SecurityFocus Newsletter #371

Peter Laborge <[email protected]> Wed, 11 Oct 2006 16:28:28 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #371
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to 
compromise confidential information, steal cookies and create requests 
that can be mistaken
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000Cc5Y

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Hacking Web 2.0 Applications with Firefox
        2. Recent Security Enhancements in NetBSD
II.   BUGTRAQ SUMMARY
        1. Sendmail Long Header Denial Of Service Vulnerability
        2. RegistroTL Main.PHP Remote File Include Vulnerability
        3. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
        4. Mono System.CodeDom.Compiler Class Insecure Temporary File 
Creation Vulnerability
        5. 4Images Search.PHP SQL Injection Vulnerability
        6. Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting 
Vulnerability
        7. Dokeos Multiple Remote File Includes Vulnerabilities
        8. CommunityPortals Bug.PHP Remote File Include Vulnerability
        9. FlatNuke Index.PHP Arbitrary File Upload Vulnerability
        10. Google Earth KML/KMZ Files Buffer Overflow Vulnerability
        11. Noah's Classifieds Index.PHP Cross-Site Scripting Vulnerability
        12. N@Board  Naboard_PNR.PHP Remote File Include Vulnerability
        13. Asbru Web Content Management Unauthorized Remote Access 
Vulnerability
        14. IBM WebSphere Application Server Prior to 6.1.0.2 Multiple 
Vulnerabilities
        15. PhpMyAgenda Language Local File Include Vulnerability
        16. Apache Mod_SSL Custom Error Document Remote Denial Of 
Service Vulnerability
        17. Microsoft Excel DATETIME Remote Code Execution Vulnerability
        18. Goss ICM CMS Multiple HTML Injection Vulnerabilities
        19. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
        20. Mozilla Multiple Products Remote Vulnerabilities
        21. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote 
Vulnerabilities
        22. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple 
Remote Vulnerabilities
        23. PHP Multiple Input Validation Vulnerabilities
        24. Microsoft XML Core Services Information Disclosure Vulnerability
        25. Microsoft Windows XML Core Services XSLT Buffer Overrun 
Vulnerability
        26. Easy Gallery Doc_Directory Parameter Multiple Remote File 
Include Vulnerabilities
        27. Eboli Index.PHP Remote File Include Vulnerability
        28. PHP ZendEngine ECalloc Integer Overflow Vulnerability
        29. PHP Ini_Restore() Safe_Mode and Open_Basedir Restriction 
Bypass Vulnerability
        30. Jasmine-Web Index.PHP Remote File Include Vulnerability
        31. RETIRED: ISearch ISEARCH_PATH Parameter Remote File Include 
Vulnerability
        32. Polaring General.PHP Remote File Include Vulnerability
        33. Novell BorderManager IPSec/IKE Remote Denial Of Service 
Vulnerability
        34. Microsoft Office Malformed Chart Record Remote Code 
Execution Vulnerability
        35. ImageMagick SGI Image File Remote Heap Buffer Overflow 
Vulnerability
        36. Microsoft Excel Style Handling and Repair Remote Code 
Execution Vulnerability
        37. Microsoft Excel Lotus 1-2-3 File Handling Remote Code 
Execution Vulnerability
        38. Microsoft Excel COLINFO Remote Code Execution Vulnerability
        39. RETIRED: Gcards Addnews.PHP Remote File Include Vulnerability
        40. Linux-HA Heartbeat Insecure Default Permissions on Shared 
Memory Vulnerability
        41. Multiple Vendor TCP Packet Fragmentation Handling Denial Of 
Service Vulnerability
        42. Microsoft Word Malformed String Remote Code Execution 
Vulnerability
        43. Microsoft Word Malformed Stack Remote Code Execution 
Vulnerability
        44. Microsoft Word Mail Merge Remote Code Execution Vulnerability
        45. Microsoft Windows SMB Rename Remote Denial of Service 
Vulnerability
        46. Microsoft Windows SMB PIPE Remote Denial of Service 
Vulnerability
        47. Linux Kernel ULE Packet Handling Remote Denial of Service 
Vulnerability
        48. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow 
Vulnerability
        49. HP Version Control Agent Remote Unauthorized Access and 
Privilege Escalation Vulnerability
        50. Linux Kernel SCTP SO_LINGER Local Denial of Service 
Vulnerability
        51. Microsoft Office Smart Tag Remote Code Execution Vulnerability
        52. Linux Kernel UDF Denial of Service Vulnerability
        53. Linux Kernel Itanium PerfMonCTL Local Denial of Service 
Vulnerability
        54. Linux-HA Heartbeat Remote Denial of Service Vulnerability
        55. Microsoft Office Improper Memory Access Remote Code 
Execution Vulnerability
        56. Microsoft PowerPoint Unspecified Remote Code Execution 
Vulnerability
        57. Microsoft Word Mac Remote Code Execution Vulnerability
        58. Microsoft PowerPoint Record Improper Memory Access Remote 
Code Execution Vulnerability
        59. Microsoft PowerPoint Data Record Remote Code Execution 
Vulnerability
        60. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
        61. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
        62. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
        63. Multiple Vendor TCP Sequence Number Approximation Vulnerability
        64. Multiple Vendor TCP/IP Implementation ICMP Remote Denial Of 
Service Vulnerabilities
        65. Microsoft IPv6 TCP/IP Loopback LAND Denial of Service 
Vulnerability
        66. AOL You've Got Pictures ActiveX Controls Buffer Overflow 
Vulnerabilities
        67. Microsoft Office Malformed Record Remote Code Execution 
Vulnerability
        68. Microsoft Windows Object Packager Remote Code Execution 
Vulnerability
        69. MIT Kerberos 5 Multiple Local Privilege Escalation 
Vulnerabilities
        70. PHP Live! Help Script File Include Vulnerability
        71. GNU GZip Archive Handling Multiple Remote Vulnerabilities
        72. MiniBill Config[Plugin_Dir] Parameter Multiple Remote File 
Include Vulnerabilities
        73. Libmusicbrainz Multiple Buffer Overflow Vulnerabilities
        74. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
        75. AWStats AWstats.PL Multiple Cross-Site Scripting Vulnerabilities
        76. Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
        77. Motorola SB4200 Remote Denial of Service Vulnerability
        78. Eazy Cart Multiple Input Validation and Authentication 
Bypass Vulnerabilities
        79. Gallery Script Injection Vulnerability
        80. Moodle Blog Module SQL Injection Vulnerability
        81. Webmedia Explorer Core.Lib.PHP Remote File Include Vulnerability
        82. EXPBlog Multiple Cross-Site Scripting Vulnerabilities
        83. GDB Multiple Vulnerabilities
        84. Linksys WRT54GX V2.0 WAN Port UPnP Vulnerability
        85. Adobe Breeze Unspecified Directory Traversal Vulnerability
        86. KMail HTML Mail Handling Denial Of Service Vulnerability
        87. Blue Smiley Organizer Unspecified SQL Injection Vulnerabilities
        88. OpenSSH-Portable Existing Password Remote Information 
Disclosure Weakness
        89. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc 
Code Execution Vulnerability
        90. ZABBIX Multiple Unspecified Remote Code Execution 
Vulnerabilities
        91. Digishop Cart.PHP Cross-Site Scripting Vulnerability
        92. AAIPortal Unspecified SQL Injection Vulnerabilities
        93. RARLAB WinRAR LHA Filename Handling Buffer Overflow 
Vulnerability
        94. Cahier De Textes SQL Injection Vulnerabilities
        95. HP-UX Ignite-UX Remote Unauthorized Access and Privilege 
Escalation Vulnerabilities
        96. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
        97. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
        98. Python Repr() Function Remote Code Execution Vulnerability
        99. OpenSSL Public Key Processing Denial of Service Vulnerability
        100. OpenSSL SSLv2 Null Pointer Dereference Client Denial of 
Service Vulnerability
III.  SECURITYFOCUS NEWS
        1. Google Code Search peers into programs' flaws
        2. Mozilla flaws more joke than jeopardy
        3. Tag-team attack exploits IE flaw
        4. HP chief apologizes, denies he knew of hacking
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Database Security Engineer, Tel-Aviv
        2. [SJ-JOB] Security Consultant, London
        3. [SJ-JOB] Sales Engineer, New York City
        4. [SJ-JOB] Security Consultant, London
        5. [SJ-JOB] Developer, Redwood Shores
        6. [SJ-JOB] Compliance Officer, Toronto
        7. [SJ-JOB] Application Security Architect, Minneapolis
        8. [SJ-JOB] Threat Analyst, Lexington
        9. [SJ-JOB] Security Researcher, Seattle/Redmond
        10. [SJ-JOB] Technical Writer, Superior
        11. [SJ-JOB] Senior Software Engineer, Superior
        12. [SJ-JOB] Security Researcher, Herndon
        13. [SJ-JOB] Security Consultant, Denver
        14. [SJ-JOB] Security Engineer, Livermore
        15. [SJ-JOB] Security Researcher, Marlboro
        16. [SJ-JOB] Security Engineer, Boston
        17. [SJ-JOB] Sales Engineer, Reston
        18. [SJ-JOB] Quality Assurance, Superior
        19. [SJ-JOB] Management, Columbia
        20. [SJ-JOB] Developer, Superior
        21. [SJ-JOB] Jr. Security Analyst, Palm Beach Gardens
        22. [SJ-JOB] Security Architect, McLean
        23. [SJ-JOB] Management, Atlanta
        24. [SJ-JOB] Sr. Security Analyst, Beaverton
        25. [SJ-JOB] Security Consultant, Columbus
        26. [SJ-JOB] Security Engineer, Atlanta
        27. [SJ-JOB] Application Security Architect, Phoenix
        28. [SJ-JOB] Software Engineer, New York
        29. [SJ-JOB] Developer, Sunnyvale
        30. [SJ-JOB] Security Researcher, San Jose
        31. [SJ-JOB] Database Security Engineer, San Diego
        32. [SJ-JOB] Sr. Security Analyst, Central Missouri
        33. [SJ-JOB] Security Engineer, New York City
        34. [SJ-JOB] Technical Support Engineer, Sunnyvale
        35. [SJ-JOB] Sales Engineer, NY or NJ
        36. [SJ-JOB] Quality Assurance, Sunnyvale
        37. [SJ-JOB] Forensics Engineer, Arlington
        38. [SJ-JOB] Regional Channel Manager, Miami
        39. [SJ-JOB] Regional Channel Manager, New York
        40. [SJ-JOB] Sr. Security Engineer, Hampshire or Dorset
        41. [SJ-JOB] Application Security Engineer, Seattle
        42. [SJ-JOB] MOD CLAS Consultant, Hampshire or Dorset
        43. [SJ-JOB] Sr. Security Analyst, Charlotte
        44. [SJ-JOB] VP of Regional Sales, Berkshire
        45. [SJ-JOB] Sales Representative, Charlotte or Raleigh
        46. [SJ-JOB] Management, Plantation
        47. [SJ-JOB] Security Consultant, Frankfurt/Main
        48. [SJ-JOB] Security Consultant, Maidenhead, Berkshire
        49. [SJ-JOB] Sales Engineer, New York Area
        50. [SJ-JOB] Senior Software Engineer, Sunnyvale
V.    INCIDENTS LIST SUMMARY
        1. RES: Massive SPAM Increase
        2. Policyd-weight: WAS: Massive SPAM Increase
        3. Massive SPAM Increase
        4. site probe
VI.   VULN-DEV RESEARCH LIST SUMMARY
        1. Fuzzing KDE based apps (narrowing down bugs)
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. security implications of disabling WMI service
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
        1. Dynamic firewall based on bandwidth usage ?
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Hacking Web 2.0 Applications with Firefox
By Shreeraj Shah
This article looks at some of the methods, tools and tricks to dissect 
web 2.0 applications (including Ajax) and discover security holes using 
Firefox and ithttp://www.securityfocus.com/infocus/1879

2. Recent Security Enhancements in NetBSD
By Elad Efrat
NetBSD is renowned for its focus on portability, but great care is also 
given to security. This paper presents the NetBSD philosophy on 
security, major desighttp://www.securityfocus.com/infocus/1878


II.  BUGTRAQ SUMMARY
--------------------
1. Sendmail Long Header Denial Of Service Vulnerability
BugTraq ID: 19714
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19714
Summary:
Sendmail is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to crash the Sendmail process, 
causing a denial of service.

2. RegistroTL Main.PHP Remote File Include Vulnerability
BugTraq ID: 20433
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20433
Summary:
RegistroTL is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

3. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
BugTraq ID: 20249
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20249
Summary:
OpenSSL is prone to a buffer-overflow vulnerability because the library 
fails to properly bounds-check user-supplied input before copying it to 
an insufficiently sized memory buffer.

Successfully exploiting this issue may result in the execution of 
arbitrary machine code in the context of applications that use the 
affected library. Failed exploit attempts may crash applications, 
denying service to legitimate users.

4. Mono System.CodeDom.Compiler Class Insecure Temporary File Creation 
Vulnerability
BugTraq ID: 20340
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20340
Summary:
The Mono 'System.CodeDom.Compiler' class creates temporary files in an 
insecure manner.

An attacker with local access could potentially exploit this issue to 
perform symlink attacks, overwriting arbitrary files in the context of 
the affected application.

Successfully exploiting a symlink attack may allow an attacker to 
overwrite or corrupt sensitive files. This may result in a denial of 
service; other attacks may also be possible.

Versions 1.0 and 2.0 are vulnerable; other versions may also be affected.

5. 4Images Search.PHP SQL Injection Vulnerability
BugTraq ID: 20394
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20394
Summary:
4Images is prone to an SQL-injection vulnerability because the 
application fails to properly sanitize user-supplied input before using 
it in an SQL query.

A successful exploit could allow an attacker to compromise the 
application, access or modify data, or exploit vulnerabilities in the 
underlying database implementation.

This issue affects versions 1.7.x.

6. Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting 
Vulnerability
BugTraq ID: 20337
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20337
Summary:
Microsoft ASP.NET is prone to a cross-site scripting vulnerability. This 
issue is due to a failure in the application to properly sanitize 
user-supplied input before it is rendered in the browser of an 
unsuspecting user in the context of the affected site.

An attacker may leverage this issue to have arbitrary script code 
executed in the browser of an unsuspecting user, with the privileges of 
the victim userĂ¢??s account. This may help the attacker steal 
cookie-based authentication credentials, disclose sensitive information, 
and launch other attacks.

7. Dokeos Multiple Remote File Includes Vulnerabilities
BugTraq ID: 20468
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20468
Summary:
Dokeos is prone to multiple remote file-include vulnerabilities. These 
issues are due to a failure in the application to properly sanitize 
user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

These issues affect version 1.6.3.

8. CommunityPortals Bug.PHP Remote File Include Vulnerability
BugTraq ID: 20467
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20467
Summary:
CommunityPortals is prone to a remote file-include vulnerability because 
it fails to sufficiently sanitize user-supplied input data.

An attacker can exploit this issue to have malicious PHP code execute in 
the context of the webserver process. This may allow the attacker to 
compromise the application and the underlying system; other attacks are 
also possible.

CommunityPortals 1.0 Build 12-31-18 and prior are affected by this issue.

9. FlatNuke Index.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 20466
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20466
Summary:
FlatNuke is prone to an arbitrary file upload vulnerability because it 
fails to sufficiently sanitize user supplied input.

This issue could allow an attacker to execute arbitrary script code in 
the context of the affected web server process.  This may facilitate the 
compromise of the application; other attacks are possible.

Versions 2.5.8 and prior are vulnerable; other versions may also be 
affected.

10. Google Earth KML/KMZ Files Buffer Overflow Vulnerability
BugTraq ID: 20464
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20464
Summary:
Google Earth is prone to a buffer-overflow vulnerability. This issue is 
due to a failure in the application to properly verify the size of 
user-supplied data before copying it into an insufficiently sized 
process buffer.

This issue allows remote attackers to execute arbitrary machine code in 
the context of the user running the affected application. Failed exploit 
attempts will likely crash applications, denying service to legitimate 
users.

Google Earth version v4.0.2091(beta) is vulnerable to this issue.

11. Noah's Classifieds Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20463
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20463
Summary:
Noah's Classifieds is prone to a cross-site scripting vulnerability. 
This issue is due to a failure in the application to properly sanitize 
user-supplied input.

An attacker may leverage this issue to have arbitrary script code 
executed in the browser of an unsuspecting user in the context of the 
affected site.  This may facilitate the theft of cookie-based 
authentication credentials as well as other attacks.

12. N@Board  Naboard_PNR.PHP Remote File Include Vulnerability
BugTraq ID: 20462
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20462
Summary:
N@Board is prone to a remote file-include vulnerability because it fails 
to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

13. Asbru Web Content Management Unauthorized Remote Access Vulnerability
BugTraq ID: 20459
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20459
Summary:
Asbru Web Content Management is prone to an unspecified remote 
unauthorized access vulnerability.

Asbru Web Content Management versions prior to 6.1.22 are vulnerable to 
this issue.

14. IBM WebSphere Application Server Prior to 6.1.0.2 Multiple 
Vulnerabilities
BugTraq ID: 20455
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20455
Summary:
IBM WebSphere Application Server is prone to multiple unspecified 
vulnerabilities, including:

- a information disclosure issue.
- a security exposure with an unknown impact
- an unauthorized access issue.

IBM WebSphere Application Server versions prior to 6.1.0.2 are 
vulnerable to these issues.

15. PhpMyAgenda Language Local File Include Vulnerability
BugTraq ID: 20453
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20453
Summary:
PhpMyAgenda is prone to a local file-include vulnerability because it 
fails to properly sanitize user-supplied input.

A remote attacker can exploit this vulnerability by uploading a 
malicious file and executing it in the context of the vulnerable 
application. Other attacks may also be possible.

This issue affects version 3.1 Beta 1; other versions may also be 
vulnerable.

16. Apache Mod_SSL Custom Error Document Remote Denial Of Service 
Vulnerability
BugTraq ID: 16152
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/16152
Summary:
Apache's mod_ssl module is susceptible to a remote denial-of-service 
vulnerability. A flaw in the module results in a NULL-pointer 
dereference that causes the server to crash. This issue is present only 
when virtual hosts are configured with a custom 'ErrorDocument' 
statement for '400' errors or 'SSLEngine optional'.

Depending on the configuration of Apache, attackers may crash the entire 
webserver or individual child processes. Repeated attacks are required 
to deny service to legitimate users when Apache is configured for 
multiple child processes to handle connections.

This issue affects Apache 2.x versions.

17. Microsoft Excel DATETIME Remote Code Execution Vulnerability
BugTraq ID: 20344
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/20344
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine 
code in the context of the user running the application.

Note that Microsoft Office applications include functionality to embed 
Office files as objects contained in other Office files. As an example, 
Microsoft Word files may contain embedded malicious Microsoft Excel 
files, making Word documents another possible attack vector.

18. Goss ICM CMS Multiple HTML Injection Vulnerabilities
BugTraq ID: 18221
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/18221
Summary:
Goss ICM CMS is prone to multiple HTML-injection vulnerabilities because 
the application fails to properly sanitize user-supplied input before 
using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of 
the affected website, potentially allowing an attacker to steal 
cookie-based authentication credentials or to control how the site is 
rendered to the user; other attacks are also possible.

19. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge 
an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 
signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA 
keys and take advantage of trust relationships that depend on these 
credentials, possibly posing as a trusted party and signing a 
certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are 
affected by this vulnerability. Updates are available.

20. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories 
specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable 
application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more 
information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

21. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
BugTraq ID: 20042
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/20042
Summary:
The Mozilla Foundation has released six security advisories specifying 
vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- supply malicious data through updates
- inject arbitrary content
- execute arbitrary JavaScript
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more 
information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.7
- Mozilla Thunderbird version 1.5.0.7
- Mozilla SeaMonkey version 1.0.5

22. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote 
Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories 
specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, 
Camino, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable 
application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the 
remote execution of machine code
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further 
information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2

23. PHP Multiple Input Validation Vulnerabilities
BugTraq ID: 19582
Remote: No
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/19582
Summary:
PHP is prone to multiple input-validation vulnerabilities. Successful 
exploits could allow an attacker to write files in unauthorized 
locations, cause a denial-of-service condition, and potentially execute 
code.

These issues are reported to affect PHP versions 4.4.3 and 5.1.4; other 
versions may also be vulnerable.

24. Microsoft XML Core Services Information Disclosure Vulnerability
BugTraq ID: 20339
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/20339
Summary:
Microsoft XML Core Services is prone to an information disclosure 
vulnerability.  This vulnerability is caused by an error in how server 
re-directs are handled by the affected component.

This vulnerability could be exploited by enticing a victim user into 
visiting a malicious web page.

25. Microsoft Windows XML Core Services XSLT Buffer Overrun Vulnerability
BugTraq ID: 20338
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/20338
Summary:
Microsoft Windows is prone to a remotely exploitable buffer-overrun 
condition in the XSLT implementation of XML core services.

An attacker can exploit this issue to execute arbitrary code on an 
unsuspecting victim's computer. This may facilitate a remote compromise.

26. Easy Gallery Doc_Directory Parameter Multiple Remote File Include 
Vulnerabilities
BugTraq ID: 20411
Remote: Yes
Last Updated: 2006-10-10
Relevant URL: http://www.securityfocus.com/bid/20411
Summary:
Easy Gallery is prone to multiple remote file-include vulnerabilities 
because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

Easy Gallery 1.4 and prior versions are affected by these issues.

27. Eboli Index.PHP Remote File Include Vulnerability
BugTraq ID: 20429
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20429
Summary:
Eboli is affected by a remote file-include vulnerability because the 
application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary server-side 
script code on an affected computer with the privileges of the webserver 
process. This may facilitate unauthorized access.

28. PHP ZendEngine ECalloc Integer Overflow Vulnerability
BugTraq ID: 20349
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20349
Summary:
PHP is prone to an integer-overflow vulnerability because the 
application fails to do proper bounds checking on user-supplied data.

An attacker can exploit this vulnerability to execute arbitrary code in 
the context of the affected application. Failed exploit attempts will 
likely cause denial-of-service conditions.

29. PHP Ini_Restore() Safe_Mode and Open_Basedir Restriction Bypass 
Vulnerability
BugTraq ID: 19933
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19933
Summary:
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass 
vulnerability. Successful exploits could allow an attacker to access 
sensitive information or to write files in unauthorized locations.

This vulnerability would be an issue in shared-hosting configurations 
where multiple users can create and execute arbitrary PHP script code; 
in such cases, the 'safe_mode' and 'open_basedir' restrictions are 
expected to isolate users from each other.

These issues are reported to affect PHP versions 5.1.6, 4.4.4, and earlier.

Reports indicate that fixes may be available to address this issue, but 
this has not been confirmed.

30. Jasmine-Web Index.PHP Remote File Include Vulnerability
BugTraq ID: 20430
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20430
Summary:
Jasmine-Web is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

31. RETIRED: ISearch ISEARCH_PATH Parameter Remote File Include 
Vulnerability
BugTraq ID: 20401
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20401
Summary:
iSearch is affected by a remote file-include vulnerability because the 
application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary server-side 
script code on an affected computer with the privileges of the webserver 
process. This may facilitate unauthorized access.

iSearch 2.16 and prior versions are reported affected.

Update: This BID is retired; further information has revealed that this 
is not a vulnerability.

32. Polaring General.PHP Remote File Include Vulnerability
BugTraq ID: 20183
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20183
Summary:
Polaring is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 0.04.03 and prior.

33. Novell BorderManager IPSec/IKE Remote Denial Of Service Vulnerability
BugTraq ID: 20428
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20428
Summary:
Novell BorderManager is affected by a remote denial-of-service 
vulnerability because the application fails to properly handle 
user-supplied input.

Exploiting this issue will allow an attacker to cause the affected 
client computer to hang, denying service to legitimate users.

Novell BorderManager version 3.8 is vulnerable.

34. Microsoft Office Malformed Chart Record Remote Code Execution 
Vulnerability
BugTraq ID: 20383
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20383
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This 
issue occurs when Office attempts to process malformed files.

An attacker could exploit this issue by enticing a victim to load a 
malicious Office file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

35. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19507
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19507
Summary:
ImageMagick is prone to a remote heap buffer-overflow vulnerability 
because the application fails to properly bounds-check user-supplied 
input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the 
context of applications that use the ImageMagick library.

ImageMagick versions in the 6.x series, up to version 6.2.8, are 
vulnerable to this issue.

36. Microsoft Excel Style Handling and Repair Remote Code Execution 
Vulnerability
BugTraq ID: 18872
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/18872
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Successfully exploiting this issue allows attackers to execute arbitrary 
code in the context of targeted users.

A proof-of-concept malicious code named 'Trojan.Hongmosa' is actively 
exploiting this vulnerability, which results in crashing Excel running 
on Simplified Chinese, Traditional Chinese, Japanese, or Korean Windows.

Note that Microsoft Office applications include functionality to embed 
Office files as objects contained in other Office files. As an example, 
Microsoft Word files may contain embedded malicious Microsoft Excel 
files, making Word documents another possible attack vector.

This issue is distinct from the issue described in BID 18422 (Microsoft 
Excel Unspecified Remote Code Execution Vulnerability). Proof-of-concept 
'Nanika.xls' was originally thought to be related to BID 18422; however, 
reports indicate that 'Nanika.xls' triggers this vulnerability.

37. Microsoft Excel Lotus 1-2-3 File Handling Remote Code Execution 
Vulnerability
BugTraq ID: 20345
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20345
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine 
code in the context of the user running the application.

This issue was originally described in BID 18989 and has now been 
assigned its own BID.

38. Microsoft Excel COLINFO Remote Code Execution Vulnerability
BugTraq ID: 20391
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20391
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine 
code in the context of the user running the application.

Note that Microsoft Office applications include functionality to embed 
Office files as objects contained in other Office files. As an example, 
Word files may contain embedded malicious Excel files, making Word 
documents another possible attack vector.

39. RETIRED: Gcards Addnews.PHP Remote File Include Vulnerability
BugTraq ID: 20461
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20461
Summary:
gcards is prone to a remote file-include vulnerability because it fails 
to sufficiently sanitize user-supplied input data.

An attacker can exploit this issue to have malicious PHP code execute in 
the context of the webserver process. This may allow the attacker to 
compromise the application and the underlying system; other attacks are 
also possible.

Version 1.13 is affected by this issue; other versions may also be affected.

This BID has been retired.

40. Linux-HA Heartbeat Insecure Default Permissions on Shared Memory 
Vulnerability
BugTraq ID: 19186
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19186
Summary:
Since Linux-HA Heartbeat has insecure default permissions set on shared 
memory, local attackers may be able to cause a denial of service.

Exploitation would most likely result in a system crash, loss of data, 
and resource exhaustion, leading to a denial of service if critical 
files are accessed improperly or overwritten in the attack. Other 
attacks may be possible as well.

41. Multiple Vendor TCP Packet Fragmentation Handling Denial Of Service 
Vulnerability
BugTraq ID: 11258
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/11258
Summary:
Multiple vendor implementations of the TCP stack are reported prone to a 
remote denial-of-service vulnerability.

The issue is reported to present itself due to inefficiencies present 
when handling fragmented TCP packets.

The discoverer of this issue has dubbed the attack style the "New Dawn 
attack"; it is a variation of a previously reported attack that was 
named the "Rose Attack".

A remote attacker may exploit this vulnerability to deny service to an 
affected computer.

Microsoft Windows 2000/XP, Linux kernel 2.4 tree, and undisclosed Cisco 
systems are reported prone to this vulnerability; other products may 
also be affected.

42. Microsoft Word Malformed String Remote Code Execution Vulnerability
BugTraq ID: 20341
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20341
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to load a 
malicious Word file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

43. Microsoft Word Malformed Stack Remote Code Execution Vulnerability
BugTraq ID: 19835
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19835
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

This issue can allow remote attackers to execute arbitrary code on a 
vulnerable computer by supplying a malicious mail merge file to a user. 
This issue is being actively exploited in the wild as Trojan.MDropper.Q.

44. Microsoft Word Mail Merge Remote Code Execution Vulnerability
BugTraq ID: 20358
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20358
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to load a 
malicious Word file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

45. Microsoft Windows SMB Rename Remote Denial of Service Vulnerability
BugTraq ID: 20373
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20373
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability 
because the Server service fails to properly handle network messages.

Exploiting this issue may cause affected computers to crash, denying 
service to legitimate users.

To exploit this issue, an attacker must have valid logon credentials.

46. Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
BugTraq ID: 19215
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19215
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability 
because the operating system fails to properly handle network traffic.

This issue may cause affected computers to crash, denying service to 
legitimate users.

Reports indicate that this issue may be currently exploited in the wild, 
but this has not been confirmed.

47. Linux Kernel ULE Packet Handling Remote Denial of Service Vulnerability
BugTraq ID: 19939
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19939
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability.

This issue is triggered when the kernel handles a specially crafted ULE 
packet.

This issue allows remote attackers to trigger a denial of service for 
legitimate users.

Kernel version 2.6.17.8 is reported vulnerable to this issue; other 
versions may be affected as well.

48. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow 
Vulnerability
BugTraq ID: 19030
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19030
Summary:
Microsoft WebViewFolderIcon ActiveX control is prone to a 
buffer-overflow vulnerability.

This issue is triggered when an attacker convinces a victim user to 
visit a malicious website.

Remote attackers may exploit this issue to execute arbitrary machine 
code in the context of the affected application, facilitating the remote 
compromise of affected computers. Failed exploit attempts likely result 
in browser crashes.

49. HP Version Control Agent Remote Unauthorized Access and Privilege 
Escalation Vulnerability
BugTraq ID: 20465
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20465
Summary:
HP Version Control Agent is prone to an unspecified remote 
unauthorized-access and privilege-escalation vulnerability.

Exploiting this issue allows remote attackers to access restricted 
information that may possibly lead to privilege escalation on remote 
computers.

To exploit this issue, the attacker must have access and be 
authenticated to the affected application.

Further information is currently unavailable. This BID will be updated 
as more information is disclosed.

Versions prior to 2.1.5 are reported vulnerable.

50. Linux Kernel SCTP SO_LINGER Local Denial of Service Vulnerability
BugTraq ID: 20087
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20087
Summary:
The Linux kernel SCTP module is prone to a local denial-of-service 
vulnerability.

This issue allows local attackers to cause kernel crashes, denying 
service to legitimate users.

Specific information regarding affected versions of the Linux kernel is 
currently unavailable. This BID will be updated as further information 
is disclosed.

51. Microsoft Office Smart Tag Remote Code Execution Vulnerability
BugTraq ID: 20320
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20320
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This 
issue occurs when Office attempts to process malformed files.

An attacker could exploit this issue by enticing a victim to load a 
malicious Office file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

52. Linux Kernel UDF Denial of Service Vulnerability
BugTraq ID: 19562
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19562
Summary:
The Linux kernel UDF file module is prone to a denial-of-service.

An attacker can exploit this issue to crash the kernel, denying further 
service to legitimate users.

53. Linux Kernel Itanium PerfMonCTL Local Denial of Service Vulnerability
BugTraq ID: 20361
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20361
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

An attacker can exploit this issue to crash the kernel, denying further 
service to legitimate users.

This issue is exploitable only on the Itanium architecture running Linux 
kernel versions prior to 2.6.18.

54. Linux-HA Heartbeat Remote Denial of Service Vulnerability
BugTraq ID: 19516
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19516
Summary:
Linux-HA Heartbeat is prone to a remote denial-of-service vulnerability.

By successfully exploiting this issue, attackers can crash the master 
control process. This may result in the failure of services that depend 
on the application's functionality.

55. Microsoft Office Improper Memory Access Remote Code Execution 
Vulnerability
BugTraq ID: 20382
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20382
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This 
issue occurs when Office attempts to process malformed files.

An attacker could exploit this issue by enticing a victim to load a 
malicious Office file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

56. Microsoft PowerPoint Unspecified Remote Code Execution Vulnerability
BugTraq ID: 20226
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20226
Summary:
Microsoft PowerPoint is prone to an unspecified remote code-execution 
vulnerability.

Exploiting this issue can allow remote attackers to execute arbitrary 
code on a vulnerable computer by supplying a malicious PowerPoint 
document to a user. This issue is being actively exploited in the wild 
by Trojan.PPDropper.F.

This vulnerability is currently known to affect Microsoft Office 2000, 
Office XP, and Office 2003.

Due to a lack of information, further details cannot be provided. This 
BID will be updated when more information becomes available.

57. Microsoft Word Mac Remote Code Execution Vulnerability
BugTraq ID: 20387
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20387
Summary:
Microsoft Word for Mac is prone to a remote code-execution vulnerability 
when parsing Word files. Exploiting this vulnerability may allow an 
attacker to execute arbitrary machine code in the context of the user 
who opened the file.

An attacker could leverage this issue to gain the permissions of an 
unsuspecting user. A successful exploit could result in the remote 
compromise of the affected system.

58. Microsoft PowerPoint Record Improper Memory Access Remote Code 
Execution Vulnerability
BugTraq ID: 20325
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20325
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

Exploiting this issue can allow remote attackers to execute arbitrary 
code on a vulnerable computer by supplying a malicious PowerPoint (.ppt) 
document to a user.

59. Microsoft PowerPoint Data Record Remote Code Execution Vulnerability
BugTraq ID: 20322
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20322
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

Exploiting this issue can allow remote attackers to execute arbitrary 
code on a vulnerable computer by supplying a malicious PowerPoint (.ppt) 
document to a user.

60. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.

The vulnerability arising in the mod_rewrite module's ldap scheme 
handling allows for potential memory corruption when an attacker 
exploits certain rewrite rules.

An attacker may exploit this issue to trigger a denial-of-service 
condition. Reportedly, arbitrary code execution may be possible as well.

61. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it 
fails to properly bounds-check user-supplied input before copying it to 
an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code 
in the context of the affected application, but this has not been confirmed.

GnuPG version 1.4.4 is vulnerable to this issue; previous versions may 
also be affected.

62. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting 
vulnerability. This issue is due to the module's failure to properly 
sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code 
executed in the browser of an unsuspecting user in the context of the 
affected site. This may facilitate the theft of cookie-based 
authentication credentials as well as other attacks.

63. Multiple Vendor TCP Sequence Number Approximation Vulnerability
BugTraq ID: 10183
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/10183
Summary:
A vulnerability in TCP implementations may permit unauthorized remote 
users to reset TCP sessions. This issue affects products released by 
multiple vendors. Exploiting this issue may permit remote attackers to 
more easily approximate TCP sequence numbers.

The problem is that affected implementations will accept TCP sequence 
numbers within a certain range of the expected sequence number for a 
packet in the session. This will permit a remote attacker to inject a 
SYN or RST packet into the session, causing it to be reset and 
effectively allowing denial-of-service attacks. An attacker would 
exploit this issue by sending a packet to a receiving implementation 
with an approximated sequence number and a forged source IP and TCP port.

Few factors may present viable target implementations, such as 
imlementations that:

- depend on long-lived TCP connections
- have known or easily guessed IP address endpoints
- have known or easily guessed TCP source ports.

Note that Border Gateway Protocol (BGP) is reported to be particularly 
vulnerable to this type of attack. As a result, this issue is likely to 
affect a number of routing platforms.

Note also that while a number of vendors have confirmed this issue in 
various products, investigations are ongoing and it is likely that many 
other vendors and products will turn out to be vulnerable as the issue 
is investigated further.

Other consequences may also result from this issue, such as injecting 
specific data in TCP sessions, but this has not been confirmed.

**Update: Microsoft platforms are also reported prone to this 
vulnerability. Vendor reports indicate that an attacker will require 
knowledge of the IP address and port numbers of the source and 
destination of an existent legitimate TCP connection in order to exploit 
this vulnerability on Microsoft platforms. Connections that involve 
persistent sessions, for example Border Gateway Protocol sessions, may 
be more exposed to this vulnerability than other TCP/IP sessions.

64. Multiple Vendor TCP/IP Implementation ICMP Remote Denial Of Service 
Vulnerabilities
BugTraq ID: 13124
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/13124
Summary:
Multiple vendor implementations of TCP/IP Internet Control Message 
Protocol (ICMP) are reported prone to several denial-of-service attacks.

ICMP is employed by network nodes to determine certain automatic actions 
to take based on network failures reported by an ICMP message.

Reportedly, the RFC doesn't recommend security checks for ICMP error 
messages. As long as an ICMP message contains a valid source and 
destination IP address and port pair, it will be accepted for an 
associated connection.

The following individual attacks are reported:

- A blind connection-reset attack. This attack takes advantage of the 
specification that describes that on receiving a 'hard' ICMP error, the 
corresponding connection should be aborted. The Mitre ID CAN-2004-0790 
is assigned to this issue.

  A remote attacker may exploit this issue to terminate target TCP 
connections and deny service for legitimate users.

- An ICMP Source Quench attack. This attack takes advantage of the 
specification that a host must react to receive ICMP Source Quench 
messages by slowing transmission on the associated connection. The Mitre 
ID CAN-2004-0791 is assigned to this issue.

A remote attacker may exploit this issue to degrade the performance of 
TCP connections and partially deny service for legitimate users.

- An attack against ICMP PMTUD is reported to affect multiple vendors 
when they are configured to employ PMTUD. By sending a suitable forged 
ICMP message to a target host, an attacker may reduce the MTU for a 
given connection. The Mitre ID CAN-2004-1060 is assigned to this issue.

A remote attacker may exploit this issue to degrade the performance of 
TCP connections and partially deny service for legitimate users.

**Update: Microsoft platforms are also reported prone to these issues.

65. Microsoft IPv6 TCP/IP Loopback LAND Denial of Service Vulnerability
BugTraq ID: 13658
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/13658
Summary:
The Microsoft Windows IPv6 TCP/IP stack is prone to a 'loopback' 
condition initiated by sending a TCP packet with the 'SYN' flag set and 
the source address and port spoofed to equal the destination source and 
port.

When a packet of this type is handled, an infinite loop is initiated and 
the affected system halts.

A remote attacker may exploit this issue to deny service for legitimate 
users.

66. AOL You've Got Pictures ActiveX Controls Buffer Overflow Vulnerabilities
BugTraq ID: 20425
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20425
Summary:
AOL You've Got Pictures (YGP) ActiveX controls are prone to multiple 
buffer-overflow vulnerabilities.

A user can invoke the object from a malicious web page to trigger the 
condition. If the vulnerabilities are successfully exploited, this would 
result in a denial-of-service condition due to a runtime error in the 
affected module that crashes the running instance of the client 
application that the object is invoked through (typically Internet 
Explorer). An attacker may also be able to exploit the condition to 
corrupt process memory, resulting in arbitrary code execution. Arbitrary 
code would be executed in the context of the client application.

YGP ScreenSaver and YGP Pic Downloader ActiveX controls are vulnerable 
to these issues.

67. Microsoft Office Malformed Record Remote Code Execution Vulnerability
BugTraq ID: 20384
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20384
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This 
issue occurs when Office attempts to process malformed files.

An attacker could exploit this issue by enticing a victim to load a 
malicious Office file. If the vulnerability is successfully exploited, 
this could result in the execution of arbitrary code in the context of 
the currently logged-in user.

68. Microsoft Windows Object Packager Remote Code Execution Vulnerability
BugTraq ID: 20318
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20318
Summary:
The Microsoft Windows Object Packager is prone to a remote 
code-execution vulnerability.  This issue is due to how the affected 
component handles file extensions.

This vulnerability could let an attacker spoof dialogues, enticing a 
victim into installing a file that has been misrepresented.  A 
successful attack that exploits this vulnerability could result in 
execution of arbitrary code.  An exploit could completely compromise the 
affected computer.

69. MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities
BugTraq ID: 19427
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19427
Summary:
MIT Kerberos 5 is prone to multiple local privilege-escalation 
vulnerabilities because it fails to properly implement 
privilege-dropping functionality when used in conjunction with Linux 2.6 
kernels or with AIX operating systems.

This issue allows local attackers to gain superuser privileges, 
facilitating the complete compromise of affected computers.

70. PHP Live! Help Script File Include Vulnerability
BugTraq ID: 20390
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20390
Summary:
PHP Live! is prone to a file-include vulnerability because it fails to 
sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

71. GNU GZip Archive Handling Multiple Remote Vulnerabilities
BugTraq ID: 20101
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20101
Summary:
The gzip utility is prone to multiple remote buffer-overflow and 
denial-of-service vulnerabilities when handling malicious archive files.

Successful exploits may allow a remote attacker to corrupt process 
memory by triggering an overflow condition. This may lead to arbitrary 
code execution in the context of an affected user and may facilitate a 
remote compromise. Attackers may also trigger denial-of-service 
conditions by crashing or hanging the application.

Specific information regarding affected versions of gzip is currently 
unavailable. This BID will be updated as more information is released.

72. MiniBill Config[Plugin_Dir] Parameter Multiple Remote File Include 
Vulnerabilities
BugTraq ID: 19568
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19568
Summary:
MiniBill is prone to multiple remote file-include vulnerabilities 
because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file 
containing malicious PHP code and execute it in the context of the 
webserver process. This may facilitate a compromise of the application 
and the underlying system; other attacks are also possible.

73. Libmusicbrainz Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19508
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19508
Summary:
The libmusicbrainz library is prone to multiple buffer-overflow 
vulnerabilities because the application fails to check the size of the 
data before copying it into a finite-sized internal memory buffer.

An attacker can exploit these issues to execute arbitrary code within 
the context of the application or to cause a denial-of-service condition.

Versions 2.1.2, SVN 8406, and prior are vulnerable to this issue; other 
versions may also be affected.

74. PPPD Winbind Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 18849
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/18849
Summary:
The 'winbind' plugin of 'pppd' can allow local attackers to gain 
elevated privileges, which may lead to a complete compromise.

Version 2.4.3 of 'pppd' is reported vulnerable. Other versions may be 
affected as well.

75. AWStats AWstats.PL Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17621
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/17621
Summary:
AWStats is prone to multiple cross-site scripting vulnerabilities. These 
issues are due to a failure in the application to properly sanitize 
user-supplied input.

An attacker may leverage these issues to have arbitrary script code 
executed in the browser of an unsuspecting user in the context of the 
affected site. This may help the attacker steal cookie-based 
authentication credentials and launch other attacks.

AWStats version 6.5 (build 1.857) and prior are vulnerable to these issues.

76. Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
BugTraq ID: 18108
Remote: No
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/18108
Summary:
Vixie cron is susceptible to a local privilege-escalation vulnerability. 
This issue is due to the application's failure to properly drop 
superuser privileges in certain circumstances when executing jobs.

This issue allows local attackers that have been authorized to execute 
cron jobs to execute arbitrary commands with superuser privileges. This 
facilitates the complete compromise of affected computers.

Vixie cron version 4.1 is vulnerable to this issue when used in 
conjunction with pam_limits. Other versions may also be affected.

77. Motorola SB4200 Remote Denial of Service Vulnerability
BugTraq ID: 20309
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20309
Summary:
Motorola SB4200 is prone to a remote denial-of-service vulnerability.

This may permit an attacker to crash affected devices, denying further 
network services to legitimate users.

78. Eazy Cart Multiple Input Validation and Authentication Bypass 
Vulnerabilities
BugTraq ID: 20423
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20423
Summary:
Eazy Cart is prone to multiple input-validation and 
authentication-bypass vulnerabilities. These include data-injection, 
cross-site scripting, and authentication-bypass issues because the 
application fails to properly sanitize user-supplied input or to control 
access to administrative functions.

A successful exploit of these vulnerabilities could allow an attacker to 
modify prices and other values when ordering products, steal 
cookie-based authentication credentials from legitimate users of the 
site, or even bypass authentication requirements. Other attacks are also 
possible.

79. Gallery Script Injection Vulnerability
BugTraq ID: 14668
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/14668
Summary:
Gallery is prone to a script-injection vulnerability because it fails to 
properly sanitize user-supplied input.

A malicious user may cause arbitrary script code to execute in the 
browser context of an unsuspecting victim. This may let the attacker 
steal cookie-based authentication credentials in the context of the 
victim's browser; further attacks are also possible.

80. Moodle Blog Module SQL Injection Vulnerability
BugTraq ID: 20395
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20395
Summary:
Moodle is prone to an SQL-injection vulnerability because it fails to 
sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application, access or modify data, or exploit latent vulnerabilities in 
the underlying database implementation.

Moodle 1.6.2 is reported vulnerable; prior versions may also be affected.

81. Webmedia Explorer Core.Lib.PHP Remote File Include Vulnerability
BugTraq ID: 20421
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20421
Summary:
Webmedia Explorer is prone to a remote file-include vulnerability 
because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 2.8.7; other versions may also be affected.

82. EXPBlog Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20420
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20420
Summary:
eXpBlog is prone to multiple cross-site scripting vulnerabilities.

An attacker may leverage this issue to have arbitrary script code 
execute in the browser of an unsuspecting user in the context of the 
affected site. This may help the attacker steal cookie-based 
authentication credentials and launch other attacks.

eXpBlog 0.3.5 and prior versions are affected by these issues.

83. GDB Multiple Vulnerabilities
BugTraq ID: 13697
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/13697
Summary:
GDB is reportedly affected by multiple vulnerabilities. These issues can 
allow an attacker to execute arbitrary code and commands on an affected 
computer. A successful attack may allow the attacker to gain elevated 
privileges or unauthorized access.

The following specific issues were identified:

- a remote heap-overflow vulnerability when loading malformed object files.
- a local privilege-escalation vulnerability.

GDB 6.3 is reportedly affected by these issues; other versions are 
likely vulnerable as well. GNU binutils 2.14 and 2.15 are affected by 
the heap-overflow issue as well.

84. Linksys WRT54GX V2.0 WAN Port UPnP Vulnerability
BugTraq ID: 20415
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20415
Summary:
Linksys WRT54GX V2.0 is prone to a design vulnerability. Reportedly, the 
device offers Universal Plug and Play (UPnP) capabilities on both the 
LAN interface and the WAN Interface when UPnP is enabled.

The design problem manifests itself as a security issue since enabled 
UPnP services on a WAN interface allow a remote user to issue an 
'AddPortMapping' command to the device. An attacker can exploit this 
vulnerability to establish arbitrary ingress port mappings to devices 
normally protected by the routing device.

This issue is reported to affect firmware version 2.00.05; other 
firmware versions may also be affected.

85. Adobe Breeze Unspecified Directory Traversal Vulnerability
BugTraq ID: 20438
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20438
Summary:
Adobe Breeze is prone to a directory-traversal vulnerability because it 
fails to properly sanitize user-supplied input.

This issue could be exploited to reveal files that contain sensitive 
information. The information gained could aid in further attacks against 
the affected computer.

86. KMail HTML Mail Handling Denial Of Service Vulnerability
BugTraq ID: 20369
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20369
Summary:
KMail is prone to an unspecified denial-of-service vulnerability.

An attacker can exploit this issue to crash the affected application, 
denying service to legitimate users.

KMail 1.9.1 and prior versions are vulnerable to this issue.

87. Blue Smiley Organizer Unspecified SQL Injection Vulnerabilities
BugTraq ID: 20417
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20417
Summary:
Blue Smiley Organizer is prone to multiple unspecified SQL-injection 
vulnerabilities because it fails to properly sanitize user-supplied 
input before using it in an SQL query.

A successful attack could allow an attacker to compromise the 
application, access or modify data, gain administrative access to the 
application, or exploit vulnerabilities in the underlying database 
implementation.

Versions prior to 4.46 are vulnerable to these issues.

88. OpenSSH-Portable Existing Password Remote Information Disclosure 
Weakness
BugTraq ID: 20418
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20418
Summary:
It is reported that OpenSSH contains an information disclosure weakness. 
This issue exists in the portable version of OpenSSH. The portable 
version is the version that is distributed for operating systems other 
than its native OpenBSD platform.

This issue has been confirmed as not deriving from either the Pluggable 
Authentication Module (PAM) issue disclosed in BID 11781 in 2004, or the 
more recent Generic Security Services Application
Programming Interface (GSSAPI) based information leak outlined in BID 
20245. It is reported that it is possible to verify access credentials 
for users with an existing system password by measuring SSH 
authentication timing differences.

This weakness allows remote users to test for the existence of valid 
usernames with a password set. Knowledge of system users with 
established passwords may aid in further attacks.

89. Microsoft Windows Graphics Rendering Engine WMF SetAbortProc Code 
Execution Vulnerability
BugTraq ID: 16074
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/16074
Summary:
Microsoft Windows WMF graphics rendering engine is affected by a remote 
code-execution vulnerability. This issue affects the 'SetAbortProc' 
function.

The problem presents itself when a user views a malicious WMF formatted 
file, triggering the vulnerability when the engine attempts to parse the 
file.

The issue may be exploited remotely or locally. Any remote code 
execution that occurs will be with the privileges of the user viewing a 
malicious image. An attacker may gain SYSTEM privileges if an 
administrator views the malicious file.

Local code execution may facilitate a complete compromise.

90. ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
BugTraq ID: 20416
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20416
Summary:
ZABBIX is prone to multiple unspecified remote code-execution 
vulnerabilities.

Reports indicate that these issues facilitate format-string and 
buffer-overflow attacks. A remote attacker may leverage these 
vulnerabilities to trigger denial-of-service conditions or to execute 
arbitrary code to gain unauthorized access to a vulnerable computer. 
This would occur in the context of the application.

ZABBIX version 1.1.2 is reported vulnerable; other versions may be 
affected as well.

91. Digishop Cart.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20297
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20297
Summary:
digiSHOP is prone to a cross-site scripting vulnerability because it 
fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute 
in the browser of an unsuspecting user in the context of the affected 
site. This may help the attacker steal cookie-based authentication 
credentials and launch other attacks.

This issue affects version 4.0.0; other versions may also be vulnerable.

92. AAIPortal Unspecified SQL Injection Vulnerabilities
BugTraq ID: 20414
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20414
Summary:
AAIportal is prone to multiple unspecified SQL-injection vulnerabilities 
because it fails to properly sanitize user-supplied input before using 
it in an SQL query.

A successful attack could allow an attacker to compromise the 
application, access or modify data, gain administrative access to the 
application, or exploit vulnerabilities in the underlying database 
implementation.

AAIportal 1.3.2 and prior versions are vulnerable to these issues.

93. RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
BugTraq ID: 19043
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/19043
Summary:
WinRAR is susceptible to a remote buffer-overflow vulnerability because 
it fails to properly bounds-check user-supplied input before copying it 
to an insufficiently sized memory buffer.

This vulnerability allows attackers to execute arbitrary machine code in 
the context of the affected application.

Versions of WinRAR from 3.0 to 3.60 beta 6 are vulnerable to this issue.

94. Cahier De Textes SQL Injection Vulnerabilities
BugTraq ID: 20389
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20389
Summary:
Cahier de textes is prone to an SQL-injection vulnerability because the 
application fails to properly sanitize user-supplied input before using 
it in an SQL query.

A successful exploit could allow an attacker to compromise the 
application, access or modify data, or exploit vulnerabilities in the 
underlying database implementation.

95. HP-UX Ignite-UX Remote Unauthorized Access and Privilege Escalation 
Vulnerabilities
BugTraq ID: 20269
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20269
Summary:
HP-UX is prone to a remote unauthorized access and privilege-escalation 
vulnerabilities.

Exploiting this issue allows remote attackers to access restricted 
information or to gain administrative privileges on affected computers. 
This facilitates the complete compromise of affected computers.

Further information is currently unavailable. This BID will be updated 
as more information is disclosed.

96. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
BugTraq ID: 20241
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20241
Summary:
Portable OpenSSH is prone to a remote code-execution vulnerability. The 
issue derives from a race condition in a vulnerable signal handler.

Reportedly, under specific conditions, it is theoretically possible to 
execute code remotely prior to authentication when GSSAPI authentication 
is enabled. This has not been confirmed; the chance of a successful 
exploit of this nature is considered minimal.

On non-Portable OpenSSH implementations, this same race condition can be 
exploited to cause a pre-authentication denial of service.

This issue occurs when OpenSSH and Portable OpenSSH are configured to 
accept GSSAPI authentication.

97. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
BugTraq ID: 20216
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20216
Summary:
OpenSSH is prone to a remote denial-of-service vulnerability because it 
fails to properly handle incoming duplicate blocks.

Remote attackers may exploit this issue to consume excessive CPU 
resources, potentially denying service to legitimate users.

This issue occurs only when OpenSSH is configured to accept SSH Version 
One traffic.

98. Python Repr() Function Remote Code Execution Vulnerability
BugTraq ID: 20376
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20376
Summary:
Python is susceptible to a remote code-execution vulnerability because 
the application fails to properly handle UTF-32/UCS-4 strings.

This issue allows remote attackers to execute arbitrary machine code 
with the privileges of the python application.

99. OpenSSL Public Key Processing Denial of Service Vulnerability
BugTraq ID: 20247
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20247
Summary:
OpenSSL is prone to a denial-of-service vulnerability because it fails 
to validate the lengths of public keys being used.

An attacker can exploit this issue to crash an affected server using 
OpenSSL.

100. OpenSSL SSLv2 Null Pointer Dereference Client Denial of Service 
Vulnerability
BugTraq ID: 20246
Remote: Yes
Last Updated: 2006-10-11
Relevant URL: http://www.securityfocus.com/bid/20246
Summary:
OpenSSL is prone to a denial-of-service vulnerability.

A malicious server could cause a vulnerable client application to crash, 
effectively denying service.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Google Code Search peers into programs' flaws
By: Robert Lemos
Security professionals warn coders that they need to be aware that their 
open-source repositories are now searchable, allowing attackers to 
target programs that are likely to be flawed.
http://www.securityfocus.com/news/11417

2. Mozilla flaws more joke than jeopardy
By: Robert Lemos
Two ToorCon presenters razz the open-source browser group for an alleged 
flawed implementation of Javascript, but the lecture appears to be more 
stand-up comedy than  substantiative research.
http://www.securityfocus.com/news/11416

3. Tag-team attack exploits IE flaw
By: Robert Lemos
Attackers exploit a zero-day vulnerability to cause a large number of 
Web sites to send their visitors to rogue pages carrying a second 
attack, this time against Microsoft's Internet Explorer.
http://www.securityfocus.com/news/11415

4. HP chief apologizes, denies he knew of hacking
By: Robert Lemos
Hewlett-Packard's CEO Mark Hurd immediately replaces former chairperson 
Patricia Dunn as the company acknowledges it knew about the "pretexting" 
but not about the "hacking."
http://www.securityfocus.com/news/11414

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Database Security Engineer, Tel-Aviv
http://www.securityfocus.com/archive/77/448308

2. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/448323

3. [SJ-JOB] Sales Engineer, New York City
http://www.securityfocus.com/archive/77/448324

4. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/448325

5. [SJ-JOB] Developer, Redwood Shores
http://www.securityfocus.com/archive/77/448332

6. [SJ-JOB] Compliance Officer, Toronto
http://www.securityfocus.com/archive/77/448305

7. [SJ-JOB] Application Security Architect, Minneapolis
http://www.securityfocus.com/archive/77/448306

8. [SJ-JOB] Threat Analyst, Lexington
http://www.securityfocus.com/archive/77/448314

9. [SJ-JOB] Security Researcher, Seattle/Redmond
http://www.securityfocus.com/archive/77/448315

10. [SJ-JOB] Technical Writer, Superior
http://www.securityfocus.com/archive/77/448319

11. [SJ-JOB] Senior Software Engineer, Superior
http://www.securityfocus.com/archive/77/448320

12. [SJ-JOB] Security Researcher, Herndon
http://www.securityfocus.com/archive/77/448317

13. [SJ-JOB] Security Consultant, Denver
http://www.securityfocus.com/archive/77/448262

14. [SJ-JOB] Security Engineer, Livermore
http://www.securityfocus.com/archive/77/448279

15. [SJ-JOB] Security Researcher, Marlboro
http://www.securityfocus.com/archive/77/448281

16. [SJ-JOB] Security Engineer, Boston
http://www.securityfocus.com/archive/77/448260

17. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/448263

18. [SJ-JOB] Quality Assurance, Superior
http://www.securityfocus.com/archive/77/448247

19. [SJ-JOB] Management, Columbia
http://www.securityfocus.com/archive/77/448249

20. [SJ-JOB] Developer, Superior
http://www.securityfocus.com/archive/77/448259

21. [SJ-JOB] Jr. Security Analyst, Palm Beach Gardens
http://www.securityfocus.com/archive/77/448261

22. [SJ-JOB] Security Architect, McLean
http://www.securityfocus.com/archive/77/448248

23. [SJ-JOB] Management, Atlanta
http://www.securityfocus.com/archive/77/448246

24. [SJ-JOB] Sr. Security Analyst, Beaverton
http://www.securityfocus.com/archive/77/448252

25. [SJ-JOB] Security Consultant, Columbus
http://www.securityfocus.com/archive/77/448181

26. [SJ-JOB] Security Engineer, Atlanta
http://www.securityfocus.com/archive/77/448191

27. [SJ-JOB] Application Security Architect, Phoenix
http://www.securityfocus.com/archive/77/448192

28. [SJ-JOB] Software Engineer, New York
http://www.securityfocus.com/archive/77/448194

29. [SJ-JOB] Developer, Sunnyvale
http://www.securityfocus.com/archive/77/448195

30. [SJ-JOB] Security Researcher, San Jose
http://www.securityfocus.com/archive/77/448177

31. [SJ-JOB] Database Security Engineer, San Diego
http://www.securityfocus.com/archive/77/448179

32. [SJ-JOB] Sr. Security Analyst, Central Missouri
http://www.securityfocus.com/archive/77/448180

33. [SJ-JOB] Security Engineer, New York City
http://www.securityfocus.com/archive/77/448188

34. [SJ-JOB] Technical Support Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/448178

35. [SJ-JOB] Sales Engineer, NY or NJ
http://www.securityfocus.com/archive/77/448146

36. [SJ-JOB] Quality Assurance, Sunnyvale
http://www.securityfocus.com/archive/77/448175

37. [SJ-JOB] Forensics Engineer, Arlington
http://www.securityfocus.com/archive/77/448145

38. [SJ-JOB] Regional Channel Manager, Miami
http://www.securityfocus.com/archive/77/448134

39. [SJ-JOB] Regional Channel Manager, New York
http://www.securityfocus.com/archive/77/448139

40. [SJ-JOB] Sr. Security Engineer, Hampshire or Dorset
http://www.securityfocus.com/archive/77/448142

41. [SJ-JOB] Application Security Engineer, Seattle
http://www.securityfocus.com/archive/77/448143

42. [SJ-JOB] MOD CLAS Consultant, Hampshire or Dorset
http://www.securityfocus.com/archive/77/448144

43. [SJ-JOB] Sr. Security Analyst, Charlotte
http://www.securityfocus.com/archive/77/448131

44. [SJ-JOB] VP of Regional Sales, Berkshire
http://www.securityfocus.com/archive/77/448133

45. [SJ-JOB] Sales Representative, Charlotte or Raleigh
http://www.securityfocus.com/archive/77/448135

46. [SJ-JOB] Management, Plantation
http://www.securityfocus.com/archive/77/448136

47. [SJ-JOB] Security Consultant, Frankfurt/Main
http://www.securityfocus.com/archive/77/448127

48. [SJ-JOB] Security Consultant, Maidenhead, Berkshire
http://www.securityfocus.com/archive/77/448128

49. [SJ-JOB] Sales Engineer, New York Area
http://www.securityfocus.com/archive/77/448129

50. [SJ-JOB] Senior Software Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/448130

V.   INCIDENTS LIST SUMMARY
---------------------------
1. RES: Massive SPAM Increase
http://www.securityfocus.com/archive/75/448183

2. Policyd-weight: WAS: Massive SPAM Increase
http://www.securityfocus.com/archive/75/448063

3. Massive SPAM Increase
http://www.securityfocus.com/archive/75/447979

4. site probe
http://www.securityfocus.com/archive/75/447797

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Fuzzing KDE based apps (narrowing down bugs)
http://www.securityfocus.com/archive/82/448138

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. security implications of disabling WMI service
http://www.securityfocus.com/archive/88/448141

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Dynamic firewall based on bandwidth usage ?
http://www.securityfocus.com/archive/91/448124

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to 
[email protected] from the subscribed address. The 
contents of the subject or message body do not matter. You will receive 
a confirmation request message to which you will have to answer. 
Alternatively you can also visit 
http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and 
ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to 
compromise confidential information, steal cookies and create requests 
that can be mistaken
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000Cc5Y