SecurityFocus Newsletter #387

[email protected] 7 Feb 2007 20:04:22 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #387
----------------------------------------

This Issue is Sponsored by: Watchfire

The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online despite security executives' efforts to prevent malicious attacks. This whitepaper identifies the most common methods of attacks that we have seen, and outlines a guideline for developing secure web applications. Download today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008fGl

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. PHP Security From The Inside
       2. Introduction to Windows Integrity Control
II.   BUGTRAQ SUMMARY
       1. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
       2. Wireshark Multiple Protocol Denial of Service Vulnerabilities
       3. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
       4. Ublog Reload HTML Injection and SQL Injection Vulnerabilities
       5. PortailPHP Multiple Remote File Include Vulnerabilities
       6. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
       7. Rapid Classified Multiple Input Validation Vulnerabilities
       8. Ipswitch IMail Server and Collaboration Suite SMTP Daemon Stack Overflow Vulnerability
       9. Cisco IOS SIP Packet Handling Remote Denial Of Service Vulnerability
       10. phpBB++ PHPBB_Root_Path Remote File Include Vulnerability
       11. F3Site Index.PHP HTML Injection Vulnerability
       12. Remotesoft .NET Explorer Remote Stack Buffer Overflow Vulnerability
       13. PHPProbid Lang.PHP Remote File Include Vulnerability
       14. Curium CMS News.PHP SQL Injection Vulnerability
       15. Chicken of the VNC Remote Denial of Service Vulnerability
       16. DreamStats System Rootpath Remote File Include Vulnerability
       17. EQDKP Backup.PHP Authentication Bypass Vulnerability
       18. DirectAdmin Multiple Cross-Site Scripting Vulnerabilities
       19. Flipper Poll Poll.PHP Remote File Include Vulnerability
       20. SMF Index.PHP HTML Injection Vulnerability
       21. Libgtop2 Library Local Buffer Overflow Vulnerability
       22. IBM AIX RDist Unspecified Buffer Overflow Vulnerability
       23. EasyMoblog Multiple Input Validation Vulnerabilities
       24. Zenphoto Directory Listing Disclosure Vulnerability
       25. CA BrightStor ARCserve Backup Message Engine/Tape Engine Remote Buffer Overflow Vulnerability
       26. Computer Associates BrightStor ARCserve Backup  Catirpc.EXE Denial Of Service Vulnerability
       27. FlashFXP PWD Command Remote Buffer Overflow Vulnerability
       28. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
       29. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnerabilities
       30. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
       31. HTTP Commander Multiple Cross-Site Scripting Vulnerabilities
       32. Microsoft Internet Explorer MSXML3 Race Condition Memory Corruption Vulnerability
       33. Samba Deferred CIFS File Open Denial of Service Vulnerability
       34. PostgreSQL Information Disclosure and Denial of Service Vulnerabilities
       35. PHP Session.Save_Path() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
       36. WebMatic Index_Album.PHP Multiple Remote File Include Vulnerabilities
       37. AgerMenu Top.Inc.PHP Remote File Include Vulnerability
       38. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
       39. LightRO CMS Inhalt.PHP Remote File Include Vulnerability 
       40. Comodo Firewall CMDMon.SYS Multiple Denial of Service Vulnerabilities
       41. MySQLNewsEngine Affichearticles.PHP3 Remote File Include Vulnerability
       42. MySQL AB MySQL Multiple Remote Vulnerabilities
       43. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
       44. Avast! Antivirus Server Edition Password Setting Security Bypass Vulnerability
       45. GhostScripter Amazon Shop Search.PHP SQL Injection Vulnerability
       46. Axis Network Camera And Video Server Multiple Vulnerabilities
       47. HP-UX IPFilter Unspecified Remote Denial Of Service Vulnerability
       48. MPG123 HTTP_Open() Connection Handling Denial of Service Vulnerability
       49. SQL-Ledger Redirect Function Arbitrary Code Execution Vulnerability
       50. X-Kryptor Secure Client Privilege Escalation Vulnerability
       51. VMware Clipboard Multiple Information Disclosure Vulnerabilities 
       52. Mozilla Multiple Products Remote Vulnerabilities
       53. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
       54. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
       55. STLPort Library Multiple Unspecified Buffer Overflow Vulnerabilities
       56. HLstats Search Class Unspecified Cross Site Scripting Vulnerability
       57. GnuPG OpenPGP Packet Processing Function Pointer Overwrite Vulnerability
       58. GnuPG Make_Printable_String Remote Buffer Overflow Vulnerability
       59. Woltlab Burning Board Lite Pms.PHP SQL Injection Vulnerability
       60. ISC BIND Remote Fetch Context Denial of Service Vulnerability
       61. GGCMS Remote PHP Code Execution Vulnerability
       62. FlashChat Info.PHP HTML Injection Vulnerability
       63. Coppermine Photo Gallery Multiple Remote And Local File Include Vulnerabilities
       64. Microsoft Internet Explorer Malformed HTML For Script Denial of Service Vulnerability
       65. Yahoo! Messenger Chat Room Denial of Service Vulnerability
       66. Linux Kernel ListXATTR Local Denial of Service Vulnerability
       67. Coppermine Photo Gallery Admin.PHP Shell Command Execution Vulnerability
       68. Jetty Insecure Random Number Generation Vulnerability
       69. Uapplication Uphotogallery Thumbnails.ASP HTML Injection Vulnerability
       70. MySearchEngine Unspecified Cross-Site Scripting Vulnerability
       71. Yukihiro Matsumoto Ruby CGI Module MIME Denial Of Service Vulnerability
       72. Yukihiro Matsumoto Ruby CGI.RB Library Remote Denial Of Service Vulnerability
       73. Adobe ColdFusion User_Agent Error Page Cross-Site Scripting Vulnerability
       74. Categories Hierarchy Class_Template.PHP Remote File Include Vulnerability
       75. Geeklog Multiple Remote File Include Vulnerabilities
       76. Kisisel Site 2007 SQL Injection Vulnerability
       77. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
       78. Xoops Multiple Unspecified SQL Injection Vulnerabilities
       79. MediaWiki Sortable Table Feature HTML Injection Vulnerability
       80. Joomla CMS Multiple SQL Injection Vulnerabilities
       81. Ulogd Unspecified Buffer Overflow Vulnerability
       82. Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness
       83. VirtueMart Joomla ECommerce Edition Multiple Input Validation Vulnerabilities
       84. Letterman ID Parameter Multiple SQL Injection Vulnerabilities
       85. Blue Coat Systems WinProxy Connect Remote Heap Overflow Vulnerability
       86. IBM Tivoli Storage Manager Multiple Buffer Overflow Vulnerabilities
       87. Microsoft Internet Explorer XmlHttpRequest Parameter Validation Weakness
       88. Adrenalin's ASP Chat HTML Injection Vulnerability
       89. SMA-DB Settings.PHP Remote File Include Vulnerability
       90. SmartFTP Banner Remote Heap Buffer Overflow Vulnerability
       91. Simple Invoices Controller.PHP Multiple Local File Include Vulnerabilities
       92. Mambo/Joomla CMS ID SQL Injection Vulnerability
       93. Oracle 10g DBMS_EXPORT_EXTENSION SQL Injection Vulnerability
       94. Links ELinks SMBClient Remote Command Execution Vulnerability
       95. GNU Ed Insecure Temporary File Creation Vulnerability
       96. Flip Multiple Remote File Include Vulnerabilities
       97. Photo Galerie View.PHP SQL Injection Vulnerability
       98. Microsoft Word 2000 Unspecified Code Execution Vulnerability
       99. Microsoft Office Malformed String Remote Code Execution Vulnerability
       100. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
III.  SECURITYFOCUS NEWS
       1. Security pros work to undo teacher's conviction
       2. Vista raises the bar for flaw finders
       3. Fraud linked to TJX data heist spreads
       4. Bug brokers offering higher bounties
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Sales Engineer, North London
       2. [SJ-JOB] Forensics Engineer, Wales
       3. [SJ-JOB] Security Consultant, London / Surrey
       4. [SJ-JOB] Security Consultant, London
       5. [SJ-JOB] Penetration Engineer, Manchester
       6. [SJ-JOB] Security Engineer, London
       7. [SJ-JOB] Sales Engineer, New York or Boston
       8. [SJ-JOB] Security Engineer, Reston
       9. [SJ-JOB] Software Engineer, Milpitas
       10. [SJ-JOB] Penetration Engineer, Redmond
       11. [SJ-JOB] Software Engineer, Milpitas
       12. [SJ-JOB] Security Engineer, Chantilly
       13. [SJ-JOB] Security Engineer, Sydney
       14. [SJ-JOB] Security Engineer, Los Angeles
       15. [SJ-JOB] VP, Information Security, Denver
       16. [SJ-JOB] Director, Information Security, Lanham
       17. [SJ-JOB] Security System Administrator, New York
       18. [SJ-JOB] Security Engineer, Phoenix
       19. [SJ-JOB] Information Assurance Analyst, Suitland
       20. [SJ-JOB] Security System Administrator, New York
       21. [SJ-JOB] Security Engineer, Phoenix
       22. [SJ-JOB] Security Architect, Calgary
       23. [SJ-JOB] Application Security Architect, frankfurt
       24. [SJ-JOB] Security Consultant, Schaumburg
       25. [SJ-JOB] Management, Fiarfax
       26. [SJ-JOB] Sr. Security Engineer, Los Angeles
       27. [SJ-JOB] Management, Burlington
       28. [SJ-JOB] Security Consultant, Atlanta
       29. [SJ-JOB] Security Architect, Los Angeles
V.    INCIDENTS LIST SUMMARY
       1. Announcing a global view on Internet events: ATLAS
       2. Tracking down random ICMP
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Help with Exploit
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
       1. administrator permissions mail server
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. PHP Security From The Inside
By Federico Biancuzzi
Stefan Esser is the founder of both the Hardened-PHP Project and the PHP Security Response Team (which he recently left). Federico Biancuzzi discussed with him how the PHP Security Response Team works, why he resigned from it, what features he plans to add to his own hardening patch, the interaction between Apache and PHP, the upcoming "Month of PHP bugs" initiative, and common mistakes in the design of well-known applications such as WordPress.
http://www.securityfocus.com/columnists/432

2. Introduction to Windows Integrity Control
By Tony Bradley, CISSP-ISSAP
This article takes a look at the Windows Integrity Control (WIC) capabilities in Windows Vista by examining how it protects objects such as files and folders on Vista computers, the different levels of protection it offers, and how administrators can control WIC using the ICACLS command-line tool.
http://www.securityfocus.com/infocus/1887


II.  BUGTRAQ SUMMARY
--------------------
1. Samba Server VFS Plugin AFSACL.SO Remote Format String Vulnerability
BugTraq ID: 22403
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22403
Summary:
Samba is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of users running the affected application. This facilitates the remote compromise of affected computers.

Samba versions 3.06 to 3.0.23d are vulnerable.

2. Wireshark Multiple Protocol Denial of Service Vulnerabilities
BugTraq ID: 22352
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22352
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues may permit attackers to cause crashes and deny service to legitimate users of the application.

Wireshark versions prior to 0.99.5 are affected.

3. Linux Kernel Netfilter Do_Replace Local Buffer Overflow Vulnerability
BugTraq ID: 17178
Remote: No
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/17178
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because the kernel fails to properly bounds-check user-supplied input before using it in a memory copy operation.

Exploiting this issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.

Linux kernel versions prior to 2.6.16 in the 2.6 series are affected by this issue.

4. Ublog Reload HTML Injection and SQL Injection Vulnerabilities
BugTraq ID: 22382
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22382
Summary:
Ublog Reload is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Other attacks are also possible.

Version 1.0.5 is reported vulnerable; other versions may also be affecred.

5. PortailPHP Multiple Remote File Include Vulnerabilities
BugTraq ID: 22381
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22381
Summary:
PortailPHP is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

Version 2 is vulnerable to these issues; other versions may also be affected.

6. Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
BugTraq ID: 22380
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22380
Summary:
Bugzilla is prone to an information-disclosure and an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input and to protect sensitive information from unauthorized users.

Attackers may exploit these issues to execute script code in the context of the affected site or to obtain sensitive information. Arbitrary code execution may allow attackers to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerability; only the development snapshot version 2.23.3  is vulnerable to the information-disclosure issue.

7. Rapid Classified Multiple Input Validation Vulnerabilities
BugTraq ID: 21197
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/21197
Summary:
Rapid Classified is prone to multiple input-validation issues, including multiple cross-site scripting issues and an SQL-injection issue, because the application fails to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

8. Ipswitch IMail Server and Collaboration Suite SMTP Daemon Stack Overflow Vulnerability
BugTraq ID: 19885
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/19885
Summary:
Ipswitch IMail Server and Collaboration Suite are prone to a stack-overflow vulnerability. Updates are available.

This vulnerability may lead to remote arbitrary code execution or denial-of-service conditions.

Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure are vulnerable.

9. Cisco IOS SIP Packet Handling Remote Denial Of Service Vulnerability
BugTraq ID: 22330
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22330
Summary:
CISCO IOS is prone to a denial-of-service vulnerability.

This issue affects only devices that support voice communications but don't have SIP enabled.

Attackers can exploit this issue to reload a vulnerable device. 

IOS releases subsequent to 12.3(14)T, 12.3(8)YC1, and 12.3(8)YG are vulnerable. All 12.4 releases are affected as well.

10. phpBB++ PHPBB_Root_Path Remote File Include Vulnerability
BugTraq ID: 22376
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22376
Summary:
phpBB++ is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

11. F3Site Index.PHP HTML Injection Vulnerability
BugTraq ID: 22379
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22379
Summary:
F3Site is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input. 

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

F3Site 2.1 and prior versions are vulnerable.

12. Remotesoft .NET Explorer Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 22377
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22377
Summary:
Remotesoft .NET Explorer is prone to a remote stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data prior to copying it to an insufficiently sized buffer.

An attacker can leverage this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.

13. PHPProbid Lang.PHP Remote File Include Vulnerability
BugTraq ID: 22374
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22374
Summary:
PHPProbid is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

14. Curium CMS News.PHP SQL Injection Vulnerability
BugTraq ID: 22373
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22373
Summary:
Curium CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

This issue affects Curium CMS 1.03 and prior versions.

15. Chicken of the VNC Remote Denial of Service Vulnerability
BugTraq ID: 22372
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22372
Summary:
Chicken of the VNC is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed server-supplied content.

Successfully exploiting this issue allows remote attackers to crash affected client applications.

Chicken of the VNC 2.0b4 is vulnerable to this issue; other versions may also be affected.

16. DreamStats System Rootpath Remote File Include Vulnerability
BugTraq ID: 22371
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22371
Summary:
DreamStats System is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

17. EQDKP Backup.PHP Authentication Bypass Vulnerability
BugTraq ID: 20805
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/20805
Summary:
EQDKP is prone to an authentication-bypass vulnerability. 

An attacker can exploit this issue to manipulate sensitive data and gain administrative access to the affected application; this may aid in further attacks. 

EQDKP 1.3.1 p1 and prior versions are vulnerable; other versions may also be affected.

18. DirectAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 21049
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/21049
Summary:
DirectAdmin is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Versions 1.28.1 and 2.29 are vulnerable; other versions may also be affected.

19. Flipper Poll Poll.PHP Remote File Include Vulnerability
BugTraq ID: 18461
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/18461
Summary:
Flipper Poll is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage this issue to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

20. SMF Index.PHP HTML Injection Vulnerability
BugTraq ID: 22143
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22143
Summary:
SMF is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

NOTE: To trigger this vulnerability, the attacker must log in with a valid account.

21. Libgtop2 Library Local Buffer Overflow Vulnerability
BugTraq ID: 22054
Remote: No
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22054
Summary:
Libgtop2 library is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying into an insufficiently sized memory buffer.

An attacker may exploit this issue by enticing victims into viewing a maliciously crafted system process with an application that uses the affected library.

Successful exploits may cause arbitrary code to run with the privileges of the victim. Failed exploit attempts will likely cause denial-of-service conditions.

Versions prior to 2.14.6 are reported vulnerable.

22. IBM AIX RDist Unspecified Buffer Overflow Vulnerability
BugTraq ID: 22370
Remote: No
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22370
Summary:
IBM AIX is prone to an unspecified buffer-overflow vulnerability because the application fails to bounds-check  user-supplied data before copying it into an insufficiently size buffer.

An attacker can exploit this vulnerability to execute arbitrary code with superuser privileges. A successful exploit could lead to a complete compromise of affected computers.  

AIX version 5.3 is vulnerable to this issue.

23. EasyMoblog Multiple Input Validation Vulnerabilities
BugTraq ID: 22369
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22369
Summary:
EasyMoblog is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue,  because the application fails to sufficiently sanitize user-supplied input.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, retrieve sensitive information, access or modify data, or exploit latent vulnerability in the underlying database implementation. 

EasyMoblog version 0.5.1 is vulnerable; other versions may also be affected.

24. Zenphoto Directory Listing Disclosure Vulnerability
BugTraq ID: 22368
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22368
Summary:
Zenphoto is prone to a vulnerability that allows remote attackers to view directory listings.

Exploiting this issue could allow remote attackers to view any directory listings within the context of the webserver. This may grant the attacker unauthorized access to information.

Zenphoto versions 1.04 to 1.06 are vulnerable to this issue.

25. CA BrightStor ARCserve Backup Message Engine/Tape Engine Remote Buffer Overflow Vulnerability
BugTraq ID: 22005
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22005
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote buffer-overflow vulnerability because the application fails to perform proper bounds-checking on data supplied to the application. 
 
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer with SYSTEM privileges. Failed exploit attempts may cause denial-of-service conditions. Successful exploits can lead to a complete compromise of affected computers.

This issue affects multiple BrightStor ARCserve Backup application agents and the base product.

26. Computer Associates BrightStor ARCserve Backup  Catirpc.EXE Denial Of Service Vulnerability
BugTraq ID: 22365
Remote: Yes
Last Updated: 2007-02-02
Relevant URL: http://www.securityfocus.com/bid/22365
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a denial-of-service vulnerability because the application mishandles unexpected user-supplied input.
 
A remote attacker may exploit this issue to cause denial-of-service conditions.

27. FlashFXP PWD Command Remote Buffer Overflow Vulnerability
BugTraq ID: 22433
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22433
Summary:
FlashFXP is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.

An attacker can exploit this issue to cause the application to consume excessive CPU resources, denying service to legitimate users. Due to the nature of this issue, the attacker may be able to execute arbitrary code within the context of the affected application.

This issue affects version 3.4.0 build 1145; other versions may also be affected.

28. GD Graphics Library JIS-Encoded Font Buffer Overflow Vulnerability
BugTraq ID: 22289
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22289
Summary:
The GD graphics library is prone to a buffer-overflow vulnerability.

An attacker can exploit this issue to cause denial-of-service conditions in applications implementing the affected library. Arbitrary code execution may also be possible; this has not been confirmed.

29. Samba NSS host lookup Winbind Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 22410
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22410
Summary:
Samba is prone to multiple remote buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker may exploit these issues to execute arbitrary code with superuser privileges, completely compromising affected computers. Failed exploit attempts will result in a denial of service.
 
These issues affects versions 3.0.21 to 3.0.23d.

30. Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 21668
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/21668
Summary:
The Mozilla Foundation has released nine security advisories specifying vulnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- inject arbitrary content
- gain escalated privileges
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

31. HTTP Commander Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22298
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22298
Summary:
HTTP Commander is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

32. Microsoft Internet Explorer MSXML3 Race Condition Memory Corruption Vulnerability
BugTraq ID: 21872
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/21872
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability because of a race condition that may cause a NULL-pointer dereference, read or write operations to invalid addresses, or other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application, but this has not been confirmed. Failed exploit attempts will likely crash the application.

NOTE: SANS has provided new information that lowers the impact of this vulnerability. Please see the reference section for details.

33. Samba Deferred CIFS File Open Denial of Service Vulnerability
BugTraq ID: 22395
Remote: No
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22395
Summary:
The smbd daemon is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to consume excessive memory resources, ultimately crashing the affected application.

This issue affects Samba versions 3.0.6 through 3.0.23d, inclusive.

34. PostgreSQL Information Disclosure and Denial of Service Vulnerabilities
BugTraq ID: 22387
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulnerabilities; fixes are available.

An attacker can exploit these vulnerabilities to cause the backend database to crash and reveal sensitive information. This may lead to other attacks. 

 These issues affect versions 8.0, 8.1, and 8.2. The second issue described also affects version 7.3 and 7.4.

35. PHP Session.Save_Path() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
BugTraq ID: 21508
Remote: No
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/21508
Summary:
PHP is prone to a 'safe_mode' and 'open_basedir' restriction-bypass vulnerability. Successful exploits could allow an attacker to access sensitive information or to write files in unauthorized locations.

This vulnerability would be an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; in such cases, the 'safe_mode' and 'open_basedir' restrictions are expected to isolate users from each other.

PHP version 5.2.0 is vulnerable to this issue.

36. WebMatic Index_Album.PHP Multiple Remote File Include Vulnerabilities
BugTraq ID: 22444
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22444
Summary:
WebMatic is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

This issue affects version 2.6; other versions may also be affected.

37. AgerMenu Top.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 22442
Remote: Yes
Last Updated: 2007-02-07
Relevant URL: http://www.securityfocus.com/bid/22442
Summary:
AgerMenu is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.01 is vulnerable; other versions may also be affected.

38. KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability
BugTraq ID: 22428
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22428
Summary:
Konquerer is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.

Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.

All versions of KDE up to and including KDE 3.5.6 are vulnerable to this issue. Apple Safari web browser is also vulnerable to this issue.

39. LightRO CMS Inhalt.PHP Remote File Include Vulnerability 
BugTraq ID: 22430
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22430
Summary:
LightRO CMS is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

40. Comodo Firewall CMDMon.SYS Multiple Denial of Service Vulnerabilities
BugTraq ID: 22357
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22357
Summary:
Comodo Firewall is prone to multiple denial-of-service vulnerabilities because it fails to adequately validate user supplied data.

Exploiting these issues may permit attackers to cause system crashes and deny service to legitimate users. Presumaby, attackers may also be able to execute arbitrary code, but this has not been confirmed.

Comodo Firewall Pro 2.4.16.174 and Comodo Personal Firewall 2.3.6.81 are vulnerable; other versions may also be affected.

41. MySQLNewsEngine Affichearticles.PHP3 Remote File Include Vulnerability
BugTraq ID: 22431
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22431
Summary:
MySQLNewsEngine is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

42. MySQL AB MySQL Multiple Remote Vulnerabilities
BugTraq ID: 12781
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/12781
Summary:
MySQL is reported prone to multiple vulnerabilities that can be exploited by a remote authenticated attacker. The following individual issues are reported: 

- Insecure temporary file-creation vulnerability. Reports indicate that an attacker with 'CREATE TEMPORARY TABLE' privileges on an affected installation may leverage this vulnerability to corrupt files with the privileges of the MySQL process. 

- Input-validation vulnerability. Remote attackers with INSERT and DELETE privileges on the 'mysql' administrative database can exploit this. Reports indicate that this issue may be leveraged to load and execute a malicious library in the context of the MySQL process. 

- Remote arbitrary-code execution vulnerability. Reportedly, the vulnerability may be triggered by employing the 'CREATE FUNCTION' statement to manipulate functions to control sensitive data structures. This issue may be exploited to execute arbitrary code in the context of the database process. 

These issues are reported to exist in MySQL versions prior to MySQL 4.0.24 and 4.1.10a.

43. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
BugTraq ID: 22231
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22231
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed DNSSEC validation requests.

Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.

44. Avast! Antivirus Server Edition Password Setting Security Bypass Vulnerability
BugTraq ID: 22425
Remote: No
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22425
Summary:
Avast! Antivirus Server Edition is prone to a security-bypass vulnerability because of an access-validation error. 

An attacker can exploit this issue to change certain settings in the affected application. This may aid in other attacks.  

This issue affects version prior to 4.7.726.

45. GhostScripter Amazon Shop Search.PHP SQL Injection Vulnerability
BugTraq ID: 15634
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/15634
Summary:
GhostScripter Amazon Shop is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 
 
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
 
GhostScripter Amazon Shop 5.0.0 and prior versions are vulnerable; other versions may also be affected.

46. Axis Network Camera And Video Server Multiple Vulnerabilities
BugTraq ID: 11011
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/11011
Summary:
Multiple vulnerabilities are reported to reside in multiple Axis network video and camera servers:
 
1. A shell metacharacter command-execution vulnerability allows an anonymous user to download the contents of the '/etc/passwd' file on the device. Other commands are also likely to work, facilitating other attacks. 
 
This issue is reported to affect: 
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.34 thru 2.40 
- Axis 2130 network cameras 
- Axis 2401 and 2401 video servers 
 
2. A directory-traversal vulnerability in HTTP POST requests. This attack is demonstrated by an anonymous user calling protected administration scripts. This bypasses authentication checks and gives anonymous users remote adminitration of the devices.
 
This issue is reported to affect: 
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.12 thru 2.40 
- Axis 2130 network cameras 
- Axis 2401,and 2401 video servers 
 
3. A hardcoded backdoor administrative-user issue allows remote attackers to administer affected devices. This likely cannot be disabled. 
 
This issue is reported to affect: 
- Axis StorePoint CD E100 CD-ROM Server with firmware version 5.30 
 
Other products and versions of firmware are likely affected by one or more of these vulnerabilities.

47. HP-UX IPFilter Unspecified Remote Denial Of Service Vulnerability
BugTraq ID: 22103
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22103
Summary:
HP-UX IPFilter is prone to a remote denial-of-service vulnerability.  The cause of this issue is unknown.
 
Exploiting this issue allows remote attackers to cause the computer to crash, denying further service to legitimate users.

48. MPG123 HTTP_Open() Connection Handling Denial of Service Vulnerability
BugTraq ID: 22274
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22274
Summary:
The 'mpg123' media player is prone to a denial-of-service vulnerability when connecting to malicious servers.

An attacker can exploit this issue to cause the affected application to crash, effectively denying service to legitimate users.

49. SQL-Ledger Redirect Function Arbitrary Code Execution Vulnerability
BugTraq ID: 22295
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22295
Summary:
SQL-Ledger is prone to an arbitrary code-execution vulnerability.

An attacker could exploit this issue to execute arbitrary code in the context of the affected application. This could lead to the compromise of a vulnerable system.

SQL-Ledger 2.6 and prior versions are vulnerable.

50. X-Kryptor Secure Client Privilege Escalation Vulnerability
BugTraq ID: 22424
Remote: No
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22424
Summary:
X-Kryptor Secure Client is is prone to a local privilege-escalation vulnerability. 

A local attacker may execute arbitrary code with SYSTEM privileges to completely compromise a vulnerable computer.

51. VMware Clipboard Multiple Information Disclosure Vulnerabilities 
BugTraq ID: 22413
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22413
Summary:
VMware is prone to two information-disclosure vulnerabilities because of multiple design errors in the clipboard plugin.

An attacker can exploit these issues to obtain sensitive information that may lead to further attacks.

Version 5.5.3 build 34685 is vulnerable to these issues; other versions may also be affected.

Note that the clipboard plugin is an add-on feature that is not active by default.

52. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

53. Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, Camino, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code 
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2
- Mozilla Camino 1.0.2

54. Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 17516
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/17516
Summary:
The Mozilla Foundation has released nine security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- gain elevated privileges in JavaScript code, potentially allowing remote machine code execution
- gain access to potentially sensitive information
- bypass security checks
- spoof window contents.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as the information embargo on the Mozilla Bugzilla entries is lifted and as further information becomes available. This BID will then be retired.

These issues are fixed in:
- Mozilla Firefox versions 1.0.8 and 1.5.0.2
- Mozilla Thunderbird versions 1.0.8 and 1.5.0.2
- Mozilla Suite version 1.7.13
- Mozilla SeaMonkey version 1.0.1

55. STLPort Library Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 22423
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22423
Summary:
The STLport library is prone to multiple unspecified buffer-overflow vulnerabilities because the library fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.

Exploiting these issues may allow attackers to execute arbitrary machine code in the context of applications that use the library. Depending on the nature of the applications using the library, these issues may be locally or remotely exploited. Failed exploit attempts may crash the affected applications.

STLport versions prior to 5.0.3 are affected by these issues.

56. HLstats Search Class Unspecified Cross Site Scripting Vulnerability
BugTraq ID: 22422
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22422
Summary:
HLstats is prone to an unspecified cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.

Exploiting this issue may help the attacker steal cookie-based authentication credentials and launch other attacks.

Versions prior to 1.35 are reported affected by this issue.

57. GnuPG OpenPGP Packet Processing Function Pointer Overwrite Vulnerability
BugTraq ID: 21462
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/21462
Summary:
GnuPG is prone to a vulnerability that could permit an attacker to overwrite a function pointer.

This issue occurs because of a design error when dealing with OpenPGP packets. Attackers may exploit this issue to execute arbitrary code.

Successful exploits may result in the remote compromise of computers using the vulnerable application.

58. GnuPG Make_Printable_String Remote Buffer Overflow Vulnerability
BugTraq ID: 21306
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/21306
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Exploiting this issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.

GnuPG versions 1.4.5 and 2.0.0 are vulnerable to this issue; previous versions may also be affected.

59. Woltlab Burning Board Lite Pms.PHP SQL Injection Vulnerability
BugTraq ID: 22415
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22415
Summary:
Woltlab Burning Board Lite is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. This vulnerability depends on MySQL 4.1 or later.    

Woltlab Burning Board Lite 1.0.2 pl3e is vulnerable to this issue; prior versions may also be affected.

60. ISC BIND Remote Fetch Context Denial of Service Vulnerability
BugTraq ID: 22229
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22229
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle unexpected DNS requests.

Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.

61. GGCMS Remote PHP Code Execution Vulnerability
BugTraq ID: 22412
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22412
Summary:
GGCMS  is prone to an arbitrary PHP code-execution vulnerability.

A successful attack would allow attackers to execute script code with the privileges of the webserver process.

Version 1.1.0 RC2 is affected by this issue.

62. FlashChat Info.PHP HTML Injection Vulnerability
BugTraq ID: 22411
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22411
Summary:
FlashChat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input. 

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

FlashChat 4.7.8 and prior versions are vulnerable.

63. Coppermine Photo Gallery Multiple Remote And Local File Include Vulnerabilities
BugTraq ID: 22409
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22409
Summary:
Coppermine Photo Gallery is prone to multiple remote and local  file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary PHP code in the context of the webserver process. This may facilitate a remote compromise of the underlying system; other attacks are also possible.

64. Microsoft Internet Explorer Malformed HTML For Script Denial of Service Vulnerability
BugTraq ID: 22408
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22408
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.

This issue is triggered when an attacker entices a victim user to visit a malicious website.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

This issue affects Internet Explorer version 6; other versions may also be vulnerable.

65. Yahoo! Messenger Chat Room Denial of Service Vulnerability
BugTraq ID: 22407
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22407
Summary:
Yahoo! Messenger is prone to a denial-of-service vulnerability.

Successful exploits will deny service to legitimate users of the application.

Yahoo! Messenger 8.1.0.239 and prior versions are vulnerable.

66. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

Successful exploits will result in denial-of-service conditions or potentially privilege escalation.

67. Coppermine Photo Gallery Admin.PHP Shell Command Execution Vulnerability
BugTraq ID: 22406
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22406
Summary:
Coppermine Photo Gallery is prone to a vulnerability that may permit the execution of arbitrary shell commands. This issue occurs because the application fails to properly sanitize user-supplied input.

Exploiting this issue allows attackers to execute arbitrary commands with the privileges of users running a vulnerable version of the application.

This issue affects version 1.4.10.

68. Jetty Insecure Random Number Generation Vulnerability
BugTraq ID: 22405
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22405
Summary:
Jetty is prone to a vulnerability that lets an attacker determine the seed of a random-number generator. 

An attacker can exploit this issue to obtain session IDs. This may allow the attacker to hijack a user's session. 
 
This issue affects versions prior to 4.2.27 for the 4.x series, 5.1.12 for the 5.x series, 6.0.2 for the 6.0x series, and 6.1.0pre3  for the 6.1.x series.

69. Uapplication Uphotogallery Thumbnails.ASP HTML Injection Vulnerability
BugTraq ID: 22404
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22404
Summary:
Uapplication Uphotogallery is prone to a HTML-injection vulnerability because the application fails to properly sanitize user-supplied input. 

Attacker-supplied HTML and script code would run  in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Uapplication Uphotogallery version 1.1 is reported vulnerable.

70. MySearchEngine Unspecified Cross-Site Scripting Vulnerability
BugTraq ID: 22402
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22402
Summary:
MySearchEngine is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

71. Yukihiro Matsumoto Ruby CGI Module MIME Denial Of Service Vulnerability
BugTraq ID: 20777
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/20777
Summary:
Ruby is prone to a remote denial-of-service vulnerability because the application's CGI module fails to properly handle specific HTTP requests that contain invalid information.
 
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected Ruby CGI Module.

72. Yukihiro Matsumoto Ruby CGI.RB Library Remote Denial Of Service Vulnerability
BugTraq ID: 21441
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/21441
Summary:
Ruby is prone to a remote denial-of-service vulnerability because the application's CGI library fails to properly handle specially crafted HTTP requests.

Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected Ruby CGI library.

73. Adobe ColdFusion User_Agent Error Page Cross-Site Scripting Vulnerability
BugTraq ID: 22401
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22401
Summary:
Adobe ColdFusion is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker could exploit this vulnerability to execute arbitrary script code in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

74. Categories Hierarchy Class_Template.PHP Remote File Include Vulnerability
BugTraq ID: 22400
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22400
Summary:
Categories Hierarchy  is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 2.1.2 is vulnerable to this issue; other versions may also be affected.

75. Geeklog Multiple Remote File Include Vulnerabilities
BugTraq ID: 22386
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22386
Summary:
Geeklog is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

Geeklog 2.0 and previous versions are vulnerable to these issues.

76. Kisisel Site 2007 SQL Injection Vulnerability
BugTraq ID: 22435
Remote: Yes
Last Updated: 2007-02-06
Relevant URL: http://www.securityfocus.com/bid/22435
Summary:
Kisisel Site 2007 is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. 

Kisisel Site 2007 is vulnerable to this issue; prior versions may also be affected.

77. LibSoup Library HTTP Headers Remote Denial of Service Vulnerability
BugTraq ID: 22034
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22034
Summary:
The Libsoup library is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input.

Attackers may exploit this vulnerability to crash an application that relies on the affected library, resulting in a denial-of-service condition.

78. Xoops Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 22399
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22399
Summary:
Xoops is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.

Xoops 2.0.16 is vulnerable.

79. MediaWiki Sortable Table Feature HTML Injection Vulnerability
BugTraq ID: 22397
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22397
Summary:
MediaWiki is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

MediaWiki versions 1.9.0 prior to 1.9.2 are vulnerable to this issue.

80. Joomla CMS Multiple SQL Injection Vulnerabilities
BugTraq ID: 22122
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22122
Summary:
Joomla CMS is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

These issues affect version 1.5.0 beta; other versions may also be affected.

81. Ulogd Unspecified Buffer Overflow Vulnerability
BugTraq ID: 22139
Remote: No
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22139
Summary:
Ulogd is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. 

Exploiting this issue allows attackers to execute arbitrary machine code in the context of the affected daemon. Failed attempts will likely result in denial-of-service conditions.

82. Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness
BugTraq ID: 22396
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22396
Summary:
Mozilla Firefox is prone to a cross-zone security-bypass weakness. This issue allows attackers to open 'file://' URIs from remote websites.

By exploiting this issue in conjunction with other weaknesses or vulnerabilities, attackers may be able to execute arbitrary script code with the elevated privileges that are granted to scripts when they are executed from local sources.

Mozilla Firefox 1.5.0.9 is affected by this issue; other versions may be affected as well.

83. VirtueMart Joomla ECommerce Edition Multiple Input Validation Vulnerabilities
BugTraq ID: 22123
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22123
Summary:
VirtueMart Joomla eCommerce Edition is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

VirtueMart Joomla eCommerce Edition version 1.0.7 is vulnerable.

84. Letterman ID Parameter Multiple SQL Injection Vulnerabilities
BugTraq ID: 22117
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22117
Summary:
Letterman is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

85. Blue Coat Systems WinProxy Connect Remote Heap Overflow Vulnerability
BugTraq ID: 22393
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22393
Summary:
WinProxy is prone to a heap-overflow vulnerability because it fails to perform sufficient boundary checks on user-supplied data before copying it to a buffer.

An attacker could leverage this issue to have arbitrary code execute with administrative privileges. A successful exploit could result in the complete compromise of the affected system.

Versions prior to 6.1r1c are vulnerable.

86. IBM Tivoli Storage Manager Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 21440
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/21440
Summary:
IBM Tivoli Storage Manager is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of message fields before copying them into finite-sized internal memory buffers. 

An attacker can exploit these issues to execute arbitrary code within the context of the Tivoli application. This may facilitate the compromise of affected servers. Authentication is not required to leverage these issues.

Tivoli Storage Manager versions prior to and including 5.2.9 and 5.3.4 are confirmed affected by these issues.

87. Microsoft Internet Explorer XmlHttpRequest Parameter Validation Weakness
BugTraq ID: 14969
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/14969
Summary:
Microsoft Internet Explorer is prone to a weakness that permits the injection of arbitrary HTTP requests due to improper verification of parameters passed to XmlHttpRequest.  
 
An attacker may craft a website that instantiates the affected control and forces the browser to request a site on the same host (or another host in case a forwarding proxy is employed).  The attacker would then intercept the response and steal sensitive data to aid in further attacks. 
 
A successful attack may have various consequences facilitating HTTP request smuggling, man-in-the-middle attacks, and information disclosure.

88. Adrenalin's ASP Chat HTML Injection Vulnerability
BugTraq ID: 22392
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22392
Summary:
Adrenalin's ASP Chat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

89. SMA-DB Settings.PHP Remote File Include Vulnerability
BugTraq ID: 22391
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22391
Summary:
SMA-DB is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

SMA-DB 0.3.9 and prior versions are affected.

90. SmartFTP Banner Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 22390
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22390
Summary:
SmartFTP is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data prior to copying it to an insufficiently sized memory buffer.

Exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the server application, facilitating the compromise of affected computers.

SmartFTP version 2.0.1002 is reported vulnerable; other versions may also be affected.

91. Simple Invoices Controller.PHP Multiple Local File Include Vulnerabilities
BugTraq ID: 22389
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22389
Summary:
Simple Invoices is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.

Exploiting these issues may allow an unauthorized user to view files and execute local scripts.

Versions prior to 20070202 are vulnerable.

92. Mambo/Joomla CMS ID SQL Injection Vulnerability
BugTraq ID: 19734
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/19734
Summary:
Mambo/Joomla CMS are prone to a common SQL-injection because the applications fail to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the applications, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Mambo 4.5.4/4.6 RC2 and Joomla 1.0.10 are vulnerable; other versions may be affected.

93. Oracle 10g DBMS_EXPORT_EXTENSION SQL Injection Vulnerability
BugTraq ID: 17699
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/17699
Summary:
Oracle 10g is prone to an SQL-injection vulnerability. An attacker could exploit this to gain DBA privileges.

This vulnerability was initially thought to have been fixed as part of the Oracle April 2006 Security Update (BID 17590), but this issue reportedly wasn't patched.

Further information indicates that this issue also affects the 'GET_DOMAIN_INDEX_TABLES' and "GET_V2_DOMAIN_INDEX_TABLES' functions.

94. Links ELinks SMBClient Remote Command Execution Vulnerability
BugTraq ID: 21082
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/21082
Summary:
Links and ELinks are prone to a remote command-execution vulnerability because the applications fail to properly process website data containing smb commands.

An attacker can exploit this issue to execute arbitrary smb commands on a victim computer. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Links version 1.00pre12 and ELinks version 0.11.1 are reportedly vulnerable; other versions may also be affected.

NOTE: This vulnerability may be exploited only if 'smbclient' is installed on a target computer.

95. GNU Ed Insecure Temporary File Creation Vulnerability
BugTraq ID: 22129
Remote: No
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22129
Summary:
GNU ed creates temporary files in an insecure way. 

An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application. 

Successfully exploiting a symlink attack may allow an attacker to overwrite or corrupt sensitive files. This may result in a denial of service; other attacks may also be possible.

GNU ed 0.3 and prior versions are vulnerable to this issue.

96. Flip Multiple Remote File Include Vulnerabilities
BugTraq ID: 22385
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22385
Summary:
Flip is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Flip version 2.01-final 1.0 is vulnerable to these issues.

97. Photo Galerie View.PHP SQL Injection Vulnerability
BugTraq ID: 22384
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22384
Summary:
Photo Galerie is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

This issue affects Photo Galerie Standard 1.1 and prior versions.

98. Microsoft Word 2000 Unspecified Code Execution Vulnerability
BugTraq ID: 22225
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22225
Summary:
Microsoft Word 2000 is prone to an unspecified remote code-execution vulnerability. 

Microsoft Word 2000 is confirmed vulnerable to an unspecified remote code-execution issue. Exploit attempts against Word 2003/XP will consume all CPU resources and will cause a denial of service for legitimate users.

Note that this issue is distinct from issues described in BID 21589 (Microsoft Word Code Execution Vulnerability), BID 21451 (Microsoft Word Unspecified Remote Code Execution Vulnerability), and BID 21518 (Microsoft Word Unspecified Code Execution Vulnerability).

99. Microsoft Office Malformed String Remote Code Execution Vulnerability
BugTraq ID: 22383
Remote: Yes
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/22383
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This issue occurs when the application processes maliciously crafted files.

This issue is currently being exploited via Excel files (.xls), but other Office applications are also reported vulnerable.

An attacker could exploit this issue by enticing a victim into opening a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

100. Linux Kernel Netfilter Do_Add_Counters Local Race Condition Vulnerability
BugTraq ID: 18113
Remote: No
Last Updated: 2007-02-05
Relevant URL: http://www.securityfocus.com/bid/18113
Summary:
The Linux kernel is susceptible to a local race-condition vulnerability.

This issue allows local attackers to gain access to potentially sensitive kernel memory, aiding them in further attacks. Failed exploit attempts may crash the kernel, denying service to legitimate users.

This issue is exploitable only by local users who have superuser privileges or have the CAP_NET_ADMIN capability. This issue is therefore a security concern only if computers run virtualization software that allows users to have superuser access to guest operating systems or if the CAP_NET_ADMIN capability is given to untrusted users.

Linux kernel versions prior to 2.6.16.17 in the 2.6 series are affected by this issue.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Security pros work to undo teacher's conviction
By: Robert Lemos
Researchers aim to recreate what caused a classroom PC to start displaying pornographic pop-ups, an incident that has led to four felony convictions for the substitute teacher involved.
http://www.securityfocus.com/news/11440

2. Vista raises the bar for flaw finders
By: Robert Lemos
Microsoft launches its latest operating system, Windows Vista--software that security researchers say will make finding exploitable vulnerabilities a lot harder.
http://www.securityfocus.com/news/11439

3. Fraud linked to TJX data heist spreads
By: Robert Lemos
Banks and retailers in the United States and Canada report an increasing amount of illicit transactions linked to a server breach at the company that owns retail chains in the U.S., Canada and Europe.
http://www.securityfocus.com/news/11438

4. Bug brokers offering higher bounties
By: Robert Lemos
Private firms and government agencies will pay thousands to tens of thousands of dollars for original research on critical software flaws--no questions asked.
http://www.securityfocus.com/news/11437

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Sales Engineer, North London
http://www.securityfocus.com/archive/77/459350

2. [SJ-JOB] Forensics Engineer, Wales
http://www.securityfocus.com/archive/77/459351

3. [SJ-JOB] Security Consultant, London / Surrey
http://www.securityfocus.com/archive/77/459352

4. [SJ-JOB] Security Consultant, London
http://www.securityfocus.com/archive/77/459353

5. [SJ-JOB] Penetration Engineer, Manchester
http://www.securityfocus.com/archive/77/459368

6. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/459349

7. [SJ-JOB] Sales Engineer, New York or Boston
http://www.securityfocus.com/archive/77/459291

8. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/459292

9. [SJ-JOB] Software Engineer, Milpitas
http://www.securityfocus.com/archive/77/459273

10. [SJ-JOB] Penetration Engineer, Redmond
http://www.securityfocus.com/archive/77/459277

11. [SJ-JOB] Software Engineer, Milpitas
http://www.securityfocus.com/archive/77/459267

12. [SJ-JOB] Security Engineer, Chantilly
http://www.securityfocus.com/archive/77/459157

13. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/459188

14. [SJ-JOB] Security Engineer, Los Angeles
http://www.securityfocus.com/archive/77/459190

15. [SJ-JOB] VP, Information Security, Denver
http://www.securityfocus.com/archive/77/459197

16. [SJ-JOB] Director, Information Security, Lanham
http://www.securityfocus.com/archive/77/458974

17. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/458975

18. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/458976

19. [SJ-JOB] Information Assurance Analyst, Suitland
http://www.securityfocus.com/archive/77/458977

20. [SJ-JOB] Security System Administrator, New York
http://www.securityfocus.com/archive/77/458981

21. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/458973

22. [SJ-JOB] Security Architect, Calgary
http://www.securityfocus.com/archive/77/458913

23. [SJ-JOB] Application Security Architect, frankfurt
http://www.securityfocus.com/archive/77/458911

24. [SJ-JOB] Security Consultant, Schaumburg
http://www.securityfocus.com/archive/77/458912

25. [SJ-JOB] Management, Fiarfax
http://www.securityfocus.com/archive/77/458914

26. [SJ-JOB] Sr. Security Engineer, Los Angeles
http://www.securityfocus.com/archive/77/458769

27. [SJ-JOB] Management, Burlington
http://www.securityfocus.com/archive/77/458768

28. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/458770

29. [SJ-JOB] Security Architect, Los Angeles
http://www.securityfocus.com/archive/77/458771

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Announcing a global view on Internet events: ATLAS
http://www.securityfocus.com/archive/75/459270

2. Tracking down random ICMP
http://www.securityfocus.com/archive/75/457701

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Help with Exploit
http://www.securityfocus.com/archive/88/458938

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. administrator permissions mail server
http://www.securityfocus.com/archive/91/459257

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online despite security executives' efforts to prevent malicious attacks. This whitepaper identifies the most common methods of attacks that we have seen, and outlines a guideline for developing secure web applications. Download today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008fGl