SecurityFocus Newsletter #386
[email protected] 31 Jan 2007 00:51:05 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #386
----------------------------------------
This Issue is Sponsored by: Black Hat
Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts.
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges. Network with 400 delegates from 25 nations, and see solutions from major sponsors.
http://www.blackhat.com
------------------------------------------------------------------
I. FRONT AND CENTER
1. The New Vista Waiting Game
2. Testing Fault Injection in Local Applications
II. BUGTRAQ SUMMARY
1. Fetchmail Remote Denial of Service Vulnerability
2. Cacti CMD.PHP Remote Command Execution Vulnerability
3. Movable Type Unspecified Cross-Site Scripting Vulnerability
4. Movable Type Comments HTML Injection Vulnerability
5. X.Org XDM XSession Script Race Condition Vulnerability
6. MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
7. WebFWLog Debug.PHP Information Disclosure Vulnerability
8. EMC Legato Networker Multiple Remote Vulnerabilities
9. PHPMyReport Lib_Head.PHP Remote File Include Vulnerability
10. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
11. Neon LibNeon Non-Ascii Character URI Data Denial Of Service Vulnerability
12. GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
13. JBoss Java Class DeploymentFileRepository Directory Traversal Vulnerability
14. Sun Solaris Kernel SSL Service Remote Denial of Service Vulnerability
15. Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities
16. Apple Mac OS X Multiple Security Vulnerabilities
17. AdMentor Admin Login SQL Injection Vulnerability
18. Yahoo! Messenger Notification Message HTML Injection Vulnerability
19. Telestream Flip4Mac WMV File Remote Memory Corruption Vulnerability
20. Foro Domus Menu.PHP Remote File Include Vulnerability
21. Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
22. X-DEV xNews xNews.php SQL Injection Vulnerability
23. SpoonLabs Vivvo Article Management CMS Show_Webfeed.PHP SQL Injection Vulnerability
24. ChernobiLe Default.ASP SQL Injection Vulnerability
25. ACGVAnnu Arbitrary User Password Change Vulnerability
26. ACGVClick Function.Inc.PHP Remote File Include Vulnerability
27. Zabbix Unspecified Buffer Overflow Vulnerability
28. SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
29. Squid Proxy FTP URI Remote Denial of Service Vulnerability
30. W3M SSL Certificate Format String Vulnerability
31. Multiple X.Org Products SetUID Local Privilege Escalation Vulnerability
32. Sendmail Long Header Denial Of Service Vulnerability
33. Sun Solaris Netstat and Ifconfig Local Denial of Service Vulnerability
34. Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability
35. KDE ArtsWrapper Local Privilege Escalation Vulnerability
36. PHPBB2 Modificat PHPBB_Root_Path Remote File Include Vulnerability
37. Apple QuickTime RTSP URI Remote Buffer Overflow Vulnerability
38. BlueZ HIDD Bluetooh HID Command Injection Vulnerability
39. GeoIP GeoIPUpdate.C Directory Traversal Vulnerability
40. ProFTPD SReplace Remote Buffer Overflow Vulnerability
41. EncapsCMS Common_Foot.PHP Remote File Include Vulnerability
42. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
43. KSirc IRC Client Remote PRIVMSG Denial of Service Vulnerability
44. Linux Kernel ListXATTR Local Denial of Service Vulnerability
45. Multiple Cisco Switches VLAN Trunking Protocol Packet Handling Denial Of Service Vulnerability
46. Inotify Incron File Permission Bypass Weakness
47. SSC DiskAccess NFS Client DAPCNFSD.DLL Stack Buffer Overflow Vulnerability
48. MyNews Themefunc.PHP Remote File Include Vulnerability
49. CascadianFaq Index.PHP SQL Injection Vulnerability
50. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
51. PHPFootball Show.PHP Information Disclosure Vulnerability
52. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
53. Linux Kernel ISO9660 Denial of Service Vulnerability
54. Drupal Comment_Form_Add_Preview Function Remote Code Execution Vulnerability
55. Microsoft Agent ActiveX Control Remote Code Execution Vulnerability
56. Linux Kernel AIO_Setup_Ring Local Denial of Service Vulnerability
57. Linux Kernel IPV6 Seqfile Handling Local Denial of Service Vulnerability
58. Linux Kernel Get_FDB_Entries Buffer Overflow Vulnerability
59. Linux Kernel S/390 Copy_From_User Local Information Disclosure Vulnerability
60. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
61. Linux Kernel FS/Buffer.C Local Information Disclosure Vulnerability
62. Yukihiro Matsumoto Ruby CGI.RB Library Remote Denial Of Service Vulnerability
63. Yukihiro Matsumoto Ruby CGI Module MIME Denial Of Service Vulnerability
64. Sun Java RunTime Environment GIF Images Buffer Overflow Vulnerability
65. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vulnerability
66. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
67. SMB4K Multiple Vulnerabilities
68. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
69. ISC BIND Remote Fetch Context Denial of Service Vulnerability
70. Sun Solaris ICMP Unspecified Remote Denial of Service Vulnerability
71. GTalkbot Username and Password Multiple Information Disclosure Vulnerabilities
72. Bloodshed Dev-C++ CPP Source File Buffer Overflow Vulnerability
73. Cisco Unified Contact Center and IP Contact Center JTapi Gateway Denial of Service Vulnerability
74. Phorum Register.PHP HTML Injection Vulnerability
75. Linux Kernel Unspecified Remote Vulnerability
76. Linux Kernel ATM SkBuff Dereference Remote Denial of Service Vulnerability
77. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
78. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
79. Php Generic MembreManager.PHP Remote File Include Vulnerability
80. Citrix Presentation and MetaFrame Server Cpprov.DLL Stack Buffer Overflow Vulnerability
81. Oracle January 2007 Security Update Multiple Vulnerabilities
82. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
83. Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
84. Sun Java Runtime Environment Information Disclosure Vulnerabilities
85. Sun Solaris LD.SO Multiple Local Vulnerabilities
86. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
87. Linux Kernel Network Bridge Incorrectly Forwarded Packets Information Disclosure Vulnerability
88. CVSTrac Remote Denial of Service Vulnerability
89. Netrik Textarea Tag Remote Arbitrary Command Execution Vulnerability
90. Gnopaste Common.PHP Remote File Include Vulnerability
91. SQL-Ledger Redirect Arbitrary Code Execution Vulnerability
92. Microsoft Word 2000 Unspecified Code Execution Vulnerability
93. WebGUI Asset Deletion Security Bypass Vulnerability
94. FreeType LWFN Files Buffer Overflow Vulnerability
95. FreeType TTF File Remote Denial of Service Vulnerability
96. FreeType TTF File Remote Buffer Overflow Vulnerability
97. MDPro Index.PHP SQL Injection Vulnerability
98. GuppY Error.PHP Remote File Include and Command Execution Vulnerability
99. Microsoft Windows Unhandled Exception Remote Code Execution Vulnerability
100. Intel 2200BG 802.11 Malformed Disassociation Packets Denial Of Service Vulnerability
III. SECURITYFOCUS NEWS
1. Vista raises the bar for flaw finders
2. Fraud linked to TJX data heist spreads
3. Bug brokers offering higher bounties
4. Vulnerability tallies surged in 2006
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Information Assurance Engineer, London
2. [SJ-JOB] Security Engineer, Zurich
3. [SJ-JOB] Security Consultant, Austin
4. [SJ-JOB] Security Engineer, Dublin
5. [SJ-JOB] Security Engineer, Kirkland
6. [SJ-JOB] Jr. Security Analyst, Schaumburg
7. [SJ-JOB] Director, Information Security, Chicago
8. [SJ-JOB] Security Engineer, Sydney
9. [SJ-JOB] Security Consultant, Newcastle
10. [SJ-JOB] Security Consultant, Basingstoke
11. [SJ-JOB] Security Engineer, Silver Spring
12. [SJ-JOB] Security Consultant, London
13. [SJ-JOB] Security Consultant, Worthing
14. [SJ-JOB] Security Consultant, London
15. [SJ-JOB] Sales Representative, Atlanta
16. [SJ-JOB] Sales Representative, Cleveland
17. [SJ-JOB] Sales Representative, Minneapolis
18. [SJ-JOB] Sales Engineer, Nashville
19. [SJ-JOB] Security Engineer, Vienna
20. [SJ-JOB] Principal Software Engineer, Buffalo Grove
21. [SJ-JOB] Security Engineer, New York
22. [SJ-JOB] Application Security Engineer, Picatinny Arsenal
23. [SJ-JOB] Sales Representative, Chicago
24. [SJ-JOB] Security Consultant, London
25. [SJ-JOB] Security Consultant, Ft. Meade
26. [SJ-JOB] Senior Software Engineer, Sunnyvale
27. [SJ-JOB] Security Engineer, Hyderabad
28. [SJ-JOB] Sales Engineer, Any
29. [SJ-JOB] Security Engineer, Phoenix
30. [SJ-JOB] Security Engineer, Kirkland
31. [SJ-JOB] Security Engineer, Santa Monica
32. [SJ-JOB] Security Engineer, Mountain View
33. [SJ-JOB] Sales Engineer, Boston
34. [SJ-JOB] Security Engineer, Chicago
35. [SJ-JOB] Sales Representative, Birmingham
36. [SJ-JOB] Sales Representative, Berkshire
V. INCIDENTS LIST SUMMARY
1. Tracking down random ICMP
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Good references to enhance security programming
2. CA brightstor msgeng.exe heap overflow exploit (win2k SP0)
3. Possible McAfee GroupShield Vulnerability
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #326
2. Blocking weblinks in MSN/Live Messenger from central point
3. Performance impact and filesystem audit
4. Automatic spam mover
5. IE security zone assignment on 2003 terminal server
6. IPSec and GRE (47)
VIII. SUN FOCUS LIST SUMMARY
1. BSM, SSH, and Session ID
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. The New Vista Waiting Game
By Kelly Martin
Vista is a step forward in security, but many businesses will be stuck with Windows XP for years to come. The cost of upgrading, the value of existing assets, and enterprise application compatibility issues trump the security advantages of Vista today in the classic enterprise waiting game.
http://www.securityfocus.com/columnists/431
2. Testing Fault Injection in Local Applications
By Chris Wysopal
This article is a book excerpt that looks at the approach and techniques used to test the security of local applications. It describes local resources and interprocess communication, how to enumerate the local resources an application depends on, and then discusses methods of testing several of those types of resources. It also describes how to test ActiveX objects, command-line programs, and applications' use of local files and shared memory.
http://www.securityfocus.com/infocus/1886
II. BUGTRAQ SUMMARY
--------------------
1. Fetchmail Remote Denial of Service Vulnerability
BugTraq ID: 21902
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21902
Summary:
Fetchmail is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
2. Cacti CMD.PHP Remote Command Execution Vulnerability
BugTraq ID: 21799
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21799
Summary:
Cacti is prone to a remote command-execution vulnerability because the application fails to properly sanitize user-supplied input to the 'cmd.php' script.
Exploiting this issue allows attackers to execute arbitrary commands in the context of the server.
A successful exploit could facilitate the compromise of an affected computer; other attacks are also possible.
Cacti 0.8.6i and prior versions are reportedly affected.
3. Movable Type Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 22292
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22292
Summary:
Movable Type is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to 3.34 are affected by this issue.
4. Movable Type Comments HTML Injection Vulnerability
BugTraq ID: 22264
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22264
Summary:
Movable Type is prone to an HTML-injection vulnerability because the application fails to sufficiently sanitize user-supplied data.
Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.
Movable Type 3.33 and prior versions are affected by this issue.
5. X.Org XDM XSession Script Race Condition Vulnerability
BugTraq ID: 20400
Remote: No
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/20400
Summary:
The X.org XDM XSession script is prone to a race-condition vulnerability.
Local unprivileged attackers can exploit this issue to gain access to the primary or alternate 'xdm' error log files. A successful exploit will result in the unintended disclosure of sensitive information.
6. MS IIS/PWS Escaped Characters Decoding Command Execution Vulnerability
BugTraq ID: 2708
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/2708
Summary:
Due to a flaw in the handling of CGI filename program requests, remote users can execute arbitrary commands on an IIS host.
When IIS receives a CGI filename request, it automatically performs two actions before completing the request:
1. IIS decodes the filename to determine the filetype and the legitimacy of the file. IIS then carries out a security check.
2. When the security check is completed, IIS decodes CGI parameters.
A flaw in IIS involves a third undocumented action: Typically, IIS decodes only the CGI parameter at this point, yet the previously decoded CGI filename is mistakenly decoded twice. If a malformed filename is submitted and circumvents the initial security check, the undocumented procedure will decode the malformed request, possibly allowing the execution of arbitrary commands.
Note that arbitrary commands will be run with the IUSR_machinename account privileges. Reportedly, various encoding combinations under Windows 2000 Server and Professional may yield different outcomes.
Personal Web Server 1.0 and 3.0 are reported vulnerable to this issue.
The worm Nimda(and variants) actively exploit this vulnerability.
7. WebFWLog Debug.PHP Information Disclosure Vulnerability
BugTraq ID: 22291
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22291
Summary:
Webfwlog is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve any file the application has read access to. Information obtained may aid in further attacks.
Version 0.92 is vulnerable to this issue.
8. EMC Legato Networker Multiple Remote Vulnerabilities
BugTraq ID: 16275
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/16275
Summary:
EMC Legato Networker is affected by multiple remote vulnerabilities. A denial-of-service issue and two remote code-execution issues have been identified.
Version 7.2.1 of Legato Networker is vulnerable to these issues; prior versions may also be affected.
9. PHPMyReport Lib_Head.PHP Remote File Include Vulnerability
BugTraq ID: 22290
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22290
Summary:
phpMyReport is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
10. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
BugTraq ID: 22289
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22289
Summary:
The GD graphics library is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions in applications implementing the affected library. Arbitrary code execution may also be possible; this has not been confirmed.
11. Neon LibNeon Non-Ascii Character URI Data Denial Of Service Vulnerability
BugTraq ID: 22035
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22035
Summary:
The Neon Library is prone to a remote denial-of-service vulnerability.
This issue occurs when parsing URI data containing non-ASCII characters.
An attacker can exploit this vulnerability to crash the library, effectively denying service to legitimate users.
Versions 0.26 to 0.26.2 are vulnerable; other versions may also be affected.
NOTE: Only 64-bit systems are affected.
12. GTK2 GDKPixBufLoader Remote Denial of Service Vulnerability
BugTraq ID: 22209
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22209
Summary:
Applications using the gtk2 library may be prone to a denial-of-service vulnerability because the library fails to handle malformed image data.
An attacker can exploit this issue to crash applications on a victim's computer.
13. JBoss Java Class DeploymentFileRepository Directory Traversal Vulnerability
BugTraq ID: 21219
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21219
Summary:
JBoss is prone to a directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to read, create, delete, and overwrite arbitrary files from the vulnerable system in the context of the affected application. Successful exploits can result in a compromise of vulnerable applications.
JBoss Web Server 1.0.0.GA is vulnerable to this issue. Other applications that use the affected JBoss Java class may also be affected.
14. Sun Solaris Kernel SSL Service Remote Denial of Service Vulnerability
BugTraq ID: 20224
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/20224
Summary:
Sun Solaris is prone to a denial-of-service vulnerability.
A remote attacker may exploit this issue to cause kernel panic, effectively denying service to legitimate users.
This issue affects only Solaris 10.
15. Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities
BugTraq ID: 22288
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22288
Summary:
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities because the application fails to handle exceptional conditions.
These issues are triggered when an attacker entices a victim user to visit a malicious website.
Remote attackers may exploit these issues to crash Internet Explorer, effectively denying service to legitimate users.
16. Apple Mac OS X Multiple Security Vulnerabilities
BugTraq ID: 19289
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/19289
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities.
These issue affect Mac OS X and various applications including AFP Server, Bluetooth, Bom, DHCP, Image RAW, ImageIO, Launch Services, OpenSSH, and WebKit. A remote attacker may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, and disclose potentially sensitive information.
Apple Mac OS X 10.4.7 and prior are reported vulnerable to these issues.
17. AdMentor Admin Login SQL Injection Vulnerability
BugTraq ID: 22281
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22281
Summary:
AdMentor is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
18. Yahoo! Messenger Notification Message HTML Injection Vulnerability
BugTraq ID: 22269
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22269
Summary:
Yahoo! Messenger is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the context of a victim's Internet Explorer temporary folder. This may help the attacker steal information and launch other attacks.
Versions prior to 2.1.0.29 are vulnerable to this issue.
19. Telestream Flip4Mac WMV File Remote Memory Corruption Vulnerability
BugTraq ID: 22286
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22286
Summary:
Flip4Mac is prone to a remote memory-corruption vulnerability.
Flip4Mac is prone to a remote memory-corruption vulnerability because the application fails to properly handle malformed WMV files.
An attacker can exploit this issue to execute arbitrary code within the context of the application or to trigger a denial-of-service condition.
Flip4Mac Windows Media Components for QuickTime version 2.1.0.33 is reported vulnerable; other versions may be affected as well.
20. Foro Domus Menu.PHP Remote File Include Vulnerability
BugTraq ID: 22285
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22285
Summary:
Domus is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Domus version 2.10 is vulnerable to this issue.
21. Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 20365
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/20365
Summary:
Multiple Computer Associates products are prone to multiple buffer-overflow vulnerabilities because the applications using an affected library fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting these issues allows attackers to execute arbitrary machine code within the context of the affected application.
22. X-DEV xNews xNews.php SQL Injection Vulnerability
BugTraq ID: 22284
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22284
Summary:
xNews is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 1.3; other versions may also be vulnerable.
23. SpoonLabs Vivvo Article Management CMS Show_Webfeed.PHP SQL Injection Vulnerability
BugTraq ID: 22282
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22282
Summary:
Vivvo Article Management CMS is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 3.40; other versions may also be vulnerable.
24. ChernobiLe Default.ASP SQL Injection Vulnerability
BugTraq ID: 22280
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22280
Summary:
ChernobiLe is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 1.0; other versions may also be vulnerable.
25. ACGVAnnu Arbitrary User Password Change Vulnerability
BugTraq ID: 22279
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22279
Summary:
ACGVannu is prone to a vulnerability that may permit attackers to change arbitrary passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's password, bypass the authentication mechanism, and gain unauthorized access to the affected application. This may lead to other attacks.
This issue affects version 1.3; other versions may also be vulnerable.
26. ACGVClick Function.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 22278
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22278
Summary:
ACGVclick is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.2.0; other versions may also be vulnerable.
27. Zabbix Unspecified Buffer Overflow Vulnerability
BugTraq ID: 22321
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22321
Summary:
ZABBIX is prone to an unspecified buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed attempts will likely cause denial-of-service conditions.
Versions prior to 1.1.5 are vulnerable.
28. SquirrelMail Multiple Cross Site Scripting and Input Validation Vulnerabilities
BugTraq ID: 21414
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21414
Summary:
SquirrelMail is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to 1.4.9a are vulnerable.
29. Squid Proxy FTP URI Remote Denial of Service Vulnerability
BugTraq ID: 22079
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22079
Summary:
Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to handle certain FTP requests.
Successfully exploiting this issue allows remote attackers to crash affected proxy applications, denying futher service to legitimate users.
Squid versions from 2.5.STABLE11 to 2.6.STABLE6 are vulnerable to this issue.
30. W3M SSL Certificate Format String Vulnerability
BugTraq ID: 21735
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21735
Summary:
W3M is prone to a format-string vulnerability. This issue can occur when the browser processes SSL certificates that include format specifiers.
A successful exploit could result in the execution of arbitrary code in the context of the user running the browser.
The vulnerability was reported to affect version 0.5.1; prior versions could also be affected.
31. Multiple X.Org Products SetUID Local Privilege Escalation Vulnerability
BugTraq ID: 19742
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/19742
Summary:
Multiple X.org products are prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to gain superuser privileges. A successful exploit would lead to the complete compromise of the affected computer.
32. Sendmail Long Header Denial Of Service Vulnerability
BugTraq ID: 19714
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/19714
Summary:
Sendmail is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the Sendmail process, causing a denial of service.
33. Sun Solaris Netstat and Ifconfig Local Denial of Service Vulnerability
BugTraq ID: 19493
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/19493
Summary:
Sun Solaris is prone to a local denial-of-service vulnerability.
A successful attack can trigger a crash in the application, leading to a denial-of-service condition for legitimate users.
Solaris 10 is affected by this issue.
34. Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability
BugTraq ID: 21910
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21910
Summary:
Multiple PDF readers are prone to multiple remote buffer-overflow vulnerabilities because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker may be able exploit this issue to execute arbitrary code within the context of the affected application. In some circumstances, the vulnerability can be exploited only to cause a denial of service.
35. KDE ArtsWrapper Local Privilege Escalation Vulnerability
BugTraq ID: 18429
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/18429
Summary:
KDE's artswrapper utility is susceptible to a local privilege-escalation vulnerability because it fails to properly implement privilege-dropping functionality when used in conjunction with Linux 2.6 kernels.
This issue allows local attackers to gain superuser privileges, facilitating the complete compromise of affected computers.
36. PHPBB2 Modificat PHPBB_Root_Path Remote File Include Vulnerability
BugTraq ID: 22320
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22320
Summary:
phpBB2 MODificat is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.2.0; other versions may also be vulnerable.
37. Apple QuickTime RTSP URI Remote Buffer Overflow Vulnerability
BugTraq ID: 21829
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21829
Summary:
Apple QuickTime is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input prior to copying it to an insufficiently sized stack-based memory buffer.
Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers.
Attackers exploit this issue by coercing targeted users to access malicious HTML or QTL files or by executing malicious JavaScript code.
QuickTime version 7.1.3 is vulnerable to this issue; other versions may also be affected.
38. BlueZ HIDD Bluetooh HID Command Injection Vulnerability
BugTraq ID: 22076
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22076
Summary:
BlueZ hidd is prone to a device-command-injection vulnerability.
A remote attacker can exploit this issue to gain control of mouse and keyboard HIDs (human interface device). This will allow the attacker to interact with the targeted computer in the context of the currently logged-in user.
Versions prior to 2.25 are vulnerable.
39. GeoIP GeoIPUpdate.C Directory Traversal Vulnerability
BugTraq ID: 21959
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21959
Summary:
The 'geoip' application is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
This issue affects versions prior to 1.4.0.
40. ProFTPD SReplace Remote Buffer Overflow Vulnerability
BugTraq ID: 20992
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/20992
Summary:
ProFTPD is prone to an remote buffer-overflow vulnerability. This issue is due to an off-by-one error, allowing attackers to corrupt memory.
Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the server application, facilitating the compromise of affected computers.
ProFTPD versions prior to 1.3.0a are vulnerable to this issue.
Update: This BID was recently updated to state that 'CommandBufferSize' was affected by a denial-of-service issue, but according to the vendor, that directive is not vulnerable.
41. EncapsCMS Common_Foot.PHP Remote File Include Vulnerability
BugTraq ID: 22319
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22319
Summary:
EncapsCMS is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects version 0.3.6; other versions may also be vulnerable.
42. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
BugTraq ID: 22317
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22317
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.
A local attacker can exploit this issue to corrupt data and cause the kernel to become unresponsive, denying further service to legitimate users.
43. KSirc IRC Client Remote PRIVMSG Denial of Service Vulnerability
BugTraq ID: 21790
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21790
Summary:
KSirc is prone to a remote denial-of-service vulnerability.
The issue arises when the client handles excessive string data. By exploiting this issue, a remote attacker may cause an affected client to crash.
KSirc 1.3.12 is vulnerable to this issue; other versions may also be affected.
The vendor states this issue cannot be exploited to execute arbitrary code. Successful exploits will, however, result in denial-of-service conditions in the client.
44. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.
Successful exploits will result in denial-of-service conditions or potentially privilege escalation.
45. Multiple Cisco Switches VLAN Trunking Protocol Packet Handling Denial Of Service Vulnerability
BugTraq ID: 22268
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22268
Summary:
Multiple Cisco switches are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause affected devices to restart, effectively denying service to legitimate users.
This issue may be related to the issues described in BID 19998 (Cisco IOS Multiple VLAN Trunking Protocol Vulnerabilities).
46. Inotify Incron File Permission Bypass Weakness
BugTraq ID: 22305
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22305
Summary:
Inotify Incron is prone to a local security-bypass weakness that may permit attackers to monitor arbitrary files with elevated privileges.
An attacker may be able to exploit this issue to gain potentially sensitive information about arbitrary files.
47. SSC DiskAccess NFS Client DAPCNFSD.DLL Stack Buffer Overflow Vulnerability
BugTraq ID: 22301
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22301
Summary:
Shaffer Solutions Corp DiskAccess is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the Spooler service. The Spooler service typically runs with the privileges of the 'LocalSystem' account.
48. MyNews Themefunc.PHP Remote File Include Vulnerability
BugTraq ID: 22313
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22313
Summary:
MyNews is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This issue affects MyNews 4.2.2 and prior versions.
49. CascadianFaq Index.PHP SQL Injection Vulnerability
BugTraq ID: 22314
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22314
Summary:
CascadianFAQ is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 4.1; earlier versions may also be vulnerable.
50. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
BugTraq ID: 22034
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22034
Summary:
The Libsoup library is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input.
Attackers may exploit this vulnerability to crash an application that relies on the affected library, resulting in a denial-of-service condition.
51. PHPFootball Show.PHP Information Disclosure Vulnerability
BugTraq ID: 22312
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22312
Summary:
PHPFootball is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to view any database information that the application has read access to. Information obtained may aid in further attacks.
Version 1.6 is vulnerable; other versions may also be affected.
52. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
BugTraq ID: 21604
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21604
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability because the kernel fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker may exploit this issue to execute arbitrary code with kernel-level privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will result in denial-of-service conditions.
Versions prior to 2.4.33.5 are vulnerable to this issue.
53. Linux Kernel ISO9660 Denial of Service Vulnerability
BugTraq ID: 20920
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/20920
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue affects the code that handles the ISO9660 filesystem.
An attacker can exploit this issue to crash the affected computer, denying service to legitimate users.
54. Drupal Comment_Form_Add_Preview Function Remote Code Execution Vulnerability
BugTraq ID: 22306
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22306
Summary:
The Drupal application is prone to an arbitrary PHP code-execution vulnerability.
To exploit this issue, attackers must have access to the 'post comments' functionality and to multiple input filters, which is not the default.
Successful exploits will result in arbitrary PHP script code running in the context of the webserver process. This issue can facilitate the compromise of vulnerable computers.
55. Microsoft Agent ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 21034
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21034
Summary:
The Microsoft Agent ActiveX control is prone to remote code execution.
An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.
56. Linux Kernel AIO_Setup_Ring Local Denial of Service Vulnerability
BugTraq ID: 22193
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22193
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability because the kernel fails to properly initialize a variable.
Exploiting this issue allows local attackers to cause kernel crashes, denying service to legitimate users.
57. Linux Kernel IPV6 Seqfile Handling Local Denial of Service Vulnerability
BugTraq ID: 20847
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/20847
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the way seqfiles are handled in the kernel.
This vulnerability allows local users to cause an infinite loop, resulting in a crash and denying further service to legitimate users.
This issue affects the Linux kernel 2.6 series up to 2.6.18-stable.
58. Linux Kernel Get_FDB_Entries Buffer Overflow Vulnerability
BugTraq ID: 21353
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21353
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
Attackers may potentially exploit this issue to execute arbitrary code within the context of the affected kernel, but this has not been confirmed. Successfully exploiting this issue would cause the complete compromise of the affected computer.
Little information is currently known about this vulnerability. Since the affected function is in the network-bridging code, remote attacks may be possible.
59. Linux Kernel S/390 Copy_From_User Local Information Disclosure Vulnerability
BugTraq ID: 20379
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/20379
Summary:
The Linux kernel is prone to a local information-disclosure vulnerability on the S/390 architecture because the kernel fails to properly initialize kernel memory before returning it to user-space programs.
Successfully exploiting this issue allows local attackers to gain access to potentially sensitive information contained in kernel memory, aiding them in further attacks.
Linux kernel versions prior to 2.6.19-rc1 on the S/390 architecture are vulnerable to this issue.
60. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
BugTraq ID: 21663
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21663
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability due to a design error.
A local attacker can exploit this issue to cause the kernel to become unresponsive, denying further service to legitimate users.
Linux Kernel versions prior to 2.4.33.6 are vulnerable.
61. Linux Kernel FS/Buffer.C Local Information Disclosure Vulnerability
BugTraq ID: 21522
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21522
Summary:
The Linux kernel is prone to a local information-disclosure vulnerability because the kernel fails to properly clear kernel memory after certain errors.
Successfully exploiting this issue allows local attackers to gain access to potentially sensitive information contained in kernel memory, aiding them in further attacks.
Linux kernel versions prior to 2.6.13 are vulnerable to this issue.
62. Yukihiro Matsumoto Ruby CGI.RB Library Remote Denial Of Service Vulnerability
BugTraq ID: 21441
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/21441
Summary:
Ruby is prone to a remote denial-of-service vulnerability because the application's CGI library fails to properly handle specially crafted HTTP requests.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected Ruby CGI library.
63. Yukihiro Matsumoto Ruby CGI Module MIME Denial Of Service Vulnerability
BugTraq ID: 20777
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/20777
Summary:
Ruby is prone to a remote denial-of-service vulnerability because the application's CGI module fails to properly handle specific HTTP requests that contain invalid information.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected Ruby CGI Module.
64. Sun Java RunTime Environment GIF Images Buffer Overflow Vulnerability
BugTraq ID: 22085
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22085
Summary:
The Java Runtime Environment is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker may exploit this issue by enticing a victim into opening a maliciously crafted Java applet.
The attacker can exploit these issues to execute arbitrary code with the privileges of the victim. Failed exploit attempts will likely result in denial-of-service conditions.
This issue is being tracked by BugID: 6445518
65. NoMachine NX Server NXCONFIGURE.SH Remote Denial Of Service Vulnerability
BugTraq ID: 22308
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22308
Summary:
NX Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the server, effectively denying service to legitimate users.
NX Server versions prior to 2.1.0-18 are vulnerable.
66. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 22304
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22304
Summary:
Apple iChat is prone to multiple remote denial-of-service vulnerabilities. These issues affect the Bonjour functionality.
Apple iChat 3.1.6 is reported affected; other versions may be vulnerable as well.
67. SMB4K Multiple Vulnerabilities
BugTraq ID: 22299
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22299
Summary:
The 'smb4k' is prone to multiple vulnerabilities, including:
- A buffer-overflow vulnerability
- A denial-of-service vulnerability
- An information-disclosure issue
- An insecure-temporary-file-creation issue.
An attacker can exploit this issue to completely compromise affected computers. This includes executing arbitrary code with superuser privileges, crashing arbitrary processes, gaining access to sensitive information, and writing to the 'sudoers' file.
These issues affect version 0.8.0; other versions may also be vulnerable.
68. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
BugTraq ID: 22231
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22231
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed DNSSEC validation requests.
Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.
69. ISC BIND Remote Fetch Context Denial of Service Vulnerability
BugTraq ID: 22229
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22229
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle unexpected DNS requests.
Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.
70. Sun Solaris ICMP Unspecified Remote Denial of Service Vulnerability
BugTraq ID: 22323
Remote: No
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22323
Summary:
Sun Solaris is prone to a remote denial-of-service vulnerability.
A successful attack can trigger a crash in the operating system, leading to a denial-of-service condition for legitimate users.
Solaris 10 is affected by this issue.
71. GTalkbot Username and Password Multiple Information Disclosure Vulnerabilities
BugTraq ID: 22322
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22322
Summary:
gtalkbot is prone to multiple information-disclosure vulnerability. This issue is due a design error in the affected application.
An attacker can exploit these issues to gain access to sensitive information. Information harvested may allow an attacker to gain unauthorized access to the affected application. This may lead to other attacks.
Version 1.1 is vulnerable to this issue; prior versions may also be affected.
72. Bloodshed Dev-C++ CPP Source File Buffer Overflow Vulnerability
BugTraq ID: 22315
Remote: Yes
Last Updated: 2007-01-30
Relevant URL: http://www.securityfocus.com/bid/22315
Summary:
Bloodshed Dev-C++ is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users, and may be able to execute arbitrary machine code, but this has not been confirmed.
Bloodshed Dev-C++ version 4.9.9.2 is affected by this issue; other versions may also be vulnerable.
73. Cisco Unified Contact Center and IP Contact Center JTapi Gateway Denial of Service Vulnerability
BugTraq ID: 21988
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21988
Summary:
Cisco Unified Contact Center and IP Contact Center are prone to a vulnerability that can cause the applications to restart and subsequently cause temporary denial-of-service conditions.
An attacker can exploit this issue to cause the vulnerable JTapi Gateway service to restart. Since the restart process can take several minutes, no new connections will be processed during that time, which effectively means a denial of service for legitimate users.
74. Phorum Register.PHP HTML Injection Vulnerability
BugTraq ID: 22297
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22297
Summary:
Phorum is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
75. Linux Kernel Unspecified Remote Vulnerability
BugTraq ID: 21835
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21835
Summary:
The Linux kernel is prone to an unspecified vulnerability.
Versions prior to 2.4.34 are vulnerable to this issue.
76. Linux Kernel ATM SkBuff Dereference Remote Denial of Service Vulnerability
BugTraq ID: 20363
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/20363
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability.
This issue is triggered when the kernel processes incoming ATM data.
Exploiting this vulnerability may allow remote attackers to crash the affected kernel, resulting in denial-of-service conditions.
This issue affects only systems that have ATM hardware and are configured for ATM kernel support.
Kernel versions from 2.6.0 up to and including 2.6.17 are vulnerable to this issue.
77. Linux Kernel Unspecified Socket Buffer Handling Remote Denial of Service Vulnerability
BugTraq ID: 19475
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/19475
Summary:
The Linux kernel is prone to an unspecified remote denial-of-service vulnerability.
This issue allows remote attackers to cause kernel panics, denying service to legitimate users.
No further information is currently available. This BID will be updated as more information is released.
Specific version information is currently unavailable. Kernel versions in the 2.6 series are currently considered vulnerable.
78. Linux Kernel ELF File Entry Point Denial of Service Vulnerability
BugTraq ID: 16925
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/16925
Summary:
Linux kernel is prone to a denial-of-service vulnerability when processing a malformed ELF file. This issue occurs only on Intel EM64T processors.
Linux kernel versions prior to 2.6.15.5 are affected by this issue.
79. Php Generic MembreManager.PHP Remote File Include Vulnerability
BugTraq ID: 22287
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22287
Summary:
PhP Generic is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
80. Citrix Presentation and MetaFrame Server Cpprov.DLL Stack Buffer Overflow Vulnerability
BugTraq ID: 22217
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22217
Summary:
Citrix Presentation and MetaFrame Server are prone to a stack-based buffer-overflow vulnerability because they fail to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with the privileges of the 'LocalSystem' account.
81. Oracle January 2007 Security Update Multiple Vulnerabilities
BugTraq ID: 22083
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22083
Summary:
Oracle has released a Critical Patch Update advisory for January 2007 to address these vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly expose affected computers to complete compromise.
82. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
BugTraq ID: 21673
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21673
Summary:
The Sun Java Runtime Environment is prone to multiple remote privilege-escalation vulnerabilities.
An attacker can execute arbitrary code and commands in the context of a user who invokes the Java applet or application.
A successful attack can facilitate privilege escalation.
83. Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
BugTraq ID: 21220
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21220
Summary:
Novell Client is prone to a remote buffer-overflow vulnerability. Successful exploits may result in a denial-of-service condition or arbitrary code execution. Remote, anonymous attackers may exploit this issue via RPC requests.
This issue affects Novell Client 4.91; other versions may also be vulnerable.
84. Sun Java Runtime Environment Information Disclosure Vulnerabilities
BugTraq ID: 21674
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21674
Summary:
The Sun Java runtime environment is prone to multiple information-disclosure vulnerabilities. These issues are due to a design flaw in the affected application.
An attacker can exploit these issues to gain access to sensitive information. This may lead to other attacks.
85. Sun Solaris LD.SO Multiple Local Vulnerabilities
BugTraq ID: 21564
Remote: No
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21564
Summary:
Solaris 'ld.so' is prone to a local directory-traversal vulnerability and a local stack-based buffer-overflow vulnerability.
Note that each of these issues cannot be exploited singularly but can be exploited in tandem to potentially execute arbitrary code with superuser privileges. Furthermore, attackers must have access to a dynamically linked setuid-privileged executable.
86. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 21675
Remote: No
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/21675
Summary:
The Java Runtime Environment is prone to multiple buffer-overflow vulnerabilities the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
A local attacker can exploit these issues to execute arbitrary code with administrative privileges. A successful exploit attempt will lead to the complete compromise of affected computers. Failed exploit attempts will result in a denial of service.
87. Linux Kernel Network Bridge Incorrectly Forwarded Packets Information Disclosure Vulnerability
BugTraq ID: 15536
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/15536
Summary:
Linux Kernel is susceptible to an information-disclosure vulnerability in its network-bridging functionality.
This issue allows attackers to poison the bridge-forwarding table, causing packets to be incorrectly forwarded to the wrong interface. Information gained from the packets may aid the malicious user in further attacks.
Kernel versions 2.6.11.11 and prior are vulnerable to this issue.
88. CVSTrac Remote Denial of Service Vulnerability
BugTraq ID: 22296
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22296
Summary:
CVSTrac is prone to a remote denial-of-service vulnerability because it fails to propely sanitize input.
Successfully exploiting this issue allows remote attackers to corrupt the application's database, resulting in a denial-of-service condition, causing further requests from legitimate users to fail.
89. Netrik Textarea Tag Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 22158
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22158
Summary:
The 'netrik' program is prone to a vulnerability that allows attackers to execute remote arbitrary shell commands in the context of the webserver application.
This issue affects versions prior to 1.15.5 beta.
90. Gnopaste Common.PHP Remote File Include Vulnerability
BugTraq ID: 18180
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/18180
Summary:
The gnopaste tool is prone to a remote file-include vulnerability. As a result, remote users may specify external PHP scripts to be included by the application.
This could result in the execution of arbitrary PHP code in the context of the webserver hosting the application.
91. SQL-Ledger Redirect Arbitrary Code Execution Vulnerability
BugTraq ID: 22295
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22295
Summary:
SQL-Ledger is prone to an arbitrary code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. This could lead to the compromise of a vulnerable system.
SQL-Ledger 2.6 and prior versions are vulnerable.
92. Microsoft Word 2000 Unspecified Code Execution Vulnerability
BugTraq ID: 22225
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22225
Summary:
Microsoft Word 2000 is prone to an unspecified remote code-execution vulnerability.
Microsoft Word 2000 is confirmed vulnerable to an unspecified remote code-execution issue. Exploit attempts against Word 2003/XP will consume all CPU resources and will cause a denial of service for legitimate users.
Note that this issue is distinct from issues described in BID 21589 (Microsoft Word Code Execution Vulnerability), BID 21451 (Microsoft Word Unspecified Remote Code Execution Vulnerability), and BID 21518 (Microsoft Word Unspecified Code Execution Vulnerability).
93. WebGUI Asset Deletion Security Bypass Vulnerability
BugTraq ID: 22294
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22294
Summary:
WebGUI is prone to a security-bypass vulnerability because the application fails to properly validate users when deleting assets.
An attacker may exploit this issue to delete assets regardless of the security settings. This may aid the attacker in further attacks.
94. FreeType LWFN Files Buffer Overflow Vulnerability
BugTraq ID: 18034
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/18034
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-overflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
95. FreeType TTF File Remote Denial of Service Vulnerability
BugTraq ID: 18329
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/18329
Summary:
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference.
This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
96. FreeType TTF File Remote Buffer Overflow Vulnerability
BugTraq ID: 18326
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/18326
Summary:
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
97. MDPro Index.PHP SQL Injection Vulnerability
BugTraq ID: 22293
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22293
Summary:
MDPro is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.0.76 is vulnerable to this issue; other versions may also be affected.
98. GuppY Error.PHP Remote File Include and Command Execution Vulnerability
BugTraq ID: 15609
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/15609
Summary:
GuppY is prone to a remote file-include vulnerability and to a command-execution vulnerability.
The software fails to properly sanitize data supplied to the 'error.php' script, allowing attackers to specify remotely hosted script files to be executed in the context of the webserver hosting the vulnerable software.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process.
An attacker can also pass malicious PHP commands through this script to be executed on an affected server, which could facilitate unauthorized access as well.
GuppY 4.5.16 and prior versions are vulnerable.
99. Microsoft Windows Unhandled Exception Remote Code Execution Vulnerability
BugTraq ID: 19384
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/19384
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability because of an error in how the OS unloads chained exceptions.
Attackers could exploit this vulnerability via a malicious web page. A successful exploit would aid in the remote compromise of affected computers.
100. Intel 2200BG 802.11 Malformed Disassociation Packets Denial Of Service Vulnerability
BugTraq ID: 22260
Remote: Yes
Last Updated: 2007-01-29
Relevant URL: http://www.securityfocus.com/bid/22260
Summary:
Intel 2200BG driver is prone to a denial-of-service vulnerability because it fails to properly handle malformed network data.
A remote attacker can exploit this issue by crafting and submitting maliciously crafted network data to a victim.
Successful exploits may allow remote attackers to corrupt kernel memory and crash affected computers, effectively denying further service to legitimate users. Given the nature of this issue, code execution seems possible, but this has not been confirmed.
This issue was discovered in the Intel 2200 driver version 9.0.3.9; other versions may also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Vista raises the bar for flaw finders
By: Robert Lemos
Microsoft launches its latest operating system, Windows Vista--software that security researchers say will make finding exploitable vulnerabilities a lot harder.
http://www.securityfocus.com/news/11439
2. Fraud linked to TJX data heist spreads
By: Robert Lemos
Banks and retailers in the United States and Canada report an increasing amount of illicit transactions linked to a server breach at the company that owns retail chains in the U.S., Canada and Europe.
http://www.securityfocus.com/news/11438
3. Bug brokers offering higher bounties
By: Robert Lemos
Private firms and government agencies will pay thousands to tens of thousands of dollars for original research on critical software flaws--no questions asked.
http://www.securityfocus.com/news/11437
4. Vulnerability tallies surged in 2006
By: Robert Lemos
Easy-to-find flaws in Web applications boosted--by more than a third--the number of security issues found last year, according to the major vulnerability databases.
http://www.securityfocus.com/news/11436
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Information Assurance Engineer, London
http://www.securityfocus.com/archive/77/458549
2. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/458550
3. [SJ-JOB] Security Consultant, Austin
http://www.securityfocus.com/archive/77/458551
4. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/458552
5. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/458483
6. [SJ-JOB] Jr. Security Analyst, Schaumburg
http://www.securityfocus.com/archive/77/458484
7. [SJ-JOB] Director, Information Security, Chicago
http://www.securityfocus.com/archive/77/458452
8. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/458451
9. [SJ-JOB] Security Consultant, Newcastle
http://www.securityfocus.com/archive/77/458450
10. [SJ-JOB] Security Consultant, Basingstoke
http://www.securityfocus.com/archive/77/458436
11. [SJ-JOB] Security Engineer, Silver Spring
http://www.securityfocus.com/archive/77/458437
12. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/458442
13. [SJ-JOB] Security Consultant, Worthing
http://www.securityfocus.com/archive/77/458478
14. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/458479
15. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/458213
16. [SJ-JOB] Sales Representative, Cleveland
http://www.securityfocus.com/archive/77/458214
17. [SJ-JOB] Sales Representative, Minneapolis
http://www.securityfocus.com/archive/77/458215
18. [SJ-JOB] Sales Engineer, Nashville
http://www.securityfocus.com/archive/77/458216
19. [SJ-JOB] Security Engineer, Vienna
http://www.securityfocus.com/archive/77/458050
20. [SJ-JOB] Principal Software Engineer, Buffalo Grove
http://www.securityfocus.com/archive/77/458074
21. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/458049
22. [SJ-JOB] Application Security Engineer, Picatinny Arsenal
http://www.securityfocus.com/archive/77/458067
23. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/458069
24. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/458071
25. [SJ-JOB] Security Consultant, Ft. Meade
http://www.securityfocus.com/archive/77/458077
26. [SJ-JOB] Senior Software Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/457983
27. [SJ-JOB] Security Engineer, Hyderabad
http://www.securityfocus.com/archive/77/457984
28. [SJ-JOB] Sales Engineer, Any
http://www.securityfocus.com/archive/77/457987
29. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/458004
30. [SJ-JOB] Security Engineer, Kirkland
http://www.securityfocus.com/archive/77/457906
31. [SJ-JOB] Security Engineer, Santa Monica
http://www.securityfocus.com/archive/77/457907
32. [SJ-JOB] Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/457943
33. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/457948
34. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/457954
35. [SJ-JOB] Sales Representative, Birmingham
http://www.securityfocus.com/archive/77/457905
36. [SJ-JOB] Sales Representative, Berkshire
http://www.securityfocus.com/archive/77/457908
V. INCIDENTS LIST SUMMARY
---------------------------
1. Tracking down random ICMP
http://www.securityfocus.com/archive/75/457701
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Good references to enhance security programming
http://www.securityfocus.com/archive/82/458369
2. CA brightstor msgeng.exe heap overflow exploit (win2k SP0)
http://www.securityfocus.com/archive/82/458368
3. Possible McAfee GroupShield Vulnerability
http://www.securityfocus.com/archive/82/458065
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #326
http://www.securityfocus.com/archive/88/458189
2. Blocking weblinks in MSN/Live Messenger from central point
http://www.securityfocus.com/archive/88/458164
3. Performance impact and filesystem audit
http://www.securityfocus.com/archive/88/458163
4. Automatic spam mover
http://www.securityfocus.com/archive/88/458108
5. IE security zone assignment on 2003 terminal server
http://www.securityfocus.com/archive/88/457897
6. IPSec and GRE (47)
http://www.securityfocus.com/archive/88/457813
VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. BSM, SSH, and Session ID
http://www.securityfocus.com/archive/92/457796
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat
Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts.
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges. Network with 400 delegates from 25 nations, and see solutions from major sponsors.
http://www.blackhat.com