SecurityFocus Newsletter #389

[email protected] 21 Feb 2007 00:18:23 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #389
----------------------------------------

This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts. 
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.  
Network with 400 delegates from 25 nations, and see solutions from major sponsors.  

http://www.blackhat.com


SecurityFocus is proud to introduce the new *Focus On: Vista* section.
Offering Vista related news, columns and vulnerabilities, SecurityFocus is your source for Vista-related security.
*Visit http://www.securityfocus.com/vista to see for yourself.*
------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Laptop Losses and Phishing Fruit Salad
       2. Vista Review: Bugs and Confusion
II.   BUGTRAQ SUMMARY
       1. Xpression News Xnews-Template Multiple Directory Traversal Vulnerabilities
       2. Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability
       3. Microsoft Internet Explorer COM Object Instantiation Variant Memory Corruption Vulnerability
       4. Microsoft Internet Explorer IMJPCKSI COM Object Instantiation Memory Corruption Vulnerability
       5. Microsoft Internet Explorer WinINet.DLL FTP Server Response Parsing Memory Corruption Vulnerability
       6. Microsoft Office Malformed String Remote Code Execution Vulnerability
       7. Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
       8. Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
       9. Microsoft HTML Help ActiveX Control Remote Code Execution Vulnerability
       10. Apple iChat AIM URL Handler Remote Format String Vulnerability
       11. Apple UserNotificationCenter Local Privilege Escalation Vulnerability
       12. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
       13. Mozilla Firefox About:Blank Spoof Vulnerability
       14. Linux Kernel ISO9660 Denial of Service Vulnerability
       15. Linux Kernel ListXATTR Local Denial of Service Vulnerability
       16. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
       17. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
       18. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
       19. Linux Kernel IPV6 Seqfile Handling Local Denial of Service Vulnerability
       20. Linux Kernel AIO_Setup_Ring Local Denial of Service Vulnerability
       21. Linux Kernel S/390 Copy_From_User Local Information Disclosure Vulnerability
       22. Linux Kernel FS/Buffer.C Local Information Disclosure Vulnerability
       23. Linux Kernel Get_FDB_Entries Buffer Overflow Vulnerability
       24. Cisco Multiple Products Multiple Remote Denial Of Service Vulnerabilities
       25. Apple Mac OS X Finder DMG Volume Memory Corruption Vulnerability
       26. Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
       27. CHM Lib Multiple Unspecified Buffer Overflow Vulnerabilities
       28. VicFTPS Remote Buffer Overflow Vulnerability
       29. MoinMoin Multiple Cross Site Scripting Vulnerabilities
       30. Linux-PAM Pam_Unix.SO Authentication Bypass Vulnerability
       31. Libevent DNS Parsing Denial Of Service Vulnerability
       32. VS-Gastebuch Gb_Pfad Remote File Include Vulnerability
       33. XLAtunes View.PHP SQL Injection Vulnerability
       34. Essentia Web Server Long URL Buffer Overflow Vulnerability
       35. Microsoft Excel DATETIME Remote Code Execution Vulnerability
       36. Microsoft Excel COLINFO Remote Code Execution Vulnerability
       37. Microsoft Excel Lotus 1-2-3 File Handling Remote Code Execution Vulnerability
       38. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
       39. IBM AIX Acctctl Command Local Arbitrary Command Execution Vulnerability
       40. DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
       41. F-Secure Anti-Virus Gatekeeper and Gateway for Linux Local Privilege Escalation Vulnerability
       42. KDE DCOPServer Local Denial of Service Vulnerability
       43. IBM Director Multiple Remote Input Validation Vulnerabilities
       44. InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
       45. Drupal Recipe Module HTML Injection Vulnerability
       46. KDE / Konqueror Embedded Common Name Certificate Validation Vulnerability
       47. PostgreSQL Information Disclosure and Denial of Service Vulnerabilities
       48. Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
       49. EBay Enhanced Picture Service ActiveX Remote Buffer Overflow Vulnerability
       50. Fire-Mouse TopList Add.PHP HTML Injection Vulnerability
       51. Microsoft Internet Explorer Structured Graphics Control Denial Of Service Vulnerability
       52. Mozilla Firefox HTML Parsing Null Pointer Dereference Denial of Service Vulnerability
       53. OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
       54. Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
       55. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
       56. AdMentor Admin Login SQL Injection Vulnerability
       57. Multiple Vendor Antivirus Products Malformed ZIP Archive Scan Evasion Vulnerability
       58. Dokeos Multiple Remote File Includes Vulnerabilities
       59. Cahier De Textes SQL Injection Vulnerabilities
       60. IBM AIX Named8 Local Privilege Escalation Vulnerability
       61. PHP Blue Dragon CMS Multiple Remote File Include Vulnerabilities
       62. Golden FTP Server NLST Command Remote Buffer Overflow Vulnerability
       63. Albatross Remote Arbitrary Code Execution Vulnerability
       64. DoceboLMS Lang Parameter Multiple Remote File Include Vulnerabilities
       65. CaLogic Calendars Multiple Remote File Include Vulnerabilities
       66. Glossaire Remote File Include Vulnerability
       67. CodeAvalanche News Default.ASP SQL Injection Vulnerability
       68. ICQ Banner Ad Cross-Application Scripting Vulnerability
       69. Webmin Remote Directory Traversal Vulnerability
       70. VUBB User Parameter Cross-Site Scripting Vulnerability
       71. Nessus LibNASL Arbitrary Code Execution Vulnerability
       72. Saxopress URL Parameter Directory Traversal Vulnerability
       73. ProFTPD Controls Module Local Buffer Overflow Vulnerability
       74. LocazoList Classifieds Viewmsg.ASP SQL Injection Vulnerability
       75. AWeb's Scripts Seller Buy.PHP Authorization Bypass Vulnerability
       76. PHPNewsManager Multiple SQL Injection Vulnerabilities
       77. IBM WebSphere Large HTTP Header Buffer Overflow Vulnerability
       78. Daverave HitHost Multiple Cross-Site Scripting Vulnerabilities
       79. PHPWebGallery Multiple SQL Injection Vulnerabilities
       80. E107 SQL Injection Vulnerability
       81. CSDoom 2005 Multiple Buffer Overflow and Format String Vulnerabilities
       82. Skull-Splitter PHP Guestbook HTML Injection Vulnerability
       83. Axigen POP3 Service Remote Format String Vulnerability
       84. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
       85. MediaWiki AJAX Index.PHP Cross-Site Scripting Vulnerability
       86. Sun Java Runtime Environment Information Disclosure Vulnerabilities
       87. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
       88. ISC BIND Remote Fetch Context Denial of Service Vulnerability
       89. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
       90. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vulnerability
       91. Sun Java RunTime Environment GIF Images Buffer Overflow Vulnerability
       92. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflow Vulnerability
       93. Yahoo! Messenger Message Handling Denial of Service Vulnerability
       94. Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
       95. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnerability
       96. Yahoo! Messenger URL Handler Remote Denial Of Service Vulnerability
       97. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
       98. KOffice PPT Files Integer Overflow Vulnerability
       99. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerability
       100. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulnerability
III.  SECURITYFOCUS NEWS
       1. Imperfect Storm aids spammers
       2. U.S. calls for more organized cyber response
       3. Security pros work to undo teacher's conviction
       4. Vista raises the bar for flaw finders
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Security Engineer, Seattle
       2. [SJ-JOB] Security Consultant, Washington DC
       3. [SJ-JOB] Security Consultant, Chicago
       4. [SJ-JOB] Sr. Security Engineer, Cupertino
       5. [SJ-JOB] Auditor, Milwaukee
       6. [SJ-JOB] Application Security Engineer, Louisville
       7. [SJ-JOB] Technology Risk Consultant, St Louis
       8. [SJ-JOB] Security Consultant, Springfield
       9. [SJ-JOB] Security Consultant, Calgary
       10. [SJ-JOB] Forensics Engineer, Calgary
       11. [SJ-JOB] Developer, Melbourne
       12. [SJ-JOB] Developer, Fort Meade
       13. [SJ-JOB] Application Security Architect, Pune
       14. [SJ-JOB] Sales Engineer, Superior
       15. [SJ-JOB] Sr. Security Engineer, Miami
       16. [SJ-JOB] Jr. Security Analyst, Reading/London
       17. [SJ-JOB] Security Consultant, Springfield
       18. [SJ-JOB] Security Engineer, Manhattan
       19. [SJ-JOB] Account Manager, Riyadh
       20. [SJ-JOB] Security System Administrator, Reston
       21. [SJ-JOB] Evangelist, Superior
       22. [SJ-JOB] Security Engineer, Superior
       23. [SJ-JOB] Security System Administrator, Mt. Laurel
       24. [SJ-JOB] Sales Representative, Los Angeles
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Hacking the Oracle SYS password
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #329
       2. Time Zone change and Kerberos Auth
VIII. SUN FOCUS LIST SUMMARY
       1. Sol DST issues - revisited
IX.   LINUX FOCUS LIST SUMMARY
       1. Did I get hacked?
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Laptop Losses and Phishing Fruit Salad
By Dr. Neal Krawetz
Dr. Neal Krawetz takes a look at the numbers behind reports of laptop thefts and phishing attacks, showing inconsistent metrics and the difficulty in using numbers to determine the real level of threat.
http://www.securityfocus.com/columnists/435

2. Vista Review: Bugs and Confusion
By Thomas C. Greene
The Register's Thomas C. Greene offers an entertaining review of Windows Vista, noting price differences in Europe, driver compatibility issues, and security and user interface issues that affect the Vista experience.
http://www.securityfocus.com/columnists/436


II.  BUGTRAQ SUMMARY
--------------------
1. Xpression News Xnews-Template Multiple Directory Traversal Vulnerabilities
BugTraq ID: 22609
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22609
Summary:
Xpression News is prone to multiple directory-traversal vulnerabilities because the application fails to properly sanitize user-supplied input. 

An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid the attacker in further attacks.

Xpression News version 1.0.1 is vulnerable to these issues.

2. Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability
BugTraq ID: 21910
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21910
Summary:
Multiple PDF readers are prone to multiple remote buffer-overflow vulnerabilities because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker may be able exploit this issue to execute arbitrary code within the context of the affected application. In some circumstances, the vulnerability can be exploited only to cause a denial of service.

3. Microsoft Internet Explorer COM Object Instantiation Variant Memory Corruption Vulnerability
BugTraq ID: 22504
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22504
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when instantiating certain COM objects.

     Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

Internet Explorer 7 on Microsoft Vista is not affected by this issue; Internet Explorer 7 on other Windows versions is affected only if COM objects have been enabled by the ActiveX opt-in feature.

This issue is similar to the ones described in previous COM object instantiation records, but it affects a different set of COM objects.

4. Microsoft Internet Explorer IMJPCKSI COM Object Instantiation Memory Corruption Vulnerability
BugTraq ID: 22486
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22486
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when instantiating certain COM objects.

     Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

Internet Explorer 7 on Microsoft Vista is not affected by this issue; Internet Explorer 7 on other Windows versions is affected only if COM objects have been enabled by the ActiveX opt-in feature.

This BID is similar to the one described in BID 15827 (Microsoft Internet Explorer COM Object Instantiation Memory Corruption Vulnerability), but it affects a different set of COM objects.

5. Microsoft Internet Explorer WinINet.DLL FTP Server Response Parsing Memory Corruption Vulnerability
BugTraq ID: 22489
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22489
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when parsing certain FTP server responses.

 Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

6. Microsoft Office Malformed String Remote Code Execution Vulnerability
BugTraq ID: 22383
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22383
Summary:
Microsoft Office is prone to a remote code-execution vulnerability. This issue occurs when the application processes maliciously crafted files.

This issue is currently being exploited via Excel files (.xls), but other Office applications may also be vulnerable.

An attacker could exploit this issue by enticing a victim into opening a malicious Office file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

7. Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
BugTraq ID: 20325
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20325
Summary:
Microsoft PowerPoint is prone to a remote code-execution vulnerability.

Exploiting this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint (.ppt) document to a user.

8. Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
BugTraq ID: 20704
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20704
Summary:
Microsoft Internet Explorer is prone to a memory-corruption condition when processing a specific method from the 'ADODB.Connection.2.7' instantiated ActiveX Object.

Successful exploits may allow attackers to crash the application, denying further service to users. This issue may also be exploited to execute arbitrary machine-code, but this has not been confirmed.

This issue does not affect Microsoft Data Access Components 2.8 on Windows Vista.

9. Microsoft HTML Help ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 22478
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22478
Summary:
The Microsoft HTML Help ActiveX control is prone to a remote code-execution vulnerability. 

An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

10. Apple iChat AIM URL Handler Remote Format String Vulnerability
BugTraq ID: 22146
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22146
Summary:
Apple iChat is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the application and to compromise affected computers.

Apple iChat version 3.1.6 (v441) is reported vulnerable; other versions may also be affected.

11. Apple UserNotificationCenter Local Privilege Escalation Vulnerability
BugTraq ID: 22188
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22188
Summary:
Apple Mac OS X is prone to a local privilege-escalation vulnerability. This issue stems from a flaw in the UserNotificationCenter application that results in arbitrary code-execution with wheel-group privileges.

Exploiting this issue allows local attackers to gain elevated privileges, potentially leading to a complete compromise of affected computers.

This issue affects Apple Mac OS X version 10.4.8; other versions may also be affected.

12. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 22304
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22304
Summary:
Apple iChat is prone to multiple remote denial-of-service vulnerabilities.  These issues affect the Bonjour functionality. 
 
Apple iChat 3.1.6 is reported affected; other versions may be vulnerable as well.

13. Mozilla Firefox About:Blank Spoof Vulnerability
BugTraq ID: 22601
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22601
Summary:
Mozilla Firefox is prone to a vulnerability that may allow attackers to spoof browser windows. This occurs because of a flaw in the security model of the application's JavaScript engine.

Successfully exploiting this issue may allow attackers to spoof legitimate websites in a manner that may be difficult for unsuspecting users to differentiate between them. This may aid in phishing or other social-engineering attacks.

14. Linux Kernel ISO9660 Denial of Service Vulnerability
BugTraq ID: 20920
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20920
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue affects the code that handles the ISO9660 filesystem.

An attacker can exploit this issue to crash the affected computer, denying service to legitimate users.

15. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

Successful exploits will result in denial-of-service conditions or potentially privilege escalation.

16. Linux Kernel Dev_Queue_XMIT Local Denial of Service Vulnerability
BugTraq ID: 22317
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22317
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A local attacker can exploit this issue to corrupt data and cause the kernel to become unresponsive, denying further service to  legitimate users.

17. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
BugTraq ID: 21604
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21604
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability because the kernel fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker may exploit this issue to execute arbitrary code with kernel-level privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will result in denial-of-service conditions. 

Versions prior to 2.4.33.5 are vulnerable to this issue.

18. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
BugTraq ID: 21663
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21663
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability due to a design error.

A local attacker can exploit this issue to cause the kernel to become unresponsive, denying further service to  legitimate users.

Linux Kernel versions prior to 2.4.33.6 are vulnerable.

19. Linux Kernel IPV6 Seqfile Handling Local Denial of Service Vulnerability
BugTraq ID: 20847
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20847
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the way seqfiles are handled in the kernel.

This vulnerability allows local users to cause an infinite loop, resulting in a crash and denying further service to legitimate users.

This issue affects the Linux kernel 2.6 series up to 2.6.18-stable.

20. Linux Kernel AIO_Setup_Ring Local Denial of Service Vulnerability
BugTraq ID: 22193
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22193
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability because the kernel fails to properly initialize a variable.

Exploiting this issue allows local attackers to cause kernel crashes, denying service to legitimate users.

21. Linux Kernel S/390 Copy_From_User Local Information Disclosure Vulnerability
BugTraq ID: 20379
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20379
Summary:
The Linux kernel is prone to a local information-disclosure vulnerability on the S/390 architecture because the kernel fails to properly initialize kernel memory before returning it to user-space programs.

Successfully exploiting this issue allows local attackers to gain access to potentially sensitive information contained in kernel memory, aiding them in further attacks.

Linux kernel versions prior to 2.6.19-rc1 on the S/390 architecture are vulnerable to this issue.

22. Linux Kernel FS/Buffer.C Local Information Disclosure Vulnerability
BugTraq ID: 21522
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21522
Summary:
The Linux kernel is prone to a local information-disclosure vulnerability because the kernel fails to properly clear kernel memory after certain errors. 

Successfully exploiting this issue allows local attackers to gain access to potentially sensitive information contained in kernel memory, aiding them in further attacks.

Linux kernel versions prior to 2.6.13 are vulnerable to this issue.

23. Linux Kernel Get_FDB_Entries Buffer Overflow Vulnerability
BugTraq ID: 21353
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21353
Summary:
The Linux kernel is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

Attackers may potentially exploit this issue to execute arbitrary code within the context of the affected kernel, but this has not been confirmed. Successfully exploiting this issue would cause the complete compromise of the affected computer.

Little information is currently known about this vulnerability. Since the affected function is in the network-bridging code, remote attacks may be possible.

24. Cisco Multiple Products Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 22561
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22561
Summary:
Multiple Cisco products are prone to multiple denial-of-service vulnerabilities.

Attackers can exploit these issues to cause vulnerable devices to reload, potentially causing denial-of-service conditions.

25. Apple Mac OS X Finder DMG Volume Memory Corruption Vulnerability
BugTraq ID: 21980
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21980
Summary:
Apple Mac OS X Finder is prone to a memory-corruption vulnerability. This issue occurs when the application fails to handle overly long DMG volume names. 

Due to the nature of this issue, an attacker may be able to execute arbitrary machine code in the context of the affected application, but this has not been confirmed. Failed exploit attempts result in memory corruption and a crash of the application, denying service to legitimate users.

Finder 10.4.6 on Mac OS X 10.4.8 X86 is vulnerable to this issue; other versions may also be affected.

26. Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
BugTraq ID: 22600
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22600
Summary:
Vivvo Article Manager is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary PHP code in the context of the webserver process.

This issue affects version 3.4; other versions may also be affected.

27. CHM Lib Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 22258
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22258
Summary:
CHM Lib is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied input prior to copying it to insufficiently sized memory buffers.

Successfully exploiting these issues may allow remote attackers to execute arbitrary machine code in the context of users running applications that uses the affected library.

Versions prior to 0.39 are vulnerable to these issues.

28. VicFTPS Remote Buffer Overflow Vulnerability
BugTraq ID: 22608
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22608
Summary:
A remote buffer-overflow vulnerability is reported in VicFTPS. This issue occurs because the application fails to properly validate the length of user-supplied strings prior to copying them into finite-sized process buffers. 

An attacker can exploit this issue to cause the affected server to crash and may be able to execute arbitrary code in the context of the server process.

VicFTPS versions prior to  5.0 are vulnerable to this issue.

29. MoinMoin Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 22515
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22515
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
 
Version 1.5.7 is vulnerable; other versions may also be affected.

30. Linux-PAM Pam_Unix.SO Authentication Bypass Vulnerability
BugTraq ID: 22204
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22204
Summary:
Linux-PAM is prone to an authentication-bypass vulnerability because it fails to effectively verify user passwords during the authentication process.

Exploiting this issue could allow an attacker to gain unauthorized access to an affected computer.

Version 0.99.7.0 is vulnerable.

31. Libevent DNS Parsing Denial Of Service Vulnerability
BugTraq ID: 22606
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22606
Summary:
Libevent is prone to a denial-of-service vulnerability.

A remote attacker may exploit this issue to cause the application to crash, denying further service to legitimate users.

Versions 1.2 to 1.2a are vulnerable to this issue.

32. VS-Gastebuch Gb_Pfad Remote File Include Vulnerability
BugTraq ID: 22605
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22605
Summary:
VS-Gastebuch is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary PHP code in the context of the webserver process.

This issue affects version 1.5.3; previous versions may also be affected.

33. XLAtunes View.PHP SQL Injection Vulnerability
BugTraq ID: 22602
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22602
Summary:
XLAtunes is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

34. Essentia Web Server Long URL Buffer Overflow Vulnerability
BugTraq ID: 4159
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/4159
Summary:
Essentia Web Server is a multi-threaded HTTP server designed for Microsoft Windows and Linux environments. Essentia is maintained by Essen. 
 
Essentia is prone to a remote denial of service. This condition may be triggered by submitting an excessively long URL (2000+ bytes). Successful exploitation will deny service to legitimate users and will require that the webserver be restarted to regain normal functionality. 
 
This problem is due to a lack of bounds-checking on the length of URLs. Because of this, an attacker may also be able to exploit this condition to execute arbitrary code. 
 
This issue was reported for Essentia Web Sever v2.1; earlier versions may also be affected.

35. Microsoft Excel DATETIME Remote Code Execution Vulnerability
BugTraq ID: 20344
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20344
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine code in the context of the user running the application. 

Note that Microsoft Office applications include functionality to embed Office files as objects contained in other Office files. As an example, Word files may contain embedded malicious Excel files, making Word documents another possible attack vector.

36. Microsoft Excel COLINFO Remote Code Execution Vulnerability
BugTraq ID: 20391
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20391
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine code in the context of the user running the application. 

Note that Microsoft Office applications include functionality to embed Office files as objects contained in other Office files. As an example, Word files may contain embedded malicious Excel files, making Word documents another possible attack vector.

37. Microsoft Excel Lotus 1-2-3 File Handling Remote Code Execution Vulnerability
BugTraq ID: 20345
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20345
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

A remote attacker may exploit this issue to execute arbitrary machine code in the context of the user running the application. 

This issue was originally described in BID 18989 and has now been assigned its own BID.

38. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 12792
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12792
Summary:
OpenSLP is prone to multiple unspecified buffer-overflow vulnerabilities that may be triggered by malformed SLP (Service Location Protocol) packets. 

If successfully exploited, these issues could allow remote code execution in the context of the software.

39. IBM AIX Acctctl Command Local Arbitrary Command Execution Vulnerability
BugTraq ID: 20206
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20206
Summary:
IBM AIX is prone to an arbitrary-command-execution vulnerability. 

An attacker in the 'adm' group can exploit this vulnerability to execute arbitrary commands with superuser privileges. A successful exploit would lead to a complete compromise of affected computers. 

AIX version 5.3 is vulnerable to this issue.

40. DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
BugTraq ID: 20257
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20257
Summary:
DokuWiki is prone to these vulnerabilities:

- A denial-of-service issue
- An arbitrary-command-execution issue

These issues present themselves when DocuWiki is configured to use ImageMagick.

The denial-of-service issue allows remote attackers to consume excessive CPU resources, denying service to legitimate users. The command-execution issue allows remote attackers to execute arbitrary shell commands with the privileges of the hosting webserver, facilitating a remote compromise of affected computers.

DokuWiki version 2006-03-09 is vulnerable to these issues; other versions may also be affected.

41. F-Secure Anti-Virus Gatekeeper and Gateway for Linux Local Privilege Escalation Vulnerability
BugTraq ID: 15339
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/15339
Summary:
F-Secure Anti-Virus products are prone to a local privilege-escalation vulnerability because of insecure setuid-superuser binary permissions. 
 
Exploiting this vulnerability allows local attackers to gain superuser privileges, leading to a complete compromise of the affected computer.

42. KDE DCOPServer Local Denial of Service Vulnerability
BugTraq ID: 12820
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12820
Summary:
KDE's Desktop Communication Protocol (DCOP) daemon is affected by a local denial-of-service vulnerability. 
 
Reportedly, a user's DCOPServer can be locked up by causing the authentication process to stall. 
 
All versions of KDE prior to 3.4 are affected by this issue. 
 
This BID will be updated when more information is available.

43. IBM Director Multiple Remote Input Validation Vulnerabilities
BugTraq ID: 19915
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/19915
Summary:
IBM Director is prone to multiple input-validation vulnerabilities.

An attacker can exploit these issues to cause denial-of-service conditions, effectively denying service to legitimate users, and to access cookie and authentication data that may aid in further attacks.

44. InnerMedia DynaZip ZIP Archive Handling Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19143
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/19143
Summary:
DynaZip is prone to multiple remote buffer-overflow vulnerabilities when handling malicious ZIP archives.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition. This may lead to arbitrary code execution in the context of an affected user and facilitate a remote compromise.

These vulnerabilities affect DynaZip Max with DZIP32.DLL version 5.0.0.7 and DynaZip Max Secure with DZIPS32.DLL version 6.0.0.4. Other versions may be vulnerable as well.
 
TurboZIP version 6.0 Build 002021004 is also affected by the first issue because it uses the DynaZip library.

45. Drupal Recipe Module HTML Injection Vulnerability
BugTraq ID: 19422
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/19422
Summary:
Drupal Recipe Module is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing the attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

Versions prior to 1.54 are vulnerable to this issue.

46. KDE / Konqueror Embedded Common Name Certificate Validation Vulnerability
BugTraq ID: 7520
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/7520
Summary:
Konqueror Embedded web browser does not correctly validate that Common Name (CN) field for X.509 certificates when a SSL/TLS session is negotiated.  The browser is not able to detect cases where the CN does not match the hostname of the server.  This could lead to a variety of attacks, including the possibility of allowing a malicious server to masquerade as a trusted server. 
 
The non-embedded Konqueror distribution is reportedly not affected by this issue.

47. PostgreSQL Information Disclosure and Denial of Service Vulnerabilities
BugTraq ID: 22387
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22387
Summary:
PostgreSQL is prone to information-disclosure and denial-of-service vulnerabilities; fixes are available.

An attacker can exploit these vulnerabilities to cause the backend database to crash and reveal sensitive information. This may lead to other attacks. 

 These issues affect versions 8.0, 8.1, and 8.2. The second issue described also affects version 7.3 and 7.4.

48. Linley Henzell Dungeon Crawl Unspecified Command Execution Vulnerability
BugTraq ID: 16337
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/16337
Summary:
Dungeon Crawl has been reported to be prone to an unspecified command-execution vulnerability. 

Local attackers can trigger this vulnerability to execute arbitrary commands to gain group games privileges.

49. EBay Enhanced Picture Service ActiveX Remote Buffer Overflow Vulnerability
BugTraq ID: 18921
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18921
Summary:
eBay Enhanced Picture Service ActiveX control is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

An attacker could exploit this issue by creating a malicious web page that would initialize the ActiveX controller and execute arbitrary code within the context of the user.

This issue could allow an attacker to execute arbitrary code.

This issue affects versions 1.0.3.36 and prior.

50. Fire-Mouse TopList Add.PHP HTML Injection Vulnerability
BugTraq ID: 19120
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/19120
Summary:
Fire-Mouse TopList is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.1; other versions may also be vulnerable.

51. Microsoft Internet Explorer Structured Graphics Control Denial Of Service Vulnerability
BugTraq ID: 18855
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18855
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because it fails to handle ActiveX controls properly.

This issue is triggered when an attacker convinces a victim user to activate a malicious ActiveX control.

Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.

52. Mozilla Firefox HTML Parsing Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 17499
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17499
Summary:
Mozilla Firefox is prone to a denial-of-service condition when parsing certain malformed HTML content. Successful exploitation will cause the browser to fail or hang.

Mozilla Firefox versions 1.5.0.1 and prior are prone to this issue.

53. OpenSSH-portable Enabled PAM Delay Information Disclosure Vulnerability
BugTraq ID: 7467
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/7467
Summary:
OpenSSH-portable with PAM support enabled has been reported prone to an information-disclosure vulnerability under certain configurative circumstances. 
 
By analyzing the response time during authentication, remote attackers may be able to determine whether or not the supplied username is valid. 
 
This issue may be related to the issues described in BID 7342 and BID 7343. BID 11781 may also be pertinent; it describes an issue very similar to this one.

54. Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
BugTraq ID: 15423
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/15423
Summary:
Multiple antivirus products from various vendors are reported prone to a vulnerability that may allow malicious files to bypass detection. 

This issue arises when an affected application processes a file with an obscured name. 

This issue could allow malicious files to bypass detection and to be opened by a recipient. 

Update: Symantec is currently investigating this issue in Symantec products. It is unclear at this time if malicious files may evade scanning or if the automatic removal feature fails. This BID will be updated as more information is disclosed.

55. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
BugTraq ID: 22584
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22584
Summary:
SpamAssassin is prone to a remote denial-of-service vulnerability. 

This issue arises when the application handles excessively long URIs.
 
SpamAssassin versions prior to 3.1.8 are vulnerable to this issue.

56. AdMentor Admin Login SQL Injection Vulnerability
BugTraq ID: 22281
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22281
Summary:
AdMentor is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

57. Multiple Vendor Antivirus Products Malformed ZIP Archive Scan Evasion Vulnerability
BugTraq ID: 12793
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12793
Summary:
Multiple antivirus products from various vendors are reported prone to a vulnerability that may allow potentially malformed ZIP archives to bypass detection. 
 
This issue arises when an affected application processes a ZIP archive containing potentially malicious files with specially crafted filenames. 
 
This issue could allow a malicious ZIP archive to bypass detection and to be executed by a recipient. 
 
This vulnerability reportedly affects Trend Micro InterScan VirusWall for Linux version 3.1.  AVG Anti-Virus is reported affected as well. 
 
Sophos Sweep is being removed as a vulnerable package since the vendor has reported that the correct procedure for scanning archives is to use the '-all' switch instead of '-archive'.  The application is not affected if '-all' switch is used to scan a malicious archive. 
 
This BID will be updated when more information becomes available.

58. Dokeos Multiple Remote File Includes Vulnerabilities
BugTraq ID: 20468
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20468
Summary:
Dokeos is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

These issues affect version 1.6.3.

59. Cahier De Textes SQL Injection Vulnerabilities
BugTraq ID: 20389
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20389
Summary:
Cahier de textes is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

60. IBM AIX Named8 Local Privilege Escalation Vulnerability
BugTraq ID: 20198
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/20198
Summary:
AIX is prone to a local privilege-escalation vulnerability

A local attacker can exploit this issue to execute arbitrary commands with superuser privileges on the affected computer. The attacker must have 'system group' permissions to exploit this issue.

AIX 5.2 and 5.3 are affected by this vulnerability.

61. PHP Blue Dragon CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 18609
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18609
Summary:
PHP Blue Dragon CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

62. Golden FTP Server NLST Command Remote Buffer Overflow Vulnerability
BugTraq ID: 17801
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17801
Summary:
Golden FTP Server is prone to a buffer-overflow vulnerability when handling data through the NLST command. 

Reportedly, passing excessive data may overflow a finite-sized internal memory buffer. A successful attack may result in memory corruption as memory adjacent to the buffer is overwritten with user-supplied data. 

This issue may lead to a denial-of-service condition or the execution of arbitrary code.

Version 2.70 of Golden FTP Server is vulnerable to this issue; other versions may also be affected.

63. Albatross Remote Arbitrary Code Execution Vulnerability
BugTraq ID: 16252
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/16252
Summary:
Albatross is prone to an arbitrary code-execution vulnerability. 

Reports indicate that malicious user-supplied data may be insecurely used as part of a template, which may lead to arbitrary code execution. 

A remote attacker may exploit this issue to gain unauthorized access to an affected computer. Other attacks may be possible as well.

64. DoceboLMS Lang Parameter Multiple Remote File Include Vulnerabilities
BugTraq ID: 18110
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18110
Summary:
DoceboLMS is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

65. CaLogic Calendars Multiple Remote File Include Vulnerabilities
BugTraq ID: 18076
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18076
Summary:
CaLogic Calendars is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

CaLogic Calendars 1.2.2 is reported to be vulnerable.  Other versions may be affected as well.

66. Glossaire Remote File Include Vulnerability
BugTraq ID: 18792
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18792
Summary:
Glossaire is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and gain access to the underlying system.

67. CodeAvalanche News Default.ASP SQL Injection Vulnerability
BugTraq ID: 18031
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18031
Summary:
CodeAvalanche News is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. An attacker can disclose the administrative authentication credentials by exploiting this issue.

CodeAvalanche News 1.2 is reported to be vulnerable. Other versions may be affected as well.

68. ICQ Banner Ad Cross-Application Scripting Vulnerability
BugTraq ID: 17913
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17913
Summary:
ICQ is prone to a cross-application scripting vulnerability. This issue is a result of the application accessing content in a different and presumably higher security context than the original content.

An attacker can exploit this issue to have arbitrary attacker-supplied HTML or JavaScript executed on a victim user's computer in the 'My Computer' security zone.

69. Webmin Remote Directory Traversal Vulnerability
BugTraq ID: 18613
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18613
Summary:
It is reported that Webmin may be prone to a directory traversal vulnerability that may allow a remote attacker to access information outside the server root directory. This issue is only reported to present itself in Webmin running on Windows platforms. A remote attacker may traverse outside the server root directory by using encoded '\..' character sequences.

70. VUBB User Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 18562
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18562
Summary:
vuBB is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input before displaying it to users of the application.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

71. Nessus LibNASL Arbitrary Code Execution Vulnerability
BugTraq ID: 7664
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/7664
Summary:
Nessus has reported that various flaws have been discovered in the 'libnasl' library used by the Nessus application. As a result, a malicious NASL script may be able to break outside of the established sandbox environment and execute arbitrary commands on the local system. 
 
Note that this malicious script must be a legitimate plugin that has been uploaded to the Nessus server. Furthermore, the affected Nessus application must have enabled the 'plugins_upload' option (which is disabled by default).

72. Saxopress URL Parameter Directory Traversal Vulnerability
BugTraq ID: 17474
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17474
Summary:
SAXoPRESS is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to retrieve and execute arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

73. ProFTPD Controls Module Local Buffer Overflow Vulnerability
BugTraq ID: 21587
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21587
Summary:
ProFTPD is prone to a local stack-based buffer-overflow vulnerability.

Attackers may exploit this issue to corrupt memory and execute arbitrary code in the context of the server application, resulting in a complete compromise of affected computers.

NOTE: ProFTPD is vulnerable only when compiled with 'mod_ctrls' support and the module is enabled.

74. LocazoList Classifieds Viewmsg.ASP SQL Injection Vulnerability
BugTraq ID: 18254
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18254
Summary:
LocazoList Classifieds is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

75. AWeb's Scripts Seller Buy.PHP Authorization Bypass Vulnerability
BugTraq ID: 17417
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17417
Summary:
AWeb's Scripts Seller is prone to an authorization-bypass vulnerability. This issue is due to a failure in the application to properly verify user-supplied input.

An attacker can exploit this issue to bypass the authorization mechanism and download arbitrary scritps without paying.

76. PHPNewsManager Multiple SQL Injection Vulnerabilities
BugTraq ID: 17301
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17301
Summary:
phpNewsManager is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

phpNewsManager 1.48 is vulnerable; other versions may also be affected.

77. IBM WebSphere Large HTTP Header Buffer Overflow Vulnerability
BugTraq ID: 5749
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/5749
Summary:
A buffer-overflow vulnerability has been reported for IBM WebSphere 4.0.3 running on a Microsoft Windows 2000 platform. Reportedly, IBM WebSphere fails to properly check bounds when receiving HTTP requests. Specifically, the vulnerability is related to the WebSphere plugin not limiting the size of HTTP POST data that would be received by the application server.  
 
The application server will crash when it receives an overly large HTTP POST request.

78. Daverave HitHost Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17025
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17025
Summary:
HitHost is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

79. PHPWebGallery Multiple SQL Injection Vulnerabilities
BugTraq ID: 15837
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/15837
Summary:
PhpWebGallery is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries. 
 
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

80. E107 SQL Injection Vulnerability
BugTraq ID: 17966
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17966
Summary:
e107 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied cookie data before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

81. CSDoom 2005 Multiple Buffer Overflow and Format String Vulnerabilities
BugTraq ID: 17248
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17248
Summary:
csDoom 2005 is prone to multiple buffer-overflow and format-string vulnerabilities.

The buffer-overflow issues are due to the application's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer. The format-string vulnerabilities are due to the application's failure to properly sanitize user-supplied input before using it in a formatted-printing function.

These issues may allow attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the targeted application. Both clients and servers are affected by these issues.

82. Skull-Splitter PHP Guestbook HTML Injection Vulnerability
BugTraq ID: 17136
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/17136
Summary:
PHP Guestbook is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for the theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

83. Axigen POP3 Service Remote Format String Vulnerability
BugTraq ID: 22603
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22603
Summary:
Axigen is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote, unauthenticated attackers to execute arbitrary code with superuser privileges, since the daemon typically runs with elevated privileges. This facitates the complete compromise of affected computers.

Axigen version 2.0.0-beta1 is vulnerable to this issue; other versions may also be affected.

84. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 21675
Remote: No
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21675
Summary:
The Java Runtime Environment is prone to multiple buffer-overflow vulnerabilities the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

A local attacker can exploit these issues to execute arbitrary code with administrative privileges. A successful exploit attempt will lead to the complete compromise of affected computers. Failed exploit attempts will result in a denial of service.

85. MediaWiki AJAX Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 21956
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21956
Summary:
MediaWiki is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

UPDATE: Although a fix was issued to address this issue, attackers may bypass the fix by encoding an exploit in UTF-7.

86. Sun Java Runtime Environment Information Disclosure Vulnerabilities
BugTraq ID: 21674
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21674
Summary:
The Sun Java runtime environment is prone to multiple information-disclosure vulnerabilities. These issues are due to a design flaw in the affected application. 

An attacker can exploit these issues to gain access to sensitive information. This may lead to other attacks.

87. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
BugTraq ID: 21673
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21673
Summary:
The Sun Java Runtime Environment is prone to multiple remote privilege-escalation vulnerabilities. 

An attacker can execute arbitrary code and commands in the context of a user who invokes the Java applet or application. 

A successful attack can facilitate privilege escalation.

88. ISC BIND Remote Fetch Context Denial of Service Vulnerability
BugTraq ID: 22229
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22229
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle unexpected DNS requests.

Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.

89. ISC BIND Remote DNSSEC Validation Denial of Service Vulnerability
BugTraq ID: 22231
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22231
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed DNSSEC validation requests.

Successfully exploiting this issue allows remote attackers to crash affected DNS servers, denying further service to legitimate users.

90. Squid Proxy Malformed HTTP Header Parsing Cache Poisoning Vulnerability
BugTraq ID: 12433
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12433
Summary:
Squid Proxy is reported prone to a cache-poisoning vulnerability when processing malformed HTTP requests and responses. This issue results from insufficient sanitization of user-supplied data. 

Squid versions 2.5 and earlier are reported prone to this issue.

91. Sun Java RunTime Environment GIF Images Buffer Overflow Vulnerability
BugTraq ID: 22085
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22085
Summary:
The Java Runtime Environment is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. 

An attacker may exploit this issue by enticing a victim into opening a maliciously crafted Java applet.

The attacker can exploit these issues to execute arbitrary code with the privileges of the victim. Failed exploit attempts will likely result in denial-of-service conditions.

This issue is being tracked by BugID: 6445518

92. Snort/Sourcefire DCE/RPC Packet Reassembly Stack Buffer Overflow Vulnerability
BugTraq ID: 22616
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22616
Summary:
Snort IDS and Sourcefire Intrusion Sensor are prone to a stack-based buffer overflow vulnerability because the network intrusion detection (NID) systems fail to handle specially crafted 'DCE' and 'RPC' network packets. 

An attacker can exploit this issue to execute malicious code in the context of the user running the affected application. Failed attempts will likely cause these applications to crash.

93. Yahoo! Messenger Message Handling Denial of Service Vulnerability
BugTraq ID: 18622
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/18622
Summary:
Yahoo! Messenger is prone to a denial-of-service vulnerability. Successful exploitation will cause the application to crash, effectively denying service.

This issue affects version 7.5.0.814; other versions may also be vulnerable.

94. Yahoo! Messenger Remote Search String Arbitrary Browser Navigation Vulnerability
BugTraq ID: 19211
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/19211
Summary:
Yahoo! Messenger is prone to a browser-navigation vulnerability that may permit a remote attacker to open a browser window on the victim user's computer to an arbitrary page.

This issue occurs because the application fails to sanitize malicious messages.

An attacker may be able to exploit this issue to execute a web browser and load an arbitrary web page. This may lead to other attacks.

This issue affects version 7.5.0.814; other versions may also be vulnerable.

95. Squid Proxy Oversize HTTP Headers Unspecified Remote Vulnerability
BugTraq ID: 12412
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12412
Summary:
A remote unspecified vulnerability reportedly affects Squid Proxy. This issue is due to the application's failure to properly handle malformed HTTP headers. 

The impact of this issue is currently unknown. This BID will be updated when more information becomes available.

96. Yahoo! Messenger URL Handler Remote Denial Of Service Vulnerability
BugTraq ID: 13626
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/13626
Summary:
Yahoo! Messenger is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions. 
 
A remote user can cause Yahoo! Messenger to disconnect through malicious emails or web pages. 
 
This issue is reported to affect Yahoo! Messenger versions 5.x to 6.0 Windows; other versions on other operating systems may also be affected.

97. Squid Proxy WCCP recvfrom() Buffer Overflow Vulnerability
BugTraq ID: 12432
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12432
Summary:
The Squid proxy server is vulnerable to a remotely exploitable buffer-overflow vulnerability. The vulnerability resides in Squid's implementation of WCCP (web cache communication protocol), a UDP-based web cache management protocol. The condition is triggered when the server reads a packet that is larger than the size of the buffer allocated to store it. This can occur because 'recvfrom()' is passed an incorrect value for its 'len' argument.

98. KOffice PPT Files Integer Overflow Vulnerability
BugTraq ID: 21354
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/21354
Summary:
KOffice is prone to an integer-overflow vulnerability because it fails to properly validate user-supplied data.

An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. Failed exploit attempts will likely cause denial-of-service conditions.

KOffice versions prior to 1.6.1 are affected.

99. Squid Proxy squid_ldap_auth Authentication Bypass Vulnerability
BugTraq ID: 12431
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/12431
Summary:
Squid Proxy is reported prone to an authentication-bypass vulnerability. This issue seems to result from insufficient input validation. 

The 'squid_ldap_auth' module is reported affected by this issue. A remote attacker may gain unauthorized access or gain elevated privileges from bypassing access controls. 

Squid versions 2.5 and earlier are reported prone to this vulnerability.

100. Ekiga GM_Main_Window_Flash_Message  Remote Format String Vulnerability
BugTraq ID: 22613
Remote: Yes
Last Updated: 2007-02-20
Relevant URL: http://www.securityfocus.com/bid/22613
Summary:
Ekiga is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

A remote attacker may execute arbitrary code with the privileges of the currently logged in user. Failed exploit attempts will result in a denial-of-service. 
 
This issue affects versions prior to 2.0.5.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Imperfect Storm aids spammers
By: Robert Lemos
The misnamed Storm Worm, actually a Trojan horse, underscores the evolution of spammers' tactics, including massive attacks on their critics and competitors. <em>The first article in a two-part series.</em>
http://www.securityfocus.com/news/11442

2. U.S. calls for more organized cyber response
By: Robert Lemos
Federal officials renew calls for the private sector to help manage threats to critical infrastructure and the Internet.
http://www.securityfocus.com/news/11441

3. Security pros work to undo teacher's conviction
By: Robert Lemos
Researchers aim to recreate what caused a classroom PC to start displaying pornographic pop-ups, an incident that has led to four felony convictions for the substitute teacher involved.
http://www.securityfocus.com/news/11440

4. Vista raises the bar for flaw finders
By: Robert Lemos
Microsoft launches its latest operating system, Windows Vista--software that security researchers say will make finding exploitable vulnerabilities a lot harder.
http://www.securityfocus.com/news/11439

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/460259

2. [SJ-JOB] Security Consultant, Washington DC
http://www.securityfocus.com/archive/77/460261

3. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/460262

4. [SJ-JOB] Sr. Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/460263

5. [SJ-JOB] Auditor, Milwaukee
http://www.securityfocus.com/archive/77/460264

6. [SJ-JOB] Application Security Engineer, Louisville
http://www.securityfocus.com/archive/77/460271

7. [SJ-JOB] Technology Risk Consultant, St Louis
http://www.securityfocus.com/archive/77/460268

8. [SJ-JOB] Security Consultant, Springfield
http://www.securityfocus.com/archive/77/460175

9. [SJ-JOB] Security Consultant, Calgary
http://www.securityfocus.com/archive/77/460226

10. [SJ-JOB] Forensics Engineer, Calgary
http://www.securityfocus.com/archive/77/460227

11. [SJ-JOB] Developer, Melbourne
http://www.securityfocus.com/archive/77/460228

12. [SJ-JOB] Developer, Fort Meade
http://www.securityfocus.com/archive/77/460174

13. [SJ-JOB] Application Security Architect, Pune
http://www.securityfocus.com/archive/77/460109

14. [SJ-JOB] Sales Engineer, Superior
http://www.securityfocus.com/archive/77/460110

15. [SJ-JOB] Sr. Security Engineer, Miami
http://www.securityfocus.com/archive/77/460111

16. [SJ-JOB] Jr. Security Analyst, Reading/London
http://www.securityfocus.com/archive/77/460112

17. [SJ-JOB] Security Consultant, Springfield
http://www.securityfocus.com/archive/77/460119

18. [SJ-JOB] Security Engineer, Manhattan
http://www.securityfocus.com/archive/77/460120

19. [SJ-JOB] Account Manager, Riyadh
http://www.securityfocus.com/archive/77/460121

20. [SJ-JOB] Security System Administrator, Reston
http://www.securityfocus.com/archive/77/460113

21. [SJ-JOB] Evangelist, Superior
http://www.securityfocus.com/archive/77/460069

22. [SJ-JOB] Security Engineer, Superior
http://www.securityfocus.com/archive/77/460066

23. [SJ-JOB] Security System Administrator, Mt. Laurel
http://www.securityfocus.com/archive/77/460067

24. [SJ-JOB] Sales Representative, Los Angeles
http://www.securityfocus.com/archive/77/460072

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Hacking the Oracle SYS password
http://www.securityfocus.com/archive/82/460361

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #329
http://www.securityfocus.com/archive/88/460056

2. Time Zone change and Kerberos Auth
http://www.securityfocus.com/archive/88/459446

VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. Sol DST issues - revisited
http://www.securityfocus.com/archive/92/460368

IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat

Black Hat Europe, March 27-30 in Amsterdam, is Europe's premier technical event for ICT security experts. 
Featuring 10 hands-on training courses and 30 Briefings presentations with lots of new content-the best of Black Hat focused on Europe's infosec challenges.  
Network with 400 delegates from 25 nations, and see solutions from major sponsors.  

http://www.blackhat.com