SecurityFocus Newsletter #383

[email protected] 11 Jan 2007 00:17:58 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #383
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

Hack Yourself- Finding Web Application Security Holes- White Paper
Learn how to defend against Web Application Attacks with real-world examples of recent hacking methods such as: SQL Injection, Cross Site Scripting and Parameter Manipulation. Learn step-by-step vulnerability testing methods for your own Web Applications and guidelines for establishing best administration and coding practices.  
Download *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=70160000000CgNW

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Wireless Forensics: Tapping the Air - Part Two
       2. PHP apps: Security's Low-Hanging Fruit
II.   BUGTRAQ SUMMARY
       1. GNU GV Stack Buffer Overflow Vulnerability
       2. ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
       3. Fetchmail Remote Denial of Service Vulnerability
       4. Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
       5. GeoIP GeoIPUpdate.C Directory Traversal Vulnerability
       6. KSirc IRC Client Remote PRIVMSG Denial of Service Vulnerability
       7. Sina UC BROWSER2UC.DLL ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
       8. Microsoft Windows Vector Markup Language Buffer Overrun Vulnerability
       9. Cisco IOS Data-link Switching Denial Of Service Vulnerability
       10. ProFTPD MOD_TLS Remote Buffer Overflow Vulnerability
       11. ProFTPD SReplace Remote Buffer Overflow Vulnerability
       12. F5 Firepass Multiple Input Validation Vulnerabilities
       13. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
       14. MediaWiki AJAX Unspecified Cross-Site Scripting Vulnerability
       15. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
       16. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
       17. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
       18. Mozilla Firefox Large History File Buffer Overflow Vulnerability
       19. Direct Web Rendering Multiple Remote Vulnerabilities
       20. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
       21. B2evolution Login.PHP Cross-Site Scripting Vulnerability
       22. Application Enhancer Local Privilege Escalation Vulnerability
       23. Fetchmail Multiple Password Information Disclosure Vulnerabilities
       24. Microsoft Office Brazilian Portuguese Grammar Checker Remote Code Execution Vulnerability
       25. Microsoft Excel IMDATA Record Remote Code Execution Vulnerability
       26. Microsoft Excel Malformed String Remote Code Execution Vulnerability
       27. GraphicsMagick PALM DCM Buffer Overflow Vulnerabilities
       28. GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
       29. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
       30. ImageMagick File Name Handling Remote Format String Vulnerability
       31. Snort Backtracking Denial of Service Vulnerability
       32. Avahi Unauthorized Data Manipulation Vulnerability
       33. W3M SSL Certificate Format String Vulnerability
       34. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
       35. Links ELinks SMBClient Remote Command Execution Vulnerability
       36. Microsoft Windows Explorer WMF File Denial of Service Vulnerability
       37. MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
       38. MIT Kerberos Administration Daemon Free Pointers Remote Code Execution Vulnerability
       39. Mono System.CodeDom.Compiler Class Insecure Temporary File Creation Vulnerability
       40. Secure Locate Local Information Disclosure Vulnerability
       41. Cisco Unified Contact Center and IP Contact Center JTapi Gateway Denial of Service Vulnerability
       42. phpMyAdmin Multiple Unspecified Input Validation Vulnerabilities
       43. X.Org DBE And Render Extensions Multiple Integer Overflow Vulnerabilities
       44. Kaspersky Anti-Virus Unspecified Denial Of Service Vulnerability
       45. WordPress Wp-trackback.PHP SQL Injection Vulnerability
       46. Linux Kernel Unw_Unwind_To_User Local Denial of Service Vulnerability
       47. Linux Kernel PPP Driver Unspecified Remote Denial Of Service Vulnerability
       48. Adobe Acrobat Reader Unspecified Heap Corruption Vulnerability
       49. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow Vulnerabilities
       50. Linux kernel Uselib() Local Privilege Escalation Vulnerability
       51. Apple Mac OS X Finder DMG Volume Memory Corruption Vulnerability
       52. Linux Kernel User Triggerable BUG() Unspecified Local Denial of Service Vulnerability
       53. Adobe ColdFusion Information Disclosure Vulnerability
       54. Yet Another Link Directory Yald.PHP HTML Injection Vulnerability
       55. Adobe Reader Plugin Open Parameters Cross-Site Scripting Vulnerability
       56. Linux Kernel ELF Binary Loading Denial Of Service Vulnerability
       57. Linux Kernel Local Denial Of Service And Memory Disclosure Vulnerabilities
       58. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
       59. Linux Kernel 2.4 RTC Handling Routines Memory Disclosure Vulnerability
       60. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
       61. Linux Kernel Coda_Pioctl Local Buffer Overflow Vulnerability
       62. Linux Kernel ELF Loader Mismatched Architecture Local Denial of Service Vulnerability
       63. Linux Kernel USB io_edgeport Driver Local Integer Overflow Vulnerability
       64. Linux Kernel Multiple Local Vulnerabilities
       65. Linux Kernel MIPS Ptrace Local Privilege Escalation Vulnerability
       66. Linux Kernel SMBFS Multiple Remote Vulnerabilities
       67. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
       68. Linux Kernel Symmetrical Multiprocessing Page Fault Local Privilege Escalation Vulnerability
       69. Linux Kernel Floating Point Register Contents Leak Vulnerability
       70. Linux Kernel USB Driver Uninitialized Structure Information Disclosure Vulnerability
       71. Linux Kernel Unspecified Local Denial of Service Vulnerability
       72. Linux Kernel Multiple Device Driver Vulnerabilities
       73. iPlanet Web Server Search Module Cross-Site Scripting Vulnerability
       74. Computer Associates BrightStor ARCserve Backup Tape Engine Remote Buffer Overflow Vulnerability
       75. Linux Kernel Panic Function Call Buffer Overflow Vulnerability
       76. Linux Kernel Invalid Proc Memory Access Local Denial of Service Vulnerability
       77. Edit-X Edit_Address.PHP Remote File Include Vulnerability
       78. Acme Thttpd Insecure Temporary Logfile Creation Vulnerability
       79. Linux kernel do_fork() Memory Leakage Vulnerability
       80. Axiom Photo Gallery Template.PHP Remote File Include Vulnerability
       81. EF Commander ISO File Remote Buffer Overflow Vulnerability
       82. GNU Tar GNUTYPE_NAMES Remote Directory Traversal Vulnerability
       83. BZip2 CHMod File Permission Modification Race Condition Weakness
       84. Easy Banner Pro info.PHP Remote File Include Vulnerability
       85. GnuPG Make_Printable_String Remote Buffer Overflow Vulnerability
       86. MADWiFi Linux Kernel Device Driver Multiple Remote Buffer Overflow Vulnerabilities
       87. uniForum WBSearch.ASPX SQL Injection Vulnerability
       88. Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
       89. Magic Photo Storage Website Multiple Remote File Include Vulnerabilities
       90. Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
       91. Intervations FileCopa LIST Command Remote Buffer Overflow Vulnerability
       92. Solaris RPC Request Denial of Service Vulnerability
       93. Adobe Flash Player Plugin HTTP Header Injection Weakness
       94. MOTIONBORG Web Real Estate Admin_Check_User.ASP SQL Injection Vulnerability
       95. KOffice PPT Files Integer Overflow Vulnerability
       96. PHPKit Comment.PHP SQL Injection Vulnerability
       97. LibGSF Remote Heap Buffer Overflow Vulnerability
       98. PPC Search Engine INC Parameter Multiple Remote File Include Vulnerabilities
       99. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
       100. TIS Firewall Toolkit FTP-GW Remote Buffer Overflow Vulnerability
III.  SECURITYFOCUS NEWS
       1. E-voting flaws put Florida in spotlight again
       2. Bots, breaches and bugs plague 2006
       3. Stock scammer gets coal for the holidays
       4. PHP security under scrutiny
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Application Security Engineer, Palo Alto
       2. [SJ-JOB] Security Engineer, Mountain View
       3. [SJ-JOB] Software Engineer, Palo Alto
       4. [SJ-JOB] Technology Risk Consultant, Mountain View
       5. [SJ-JOB] Forensics Engineer, Foster City
       6. [SJ-JOB] Software Engineer, Palo Alto
       7. [SJ-JOB] Manager, Information Security, Zurich
       8. [SJ-JOB] Security Architect, St. Louis
       9. [SJ-JOB] Technical Support Engineer, Berkshire
       10. [SJ-JOB] Jr. Security Analyst, DC
       11. [SJ-JOB] Sr. Security Analyst, Skokie
       12. [SJ-JOB] Information Assurance Analyst, New York
       13. [SJ-JOB] Director, Information Security, New York
       14. [SJ-JOB] Sales Representative, San Diego
       15. [SJ-JOB] Incident Handler, Portland
       16. [SJ-JOB] Security Auditor, Bellevue
       17. [SJ-JOB] Security System Administrator, Toronto
       18. [SJ-JOB] Security Consultant, Dubai
       19. [SJ-JOB] Sr. Security Engineer, Roseland
       20. [SJ-JOB] Penetration Engineer, London/South/UK Wide
       21. [SJ-JOB] Security Researcher, London/Reading
       22. [SJ-JOB] Application Security Engineer, Anywhere
       23. [SJ-JOB] Senior Software Engineer, Atlanta
       24. [SJ-JOB] Sr. Security Analyst, Charlotte
       25. [SJ-JOB] Compliance Officer, Reston
       26. [SJ-JOB] Management, New York
       27. [SJ-JOB] Manager, Information Security, Towson
       28. [SJ-JOB] Sr. Security Engineer, Atlanta
       29. [SJ-JOB] Sr. Security Analyst, Vancouver
V.    INCIDENTS LIST SUMMARY
       1. Bruteforce attack against smtp-auth
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Remote exploit for CA brightstor tapeeng (win2k SP4)
       2. .Net Debug
       3. Debugger
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Deploying Microsoft SMS in a DMZ
       2. How to deploy Microsoft OWA without using ISA?
       3. SecurityFocus Microsoft Newsletter #323
       4. Secure Remote access - windows 2003
VIII. SUN FOCUS LIST SUMMARY
       1. Solaris 2.7 Daylight saving time fix.
IX.   LINUX FOCUS LIST SUMMARY
       1. SF new article announcement: Wireless Forensics: Tapping the Air - Part Two (fwd)
       2. SF new column announcement: PHP apps - Security's Low-Hanging Fruit (fwd)
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Wireless Forensics: Tapping the Air - Part Two
By Raul Siles, GSE
This two-part series looks at the issues associated with collecting and analyzing network traffic from wireless networks in an accurate and comprehensive way; a discipline known as wireless forensics. Part two focuses on the technical challenges for wireless traffic analysis, advanced anti-forensic techniques that could thwart a forensic investigation, and some legal considerations for both the U.S. and Europe.
http://www.securityfocus.com/infocus/1885

2. PHP apps: Security's Low-Hanging Fruit
By Kelly Martin
PHP has become the most popular application language on the web, but common security mistakes by developers are giving PHP a bad name. Here's how PHP coding errors have become the new low-hanging fruit for attackers, contributing to the phishing problems on the web. 
http://www.securityfocus.com/columnists/427


II.  BUGTRAQ SUMMARY
--------------------
1. GNU GV Stack Buffer Overflow Vulnerability
BugTraq ID: 20978
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/20978
Summary:
GNU gv is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. 

Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application. Failed attempts will likely crash the application, resulting in denial-of-service conditions.

Version 3.6.2 is reported vulnerable; other versions may also be affected.

NOTE: Various other applications may employ embedded GNU gv code and could also be vulnerable as a result.

2. ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 21185
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21185
Summary:
ImageMagick is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.

3. Fetchmail Remote Denial of Service Vulnerability
BugTraq ID: 21902
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21902
Summary:
Fetchmail is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions. 

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

4. Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 21183
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21183
Summary:
Dovecot is prone to an off-by-one buffer-overflow condition due to an error that results in insufficient memory allocation.

An attacker may exploit this issue to trigger denial-of-service conditions. Presumably, arbitrary code execution may be possible as well.

Versions 1.0test53 to 1.0.rc14 are vulnerable.

5. GeoIP GeoIPUpdate.C Directory Traversal Vulnerability
BugTraq ID: 21959
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21959
Summary:
The 'geoip' application is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks. 

This issue affects versions prior to 1.4.0.

6. KSirc IRC Client Remote PRIVMSG Denial of Service Vulnerability
BugTraq ID: 21790
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21790
Summary:
KSirc is prone to a remote denial-of-service vulnerability. 

The issue arises when the client handles excessive string data. By exploiting this issue, a remote attacker may cause an affected client to crash. 

KSirc 1.3.12 is vulnerable to this issue; other versions may also be affected.

The vendor states this issue cannot be exploited to execute arbitrary code. Successful exploits will, however, result in denial-of-service conditions in the client.

7. Sina UC BROWSER2UC.DLL ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
BugTraq ID: 21958
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21958
Summary:
Sina UC ActiveX control is prone to multiple remote stack-based buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.

Exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.

Sina UC 2006 and prior versions are vulnerable to this issue.

8. Microsoft Windows Vector Markup Language Buffer Overrun Vulnerability
BugTraq ID: 21930
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21930
Summary:
Microsoft Windows is prone to a buffer-overrun vulnerability that arises because of an error in the processing of Vector Markup Language documents.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application.

9. Cisco IOS Data-link Switching Denial Of Service Vulnerability
BugTraq ID: 21990
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21990
Summary:
CISCO IOS Data-link Switching (DLSw) is prone to a denial-of-service vulnerability.

Only network appliances that have the affected service enabled are vulnerable to this issue. To exploit this issue, attackers must be able to connect to the affected service. 

Attackers can exploit this issue to cause a reload of the affected service, effectively denying further service to legitimate users.

This issue affects all CISCO routers using Cisco IOS   Software versions 11.0 through 12.4.

This issue is being tracked by the Cisco Bug ID: CSCsf28840

10. ProFTPD MOD_TLS Remote Buffer Overflow Vulnerability
BugTraq ID: 21326
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21326
Summary:
ProFTPD is prone to a remote buffer-overflow vulnerability.

Exploiting this issue allows remote attackers to cause a buffer overflow, to corrupt memory, and to execute arbitrary machine code in the context of the server application, facilitating the compromise of affected computers.

ProFTPD 1.3.0a and prior versions are vulnerable to this issue.

11. ProFTPD SReplace Remote Buffer Overflow Vulnerability
BugTraq ID: 20992
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/20992
Summary:
ProFTPD is prone to an remote buffer-overflow vulnerability. This issue is due to an off-by-one error, allowing attackers to corrupt memory.

Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the server application, facilitating the compromise of affected computers.

ProFTPD versions prior to 1.3.0a are vulnerable to this issue.

Update: This BID was recently updated to state that 'CommandBufferSize' was affected by a denial-of-service issue, but according to the vendor, that directive is not vulnerable.

12. F5 Firepass Multiple Input Validation Vulnerabilities
BugTraq ID: 21957
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21957
Summary:
F5 Firepass is prone to multiple input-validation vulnerabilities because the device fails to sufficiently sanitize user-supplied input. These issues include information-disclosure, security bypass, and cross-site scripting vulnerabilities.

An attacker can exploit these issues to bypass security restrictions, to view sensitive information, and to steal cookie-based authentication credentials. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

13. Mozilla Thunderbird Multiple Remote Information Disclosure Vulnerabilities
BugTraq ID: 16881
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/16881
Summary:
Mozilla Thunderbird is susceptible to multiple remote information-disclosure vulnerabilities. These issues are due to the application's failure to properly enforce the restriction for downloading remote content in email messages.

These issues allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also exploit these issues to know whether and when users read email messages.

Mozilla Thunderbird version 1.5 is vulnerable to these issues; other versions may also be affected.

14. MediaWiki AJAX Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 21956
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21956
Summary:
MediaWiki is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects the following versions:

Branch 1.9 versions prior to 1.9.0rc2
Branch 1.8 versions prior to 1.8.3
Branch 1.7 versions prior to 1.7.2
Branch 1.6 versions prior to 1.6.9

15. Multiple Mozilla Products IFRAME JavaScript Execution Vulnerability
BugTraq ID: 16770
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/16770
Summary:
Multiple Mozilla products are prone to a script-execution vulnerability. 

The vulnerability presents itself when an attacker supplies a specially crafted email to a user containing malicious script code in an IFRAME and the user tries to reply to the mail. Arbitrary JavaScript can be executed even if the user has disabled JavaScript execution in the client. 

The following mozilla products are vulnerable to this issue:
- Mozilla Thunderbird, versions prior to 1.5.0.2, and prior to 1.0.8
- Mozilla SeaMonkey, versions prior to 1.0.1
- Mozilla Suite, versions prior to 1.7.13

16. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

17. Multiple Mozilla Products Memory Corruption/Code Injection/Access Restriction Bypass Vulnerabilities
BugTraq ID: 16476
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/16476
Summary:
Multiple Mozilla products are prone to multiple vulnerabilities. These issues include various memory-corruption, code-injection, and access-restriction-bypass vulnerabilities. Other undisclosed issues may have also been addressed in the various updated vendor applications.

Successful exploitation of these issues may permit an attacker to execute arbitrary code in the context of the affected application. This may facilitate a compromise of the affected computer; other attacks are also possible.

18. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial-of-service vulnerability. 

This issue presents itself when the browser handles a large entry in the 'history.dat' file. An attacker may trigger this issue by enticing a user to visit a malicious website and by supplying excessive data to be stored in the affected file. 

This may cause a denial-of-service condition. 

**UPDATE: Proof-of-concept exploit code has been published. The author of the code attributes the crash to a buffer-overflow condition. Symantec has not reproduced the alleged flaw.

19. Direct Web Rendering Multiple Remote Vulnerabilities
BugTraq ID: 21955
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21955
Summary:
Direct Web Rendering is prone to multiple remote vulnerabilities, including a security-bypass issue and a denial-of-service issue. 

 An attacker can exploit these issues to access restricted methods and to crash the affected application, denying service to legitimate users. Other attacks are also possible. 

These issues affect versions prior to 1.1.4.

20. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
BugTraq ID: 21673
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21673
Summary:
The Sun Java Runtime Environment is prone to multiple remote privilege-escalation vulnerabilities. 

An attacker can execute arbitrary code and commands in the context of a user who invokes the Java applet or application. 

A successful attack can facilitate privilege escalation.

21. B2evolution Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 21953
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21953
Summary:
B2evolution is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects version 1.8.6; other versions may also be vulnerable.

22. Application Enhancer Local Privilege Escalation Vulnerability
BugTraq ID: 21951
Remote: No
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21951
Summary:
Application Enhancer is prone to a local privilege-escalation vulnerability. 

Local attackers can gain superuser privileges by patching the 'ApplicationEnhancer' binary or by replacing it. The 'aped' process is launched with root privileges, which enables privilege escalation if the 'ApplicationEnhancer' binary is maliciously modified. 

Application Enhancer 2.0.2 running on Mac OS X 10.4.8 (8L2127) x86 is vulnerable to this issue; other versions may also be affected.

23. Fetchmail Multiple Password Information Disclosure Vulnerabilities
BugTraq ID: 21903
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21903
Summary:
Fetchmail is prone to multiple information-disclosure vulnerabilities. These issues occur because the application discloses information about user passwords.

An attacker can exploit these issue to access sensitive information that may aid the attacker in other attacks.

These issue affects version prior to 6.3.6-rc4

24. Microsoft Office Brazilian Portuguese Grammar Checker Remote Code Execution Vulnerability
BugTraq ID: 21942
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21942
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This issue occurs when the application processes certain Office files.

Note that this issue may not be exploited automatically through email. For an attack to succeed, a victim must manually open an attachment sent by email or obtained through other means. 

An attacker may exploit this issue to execute arbitrary code in the context of the currently logged-in user.

This issue affects the Microsoft Office 2003 Brazilian Grammar Checker application used in various Microsoft applications that have Brazilian Portuguese language support.

25. Microsoft Excel IMDATA Record Remote Code Execution Vulnerability
BugTraq ID: 21856
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21856
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers can exploit this issue to execute arbitrary code with the privileges of the user running the application, which can result in the compromise of affected computers.

26. Microsoft Excel Malformed String Remote Code Execution Vulnerability
BugTraq ID: 21877
Remote: Yes
Last Updated: 2007-01-09
Relevant URL: http://www.securityfocus.com/bid/21877
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, which could result in the compromise of affected computers.

27. GraphicsMagick PALM DCM Buffer Overflow Vulnerabilities
BugTraq ID: 20707
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/20707
Summary:
GraphicsMagick is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.

Successful exploits may allow an attacker to execute arbitrary machine code to compromise an affected computer or to cause denial-of-service conditions.

GraphicsMagick 1.1.7 and prior versions are vulnerable.

28. GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
BugTraq ID: 21650
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21650
Summary:
GNU Wget is prone to a remote denial-of-service vulnerability.

Exploiting this issue allows remote attackers to crash the application, denying further service to legitimate users.

Version 1.10.2 is vulnerable; other versions may also be affected.

29. ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19507
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/19507
Summary:
ImageMagick is prone to a remote heap buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.

ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.

30. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability. 

Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user. 

Note that there are other attack vectors that may not require user interaction, since the application can be used with custom printing systems and web applications. 

A successful attack may crash the application or lead to arbitrary code execution. 

All versions of ImageMagick are considered vulnerable at the moment.

31. Snort Backtracking Denial of Service Vulnerability
BugTraq ID: 21991
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21991
Summary:
Snort is prone to a denial-of-service vulnerability because the network intrusion detection (NID) system fails to handle specially crafted network packets. 

An attacker can exploit this issue to cause the affected NID system to consume 100% CPU resources, allowing malicious network traffic to avoid detection.

This issue affects versions prior to 2.6.1.

32. Avahi Unauthorized Data Manipulation Vulnerability
BugTraq ID: 21016
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21016
Summary:
Avahi is prone to a vulnerability that may allow remote attackers to manipulate the service.
 
Avahi versions prior to 0.6.15 are vulnerable.

33. W3M SSL Certificate Format String Vulnerability
BugTraq ID: 21735
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21735
Summary:
W3M is prone to a format-string vulnerability.  This issue can occur when the browser processes SSL certificates that include format specifiers.

A successful exploit could result in the execution of arbitrary code in the context of the user running the browser.

The vulnerability was reported to affect version 0.5.1; prior versions could also be affected.

34. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 21668
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21668
Summary:
The Mozilla Foundation has released nine security advisories specifying vulnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- inject arbitrary content
- gain escalated privileges
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

35. Links ELinks SMBClient Remote Command Execution Vulnerability
BugTraq ID: 21082
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21082
Summary:
Links and ELinks are prone to a remote command-execution vulnerability because the applications fail to properly process website data containing smb commands.

An attacker can exploit this issue to execute arbitrary smb commands on a victim computer. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Links version 1.00pre12 and ELinks version 0.11.1 are reportedly vulnerable; other versions may also be affected.

NOTE: This vulnerability may be exploited only if 'smbclient' is installed on a target computer.

36. Microsoft Windows Explorer WMF File Denial of Service Vulnerability
BugTraq ID: 21992
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21992
Summary:
Microsoft Windows Explorer is prone to a denial-of-service vulnerability.
 
A remote attacker may exploit this vulnerability by presenting a malicious file to a victim user and enticing them to open it with the vulnerable application. Users that simply browse folders containing the malicious file will also trigger this issue.

It is not known at this time if this issue can be leveraged to execute arbitrary code; this BID will be updated as further information becomes available.

37. MIT Kerberos 5 RPC Library Remote Code Execution Vulnerability
BugTraq ID: 21970
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21970
Summary:
MIT Kerberos 5 is prone to a remote code-execution vulnerability. This issue resides in the server-side portion of the Kerberos RPC library. Currently, the 'kadmind' service is known to be vulnerable, but other applications that use this library may also be affected.

An attacker can exploit this issue to execute arbitrary code with administrative privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service. After a Kerberos database computer has been compromised, attackers may gain unauthorized access to
other services that rely on the Kerberos infrastructure for authentication.

38. MIT Kerberos Administration Daemon Free Pointers Remote Code Execution Vulnerability
BugTraq ID: 21975
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21975
Summary:
MIT Kerberos 5 is prone to a remote code-execution vulnerability.

This issue occurs because of memory-management problems in the abstraction interface of the GSS-API implementation.

An attacker can exploit this issue to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will likely result in a denial-of-service conditions.

This issue also affects third-party applications using the affected API.

39. Mono System.CodeDom.Compiler Class Insecure Temporary File Creation Vulnerability
BugTraq ID: 20340
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/20340
Summary:
The Mono 'System.CodeDom.Compiler' class creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application. 

Successfully exploiting a symlink attack may allow an attacker to overwrite or corrupt sensitive files. This may result in a denial of service; other attacks may also be possible.

Versions 1.0 and 2.0 are vulnerable; other versions may also be affected.

40. Secure Locate Local Information Disclosure Vulnerability
BugTraq ID: 21989
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21989
Summary:
Secure Locate is prone to a local information-disclosure vulnerability because the utility fails to properly interpret filesystem permissions.
 
 Successfully exploiting this issue allows attackers to gain access to the names of files located in directories they do not have permissions to access. Information that attackers harvest may aid them in further attacks.
 
 Secure Locate 3.1 is vulnerable to this issue; other versions may also be affected.

41. Cisco Unified Contact Center and IP Contact Center JTapi Gateway Denial of Service Vulnerability
BugTraq ID: 21988
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21988
Summary:
Cisco Unified Contact Center and IP Contact Center are prone to a vulnerability that can cause the applications to restart and subsequently cause temporary denial-of-service conditions.

An attacker can exploit this issue to cause the vulnerable JTapi Gateway service to restart. Since the restart process can take several minutes, no new connections will be processed during that time, which effectively means a denial of service for legitimate users.

42. phpMyAdmin Multiple Unspecified Input Validation Vulnerabilities
BugTraq ID: 21987
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21987
Summary:
phpMyAdmin is prone to multiple input-validation vulnerabilities, including multiple HTML-injection issues and other unspecified vulnerabilities.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. Other attacks are also possible.

Version 2.9.1.1 is vulnerable to this issue; other versions may also be affected.

43. X.Org DBE And Render Extensions Multiple Integer Overflow Vulnerabilities
BugTraq ID: 21968
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21968
Summary:
X.Org is prone to multiple integer-overflow vulnerabilities.

Attackers can exploit this issue to execute arbitrary code with superuser privileges. A successful exploit will result in the complete compromise of affected computers. Failed exploit attempts will likely result in denial-of-service conditions.

44. Kaspersky Anti-Virus Unspecified Denial Of Service Vulnerability
BugTraq ID: 16942
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/16942
Summary:
Kaspersky Anti-Virus is prone to a denial-of-service vulnerability. This is due to a failure in the application to handle unspecified files. 

Attackers could cause the application to consume excessive CPU and memory resources, resulting in a denial of service.

Versions 5.0.5 and 5.5.3 of Kaspersky Anti-Virus for UNIX are vulnerable to this issue; other versions and platforms may also be affected.

Further details about this vulnerability are currently unavailable. This BID will be updated as more information is disclosed.

Note that the vendor cannot reproduce this issue.

45. WordPress Wp-trackback.PHP SQL Injection Vulnerability
BugTraq ID: 21983
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21983
Summary:
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Successful exploits may result in unauthorized access.

WordPress 2.0.6 and prior versions are vulnerable.

46. Linux Kernel Unw_Unwind_To_User Local Denial of Service Vulnerability
BugTraq ID: 13266
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/13266
Summary:
A local denial-of-service vulnerability affects the Linux kernel. 

A local attacker may leverage this issue to cause an affected Linux kernel to panic, effectively denying service to legitimate users.

47. Linux Kernel PPP Driver Unspecified Remote Denial Of Service Vulnerability
BugTraq ID: 12810
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12810
Summary:
Linux Kernel (Point-to-Point Protocol) PPP Driver is reported prone to an unspecified remote denial-of-service vulnerability. 

A successful attack can cause a denial-of-service condition in the server and can prevent access to legitimate users. 

Linux Kernel 2.6.8 was reported vulnerable. Subsequent versions may be affected as well. 

Due to a lack of details, further information is not available at the moment. This BID will be updated when more information becomes available.

48. Adobe Acrobat Reader Unspecified Heap Corruption Vulnerability
BugTraq ID: 21981
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21981
Summary:
Adobe Acrobat Reader is prone to a heap-based buffer-overflow vulnerability because the application fails to properly bounds-check malicious PDF files, resulting in a heap-based buffer overflow. 

Successfully exploiting this issue may allow a remote attacker to execute arbitrary code in the context of the victim user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions. 

An attacker could exploit this issue by enticing a victim to open a malicious PDF file.

49. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow Vulnerabilities
BugTraq ID: 12195
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12195
Summary:
The MOXA serial driver in the Linux kernel is reported prone to multiple buffer-overflow vulnerabilities. The driver fails to perform proper bounds checks before copying user-supplied data to fixed-size memory buffers. 

These vulnerabilities reside in the 'drivers/char/moxa.c' file. 

The vulnerable functions perform a 'copy_from_user()' call to copy user-supplied, user-space data to a fixed-size, static kernel memory buffer (moxaBuff) of 10240 bytes in length while using the user-supplied length argument as passed from 'MoxaDriverIoctl()'. This reportedly results in improperly bounded operations, potentially causing locally exploitable buffer overflows. 

Linux kernels from 2.2 through 2.4 and 2.6 are all reported prone to these vulnerabilities.

50. Linux kernel Uselib() Local Privilege Escalation Vulnerability
BugTraq ID: 12190
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12190
Summary:
Linux kernel is reported prone to a local privilege-escalation vulnerability. This issue arises in the 'uselib()' functions of the Linux binary-format loader as a result of a race condition. Successful exploitation of this vulnerability can allow a local attacker to gain elevated privileges on a vulnerable computer. 

The ELF and a.out loaders are reportedly affected by this vulnerability.

51. Apple Mac OS X Finder DMG Volume Memory Corruption Vulnerability
BugTraq ID: 21980
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21980
Summary:
Apple Mac OS X Finder is prone to a memory-corruption vulnerability. This issue occurs when the application fails to handle overly long DMG volume names. 

Due to the nature of this issue, an attacker may be able to execute arbitrary machine code in the context of the affected application, but this has not been confirmed. Failed exploit attempts result in memory corruption and a crash of the application, denying service to legitimate users.

Finder 10.4.6 on Mac OS X 10.4.8 X86 is vulnerable to this issue; other versions may also be affected.

52. Linux Kernel User Triggerable BUG() Unspecified Local Denial of Service Vulnerability
BugTraq ID: 12261
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12261
Summary:
Linux Kernel is reported prone to a local denial-of-service vulnerability. 

Reportedly, this issue presents itself when a user creates a large Virtual Memory Area (VMA) that overlaps with arg pages during the exec() system call. 

Successful exploitation will lead to a denial-of-service condition in a vulnerable computer. 

No further details are available at this time. This issue will be updated as more information becomes available.

53. Adobe ColdFusion Information Disclosure Vulnerability
BugTraq ID: 21978
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21978
Summary:
Adobe ColdFusion is prone to an information-disclosure vulnerability.

Successfully exploiting this issue allows remote attackers to gain access to the contents of arbitrary files that are not interpreted by ColdFusion. This includes the source of scripting files not handled by ColdFusion, configuration files, log files, and other data files. Information harvested may aid attackers in further attacks.

Adobe ColdFusion MX7, 7.0.1 and 7.0.2 are vulnerable.

54. Yet Another Link Directory Yald.PHP HTML Injection Vulnerability
BugTraq ID: 21904
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21904
Summary:
Yet Another Link Directory is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.

Attacker-supplied HTML and script code may run in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.0.

55. Adobe Reader Plugin Open Parameters Cross-Site Scripting Vulnerability
BugTraq ID: 21858
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21858
Summary:
Adobe Reader Plugin is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 
 
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the visited site.  This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects Adobe Reader versions 6 and 7 for Mozilla Firefox, Opera, and Microsoft Internet Explorer. Other versions for other browsers may also be affected.

56. Linux Kernel ELF Binary Loading Denial Of Service Vulnerability
BugTraq ID: 12101
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12101
Summary:
The Linux kernel is affected by a denial-of-service vulnerability that occurs when malformed ELF binaries are loaded.

An attacker may leverage this issue to cause the affected kernel to crash, denying service to legitimate users.

57. Linux Kernel Local Denial Of Service And Memory Disclosure Vulnerabilities
BugTraq ID: 11754
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11754
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities:

- A handcrafted 'a.out' file may be used to trigger a local denial-of-service condition. A local attacker may exploit this vulnerability to trigger a system-wide denial of service, potentially resulting in a kernel panic. 

- A memory-disclosure vulnerability reportedly affects only SMP computers with more than 4GB of memory. A local attacker may exploit this vulnerability to access random pages of physical memory.

58. Linux Kernel AF_UNIX Arbitrary Kernel Memory Modification Vulnerability
BugTraq ID: 11715
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11715
Summary:
A serialization error is reported to reside in the AF_UNIX address family. The error creates a race condition that allows local users to repeatedly increment arbitrary kernel memory locations. 

This vulnerability allows local users to modify arbitrary kernel memory, facilitating privilege escalation; it may possibly allow code execution in the context of the kernel. 

Versions prior to 2.4.28 are reportedly affected by this vulnerability.

59. Linux Kernel 2.4 RTC Handling Routines Memory Disclosure Vulnerability
BugTraq ID: 9154
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/9154
Summary:
The Linux kernel 2.4 tree has been reported prone to a memory-disclosure vulnerability. The issue is reported to present itself in kernel realtime clock (RTC) interface procedures and may result in kernel memory stack data being leaked into userland. The problem stems from an internal RTC structure that isn't properly initialized with zeros before being read, potentially returning random contents of kernel stack memory when this operation occurs. This could expose sensitive information such as credentials to unprivileged users.

60. Linux Kernel BINFMT_ELF Loader Local Privilege Escalation Vulnerabilities
BugTraq ID: 11646
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11646
Summary:
Multiple vulnerabilities have been identified in the Linux ELF binary loader. These issues can allow local attackers to gain elevated privileges. The source of these issues resides in the 'load_elf_binary' function of the 'binfmt_elf.c' file. 

The first issue results from an improper check performed on the return value of the 'kernel_read()' function. An attacker may gain control over execution flow of a setuid binary by modifying the memory layout of a binary. 

The second issue results from improper error-handling when the 'mmap()' function fails. 

The third vulnerability results from a bad return value when the program interpreter (linker) is mapped into memory. It is reported that this issue occurs only in the 2.4.x versions of the Linux kernel. 

The fourth issue presents itself because a user can execute a binary with a malformed interpreter name string. This issue can lead to a system crash. 

The final issue resides in the 'execve()' code. This issue may allow an attacker to disclose sensitive data that can potentially be used to gain elevated privileges. 

These issues are currently undergoing further analysis. This BID will be updated and divided into separate BIDS in the future.

61. Linux Kernel Coda_Pioctl Local Buffer Overflow Vulnerability
BugTraq ID: 14967
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/14967
Summary:
Linux kernel is prone to a local buffer-overflow vulnerability. 

Specifically, the vulnerability affects the 'coda_pioctl()' function of the 'pioctl.c' file. 

A successful attack may result in a denial-of-service condition or arbitrary code execution with superuser privileges. 

This issue may be related to the issues described in BID 12239 (Linux Kernel Multiple Unspecified Vulnerabilities).

62. Linux Kernel ELF Loader Mismatched Architecture Local Denial of Service Vulnerability
BugTraq ID: 18174
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/18174
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the ELF object file loader.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.4.25.

63. Linux Kernel USB io_edgeport Driver Local Integer Overflow Vulnerability
BugTraq ID: 12102
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12102
Summary:
A local integer-overflow vulnerability affects the Linux kernel's 'io_edgeport' USB driver. This issue is due to the driver's failure to validate integer bounds. 

An attacker may leverage this issue to execute arbitrary instructions or cause the affected kernel to crash.

64. Linux Kernel Multiple Local Vulnerabilities
BugTraq ID: 11956
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11956
Summary:
The Linux kernel is reported prone to multiple local vulnerabilities. The following individual issues are reported: 

- An integer overflow is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file. This vulnerability is reported to exist only in the 2.6 kernel tree. Although unconfirmed, due to its nature this issue presumably may be further leveraged to execute arbitrary code with ring-0 privileges. 

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible. 

- A second integer-overflow vulnerability is reported to exist in the 'vc_resize()' function of the Linux kernel. This vulnerability is reported to exist in the 2.6 and 2.4 kernel trees. Although unconfirmed, due to its nature this issue presumably may be further leveraged to execute arbitrary code with ring-0 privileges. 

A local attacker may exploit this vulnerability to deny service to legitimate users. Other attacks are also likely possible. 

- A memory leak is reported to exist in 'ip_options_get()' of the 'ip_options.c' kernel source file. This vulnerability is reported to exist in the 2.6, and 2.4 kernel tree. 

A local attacker may exploit this vulnerability to consume kernel heap memory resources and in doing so may impact system performance, ultimately resulting in a denial of service to legitimate users.

65. Linux Kernel MIPS Ptrace Local Privilege Escalation Vulnerability
BugTraq ID: 18176
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/18176
Summary:
The Linux kernel is susceptible to a local privilege-escalation vulnerability. This issue occurs only on MIPS architectures.

This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.

Specific information regarding affected versions is not currently available; this BID will be updated as further information is disclosed.

66. Linux Kernel SMBFS Multiple Remote Vulnerabilities
BugTraq ID: 11695
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11695
Summary:
The Linux kernel is reported prone to multiple remote vulnerabilities in the SMBFS network filesystem. 

These vulnerabilities may lead to the execution of attacker-supplied machine code, information disclosure of kernel memory, or crashes of the kernel, denying service to legitimate users. 

Versions of the kernel in both the 2.4 and the 2.6 series are reported prone to various issues.

67. Linux Kernel SCM_SEND Local Denial of Service Vulnerability
BugTraq ID: 11921
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/11921
Summary:
Linux kernel is reported prone to a local denial-of-service vulnerability. This issue presents itself in the SCM logical sub-layer of the socket API. 

An unprivileged application can craft a malformed auxiliary message and send it to a socket, which results in the kernel invoking '__scm_send()' in a manner that leads to a crash. This issue can allow local attackers to cause a denial-of-service condition on a vulnerable computer. It is not confirmed if this vulnerability can be leveraged to gain elevated privileges.

68. Linux Kernel Symmetrical Multiprocessing Page Fault Local Privilege Escalation Vulnerability
BugTraq ID: 12244
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12244
Summary:
A local privilege-escalation vulnerability affects the page-fault handler of the Linux Kernel on symmetric multiprocessor (SMP) computers. This issue is due to a race-condition error that may allow an attacker to gain superuser privileges. 

A malicious local attacker may exploit this issue to gain superuser privileges on an affected computer.

69. Linux Kernel Floating Point Register Contents Leak Vulnerability
BugTraq ID: 10687
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10687
Summary:
The Linux kernel is reported prone to a data-disclosure vulnerability. 

Reportedly, this issue may permit a malicious executable to access the contents of floating-point registers that belong to another process. 

This vulnerability is reported to affect only ia64 systems.

70. Linux Kernel USB Driver Uninitialized Structure Information Disclosure Vulnerability
BugTraq ID: 10892
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10892
Summary:
Certain Linux Kernel USB drivers are prone to a vulnerability that may permit a local attacker to access unauthorized contents of kernel memory. This could reportedly reveal sensitive information to the attacker.

71. Linux Kernel Unspecified Local Denial of Service Vulnerability
BugTraq ID: 10783
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10783
Summary:
Linux kernel is reported prone to an unspecified local denial-of-service vulnerability. Reportedly, this issue affects only ia64 systems. A local attacker can exploit this issue by dereferencing a NULL pointer and causing a kernel panic. Successful exploitation will lead to a denial-of-service condition in a vulnerable computer. 

No further details are available at this time. This issue will be updated as more information becomes available.

72. Linux Kernel Multiple Device Driver Vulnerabilities
BugTraq ID: 10566
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10566
Summary:
The Linux kernel is reported prone to multiple device-driver issues. These issues were found during a recent audit of the Linux kernel source. 

The following drivers are reportedly affected by these issues:

aironet
asus_acpi
decnet
mpu401
msnd
pss 

These issues may reportedly allow attackers to access kernel memory or gain escalated privileges on the affected computer.

73. iPlanet Web Server Search Module Cross-Site Scripting Vulnerability
BugTraq ID: 21977
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21977
Summary:
iPlanet Web Server is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects all versions of iPlanet Web Server 4.

74. Computer Associates BrightStor ARCserve Backup Tape Engine Remote Buffer Overflow Vulnerability
BugTraq ID: 21221
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21221
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions.

BrightStore ARCserver Backup 11.5 is vulnerable to this issue; other versions may also be affected.

75. Linux Kernel Panic Function Call Buffer Overflow Vulnerability
BugTraq ID: 10233
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10233
Summary:
The panic() function call of the Linux kernel has been reported prone to a buffer-overflow vulnerability. 

The vulnerability is reported to present itself when an unbounded vsprintf() call within panic() copies user-supplied data into a fixed buffer. Reportedly, a user may be able to overrun the bounds of the affected buffer and corrupt adjacent memory. Because this buffer resides in kernel memory space, an attacker may be able to exploit this issue to corrupt kernel memory, access memory contents, and -- although unconfirmed -- execute arbitrary code. Some reports, however, indicate that this vulnerability is not exploitable.

76. Linux Kernel Invalid Proc Memory Access Local Denial of Service Vulnerability
BugTraq ID: 18173
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/18173
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a flaw in the 'proc' filesystem.

This vulnerability allows local users to cause a kernel panic, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.4.27.

77. Edit-X Edit_Address.PHP Remote File Include Vulnerability
BugTraq ID: 21974
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21974
Summary:
Edit-x is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

78. Acme Thttpd Insecure Temporary Logfile Creation Vulnerability
BugTraq ID: 20891
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/20891
Summary:
The 'thttpd' program creates temporary log files in an insecure manner. 
 
An attacker with local access could potentially exploit this issue to overwrite files in the context of the webserver process. 
 
A successful exploit would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

Versions prior to 2.23 beta 1 are vulnerable.

79. Linux kernel do_fork() Memory Leakage Vulnerability
BugTraq ID: 10221
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/10221
Summary:
The Linux kernel is reported prone to a memory-leakage vulnerability because the software allocates but never frees memory for child processes.

This issue has been identified in kernel versions 2.4 and 2.6.

80. Axiom Photo Gallery Template.PHP Remote File Include Vulnerability
BugTraq ID: 21972
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21972
Summary:
Axiom Photo Gallery is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Axiom Photo Gallery version 0.8.6 is vulnerable to this issue; other versions may also be vulnerable.

81. EF Commander ISO File Remote Buffer Overflow Vulnerability
BugTraq ID: 21969
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21969
Summary:
EF Commander is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data prior to using it in a finite-sized buffer. 

An attacker can exploit this issue to execute arbitrary code within the context of the user running the affected application.

This issue affects version 5.75; other versions may also be vulnerable.

82. GNU Tar GNUTYPE_NAMES Remote Directory Traversal Vulnerability
BugTraq ID: 21235
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21235
Summary:
GNU Tar is prone to a vulnerability that may allow an attacker to place files and overwrite files in arbitrary locations on a vulnerable computer. These issues present themselves when the application processes malicious archives. 

A successful attack can allow the attacker to place potentially malicious files and overwrite files on a computer in the context of the user running the affected application. Successful exploits may aid in further attacks.

83. BZip2 CHMod File Permission Modification Race Condition Weakness
BugTraq ID: 12954
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/12954
Summary:
The 'bzip2' utility is reported prone to a security weakness. The issue is present only when an archive is extracted into a world- or group-writeable directory. It is reported that bzip2 employs non-atomic procedures to write a file and later changes the permissions on the newly extracted file. 

A local attacker may leverage this issue to modify file permissions of target files. 

This weakness is reported to affect bzip2 version 1.0.2 and previous versions.

84. Easy Banner Pro info.PHP Remote File Include Vulnerability
BugTraq ID: 21967
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21967
Summary:
Easy Banner Pro is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Easy Banner Pro 2.8 is reported vulnerable to this issue; other versions may also be vulnerable.

85. GnuPG Make_Printable_String Remote Buffer Overflow Vulnerability
BugTraq ID: 21306
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21306
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Exploiting this issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.5 and 2.0.0 are vulnerable to this issue; previous versions may also be affected.

86. MADWiFi Linux Kernel Device Driver Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 21486
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21486
Summary:
The MADWiFi device driver is prone to multiple remote stack-based buffer-overflow vulnerabilities because the software fails to do proper bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer.

These issues affect only computers with the vulnerable device driver compiled, installed, and enabled on Linux operating systems. Also, victims must be running a local application to scan available access points for the return packets.

A remote attacker may exploit these issues to cause denial-of-service conditions or to possibly execute arbitrary code in the context of the affected kernel. Successful exploits can result in a complete compromise of affected computers.

Versions of the MADWiFi device driver prior to 0.9.2.1 are vulnerable.

87. uniForum WBSearch.ASPX SQL Injection Vulnerability
BugTraq ID: 21966
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21966
Summary:
uniForum is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

uniForum  4 and prior versions are vulnerable; other versions may also be affected.

88. Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
BugTraq ID: 21925
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21925
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

An attacker could exploit this issue to execute arbitrary code with the privileges of the user running the application. The attacker could leverage the issue to compromise affected computers.

89. Magic Photo Storage Website Multiple Remote File Include Vulnerabilities
BugTraq ID: 21965
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21965
Summary:
Magic Photo Storage Website is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

90. Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
BugTraq ID: 21922
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21922
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, which can result in the compromise of affected computers.

91. Intervations FileCopa LIST Command Remote Buffer Overflow Vulnerability
BugTraq ID: 19065
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/19065
Summary:
FileCopa is prone to a buffer-overflow vulnerability when handling data through the LIST command. 

Reportedly, passing excessive data may overflow a finite-sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data. 

This issue may lead to a denial-of-service condition or allow arbitrary code to run.

92. Solaris RPC Request Denial of Service Vulnerability
BugTraq ID: 21964
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21964
Summary:
The Solaris operating system is prone to a denial-of-service vulnerability. 

An attacker can exploit this issue to crash the 'rpcbind(1M)' server, denying service to legitimate users.

93. Adobe Flash Player Plugin HTTP Header Injection Weakness
BugTraq ID: 20592
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/20592
Summary:
Adobe Flash Player Plugin is prone to a weakness that permits the injection of arbitrary HTTP headers because it fails to sanitize user-supplied input.

A successful attack may allow attackers to perform arbitrary HTTP requests facilitating cross-site request forgery, cross-site scripting, HTTP request smuggling, and other attacks. 

Since this weakness would typically be used as one component in a larger attack scenario, the consequences of an attack will depend on the vulnerabilities exploited along with this weakness.

Version 9.0.16 for Windows and 7.0.63 for Linux are affected by this issue.

94. MOTIONBORG Web Real Estate Admin_Check_User.ASP SQL Injection Vulnerability
BugTraq ID: 21963
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21963
Summary:
MOTIONBORG Web Real Estate is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

This issue affects version 2.1 and prior.

95. KOffice PPT Files Integer Overflow Vulnerability
BugTraq ID: 21354
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21354
Summary:
KOffice is prone to an integer-overflow vulnerability because it fails to properly validate user-supplied data.

An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. Failed exploit attempts will likely cause denial-of-service conditions.

KOffice versions prior to 1.6.1 are affected.

96. PHPKit Comment.PHP SQL Injection Vulnerability
BugTraq ID: 21962
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21962
Summary:
PHPKIT is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

PHPKIT 1.6.1 R2 and prior versions are vulnerable to this issue.

97. LibGSF Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 21358
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21358
Summary:
The libgsf library is prone to a remote heap buffer-overflow vulnerability.

Exploiting this issue may allow attackers to execute arbitrary machine code within the context of the vulnerable application or to cause a denial of service.

98. PPC Search Engine INC Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 21961
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21961
Summary:
PPC Search Engine is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

99. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
BugTraq ID: 18113
Remote: No
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/18113
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability.

This issue allows local attackers to gain access to potentially sensitive kernel memory, aiding them in further attacks. Failed exploit attempts may crash the kernel, denying service to legitimate users.

This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.

Linux kernel versions prior to 2.6.16.17 in the 2.6 series are affected by this issue.

100. TIS Firewall Toolkit FTP-GW Remote Buffer Overflow Vulnerability
BugTraq ID: 21960
Remote: Yes
Last Updated: 2007-01-10
Relevant URL: http://www.securityfocus.com/bid/21960
Summary:
TIS Firewall Toolkit is prone to a remote buffer-overflow vulnerability because the software fails to properly check boundaries of user-supplied input prior to copying it to an insufficiently sized stack-based memory buffer.

Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the server application, facilitating the compromise of affected computers.

Other vulnerabilities may also be present, but this has not been confirmed.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. E-voting flaws put Florida in spotlight again
By: Robert Lemos
A Republican congressman gets seated in the U.S. House of Representatives, but without a bug in the electronic ballot, the challenger would have won, voting experts say.
http://www.securityfocus.com/news/11433

2. Bots, breaches and bugs plague 2006
By: Robert Lemos
Vulnerabilities, especially in Web applications, take off, while bot nets and their controllers cause a jump in spam, and data breaches continue to worry companies and their customers.
http://www.securityfocus.com/news/11432

3. Stock scammer gets coal for the holidays
By: Robert Lemos
The U.S. Securities and Exchange Commission puts a suspected Russian brokerage-account thief's money on ice, after he allegedly used illicit access to people's portfolios to drive up stock prices.
http://www.securityfocus.com/news/11431

4. PHP security under scrutiny
By: Robert Lemos
The departure of a security team member and recent data showing that PHP Web applications account for four out of every ten security flaws found in 2006 highlight the need for better protections, say experts.
http://www.securityfocus.com/news/11430

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Application Security Engineer, Palo Alto
http://www.securityfocus.com/archive/77/456496

2. [SJ-JOB] Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/456497

3. [SJ-JOB] Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/456498

4. [SJ-JOB] Technology Risk Consultant, Mountain View
http://www.securityfocus.com/archive/77/456494

5. [SJ-JOB] Forensics Engineer, Foster City
http://www.securityfocus.com/archive/77/456495

6. [SJ-JOB] Software Engineer, Palo Alto
http://www.securityfocus.com/archive/77/456487

7. [SJ-JOB] Manager, Information Security, Zurich
http://www.securityfocus.com/archive/77/456485

8. [SJ-JOB] Security Architect, St. Louis
http://www.securityfocus.com/archive/77/456488

9. [SJ-JOB] Technical Support Engineer, Berkshire
http://www.securityfocus.com/archive/77/456486

10. [SJ-JOB] Jr. Security Analyst, DC
http://www.securityfocus.com/archive/77/456374

11. [SJ-JOB] Sr. Security Analyst, Skokie
http://www.securityfocus.com/archive/77/456375

12. [SJ-JOB] Information Assurance Analyst, New York
http://www.securityfocus.com/archive/77/456304

13. [SJ-JOB] Director, Information Security, New York
http://www.securityfocus.com/archive/77/456324

14. [SJ-JOB] Sales Representative, San Diego
http://www.securityfocus.com/archive/77/456335

15. [SJ-JOB] Incident Handler, Portland
http://www.securityfocus.com/archive/77/456297

16. [SJ-JOB] Security Auditor, Bellevue
http://www.securityfocus.com/archive/77/456338

17. [SJ-JOB] Security System Administrator, Toronto
http://www.securityfocus.com/archive/77/456336

18. [SJ-JOB] Security Consultant, Dubai
http://www.securityfocus.com/archive/77/456208

19. [SJ-JOB] Sr. Security Engineer, Roseland
http://www.securityfocus.com/archive/77/456078

20. [SJ-JOB] Penetration Engineer, London/South/UK Wide
http://www.securityfocus.com/archive/77/456079

21. [SJ-JOB] Security Researcher, London/Reading
http://www.securityfocus.com/archive/77/456080

22. [SJ-JOB] Application Security Engineer, Anywhere
http://www.securityfocus.com/archive/77/456081

23. [SJ-JOB] Senior Software Engineer, Atlanta
http://www.securityfocus.com/archive/77/456058

24. [SJ-JOB] Sr. Security Analyst, Charlotte
http://www.securityfocus.com/archive/77/456061

25. [SJ-JOB] Compliance Officer, Reston
http://www.securityfocus.com/archive/77/456064

26. [SJ-JOB] Management, New York
http://www.securityfocus.com/archive/77/456062

27. [SJ-JOB] Manager, Information Security, Towson
http://www.securityfocus.com/archive/77/456063

28. [SJ-JOB] Sr. Security Engineer, Atlanta
http://www.securityfocus.com/archive/77/456065

29. [SJ-JOB] Sr. Security Analyst, Vancouver
http://www.securityfocus.com/archive/77/455883

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Bruteforce attack against smtp-auth
http://www.securityfocus.com/archive/75/456450

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Remote exploit for CA brightstor tapeeng (win2k SP4)
http://www.securityfocus.com/archive/82/456093

2. .Net Debug
http://www.securityfocus.com/archive/82/456089

3. Debugger
http://www.securityfocus.com/archive/82/455354

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Deploying Microsoft SMS in a DMZ
http://www.securityfocus.com/archive/88/456479

2. How to deploy Microsoft OWA without using ISA?
http://www.securityfocus.com/archive/88/456037

3. SecurityFocus Microsoft Newsletter #323
http://www.securityfocus.com/archive/88/455838

4. Secure Remote access - windows 2003
http://www.securityfocus.com/archive/88/455670

VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. Solaris 2.7 Daylight saving time fix.
http://www.securityfocus.com/archive/92/456512

IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. SF new article announcement: Wireless Forensics: Tapping the Air - Part Two (fwd)
http://www.securityfocus.com/archive/91/456372

2. SF new column announcement: PHP apps - Security's Low-Hanging Fruit (fwd)
http://www.securityfocus.com/archive/91/456371

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

Hack Yourself- Finding Web Application Security Holes- White Paper
Learn how to defend against Web Application Attacks with real-world examples of recent hacking methods such as: SQL Injection, Cross Site Scripting and Parameter Manipulation. Learn step-by-step vulnerability testing methods for your own Web Applications and guidelines for establishing best administration and coding practices.  
Download *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=70160000000CgNW