SecurityFocus Newsletter #409

[email protected] 11 Jul 2007 19:49:23 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #409
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Achtung! New German Laws on Cybercrime
       2. Don't Be Evil
II.   BUGTRAQ SUMMARY
       1. SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remo=
te Command Execution Vulnerabilities
       2. HP TCP/IP Services for OpenVMS User Enumeration Weakness and Se=
curity Bypass Vulnerabilities
       3. GameSiteScript Index.PHP SQL Injection Vulnerability
       4. Lhaca File Archiver Unspecified Stack Buffer Overflow Vulnerabi=
lity
       5. Nonnoi ASP/Barcode COM Component NONNOI_ASPBarcode.DLL Arbitrar=
y File Overwrite Vulnerability
       6.  Symantec Norton Ghost RemoteCommand.DLL Buffer Overflow Vulner=
ability
       7. Yb Ve Bayi Babvuru Formu Multiple HTML Injection Vulnerabilitie=
s
       8. Computer Associates ERwin Data Model Validator Multiple Denial =
Of Service Vulnerabilities
       9. Mozilla Firefox Multiple Popup Tabs Denial of Service Vulnerabi=
lity
       10. Linux Kernel SCTP Connection Denial Of Service Vulnerability
       11. Linux Kernel Decode_Choices Function Remote Denial Of Service =
Vulnerability
       12. Microsoft Windows Vista Kernel Unspecified Remote Denial Of Se=
rvice Vulnerability
       13. Linux Kernel IPV6_SockGlue.c NULL Pointer Dereference Vulnerab=
ility
       14. VLC Media Player Multiple Format String Vulnerabilities
       15. SAP Message Server Group Parameter Remote Buffer Overflow Vuln=
erability
       16. Apple Safari Cross-Domain Race Condition Information Disclosur=
e Vulnerability
       17. Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
       18. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE 19=
1 Buffer Overflow Vulnerability
       19. McAfee NeoTrace ActiveX Control Remote Buffer Overflow Vulnera=
bility
       20. PHP 5 User-Supplied Session ID Input Validation Vulnerability
       21. PHPPost Multiple Cross-Site Scripting Vulnerabilities
       22. PHP Multiple Input Validation Vulnerabilities
       23. PHP Prior to 5.2.2/4.4.7 Multiple Remote Buffer Overflow Vulne=
rabilities
       24. PHP Zip URL Wrapper Stack Buffer Overflow Vulnerability
       25. Linux Kernel IPv6 TCP Sockets Local Denial of Service Vulnerab=
ility
       26. Linux Kernel AppleTalk ATalk_Sum_SKB Function Denial Of Servic=
e Vulnerability
       27. Microsoft Windows Active Directory LDAP Request Validation Rem=
ote Code Execution Vulnerability
       28. Symantec Veritas Backup Exec for Windows Server Unspecified He=
ap Buffer Overflow Vulnerability
       29. Sun Java Runtime Environment WebStart JNLP File Stack Buffer O=
verflw Vulnerability
       30. Entertainment CMS AdminLogged Cookie Parameter Authentication =
Bypass Vulnerability
       31. TippingPoint IPS Fragmented Packets Detection Bypass Vulnerabi=
lity
       32. X.Org X11 XC-MISC Extension Local Integer Overflow Vulnerabili=
ty
       33. Wireshark Multiple Protocol Denial of Service Vulnerabilities
       34. X.Org LibXFont Multiple Local Integer Overflow Vulnerabilities
       35. Microsoft Internet Explorer FirefoxURL Protocol Handler Comman=
d Injection Vulnerability
       36. Microsoft Windows Vista Teredo Interface Firewall Bypass Vulne=
rability
       37. OpenOffice RTF File Parser Buffer Overflow Vulnerability
       38. Sun Java System Access Manager Logging Output Password Disclos=
ure Vulnerability
       39. Sun Java System Server XSLT Processing Remote Java Method Exec=
ution Vulnerability
       40. Microsoft Office Publisher Invalid Memory Reference Remote Cod=
e Execution Vulnerability
       41. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
       42. Adobe Photoshop Multiple File Format Buffer Overflow Vulnerabi=
lity
       43. Multiple Image Editing Applications .PNG Format Handling Remot=
e Buffer Overflow Vulnerability
       44. Opera Web Browser Running Adobe Flash Player Information Discl=
osure Vulnerability
       45. Adobe Flash Player SWF File Handling Remote Code Execution Vul=
nerability
       46. Linux Kernel IPV6_Getsockopt_Sticky Memory Leak Information Di=
sclosure Vulnerability
       47. Mike's World Mail Machine Mailmachine.CGI Local File Include V=
ulnerability
       48. EVisit Analyst ID Parameter Multiple SQL Injection Vulnerabili=
ties
       49. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulner=
ability
       50. TippingPoint IPS Unicode Character Detection Bypass Vulnerabil=
ity
       51. Microsoft .Net Framework Multiple Null Byte Injection Vulnerab=
ilities
       52. ImgSvr Template Parameter Local File Include Vulnerability
       53. RCP Shell Utility Arbitrary Command Execution Vulnerability
       54. Windows Media Player Remote ASF File Buffer Overflow Vulnerabi=
lity
       55. Windows Media Player ASX PlayList File Heap Overflow Vulnerabi=
lity
       56. SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Comma=
nd Execution Vulnerability
       57. Zenturi ProgramChecker ActiveX Control Fill Method Stack Based=
 Buffer Overflow Vulnerability
       58. Apple Safari for Windows SVG Parse Engine Multiple Unspecified=
 Vulnerabilities
       59. IBM Proventia Sensor Appliance Multiple Input Validation Vulne=
rabilities
       60. McAfee Common Management Agent (CMA) Multiple Memory Corruptio=
n Vulnerabilities
       61. EnViVo!CMS Default.ASP ID Parameter SQL Injection Vulnerabilit=
y
       62. Symantec Client Security Internet E-mail Auto-Protect Stack Ov=
erflow Vulnerability
       63. Retired: Microsoft July 2007 Advance Notification Multiple Vul=
nerabilities
       64. AlstraSoft Video Share Enterprise Multiple Remote Vulnerabilit=
ies
       65. SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerab=
ilities
       66. Microsoft .NET Framework PE Loader Remote Buffer Overflow Vuln=
erability
       67. Microsoft .NET Framework JIT Compiler Remote Buffer Overflow V=
ulnerability
       68. FlashBB Sendmsg.PHP Remote File Include Vulnerability
       69. Microsoft Excel Workspace Designation Remote Code Execution Vu=
lnerability
       70. Microsoft Excel Worksheet Remote Code Execution Vulnerability
       71. Microsoft .NET Framework Request Filtering Bypass Vulnerabilit=
y
       72. Microsoft Internet Information Server 5.1 DLL Request Remote C=
ode Execution Vulnerability
       73. Microsoft Excel Version Information Validation Remote Code Exe=
cution Vulnerability
       74. Microsoft Windows Active Directory LDAP Request Validation Rem=
ote Denial Of Service Vulnerability
       75. Microsoft Excel Unspecified Security Vulnerability
       76. WinPcap NPF.SYS BIOCGSTATS Parameters Local Privilege Escalati=
on Vulnerability
       77. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Servic=
e Vulnerability
       78. Unobtrusive AJAX Star Rating Bar Multiple Input Validation Vul=
nerabilities
       79. Visual IRC Join Response Buffer Overflow Vulnerability
       80. ImageMagick DCM XWD Formats Multiple Integer Overflow Vulnerab=
ilities
       81. ImageMagick XGetPixel/XInitImage Multiple Integer Overflow Vul=
nerabilities
       82. IBM AIX Libodm ODMPath Stack Overflow Vulnerability
       83. Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Ove=
rflow Vulnerability
       84. Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vuln=
erability
       85. Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulne=
rability
       86. Samba SID Names Local Privilege Escalation Vulnerability
       87. Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Bu=
ffer Overflow Vulnerability
       88. Samba MS-RPC Remote Shell Command Execution Vulnerability
       89. Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Base=
d Buffer Overflow Vulnerability
       90. Inferno Technologies VBulletin RPG Inferno Inferno.PHP SQL Inj=
ection Vulnerability
       91. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
       92. File(1) Command File_PrintF Integer Underflow Vulnerability
       93. File Multiple Denial of Service Vulnerabilities
       94. IBM Hardware Management Console Unspecified Vulnerability
       95. OpenLD Index.PHP SQL Injection Vulnerability
       96. GNU Image Manipulation Program Multiple Integer Overflow Vulne=
rabilities
       97. Aigaion Index.PHP SQL Injection Vulnerability
       98. Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control Denial =
of Service Vulnerability
       99. Media Player Classic .FLV Remote Denial Of Service Vulnerabili=
ty
       100. Mozilla Firefox WYCIWYG:// URI Cache Zone Bypass Vulnerabilit=
y
III.  SECURITYFOCUS NEWS
       1. Fast flux foils bot-net takedown
       2. Lawmakers worry over gov't network breaches
       3. Amero case spawns effort to educate
       4. Group: Anti-hacking laws can hobble Net security
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Application Security Architect, Noida
       2. [SJ-JOB] Security System Administrator, Denver
       3. [SJ-JOB] Management, Cupertino
       4. [SJ-JOB] Security Engineer, Rockville
       5. [SJ-JOB] Quality Assurance, Columbia
       6. [SJ-JOB] Sr. Security Engineer, Cupertino
       7. [SJ-JOB] Manager, Information Security, Cincinnati
       8. [SJ-JOB] Security Engineer, San Francisco
       9. [SJ-JOB] Security Engineer, Columbia
       10. [SJ-JOB] Sr. Security Engineer, Wilmington
       11. [SJ-JOB] Management, Mountain View
       12. [SJ-JOB] Security Researcher, Houston
       13. [SJ-JOB] Manager, Information Security, Cincinnati
       14. [SJ-JOB] Management, Milwaukee
       15. [SJ-JOB] Security Architect, Melville LI
       16. [SJ-JOB] Auditor, Multiple Locations
       17. [SJ-JOB] Sales Engineer, Reston
       18. [SJ-JOB] Security Architect, Virtual
       19. [SJ-JOB] Security Engineer, New York
       20. [SJ-JOB] Manager, Information Security, Skokie
       21. [SJ-JOB] Information Assurance Engineer, DC/Metro Area
       22. [SJ-JOB] Security Architect, Cincinnati
       23. [SJ-JOB] Principal Software Engineer, Noida
       24. [SJ-JOB] Security Architect, Wilmington
       25. [SJ-JOB] Application Security Engineer, Cincinnati
       26. [SJ-JOB] Security Engineer, Schaumburg
       27. [SJ-JOB] Forensics Engineer, Cupertino
       28. [SJ-JOB] Jr. Security Analyst, Ramstein
       29. [SJ-JOB] Security Engineer, Cupertino
       30. [SJ-JOB] Manager, Information Security, New York
       31. [SJ-JOB] Security Architect, Leatherhead & Europe
       32. [SJ-JOB] Security Architect, Cheltenham, Gloucs
       33. [SJ-JOB] Sr. Security Engineer, New York City
       34. [SJ-JOB] VP of Marketing, Cleveland
       35. [SJ-JOB] Manager, Information Security, Skokie
       36. [SJ-JOB] Security Architect, Surrey & Berkshire
       37. [SJ-JOB] Developer, London
       38. [SJ-JOB] Sr. Security Analyst, Reston
       39. [SJ-JOB] Security Consultant, Chicago
       40. [SJ-JOB] Sr. Security Analyst, Leatherhead (Surrey) & Reading =
(Berks)
       41. [SJ-JOB] Technology Risk Consultant, Bay Area
       42. [SJ-JOB] Threat Analyst, Fort Lauderdale
       43. [SJ-JOB] Security Consultant, St. Louis
       44. [SJ-JOB] Security Architect, Leatherhead (Surrey) & Reading (B=
erks)
       45. [SJ-JOB] Sr. Security Analyst, Olympia
       46. [SJ-JOB] Manager, Information Security, Fort Meade
       47. [SJ-JOB] Security Director, Cleveland
       48. [SJ-JOB] Security Consultant, Leatherhead, Surrey
       49. [SJ-JOB] Channel / Business Development, London
       50. [SJ-JOB] Threat Analyst, Warren
       51. [SJ-JOB] Director, Information Security, San Diego
       52. [SJ-JOB] Sales Engineer, New York
       53. [SJ-JOB] Auditor, Columbia
       54. [SJ-JOB] Sales Representative, London
       55. [SJ-JOB] Forensics Engineer, Birmingham
       56. [SJ-JOB] Security Engineer, San Diego
       57. [SJ-JOB] Technical Support Engineer, Leatherhead, Surrey & Eur=
ope
       58. [SJ-JOB] Principal Software Engineer, Columbia
       59. [SJ-JOB] Sr. Security Engineer, Elgin
       60. [SJ-JOB] Auditor, Chicago
       61. [SJ-JOB] Auditor, Hartford
       62. [SJ-JOB] Forensics Engineer, Manchester
       63. [SJ-JOB] Information Assurance Analyst, Baltimore
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. USB device control software
       2. SecurityFocus Microsoft Newsletter #349
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Achtung! New German Laws on Cybercrime
By Federico Biancuzzi
Germany is passing some new laws regarding cybercrime that might affect s=
ecurity professionals. Federico Biancuzzi interviewed Marco Gercke, one o=
f the experts that was invited to the parliamentary hearing, to learn mor=
e about this delicate subject. They discussed what is covered by the new =
laws, which areas remain in the dark, and how they might affect vulnerabi=
lity disclosure and the use of common tools, such as nmap.
http://www.securityfocus.com/columnists/448

2. Don't Be Evil
By Mark Rasch
A series of developments raise the specter that remotely stored or create=
d documents may be subject to subpoena or discovery all without the knowl=
edge or consent of the document's creators.
http://www.securityfocus.com/columnists/447


II.  BUGTRAQ SUMMARY
--------------------
1. SquirrelMail G/PGP Encryption Plug-in Multiple Unspecified Remote Comm=
and Execution Vulnerabilities
BugTraq ID: 24828
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24828
Summary:
Vulnerabilities in the SquirrelMail G/PGP encryption plugin may allow mal=
icious webmail users to execute system commands remotely. These issues oc=
cur because the application fails to sufficiently sanitize user-supplied =
data.

Commands would run in the context of the webserver hosting the vulnerable=
 software.

Reports indicate that these vulnerabilities reside in SquirrelMail G/PGP =
2.0 and 2.1 and that the vendor is aware of the issues. This has not been=
 confirmed.

No further technical details are currently available. We will update this=
 BID as more information emerges.

2. HP TCP/IP Services for OpenVMS User Enumeration Weakness and Security =
Bypass Vulnerabilities
BugTraq ID: 24751
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24751
Summary:
HP TCP/IP Services for OpenVMS is prone to a user-enumeration weakness an=
d a security-bypass vulnerability.

An attacker can exploit these issues to enumerate valid usernames and to =
launch brute-force attacks.

 These issues affect the POP3 service included in TCP/IP 5.6 for OpenVMS;=
 other versions may also be affected. The POP3 service is not enabled by =
default.

3. GameSiteScript Index.PHP SQL Injection Vulnerability
BugTraq ID: 24807
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24807
Summary:
GameSiteScript is prone to an SQL-injection vulnerability because the app=
lication fails to properly sanitize user-supplied input before using it i=
n an SQL query.=20
=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.

GameSiteScript 3.1 and prior versions are vulnerable to this issue.

4. Lhaca File Archiver Unspecified Stack Buffer Overflow Vulnerability
BugTraq ID: 24604
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24604
Summary:
Lhaca file archiver is prone to an unspecified stack-based buffer-overflo=
w vulnerability. The application fails to properly decompress malicious L=
ZH archive files.

An attacker can exploit this issue to crash the application and execute a=
rbitrary code within the context of the affected application.=20

Lhaca 1.20 is vulnerable to this issue; other versions may also be affect=
ed.

5. Nonnoi ASP/Barcode COM Component NONNOI_ASPBarcode.DLL Arbitrary File =
Overwrite Vulnerability
BugTraq ID: 24822
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24822
Summary:
Nonnoi ASP/Barcode ActiveX control is prone to a vulnerability that lets =
attackers overwrite arbitrary files on the victim's computer in the conte=
xt of the vulnerable application using the ActiveX control (typically Int=
ernet Explorer).

This issue affects Nonnoi ASP/Barcode 2.20; other versions may also be af=
fected.

6.  Symantec Norton Ghost RemoteCommand.DLL Buffer Overflow Vulnerability
BugTraq ID: 24825
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24825
Summary:
Symantec Norton Ghost is prone to a buffer-overflow vulnerability because=
 the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20

This issue affects Symantec Ghost 12.0; other versions may also be affect=
ed.

7. Yb Ve Bayi Babvuru Formu Multiple HTML Injection Vulnerabilities
BugTraq ID: 24812
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24812
Summary:
=C3=9Db Ve Bayi Babvuru Formu is prone to multiple HTML-injection vulnera=
bilities because it fails to sufficiently sanitize user-supplied input da=
ta.

Exploiting these issues may allow an attacker to execute HTML and script =
code in the context of the affected site, to steal cookie-based authentic=
ation credentials, or to control how the site is rendered to the user; ot=
her attacks are also possible.

8. Computer Associates ERwin Data Model Validator Multiple Denial Of Serv=
ice Vulnerabilities
BugTraq ID: 24814
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24814
Summary:
Computer Associates ERwin Data Model Validator is prone to multiple denia=
l-of-service vulnerabilities because the software fails to handle special=
ly crafted '.EXP' database files. These issues include a NULL-pointer der=
eference vulnerability and a denial-of-service vulnerability.

An attacker can exploit these issues to cause a denial-of-service conditi=
on. Arbitrary code execution may be possible for the NULL-pointer derefer=
ence issue, but this has not been confirmed.

9. Mozilla Firefox Multiple Popup Tabs Denial of Service Vulnerability
BugTraq ID: 24820
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24820
Summary:
Firefox is prone to a remote denial-of-service vulnerability.=20

An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted HTML document.

Successful exploits can allow attackers to crash the affected browser, re=
sulting in denial-of-service conditions.=20
=20
Firefox 2.0.0.4 is vulnerable to this issue; other versions may also be a=
ffected.

10. Linux Kernel SCTP Connection Denial Of Service Vulnerability
BugTraq ID: 24376
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24376
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.

Linux kernel versions prior to 2.6.21.4 are vulnerable to this issue.

This BID initially discussed three weaknesses/vulnerabilities in the Linu=
x kernel. These issues have been separated into the following individual =
records:

24389 Linux Kernel CPUSet Tasks Memory Leak Information Disclosure Vulner=
ability
24390 Linux Kernel PRNG Entropy Weakness
24376 Linux Kernel SCTP Connection Denial Of Service Vulnerability

11. Linux Kernel Decode_Choices Function Remote Denial Of Service Vulnera=
bility
BugTraq ID: 24818
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24818
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability bec=
ause it fails to handle certain H.323 data.

Attackers can exploit this issue to crash the affected operating system, =
denying access to legitimate users.

Versions prior to 2.6.21.6, 2.6.20.15, and 2.6.22 are vulnerable.

12. Microsoft Windows Vista Kernel Unspecified Remote Denial Of Service V=
ulnerability
BugTraq ID: 24816
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24816
Summary:
Microsoft Windows Vista is prone to an unspecified remote denial-of-servi=
ce vulnerability.

Attackers may exploit this issue to crash the affected operating system, =
denying further service to legitimate users. Remote code-execution may be=
 possible, but this has not been confirmed.

13. Linux Kernel IPV6_SockGlue.c NULL Pointer Dereference Vulnerability
BugTraq ID: 23142
Remote: No
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/23142
Summary:
The Linux kernel is prone to a NULL-pointer dereference vulnerability.

A local attacker can exploit this issue to crash the affected application=
, denying service to legitimate users. The attacker may also be able to e=
xecute arbitrary code with elevated privileges, but this has not been con=
firmed.

14. VLC Media Player Multiple Format String Vulnerabilities
BugTraq ID: 24555
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24555
Summary:
VLC media player is affected by multiple format-string vulnerabilities.=20

Exploiting these issues can allow remote attackers to execute arbitrary c=
ode in the context of the application.=20

Versions prior to VLC media player 0.8.6c are affected.

15. SAP Message Server Group Parameter Remote Buffer Overflow Vulnerabili=
ty
BugTraq ID: 24765
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24765
Summary:
SAP Message Server is prone to a remote heap-based buffer-overflow vulner=
ability because the application fails to perform adequate boundary checks=
 on user-supplied data before copying it to an insufficiently sized buffe=
r.

Remote attackers can exploit this issue to execute arbitrary code with SY=
STEM-level privileges. Successful attacks will result in a complete  comp=
romise of affected computers.  Failed attacks will likely result in  deni=
al-of-service conditions that disable all functionality of the applicatio=
n.

16. Apple Safari Cross-Domain Race Condition Information Disclosure Vulne=
rability
BugTraq ID: 24599
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24599
Summary:
Apple Safari is prone to an information-disclosure vulnerability because =
it fails to properly enforce cross-domain JavaScript restrictions.

Exploiting this issue may allow attackers to access locations that a user=
 visits, even if those locations are in a different domain than the attac=
ker's site. The most common manifestation of this condition would typical=
ly be in blogs or forums. Attackers may be able to access potentially sen=
sitive information that would aid in phishing attacks.

This issue affects versions prior to Safari 3 Beta Update 3.0.2

17. Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability
BugTraq ID: 22791
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/22791
Summary:
Apache Tomcat is prone to a vulnerability that will allow remote attacker=
s to execute arbitrary code on an affected computer. A successful attack =
may result in a complete compromise.

18. Computer Associates BrightStor ARCserve Backup MediaSVR.EXE 191 Buffe=
r Overflow Vulnerability
BugTraq ID: 23209
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/23209
Summary:
Computer Associates BrightStor ARCserve Backup is affected by a remote bu=
ffer-overflow vulnerability because the application fails to perform prop=
er bounds-checking on data supplied to the application.=20
=20
A remote attacker may exploit this issue to execute arbitrary code on a v=
ulnerable computer with SYSTEM privileges. Failed exploit attempts may ca=
use denial-of-service conditions.

19. McAfee NeoTrace ActiveX Control Remote Buffer Overflow Vulnerability
BugTraq ID: 21697
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/21697
Summary:
The NeoTraceExplorer.NeoTraceLoader ActiveX control shipped with NeoTrace=
 is prone to a buffer-overflow vulnerability. The software fails to perfo=
rm sufficient bounds-checking of user-supplied input before copying it to=
 an insufficiently sized memory buffer.

NeoTrace Express 3.25 and NeoTrace Professional 3.25 are vulnerable to th=
is issue.

20. PHP 5 User-Supplied Session ID Input Validation Vulnerability
BugTraq ID: 16220
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/16220
Summary:
PHP 5 is prone to an input-validation vulnerability. This is due to a lac=
k of proper sanitization of user-supplied input of PHP session IDs, trans=
mitted by way of HTTP headers.=20

An attacker may use this vulnerability to perform HTTP response splitting=
, often resulting in content spoofing and cross-site scripting attacks.=20

PHP 5.1.1 and prior versions are affected.

21. PHPPost Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15524
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/15524
Summary:
PHP-Post is prone to multiple cross-site scripting vulnerabilities becaus=
e the application fails to properly sanitize user-supplied input.
=20
An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
  The attacker may also be able to steal cookie-based authentication cred=
entials and launch other attacks.

22. PHP Multiple Input Validation Vulnerabilities
BugTraq ID: 19582
Remote: No
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/19582
Summary:
PHP is prone to multiple input-validation vulnerabilities. Successful exp=
loits could allow an attacker to write files in unauthorized locations, c=
ause a denial-of-service condition, and potentially execute code.

These issues are reported to affect PHP versions 4.4.3 and 5.1.4; other v=
ersions may also be vulnerable.

23. PHP Prior to 5.2.2/4.4.7 Multiple Remote Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 23813
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/23813
Summary:
PHP is prone to three remote buffer-overflow vulnerabilities because the =
application fails to perform boundary checks before copying user-supplied=
 data to insufficiently sized memory buffers.

An attacker can exploit these issues to execute arbitrary machine code in=
 the context of the affected webserver. Failed exploit attempts will like=
ly crash the webserver, denying service to legitimate users.=20

All three issues affect PHP 5.2.1 and prior versions; PHP 4.4.6 and prior=
 versions are affected only by one of the issues.

Few details are available at the moment. These issues may have been previ=
ously described in other BIDs. This record may be updated or retired if f=
urther analysis shows that these issues have been reported in the past.

24. PHP Zip URL Wrapper Stack Buffer Overflow Vulnerability
BugTraq ID: 22883
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/22883
Summary:
PHP is prone to a remote stack-based buffer-overflow vulnerability becaus=
e the application fails to properly bounds-check user-supplied input befo=
re copying it to an insufficiently sized memory buffer.

Exploiting this issue may allow attackers to execute arbitrary machine co=
de in the context of the affected application. Failed exploit attempts wi=
ll likely result in a denial-of-service condition.

This issue affects PHP 5.2.0 and PHP with PECL ZIP <=3D 1.8.3.

25. Linux Kernel IPv6 TCP Sockets Local Denial of Service Vulnerability
BugTraq ID: 23104
Remote: No
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/23104
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.

Exploiting this issue allows local attackers to cause the kernel to crash=
, effectively denying service to legitimate users. Attackers may also be =
able to execute arbitrary code with elevated privileges, but this has not=
 been confirmed.

This issue affects the Linux kernel 2.6 series.

26. Linux Kernel AppleTalk ATalk_Sum_SKB Function Denial Of Service Vulne=
rability
BugTraq ID: 23376
Remote: Yes
Last Updated: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/23376
Summary:
The Linux kernel is prone to a denial-of-service vulnerability. This issu=
e presents itself when malformed AppleTalk frames are processed.

An attacker can exploit this issue to crash host computers, effectively d=
enying service to legitimate users.

Versions prior to 2.6.20.5 are vulnerable.

27. Microsoft Windows Active Directory LDAP Request Validation Remote Cod=
e Execution Vulnerability
BugTraq ID: 24800
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24800
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability becau=
se Microsoft Active Directory fails to handle specially crafted user-supp=
lied Lightweight Directory Access Protocol (LDAP) requests.=20

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

28. Symantec Veritas Backup Exec for Windows Server Unspecified Heap Buff=
er Overflow Vulnerability
BugTraq ID: 23897
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23897
Summary:
Symantec Veritas Backup Exec for Windows Server is prone to a heap-based =
buffer-overflow vulnerability because the application fails to bounds-che=
ck user-supplied data before copying it into an insufficiently sized buff=
er.=20

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

29. Sun Java Runtime Environment WebStart JNLP File Stack Buffer Overflw =
Vulnerability
BugTraq ID: 24832
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24832
Summary:
Sun Java Runtime Environment is prone to a stack-based buffer-overflow vu=
lnerability because it fails to adequately bounds-check user-supplied inp=
ut before copying it to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will likely result in a denial-of-service condition.

This issue affects these versions:

Java Runtime Environment 6 update 1
Java Runtime Environment 5 update 11

Prior versions are also affected.

30. Entertainment CMS AdminLogged Cookie Parameter Authentication Bypass =
Vulnerability
BugTraq ID: 24847
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24847
Summary:
Entertainment CMS is prone to an authentication-bypass vulnerability beca=
use the application fails to sufficiently sanitize user-supplied input.=20

An attacker can exploit this issue to gain administrative access to the a=
ffected application.

31. TippingPoint IPS Fragmented Packets Detection Bypass Vulnerability
BugTraq ID: 24861
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24861
Summary:
TippingPoint IPS is prone to a detection-bypass vulnerability because the=
 appliance fails to properly handle fragmented packets.

A successful exploit of this issue may allow an attacker to bypass the fi=
lter and detection system of vulnerable appliances, allowing malicious tr=
affic through. This will likely aid the attacker in further attacks.

32. X.Org X11 XC-MISC Extension Local Integer Overflow Vulnerability
BugTraq ID: 23284
Remote: No
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23284
Summary:
X11 is prone to a local integer-overflow vulnerability because it fails t=
o adequately bounds-check user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary code with=
 superuser privileges. Failed exploit attempts will likely cause denial-o=
f-service conditions.

33. Wireshark Multiple Protocol Denial of Service Vulnerabilities
BugTraq ID: 24662
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24662
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues may permit attackers to cause crashes and deny se=
rvice to legitimate users of the application.

Versions prior to Wireshark 0.99.6 are affected.

34. X.Org LibXFont Multiple Local Integer Overflow Vulnerabilities
BugTraq ID: 23283
Remote: No
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23283
Summary:
The 'libXfont' library is prone to multiple local integer-overflow vulner=
abilities because it fails to adequately bounds-check user-supplied data.

An attacker can exploit these vulnerabilities to execute arbitrary code w=
ith superuser privileges. Failed exploit attempts will likely cause denia=
l-of-service conditions.

These issues affect libXfont 1.2.2; other versions may also be vulnerable=
.

35. Microsoft Internet Explorer FirefoxURL Protocol Handler Command Injec=
tion Vulnerability
BugTraq ID: 24837
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24837
Summary:
Microsoft Internet Explorer is prone to a vulnerability that lets attacke=
rs inject commands through the 'FirefoxURL' protocol handler.

Exploiting the issue allows remote attackers to pass and execute arbitrar=
y commands and arguments through the 'firefox.exe' process by employing t=
he 'FirefoxURL' handler.

An attacker can also employ this issue to carry out cross-browser scripti=
ng attacks by using the '-chrome' argument. This can allow the attacker t=
o run JavaScript code with the privileges of trusted Chrome context and g=
ain full access to Firefox's resources.

Exploiting the issue would permit remote attackers to influence command o=
ptions that can be called through the 'FirefoxURL' handler and therefore =
execute commands and script code with the privileges of a user running th=
e applications. Successful attacks may result in a variety of consequence=
s, including remote unauthorized access.

36. Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerabilit=
y
BugTraq ID: 24779
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24779
Summary:
Windows Firewall for Windows Vista is prone to a vulnerability that may p=
ermit a bypass of existing firewall rules.

An attacker may trigger this vulnerability by sending malicious network d=
ata through the Teredo network transport system to obtain sensitive infor=
mation; other attacks are also possible.

Note that Windows Vista systems configured with a 'Public' network profil=
e are not vulnerable to this issue.

37. OpenOffice RTF File Parser Buffer Overflow Vulnerability
BugTraq ID: 24450
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24450
Summary:
OpenOffice is prone to a remote heap-based buffer-overflow vulnerability =
because the application fails to bounds-check user-supplied data before c=
opying it into an insufficiently sized buffer.

Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted RTF files.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.

38. Sun Java System Access Manager Logging Output Password Disclosure Vul=
nerability
BugTraq ID: 24859
Remote: No
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24859
Summary:
Sun Java System Access Manager may allow local attackers to access user p=
asswords.
=20
By exploiting this issue, attackers may subsequently gain unauthorized ac=
cess to user identities that are managed by Java System Access Manager.

39. Sun Java System Server XSLT Processing Remote Java Method Execution V=
ulnerability
BugTraq ID: 24850
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24850
Summary:
Sun Java System Web Servers and Application Servers are prone to a vulner=
ability that lets attackers execute arbitrary Java methods. This issue oc=
curs because the application fails to securely process XSLT stylesheets.

Successfully exploiting this issue may allow remote attackers to execute =
arbitrary Java methods, aiding them in further attacks.

Sun Java System Web Server 7.0 for the following operating systems is aff=
ected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
- HP-UX

Sun Java System Application Server Platform and Enterprise Editions 8.2 a=
nd Platform Edition 9.0 for the following operating systems are also affe=
cted:
- Sun Solaris SPARC and x86 platforms
 - Linux
 - Microsoft Windows

40. Microsoft Office Publisher Invalid Memory Reference Remote Code Execu=
tion Vulnerability
BugTraq ID: 22702
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/22702
Summary:
Microsoft Office Publisher is prone to a remote code-execution vulnerabil=
ity.

An attacker can exploit this issue by enticing an unsuspecting victim to =
open a maliciously crafted Publisher file.=20

Successful exploits may allow attackers to execute arbitrary code with pr=
ivileges of the user running the application. This may facilitate a compr=
omise of vulnerable computers.

41. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 24854
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24854
Summary:
Centericq is prone to multiple remote buffer-overflow vulnerabilities bec=
ause the application fails to properly bounds-check user-supplied input b=
efore copying it to an insufficiently sized memory buffer

An attacker can exploit these issues to execute arbitrary code within the=
 context of the affected application. Failed exploit attempts will result=
 in a denial of service.

42. Adobe Photoshop Multiple File Format Buffer Overflow Vulnerability
BugTraq ID: 23621
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23621
Summary:
Adobe Photoshop is prone to a buffer-overflow  vulnerability because the =
application fails to bounds-check user-supplied data before copying it in=
to an insufficiently sized buffer.=20

An attacker could exploit this issue by enticing a victim to load a malic=
ious file. If successful, the attacker can execute arbitrary code in the =
context of the affected application.

This issue affects Photoshop CS2 and CS3.

43. Multiple Image Editing Applications .PNG Format Handling Remote Buffe=
r Overflow Vulnerability
BugTraq ID: 23698
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23698
Summary:
Multiple image editors are prone to a remote buffer-overflow vulnerabilit=
y because the software fails to properly bounds-check user-supplied input=
 before copying it to an insufficiently sized memory buffer.

Successful exploits allow remote attackers to execute arbitrary machine c=
ode in the context of a vulnerable application. Failed exploit attempts l=
ikely result in denial-of-service conditions.

The following are vulnerable:

Adobe Photoshop CS2, CS3, and Elements 5.0
Corel Paint Shop Pro 11.20=20

Other versions may also be affected.

44. Opera Web Browser Running Adobe Flash Player Information Disclosure V=
ulnerability
BugTraq ID: 23437
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23437
Summary:
Opera Web Browser is prone to an information-disclosure vulnerability whe=
n running Adobe Flash Player.

An attacker can exploit this issue to access potentially sensitive inform=
ation.

These versions are vulnerable:

Opera Web Browser prior to 9.20 for Linux, Solaris, and FreeBSD
Adobe Flash Player prior to 9.0.28.0

This issue also affects the Konqueror browser.

45. Adobe Flash Player SWF File Handling Remote Code Execution Vulnerabil=
ity
BugTraq ID: 24856
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24856
Summary:
Adobe Flash Player is prone to a remote code-execution vulnerability beca=
use it fails to properly sanitize user-supplied input.=20

An attacker can exploit this issue by tricking an unsuspecting victim int=
o opening a malicious file.

A successful exploit will result in the execution of arbitrary attacker-s=
upplied code in the context of the victim running the vulnerable applicat=
ion.

Adobe Flash Player 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69=
.0 and earlier are affected.

46. Linux Kernel IPV6_Getsockopt_Sticky Memory Leak Information Disclosur=
e Vulnerability
BugTraq ID: 22904
Remote: No
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/22904
Summary:
Linux Kernel is prone to an information-disclosure vulnerability because =
it fails to handle unexpected user-supplied input.

Successful exploits will allow attackers to obtain portions of kernel mem=
ory. Information harvested may be used in further attacks.

Kernel versions 2.6.0 up to 2.6.20.1 are vulnerable to this issue.

47. Mike's World Mail Machine Mailmachine.CGI Local File Include Vulnerab=
ility
BugTraq ID: 24852
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24852
Summary:
Mike's World Mail Machine is prone to a local file-include vulnerability =
because it fails to properly sanitize user-supplied input.

Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.

48. EVisit Analyst ID Parameter Multiple SQL Injection Vulnerabilities
BugTraq ID: 24849
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24849
Summary:
eVisit Analyst is prone to multiple SQL-injection vulnerabilities because=
 it fails to sufficiently sanitize user-supplied data before using it in =
an SQL query.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

49. Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability
BugTraq ID: 24846
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24846
Summary:
The Sun JSSE (Java Secure Socket Extension) is prone to a denial-of-servi=
ce vulnerability.

An attacker can exploit this issue to crash the computer, denying access =
to legitimate users.

50. TippingPoint IPS Unicode Character Detection Bypass Vulnerability
BugTraq ID: 24855
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24855
Summary:
TippingPoint IPS is prone to a detection-bypass vulnerability because the=
 appliance fails to properly handle Unicode characters.

A successful exploit of this issue may allow an attacker to bypass the fi=
lter and detection system of vulnerable appliances, allowing malicious UR=
I traffic through. This will likely aid the attacker in further attacks.

51. Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
BugTraq ID: 24791
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24791
Summary:
Microsoft .NET Framework is prone to multiple NULL-byte injection vulnera=
bilities because it fails to adequately sanitize user-supplied data.

An attacker can exploit these issues to access sensitive information that=
 may aid in further attacks; other attacks are also possible.

52. ImgSvr Template Parameter Local File Include Vulnerability
BugTraq ID: 24853
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24853
Summary:
ImgSvr is prone to a local file-include vulnerability because it fails to=
 sanitize user-supplied  input.=20

Attackers may exploit this issue to access files that may contain sensiti=
ve information.

53. RCP Shell Utility Arbitrary Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
The RCP shell utility is prone to an arbitrary command-execution vulnerab=
ility because the application fails to properly sanitize user-supplied in=
put before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the =
privileges of users executing a vulnerable version of RCP.

 NOTE: OpenSSH SCP is a fork of RCP and is known to also be affected by t=
his issue.

54. Windows Media Player Remote ASF File Buffer Overflow Vulnerability
BugTraq ID: 21505
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/21505
Summary:
Windows Media Player is prone to a buffer-overflow vulnerability because =
the application fails to properly bounds-check user-supplied data.

Attackers may attempt to exploit this issue by coercing users to visit a =
malicious website or to access malicious ASF files.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the user running the affected appli=
cation. This facilitates the remote compromise of affected computers.

55. Windows Media Player ASX PlayList File Heap Overflow Vulnerability
BugTraq ID: 21247
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/21247
Summary:
Windows Media Player is prone to a heap-overflow issue.=20

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.

56. SquirrelMail G/PGP Encryption Plug-in Unspecified Remote Command Exec=
ution Vulnerability
BugTraq ID: 24782
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24782
Summary:
A vulnerability in the SquirrelMail G/PGP encryption plugin may allow mal=
icious webmail users to execute system commands remotely. The issue occur=
s because the application fails to sufficiently sanitize user data.

Commands would run in the context of the webserver hosting the vulnerable=
 software. This issue may be exploited by sending email to a user utilizi=
ng the affected plugin. When the plugin attempts to process the email, th=
e malicious code will be executed, making successful exploits easier for =
attackers to attempt.

Reports indicate that this issue has been tested with SquirrelMail 1.4.10=
a and G/PGP Plugin 2.0. Other versions may be affected as well.

57. Zenturi ProgramChecker ActiveX Control Fill Method Stack Based Buffer=
 Overflow Vulnerability
BugTraq ID: 24848
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24848
Summary:
Zenturi ProgramChecker ActiveX control is prone to a stack-based buffer-o=
verflow vulnerability because the application fails to bounds-check user-=
supplied data before copying it into an insufficiently sized buffer.=20

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.

ProgramChecker 1.5.0.531 is vulnerable; other versions may also be affect=
ed.

58. Apple Safari for Windows SVG Parse Engine Multiple Unspecified Vulner=
abilities
BugTraq ID: 24446
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24446
Summary:
Apple Safari for Microsoft Windows is prone to multiple unspecified vulne=
rabilities.

Few technical details are currently available. We will update this BID as=
 more information emerges.

Safari 3 public beta for Windows is reported vulnerable.

59. IBM Proventia Sensor Appliance Multiple Input Validation Vulnerabilit=
ies
BugTraq ID: 24864
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24864
Summary:
The IBM Proventia Sensor Appliance is prone to multiple input-validation =
vulnerabilities, including multiple remote file-include issues and a cros=
s-site scripting issue.=20

An attacker can exploit these issues to steal cookie-based authentication=
 credentials, view files, and to execute arbitrary server-side script cod=
e on an affected device in the context of the webserver process. Other at=
tacks are also possible.

IBM Proventia Sensor Appliance CX5108 and GX5008 are vulnerable.

60. McAfee Common Management Agent (CMA) Multiple Memory Corruption Vulne=
rabilities
BugTraq ID: 24863
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24863
Summary:
McAfee Common Management Agent is prone to mutiple memory-corruption vuln=
erabilities. The application fails to properly bounds-check user-supplied=
 data in several instances before copying it into insufficiently sized me=
mory buffers.=20

A remote attacker may exploit these issues to execute arbitrary code on a=
 vulnerable computer with SYSTEM privileges. Failed exploit attempts may =
result in denial-of-service conditions.

Various versions of CMA are affected by these issues. CMA is also include=
d with ePolicy Orchestrator and ProtectionPilot.

61. EnViVo!CMS Default.ASP ID Parameter SQL Injection Vulnerability
BugTraq ID: 24860
Remote: Yes
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24860
Summary:
enVivo!CMS is prone to an SQL-injection vulnerability because the applica=
tion fails to properly sanitize user-supplied input before using it in an=
 SQL query.=20

A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.

All versions are considered to be vulnerable to this issue.

62. Symantec Client Security Internet E-mail Auto-Protect Stack Overflow =
Vulnerability
BugTraq ID: 24802
Remote: No
Last Updated: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24802
Summary:
Symantec Client Security is prone to a stack buffer-overflow vulnerabilit=
y. This issue occurs because the application fails to properly bounds-che=
ck user-supplied data before copying it into an insufficiently sized memo=
ry buffer.

An attacker can exploit this issue to cause denial-of-service conditions.

63. Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabil=
ities
BugTraq ID: 24771
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24771
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing six security bulletins on July 10, 2007. The highest severity rating=
 for these issues is 'Critical'.

Further details about these issues are not currently available. Individua=
l BIDs will be created for each issue; this record will be removed when t=
he security bulletins are released.

These vulnerabilities have been assigned to the following BIDs:
24800 Microsoft Windows Active Directory LDAP Request Validation Remote C=
ode Execution Vulnerability
24796 Microsoft Windows Active Directory LDAP Request Validation Remote D=
enial Of Service Vulnerability
24778 Microsoft .NET Framework PE Loader Remote Buffer Overflow Vulnerabi=
lity
24791 Microsoft .Net Framework Null Byte Injection Vulnerability
24811 Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulner=
ability
20753 Microsoft .NET Framework Request Filtering Bypass Vulnerability
24779 Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerabil=
ity
24801 Microsoft Excel Version Information Validation Remote Code Executio=
n Vulnerability
22555 Microsoft Excel Worksheet Remote Code Execution Vulnerability
24803 Microsoft Excel Workspace Designation Remote Code Execution Vulnera=
bility
24843 Microsoft Excel Unspecified Security Vulnerability
22702 Microsoft Office Publisher Invalid Memory Reference Remote Code Exe=
cution Vulnerability
15921 Microsoft Internet Information Server 5.1 DLL Request Remote Code E=
xecution Vulnerability

64. AlstraSoft Video Share Enterprise Multiple Remote Vulnerabilities
BugTraq ID: 23409
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23409
Summary:
AlstraSoft Video Share Enterprise is prone to multiple remote vulnerabili=
ties, including an unauthorized-access issue and an SQL-injection issue.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data or user profiles, or exploit latent vulnerabi=
lities in the underlying database implementation.

This issue affects Video Share Enterprise 4.3 and prior versions.

65. SAP DB Web Server WAHTTP.EXE Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 24773
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24773
Summary:
SAP DB Web Server is prone to multiple buffer-overflow vulnerabilities be=
cause it fails to adequately bounds-check user-supplied input before copy=
ing it to an insufficiently sized buffer.

Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code with SYSTEM-level privileges. Failed exploit attempts will r=
esult in a denial-of-service condition.

66. Microsoft .NET Framework PE Loader Remote Buffer Overflow Vulnerabili=
ty
BugTraq ID: 24778
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24778
Summary:
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
data.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user running the application. Successful exploits can result in t=
he complete compromise of affected computers. Failed attacks will likely =
result in denial-of-service conditions.

67. Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerab=
ility
BugTraq ID: 24811
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24811
Summary:
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
data.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user running the application. Successful exploits can result in t=
he complete compromise of affected computers. Failed attacks will likely =
result in denial-of-service conditions.

68. FlashBB Sendmsg.PHP Remote File Include Vulnerability
BugTraq ID: 24842
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24842
Summary:
FlashBB is prone to a remote file-include vulnerability because it fails =
to properly sanitize user-supplied input to the application.

An attacker may leverage this issue to execute an arbitrary remote file c=
ontaining malicious script code in the context of the webserver process. =
This may allow the attacker to compromise the application and the underly=
ing system. Other attacks are also possible.

FlashBB 1.1.7 is vulnerable; other versions may also be affected.

69. Microsoft Excel Workspace Designation Remote Code Execution Vulnerabi=
lity
BugTraq ID: 24803
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24803
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file (.xls).

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

70. Microsoft Excel Worksheet Remote Code Execution Vulnerability
BugTraq ID: 22555
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/22555
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file (.xls).

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

This issue was previously reported as a denial-of-service vulnerability, =
but has been updated to reflect new information.

71. Microsoft .NET Framework Request Filtering Bypass Vulnerability
BugTraq ID: 20753
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/20753
Summary:
Microsoft .NET framework is prone to a vulnerability that may permit an a=
ttacker to bypass content filtering.=20

The attacker can exploit this issue to perform multiple input-validation =
attacks such as cross-site scripting, SQL-injection, and HTML-injection; =
other attacks are also possible.

72. Microsoft Internet Information Server 5.1 DLL Request Remote Code Exe=
cution Vulnerability
BugTraq ID: 15921
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/15921
Summary:
Microsoft IIS is prone to a remote code-execution vulnerability because t=
he application fails to properly bounds-check user-supplied data before c=
opying it to an insufficiently sized memory buffer.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the vulnerable application, which may lead =
to the complete compromise of affected computers.

This issue affects Microsoft IIS 5.1 running on Windows XP SP2.

Note: this issue was previously reported as a denial-of-service vulnerabi=
lity. New information from the vendor states that code execution is possi=
ble.

73. Microsoft Excel Version Information Validation Remote Code Execution =
Vulnerability
BugTraq ID: 24801
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24801
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

74. Microsoft Windows Active Directory LDAP Request Validation Remote Den=
ial Of Service Vulnerability
BugTraq ID: 24796
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24796
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause Microsoft Active Directory fails to handle specially crafted Lightw=
eight Directory Access Protocol (LDAP) requests.=20

An attacker can exploit this issue to cause the affected application to s=
top responding, denying further service to legitimate users.

75. Microsoft Excel Unspecified Security Vulnerability
BugTraq ID: 24843
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24843
Summary:
Microsoft Excel is prone to an unspecified security vulnerability.

Very little information is currently available regarding this issue. We w=
ill update this BID as more information emerges.

76. WinPcap NPF.SYS BIOCGSTATS Parameters Local Privilege Escalation Vuln=
erability
BugTraq ID: 24829
Remote: No
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24829
Summary:
WinPcap is prone to a local privilege-escalation vulnerability.=20

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

WinPcap 4.0 is vulnerable to this issue.

77. Linux PowerPC Kernel Restore_Sigcontext Local Denial of Service Vulne=
rability
BugTraq ID: 24845
Remote: No
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24845
Summary:
The PowerPC Linux kernel is prone to a denial-of-service vulnerability.

Exploiting this issue allows local attackers to corrupt memory resources =
and eventually cause the kernel to crash, effectively denying service to =
legitimate users.

Note that this issue affects only the Linux kernel on PowerPC architectur=
es.

78. Unobtrusive AJAX Star Rating Bar Multiple Input Validation Vulnerabil=
ities
BugTraq ID: 24840
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24840
Summary:
Unobtrusive AJAX Star Rating Bar is prone to input-validation vulnerabili=
ties, including an SQL-injection issue, a security-bypass issue, and a cr=
oss-site scripting issue, because the application fails to sanitize user-=
supplied input.

A successful exploit may allow an attacker to steal cookie-based authenti=
cation credentials, compromise the application, access or modify data, ex=
ploit latent vulnerabilities in the underlying database, and bypass certa=
in security restriction to inject arbitrary HTTP header and body data.

Versions prior to Unobtrusive AJAX Star Rating Bar 1.2.0 are affected.

79. Visual IRC Join Response Buffer Overflow Vulnerability
BugTraq ID: 24798
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24798
Summary:
Visual IRC (ViRC) is prone to a remote buffer-overflow vulnerability beca=
use it fails to perform adequate boundary checks on user-supplied data be=
fore copying it to an insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code in the context=
 of a user running the affected application. Successful attacks will comp=
romise the application. Failed exploits will likely cause denial-of-servi=
ce conditions.

ViRC 2.0 is vulnerable; other versions may also be affected.

80. ImageMagick DCM XWD Formats Multiple Integer Overflow Vulnerabilities
BugTraq ID: 23347
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23347
Summary:
ImageMagick is prone to multiple integer-overflow vulnerabilities because=
 it fails to adequately handle user-supplied data.

An attacker can exploit these issues to execute arbitrary code in the con=
text of the application. Failed exploit attempts will likely cause denial=
-of-service conditions.

ImageMagick 6.2.9 through 6.3.3-4 are vulnerable.

81. ImageMagick XGetPixel/XInitImage Multiple Integer Overflow Vulnerabil=
ities
BugTraq ID: 23300
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23300
Summary:
ImageMagick is prone to multiple integer-overflow vulnerabilities because=
 it fails to properly validate user-supplied data.

An attacker can exploit these issues to execute arbitrary code in the con=
text of the application. Failed exploit attempts will likely cause denial=
-of-service conditions.

82. IBM AIX Libodm ODMPath Stack Overflow Vulnerability
BugTraq ID: 24841
Remote: No
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24841
Summary:
IBM AIX 'libodm' is prone to a local stack-based buffer-overflow vulnerab=
ility.=20

A successful attack may allow arbitrary machine code to run with superuse=
r privileges.

IBM AIX 5.2 and 5.3 are reported affected; other versions may be vulnerab=
le as well.

83. Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Overflow V=
ulnerability
BugTraq ID: 24196
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24196
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.

This issue affects Samba 3.0.25rc3 and prior versions.

84. Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vulnerabili=
ty
BugTraq ID: 24197
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24197
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.

This issue affects Samba 3.0.25rc3 and prior versions.

85. Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vulnerabilit=
y
BugTraq ID: 24198
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24198
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.

This issue affects Samba 3.0.25rc3 and prior versions.

86. Samba SID Names Local Privilege Escalation Vulnerability
BugTraq ID: 23974
Remote: No
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23974
Summary:
Samba is prone to a local privilege-escalation vulnerability due to a log=
ic error in the 'smbd' daemon's internal security stack.

An attacker can exploit this issue to temporarily perform SMB/CIFS operat=
ions with superuser privileges. The attacker may leverage this issue to g=
ain superuser access to the server.

Samba 3.0.23d through 3.0.25pre2 are vulnerable.

87. Samba NDR RPC Request LsarAddPrivilegesToAccount Heap-Based Buffer Ov=
erflow Vulnerability
BugTraq ID: 23973
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23973
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.

This issue affects Samba 3.0.25rc3 and prior versions.

This BID previously documented multiple heap-based buffer-overflow vulner=
abilities affecting Samba. Each issue has been assigned its own individua=
l record. The issues are covered in this BID and the following records:
=20
BID 24195 - Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Bas=
ed Buffer Overflow Vulnerability
BID 24196 - Samba NDR RPC Request NetSetFileSecurity Heap-Based Buffer Ov=
erflow Vulnerability
BID 24197 - Samba NDR RPC Request RFNPCNEX Heap-Based Buffer Overflow Vul=
nerability
BID 24198 - Samba NDR RPC Request DFSEnum Heap-Based Buffer Overflow Vuln=
erability

88. Samba MS-RPC Remote Shell Command Execution Vulnerability
BugTraq ID: 23972
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23972
Summary:
Samba is prone to a vulnerability that allows attackers to execute arbitr=
ary shell commands because the software fails to sanitize user-supplied i=
nput.

An attacker may leverage this issue to execute arbitrary shell commands o=
n an affected computer with the privileges of the application.

This issue affects Samba 3.0.0 to 3.0.25rc3.

89. Samba NDR RPC Request LsarLookupSids/LsarLookupSids2 Heap-Based Buffe=
r Overflow Vulnerability
BugTraq ID: 24195
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24195
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges, facilitating the complete remote compromise of affected co=
mputers. Failed exploit attempts will result in a denial of service.

This issue affects Samba 3.0.25rc3 and prior versions.

90. Inferno Technologies VBulletin RPG Inferno Inferno.PHP SQL Injection =
Vulnerability
BugTraq ID: 24839
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24839
Summary:
Inferno Technologies vBulletin RPG Inferno is prone to an SQL-injection v=
ulnerability because the application fails to properly sanitize user-supp=
lied input before using it in an SQL query.=20

A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.

RPG Inferno 2.4 is vulnerable to this issue.

91. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
BugTraq ID: 24339
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24339
Summary:
MPlayer is prone to multiple buffer-overflow vulnerabilities when it atte=
mpts to process malformed album and category titles. These issues occur b=
ecause the application fails to perform proper bounds-checking on user-su=
pplied data before copying it to an insufficiently sized memory buffer.

An attacker may exploit these issues to execute arbitrary code with the p=
rivileges of the user that activated the vulnerable application. This may=
 facilitate unauthorized access or privilege escalation.

MPlayer 1.0rc1 is vulnerable to these issues; other versions may also be =
affected.

92. File(1) Command File_PrintF Integer Underflow Vulnerability
BugTraq ID: 23021
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/23021
Summary:
The file(1) command is prone to an integer-underflow vulnerability becaus=
e the command fails to adequately handle user-supplied data.

An attacker can leverage this issue to corrupt heap memory and execute ar=
bitrary code with the privileges of a user running the command. A success=
ful attack may result in the compromise of affected computers. Failed att=
empts will likely cause denial-of-service conditions.

Versions prior to 4.20 are vulnerable.

93. File Multiple Denial of Service Vulnerabilities
BugTraq ID: 24146
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24146
Summary:
The 'file' utility is prone to multiple denial-of-service vulnerabilities=
 because it fails to handle exceptional conditions.=20

An attacker could exploit this issue by enticing a victim to open a speci=
ally crafted file. A denial-of-service condition can occur. Arbitrary cod=
e execution may be possible, but Symantec has not confirmed  this.

94. IBM Hardware Management Console Unspecified Vulnerability
BugTraq ID: 24844
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24844
Summary:
IBM Hardware Management Console is prone to an unspecified vulnerability.

Currently, very little is known about this issue. We will update this BID=
 as more information emerges.

This issue affects Hardware Management Console 7R3.1.0; other versions ma=
y also be affected.

95. OpenLD Index.PHP SQL Injection Vulnerability
BugTraq ID: 24838
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24838
Summary:
OpenLD is prone to an SQL-injection vulnerability because the application=
 fails to properly sanitize user-supplied input before using it in an SQL=
 query.=20
=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.

OpenLD 1.2.2 and prior versions are vulnerable to this issue.

96. GNU Image Manipulation Program Multiple Integer Overflow Vulnerabilit=
ies
BugTraq ID: 24835
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24835
Summary:
GNU Image Manipulation Program (GIMP) is prone to multiple integer-overfl=
ow vulnerabilities because it fails to adequately bounds-check user-suppl=
ied data.

An attacker can exploit these vulnerabilities to execute arbitrary code w=
ith the privileges of the user running GIMP. Failed exploit attempts will=
 likely cause denial-of-service conditions.

Versions prior to GIMP 2.2.16 are vulnerable.

97. Aigaion Index.PHP SQL Injection Vulnerability
BugTraq ID: 24836
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24836
Summary:
Aigaion is prone to an SQL-injection vulnerability because the applicatio=
n fails to properly sanitize user-supplied input before using it in an SQ=
L query.=20
=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.

Aigaion 1.3.3 is vulnerable to this issue.

98. Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control Denial of Serv=
ice Vulnerability
BugTraq ID: 24834
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24834
Summary:
Innovasys DockStudioXP ActiveX control is prone to a denial-of-service vu=
lnerability.
=20
An attacker may exploit this issue by enticing victims into opening a mal=
icious webpage or HTML email that invokes the affected control.

The attacker can exploit this issue to cause denial-of-service conditions=
 in Internet Explorer or other applications that use the vulnerable Activ=
eX control.

99. Media Player Classic .FLV Remote Denial Of Service Vulnerability
BugTraq ID: 24830
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24830
Summary:
Media Player Classic is prone to a remote denial-of-service vulnerability=
.

Attackers can exploit this issue to crash the application. Reports indica=
te that remote code execution may also be possible, but this has not been=
 confirmed.

Media Player Classic 6.4.9.0 is vulnerable; other versions may also be af=
fected.

100. Mozilla Firefox WYCIWYG:// URI Cache Zone Bypass Vulnerability
BugTraq ID: 24831
Remote: Yes
Last Updated: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24831
Summary:
Mozilla Firefox is prone to a cache-zone-bypass vulnerability because the=
 application fails to properly block remote access to special internally =
generated URIs containing cached data.

Exploiting this issue allows remote attackers to access potentially sensi=
tive information and to place markers with similar functionality to cooki=
es onto targeted users' computers, regardless of cookie security settings=
. Information harvested in successful exploits may aid in further attacks=
.

Attackers may also potentially exploit this issue to perform cache-poison=
ing or URL-spoofing attacks.

This issue is being tracked by Mozilla's Bugzilla Bug 387333.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Fast flux foils bot-net takedown
By: Robert Lemos
Malicious coders are increasingly playing a shell game, using a technolog=
y known as "fast flux" to make locating key servers more difficult.
http://www.securityfocus.com/news/11473

2. Lawmakers worry over gov't network breaches
By: Robert Lemos
Hearings on the Hill reveal a significant number of security breaches at =
the Departments of Commerce, Defense, Homeland Security, State and Energy=
.
http://www.securityfocus.com/news/11472

3. Amero case spawns effort to educate
By: Robert Lemos
Following a judge's ruling to throw out a verdict based on faulty digital=
 forensics, a group of security professionals, legal experts and educator=
s look to the future.
http://www.securityfocus.com/news/11471

4. Group: Anti-hacking laws can hobble Net security
By: Robert Lemos
A working group of security researchers, digital-rights activists and gov=
ernment prosecutors discuss whether bug hunters can find vulnerabilities =
in Web sites without violating laws.
http://www.securityfocus.com/news/11470

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Application Security Architect, Noida
http://www.securityfocus.com/archive/77/472985

2. [SJ-JOB] Security System Administrator, Denver
http://www.securityfocus.com/archive/77/472988

3. [SJ-JOB] Management, Cupertino
http://www.securityfocus.com/archive/77/472989

4. [SJ-JOB] Security Engineer, Rockville
http://www.securityfocus.com/archive/77/472991

5. [SJ-JOB] Quality Assurance, Columbia
http://www.securityfocus.com/archive/77/472978

6. [SJ-JOB] Sr. Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/472979

7. [SJ-JOB] Manager, Information Security, Cincinnati
http://www.securityfocus.com/archive/77/472986

8. [SJ-JOB] Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/472987

9. [SJ-JOB] Security Engineer, Columbia
http://www.securityfocus.com/archive/77/472993

10. [SJ-JOB] Sr. Security Engineer, Wilmington
http://www.securityfocus.com/archive/77/472970

11. [SJ-JOB] Management, Mountain View
http://www.securityfocus.com/archive/77/472973

12. [SJ-JOB] Security Researcher, Houston
http://www.securityfocus.com/archive/77/472977

13. [SJ-JOB] Manager, Information Security, Cincinnati
http://www.securityfocus.com/archive/77/472992

14. [SJ-JOB] Management, Milwaukee
http://www.securityfocus.com/archive/77/472969

15. [SJ-JOB] Security Architect, Melville LI
http://www.securityfocus.com/archive/77/472971

16. [SJ-JOB] Auditor, Multiple Locations
http://www.securityfocus.com/archive/77/472972

17. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/472976

18. [SJ-JOB] Security Architect, Virtual
http://www.securityfocus.com/archive/77/472980

19. [SJ-JOB] Security Engineer, New York
http://www.securityfocus.com/archive/77/472964

20. [SJ-JOB] Manager, Information Security, Skokie
http://www.securityfocus.com/archive/77/472966

21. [SJ-JOB] Information Assurance Engineer, DC/Metro Area
http://www.securityfocus.com/archive/77/472967

22. [SJ-JOB] Security Architect, Cincinnati
http://www.securityfocus.com/archive/77/472968

23. [SJ-JOB] Principal Software Engineer, Noida
http://www.securityfocus.com/archive/77/472962

24. [SJ-JOB] Security Architect, Wilmington
http://www.securityfocus.com/archive/77/472965

25. [SJ-JOB] Application Security Engineer, Cincinnati
http://www.securityfocus.com/archive/77/472958

26. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/472959

27. [SJ-JOB] Forensics Engineer, Cupertino
http://www.securityfocus.com/archive/77/472961

28. [SJ-JOB] Jr. Security Analyst, Ramstein
http://www.securityfocus.com/archive/77/472942

29. [SJ-JOB] Security Engineer, Cupertino
http://www.securityfocus.com/archive/77/472947

30. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/472949

31. [SJ-JOB] Security Architect, Leatherhead & Europe
http://www.securityfocus.com/archive/77/472951

32. [SJ-JOB] Security Architect, Cheltenham, Gloucs
http://www.securityfocus.com/archive/77/472953

33. [SJ-JOB] Sr. Security Engineer, New York City
http://www.securityfocus.com/archive/77/472950

34. [SJ-JOB] VP of Marketing, Cleveland
http://www.securityfocus.com/archive/77/472955

35. [SJ-JOB] Manager, Information Security, Skokie
http://www.securityfocus.com/archive/77/472956

36. [SJ-JOB] Security Architect, Surrey & Berkshire
http://www.securityfocus.com/archive/77/472960

37. [SJ-JOB] Developer, London
http://www.securityfocus.com/archive/77/472931

38. [SJ-JOB] Sr. Security Analyst, Reston
http://www.securityfocus.com/archive/77/472933

39. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/472934

40. [SJ-JOB] Sr. Security Analyst, Leatherhead (Surrey) & Reading (Berks)
http://www.securityfocus.com/archive/77/472943

41. [SJ-JOB] Technology Risk Consultant, Bay Area
http://www.securityfocus.com/archive/77/472954

42. [SJ-JOB] Threat Analyst, Fort Lauderdale
http://www.securityfocus.com/archive/77/472932

43. [SJ-JOB] Security Consultant, St. Louis
http://www.securityfocus.com/archive/77/472935

44. [SJ-JOB] Security Architect, Leatherhead (Surrey) & Reading (Berks)
http://www.securityfocus.com/archive/77/472948

45. [SJ-JOB] Sr. Security Analyst, Olympia
http://www.securityfocus.com/archive/77/472952

46. [SJ-JOB] Manager, Information Security, Fort Meade
http://www.securityfocus.com/archive/77/472912

47. [SJ-JOB] Security Director, Cleveland
http://www.securityfocus.com/archive/77/472929

48. [SJ-JOB] Security Consultant, Leatherhead, Surrey
http://www.securityfocus.com/archive/77/472939

49. [SJ-JOB] Channel / Business Development, London
http://www.securityfocus.com/archive/77/472941

50. [SJ-JOB] Threat Analyst, Warren
http://www.securityfocus.com/archive/77/472913

51. [SJ-JOB] Director, Information Security, San Diego
http://www.securityfocus.com/archive/77/472914

52. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/472915

53. [SJ-JOB] Auditor, Columbia
http://www.securityfocus.com/archive/77/472926

54. [SJ-JOB] Sales Representative, London
http://www.securityfocus.com/archive/77/472940

55. [SJ-JOB] Forensics Engineer, Birmingham
http://www.securityfocus.com/archive/77/472911

56. [SJ-JOB] Security Engineer, San Diego
http://www.securityfocus.com/archive/77/472925

57. [SJ-JOB] Technical Support Engineer, Leatherhead, Surrey & Europe
http://www.securityfocus.com/archive/77/472928

58. [SJ-JOB] Principal Software Engineer, Columbia
http://www.securityfocus.com/archive/77/472936

59. [SJ-JOB] Sr. Security Engineer, Elgin
http://www.securityfocus.com/archive/77/472902

60. [SJ-JOB] Auditor, Chicago
http://www.securityfocus.com/archive/77/472903

61. [SJ-JOB] Auditor, Hartford
http://www.securityfocus.com/archive/77/472904

62. [SJ-JOB] Forensics Engineer, Manchester
http://www.securityfocus.com/archive/77/472905

63. [SJ-JOB] Information Assurance Analyst, Baltimore
http://www.securityfocus.com/archive/77/472901

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. USB device control software
http://www.securityfocus.com/archive/88/472910

2. SecurityFocus Microsoft Newsletter #349
http://www.securityfocus.com/archive/88/472860

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
 body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000Cu=
6j