SecurityFocus Newsletter #390

[email protected] 27 Feb 2007 23:14:45 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #390
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: Hackerproof your Web Apps with WebInspect - FREE Test
Hackers exploiting Web applications gain entry to backend data via Port 80 and 443! 
Firewalls and IDS don't stop these attacks because hackers using the Web App Layer are NOT 
seen as intruders. Run a FREE Test of your Web Apps via our 15 Day WebInspect Product Trial 
that delivers a comprehensive vulnerability report. 

https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cj4h


SecurityFocus is proud to introduce the new *Focus On: Vista* section.
Offering Vista related news, columns and vulnerabilities, SecurityFocus is your source for Vista-related security.
*Visit http://www.securityfocus.com/vista to see for yourself.*
------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Building Secure Applications: Consistent Logging
       2. Vista Review: Bugs and Confusion
II.   BUGTRAQ SUMMARY
       1. TCPDump ISIS Decoding Routines Denial Of Service Vulnerability
       2. WebMplayer Multiple Input Validation Vulnerabilities
       3. Putmail Improper Authentication Weakness
       4. Mozilla Firefox OnUnload Memory Corruption Vulnerability
       5. Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
       6. Microsoft Office 2003 Denial of Service Vulnerability
       7. UFO2000 Multiple Remote Vulnerabilities
       8. PHPMIP Top.PHP Remote File Include Vulnerability
       9. UFO2000 SQL Injection Vulnerability
       10. Nexuiz Remote Command Execution and Denial of Service Vulnerabilities
       11. NoMoKeTos PHPBB Module PHPBB_Root_Path Remote File Include Vulnerability
       12. CS-Gallery Index.PHP Remote File Include Vulnerability
       13. PHPWebGallery Multiple Scripts Multiple Cross-Site Scripting Vulnerabilities
       14. PHPPeanuts Inspect.PHP Remote File Include Vulnerability
       15. Windows Shell User Logon ActiveX Control Create Method Unauthorized User Creation Vulnerability
       16. Coppermine Photo Gallery ThumbNails.PHP SQL Injection Vulnerability
       17. Extreme PHPBB PHPBB_Root_Path Remote File Include Vulnerability
       18. PHP-Nuke Multiple SQL Injection Vulnerabilities
       19. PhotoStand Index.PHP Cross-Site Scripting Vulnerability
       20. PhotoStand Multiple HTML Injection Vulnerabilities
       21. Active Calendar Multiple Cross-Site Scripting Vulnerabilities
       22. Active Calendar ShowCode.PHP Local File Include Vulnerability
       23. Pickle Download.PHP Local File Include Vulnerability
       24. Microsoft Office Publisher Unspecified Remote Code Execution Vulnerability
       25. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
       26. Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
       27. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
       28. Microsoft Internet Explorer Drag and Drop TIF Folder Information Disclosure Vulnerability
       29. Microsoft Internet Explorer Object Tag TIF Folder Information Disclosure Vulnerability
       30. Microsoft Internet Explorer DHTML Script Function Remote Code Execution Vulnerability
       31. Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
       32. KDE PCX Image File Handling Buffer Overflow Vulnerability
       33. SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed
       34. Ethereal Multiple Remote Protocol Dissector Vulnerabilities
       35. PostgreSQL TSearch2 Design Error Vulnerability
       36. Mozilla Firefox OnUnload Javascript Browser Entrapment Vulnerability
       37. NetProxy Security Restriction Bypass Vulnerability
       38. Admin Phorum DEL.PHP Remote File Include Vulnerability
       39. CHM Lib Multiple Unspecified Buffer Overflow Vulnerabilities
       40. Wordpress Multiple Cross-Site Scripting Vulnerabilities
       41. Wordpress Post.PHP Cross-Site Scripting Vulnerability
       42. ClamAV CAB File Remote Denial of Service Vulnerability
       43. Shop Kit Plus StyleCSS.PHP Local File Include Vulnerability
       44. TaskFreak! Error.PHP Cross-Site Scripting Vulnerability
       45. ClamAV MIME Header ID Parameter String Directory Traversal Vulnerability
       46. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
       47. Linux Kernel ISDN PPP CCP Reset State Timer Denial of Service Vulnerability
       48. Linux Kernel ListXATTR Local Denial of Service Vulnerability
       49. Linux Kernel ISDN PPP Remote Denial of Service Vulnerability
       50. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
       51. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
       52. Linux Kernel NFSACL Denial of Service Vulnerability
       53. Phorum Register.PHP HTML Injection Vulnerability
       54. Xine-Lib RuleMatches Remote Buffer Overflow Vulnerability
       55. Linux Kernel Audit Subsystems Local Denial of Service Vulnerability
       56. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
       57. Linux Kernel ATM SkBuff Dereference Remote Denial of Service Vulnerability
       58. Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness
       59. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability 
       60. Mozilla Thunderbird/SeaMonkey/Firefox Multiple Remote Vulnerabilities
       61. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
       62. Sun Java Runtime Environment Information Disclosure Vulnerabilities
       63. XFree86 Multiple Unspecified Integer Overflow Vulnerabilities
       64. Secunia Software Inspector Security Update Verification Weakness
       65. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
       66. Mozilla Firefox Location.Hostname Dom Property Cookie Theft Vulnerability
       67. Mozilla Firefox 2 Password Manager Cross-Site Information Disclosure Weakness
       68. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
       69. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
       70. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
       71. Microsoft MFC Embedded OLE Object Remote Code Execution Vulnerability
       72. Microsoft Windows OLE Dialog Remote Code Execution Vulnerability
       73. Microsoft Internet Explorer IMJPCKSI COM Object Instantiation Memory Corruption Vulnerability
       74. Microsoft Internet Explorer COM Object Instantiation Variant Memory Corruption Vulnerability
       75. Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
       76. Microsoft Internet Explorer WinINet.DLL FTP Server Response Parsing Memory Corruption Vulnerability
       77. Microsoft Office And Microsoft Windows RichEdit Component Remote Code Execution Vulnerability
       78. Microsoft HTML Help ActiveX Control Remote Code Execution Vulnerability
       79. Microsoft Step-by-Step Interactive Training Buffer Overflow Vulnerability
       80. Multiple Mercury Products Magnetproc.EXE Buffer Overflow Vulnerability
       81. Microsoft Windows Explorer WMF File Handling Denial of Service Vulnerability
       82. Sun Multiple Java System Request Smuggling Vulnerability
       83. Pagesetter Index.PHP Local File Include Vulnerability
       84. SQLiteManager Main.PHP Multiple HTML Injection Vulnerabilities
       85. PHPBB2 Admin_Ug_Auth.PHP Administrative Security Bypass Vulnerability
       86. IBM DB2 Fenced UserID Unspecified Authentication Bypass Vulnerability
       87. Audins Audiens Multiple Input Validation Vulnerabilities
       88. SQLiteManager Local File Include Vulnerability
       89. Microsoft Office Publisher Remote Denial of Service Vulnerability
       90. STWC-Counter Downloadcounter.PHP Remote File Include Vulnerability
       91. SolarPay Index.PHP Local File Include Vulnerability
       92. Watchtower Unspecified Authentication Bypass Vulnerability
       93. Docebo Multiple Cross-Site Scripting Vulnerabilities
       94. Xpression News Xnews-Template Multiple Directory Traversal Vulnerabilities
       95. Oracle Database SYS.KUPV$FT Multiple SQL Injection Vulnerabilities
       96. Oracle July 2006 Security Update Multiple Vulnerabilities
       97. Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability
       98. Oracle January Security Update Multiple Vulnerabilities
       99. Google Desktop Cross-Site Scripting Weakness
       100. ProFTPD Controls Module Local Buffer Overflow Vulnerability
III.  SECURITYFOCUS NEWS
       1. Legal threats scuttle RFID flaw demo
       2. Google Desktop flaw allows data theft
       3. Imperfect Storm aids spammers
       4. U.S. calls for more organized cyber response
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Security System Administrator, Springfield
       2. [SJ-JOB] Jr. Security Analyst, Mountain View
       3. [SJ-JOB] Security Engineer, Phoenix
       4. [SJ-JOB] Security Auditor, Idaho Falls
       5. [SJ-JOB] Account Manager, Any location
       6. [SJ-JOB] Account Manager, any location in the North East
       7. [SJ-JOB] Application Security Architect, Chicago
       8. [SJ-JOB] Application Security Architect, Chicago
       9. [SJ-JOB] Account Manager, any location
       10. [SJ-JOB] Security Consultant, Hyderabad
       11. [SJ-JOB] Security Consultant, Hyderabad
       12. [SJ-JOB] Penetration Engineer, Amsterdam
       13. [SJ-JOB] Developer, Austin
       14. [SJ-JOB] Senior Software Engineer, Austin
       15. [SJ-JOB] Software Engineer, Columbia
       16. [SJ-JOB] Account Manager, Slough
       17. [SJ-JOB] Sr. Security Analyst, Dunstable
       18. [SJ-JOB] Security Researcher, Columbia
       19. [SJ-JOB] Security Engineer, Warsaw
       20. [SJ-JOB] Customer Support, Columbia
       21. [SJ-JOB] Software Engineer, Columbia
       22. [SJ-JOB] Sr. Security Engineer, Schaumburg
       23. [SJ-JOB] Technical Support Engineer, Schaumburg
       24. [SJ-JOB] Principal Software Engineer, SAN JOSE
       25. [SJ-JOB] Information Assurance Engineer, Zurich
       26. [SJ-JOB] Principal Software Engineer, Fullerton
       27. [SJ-JOB] Developer, SAN JOSE
       28. [SJ-JOB] Application Security Architect, Hyderabad
       29. [SJ-JOB] Principal Software Engineer, SAN JOSE
       30. [SJ-JOB] Application Security Architect, Any - Candidates holding    Business Visa
       31. [SJ-JOB] Application Security Architect, Any - Candidates holding    Business Visa
       32. [SJ-JOB] Security Consultant, New York
       33. [SJ-JOB] Senior Software Engineer, Fullerton
       34. [SJ-JOB] Security Engineer, Dublin
       35. [SJ-JOB] Manager, Information Security, Hunt Valley
       36. [SJ-JOB] Quality Assurance, Fredericton
       37. [SJ-JOB] Sr. Security Analyst, Chicago/Waukegan
       38. [SJ-JOB] Security Engineer, Madison
       39. [SJ-JOB] Security Engineer, Dublin
       40. [SJ-JOB] Information Assurance Engineer, Dublin
       41. [SJ-JOB] Security Engineer, Sydney
       42. [SJ-JOB] Security System Administrator, Austin
       43. [SJ-JOB] Security Engineer, singapore
       44. [SJ-JOB] Security Engineer, Wilmington
       45. [SJ-JOB] Security System Administrator, Tempe
       46. [SJ-JOB] Security Consultant, Amsterdam
       47. [SJ-JOB] Management, NYC
       48. [SJ-JOB] Sales Engineer, Houston
       49. [SJ-JOB] Security Consultant, Reading
       50. [SJ-JOB] Information Assurance Analyst, Rickmansworth
       51. [SJ-JOB] Security Architect, Omaha
       52. [SJ-JOB] Application Security Engineer, Chicago
       53. [SJ-JOB] Information Assurance Analyst, Dunstable
       54. [SJ-JOB] Application Security Engineer, Edmonton
       55. [SJ-JOB] Director, Information Security, San Diego
       56. [SJ-JOB] Security Auditor, Charlotte
       57. [SJ-JOB] Security Architect, Saint Paul
       58. [SJ-JOB] Regional Channel Manager, Atlanta
       59. [SJ-JOB] Instructor, Various US Citites
       60. [SJ-JOB] Security Engineer, Pittsburgh
       61. [SJ-JOB] Security Architect, CUPERTINO
V.    INCIDENTS LIST SUMMARY
       1. Increased activity on port 110
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. WordPress AdminPanel CSRF/XSS - 0day
       2. SyScan'07 CFP
       3. vd_proftpd.pm  Metasploit module for ProFTPD stack overflow
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. IIS 5
       2. AD Global Security group with an email address behavior.
       3. Vista "complaints"
       4. App FW for isa2K4 2K6
       5. Prevent users/admin from installing softwares.
       6. SecurityFocus Microsoft Newsletter #330
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
       1. Did I get hacked?
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Building Secure Applications: Consistent Logging
By Rohit Sethi and Nish Bhalla
This article focuses on developers and discusses how to use consistent application-layer logging along with Log4J or Log4net for the real-time detection of attacks. 
http://www.securityfocus.com/infocus/1888

2. Vista Review: Bugs and Confusion
By Thomas C. Greene
The Register's Thomas C. Greene offers an entertaining review of Windows Vista, noting price differences in Europe, driver compatibility issues, and security and user interface issues that affect the Vista experience.
http://www.securityfocus.com/columnists/436


II.  BUGTRAQ SUMMARY
--------------------
1. TCPDump ISIS Decoding Routines Denial Of Service Vulnerability
BugTraq ID: 13392
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/13392
Summary:
The tcpdump utility is prone to a vulnerability that may allow a remote attacker to cause a denial-of-service condition in the software. The issue occurs due to the way tcpdump decodes Intermediate System to Intermediate System (ISIS) packets. A remote attacker may cause the software to enter an infinite loop by sending malformed ISIS packets, resulting in the software hanging. 

Versions up to and including 3.9.x/CVS of tcpdump are reported prone to this issue.

2. WebMplayer Multiple Input Validation Vulnerabilities
BugTraq ID: 22726
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22726
Summary:
WebMplayer is prone to multiple SQL-injection vulnerabilities and an arbitrary  shell command execution vulnerability because the application fails to properly sanitize user-supplied input.

A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database implementation, or execute arbitrary shell commands in the context of the webserver process. 

WebMplayer versions prior to 0.6.1-alpha are vulnerable.

3. Putmail Improper Authentication Weakness
BugTraq ID: 22718
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22718
Summary:
Putmail is prone to a weakness that may disclose user credentials to a remote attacker.

The application may choose to send authentication credentials in cleartext format without notifying a vulnerable user.

An attacker can potentially obtain authentication credentials in cleartext format by using a network sniffer application. This can lead to other attacks.

Putmail versions prior to 1.4 are vulnerable to this issue.

4. Mozilla Firefox OnUnload Memory Corruption Vulnerability
BugTraq ID: 22679
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22679
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability. 

     Successfully exploiting this issue may allow remote attackers to execute arbitrary machine code in the context of the affected application. This could facilitate the remote compromise of affected computers.

 Mozilla Firefox version 2.0.0.1 is vulnerable to this issue; other versions are also likely affected.

5. Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
BugTraq ID: 22717
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22717
Summary:
Microsoft Excel is reportedly prone to a denial-of-service vulnerability. This issue occurs when the application handles a specially crafted file. This issue stems from a NULL-pointer dereference.

Initial reports indicate that this issue is distinct from that outlined in BID 22555 Microsoft Excel Remote Denial Of Service Vulnerability.

Exploitation could cause the application to crash, resulting in a denial of service.

6. Microsoft Office 2003 Denial of Service Vulnerability
BugTraq ID: 22716
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22716
Summary:
Microsoft Office is prone to a denial-of-service condition when the malformed WMF file is viewed in an Office application. 
 
Exploiting this issue allows remote attackers to crash applications, denying service to legitimate users.

Microsoft Office 2003 is vulnerable to this issue; other versions may also be affected.

Note: IrfanView version 3.99 is also vulnerable to this issue.

7. UFO2000 Multiple Remote Vulnerabilities
BugTraq ID: 19035
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/19035
Summary:
UFO2000 is affected by multiple remote vulnerabilities that arise when the application handles malicious network data.

A remote attacker may execute arbitrary code to gain unauthorized access or to crash the application, effectively denying service to legitimate users.

Versions SVN 1057 and earlier are prone to these issues; other versions may also be affected.

8. PHPMIP Top.PHP Remote File Include Vulnerability
BugTraq ID: 22714
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22714
Summary:
PHPMIP is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

PHPMIP version 0.00.01 is vulnerable; other versions may also be affected.

9. UFO2000 SQL Injection Vulnerability
BugTraq ID: 19028
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/19028
Summary:
UFO2000 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

10. Nexuiz Remote Command Execution and Denial of Service Vulnerabilities
BugTraq ID: 21574
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/21574
Summary:
Nexuiz is prone is prone to multiple remote vulnerabilities, including a remote command-execution issue and a denial-of-service issue. 

A remote attacker can exploit these issues to execute arbitrary commands within the context of the affected application or to cause the affected application to crash, denying service to legitimate users. 

Versions prior to 2.2.1 are vulnerable to these issues.

11. NoMoKeTos PHPBB Module PHPBB_Root_Path Remote File Include Vulnerability
BugTraq ID: 22713
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22713
Summary:
NoMoKeTos Module is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.0.1 is vulnerable; other versions may also be affected.

12. CS-Gallery Index.PHP Remote File Include Vulnerability
BugTraq ID: 22712
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22712
Summary:
CS-Gallery is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

CS-Gallery 2.0 is vulnerable; other versions may also be affected.

13. PHPWebGallery Multiple Scripts Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22711
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22711
Summary:
PhpWebGallery is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 1.4.1 is vulnerable; other versions may also be affected.

14. PHPPeanuts Inspect.PHP Remote File Include Vulnerability
BugTraq ID: 21057
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/21057
Summary:
PHPPeanuts is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

15. Windows Shell User Logon ActiveX Control Create Method Unauthorized User Creation Vulnerability
BugTraq ID: 22710
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22710
Summary:
The Windows Shell User Logon ActiveX control is prone to a vulnerability that allows attackers to create user accounts on victim computers.

Exploiting this issue can aid in further attacks and may result in the compromise of affected computers.

Version 6.0.2900.2180 is vulnerable; other versions may also be affected.

16. Coppermine Photo Gallery ThumbNails.PHP SQL Injection Vulnerability
BugTraq ID: 22709
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22709
Summary:
Coppermine Photo Gallery is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Version 1.3.1 is vulnerable; other versions may also be affected.

17. Extreme PHPBB PHPBB_Root_Path Remote File Include Vulnerability
BugTraq ID: 22708
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22708
Summary:
Extreme PHPBB is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 3.0.1; other versions may also be vulnerable.

18. PHP-Nuke Multiple SQL Injection Vulnerabilities
BugTraq ID: 22638
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22638
Summary:
PHP-Nuke is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

PHP-Nuke 8.0 Final and prior versions are vulnerable.

19. PhotoStand Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 22707
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22707
Summary:
PhotoStand is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

20. PhotoStand Multiple HTML Injection Vulnerabilities
BugTraq ID: 22706
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22706
Summary:
PhotoStand is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.

Version 1.2.0 vulnerable; other versions may also be affected.

21. Active Calendar Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22705
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22705
Summary:
Active Calendar is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 1.2.0 is vulnerable; other versions may also be affected.

22. Active Calendar ShowCode.PHP Local File Include Vulnerability
BugTraq ID: 22704
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22704
Summary:
Active Calendar is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to view files and execute local scripts.

Version 1.2.0 is vulnerable; other versions may also be affected.

23. Pickle Download.PHP Local File Include Vulnerability
BugTraq ID: 22703
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22703
Summary:
picKLE is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to view files and execute local scripts.

Version 0.3 is vulnerable to this issue; other versions may also be affected.

24. Microsoft Office Publisher Unspecified Remote Code Execution Vulnerability
BugTraq ID: 22702
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22702
Summary:
Microsoft Office Publisher is prone to an unspecified remote code-execution vulnerability.

An attacker could exploit this issue by enticing an unsuspecting victim to open a malicious file. A successful exploit will allow arbitrary code to run in the context of the currently logged-in user.

Currently, little is known about this issue. This BID will be updated as more information becomes available.

25. SpamAssassin Long URI Handling Remote Denial of Service Vulnerability
BugTraq ID: 22584
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22584
Summary:
SpamAssassin is prone to a remote denial-of-service vulnerability. 

This issue arises when the application handles excessively long URIs.
 
SpamAssassin versions prior to 3.1.8 are vulnerable to this issue.

26. Multiple Web Browser UTF-7 Cross-Domain Character-Set-Inheritance Vulnerability
BugTraq ID: 22701
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22701
Summary:
Opera Web Browser and Microsoft Internet Explorer are prone to a cross-domain character-set-inheritance vulnerability.

Exploiting this issue can allow attackers to perform cross-site scripting attacks on unsuspecting users. If successful, attackers can steal cookie-based authentication credentials.

Opera Web Browser 9 series and Microsoft Internet Explorer 7 series are affected.

27. PHP Version 5.2.0 and Prior Multiple Vulnerabilities
BugTraq ID: 22496
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22496
Summary:
PHP version 5.2.0 and prior is prone to multiple security vulnerabilities. Successful exploits could allow an attacker to write files in unauthorized locations, cause a denial-of-service condition, and potentially execute code.

These issues are reported to affect PHP 4.4.4 and prior versions in the 4 branch, and 5.2.0 and prior versions in the 5 branch; other versions may also be vulnerable.

28. Microsoft Internet Explorer Drag and Drop TIF Folder Information Disclosure Vulnerability
BugTraq ID: 21494
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21494
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to access sensitive information that may aid in further attacks.

29. Microsoft Internet Explorer Object Tag TIF Folder Information Disclosure Vulnerability
BugTraq ID: 21507
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21507
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to access sensitive information that may aid in further attacks.

30. Microsoft Internet Explorer DHTML Script Function Remote Code Execution Vulnerability
BugTraq ID: 21546
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21546
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerability. 

This vulnerability is related to how the browser renders DHTML script functions or nonexistent DHTML  elements. An attacker could exploit this issue to execute arbitrary code in the context of the affected browser.

31. Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
BugTraq ID: 21552
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21552
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerability. 

This vulnerability is related to how the browser handles script errors. An attacker may exploit this vulnerability to execute arbitrary code in the context of the user running the affected browser.

32. KDE PCX Image File Handling Buffer Overflow Vulnerability
BugTraq ID: 13096
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/13096
Summary:
KDE is reported prone to a buffer-overflow vulnerability when handling PCX image files because the 'kimgio' image library fails to properly validate PCX image data. 
 
This vulnerability was reported to reside in PCX image-handling routines, but the vendor has patched other image handlers, which may mean that other image formats may also be affected by similar problems. 
 
Attackers may exploit this vulnerability to crash applications using the affected library or possibly to execute arbitrary machine code in the context of the affected application.

33. SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed
BugTraq ID: 15495
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/15495
Summary:
Updates for the SCO OpenServer Mozilla browser have been released, addressing multiple security vulnerabilities and weaknesses. 
 
This release fixes a number of bugs, including some security vulnerabilities and weaknesses.   
 
Many of the bugs that have been fixed in this maintenance pack may have a security impact that may be exploited by a local or remote attacker.  Possible consequences include denial of service, spoofing, gaining knowledge of potentially sensitive information, conducting cross-site scripting attacks, bypassing certain security restrictions, manipulating certain data, or compromising a user's system, and gaining local privilege escalation.

34. Ethereal Multiple Remote Protocol Dissector Vulnerabilities
BugTraq ID: 13504
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/13504
Summary:
Many vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors. 

These issues include:

- Buffer-overflow vulnerabilities 
- Format-string vulnerabilities 
- NULL-pointer dereference denial-of-service vulnerabilities 
- Segmentation fault denial-of-service vulnerabilities 
- Infinite-loop denial-of-service vulnerabilities 
- Memory exhaustion denial-of-service vulnerabilities 
- Double-free vulnerabilities 
- Unspecified denial-of-service vulnerabilities 

These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application. 

Various vulnerabilities affect several versions of Ethereal, from 0.8.14 through to 0.10.10. 

This BID will be split into individual BIDs for each separate issue. 

BID 13567 has been created for the DISTCC issue.

35. PostgreSQL TSearch2 Design Error Vulnerability
BugTraq ID: 13475
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/13475
Summary:
The PostgreSQL 'contrib/tsearch2' module is prone to a security vulnerability. The issue occurs because the module doesn't correctly declare several functions. 

Although unconfirmed, presumably this issue allows a remote user who can write SQL queries to the affected database to call these functions, which shouldn't be accessible directly from SQL commands. 

This vulnerability affects PostgreSQL 7.4 and later.

36. Mozilla Firefox OnUnload Javascript Browser Entrapment Vulnerability
BugTraq ID: 22688
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22688
Summary:
Mozilla Firefox is prone to a vulnerability that allows attackers to trap users at a particular webpage and spoof page transitions. 

Attackers may exploit this via a malicious page to spoof the contents and origin of a page that the victim may trust. This vulnerability may be useful in phishing or other attacks that rely on content spoofing.

37. NetProxy Security Restriction Bypass Vulnerability
BugTraq ID: 22741
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22741
Summary:
NetProxy is prone to a security-restriction-bypass vulnerability because the software fails to properly sanitize user-supplied input.
 
Attackers can exploit this issue to bypass the security restrictions and gain unauthorized access to restricted sites. This may allow attackers to bypass the security restrictions enforced by the application.

NetProxy version 4.03 is vulnerable; other versions may also be affected.

38. Admin Phorum DEL.PHP Remote File Include Vulnerability
BugTraq ID: 22739
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22739
Summary:
Admin Phorum is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

Version 3.3.1.a is vulnerable; other versions may also be affected.

39. CHM Lib Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 22258
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22258
Summary:
CHM Lib is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied input prior to copying it to insufficiently sized memory buffers.

Successfully exploiting these issues may allow remote attackers to execute arbitrary machine code in the context of users running applications that uses the affected library.

Versions prior to 0.39 are vulnerable to these issues.

40. Wordpress Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22738
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22738
Summary:
Wordpress is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Version 2.1.1 is vulnerable; other versions may also be affected.

41. Wordpress Post.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 22735
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22735
Summary:
Wordpress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 
 
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Wordpress 2.1.1 is vulnerable to this issue; other versions may also be affected.

42. ClamAV CAB File Remote Denial of Service Vulnerability
BugTraq ID: 22580
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22580
Summary:
ClamAV is prone to a denial-of-service vulnerability.

An attacker can exploit this vulnerability to prevent the software from scanning certain types of data. When it encounters the data, the application will reject it. This can result in denial-of-service conditions.

Versions prior to 0.90 stable are vulnerable.

43. Shop Kit Plus StyleCSS.PHP Local File Include Vulnerability
BugTraq ID: 22697
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22697
Summary:
Shop Kit Plus is prone to a local file-include vulnerability because it fails to adequately sanitize user-supplied data.

An attacker can exploit this vulnerability using directory-traversal strings to execute local script code in the context of the application. This may allow the attacker to access sensitive information that may aid in further attacks.

44. TaskFreak! Error.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 22537
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22537
Summary:
TaskFreak! is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

TaskFreak! 0.5.5 multiuser edition is reportedly vulnerable; other versions may be affected as well.

45. ClamAV MIME Header ID Parameter String Directory Traversal Vulnerability
BugTraq ID: 22581
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22581
Summary:
ClamAV is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to create or overwrite arbitrary files on vulnerable computers in the context of the affected application. This may aid in further attacks. 

This issue affects ClamAV versions prior to the 0.90 stable release.

46. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerability
BugTraq ID: 21604
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21604
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability because the kernel fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker may exploit this issue to execute arbitrary code with kernel-level privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will result in denial-of-service conditions. 

Versions prior to 2.4.33.5 are vulnerable to this issue.

47. Linux Kernel ISDN PPP CCP Reset State Timer Denial of Service Vulnerability
BugTraq ID: 21883
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21883
Summary:
The Linux kernel is prone to a denial-of-service vulnerability because it fails to handle exceptional conditions. 

An attacker can exploit this issue to crash the affected kernel, denying service to legitimate users.

48. Linux Kernel ListXATTR Local Denial of Service Vulnerability
BugTraq ID: 22316
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22316
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

Successful exploits will result in denial-of-service conditions or potentially privilege escalation.

49. Linux Kernel ISDN PPP Remote Denial of Service Vulnerability
BugTraq ID: 21835
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21835
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.
 
An attacker can exploit this issue to cause an affected kernel to crash, effectively denying service to legitimate users.

Versions prior to 2.4.34 are vulnerable to this issue.

50. Linux Kernel MinCore User Space Access Locking Local Denial of Service Vulnerability
BugTraq ID: 21663
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21663
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability due to a design error.

A local attacker can exploit this issue to cause the kernel to become unresponsive, denying further service to  legitimate users.

Linux Kernel versions prior to 2.4.33.6 are vulnerable.

51. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

52. Linux Kernel NFSACL Denial of Service Vulnerability
BugTraq ID: 22625
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22625
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. 

An attacker can exploit this issue to crash the affected computer, denying service to legitimate users.

This issue affects the Linux kernel 2.6 series up to 2.6.20.

53. Phorum Register.PHP HTML Injection Vulnerability
BugTraq ID: 22297
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22297
Summary:
Phorum is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input. 
 
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

54. Xine-Lib RuleMatches Remote Buffer Overflow Vulnerability
BugTraq ID: 21435
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21435
Summary:
The 'xine-lib' library running on Real media is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.

An attacker can exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial of service.

55. Linux Kernel Audit Subsystems Local Denial of Service Vulnerability
BugTraq ID: 22737
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22737
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A local attacker can exploit this issue to crash the kernel.

Linux kernel versions 2.6.x are vulnerable to this issue.

56. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with arbitrary data, potentially allowing them to execute malicious machine code in the context of affected kernels. This vulnerability facilitates the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

57. Linux Kernel ATM SkBuff Dereference Remote Denial of Service Vulnerability
BugTraq ID: 20363
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/20363
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability.

This issue is triggered when the kernel processes incoming ATM data.

Exploiting this vulnerability may allow remote attackers to crash the affected kernel, resulting in denial-of-service conditions.

This issue affects only systems that have ATM hardware and are configured for ATM kernel support.

Kernel versions from 2.6.0 up to and including 2.6.17 are vulnerable to this issue.

58. Mozilla Firefox Popup Blocker Cross Zone Security Bypass Weakness
BugTraq ID: 22396
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22396
Summary:
Mozilla Firefox is prone to a cross-zone security-bypass weakness. This issue allows attackers to open 'file://' URIs from remote websites.

By exploiting this issue in conjunction with other weaknesses or vulnerabilities, attackers may be able to execute arbitrary script code with the elevated privileges that are granted to scripts when they are executed from local sources.

Mozilla Firefox 1.5.0.9 is affected by this issue; other versions may be affected as well.

59. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability 
BugTraq ID: 19849
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 signature when an RSA key with exponent 3 is used. 

An attacker may exploit this issue to sign digital certificates or RSA keys and take advantage of trust relationships that depend on these credentials, possibly posing as a trusted party and signing a certificate or key. 

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are affected by this vulnerability. Updates are available.

60. Mozilla Thunderbird/SeaMonkey/Firefox Multiple Remote Vulnerabilities
BugTraq ID: 22694
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22694
Summary:
The Mozilla Foundation has released six security advisories specifying vulnerabilities in Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- Execute arbitrary code
- Cause denial-of-service conditions
- Perform cross-site scripting attacks
- Obtain potentially sensitive information
- Spoof legitimate content

Other attacks may also be possible.

61. Sun Java RunTime Environment Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 21675
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21675
Summary:
The Java Runtime Environment is prone to multiple buffer-overflow vulnerabilities the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

A local attacker can exploit these issues to execute arbitrary code with administrative privileges. A successful exploit attempt will lead to the complete compromise of affected computers. Failed exploit attempts will result in a denial of service.

62. Sun Java Runtime Environment Information Disclosure Vulnerabilities
BugTraq ID: 21674
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21674
Summary:
The Sun Java runtime environment is prone to multiple information-disclosure vulnerabilities. These issues are due to a design flaw in the affected application. 

An attacker can exploit these issues to gain access to sensitive information. This may lead to other attacks.

63. XFree86 Multiple Unspecified Integer Overflow Vulnerabilities
BugTraq ID: 8514
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/8514
Summary:
Multiple integer-overflow vulnerabilities have been discovered in the XFree86 font libraries. The problem occurs because of insufficient sanity checks on integers passed to clients from an X font server. As a result, an unexpected buffer overrun may occur within the stack or heap space of process memory. An attacker could potentially exploit this to execute arbitrary code within a target X client. 
 
Precise technical details regarding these vulnerabilities are currently unavailable; as further information is released, this BID will be updated accordingly.

64. Secunia Software Inspector Security Update Verification Weakness
BugTraq ID: 22736
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22736
Summary:
Secunia Software Inspector is prone to a weakness that provides a false sense of security to users.

Users rely on this application to provide assurance of security updates for their computers. However, this issue may cause users to be unaware of available patches for known vulnerabilities.

65. Linux Kernel Key_Alloc_Serial() Local Denial of Service Vulnerability
BugTraq ID: 22539
Remote: No
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22539
Summary:
The Linux Kernel is prone to a denial-of-service vulnerability.

A successful attack can allow local attackers to trigger a crash and deny service to legitimate users.
 
Kernel versions 2.6.x are vulnerable.

66. Mozilla Firefox Location.Hostname Dom Property Cookie Theft Vulnerability
BugTraq ID: 22566
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22566
Summary:
Mozilla Firefox is prone to a vulnerability that allows attackers to steal cookies. This issue occurs because the application fails to sufficiently sanitize user-supplied input. 

An attacker can exploit this issue to manipulate cookie-based authentication credentials for third-party web pages or to control how the site is rendered to the user. Exploiting this issue may allow the attacker to bypass the same-origin policy for cross-window/cross-frame data access; other attacks are also possible.

This issue affects version 2.0.0.1; prior versions may also be affected.

67. Mozilla Firefox 2 Password Manager Cross-Site Information Disclosure Weakness
BugTraq ID: 21240
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21240
Summary:
Mozilla Firefox is reportedly prone to an information-disclosure weakness because it fails to properly notify users of the automatic population of form fields in disparate URLs deriving from the same domain.

Exploiting this issue may allow attackers to obtain user credentials that have been saved in forms deriving from the same website where attack code resides. The most common manifestation of this condition would typically be in blogs or forums. This may allow attackers to access potentially sensitive information that would facilitate the success of phishing attacks.

Initial reports and preliminary testing indicate that this issue affects only Firefox 2.

68. Sun Java Runtime Environment Multiple Remote Privilege Escalation Vulnerabilities
BugTraq ID: 21673
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/21673
Summary:
The Sun Java Runtime Environment is prone to multiple remote privilege-escalation vulnerabilities. 

An attacker can execute arbitrary code and commands in the context of a user who invokes the Java applet or application. 

A successful attack can facilitate privilege escalation.

69. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
BugTraq ID: 22742
Remote: Yes
Last Updated: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22742
Summary:
Nullsoft SHOUTcast is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.9.7 for Microsoft Windows; other versions may also be vulnerable.

70. Apple iChat Bonjour Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 22304
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22304
Summary:
Apple iChat is prone to multiple remote denial-of-service vulnerabilities.  These issues affect the Bonjour functionality. 
 
Apple iChat 3.1.6 is reported affected; other versions may be vulnerable as well.

71. Microsoft MFC Embedded OLE Object Remote Code Execution Vulnerability
BugTraq ID: 22476
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22476
Summary:
The Microsoft MFC component for Microsoft Windows and Microsoft Visual Studio .NET is prone to a remote code-execution vulnerability. This issue occurs when the application using the component attempts to parse malformed Rich Text Files (RTF).

An attacker could exploit this issue by enticing a victim to load a malicious RTF file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

72. Microsoft Windows OLE Dialog Remote Code Execution Vulnerability
BugTraq ID: 22483
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22483
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability that occurs when the application attempts to parse malformed Rich Text Files (RTF).

An attacker could exploit this issue by enticing a victim to load a malicious RTF file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

73. Microsoft Internet Explorer IMJPCKSI COM Object Instantiation Memory Corruption Vulnerability
BugTraq ID: 22486
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22486
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when instantiating certain COM objects.

     Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

Internet Explorer 7 on Microsoft Vista is not affected by this issue; Internet Explorer 7 on other Windows versions is affected only if COM objects have been enabled by the ActiveX opt-in feature.

This BID is similar to the one described in BID 15827 (Microsoft Internet Explorer COM Object Instantiation Memory Corruption Vulnerability), but it affects a different set of COM objects.

74. Microsoft Internet Explorer COM Object Instantiation Variant Memory Corruption Vulnerability
BugTraq ID: 22504
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22504
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when instantiating certain COM objects.

     Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

Internet Explorer 7 on Microsoft Vista is not affected by this issue; Internet Explorer 7 on other Windows versions is affected only if COM objects have been enabled by the ActiveX opt-in feature.

This issue is similar to the ones described in previous COM object instantiation records, but it affects a different set of COM objects.

75. Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
BugTraq ID: 20704
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/20704
Summary:
Microsoft Internet Explorer is prone to a memory-corruption condition when processing a specific method from the 'ADODB.Connection.2.7' instantiated ActiveX Object.

Successful exploits may allow attackers to crash the application, denying further service to users. This issue may also be exploited to execute arbitrary machine-code, but this has not been confirmed.

This issue does not affect Microsoft Data Access Components 2.8 on Windows Vista.

76. Microsoft Internet Explorer WinINet.DLL FTP Server Response Parsing Memory Corruption Vulnerability
BugTraq ID: 22489
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22489
Summary:
Microsoft Internet Explorer is prone to a memory-corruption vulnerability when parsing certain FTP server responses.

 Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers.

77. Microsoft Office And Microsoft Windows RichEdit Component Remote Code Execution Vulnerability
BugTraq ID: 21876
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/21876
Summary:
Microsoft Office and Microsoft Windows RichEdit component  are prone to a remote code-execution vulnerability. This issue occurs when malformed Rich Text Files (RTF) are processed.

An attacker could exploit this issue by enticing a victim to load a malicious RTF file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

78. Microsoft HTML Help ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 22478
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22478
Summary:
The Microsoft HTML Help ActiveX control is prone to a remote code-execution vulnerability. 

An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

79. Microsoft Step-by-Step Interactive Training Buffer Overflow Vulnerability
BugTraq ID: 22484
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22484
Summary:
Microsoft Step-by-Step Interactive Training is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker could exploit this issue by enticing a victim to load a bookmark link file. If the vulnerability is successfully exploited, this could result in the execution of arbitrary code in the context of the currently logged-in user.

80. Multiple Mercury Products Magnetproc.EXE Buffer Overflow Vulnerability
BugTraq ID: 22487
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22487
Summary:
Multiple Mercury products are prone to a stack-based buffer-overflow vulnerability because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 

An attacker can exploit this issue to execute arbitrary code wtih the privileges of the currently logged-in user. Failed exploit attempts will result in a denial of service.

81. Microsoft Windows Explorer WMF File Handling Denial of Service Vulnerability
BugTraq ID: 22715
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22715
Summary:
Microsoft Windows Explorer is prone to a denial-of-service vulnerability.

A remote attacker may exploit this vulnerability by presenting a malicious file to a victim user.  Users do not have to open the file -- simply browsing a folder containing the malicious file is sufficient to trigger this issue.
 
A successful exploit will crash the vulnerable application, effectively denying service.

This issue may be related to BID 19365 (Microsoft Windows GDI32.DLL WMF Remote Denial of Service Vulnerability) or BID 21992 (Microsoft Windows Explorer WMF File Denial of Service Vulnerability).

82. Sun Multiple Java System Request Smuggling Vulnerability
BugTraq ID: 21371
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/21371
Summary:
Multiple Sun Java System servers are prone to an HTTP-request-smuggling attack. 

This class of attack basically involves piggybacking an HTTP request inside of another HTTP request. By leveraging failures to implement the HTTP/1.1 RFC properly, this class of attack has been demonstrated to cause cache poisoning, cross-site scripting, session hijacking, and other attacks.

83. Pagesetter Index.PHP Local File Include Vulnerability
BugTraq ID: 22733
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22733
Summary:
Pagesetter is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to view files and execute local scripts.

Pagesetter 6.3.0 beta 5 and prior versions are vulnerable to this issue.

84. SQLiteManager Main.PHP Multiple HTML Injection Vulnerabilities
BugTraq ID: 22731
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22731
Summary:
SQLiteManager is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.

Version 1.2.0 is vulnerable; other versions may also be affected.

85. PHPBB2 Admin_Ug_Auth.PHP Administrative Security Bypass Vulnerability
BugTraq ID: 22730
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22730
Summary:
PHPBB2 is prone to a vulnerability that will let attackers gain administrative access to the application because it fails to properly validate access.

Successful exploits may result in a complete compromise of vulnerable applications.

86. IBM DB2 Fenced UserID Unspecified Authentication Bypass Vulnerability
BugTraq ID: 22729
Remote: No
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22729
Summary:
IBM DB2 is prone to an unspecified authentication-bypass vulnerability because it fails to effectively restrict access to certain directories.

An attacker could exploit this issue to gain unauthorized access to privileged directories. 

Versions prior to 8.1 FixPak 14 and 9.1 FixPak 2 are vulnerable.

87. Audins Audiens Multiple Input Validation Vulnerabilities
BugTraq ID: 22728
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22728
Summary:
Audins Audiens is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue,  because the application fails to sufficiently sanitize user-supplied input.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, retrieve and overwrite sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. 

Audins Audiens version 3.3 is vulnerable; other versions may also be affected.

88. SQLiteManager Local File Include Vulnerability
BugTraq ID: 22727
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22727
Summary:
SQLiteManager is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to view files and execute local scripts.

SQLiteManager 1.2.0 is vulnerable to this issue; other versions may also be affected.

89. Microsoft Office Publisher Remote Denial of Service Vulnerability
BugTraq ID: 22724
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22724
Summary:
Microsoft Office Publisher is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed files.

Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.

Microsoft Office Publisher 2007 is vulnerable; other versions may also be affected.

90. STWC-Counter Downloadcounter.PHP Remote File Include Vulnerability
BugTraq ID: 22723
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22723
Summary:
STWC-Counter is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.

Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.

This issue affects version 3.4.0; other versions may also be vulnerable.

91. SolarPay Index.PHP Local File Include Vulnerability
BugTraq ID: 22722
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22722
Summary:
SolarPay is prone to a local file-include vulnerability because the utility fails to properly sanitize user-supplied input.
 
 Successfully exploiting this issue allows attackers to gain access to files located in directories they do not have permissions to access. Information that attackers harvest may aid them in further attacks.

92. Watchtower Unspecified Authentication Bypass Vulnerability
BugTraq ID: 22721
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22721
Summary:
Watchtower is prone to an unspecified authentication-bypass vulnerability.

An attacker can exploit this issue to gain unauthorized access to the application.

Versions prior to 0.12 are vulnerable.

93. Docebo Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 22719
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22719
Summary:
Docebo is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. 

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Docebo 3.0.5 and prior versions are vulnerable; other versions may also be affected.

94. Xpression News Xnews-Template Multiple Directory Traversal Vulnerabilities
BugTraq ID: 22609
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22609
Summary:
Xpression News is prone to multiple directory-traversal vulnerabilities because the application fails to properly sanitize user-supplied input. 

An attacker can exploit these vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid the attacker in further attacks.

Xpression News version 1.0.1 is vulnerable to these issues.

95. Oracle Database SYS.KUPV$FT Multiple SQL Injection Vulnerabilities
BugTraq ID: 16294
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/16294
Summary:
Oracle 10g is prone to multiple SQL-injection vulnerabilities.  These issues affect various functions of the 'SYS.KUPV$FT' package. 
 
Exploiting these vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.  Successful exploitation may allow the attacker to compromise the application, retrieve sensitive information, or modify data; other consequences are possible as well.
 
Oracle 10g Release 1 and prior versions are considered vulnerable to these issues. 
 
These issues are part of the vulnerabilities addressed by Oracle in Oracle Critical Patch Update - January 2006.  Please see BID 16287 (Oracle January Security Update Multiple Vulnerabilities) for more information.

96. Oracle July 2006 Security Update Multiple Vulnerabilities
BugTraq ID: 19054
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/19054
Summary:
Various Oracle applications including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Pharmaceutical Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.

Oracle has released a Critical Patch Update advisory for July 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well.

These issues will be split into individual records when more information has been disclosed.

97. Oracle 10g Database SUBSCRIPTION_NAME Remote SQL Injection Vulnerability
BugTraq ID: 13236
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/13236
Summary:
Oracle database is prone to an SQL-injection vulnerability because the software fails to properly sanitize user-supplied data. The 'SUBSCRIPTION_NAME' parameter is vulnerable. 
 
Packages that employ this parameter execute with 'SYS' user privileges. Exploiting the SQL-injection vulnerability can allow an attacker to gain 'SYS' privileges. 
 
The attacker can exploit this issue using malformed PL/SQL statements to pass unauthorized SQL statements to the database. A successful exploit could allow the attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
 
This issue was originally disclosed in the 'Oracle Critical Patch Update - April 2005' advisory. BID 13139 Oracle Multiple Vulnerabilities describes the issues covered in the Oracle advisory. There is insufficient information at this time to associate this vulnerability with an identifier from the Oracle advisory.

98. Oracle January Security Update Multiple Vulnerabilities
BugTraq ID: 16287
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/16287
Summary:
Various Oracle products -- Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, PeopleSoft Enterprise Portal, JD Edwards EnterpriseOne Tools, OneWorld Tools, Oracle Developer Suite, and Oracle Workflow -- are prone to multiple vulnerabilities. 
 
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. 
 
Oracle has released a Critical Patch Update advisory for January 2006 to address these vulnerabilities.  This Critical Patch Update addresses the vulnerabilities for supported releases.  Earlier, unsupported releases are likely to be affected by the issues as well.

99. Google Desktop Cross-Site Scripting Weakness
BugTraq ID: 22650
Remote: Yes
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22650
Summary:
Google Desktop is prone to a cross-site scripting weakness because the application fails to properly sanitize user-supplied input.

Successful attacks must exploit this weakness in conjunction with a latent cross-site scripting vulnerability in the 'google.com' domain.

Attackers may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow attackers to access the contents of the Google Desktop search index or potentially to execute arbitrary code.

100. ProFTPD Controls Module Local Buffer Overflow Vulnerability
BugTraq ID: 21587
Remote: No
Last Updated: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/21587
Summary:
ProFTPD is prone to a local stack-based buffer-overflow vulnerability.

Attackers may exploit this issue to corrupt memory and execute arbitrary code in the context of the server application, resulting in a complete compromise of affected computers.

NOTE: ProFTPD is vulnerable only when compiled with 'mod_ctrls' support and the module is enabled.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Legal threats scuttle RFID flaw demo
By: Robert Lemos
Security technology giant HID uses patent claims to silence a security researcher scheduled to detail issues in radio-frequency identification (RFID) technology at a conference this week.
http://www.securityfocus.com/news/11444

2. Google Desktop flaw allows data theft
By: Robert Lemos
A security firm warns Google Desktop users to update after the search giant fixes a vulnerability in the program that could allow an attacker to use JavaScript to search for and steal specific data on a user's system.
http://www.securityfocus.com/news/11443

3. Imperfect Storm aids spammers
By: Robert Lemos
The misnamed Storm Worm, actually a Trojan horse, underscores the evolution of spammers' tactics, including massive attacks on their critics and competitors. <em>The first article in a two-part series.</em>
http://www.securityfocus.com/news/11442

4. U.S. calls for more organized cyber response
By: Robert Lemos
Federal officials renew calls for the private sector to help manage threats to critical infrastructure and the Internet.
http://www.securityfocus.com/news/11441

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security System Administrator, Springfield
http://www.securityfocus.com/archive/77/461430

2. [SJ-JOB] Jr. Security Analyst, Mountain View
http://www.securityfocus.com/archive/77/461433

3. [SJ-JOB] Security Engineer, Phoenix
http://www.securityfocus.com/archive/77/461434

4. [SJ-JOB] Security Auditor, Idaho Falls
http://www.securityfocus.com/archive/77/461429

5. [SJ-JOB] Account Manager, Any location
http://www.securityfocus.com/archive/77/461428

6. [SJ-JOB] Account Manager, any location in the North East
http://www.securityfocus.com/archive/77/461367

7. [SJ-JOB] Application Security Architect, Chicago
http://www.securityfocus.com/archive/77/461362

8. [SJ-JOB] Application Security Architect, Chicago
http://www.securityfocus.com/archive/77/461364

9. [SJ-JOB] Account Manager, any location
http://www.securityfocus.com/archive/77/461366

10. [SJ-JOB] Security Consultant, Hyderabad
http://www.securityfocus.com/archive/77/461361

11. [SJ-JOB] Security Consultant, Hyderabad
http://www.securityfocus.com/archive/77/461360

12. [SJ-JOB] Penetration Engineer, Amsterdam
http://www.securityfocus.com/archive/77/461365

13. [SJ-JOB] Developer, Austin
http://www.securityfocus.com/archive/77/461327

14. [SJ-JOB] Senior Software Engineer, Austin
http://www.securityfocus.com/archive/77/461335

15. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/461332

16. [SJ-JOB] Account Manager, Slough
http://www.securityfocus.com/archive/77/461331

17. [SJ-JOB] Sr. Security Analyst, Dunstable
http://www.securityfocus.com/archive/77/461333

18. [SJ-JOB] Security Researcher, Columbia
http://www.securityfocus.com/archive/77/461334

19. [SJ-JOB] Security Engineer, Warsaw
http://www.securityfocus.com/archive/77/461288

20. [SJ-JOB] Customer Support, Columbia
http://www.securityfocus.com/archive/77/461290

21. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/461291

22. [SJ-JOB] Sr. Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/461289

23. [SJ-JOB] Technical Support Engineer, Schaumburg
http://www.securityfocus.com/archive/77/461287

24. [SJ-JOB] Principal Software Engineer, SAN JOSE
http://www.securityfocus.com/archive/77/461088

25. [SJ-JOB] Information Assurance Engineer, Zurich
http://www.securityfocus.com/archive/77/461093

26. [SJ-JOB] Principal Software Engineer, Fullerton
http://www.securityfocus.com/archive/77/461094

27. [SJ-JOB] Developer, SAN JOSE
http://www.securityfocus.com/archive/77/461083

28. [SJ-JOB] Application Security Architect, Hyderabad
http://www.securityfocus.com/archive/77/461084

29. [SJ-JOB] Principal Software Engineer, SAN JOSE
http://www.securityfocus.com/archive/77/461090

30. [SJ-JOB] Application Security Architect, Any - Candidates holding    Business Visa
http://www.securityfocus.com/archive/77/461091

31. [SJ-JOB] Application Security Architect, Any - Candidates holding    Business Visa
http://www.securityfocus.com/archive/77/461092

32. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/461082

33. [SJ-JOB] Senior Software Engineer, Fullerton
http://www.securityfocus.com/archive/77/461087

34. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/461002

35. [SJ-JOB] Manager, Information Security, Hunt Valley
http://www.securityfocus.com/archive/77/461008

36. [SJ-JOB] Quality Assurance, Fredericton
http://www.securityfocus.com/archive/77/461020

37. [SJ-JOB] Sr. Security Analyst, Chicago/Waukegan
http://www.securityfocus.com/archive/77/461072

38. [SJ-JOB] Security Engineer, Madison
http://www.securityfocus.com/archive/77/461000

39. [SJ-JOB] Security Engineer, Dublin
http://www.securityfocus.com/archive/77/461001

40. [SJ-JOB] Information Assurance Engineer, Dublin
http://www.securityfocus.com/archive/77/461005

41. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/460941

42. [SJ-JOB] Security System Administrator, Austin
http://www.securityfocus.com/archive/77/460942

43. [SJ-JOB] Security Engineer, singapore
http://www.securityfocus.com/archive/77/460943

44. [SJ-JOB] Security Engineer, Wilmington
http://www.securityfocus.com/archive/77/460935

45. [SJ-JOB] Security System Administrator, Tempe
http://www.securityfocus.com/archive/77/460945

46. [SJ-JOB] Security Consultant, Amsterdam
http://www.securityfocus.com/archive/77/460969

47. [SJ-JOB] Management, NYC
http://www.securityfocus.com/archive/77/460914

48. [SJ-JOB] Sales Engineer, Houston
http://www.securityfocus.com/archive/77/460968

49. [SJ-JOB] Security Consultant, Reading
http://www.securityfocus.com/archive/77/460807

50. [SJ-JOB] Information Assurance Analyst, Rickmansworth
http://www.securityfocus.com/archive/77/460809

51. [SJ-JOB] Security Architect, Omaha
http://www.securityfocus.com/archive/77/460810

52. [SJ-JOB] Application Security Engineer, Chicago
http://www.securityfocus.com/archive/77/460812

53. [SJ-JOB] Information Assurance Analyst, Dunstable
http://www.securityfocus.com/archive/77/460806

54. [SJ-JOB] Application Security Engineer, Edmonton
http://www.securityfocus.com/archive/77/460808

55. [SJ-JOB] Director, Information Security, San Diego
http://www.securityfocus.com/archive/77/460751

56. [SJ-JOB] Security Auditor, Charlotte
http://www.securityfocus.com/archive/77/460733

57. [SJ-JOB] Security Architect, Saint Paul
http://www.securityfocus.com/archive/77/460750

58. [SJ-JOB] Regional Channel Manager, Atlanta
http://www.securityfocus.com/archive/77/460732

59. [SJ-JOB] Instructor, Various US Citites
http://www.securityfocus.com/archive/77/460736

60. [SJ-JOB] Security Engineer, Pittsburgh
http://www.securityfocus.com/archive/77/460776

61. [SJ-JOB] Security Architect, CUPERTINO
http://www.securityfocus.com/archive/77/460734

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Increased activity on port 110
http://www.securityfocus.com/archive/75/461297

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. WordPress AdminPanel CSRF/XSS - 0day
http://www.securityfocus.com/archive/82/461355

2. SyScan'07 CFP
http://www.securityfocus.com/archive/82/461300

3. vd_proftpd.pm  Metasploit module for ProFTPD stack overflow
http://www.securityfocus.com/archive/82/461337

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. IIS 5
http://www.securityfocus.com/archive/88/461417

2. AD Global Security group with an email address behavior.
http://www.securityfocus.com/archive/88/461303

3. Vista "complaints"
http://www.securityfocus.com/archive/88/461046

4. App FW for isa2K4 2K6
http://www.securityfocus.com/archive/88/460880

5. Prevent users/admin from installing softwares.
http://www.securityfocus.com/archive/88/460879

6. SecurityFocus Microsoft Newsletter #330
http://www.securityfocus.com/archive/88/460755

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Did I get hacked?
http://www.securityfocus.com/archive/91/459940

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: Hackerproof your Web Apps with WebInspect - FREE Test
Hackers exploiting Web applications gain entry to backend data via Port 80 and 443! 
Firewalls and IDS don't stop these attacks because hackers using the Web App Layer are NOT 
seen as intruders. Run a FREE Test of your Web Apps via our 15 Day WebInspect Product Trial 
that delivers a comprehensive vulnerability report. 

https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cj4h