza Professional CMS Show_Hlp.PHP Remote File Include Vulnerability
BugTraq ID: 20323
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20323
Summary:
Klinza Professional CMS is prone to a remote file-include vulnerability
because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
Klinza 5.0.1 and prior versions are vulnerable; other versions may also
be affected.
29. Drupal IMCE Module Arbitrary File Deletion Vulnerability
BugTraq ID: 20312
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20312
Summary:
The Drupal IMCE module is prone to an arbitrary file-deletion
vulnerability because the application fails to sufficiently sanitize
user-supplied input.
Successfully exploiting this issue allows attackers to delete arbitrary
files with the privileges of the targeted webserver process.
30. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20253
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20253
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage this issue to have arbitrary script code
execute in the browser of an unsuspecting user in the context of the
affected site. This may help the attacker steal cookie-based
authentication credentials and launch other attacks.
31. Novell GroupWise Messenger Server Nmma.EXE Denial of Service
Vulnerability
BugTraq ID: 20316
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20316
Summary:
Novell GroupWise Messenger server is prone to a denial-of-service
vulnerability that occurs when the application fails to handle a client
request with an unexpected parameter.
An attacker may exploit this issue to crash the vulnerable application,
denying further service to legitimate users.
32. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service
Vulnerability
BugTraq ID: 18755
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18755
Summary:
The Linux kernel 'netfilter' module is prone to a denial-of-service
vulnerability.
Successful exploits of this vulnerability will cause the kernel to
crash, effectively denying service to legitimate users.
33. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability
because it fails to properly bounds-check user-supplied input before
using it in a memory copy operation.
This issue allows local attackers to overwrite kernel memory with
arbitrary data, potentially allowing them to execute malicious machine
code in the context of affected kernels. This vulnerability facilitates
the complete compromise of affected computers.
Linux kernel version 2.6.17.3 and prior are affected by this issue.
34. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.
This issue is due to a design error in the USB FTDI SIO driver.
This vulnerability allows local users to consume all available memory
resources, denying further service to legitimate users.
This issue affects Linux kernel versions prior to 2.6.16.27.
35. PostNuke Admin.PHP SQL Injection Vulnerability
BugTraq ID: 20317
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20317
Summary:
PostNuke is prone to an SQL-injection vulnerability because it fails to
sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the
application, access or modify data, or exploit latent vulnerabilities in
the underlying database implementation.
Version 0.762 is vulnerable; other versions may also be affected.
36. Jetty Directory Traversal Vulnerability
BugTraq ID: 11330
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/11330
Summary:
Jetty is reported prone to a directory-traversal vulnerability because
the application fails to properly sanitize HTTP-request URIs.
Exploiting this vulnerability allows remote attackers to retrieve the
contents of arbitrary, potentially sensitive files located on the
serving computer with the credentials of the affected process.
It is unclear at this time exactly which versions of Jetty are affected
by this vulnerability. This BID will be updated as further information
is disclosed.
This vulnerability may be related to BID 4360.
37. Net2FTP Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20313
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20313
Summary:
The net2ftp program is prone to a cross-site scripting vulnerability
because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to have arbitrary script code execute
in the browser of an unsuspecting user in the context of the affected
site. This may help the attacker steal cookie-based authentication
credentials and launch other attacks.
This issue affects version 0.93; other versions may also be vulnerable.
38. HAMweather Template.PHP Script Code Injection Vulnerability
BugTraq ID: 20311
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20311
Summary:
HAMweather is prone to a script-code-injection vulnerability because it
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
HAMweather 3.9.8.4 and prior versions are vulnerable; other versions may
also be affected.
39. JAF CMS Forum.PHP Remote File Include Vulnerability
BugTraq ID: 20310
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20310
Summary:
JAF CMS is prone to a remote file-include vulnerability because the
application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
This issue affects version 4.0 and earlier.
40. Motorola SB4200 Remote Denial of Service Vulnerability
BugTraq ID: 20309
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20309
Summary:
Motorola SB4200 is prone to a remote denial-of-service vulnerability.
This may permit an attacker to crash affected devices, denying further
network services to legitimate users.
41. WebspotBlogging Multiple Remote File Include Vulnerabilities
BugTraq ID: 18260
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18260
Summary:
WebspotBlogging is prone to multiple remote file-include vulnerabilities
because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
42. IBM Client Security Password Manager Design Error Vulnerability
BugTraq ID: 20308
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20308
Summary:
IBM Client Security Password Manager is prone to a design error that
degrades the integrity of client-side web security.
The vulnerability stems from the fact that the Password Manager relies
on 'Window Title' information as part of the authentication routine it
performs on behalf of the user. A malicious website can establish a web
page that spoofs the same window title that the application expects to
map. This will allow authentication to proceed with the hostile site and
in turn establish a false sense of security on the part of visitors who
use the affected software.
Exploiting this issue can help attackers steal user credentials. Other
attacks are also possible.
43. RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
BugTraq ID: 20294
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20294
Summary:
Mozilla Firefox is prone to multiple unspecified JavaScript
vulnerabilities because the application fails to properly sanitize
user-supplied input before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or
execute arbitrary machine code in the context of the affected application.
Reportedly, about 30 undisclosed flaws exist.
Update (October 3, 2006): This BID is being retired because reports
indicate that these issues are a hoax. The researchers responsible for
disclosing these vulnerabilities have claimed that their original
reports were incorrect. A remote denial-of-service vulnerability may
possibly affect the browser, but this has not been confirmed. A new BID
will be created if subsequent reports confirm the possibility of the
potential denial-of-service issue. Please see the references for more
information.
44. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow
Vulnerability
BugTraq ID: 19030
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19030
Summary:
Microsoft WebViewFolderIcon ActiveX control is prone to a
buffer-overflow vulnerability.
This issue is triggered when an attacker convinces a victim user to
visit a malicious website.
Remote attackers may exploit this issue to execute arbitrary machine
code in the context of the affected application, facilitating the remote
compromise of affected computers. Failed exploit attempts likely result
in browser crashes.
45. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
BugTraq ID: 17446
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/17446
Summary:
Cyrus SASL is affected by a remote denial-of-service vulnerability. This
issue occurs before successful authentication, allowing anonymous remote
attackers to trigger it.
This vulnerability allows remote attackers to crash services using the
affected SASL library, denying service to legitimate users.
This issue reportedly affects version 2.1.18 of Cyrus SASL; other
versions may also be affected.
46. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
BugTraq ID: 19980
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19980
Summary:
Adobe Flash Player is prone to multiple remote code-execution
vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could exploit this issue by creating a media file containing
large, dynamically generated string data and submitting it to be
processed by the media player.
These issues allow remote attackers to execute arbitrary machine code in
the context of the user running the application. Other attacks are also
possible.
Adobe Flash Player 8.0.24.0 and prior, Adobe Flash Professional 8, Flash
Basic, Adobe Flash MX, and 2004Adobe Flex 1.5 are affected.
47. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
BugTraq ID: 18894
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18894
Summary:
The Macromedia Flash plug-in is prone to multiple remote vulnerabilities.
An attacker can exploit these vulnerabilities to execute arbitrary code
or to crash the application hosting the Flash player (typically a web
browser). Attackers exploit these issues through maliciously malformed
SWF files that have been placed on a website or emailed to unsuspecting
users.
Version 8.0.24.0 of Flash is vulnerable to these issues; other versions
may also be affected.
48. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
BugTraq ID: 20249
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20249
Summary:
OpenSSL is prone to a buffer-overflow vulnerability because the library
fails to properly bounds-check user-supplied input before copying it to
an insufficiently sized memory buffer.
Successfully exploiting this issue may result in the execution of
arbitrary machine code in the context of applications that use the
affected library. Failed exploit attempts may crash applications,
denying service to legitimate users.
49. Apple Mac OS X Pre 10.4.8 Multiple Security Vulnerabilities
BugTraq ID: 20271
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20271
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities.
These issue affect Mac OS X and various applications including
CFNetwork, Safari, Kernel, ImageIO, LoginWindow, System Preferences,
QuickDraw Manager, and Workgroup Manager. An attacker can exploit these
issues to execute arbitrary code, gain elevated privileges, cause
denial-of-service conditions, and gain unauthorized access.
Apple Mac OS X versions prior to 10.4.8 are vulnerable to these issues.
50. OpenSSL ASN.1 Structures Denial of Service Vulnerability
BugTraq ID: 20248
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20248
Summary:
OpenSSL is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to cause applications that use the
vulnerable library to consume excessive CPU and memory resources and
crash, denying further service to legitimate users.
51. OpenSSL SSLv2 Null Pointer Dereference Client Denial of Service
Vulnerability
BugTraq ID: 20246
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20246
Summary:
OpenSSL is prone to a denial-of-service vulnerability.
A malicious server could cause a vulnerable client application to crash,
effectively denying service.
52. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge
an RSA signature. The attacker may be able to forge a PKCS #1 v1.5
signature when an RSA key with exponent 3 is used.
An attacker may exploit this issue to sign digital certificates or RSA
keys and take advantage of trust relationships that depend on these
credentials, possibly posing as a trusted party and signing a
certificate or key.
All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are
affected by this vulnerability. Updates are available.
53. WheatBlog Multiple HTML Injection Vulnerabilities
BugTraq ID: 20306
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20306
Summary:
WheatBlog is prone to multiple HTML-injection vulnerabilities because
the application fails to properly sanitize user-supplied input before
using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of
the affected website, potentially allowing an attacker to steal
cookie-based authentication credentials or to control how the site is
rendered to the user; other attacks are also possible.
54. OpenBiblio Multiple Input Validation Vulnerabilities
BugTraq ID: 20301
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20301
Summary:
OpenBiblio is prone to multiple input-validation vulnerabilities because
the application fails to sufficiently sanitize user-supplied input.
These include multiple local file-include vulnerabilties and an
SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the
application, access sensitive information, modify data, or exploit
latent vulnerabilities in the underlying database implementation.
55. AllMyGuests SignIn.PHP Remote File Include Vulnerability
BugTraq ID: 20303
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20303
Summary:
AllMyGuests is prone to a remote file-include vulnerability because it
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
AllMyGuests 0.4.1 is vulnerable; other versions may also be affected.
56. Pebble Search Functionality HTML Injection Vulnerability
BugTraq ID: 20298
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20298
Summary:
Pebble is prone to an HTML-injection vulnerability because the
application fails to properly sanitize user-supplied input before using
it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of
the affected website, potentially allowing an attacker to steal
cookie-based authentication credentials or to control how the site is
rendered to the user; other attacks are also possible.
57. Multiple Vendor gethostbyname() Buffer Overflow Vulnerability
BugTraq ID: 6853
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/6853
Summary:
A vulnerability has been discovered in multiple vendor implementations
of the 'gethostbyname()' library function, which is used to resolve
network addresses.
The 'gethostbyname()' function fails to implement sufficient bounds
checking on data copied into local memory buffers.
Under some circumstances, attackers may exploit this issue to overwrite
sensitive locations in memory and may leverage the issue to execute
arbitrary commands with the privileges of the vulnerable application.
This issue may be local or remote, depending on the particular
applications that use the function on vulnerable systems.
Several applications may implement the 'gethostbyname()' function, thus
exposing them to this vulnerability. Applications known to implement
'gethostbyname()' include various implementations of 'ping', 'ftp', and
'tftp'. Other applications may also be vulnerable.
58. BBaCE Functions.PHP Remote File Include Vulnerability
BugTraq ID: 20302
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20302
Summary:
BBaCE is prone to a remote file-include vulnerability because the
application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
This issue affects version 3; other versions may also be vulnerable.
59. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19282
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19282
Summary:
The Next RLE Decoder for libTIFF is prone to a remote heap
buffer-overflow vulnerability.
This issue occurs because the application fails to check boundary
conditions on certain RLE decoding operations.
This issue may allow attackers to execute arbitrary machine code within
the context of the vulnerable application or to cause a denial of service.
60. IBM Informix Dynamic Server Installer Insecure Temporary File
Creation Vulnerability
BugTraq ID: 20300
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20300
Summary:
The installation process for IBM Informix Dynamic Server creates
temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to
perform symlink attacks, overwriting arbitrary files in the context of
the affected application.
Successfully exploiting a symlink attack may allow an attacker to
overwrite or corrupt sensitive files. This may result in a denial of
service; other attacks may also be possible.
IBM Informix Dynamic Server version 10.0 is vulnerable; other versions
may also be affected.
61. Sunbelt Kerio Personal Firewall Multiple Local Denial of Service
Vulnerabilities
BugTraq ID: 20299
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20299
Summary:
Sunbelt Kerio Personal Firewall is prone to multiple local
denial-of-service vulnerabilities because the application fails to
properly sanitize user-supplied input.
These vulnerabilities allow local attackers to crash affected systems,
facilitating a denial-of-service condition on the local computer. Code
execution may also be possible, but this has not been confirmed.
62. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
BugTraq ID: 19283
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19283
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library
fails to do proper boundary checks before copying user-supplied data
into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in
the context of appications using the affected library. Failed exploit
attempts will likely crash the application, denying service to
legitimate users.
63. LibTIFF EstimateStripByteCounts() Denial of Service Vulnerability
BugTraq ID: 19284
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19284
Summary:
LibTIFF is affected by a denial-of-service vulnerability.
An attacker can exploit this vulnerability to cause a denial of service
in applications using the affected library.
64. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
BugTraq ID: 19286
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19286
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.
An attacker can exploit these vulnerabilities to cause a denial of
service in applications using the affected library.
65. LibTIFF Library Anonymous Field Merging Denial of Service Vulnerability
BugTraq ID: 19287
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19287
Summary:
The libTIFF library is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by submitting malformed image files.
When the libTIFF library routines process a malicious TIFF file, this
could result in abnormal behavior, cause the application to become
unresponsive, or possibly allow malicious code to execute.
66. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
BugTraq ID: 19288
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19288
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library
fails to do proper boundary checks before copying user-supplied data
into a finite-sized buffer.
This issue allows remote attackers to execute arbitrary machine code in
the context of applications using the affected library. Failed exploit
attempts will likely crash the application, denying service to
legitimate users.
67. Digishop Cart.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20297
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20297
Summary:
digiSHOP is prone to a cross-site scripting vulnerability because it
fails to properly sanitize user-supplied input.
An attacker can exploit this issue to have arbitrary script code execute
in the browser of an unsuspecting user in the context of the affected
site. This may help the attacker steal cookie-based authentication
credentials and launch other attacks.
This issue affects version 4.0.0; other versions may also be vulnerable.
68. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19290
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19290
Summary:
The PixarLog Decoder for libTIFF is prone to a remote heap
buffer-overflow vulnerability.
This issue may allow attackers to execute arbitrary machine code within
the context of the vulnerable application or to cause a denial-of-service.
69. McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote
Buffer Overflow Vulnerability
BugTraq ID: 20288
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20288
Summary:
The HTTP server component of McAfee ePolicy Orchestrator and
ProtectionPilot is prone to a remote stack-based buffer-overflow
vulnerability that can lead to complete system compromise.
This issue arises because the application fails to perform boundary
checks before copying user-supplied data into sensitive process buffers.
A successful attack may result in arbitrary code execution with SYSTEM
privileges, leading to a full compromise.
McAfee ePolicy Orchestrator 3.5.0 patch 5 and prior versions as well as
ProtectionPilot 1.1.1 patch 2 and prior versions are vulnerable to this
issue.
70. OpenSSL Public Key Processing Denial of Service Vulnerability
BugTraq ID: 20247
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20247
Summary:
OpenSSL is prone to a denial-of-service vulnerability. This issue is due
to a lack of validation of the lengths of public keys being used.
An attacker can exploit this issue to crash an affected server using
OpenSSL.
71. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 12792
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/12792
Summary:
OpenSLP is prone to multiple unspecified buffer-overflow vulnerabilities
that may be triggered by malformed SLP (Service Location Protocol) packets.
If successfully exploited, these issues could allow remote code
execution in the context of the software.
72. ProRat Remote Login Authentication Bypass Vulnerability
BugTraq ID: 20293
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20293
Summary:
ProRat is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain remote access to computers
running this application. A successful exploit will lead to the complete
compromise of affected computers.
73. DeluxeBB Sig.PHP Remote File Include Vulnerability
BugTraq ID: 20292
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20292
Summary:
DeluxeBB is prone to a remote file-include vulnerability because the
application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files
containing malicious PHP code and execute it in the context of the
webserver process. This may allow the attacker to compromise the
application and the underlying system; other attacks are also possible.
This issue affects version 1.09; other versions may also be vulnerable.
74. Loudblog Message Comment HTML Injection Vulnerability
BugTraq ID: 20296
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20296
Summary:
Loudblog is prone to an unspecified HTML-injection vulnerability because
the application fails to properly sanitize user-supplied input before
using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of
the affected website, potentially allowing an attacker to steal
cookie-based authentication credentials or to control how the site is
rendered to the user; other attacks are also possible.
75. PHP Web Scripts Easy Banner Functions.PHP Remote File Include
Vulnerability
BugTraq ID: 20295
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20295
Summary:
Easy Banner is prone to a remote file-include vulnerability because it
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the
application and the underlying system; other attacks are also possible.
Easy Banner Free is vulnerable; other versions may also be affected.
76. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
BugTraq ID: 20042
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20042
Summary:
The Mozilla Foundation has released six security advisories specifying
vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary code
- perform cross-site scripting attacks
- supply malicious data through updates
- inject arbitrary content
- execute arbitrary JavaScript
- crash affected applications and potentially execute arbitrary code.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as more
information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.7
- Mozilla Thunderbird version 1.5.0.7
- Mozilla SeaMonkey version 1.0.5
77. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption
Vulnerability
BugTraq ID: 19488
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19488
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability.
This issue is due to a race condition that may result in double-free or
other memory-corruption issues.
Attackers may likely exploit this issue to execute arbitrary machine
code in the context of the vulnerable application, but this has not been
confirmed. Failed exploit attempts will likely crash the application.
Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other
Mozilla products are also likely affected.
78. Mozilla Firefox Javascript Navigator Object Remote Code Execution
Vulnerability
BugTraq ID: 19192
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19192
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability
because the application fails to properly sanitize user-supplied input
before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or
execute arbitrary machine code in the context of the affected application.
This issue was previously discussed in BID 19181 (Mozilla Multiple
Products Remote Vulnerabilities).
It has been assigned a separate BID because new information has become
available.
79. Mozilla Foundation Products XPCOM Memory Corruption Vulnerability
BugTraq ID: 19197
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19197
Summary:
Various Mozilla Foundation products are prone to a memory-corruption
vulnerability.
This issue occurs because the applications fail to handle simultaneous
XPCOM events that would cause the deletion of the timer object.
An attacker can exploit this issue to execute arbitrary code.
This issue was previously discussed in BID 19181 (Mozilla Multiple
Products Remote Vulnerabilities). It has been assigned a separate BID
because new information has become available.
80. Forum82 Multiple Remote File Include Vulnerabilities
BugTraq ID: 20291
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20291
Summary:
Forum82 is prone to multiple remote file-include vulnerabilities because
it fails to sufficiently sanitize user-supplied data.
This may allow an attacker to compromise the application and the
underlying system; other attacks are also possible.
Forum82 2.5.2 and prior versions are vulnerable; other versions may also
be affected.
81. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories
specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- execute arbitrary machine code in the context of the vulnerable
application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.
Other attacks may also be possible.
The issues described here will be split into individual BIDs as more
information becomes available.
These issues are fixed in:
- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3
82. Microsoft Indexing Service Query Validation Cross-Site Scripting
Vulnerability
BugTraq ID: 19927
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19927
Summary:
Microsoft Indexing Service is prone to a cross-site scripting
vulnerability because the application fails to properly sanitize
user-supplied input before it is rendered to other users.
An attacker may leverage this issue to have arbitrary script code
execute in the browser of an unsuspecting user, in the context of the
victim's session. This could allow the attacker to perform actions on
behalf of the victim, such as spoofing content or hijacking their session.
Microsoft Indexing Service is not installed or enabled by default. Even
if installed, it is not accessible from Internet Information Services
(IIS). This vulnerability affects only systems that have IIS and
Indexing Service installed and that have the Indexing Service configured
to be accessible from IIS through a web-based interface.
83. BisonFTP Remote Denial Of Service Vulnerability
BugTraq ID: 14079
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/14079
Summary:
BisonFTP is prone to a remote denial-of-service vulnerability. A remote
attacker may exploit this issue to deny service for legitimate users.
Reports indicate that the issue may be exploited only after successful
authentication.
84. GDB DWARF Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19802
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19802
Summary:
GDB is prone to multiple buffer-overflow vulnerabilities because of
insufficient bounds checking when handling DWARF and DWARF2 data.
Attackers could leverage this issue to run arbitrary code outside of a
restricted environment; this may lead to privilege escalation.
85. CPanel SUID Wrapper Remote Privilege Escalation Vulnerability
BugTraq ID: 20163
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20163
Summary:
cPanel is prone to a remote privilege-escalation vulnerability.
A remote attacker can exploit this issue to gain administrative access
to the affected application. This may lead to other attacks.
86. PHP Download Download.PHP Directory Traversal Vulnerability
BugTraq ID: 19872
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19872
Summary:
Php download is prone to a directory-traversal vulnerability because it
fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files
from the vulnerable system in the context of the affected application.
Information obtained may aid in further attacks.
The vendor reports that exploitability of this issue is limited to text
files only.
87. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
BugTraq ID: 20216
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20216
Summary:
OpenSSH is prone to a remote denial-of-service vulnerability because it
fails to properly handle incoming duplicate blocks.
Remote attackers may exploit this issue to consume excessive CPU
resources, potentially denying service to legitimate users.
This issue occurs only when OpenSSH is configured to accept SSH Version
One traffic.
88. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because
the application fails to properly sanitize user-supplied input before
using it in a 'system()' function call.
This issue allows attackers to execute arbitrary shell commands with the
privileges of users executing a vulnerable version of SCP.
This issue reportedly affects version 4.2 of OpenSSH. Other versions may
also be affected.
89. MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
BugTraq ID: 20290
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20290
Summary:
MailEnable is prone to multiple remote vulnerabilities.
These issues arise in the SMTP server during NTLM authentication and may
facilitate arbitrary code execution or denial-of-service conditions.
MailEnable Professional 2.0 and MailEnable Enterprise 2.0 are reported
vulnerable to these issues.
90. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
BugTraq ID: 7831
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/7831
Summary:
A vulnerability has been reported for OpenSSH that may allow
unauthorized access to an OpenSSH server's login mechanism.
The vulnerability occurs because of the way OpenSSH restricts access.
It's possible to configure OpenSSH to restrict access based on certain
patterns. When a numeric IP address is provided as the host that is
attempting a connection, an attacker can trick the OpenSSH server to
allow access.
91. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
BugTraq ID: 20241
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20241
Summary:
Portable OpenSSH is prone to a remote code-execution vulnerability. The
issue derives from a race condition in a vulnerable signal handler.
Reportedly, under specific conditions, it is theoretically possible to
execute code remotely prior to authentication when GSSAPI authentication
is enabled. This has not been confirmed; the chance of a successful
exploit of this nature is considered minimal.
On non-Portable OpenSSH implementations, this same race condition can be
exploited to cause a pre-authentication denial of service.
This issue occurs when OpenSSH and Portable OpenSSH are configured to
accept GSSAPI authentication.
92. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
BugTraq ID: 19661
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19661
Summary:
Apache HTTP server is prone to an HTTP request header security weakness.
An attacker may exploit this issue to steal cookie-based authentication
credentials and launch other attacks.
93. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting
vulnerability. This issue is due to the module's failure to properly
sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code
executed in the browser of an unsuspecting user in the context of the
affected site. This may facilitate the theft of cookie-based
authentication credentials as well as other attacks.
94. VAMP Webmail Yesno.PHTML Remote File Include Vulnerability
BugTraq ID: 20289
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20289
Summary:
VAMP Webmail is prone to a remote file-include vulnerability because it
fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file
containing malicious PHP code and execute it in the context of the
webserver process. This may facilitate a compromise of the application
and the underlying system; other attacks are also possible.
VAMP Webmail 2.0beta1 and prior versions are vulnerable to this issue.
95. BasiliX Multiple Remote File Include Vulnerabilities
BugTraq ID: 20287
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20287
Summary:
BasiliX is affected by multiple remote file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code
on an affected computer with the privileges of the webserver process.
This may potentially facilitate unauthorized access.
BasiliX version 1.1.1 is reported vulnerable. Other versions may be
affected as well.
96. Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String
Vulnerability
BugTraq ID: 20284
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20284
Summary:
Trend Micro OfficeScan is prone to a remote format-string vulnerability.
This vulnerability requires a certain amount of user-interaction for an
attack to occur, such as visiting a malicious website. A successful
exploit would let a remote attacker execute code with the privileges of
the currently logged-in user.
Trend Micro OfficeScan Corporate Edition 7.3 is reported vulnerable.
Other versions may be affected as well.
97. FFmpeg Image File Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 20009
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20009
Summary:
FFmpeg is prone to multiple remote buffer-overflow vulnerabilities
because the application using this library fails to properly
bounds-check user-supplied input before copying it to an insufficiently
sized memory buffer.
These issues allow attackers to execute arbitrary machine code within
the context of the affected application.
Versions prior to 0.4.9_p20060530 are vulnerable to this issue.
98. SquirrelMail Compose.PHP Multiple Information Disclosure and Data
Modification Vulnerabilities
BugTraq ID: 19486
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and
data-modification vulnerabilities because the application fails to
properly sanitize user-supplied input.
Successful exploits may allow an authenticated remote attacker to read
and write email attachments or preferences from other users. This may
lead to other attacks.
99. Mozilla Firefox Unspecified Javascript Remote Code Execution
Vulnerability
BugTraq ID: 20282
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20282
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability
because the application fails to properly sanitize user-supplied input
before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or
execute arbitrary machine code in the context of the affected application.
Details regarding this vulnerability are not currently available; this
BID will be updated when more information becomes available.
100. SiteDepth CMS Constants.PHP Remote File Include Vulnerability
BugTraq ID: 19094
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19094
Summary:
SiteDepth CMS is prone to a remote file-include vulnerability because it
fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file
containing malicious PHP code and execute it in the context of the
webserver process. This may facilitate a compromise of the application
and the underlying system; other attacks are also possible.
SiteDepth CMS 3.01 and prior versions are vulnerable to this issue.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Mozilla flaws more joke than jeopardy
By: Robert Lemos
Two ToorCon presenters razz the open-source browser group for an alleged
flawed implementation of Javascript, but the lecture appears to be more
stand-up comedy than substantiative research.
http://www.securityfocus.com/news/11416
2. Tag-team attack exploits IE flaw
By: Robert Lemos
Attackers exploit a zero-day vulnerability to cause a large number of
Web sites to send their visitors to rogue pages carrying a second
attack, this time against Microsoft's Internet Explorer.
http://www.securityfocus.com/news/11415
3. HP chief apologizes, denies he knew of hacking
By: Robert Lemos
Hewlett-Packard's CEO Mark Hurd immediately replaces former chairperson
Patricia Dunn as the company acknowledges it knew about the "pretexting"
but not about the "hacking."
http://www.securityfocus.com/news/11414
4. Web flaws race ahead in 2006
By: Robert Lemos
Less rigor in Web programming, a growing number of software projects,
and restrictions on Web security testing are combining to make Web-site
vulnerabilities the most common class of security issues this year.
http://www.securityfocus.com/news/11413
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Information Assurance Engineer, Clarksburg
http://www.securityfocus.com/archive/77/447392
2. [SJ-JOB] Sr. Security Engineer, Hyderabad
http://www.securityfocus.com/archive/77/447390
3. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
http://www.securityfocus.com/archive/77/447391
4. [SJ-JOB] Management, Charlotte
http://www.securityfocus.com/archive/77/447394
5. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/447388
6. [SJ-JOB] Software Engineer, San Francisco
http://www.securityfocus.com/archive/77/447389
7. [SJ-JOB] Developer, Columbia
http://www.securityfocus.com/archive/77/447384
8. [SJ-JOB] Security Engineer, Burlington
http://www.securityfocus.com/archive/77/447385
9. [SJ-JOB] Manager, Information Security, Columbia
http://www.securityfocus.com/archive/77/447386
10. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
http://www.securityfocus.com/archive/77/447387
11. [SJ-JOB] Security Consultant, Newport Beach
http://www.securityfocus.com/archive/77/447154
12. [SJ-JOB] Developer, Broomfield
http://www.securityfocus.com/archive/77/447165
13. [SJ-JOB] Information Assurance Analyst, Broomfield
http://www.securityfocus.com/archive/77/447166
14. [SJ-JOB] Security Engineer, Broomfield
http://www.securityfocus.com/archive/77/447139
15. [SJ-JOB] Jr. Security Analyst, LOS ANGELES
http://www.securityfocus.com/archive/77/447137
16. [SJ-JOB] Security Consultant, berkshire
http://www.securityfocus.com/archive/77/447138
17. [SJ-JOB] Security Architect, Broomfield
http://www.securityfocus.com/archive/77/447140
18. [SJ-JOB] Security Engineer, berkshire
http://www.securityfocus.com/archive/77/447136
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Allow regular user to unlock screensaver locked computer
http://www.securityfocus.com/archive/88/447483
2. a question of usb token
http://www.securityfocus.com/archive/88/447484
3. How can this happen with Windows Vista?
http://www.securityfocus.com/archive/88/447296
4. Security Policy Anomaly
http://www.securityfocus.com/archive/88/447248
5. SecurityFocus Microsoft Newsletter #310
http://www.securityfocus.com/archive/88/447144
6. Microsoft Security Clamp
http://www.securityfocus.com/archive/88/446467
VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. LDAP in Unix
http://www.securityfocus.com/archive/92/447230
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to
[email protected] from the subscribed address. The
contents of the subject or message body do not matter. You will receive
a confirmation request message to which you will have to answer.
Alternatively you can also visit
http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and
ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web
application security assessments should be considered a crucial phase in
the development of any web application. What methodology should be
followed? What tools can accelerate the assessment process? See for
yourself. Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008YSf