SecurityFocus Newsletter #404
[email protected] 6 Jun 2007 21:49:00 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #404
----------------------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008uP=
d
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Security Analogies
2. Your Space, My Space, Everybody's Space
II. BUGTRAQ SUMMARY
1. Computer Associates Multiple Products Remote Stack Buffer Overf=
low Vulnerability
2. Computer Associates Anti-Virus Engine Malformed CAB Filename Bu=
ffer Overflow Vulnerability
3. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerabilit=
y
4. Linker Index.PHP Cross-Site Scripting Vulnerability
5. MIT Kerberos Administration Daemon Kadmind Double Free Memory C=
orruption Vulnerabilities
6. SNMPC Username/Password Remote Denial of Service Vulnerability
7. HP Tru64 Valid User Enumeration Weakness
8. Iputils Rarpd Remote Denial Of Service Vulnerability
9. NetcPlus SmartServer3 DoS Vulnerability
10. NetCPlus BusinessMail Multiple Remote Buffer Overflow Vulnerab=
ilities
11. Mozilla FireFox About:Blank IFrame Cross Domain Information Di=
sclosure Vulnerability
12. Hunkaray Okul Portaly Haberoku.ASP SQL Injection Vulnerability
13. PHP Chunk_Split() Function Integer Overflow Vulnerability
14. PHP Filter_Var FILTER_VALIDATE_EMAIL Newline Injection Vulnera=
bility
15. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vu=
lnerability
16. Credant Mobile Guardian Shield Information Disclosure Vulnerab=
ility
17. Cisco Wireless Control System Multiple Security Vulnerabilitie=
s
18. Okyanusmedya Index.PHP Cross-Site Scripting Vulnerability
19. Agnitum Outpost Firewall Outpost_IPC_HDR Local Denial of Servi=
ce Vulnerability
20. Open Solution QuickCart Index.PHP Local File Include Vulnerabi=
lity
21. Mutt Insecure Temporary File Creation Multiple Vulnerabilities
22. GD Graphics Library PNG File Processing Denial of Service Vuln=
erability
23. IBM Web-based System Manager Unspecified Denial of Service Vul=
nerability
24. Provideo Camimage Class ISSCamControl.DLL ActiveX Control Buff=
er Overflow Vulnerability
25. DVD X Player PLF File Buffer Overflow Vulnerability
26. PHPLive Multiple Scripts Multiple Cross-Site Scripting Vulnera=
bilities
27. Symantec Ghost Solution Suite UDP Packet Multiple Denial of Se=
rvice Vulnerabilities
28. MadWifi Multiple Denial of Service Vulnerabilities
29. Sun Java Runtime Environment Image Parsing Buffer Overflow Vul=
nerability
30. ComicSense Index.PHP SQL Injection Vulnerability
31. Mozilla Products Multiple Remote Vulnerabilities
32. APOP Protocol Insecure MD5 Hash Weakness
33. Libpng Library Remote Denial of Service Vulnerability
34. Kravchuk K-Letter Multiple Remote File Include Vulnerabilities
35. FreeVMS Backup Utility Unspecified Buffer Overflow Vulnerabili=
ty
36. Microsoft Internet Explorer Javascript Cross Domain Informatio=
n Disclosure Vulnerability
37. W3M Browser InputAnswer Format String Vulnerability
38. Acme.Serve v1.7 Arbitrary File Access Vulnerability
39. Symantec System Center Reporting Server Remote Privilege Escal=
ation Vulnerability
40. Symantec Reporting Server Authentication Bypass Vulnerability
41. Symantec Reporting Server Password Information Disclosure Vuln=
erability
42. Net-SNMP TCP Disconnect Remote Denial Of Service Vulnerability
43. File Multiple Denial of Service Vulnerabilities
44. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulne=
rability
45. ASP Folder Gallery Download_Script.ASP Arbitrary File Download=
Vulnerability
46. Wordpress XMLRPC.PHP SQL Injection Vulnerability
47. JD Wiki For Joomla Multiple Remote File Include Vulnerabilitie=
s
48. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vu=
lnerabilities
49. PBLang Login.PHP Local File Include Vulnerability
50. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
51. MaraDNS Multiple Remote Denial of Service Vulnerabilities
52. LibEXIF Exif_Data_Load_Data_Entry Remote Integer Overflow Vuln=
erability
53. E-Book Systems FlipViewer FlipViewerX.DLL ActiveX Multiple Buf=
fer Overflow Vulnerabilities
54. HP System Management Homepage (SMH) Unspecified Cross Site Scr=
ipting Vulnerability
55. Kevin Johnson BASE Base_Main.PHP Authentication Bypass Vulnera=
bility
56. Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Ove=
rflow Vulnerability
57. Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Base=
d Buffer Overflow Vulnerability
58. Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulne=
rability
59. Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Bu=
ffer Overflow Vulnerability
60. Samba MS-RPC Remote Shell Command Execution Vulnerability
61. Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vuln=
erability
62. Sun Solaris Management Console Logging Mechanism Remote Privil=
ege Escalation Vulnerability
63. Sun Solaris Management Console Authentication Mechanism Remote=
Privilege Escalation Vulnerability
64. Util-linux Login Security Bypass Vulnerability
65. Mozilla Firefox Beatnik Extension Remote Script Code Execution=
Vulnerability
66. SSL-Explorer Multiple Input Validation Vulnerabilities
67. Multiple Vendor XFERWAN.EXE Filename Remote Buffer Overflow Vu=
lnerability
68. WebStudio CMS Index.PHP Cross-Site Scripting Vulnerability
69. IBM Lotus Domino Agent Signature Verification Local Privilege =
Escalation Vulnerability
70. Symantec Storage Foundation VxSchedService.EXE Scheduler Servi=
ce Authentication Bypass Vulnerability
71. Xine-Lib RuleMatches Remote Buffer Overflow Vulnerability
72. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vul=
nerability
73. Sun Solaris Gnome Assistive Technology XScreenSaver Local Arbi=
trary Command Execution Vulnerability
74. My DataBook Diary.PHP Multiple Input Validation Vulnerabilitie=
s
75. WebSVN Filedetails.PHP Cross-Site Scripting Vulnerability
76. Movable Type Multiple Input Validation Vulnerabilities And Use=
r Enumeration Weakness
77. Quick.Cart General.PHP Local File Include Vulnerability
78. Microsoft Internet Explorer Location Object Webpage Spoofing V=
ulnerability
79. Linker Search.PHP Cross-Site Scripting Vulnerability
80. PostNuke PNPHPBB2 Module Index.PHP SQL Injection Vulnerability
81. EQDKP Listmembers.PHP SQL Injection Vulnerability
82. Meneame Multiple Unspecified Cross Site Scripting Vulnerabilit=
ies
83. Mutt Mutt_Gecos_Name Function Local Buffer Overflow Vulnerabil=
ity
84. PHP PEAR INSTALL-AS Attribute Arbitrary File Overwrite Vulnera=
bility
85. LHA Insecure Temporary File Creation Vulnerability
86. WordPress Predictable Cookie Generation Information Disclosure=
Vulnerability
87. SendCard SendCard.PHP Local File Include Vulnerability
88. IBM Lotus Domino Web Server Unspecified Remote Denial of Servi=
ce Vulnerability
89. F5 FirePass 4100 SSL VPN My.Activiation.PHP3 Remote Command In=
jection Vulnerability
90. XOOPS IContent Module Spaw_Control.Class.PHP Remote File Inclu=
de Vulnerability
91. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnera=
bility
92. Hitachi XP/W Unspecified Remote Denial of Service Vulnerabilit=
y
93. Microsoft Excel Malformed Column Record Remote Code Execution =
Vulnerability
94. Microsoft Excel Malformed String Remote Code Execution Vulnera=
bility
95. Microsoft Excel IMDATA Record Remote Code Execution Vulnerabil=
ity
96. eSellerate SDK eSellerateControl365.DLL ActiveX Control Buffer=
Overflow Vulnerability
97. Mozilla Firefox Resource Variant Directory Traversal Vulnerabi=
lity
98. IBM Tivoli Provisioning Manager OS Deployment Multiple Stack B=
uffer Overflow Vulnerabilities
99. Mozilla Firefox Action Prompt Delay Security Mechanism Bypass =
Vulnerability
100. GDB Process_Coff_Symbol UPX File Buffer Overflow Vulnerabilit=
y
III. SECURITYFOCUS NEWS
1. Judge nixes teacher's conviction on porn pop-ups
2. Zero-day sales not "fair" -- to researchers
3. Insecure plug-ins pose danger to Firefox users
4. Peer-to-peer networks co-opted for DOS attacks
IV. SECURITY JOBS LIST SUMMARY
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #344
VIII. SUN FOCUS LIST SUMMARY
1. SSL Cert for patchpro.sun.com Invalid?
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Security Analogies
By Scott Granneman
Scott Granneman discusses security analogies and their function in educat=
ing the masses on security concepts.
http://www.securityfocus.com/columnists/445
2. Your Space, My Space, Everybody's Space
By Mark Rasch
Privacy is about protecting data when somebody wants it for some purpose.=
It is easy to protect data that nobody wants.
http://www.securityfocus.com/columnists/444
II. BUGTRAQ SUMMARY
--------------------
1. Computer Associates Multiple Products Remote Stack Buffer Overflow Vul=
nerability
BugTraq ID: 24330
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24330
Summary:
Multiple Computer Associates products are prone to a remote stack-based b=
uffer-overflow vulnerability because the scan engine fails to properly bo=
unds-check user-supplied data before copying it to an insufficiently size=
d buffer.
A successful exploit will allow an attacker to execute arbitrary code wit=
h SYSTEM-level privileges.
2. Computer Associates Anti-Virus Engine Malformed CAB Filename Buffer Ov=
erflow Vulnerability
BugTraq ID: 24331
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24331
Summary:
Multiple Computer Associates products that implement the antivirus engine=
are prone to a stack-based buffer-overflow vulnerability. This issue occ=
urs because the software fails to bounds-check user-supplied data before =
copying it into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.
3. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerability
BugTraq ID: 24235
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24235
Summary:
Multiple F-Secure Anti-Virus applications are prone to a buffer-overflow =
vulnerability when they process certain LHA archive files. This issue occ=
urs because the applications fail to properly check boundaries on user-su=
pplied data before copying it to an insufficiently sized memory buffer.
Successful exploits can allow attackers to execute arbitrary code with th=
e privileges of the vulnerable application. Failed exploit attempts will =
likely result in denial-of-service conditions.
Reports indicate that this vulnerability also occurs when processing malf=
ormed LZH archives, ARJ files, and FSG packed files.
4. Linker Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 24277
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24277
Summary:
Codelib Linker is prone to a cross-site scripting vulnerability because t=
he application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
5. MIT Kerberos Administration Daemon Kadmind Double Free Memory Corrupti=
on Vulnerabilities
BugTraq ID: 23282
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/23282
Summary:
MIT Kerberos 5 is prone to a double-free memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code with superus=
er or SYSTEM-level privileges, completely compromising affected computers=
. Failed exploit attempts will likely result in a denial-of-service condi=
tions.
This issue also affects third-party applications using the affected API.
6. SNMPC Username/Password Remote Denial of Service Vulnerability
BugTraq ID: 24292
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24292
Summary:
SNMPc is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue would cause the affected application t=
o crash, denying service to legitimate users.=20
This issue is reported to affect versions of SNMPc prior to 7.0.19.
7. HP Tru64 Valid User Enumeration Weakness
BugTraq ID: 24021
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24021
Summary:
Hewlett Packard Tru64 is prone to an information-disclosure weakness.
An attacker can exploit this issue to enumerate valid user names. This ma=
y aid in further attacks.
HP Tru64 UNIX v5.1B-3 and v5.1B-4 are vulnerable.
8. Iputils Rarpd Remote Denial Of Service Vulnerability
BugTraq ID: 23706
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/23706
Summary:
The 'iputils rarpd' program is affected by a remote denial-of-service vul=
nerability because the software fails to properly handle certain network =
packets.
A successful attack allows a remote attacker to crash the application, de=
nying further service to legitimate users.
9. NetcPlus SmartServer3 DoS Vulnerability
BugTraq ID: 1965
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/1965
Summary:
SmartServer3 is an email server designed for small networks.
The POP3 and SMTP services within SmartServer3 are prone to a denial-of-=
service issue. Submitting an unusually long argument to the User or Pass =
command in the POP3 service will cause the server to stop responding and =
refuse any new connections. An unusually long argument submitted to the S=
MTP service after the 'HELO' command will cause the server to stop respon=
ding, yet will still accept new connections. In either instance, a restar=
t of the server is required to gain normal functionality.
Successful exploits could allow attackers to execute arbitrary commands,=
but this has not been confirmed.
10. NetCPlus BusinessMail Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 14434
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/14434
Summary:
BusinessMail is affected by multiple remote buffer-overflow vulnerabiliti=
es because the software fails to perform boundary checks. Remote attacker=
s may be able to execute machine code in the context of the server proces=
s. =20
=20
BusinessMail 4.60 is reportedly vulnerable; other versions may be affecte=
d as well.
11. Mozilla FireFox About:Blank IFrame Cross Domain Information Disclosur=
e Vulnerability
BugTraq ID: 24286
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24286
Summary:
Mozilla Firefox is prone to a cross-domain information-disclosure vulnera=
bility because scripts may persist across navigations.=20
A malicious site may be able to modify the iframe of a site in an arbitra=
ry external domain. Attackers could exploit this to gain access to sensit=
ive information that is associated with the external domain. Other attack=
s are also possible, such as executing script code in other browser secur=
ity zones.
This issue is being tracked by Bugzilla Bug 382686 and is reportedly rela=
ted to Bug 343168.
Firefox 2.0.0.4 and prior versions are vulnerable.
12. Hunkaray Okul Portaly Haberoku.ASP SQL Injection Vulnerability
BugTraq ID: 24288
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24288
Summary:
H=C3=BCnkaray Okul Portal=C3=BD is prone to an SQL-injection vulnerabilit=
y because it fails to sufficiently sanitize user-supplied data before usi=
ng it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to=
carry out unauthorized actions on the underlying database.
H=C3=BCnkaray Okul Portal=C3=BD 1.1 is vulnerable to this issue.
13. PHP Chunk_Split() Function Integer Overflow Vulnerability
BugTraq ID: 24261
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24261
Summary:
PHP is prone to an integer-overflow vulnerability because it fails to ens=
ure that integer values aren't overrun. Attackers may exploit this issue =
to cause a buffer overflow and to corrupt process memory.
Attackers may be able to execute arbitrary machine code in the context of=
the affected application. Failed exploit attempts will likely result in =
a denial-of-service condition.
This issue affects versions of PHP prior to 5.2.3.
14. PHP Filter_Var FILTER_VALIDATE_EMAIL Newline Injection Vulnerability
BugTraq ID: 23359
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/23359
Summary:
PHP is prone to an email-newline-injection vulnerability because it fails=
to properly sanitize user-supplied input.
Exploiting this issue may allow a malicious user to create arbitrary emai=
l headers, and then create and transmit spam messages from the affected c=
omputer.
15. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 24289
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24289
Summary:
ClamAV is prone to a denial-of-service vulnerability.
A successful attack may allow an attacker to cause denial-of-service cond=
itions.
16. Credant Mobile Guardian Shield Information Disclosure Vulnerability
BugTraq ID: 24139
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24139
Summary:
Credant Mobile Guardian Shield is prone to an information-disclosure vuln=
erability because it stores sensitive password information in plain text.
This issue affects Credant Mobile Guardian Shield 5.2.1.105 and prior ver=
sions.
17. Cisco Wireless Control System Multiple Security Vulnerabilities
BugTraq ID: 18701
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/18701
Summary:
Cisco Wireless Control System is prone to multiple security vulnerabiliti=
es.
The following issues have been disclosed:
- Authorization-bypass vulnerability due to multiple hardcoded username a=
nd password pairs
- Arbitrary file access vulnerability
- Cross-site scripting vulnerability
- Information-disclosure vulnerability
An attacker can exploit these issues to retrieve potentially sensitive in=
formation, overwrite files, perform cross-site scripting attacks, and gai=
n unauthorized access; other attacks are also possible.
18. Okyanusmedya Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 24285
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24285
Summary:
Okyanusmedya is prone to a cross-site scripting vulnerability because the=
application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
19. Agnitum Outpost Firewall Outpost_IPC_HDR Local Denial of Service Vuln=
erability
BugTraq ID: 24284
Remote: No
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24284
Summary:
Outpost Firewall is prone to a local denial-of-service vulnerability.=20
An attacker can exploit this issue to block arbitrary processes, denying =
service to legitimate users.=20
This issue affects Outpost Firewall 4.0 build 1007.591.145 and build 964.=
582.059; other versions may also be affected.
20. Open Solution QuickCart Index.PHP Local File Include Vulnerability
BugTraq ID: 24281
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24281
Summary:
Quick.Cart is prone to a local file-include vulnerability because the app=
lication fails to sufficiently sanitize user-supplied input.
=20
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts. =20
=20
Quick.Cart 2.2 and prior versions are vulnerable to this issue.
21. Mutt Insecure Temporary File Creation Multiple Vulnerabilities
BugTraq ID: 20733
Remote: No
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/20733
Summary:
Mutt creates temporary files in an insecure manner.
Attackers could exploit these issues to perform symlink attacks to overwr=
ite arbitrary files using the privileges of the user running the vulnerab=
le application.
Mutt 1.5.12 and prior versions are vulnerable.
22. GD Graphics Library PNG File Processing Denial of Service Vulnerabili=
ty
BugTraq ID: 24089
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24089
Summary:
The GD graphics library is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions =
in applications implementing the affected library.
=20
GD graphics library 2.0.34 is reported vulnerable; other versions may be =
affected as well.
23. IBM Web-based System Manager Unspecified Denial of Service Vulnerabil=
ity
BugTraq ID: 24240
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24240
Summary:
IBM Web-based System Manager (WebSM) is prone to an unspecified denial-of=
-service vulnerability.
An attacker can exploit this issue to consume excessive memory, resulting=
in a denial-of-service condition.
24. Provideo Camimage Class ISSCamControl.DLL ActiveX Control Buffer Over=
flow Vulnerability
BugTraq ID: 24279
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24279
Summary:
Provideo Camimage Class ActiveX control is prone to a buffer-overflow vul=
nerability because the application fails to bounds-check user-supplied da=
ta before copying it into an insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
This issue affects Provideo Camimage Class 1.0.1.5; other versions may al=
so be affected.
25. DVD X Player PLF File Buffer Overflow Vulnerability
BugTraq ID: 24278
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24278
Summary:
DVD X Player is prone to a buffer-overflow vulnerability because the appl=
ication fails to bounds-check user-supplied data before copying it into a=
n insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.
This issue affects DVD X Player 4.1; other versions may also be affected.
26. PHPLive Multiple Scripts Multiple Cross-Site Scripting Vulnerabilitie=
s
BugTraq ID: 24276
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24276
Summary:
PHP Live! is prone to multiple cross-site scripting vulnerabilities becau=
se it fails to properly sanitize user-supplied input.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks.
PHP Live! 3.2.2 is vulnerable to this issue; other versions may also be a=
ffected.
27. Symantec Ghost Solution Suite UDP Packet Multiple Denial of Service V=
ulnerabilities
BugTraq ID: 24323
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24323
Summary:
Symantec Ghost Solution Suite is prone to multiple denial-of-service vuln=
erabilities because it fails to handle certain UDP network packets.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions via the client or server daemons.
These issues affects Ghost Solution Suite 2.0.0 and prior versions.
28. MadWifi Multiple Denial of Service Vulnerabilities
BugTraq ID: 24114
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24114
Summary:
MadWifi is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may permit attackers to cause system crashes and =
deny service to legitimate users.=20
Versions of MadWifi prior to 0.9.3.1 are vulnerable.
29. Sun Java Runtime Environment Image Parsing Buffer Overflow Vulnerabil=
ity
BugTraq ID: 24267
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24267
Summary:
The Sun Java Runtime Environment is prone to a buffer-overflow vulnerabil=
ity because the application fails to bounds-check user-supplied data befo=
re copying it into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user who invokes a malicious Java applet.
30. ComicSense Index.PHP SQL Injection Vulnerability
BugTraq ID: 24329
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24329
Summary:
ComicSense is prone to an SQL-injection vulnerability because it fails to=
sufficiently sanitize user-supplied data before using it in an SQL query=
.
An attacker can exploit this issue by manipulating the SQL query logic to=
carry out unauthorized actions on the underlying database.
31. Mozilla Products Multiple Remote Vulnerabilities
BugTraq ID: 24242
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24242
Summary:
The Mozilla Foundation has released six security advisories specifying vu=
lnerabilities in Firefox, SeaMonkey, and Thunderbird.
These vulnerabilities allow attackers to:
- Execute arbitrary code
- Cause denial-of-service conditions
- Perform cross-site scripting attacks
- Obtain potentially sensitive information
- Spoof legitimate content
Other attacks may also be possible.
32. APOP Protocol Insecure MD5 Hash Weakness
BugTraq ID: 23257
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/23257
Summary:
Applications that implement the APOP protocol may be vulnerable to a pass=
word-hash weakness. This issue occurs because the MD5 hash algorithm fail=
s to properly prevent collisions.
Attackers may exploit this issue in man-in-the-middle attacks to potentia=
lly gain access to the first three characters of passwords. This will inc=
rease the likelihood of successful brute-force attacks against APOP authe=
ntication.
To limit the possibility of successful exploits, applications that implem=
ent the APOP protocol should set up safeguards to ensure that message IDs=
are RFC-compliant.
Mozilla Thunderbird, Evolution, mutt, and fetchmail are reportedly affect=
ed by this issue.
33. Libpng Library Remote Denial of Service Vulnerability
BugTraq ID: 24000
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24000
Summary:
The 'libpng' library is prone to a remote denial-of-service vulnerability=
because the library fails to handle malicious PNG files.=20
Successful exploits may allow remote attackers to cause denial-of-service=
conditions on computers running the affected library.
This issue affects 'libpng' 1.2.16 and prior versions.
34. Kravchuk K-Letter Multiple Remote File Include Vulnerabilities
BugTraq ID: 24334
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24334
Summary:
Kravchuk K-letter is prone to multiple remote file-include vulnerabilitie=
s because it fails to properly sanitize user-supplied input to the applic=
ation.
An attacker may leverage these issues to execute an arbitrary remote file=
containing malicious script code in the context of the webserver process=
. This may allow the attacker to compromise the application and the under=
lying system. Other attacks are also possible.
These issues affect K-letter 1.0; other versions may also be affected.
35. FreeVMS Backup Utility Unspecified Buffer Overflow Vulnerability
BugTraq ID: 24333
Remote: No
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24333
Summary:
FreeVMS backup utility is prone to a buffer-overflow vulnerability becaus=
e it fails to bounds-check user-supplied data before copying it into an i=
nsufficiently sized buffer.
=20
Successfully exploiting this issue allows attackers to execute arbitrary =
code in the context of the vulnerable application. Failed exploit attempt=
s likely result in denial-of-service conditions.
This issue affects versions prior to FreeVMS 0.3.6
36. Microsoft Internet Explorer Javascript Cross Domain Information Discl=
osure Vulnerability
BugTraq ID: 24283
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24283
Summary:
The browser is prone to a cross-domain information-disclosure vulnerabili=
ty because scripts may persist across navigations.
This vulnerability may let a malicious site interact with a site in an ar=
bitrary external domain. Attackers could exploit this to gain access to s=
ensitive information that is associated with the external domain. Other a=
ttacks may be possible, such as executing script code in other browser se=
curity zones.
UPDATE: Reports indicate that Safari browser may also be vulnerable, but =
this has not been confirmed.
UPDATE - June 6 2007: The WebKit framework used by Safari is reported to =
be vulnerable. Builds 522 and later which are associated with the nightly=
WebKit build are vulnerable; other versions may also be affected.
37. W3M Browser InputAnswer Format String Vulnerability
BugTraq ID: 24332
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24332
Summary:
W3M is prone to a format-string vulnerability because it fails to properl=
y sanitize user-supplied input before passing it as the format specifier =
to a formatted-printing function.
An attack can exploit this issue to execute arbitrary machine code in the=
context of the user running the affected browser. A successful attack wi=
ll compromise the application. Failed attempts may cause denial-of-servic=
e conditions.
Versions prior to W3M 0.5.2 are vulnerable.
38. Acme.Serve v1.7 Arbitrary File Access Vulnerability
BugTraq ID: 2809
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/2809
Summary:
Acme.Serve is a free, open source embeddable web server written in Java. =
It is small and intended to provide minimal functionality and is fully co=
mpatible with JavaServer.=20
=20
Acme.Serve version 1.7 comes with a webserver that listens on port 9090. =
This webserver allows clients to browse the filesystem. By default, th=
is webserver is enabled and accessible by any remote host on the Internet=
.=20
=20
If an attacker were to connect, they could view possibly sensitive inform=
ation.
39. Symantec System Center Reporting Server Remote Privilege Escalation V=
ulnerability
BugTraq ID: 24313
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24313
Summary:
Symantec System Center Reporting Server is prone to a remote privilege-es=
calation vulnerability.
Attackers can exploit this issue to execute malicious code on an affected=
server and gain the privileges of the user running the server. Successfu=
l attacks will compromise the application and possibly the underlying com=
puter.
Reporting Server is distributed with Symantec AntiVirus Corporate Edition=
10.1 and later and Symantec Client Security 3.1 and later.=20
Versions prior to Reporting Server 1.0.224.0, AntiVirus Corporate Edition=
10.1.6.6000, and Client Security 3.1.6.6000 are vulnerable.
40. Symantec Reporting Server Authentication Bypass Vulnerability
BugTraq ID: 24325
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24325
Summary:
Symantec Reporting Server is prone to an authentication-bypass vulnerabil=
ity.
An attacker can exploit this issue to gain access to the reporting databa=
se.
41. Symantec Reporting Server Password Information Disclosure Vulnerabili=
ty
BugTraq ID: 24312
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24312
Summary:
Symantec Reporting Server is prone to an information-disclosure vulnerabi=
lity.
Successfully exploiting this issue would allow an attacker to obtain sens=
itive information that will allow the attacker to gain administrative acc=
ess to the server database.
42. Net-SNMP TCP Disconnect Remote Denial Of Service Vulnerability
BugTraq ID: 23762
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/23762
Summary:
Net-SNMP is prone to a remote denial-of-service vulnerability. The issue =
is exposed when Net-SNMP is configured to communicate over TCP; Net-SNMP =
using UDP is unaffected.=20
This issue affects Net-SNMP when running in 'master agentx' mode. An atta=
cker can exploit this issue to cause the affected service to crash, effec=
tively denying service to legitimate users.
43. File Multiple Denial of Service Vulnerabilities
BugTraq ID: 24146
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24146
Summary:
The 'file' utility is prone to multiple denial-of-service vulnerabilities=
because it fails to handle exceptional conditions.=20
An attacker could exploit this issue by enticing a victim to open a speci=
ally crafted file. A denial-of-service condition can occur. Arbitrary cod=
e execution may be possible, but Symantec has not confirmed this.
44. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulnerabilit=
y
BugTraq ID: 24346
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24346
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to properly handle maliciously crafted ICO files.
An attacker may exploit this issue by enticing victims into opening a mal=
icious file.
Successful exploits will result in denial-of-service conditions on applic=
ations using the affected library. Applications such as Windows Explorer =
or Picture and Fax viewer have been identified as vulnerable.
45. ASP Folder Gallery Download_Script.ASP Arbitrary File Download Vulner=
ability
BugTraq ID: 24345
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24345
Summary:
ASP Folder Gallery is prone to an arbitrary file-download vulnerability b=
ecause the application fails to sufficiently sanitize user-supplied input=
.
An attacker can exploit this issue to download arbitrary files within the=
context of the affected webserver.
46. Wordpress XMLRPC.PHP SQL Injection Vulnerability
BugTraq ID: 24344
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24344
Summary:
WordPress is prone to an SQL-injection vulnerability because the applicat=
ion fails to properly sanitize user-supplied input before using it in an =
SQL query.
=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase implementation.
=20
This issue affects WordPress 2.2; other versions may also be vulnerable.
47. JD Wiki For Joomla Multiple Remote File Include Vulnerabilities
BugTraq ID: 24342
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24342
Summary:
JD-Wiki is prone to multiple remote file-include vulnerabilities because =
it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may allow the attacker to compromise the application and =
to gain access to the underlying system.
JD-Wiki 1.0.2 and earlier are vulnerable to this issue; other versions ma=
y also be affected.
48. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vulnerabi=
lities
BugTraq ID: 24341
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24341
Summary:
Yahoo! Messenger is prone to multiple unspecified remote code-execution v=
ulnerabilities.
No further information is currently available. This BID will be updated a=
s more information is disclosed.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers.
Specific vulnerable Yahoo! Messenger versions are not known, but versions=
in the 8 series for Microsoft Windows are reportedly affected.
49. PBLang Login.PHP Local File Include Vulnerability
BugTraq ID: 24340
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24340
Summary:
PBLang is prone to a local file-include vulnerability because it fails to=
properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
Version 4.67.16.a is vulnerable to this issue; prior versions may also be=
affected.
50. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
BugTraq ID: 24339
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24339
Summary:
MPlayer is prone to multiple buffer-overflow vulnerabilities when it atte=
mpts to process malformed album and category titles. These issues occur b=
ecause the application fails to perform proper bounds-checking on user-su=
pplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit these issues to execute arbitrary code with the p=
rivileges of the user that activated the vulnerable application. This may=
facilitate unauthorized access or privilege escalation.
MPlayer 1.0rc1 is vulnerable to these issues; other versions may also be =
affected.
51. MaraDNS Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 24337
Remote: Yes
Last Updated: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24337
Summary:
MaraDNS is prone to multiple remote denial-of-service vulnerabilities bec=
ause of memory leaks.
=20
Successfully exploiting these issues allows remote attackers to crash aff=
ected servers by exhausting memory resources. This will deny further serv=
ice to legitimate users.
MaraDNS versions prior to 1.2.12.06 are vulnerable.
52. LibEXIF Exif_Data_Load_Data_Entry Remote Integer Overflow Vulnerabili=
ty
BugTraq ID: 23927
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/23927
Summary:
The libexif library is prone to an integer-overflow vulnerability because=
the software fails to properly ensure that integer math operations do no=
t result in unintended overflows.
Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of an application using the vuln=
erable library. Failed attempts will likely result in denial-of-service c=
onditions.
=20
Versions of libexif prior to 0.6.14 are vulnerable to this issue.
53. E-Book Systems FlipViewer FlipViewerX.DLL ActiveX Multiple Buffer Ove=
rflow Vulnerabilities
BugTraq ID: 24328
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24328
Summary:
E-Book Systems FlipViewer ActiveX Control is prone to multiple buffer-ove=
rflow vulnerabilities.
=20
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
(typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.
Versions prior to FlipViewer 4.0 are vulnerable; other versions may also =
be affected.
54. HP System Management Homepage (SMH) Unspecified Cross Site Scripting =
Vulnerability
BugTraq ID: 24256
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24256
Summary:
HP System Management Homepage is prone to a cross-site scripting vulnerab=
ility.=20
Exploiting this vulnerability may allow an attacker to perform cross-site=
scripting attacks on unsuspecting users in the context of the affected w=
ebsite. As a result, the attacker may be able to steal cookie-based authe=
ntication credentials and to launch other attacks.
Versions of HP System Management Homepage (SMH) prior to 2.1.2 for Linux =
and Windows are affected.
55. Kevin Johnson BASE Base_Main.PHP Authentication Bypass Vulnerability
BugTraq ID: 24315
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24315
Summary:
BASE is prone to an authentication-bypass vulnerability due to a design e=
rror.
An attacker can exploit this issue to gain unauthorized access to the aff=
ected application.
This issue affects BASE 1.3.6; prior versions may also be affected.
56. Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Overflow V=
ulnerability
BugTraq ID: 24196
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24196
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
57. Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Based Buffe=
r Overflow Vulnerability
BugTraq ID: 24195
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24195
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
58. Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulnerabilit=
y
BugTraq ID: 24198
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24198
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
59. Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Ov=
erflow Vulnerability
BugTraq ID: 23973
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/23973
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
This BID previously documented multiple heap-based buffer-overflow vulner=
abilities affecting Samba. Each issue has been assigned its own individua=
l record. The issues are covered in this BID and the following records:
=20
BID 24195 - Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Bas=
ed Buffer Overflow Vulnerability
BID 24196 - Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Ov=
erflow Vulnerability
BID 24197 - Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vul=
nerability
BID 24198 - Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vuln=
erability
60. Samba MS-RPC Remote Shell Command Execution Vulnerability
BugTraq ID: 23972
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/23972
Summary:
Samba is prone to a vulnerability that allows attackers to execute arbitr=
ary shell commands because the software fails to sanitize user-supplied i=
nput.
An attacker may leverage this issue to execute arbitrary shell commands o=
n an affected computer with the privileges of the application.
This issue affects Samba 3.0.0 to 3.0.25rc3.
61. Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vulnerabili=
ty
BugTraq ID: 24197
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24197
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.
This issue affects Samba 3.0.25rc3 and prior versions.
62. Sun Solaris Management Console Logging Mechanism Remote Privilege Esc=
alation Vulnerability
BugTraq ID: 24327
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24327
Summary:
Sun Solaris Management Console is prone to a remote privilege-escalation =
vulnerability.
Attackers can exploit this issue to gain superuser privileges. Successful=
attacks will result in the complete compromise of affected computers.
63. Sun Solaris Management Console Authentication Mechanism Remote Privil=
ege Escalation Vulnerability
BugTraq ID: 24326
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24326
Summary:
Sun Solaris Management Console is prone to a remote privilege-escalation =
vulnerability.
Attackers can exploit this issue to gain superuser privileges. Successful=
attacks will result in the complete compromise of affected computers.
64. Util-linux Login Security Bypass Vulnerability
BugTraq ID: 24321
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24321
Summary:
The 'login' utility (in 'util-linux') is prone to a security-bypass vulne=
rability because the utility fails to properly validate user privileges.
Exploiting this issue can allow an attacker to bypass certain security re=
strictions and potentially gain unauthorized access.
Versions prior to 'util-linux' 2.12 are vulnerable.
65. Mozilla Firefox Beatnik Extension Remote Script Code Execution Vulner=
ability
BugTraq ID: 24324
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24324
Summary:
A remote code-execution vulnerability affects the Beatnik extension for M=
ozilla Firefox because the application fails to validate input errors whe=
n processing RSS feeds.
=20
An attacker may leverage this issue to execute arbitrary code in the cont=
ext of the user account running the affected extension. This may facilita=
te cross-site scripting as well as a compromise of an affected computer.
Beatnik 1.0 is vulnerable; other versions may also be affected.
66. SSL-Explorer Multiple Input Validation Vulnerabilities
BugTraq ID: 24319
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24319
Summary:
SSL-Explorer is prone to multiple input-validation vulnerabilities, inclu=
ding HTML-injection, cross-site scripting, and directory-traversal issues=
, because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, execute arbitrary script code in the context of =
the webserver process, compromise the application, obtain sensitive infor=
mation, and access or modify data.
67. Multiple Vendor XFERWAN.EXE Filename Remote Buffer Overflow Vulnerabi=
lity
BugTraq ID: 24317
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24317
Summary:
Multiple vendor products are prone to a remote buffer-overflow vulnerabil=
ity in 'XFERWAN.EXE'.=20
The vulnerability arises in the service when handling logging requests. S=
pecifically, a long filename can trigger an overflow condition that will =
corrupt memory.
A remote attacker may trigger a denial-of-service condition or may execut=
e arbitrary code with SYSTEM privileges. This may facilitate a complete c=
ompromise of affected systems.
The following versions contain the affected executable and are considered=
vulnerable:
Centennial Discovery 2006 Feature Pack 1
Symantec Discovery 6.5=20
Numara Asset Manager 8.0
Earlier versions of each application may be affected as well.
68. WebStudio CMS Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 24297
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24297
Summary:
WebStudio CMS is prone to a cross-site scripting vulnerability because th=
e application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
69. IBM Lotus Domino Agent Signature Verification Local Privilege Escalat=
ion Vulnerability
BugTraq ID: 24322
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24322
Summary:
IBM Lotus Domino Server is prone to a privilege-escalation vulnerability =
because of a design error.
=20
An attacker can exploit this issue to gain administrative access to the d=
atabase server.
=20
Versions prior to IBM Lotus Domino 7.0.2 Fix Pack 2 (FP2) are vulnerable.
70. Symantec Storage Foundation VxSchedService.EXE Scheduler Service Auth=
entication Bypass Vulnerability
BugTraq ID: 24194
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24194
Summary:
Symantec Storage Foundation is prone to an authentication-bypass vulnerab=
ility.
Attackers may exploit this issue to bypass the authentication mechanism i=
n the management console and gain access to the scheduler service socket.=
This will allow attackers to add arbitrary commands to be executed durin=
g normal scheduled runs, compromising affected computers.
Since the affected service is not commonly exposed to unauthorized networ=
k hosts, the attacker must have local network access to exploit this issu=
e.
This issue affects Symantec Storage Foundation 5.0 for Windows.
71. Xine-Lib RuleMatches Remote Buffer Overflow Vulnerability
BugTraq ID: 21435
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/21435
Summary:
The 'xine-lib' library running on Real media is prone to a remote buffer-=
overflow vulnerability because the application fails to properly bounds-c=
heck user-supplied data before copying it into an insufficiently sized bu=
ffer.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the currently logged-in user. Failed exploit attempts will res=
ult in a denial of service.
72. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vulnerabil=
ity
BugTraq ID: 24316
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24316
Summary:
ClamAV is prone to a denial-of-service vulnerability when handling malfor=
med OLE2 files.
A successful attack may allow an attacker to cause denial-of-service cond=
itions.
=20
Versions prior to ClamAV 0.90.3 are affected.
73. Sun Solaris Gnome Assistive Technology XScreenSaver Local Arbitrary C=
ommand Execution Vulnerability
BugTraq ID: 24314
Remote: No
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24314
Summary:
Sun Solaris, running Gnome sessions with Assistive Technology and xscreen=
saver, is prone to a local arbitrary-command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary commands with the=
privileges of the user running xscreensaver.
74. My DataBook Diary.PHP Multiple Input Validation Vulnerabilities
BugTraq ID: 24311
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24311
Summary:
My DataBook is prone to multiple input-validation vulnerabilities, includ=
ing cross-site scripting and SQL-injection issues.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, compromise the application, access or modify dat=
a, or exploit latent vulnerabilities in the underlying database.
75. WebSVN Filedetails.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 24310
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24310
Summary:
WebSVN is prone to a cross-site scripting vulnerability because the appli=
cation fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
WebSVN 2.0rc4 is affected; other versions may also be vulnerable.
76. Movable Type Multiple Input Validation Vulnerabilities And User Enume=
ration Weakness
BugTraq ID: 24304
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24304
Summary:
Movable Type is prone to multiple input-validation vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data. It is also prone =
to a username-enumeration weakness.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, compromise the application, access or modify dat=
a, cause arbitrary script code to run within the context of the webserver=
process that is hosting the affected software, and compromise the availa=
bility and integrity of a computer to ultimately gain remote unauthorized=
access by overwriting sensitive files (such as the password file).
Movable Type 3.16 is affected; other versions may also be vulnerable.
77. Quick.Cart General.PHP Local File Include Vulnerability
BugTraq ID: 24299
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24299
Summary:
Quick.Cart is prone to a local file-include vulnerability because it fail=
s to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
Quick.Cart 2.2 is vulnerable; other versions may also be affected.
78. Microsoft Internet Explorer Location Object Webpage Spoofing Vulnerab=
ility
BugTraq ID: 24298
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24298
Summary:
Microsoft Internet Explorer is prone to a webpage-spoofing vulnerability.
Attackers may exploit this vulnerability via a malicious webpage to spoof=
the contents and origin of a page that the victim may trust. Attackers m=
ay find this issue useful in phishing or other attacks that rely on conte=
nt spoofing.
79. Linker Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 24296
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24296
Summary:
Codelib Linker is prone to a cross-site scripting vulnerability because t=
he application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
Codelib Linker 2.0.4 is vulnerable; other versions may also be affected.
80. PostNuke PNPHPBB2 Module Index.PHP SQL Injection Vulnerability
BugTraq ID: 24295
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24295
Summary:
The PostNuke PNPHPBB2 module is prone to an SQL-injection vulnerability b=
ecause it fails to sufficiently sanitize user-supplied data before using =
it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to=
carry out unauthorized actions on the underlying database.
This issue affects PNPHPBB2 1.2; prior versions are also affected.
81. EQDKP Listmembers.PHP SQL Injection Vulnerability
BugTraq ID: 24294
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24294
Summary:
EQdkp is prone to an SQL-injection vulnerability because it fails to suff=
iciently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to=
carry out unauthorized actions on the underlying database.
EQdkp 1.3.2 is vulnerable to this issue; earlier versions may also be aff=
ected.
82. Meneame Multiple Unspecified Cross Site Scripting Vulnerabilities
BugTraq ID: 24290
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24290
Summary:
Men=C3=A9ame is prone to multiple cross-site scripting vulnerabilities be=
cause it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.
Versions prior to Men=C3=A9ame 2 are vulnerable.
83. Mutt Mutt_Gecos_Name Function Local Buffer Overflow Vulnerability
BugTraq ID: 24192
Remote: No
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24192
Summary:
Mutt is prone to a local buffer-overflow vulnerability because it fails t=
o properly bounds-check user-supplied input before using it in a memory c=
opy operation.
An attacker can exploit this issue to execute arbitrary code with the wit=
h the privileges of the victim. Failed exploit attempts will result in a =
denial of service.
84. PHP PEAR INSTALL-AS Attribute Arbitrary File Overwrite Vulnerability
BugTraq ID: 24111
Remote: Yes
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24111
Summary:
PEAR is prone to a vulnerability that lets attackers overwrite arbitrary =
files.
=20
An attacker-supplied package may supply directory-traversal strings throu=
gh the 'install-as' attribute to create and overwrite files in arbitrary =
locations.
=20
This issue affects PEAR 1.0 to 1.5.3.
85. LHA Insecure Temporary File Creation Vulnerability
BugTraq ID: 24336
Remote: No
Last Updated: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24336
Summary:
The lha application creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
Successfully mounting a symlink attack may allow the attacker to overwrit=
e or corrupt sensitive files, which may result in a denial of service. Ot=
her attacks may also be possible.
86. WordPress Predictable Cookie Generation Information Disclosure Vulner=
ability
BugTraq ID: 24309
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24309
Summary:
WordPress is prone to an information-disclosure vulnerability because it =
generates author cookies in a predictable manner.
Attackers can exploit this issue to view unmoderated comments which could=
contain potentially sensitive information.
WordPress 2.2 and prior versions are vulnerable.
87. SendCard SendCard.PHP Local File Include Vulnerability
BugTraq ID: 24308
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24308
Summary:
Sendcard is prone to a local file-include vulnerability because it fails =
to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
This issue affects Sendcard 3.4.1; prior versions are also affected.
88. IBM Lotus Domino Web Server Unspecified Remote Denial of Service Vuln=
erability
BugTraq ID: 24307
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24307
Summary:
The webserver included with IBM Lotus Domino is prone to a remote denial-=
of-service vulnerability because the software fails to properly handle ce=
rtain HTTP requests.
Successfully exploiting this issue allows remote attackers to crash affec=
ted webservers, denying further service to legitimate users.
This issue is a regression introduced in version 6.0 of Lotus Domino.
89. F5 FirePass 4100 SSL VPN My.Activiation.PHP3 Remote Command Injection=
Vulnerability
BugTraq ID: 24306
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24306
Summary:
F5 Firepass 4100 SSL VPN is prone to a remote command-injection vulnerabi=
lity because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary commands on the aff=
ected device. Successful attacks will compromise the device.
90. XOOPS IContent Module Spaw_Control.Class.PHP Remote File Include Vuln=
erability
BugTraq ID: 24302
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24302
Summary:
XOOPS iContent is prone to a remote file-include vulnerability because it=
fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
91. Todd Miller Sudo Ptrace API Local Privilege Escalation Vulnerability
BugTraq ID: 24287
Remote: No
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24287
Summary:
The 'sudo' utility and the 'ptrace' call are prone to a local privilege-e=
scalation vulnerability.=20
An attacker can exploit this issue to execute arbitrary commands with sup=
eruser privileges. Successfully exploiting this issue will result in the =
complete compromise of affected computers.
92. Hitachi XP/W Unspecified Remote Denial of Service Vulnerability
BugTraq ID: 24262
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24262
Summary:
Hitachi XP/W are prone to a remote denial-of-service vulnerability.
Successful exploits may allow attackers to crash affected servers, effec=
tively denying further service to legitimate users.
93. Microsoft Excel Malformed Column Record Remote Code Execution Vulnera=
bility
BugTraq ID: 21925
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/21925
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the user running the application. The attacker could leverag=
e the issue to compromise affected computers.
94. Microsoft Excel Malformed String Remote Code Execution Vulnerability
BugTraq ID: 21877
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/21877
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the user running the affected application, which could result in=
the compromise of affected computers.
95. Microsoft Excel IMDATA Record Remote Code Execution Vulnerability
BugTraq ID: 21856
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/21856
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the user running the application, which can result in the compro=
mise of affected computers.
96. eSellerate SDK eSellerateControl365.DLL ActiveX Control Buffer Overfl=
ow Vulnerability
BugTraq ID: 24300
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24300
Summary:
eSellerate SDK ActiveX control is prone to a buffer-overflow vulnerabilit=
y because the application fails to bounds-check user-supplied data before=
copying it into an insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
This issue affects eSellerate SDK 3.6.5.0; other versions may also be aff=
ected.
97. Mozilla Firefox Resource Variant Directory Traversal Vulnerability
BugTraq ID: 24303
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24303
Summary:
Mozilla Firefox is prone to a directory-traversal vulnerability because i=
t fails to adequately sanitize user-supplied data.
An attacker can exploit this issue to access arbitrary files on an unsusp=
ecting user's computer. Successful exploits can expose potentially sensit=
ive information that could aid in further attacks.
This issue was introduced as part of the fix for BID 24191 (Mozilla Firef=
ox Resource Directory Traversal Vulnerability) in Firefox 2.0.0.4.
98. IBM Tivoli Provisioning Manager OS Deployment Multiple Stack Buffer O=
verflow Vulnerabilities
BugTraq ID: 23264
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/23264
Summary:
IBM Tivoli Provisioning Manager for OS Deployment is prone to multiple st=
ack-based buffer-overflow issues because the software fails to bounds-che=
ck user-supplied input.
An attacker can exploit these issues to execute arbitrary code with SYSTE=
M-level privileges or to crash services. Successful attacks may result in=
the complete compromise of affected computers.
IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.116 is vulnerable=
; other versions may also be affected.
99. Mozilla Firefox Action Prompt Delay Security Mechanism Bypass Vulnera=
bility
BugTraq ID: 24293
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24293
Summary:
Mozilla Firefox is prone to a security-mechanism-bypass vulnerability bec=
ause it fails to adequately prevent action prompt options from being sele=
cted before a delay timer has finished counting down.
Attackers can exploit this issue to initiate downloads or run files on a =
user's computer without their knowledge or consent. Successful attacks ca=
n allow arbitrary code to run with the privileges of the user running the=
application.
This issue is reportedly being tracked by Bugzilla Bug 376473.
Firefox 2.0.0.4 and prior versions are vulnerable.
100. GDB Process_Coff_Symbol UPX File Buffer Overflow Vulnerability
BugTraq ID: 24291
Remote: Yes
Last Updated: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24291
Summary:
GDB is prone to a buffer-overflow vulnerability because it fails to prope=
rly check bounds when handling specially crafted executable files.
Attackers could leverage this issue to run arbitrary code outside of a re=
stricted environment, which may lead to privilege escalation. Symantec ha=
s not confirmed code execution.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Judge nixes teacher's conviction on porn pop-ups
By: Robert Lemos
A Connecticut judge grants a new trial for substitute teacher Julie Amero=
, saying that forensics information discovered after her conviction has d=
irect bearing on her case.
http://www.securityfocus.com/news/11469
2. Zero-day sales not "fair" -- to researchers
By: Robert Lemos
A security analyst tries his hand at selling two vulnerabilities and find=
s that economics and time are against him.
http://www.securityfocus.com/news/11468
3. Insecure plug-ins pose danger to Firefox users
By: Robert Lemos
A security researcher warns that an insecure update mechanism for some of=
the open-source browser's third-party add-ons could allow an attacker th=
e ability to install malicious code.
http://www.securityfocus.com/news/11467
4. Peer-to-peer networks co-opted for DOS attacks
By: Robert Lemos
Attackers compromise the hub servers of the DC++ peer-to-peer network, tu=
rning hundreds of thousands of clients into hard-to-stop distributed deni=
al-of-service attacks.
http://www.securityfocus.com/news/11466
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #344
http://www.securityfocus.com/archive/88/470135
VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. SSL Cert for patchpro.sun.com Invalid?
http://www.securityfocus.com/archive/92/470584
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored. This paper examines a few vulnerability detectio=
n methods - specifically comparing and contrasting manual penetration tes=
ting with automated scanning tools. Download Watchfire's "Web Application=
Security: Automated Scanning or Manual Penetration Testing?" whitepaper =
today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D701500000008uP=
d