SecurityFocus Newsletter #438
[email protected] 2 Feb 2008 01:57:21 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #438
----------------------------------------
This issue is Sponsored by: Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Mother May I?
2. Finding a Cure for Data Loss
II. BUGTRAQ SUMMARY
1. 2Wire Routers 'H04_POST' Access Validation Vulnerability
2. Savant Webserver Buffer Overflow Vulnerability
3. Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerabili=
ty
4. Drupal Secure Site Module Authentication Bypass Vulnerability
5. Chilkat FTP 'ChilkatCert.dll' ActiveX Control Insecure Method V=
ulnerability
6. QuickTicket QTI_CheckName.PHP Local File Include Vulnerability
7. Skype Web Content Zone Remote Code Execution Vulnerability
8. 2Wire Routers Cross-Site Request Forgery Vulnerability
9. Gnumeric XLS HLINK Opcode Handling Remote Arbitrary Code Execut=
ion Vulnerability
10. OpenBSD bgplg 'cmd' Parameter Cross-Site Scripting Vulnerabili=
ty
11. VirtueMart Information Disclosure Vulnerability
12. ELOG 'logbook' HTML Injection Vulnerability
13. SwiftView ActiveX Control and Browser Plugin Stack Buffer Over=
flow Vulnerability
14. ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remo=
te File Include Vulnerabilities
15. DeltaScripts PHP Links 'vote.php' SQL Injection Vulnerability
16. DeltaScripts PHP Links 'smarty.php' Remote File Include Vulner=
ability
17. Ruby Net::HTTP SSL Insecure Certificate Validation Weakness
18. Ruby Multiple Libraries SSL Multiple Insecure Certificate Vali=
dation Weaknesses
19. QuickTalk Forum Lang Parameter Multiple Local File Include Vul=
nerabilities
20. RETIRED: Endian Firewall 'userlist.php' Cross Site Scripting V=
ulnerability
21. BitDefender Products Update Server HTTP Daemon Directory Trave=
rsal Vulnerability
22. WordPress WassUp Plugin 'spy.php' SQL Injection Vulnerability
23. Logitech VideoCall Multiple ActiveX Controls Multiple Buffer O=
verflow Vulnerabilities
24. PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilitie=
s
25. LanDesk Management Suite Alert Service AOLSRVR.EXE Buffer Over=
flow Vulnerability
26. libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Serv=
ice Vulnerability
27. Alt-N WebAdmin Remote File Disclosure Vulnerability
28. Alt-N WebAdmin Remote File Viewing Vulnerability
29. 'distcc' Access Control Bypass Vulnerability
30. IrfanView FPX File Remote Memory Corruption Vulnerability
31. Citrix Presentation Server IMA Service Buffer Overflow Vulnera=
bility
32. Corel WordPerfect Office PRS Stack Buffer Overflow Vulnerabili=
ty
33. Joomla! and Mambo NeoReferences Component 'catid' Parameter SQ=
L Injection Vulnerability
34. Archimede Net 2000 'E-Guest_show.php' SQL Injection Vulnerabil=
ity
35. eIQnetworks Enterprise Security Analyzer Topology Server Remot=
e Buffer Overflow Vulnerability
36. RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerab=
ility
37. AskJeeves Toolbar Settings Plugin ActiveX Control Remote Heap =
Based Buffer Overflow Vulnerability
38. IMLib/IMLib2 Multiple BMP Image Decoding Buffer Overflow Vulne=
rabilities
39. Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability
40. GAMSoft Telsrv DoS Vulnerability
41. Hummingbird Connectivity 10 LPD Daemon Stack Overflow Vulnerab=
ility
42. iTinySoft Studio Total Video Player M3U Playlist Buffer Overfl=
ow Vulnerability
43. IASystemInfo.DLL ActiveX Control Remote Buffer Overflow Vulner=
abilities
44. Trend Micro ServerProtect SpntSvc.EXE Remote Stack Based Buffe=
r Overflow Vulnerability
45. Trend Micro OfficeScan Client ActiveX Control Remote Buffer Ov=
erflow Vulnerability
46. Trend Micro ServerProtect EarthAgent.EXE Remote Stack Based Bu=
ffer Overflow Vulnerability
47. Novell NetWare CIFS.NLM Denial of Service Vulnerability
48. Novell NetMail IMAP Unspecified Buffer Overflow Vulnerability
49. Novell Netmail NMAP STOR Buffer Overflow Vulnerability
50. Novell Netmail IMAP SUBSCRIBE Buffer Overflow Vulnerability
51. Sun Solaris NFS 'netgroups' Security Bypass Vulnerability
52. PCRE Regular Expression Library Multiple Security Vulnerabilit=
ies
53. PCRE Regular Expression Library UTF-8 Options Multiple Remote =
Denial of Service Vulnerabilities
54. PCRE Regular Expression Library Multiple Integer and Buffer Ov=
erflow Vulnerabilities
55. PCRE Perl Compatible Regular Expression Subpattern Memory Allo=
cation Denial Of Service Vulnerability
56. PCRE Perl Compatible Regular Expressions Library POSIX Denial =
Of Service Vulnerability
57. Novell Netmail IMAP APPEND Buffer Overflow Vulnerability
58. PostgreSQL Multiple Privilege Escalation and Denial of Service=
Vulnerabilities
59. LightBlog 'cp_upload_image.php' Arbitrary File Upload Vulnerab=
ility
60. LiveCart Multiple Cross-Site Scripting Vulnerabilities
61. SunGard Banner Student 'add1' Parameter Cross-Site Scripting V=
ulnerability
62. UltraVNC VNCViewer 'ClientConnection.cpp' Remote Buffer Overfl=
ow Vulnerability
63. Uniwin eCart Professional 'rp' Cross-Site Scripting Vulnerabil=
ities
64. xdg-utils 'xdg-open' and 'xdg-email' Multiple Remote Command E=
xecution Vulnerabilities
65. MySpace Uploader 'MySpaceUploader.ocx' ActiveX Control Buffer =
Overflow Vulnerability
66. Facebook Photo Uploader 4 'ImageUploader4.1.ocx' ActiveX Contr=
ol Buffer Overflow Vulnerability
67. Aurigma Image Uploader 'ImageUploader4.ocx' ActiveX Control Bu=
ffer Overflow Vulnerability
68. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerabil=
ity
69. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation =
Vulnerability
70. X.Org X Server 'PassMessage' Request Local Privilege Escalatio=
n Vulnerability
71. X.Org X Server 'EVI' Extension Local Privilege Escalation Vuln=
erability
72. X.Org X Server 'Xinput' Extension Local Privilege Escalation V=
ulnerability
73. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
74. VideoLAN VLC Multiple Remote Code Execution Vulnerabilities
75. Invision Gallery Index.PHP SQL Injection Vulnerability
76. Nilson's Blogger 'comments.php' Local File Include Vulnerabili=
ty
77. Joomla! and Mambo CatalogShop Component 'id' Parameter SQL Inj=
ection Vulnerability
78. Joomla! and Mambo AkoGallery Component 'id' Parameter SQL Inje=
ction Vulnerability
79. PulseAudio Local Privilege Escalation Vulnerability
80. Sun Java RunTime Environment XML Parsing Unspecified Vulnerabi=
lity
81. Linux Kernel Page Faults Using NUMA Local Denial of Service Vu=
lnerability
82. Linux Kernel PowerPC 'chrp/setup.c' NULL Pointer Dereference D=
enial of Serviced Vulnerability
83. Linux Kernel VFS Unauthorized File Access Vulnerability
84. Linux Kernel DO_COREDUMP Local Information Disclosure Vulnerab=
ility
85. Liferay Enterprise Portal Admin Portlet Shutdown Message HTML =
Injection Vulnerability
86. Joomla! and Mambo com_restaurant Component 'id' Parameter SQL =
Injection Vulnerability
87. Liferay Enterprise Portal 'User-Agent' HTTP Header Script Inje=
ction Vulnerability
88. Liferay Enterprise Portal User-Agent HTTP Header Cross Site Sc=
ripting Vulnerability
89. Liferay Enterprise Portal User Profile Greeting HTML Injection=
Vulnerability
90. Linux Kernel 'isdn_common.c' Local Buffer Overflow Vulnerabili=
ty
91. Linux Kernel ISDN_Net.C Local Buffer Overflow Vulnerability
92. Linux Kernel wait_task_stopped Local Denial of Service Vulnera=
bility
93. ImageMagick Image Filename Remote Command Execution Vulnerabil=
ity
94. ImageMagick File Name Handling Remote Format String Vulnerabil=
ity
95. Sun Java System Access Manager Multiple Vulnerabilities
96. sflog! 'index.php' Multiple Local File Include Vulnerabilities
97. Livelink ECM UTF-7 Cross Site Scripting Vulnerability
98. Mindmeld 'MM_GLOBALS['home']' Multiple Remote File Include Vul=
nerabilities
99. Drupal Project Issue Tracking Module Multiple Input Validation=
Vulnerabilities
100. Drupal Comment Upload Module Upload Validation Function Arbit=
rary File Upload Vulnerability
III. SECURITYFOCUS NEWS
1. Universities fend off phishing attacks
2. Antivirus firms, test labs to form standards group
3. Legitimate sites serving up stealthy attacks
4. Malware hitches a ride on digital devices
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Engineer, Cleveland
2. [SJ-JOB] Customer Service, Atlanta
3. [SJ-JOB] Account Manager, Columbia
4. [SJ-JOB] Auditor, New York
5. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
6. [SJ-JOB] Sales Engineer, Sunnyvale
7. [SJ-JOB] Jr. Security Analyst, London
8. [SJ-JOB] Security Engineer, Washington DC
9. [SJ-JOB] Jr. Security Analyst, London
10. [SJ-JOB] Forensics Engineer, London
11. [SJ-JOB] Sr. Security Analyst, Cupertino
12. [SJ-JOB] Sr. Security Engineer, Long Island
13. [SJ-JOB] Sales Representative, Chicago
14. [SJ-JOB] Security Researcher, San Jose
15. [SJ-JOB] Security Engineer, Bethlehem
V. INCIDENTS LIST SUMMARY
1. DNS CACHE POISONING? - Our Portal is redirecting to our first c=
ompetition
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
1. Fwd: Centralizing Event Viewer Logs
2. Centralizing Event Viewer Logs
3. Under the hood question about Remote Desktop Connection
4. FTP on IIS
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Mother May I?
By Mark Rasch
"Sure, you can have a cookie, but you may not."We all have had that discu=
ssion before -- either with our parents or our kids. A recent case from N=
orth Dakota reveals that the difference between those two concepts may le=
ad not only to civil liability, but could land you in jail.
http://www.securityfocus.com/columnists/463
2.Finding a Cure for Data Loss
By Jamie Reid
Despite missteps in protecting customer information, companies have large=
ly escaped the wrath of consumers.=20
http://www.securityfocus.com/columnists/462
II. BUGTRAQ SUMMARY
--------------------
1. 2Wire Routers 'H04_POST' Access Validation Vulnerability
BugTraq ID: 27516
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27516
Summary:
Multiple 2Wire routers are prone to an access-validation vulnerability be=
cause they fail to adequately authenticate users before performing certai=
n actions.
Unauthenticated attackers can leverage this issue to change the password =
of arbitrary user accounts on the router. Successful attacks will complet=
ely compromise affected devices.
2Wire routers that have the 'H04_POST' page are affected by this issue.
UPDATE: This BID has been retired because it has been found to be a dupli=
cate of BID 27246 (2Wire Routers Cross-Site Request Forgery Vulnerability=
).=20
UPDATE (February 1, 2008): This BID is being reinstated. Further investig=
ation and new information reveal that this vulnerability differs from the=
one described in BID 27246.
2. Savant Webserver Buffer Overflow Vulnerability
BugTraq ID: 5686
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/5686
Summary:
A buffer-overflow vulnerability has been reported in Savant webserver. I=
f the argument to a GET request exceeds 291 bytes in length, a stack over=
run will occur. Remote attackers may be exploit this condition to execute=
arbitrary instructions on the affected host.
3. Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
BugTraq ID: 27542
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27542
Summary:
The OpenID module for Drupal is prone to a vulnerability that allows atta=
ckers to set up malicious OpenID Providers to spoof a legitimate OpenID A=
uthority.
Attackers can exploit this issue to gain unauthorized access to websites =
that rely on OpenID authentication.
Versions prior to OpenID 5.x-1.1 are vulnerable.
4. Drupal Secure Site Module Authentication Bypass Vulnerability
BugTraq ID: 27543
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27543
Summary:
The Secure Site module for Drupal is prone to an authentication-bypass vu=
lnerability because of an error in the IP-authentication feature.
An attacker can exploit this issue to gain unauthorized access to the aff=
ected application. This may lead to further attacks.
This issue affects Secure Site for Drupal 5.x and 4.7.x. Note that Drupa=
l Core without this module is not affected by this issue.
5. Chilkat FTP 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerab=
ility
BugTraq ID: 27540
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27540
Summary:
Chilkat FTP ActiveX control is prone to a vulnerability that allows attac=
kers to create or overwrite arbitrary data with the privileges of the app=
lication using the control (typically Internet Explorer).
Successful exploits can compromise affected computers or cause denial-of-=
service conditions; other attacks are possible.
This issue affects Chilkat FTP ActiveX 2.0; other versions may also be af=
fected.
6. QuickTicket QTI_CheckName.PHP Local File Include Vulnerability
BugTraq ID: 24670
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/24670
Summary:
QuickTicket is prone to a local file-include vulnerability because it fai=
ls to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
This issue affects QuickTicket versions prior to 1.5.
7. Skype Web Content Zone Remote Code Execution Vulnerability
BugTraq ID: 27338
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27338
Summary:
Skype is prone to a vulnerability that allows arbitrary code to run. The =
issue occurs because the application uses Windows 'Web content Zones' in =
an insecure manner.
Attackers can leverage the issue by enticing an unsuspecting user to use =
a Skype dialog on a malicious web object. Successful exploits will allow =
arbitrary code to run in the context of the user running the application.
Skype 3.5 and 3.6 series are vulnerable.
8. 2Wire Routers Cross-Site Request Forgery Vulnerability
BugTraq ID: 27246
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27246
Summary:
Multiple 2Wire routers are prone to a cross-site request-forgery vulnerab=
ility.
Exploiting this issue may allow a remote attacker to execute arbitrary ac=
tions on an affected device.
9. Gnumeric XLS HLINK Opcode Handling Remote Arbitrary Code Execution Vul=
nerability
BugTraq ID: 27536
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27536
Summary:
Gnumeric is prone to a vulnerability that lets remote attakers execute ar=
bitrary code.
Attackers may exploit this issue to corrupt memory and execute machine co=
de in the context of the affected application. Failed exploit attempts wi=
ll result in denial-of-service conditions.
The issue affects Gnumeric 1.6.3; other versions may also be vulnerable.
10. OpenBSD bgplg 'cmd' Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 27535
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27535
Summary:
OpenBSD bgplg is prone to a cross-site scripting vulnerability because th=
e application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
bgplg shipped with OpenBSD 4.1 is vulnerable; other versions may also be =
affected.
11. VirtueMart Information Disclosure Vulnerability
BugTraq ID: 27532
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27532
Summary:
VirtueMart is prone to an information-disclosure vulnerability because it=
fails to properly sanitize user-supplied input.
Attackers can exploit this issue to view arbitrary files and obtain poten=
tially sensitive information in the context of the webserver process. Inf=
ormation obtained could aid in further attacks.
The issue affects VirtueMart 1.0.13a and prior versions.
12. ELOG 'logbook' HTML Injection Vulnerability
BugTraq ID: 27526
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27526
Summary:
ELOG is prone to an HTML-injection vulnerability because the application =
fails to properly sanitize user-supplied input before using it in dynamic=
ally generated content.=20
Attacker-supplied HTML and script code would execute in the context of th=
e affected site, potentially allowing the attacker to steal cookie-based =
authentication credentials or to control how the site is rendered to the =
user; other attacks are also possible.
This issue affects versions prior to ELOG 2.7.2.
13. SwiftView ActiveX Control and Browser Plugin Stack Buffer Overflow Vu=
lnerability
BugTraq ID: 27527
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27527
Summary:
SwiftView is prone to a stack-based buffer-overflow vulnerability. This =
issue affects both the SwiftView ActiveX control and the browser plugin.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application using the affected application. Successful attacks ca=
n compromise the application and possibly the underlying computer. Failed=
attacks will likely cause denial-of-service conditions.
14. ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File=
Include Vulnerabilities
BugTraq ID: 27531
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27531
Summary:
ChronoEngine ChronoForms component for Joomla! is prone to multiple remot=
e file-include vulnerabilities because it fails to sufficiently sanitize =
user-supplied input.
An attacker can exploit these issues to execute malicious PHP code in the=
context of the webserver process. This may allow the attacker to comprom=
ise the application and the underlying system; other attacks are also pos=
sible.
These issues affect ChronoForms 2.3.5; other versions may also be vulnera=
ble.
15. DeltaScripts PHP Links 'vote.php' SQL Injection Vulnerability
BugTraq ID: 27530
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27530
Summary:
DeltaScripts PHP Links is prone to an SQL-injection vulnerability because=
it fails to sufficiently sanitize user-supplied data before using it in =
an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects PHP Links 1.3 and prior versions.
16. DeltaScripts PHP Links 'smarty.php' Remote File Include Vulnerability
BugTraq ID: 27529
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27529
Summary:
DeltaScripts PHP Links is prone to a remote file-include vulnerability be=
cause it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may facilitate a compromise of the application and the un=
derlying system; other attacks are also possible.
This issue affects PHP Links 1.3 and prior versions.
17. Ruby Net::HTTP SSL Insecure Certificate Validation Weakness
BugTraq ID: 25847
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/25847
Summary:
Ruby's Net::HTTP library is prone to an insecure-certificate-validation w=
eakness because the library fails to properly perform validity checks on =
X.509 certificates.
Successfully exploiting this issue may allow attackers to perform man-in-=
the-middle attacks against applications that insecurely use the affected =
library. Other attacks may also be possible.
NOTE: This issue is related to multiple weaknesses covered by BID 26421 -=
Ruby Multiple Libraries SSL Multiple Insecure Certificate Validation Wea=
knesses.
18. Ruby Multiple Libraries SSL Multiple Insecure Certificate Validation =
Weaknesses
BugTraq ID: 26421
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/26421
Summary:
Ruby is prone to multiple weaknesses related to its validation of certifi=
cates. The problem is that multiple libraries fail to properly perform va=
lidity checks on X.509 certificates.
Successfully exploiting these issues may allow attackers to perform man-i=
n-the-middle attacks against applications that insecurely use an affected=
library. Other attacks may also be possible.
NOTE: These issues are related to a weakness covered by BID 25847 (Ruby N=
et::HTTP SSL Insecure Certificate Validation Weakness).
19. QuickTalk Forum Lang Parameter Multiple Local File Include Vulnerabil=
ities
BugTraq ID: 24671
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/24671
Summary:
QuickTalk Forum is prone to multiple local file-include vulnerabilities b=
ecause it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an unauthorized user to view files and =
execute local scripts.
These issues affect QuickTalk Forum 1.3; other versions may also be vulne=
rable.
20. RETIRED: Endian Firewall 'userlist.php' Cross Site Scripting Vulnerab=
ility
BugTraq ID: 27477
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27477
Summary:
Endian Firewall is prone to a cross-site scripting vulnerability because =
it fails to sufficiently sanitize user-supplied input.=20
Exploiting this vulnerability could allow an attacker to perform cross-si=
te scripting attacks on unsuspecting users in the context of the affected=
website. As a result, the attacker may be able to steal cookie-based aut=
hentication credentials and to launch other attacks.
Endian Firewall 2.1.2 is reported vulnerable; other versions may also be =
affected.
NOTE: This BID is being retired because information from the vendor indic=
ates that the device is not prone to this issue.
21. BitDefender Products Update Server HTTP Daemon Directory Traversal Vu=
lnerability
BugTraq ID: 27358
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27358
Summary:
BitDefender Update Server is prone to a directory-traversal vulnerability=
because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access potentially sensitive =
information that could aid in further attacks.
BitDefender Security for File Servers, BitDefender Enterprise Manger, and=
other BitDefender products that include the Update Server are vulnerable=
. This issue affects Update Server when running on Windows; Linux and UNI=
X variants may also be affected.
22. WordPress WassUp Plugin 'spy.php' SQL Injection Vulnerability
BugTraq ID: 27525
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27525
Summary:
WordPress WassUp plugin is prone to an SQL-injection vulnerability becaus=
e it fails to sufficiently sanitize user-supplied data before using it in=
an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
The issue affects WassUp 1.4.3; other versions may also be vulnerable.
23. Logitech VideoCall Multiple ActiveX Controls Multiple Buffer Overflow=
Vulnerabilities
BugTraq ID: 24254
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/24254
Summary:
Multiple Logitech VideoCall ActiveX controls are prone to multiple buffer=
-overflow vulnerabilities because they fail to bounds-check user-supplied=
data before copying it into an insufficiently sized buffer.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
(typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.
24. PeerCast HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 26899
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/26899
Summary:
PeerCast is prone to multiple buffer-overflow vulnerabilities because it =
fails to adequately bounds-check user-supplied input before copying it to=
an insufficiently sized buffer.
Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code with the privileges of the user running the affected applica=
tion. Failed exploit attempts will likely crash the application.
These issues affect PeerCast 0.12.17, SVN 334 and prior versions.
25. LanDesk Management Suite Alert Service AOLSRVR.EXE Buffer Overflow Vu=
lnerability
BugTraq ID: 23483
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/23483
Summary:
LANDesk Management Suite is prone to a remote stack-based buffer-overflow=
vulnerability because the application fails to bounds-check user-supplie=
d data before copying it into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue would result in the =
complete compromise of affected computers. Failed exploit attempts will =
result in a denial of service.=20
=20
This issue affects LANDesk Management Suite 8.7; prior versions may also =
be affected.
26. libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vul=
nerability
BugTraq ID: 27248
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27248
Summary:
The libxml2 library is prone to a denial-of-service vulnerability because=
of an infinite-loop flaw.
Exploiting this issue allows remote attackers to cause denial-of-service =
conditions in the context of an application using the vulnerable library.
Versions prior to libxml2 2.6.31 are affected by this issue.
27. Alt-N WebAdmin Remote File Disclosure Vulnerability
BugTraq ID: 7439
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/7439
Summary:
Reportedly, remote users can discover the installation directory of certa=
in software on the underlying system by submitting an HTTP request to the=
WebAdmin server. This could allow an attacker to obtain sensitive infor=
mation.
28. Alt-N WebAdmin Remote File Viewing Vulnerability
BugTraq ID: 7438
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/7438
Summary:
Alt-N WebAdmin allows a remote user to access files that they should not =
be able to access. The remote user can submit an HTTP request that will =
return the contents of any webserver-readable file on the system.=20
=20
NOTE: The user must have administrative privileges in WebAdmin to access =
these files.
29. 'distcc' Access Control Bypass Vulnerability
BugTraq ID: 11319
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/11319
Summary:
The access controls for the 'distcc' program may malfunction under certai=
n circumstances and may not be enforced.=20
=20
A remote attacker may potentially exploit this vulnerability to access th=
e affected 'distcc' service, regardless of access-control rules that are =
set in place.=20
=20
This vulnerability is addressed in 'distcc' 2.16.
30. IrfanView FPX File Remote Memory Corruption Vulnerability
BugTraq ID: 27479
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27479
Summary:
IrfanView is prone to a remote memory-corruption vulnerability.=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.=20
This issue affects IrfanView 4.10; other versions may also be affected.
31. Citrix Presentation Server IMA Service Buffer Overflow Vulnerability
BugTraq ID: 27329
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27329
Summary:
Citrix Presentation Server is prone to a buffer-overflow vulnerability be=
cause the IMA service fails to properly bounds-check user-supplied input =
before copying it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitra=
ry machine code in the context of the IMA server process. Failed exploit =
attempts will likely result in denial-of-service conditions.
The issue affects the following versions:
Citrix MetaFrame and Presentation Server 4.5 (and earlier)
Citrix Access Essentials 2.0 (and earlier)
Citrix Desktop Server 1.0 (and earlier)
32. Corel WordPerfect Office PRS Stack Buffer Overflow Vulnerability
BugTraq ID: 23177
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/23177
Summary:
Corel WordPerfect Office is prone to a stack-based buffer-overflow vulner=
ability because the software fails to adequately bounds-check user-suppli=
ed data before copying it to an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the application. A successful attack can resu=
lt in the compromise of the application. Failed attempts will likely resu=
lt in denial-of-service conditions.
WordPerfect X3 version 13.0.0.565 is vulnerable to this issue; other vers=
ions may also be affected.
33. Joomla! and Mambo NeoReferences Component 'catid' Parameter SQL Injec=
tion Vulnerability
BugTraq ID: 27564
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27564
Summary:
The NeoReferences component for Joomla! and Mambo is prone to an SQL-inj=
ection vulnerability because it fails to sufficiently sanitize user-suppl=
ied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects NeoReferences 1.3.1; other versions may also be affect=
ed.
34. Archimede Net 2000 'E-Guest_show.php' SQL Injection Vulnerability
BugTraq ID: 27563
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27563
Summary:
Archimede Net 2000 is prone to an SQL-injection vulnerability because it =
fails to sufficiently sanitize user-supplied data before using it in an S=
QL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
35. eIQnetworks Enterprise Security Analyzer Topology Server Remote Buffe=
r Overflow Vulnerability
BugTraq ID: 19164
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/19164
Summary:
eIQnetworks Enterprise Security Analyzer Topology Server is prone to a re=
mote buffer-overflow vulnerability.
This issue can facilitate a remote compromise due to arbitrary code execu=
tion.
Enterprise Security Analyzer versions prior to 2.5.0 are vulnerable. OEM =
vendors' versions prior to 4.6 are also vulnerable.
36. RETIRED: Solaris in.telnetd TTYPROMPT Buffer Overflow Vulnerability
BugTraq ID: 5531
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/5531
Summary:
The telnet server shipped with Sun Microsystem's Solaris operating system=
is vulnerable to a buffer-overflow condition. Remote attackers may expl=
oit this vulnerability to gain root access on target hosts.=20
=20
**RETRACTION NOTE: It has been determined that this report was sent out i=
n error and that the listed patches likely correct BID 3064 ("Multiple Ve=
ndor Telnetd Buffer Overflow Vulnerability"). This alert was originally =
published after the discovery of functional exploit code that appeared to=
exploit telnetd. It has since been determined that the code, an exploit=
for BID 3681 ("Multiple Vendor System V Derived 'login' Buffer Overflow =
Vulnerability"), was leaked from Internet Security Systems. It has been =
removed from the SecurityFocus archives. This BID will be retired.
37. AskJeeves Toolbar Settings Plugin ActiveX Control Remote Heap Based B=
uffer Overflow Vulnerability
BugTraq ID: 25785
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/25785
Summary:
AskJeeves Toolbar Settings Plugin ActiveX control is prone to a remote he=
ap-based buffer-overflow vulnerability because the application fails to p=
roperly bounds-check user-supplied data before copying it to an insuffici=
ently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
38. IMLib/IMLib2 Multiple BMP Image Decoding Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 11084
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/11084
Summary:
Multiple buffer-overflow vulnerabilities are reported to reside in the Ii=
mlib/Imlib2 libraries. These issues may be triggered when handling malfor=
med bitmap images. =20
=20
A remote attacker could exploit these vulnerabilities to cause a denial o=
f service in applications that use the vulnerable library to render image=
s. Reportedly, attackers may also exploit these vulnerabilities to execut=
e arbitrary code.
39. Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability
BugTraq ID: 11043
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/11043
Summary:
Ipswitch WhatsUp Gold is affected by a remote buffer-overflow vulnerabili=
ty because the application fails to properly validate user-supplied strin=
g lengths before copying them into static process buffers.=20
=20
An attacker might leverage this issue to execute arbitrary code on the af=
fected computer with the privileges of the user that started the vulnerab=
le application.
40. GAMSoft Telsrv DoS Vulnerability
BugTraq ID: 1478
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/1478
Summary:
GAMSoft Telsrv telnet server is prone to a trivial denial-of-service atta=
ck. If a malicious user were to connect to port 23 and supply a username=
of approximately 4550 characters, the telnet application would crash. R=
estarting the service is required to regain normal functionality. =20
In some cases, Telsrv will return an error message that contains a valid=
username and password in plain-text format. This can be used to gain un=
authorized access to the telnet server.
41. Hummingbird Connectivity 10 LPD Daemon Stack Overflow Vulnerability
BugTraq ID: 13788
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/13788
Summary:
Hummingbird Connectivity 10 LPD daemon is prone to a remote stack-based b=
uffer-overflow vulnerability because the software fails to perform suffic=
ient boundary checks on user-supplied data. =20
=20
A successful exploit will allow an unauthenticated attacker to obtain SYS=
TEM-level access to a vulnerable computer.
42. iTinySoft Studio Total Video Player M3U Playlist Buffer Overflow Vuln=
erability
BugTraq ID: 22553
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/22553
Summary:
Total Video Player is prone to a buffer-overflow vulnerability because th=
e application fails to properly verify the size of user-supplied data bef=
ore copying it into an insufficiently sized process buffer.
Exploiting this issue allows remote attackers to execute arbitrary machin=
e code in the context of the user running the affected application. Faile=
d exploit attempts will likely crash applications, denying service to leg=
itimate users.
This issue affects Total Video Player 1.03; other versions may also be vu=
lnerable.
43. IASystemInfo.DLL ActiveX Control Remote Buffer Overflow Vulnerabiliti=
es
BugTraq ID: 23071
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/23071
Summary:
The IASystemInfo.dll ActiveX control of InterActual Player and CinePlayer=
is prone to buffer-overflow vulnerabilities. This software fails to suff=
iciently check boundaries of user-supplied input before copying it to an =
insufficiently sized memory buffer.
InterActual Player version 2.60.12.0717 is vulnerable to these issues; ot=
her versions may also be affected.=20
CinePlayer version 3.2 is vulnerable to these issues; other versions may =
also be affected.
44. Trend Micro ServerProtect SpntSvc.EXE Remote Stack Based Buffer Overf=
low Vulnerability
BugTraq ID: 23868
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/23868
Summary:
Trend Micro ServerProtect is prone to a stack-based buffer-overflow vulne=
rability because the application fails to properly bounds-check user-supp=
lied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code =
with SYSTEM-level privileges and to completely compromise affected comput=
ers. Failed exploit attempts will result in a denial of service.
45. Trend Micro OfficeScan Client ActiveX Control Remote Buffer Overflow =
Vulnerability
BugTraq ID: 22585
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/22585
Summary:
Trend Micro OfficeScan Client is prone to a remote buffer-overflow vulner=
ability because the application fails to properly bounds-check user-suppl=
ied data before copying it into an insufficiently sized memory buffer.
Exploiting this issue allows remote attackers to execute arbitrary code i=
n the context of applications using the affected ActiveX control and to c=
ompromise affected computers. Failed attempts will likely result in denia=
l-of-service conditions.
46. Trend Micro ServerProtect EarthAgent.EXE Remote Stack Based Buffer Ov=
erflow Vulnerability
BugTraq ID: 23866
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/23866
Summary:
Trend Micro ServerProtect is prone to a stack-based buffer-overflow vulne=
rability because the application fails to properly bounds-check user-supp=
lied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code =
with SYSTEM-level privileges and to completely compromise affected comput=
ers. Failed exploit attempts will result in a denial of service.
47. Novell NetWare CIFS.NLM Denial of Service Vulnerability
BugTraq ID: 14701
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/14701
Summary:
NetWare CIFS.NLM is prone to a remote denial-of-service vulnerability.=20
=20
Reportedly, the W32.Randex.CCC worm can trigger this issue resulting in a=
denial-of-service condition due to an ABEND.=20
=20
The following versions are vulnerable:
NetWare 5.1
NetWare 6.0
NetWare 6.5 SP2
NetWare 6.5 SP3
48. Novell NetMail IMAP Unspecified Buffer Overflow Vulnerability
BugTraq ID: 15491
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/15491
Summary:
Novell NetMail is prone to a buffer-overflow vulnerability in an unspecif=
ied IMAP command. Successful exploits may result in a denial of service =
or arbitrary code execution.=20
=20
NetMail 3.52D is affected, but earlier versions may also be vulnerable.=20
=20
Details regarding the precise nature of this vulnerability are not curren=
tly available. We will update this BID as more information emerges.
49. Novell Netmail NMAP STOR Buffer Overflow Vulnerability
BugTraq ID: 21725
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/21725
Summary:
Novell Netmail is prone to a remotely exploitable buffer overflow vulnera=
bility because it fails to do proper bounds checking on NMAP (Network Mes=
saging Application Protocol) STOR command parameters.
A successful exploit could let an authenticated remote attacker execute a=
rbitrary code in the context of the affected program.
50. Novell Netmail IMAP SUBSCRIBE Buffer Overflow Vulnerability
BugTraq ID: 21728
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/21728
Summary:
Novell Netmail is prone to a remotely exploitable buffer-overflow vulnera=
bility because it fails to do proper bounds checking on arguments for IMA=
P SUBSCRIBE commands.
A successful exploit could let an authenticated remote attacker execute a=
rbitrary code in the context of the affected program.
51. Sun Solaris NFS 'netgroups' Security Bypass Vulnerability
BugTraq ID: 26872
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26872
Summary:
Sun Solaris is prone to a security-bypass vulnerability due to an unspeci=
fied error.
A successful attack will allow an unauthorized remote user to gain superu=
ser access to shared NFS resources on the vulnerable system with 'netgrou=
ps' access configured.
This issue affects Sun Solaris 10 with the following kernel patches:
- kernel patches 120011-04 (and later) that are prior to 127111-05 on SPA=
RC platforms
- kernel patches 120012-04 (and later) that are prior to 127954-03 on x86=
platforms
52. PCRE Regular Expression Library Multiple Security Vulnerabilities
BugTraq ID: 26346
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26346
Summary:
PCRE regular-expression library is prone to multiple security vulnerabili=
ties.
Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.
53. PCRE Regular Expression Library UTF-8 Options Multiple Remote Denial =
of Service Vulnerabilities
BugTraq ID: 26550
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26550
Summary:
PCRE regular-expression library is prone to multiple remote denial-of-ser=
vice vulnerabilities because a memory-calculation error occurs for certai=
n regular expressions.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions on computers running the affected library.
These issues affect versions prior to PCRE 7.0.
54. PCRE Regular Expression Library Multiple Integer and Buffer Overflow =
Vulnerabilities
BugTraq ID: 26462
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26462
Summary:
PCRE regular-expression library is prone to multiple integer- and buffer-=
overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.
55. PCRE Perl Compatible Regular Expression Subpattern Memory Allocation =
Denial Of Service Vulnerability
BugTraq ID: 26727
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26727
Summary:
PCRE (Perl Compatible Regular Expressions) is prone to a denial-of-servic=
e vulnerability. The library fails to allocate sufficient memory for quan=
tified subpatterns that contain certain data.
A successful attack can cause an application using the library to crash, =
denying service to legitimate users.
Versions prior to PCRE 6.7 are vulnerable.
56. PCRE Perl Compatible Regular Expressions Library POSIX Denial Of Serv=
ice Vulnerability
BugTraq ID: 26725
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/26725
Summary:
PCRE (Perl Compatible Regular Expressions) is prone to a denial-of-servic=
e vulnerability because it fails to adequately sanitize user-supplied reg=
ular expressions.
A successful attack will cause an application using the library to crash,=
denying service to legitimate users.
Versions prior to PCRE 6.7 are vulnerable.
57. Novell Netmail IMAP APPEND Buffer Overflow Vulnerability
BugTraq ID: 21723
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/21723
Summary:
Novell Netmail is prone to a remotely exploitable buffer-overflow vulnera=
bility because it fails to do proper bounds checking on a client-supplied=
IMAP APPEND parameter.
A successful exploit could let an authenticated remote attacker execute a=
rbitrary code in the context of the affected program.
58. PostgreSQL Multiple Privilege Escalation and Denial of Service Vulner=
abilities
BugTraq ID: 27163
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27163
Summary:
PostgreSQL is prone to multiple remote vulnerabilities, including:=20
- Three privilege-escalation vulnerabilities=20
- Three denial-of-service vulnerabilities
An attacker can exploit these issues to gain complete control of the affe=
cted application or to cause a denial-of-service condition.
These issues affect PostgreSQL 8.2, 8.1, 8.0, 7.4, and 7.3; other version=
s may also be affected.
59. LightBlog 'cp_upload_image.php' Arbitrary File Upload Vulnerability
BugTraq ID: 27562
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27562
Summary:
LightBlog is prone to a vulnerability that lets attackers upload arbitrar=
y files because it fails to adequately sanitize user-supplied input.=20
An attacker can exploit this vulnerability to upload arbitrary code and e=
xecute it in the context of the webserver process. This may facilitate un=
authorized access or privilege escalation; other attacks are also possibl=
e.=20
LightBlog 9.5 is affected; other versions may also be vulnerable.
60. LiveCart Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 27087
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27087
Summary:
LiveCart is prone to multiple cross-site scripting vulnerabilities becaus=
e it fails to properly sanitize user-supplied input.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks.
LiveCart 1.0.1 is vulnerable to these issues; other versions may also be =
affected.
61. SunGard Banner Student 'add1' Parameter Cross-Site Scripting Vulnerab=
ility
BugTraq ID: 27490
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27490
Summary:
Banner Student is prone to a cross-site scripting vulnerability because i=
t fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
=20
Banner Student 7.3 is vulnerable; other versions may also be affected.
62. UltraVNC VNCViewer 'ClientConnection.cpp' Remote Buffer Overflow Vuln=
erability
BugTraq ID: 27561
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27561
Summary:
UltraVNC VNCViewer is affected by a remote buffer-overflow vulnerability =
because the application fails to properly validate user-supplied string l=
engths before copying them into static process buffers.=20
=20
An attacker might leverage this issue to execute arbitrary code on the af=
fected computer with the privileges of the user running the vulnerable ap=
plication.
UltraVNC 1.0.2 and UltraVNC 104 release candidates released prior to Janu=
ary 25, 2008 are vulnerable to this issue.=20
NOTE: This issue affects only VNCViewer. The UltraVNC server is not affec=
ted.
63. Uniwin eCart Professional 'rp' Cross-Site Scripting Vulnerabilities
BugTraq ID: 27560
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27560
Summary:
Uniwin eCart Professional is prone to multiple cross-site scripting vulne=
rabilities because it fails to sufficiently sanitize user-supplied input =
data.
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may help the attacker steal cookie-based authentication credentials=
and launch other attacks.
=20
These issues affect versions prior to Uniwin eCart Professional 2.0.16.
64. xdg-utils 'xdg-open' and 'xdg-email' Multiple Remote Command Executio=
n Vulnerabilities
BugTraq ID: 27528
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27528
Summary:
The 'xdg-utils' package is prone to a remote command-execution vulnerabil=
ities.
An attacker could exploit this issue by enticing an unsuspecting victim t=
o open a malicious file.=20
Successful exploits will allow attackers to execute arbitrary commands wi=
th the privileges of the user running the affected application.
65. MySpace Uploader 'MySpaceUploader.ocx' ActiveX Control Buffer Overflo=
w Vulnerability
BugTraq ID: 27533
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27533
Summary:
MySpace Uploader ActiveX control is prone to a buffer-overflow vulnerabil=
ity because the application fails to perform adequate boundary checks on =
user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
The Symantec DeepSight team has confirmed that this issue can be used to =
execute code or crash the vulnerable application using 'MySpaceUploader.o=
cx' 1.0.0.4 and 1.0.0.5; other versions may also be vulnerable.
66. Facebook Photo Uploader 4 'ImageUploader4.1.ocx' ActiveX Control Buff=
er Overflow Vulnerability
BugTraq ID: 27534
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27534
Summary:
Facebook Photo Uploader ActiveX control is prone to a buffer-overflow vul=
nerability because the application fails to perform adequate boundary che=
cks on user-supplied data.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of the application using the ActiveX contro=
l (typically Internet Explorer). Failed exploit attempts will result in d=
enial-of-service conditions.
The Symantec DeepSight team has confirmed that this issue leads to a cra=
sh in 'ImageUploader4.1.ocx' 4.5.57.0; other versions may also be vulnera=
ble. We will update this BID as more information emerges.
67. Aurigma Image Uploader 'ImageUploader4.ocx' ActiveX Control Buffer Ov=
erflow Vulnerability
BugTraq ID: 27539
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27539
Summary:
Aurigma Image Uploader ActiveX control is prone to a buffer-overflow vuln=
erability because the application fails to perform adequate boundary chec=
ks on user-supplied data.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of the application using the ActiveX contro=
l (typically Internet Explorer). Failed exploit attempts likely result in=
denial-of-service conditions.
Image Uploader 4.5.70.0 is vulnerable; other versions may also be affecte=
d.
NOTE: This issue may be related to the issues covered in BID 27533 (MySpa=
ce Uploader 'MySpaceUploader.ocx' ActiveX Control Buffer Overflow) and BI=
D 27534 (Facebook Photo Uploader 4 'ImageUploader4.1.ocx' ActiveX Control=
Buffer Overflow Vulnerability).
68. X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
BugTraq ID: 27350
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27350
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
69. X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulnera=
bility
BugTraq ID: 27355
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27355
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
70. X.Org X Server 'PassMessage' Request Local Privilege Escalation Vulne=
rability
BugTraq ID: 27354
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27354
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.=20
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges. Successfully exploiting this issue will result in the comple=
te compromise of an affected computer. Failed exploit attempts will likel=
y crash the computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
71. X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerabili=
ty
BugTraq ID: 27353
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27353
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
72. X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerab=
ility
BugTraq ID: 27351
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27351
Summary:
X.Org X Server is prone to a local privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary code with superuser=
privileges or to crash the affected computer.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vulner=
abilities), but has been given its own record to better document the issu=
e.
73. X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
BugTraq ID: 27352
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27352
Summary:
X.Org X Server is prone to a buffer-overflow vulnerability because it fai=
ls to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the server. Failed attacks will cause denial-of-service conditio=
ns.
NOTE: This vulnerability was previously covered in BID 27336 (X.Org X Ser=
ver Multiple Local Privilege Escalation and Information Disclosure Vuln=
erabilities), but has been given its own record to better document the i=
ssue.
74. VideoLAN VLC Multiple Remote Code Execution Vulnerabilities
BugTraq ID: 27015
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27015
Summary:
VideoLAN VLC media player is prone to multiple remote code-execution vuln=
erabilities, including multiple buffer-overflow issues and a format-strin=
g issue.
Exploiting these issues allows remote attackers to execute arbitrary mach=
ine code in the context of the affected application.
VLC 0.8.6d is vulnerable to these issues; other versions may also be affe=
cted.
75. Invision Gallery Index.PHP SQL Injection Vulnerability
BugTraq ID: 20327
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/20327
Summary:
Invision Gallery is prone to an SQL-injection vulnerability because the a=
pplication fails to properly sanitize user-supplied input before using it=
in an SQL query.=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.
This issue affects versions prior to Invision Gallery 2.1.0.
76. Nilson's Blogger 'comments.php' Local File Include Vulnerability
BugTraq ID: 27559
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27559
Summary:
Nilson's Blogger is prone to a local file-include vulnerability because i=
t fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal stri=
ngs to include local files in the context of the webserver process. This =
may allow the attacker to obtain potentially sensitive information; other=
attacks are also possible.
This issue affects Nilson's Blogger 0.11; other versions may also be vuln=
erable.
77. Joomla! and Mambo CatalogShop Component 'id' Parameter SQL Injection =
Vulnerability
BugTraq ID: 27558
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27558
Summary:
The CatalogShop component for Mambo and Joomla! is prone to an SQL-inject=
ion vulnerability because it fails to sufficiently sanitize user-supplied=
data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects CatalogShop 1.0 b1; other versions may also be affecte=
d.
78. Joomla! and Mambo AkoGallery Component 'id' Parameter SQL Injection V=
ulnerability
BugTraq ID: 27557
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27557
Summary:
The AkoGallery component for Joomla! and Mambo is prone to an SQL-injecti=
on vulnerability because it fails to sufficiently sanitize user-supplied =
data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
79. PulseAudio Local Privilege Escalation Vulnerability
BugTraq ID: 27449
Remote: No
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27449
Summary:
PulseAudio is prone to a local privilege-escalation vulnerability because=
the application fails to properly ensure that it has dropped its privile=
ges.
Exploiting this issue could allow attackers to perform certain actions wi=
th superuser privileges.
This vulnerability affects versions prior to PulseAudio 0.9.9.
80. Sun Java RunTime Environment XML Parsing Unspecified Vulnerability
BugTraq ID: 27553
Remote: Yes
Last Updated: 2008-02-01
Relevant URL: http://www.securityfocus.com/bid/27553
Summary:
Sun Java Runtime Environment (JRE) is prone to an unspecified vulnerabili=
ty that can occur when parsing malicious XML content.
Exploiting this issue will allow JRE to process external references even =
if it has been configured not to do so. Attackers can leverage this issue=
to launch further attacks or to cause denial-of-service conditions.
This issue affects JDK and JRE 6 Update 3 and earlier.
81. Linux Kernel Page Faults Using NUMA Local Denial of Service Vulnerabi=
lity
BugTraq ID: 27556
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27556
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly handle certain page faults when using NUMA (Non-=
Uniform Memory Access) methods. =20
Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users.
Linux kernel 2.6.9 and prior versions are vulnerable. This issue affects=
the Itanium architecture; other architectures may also be vulnerable.
82. Linux Kernel PowerPC 'chrp/setup.c' NULL Pointer Dereference Denial o=
f Serviced Vulnerability
BugTraq ID: 27555
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27555
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.=20
Attackers can exploit this issue to crash the affected kernel, denying se=
rvice to legitimate users.
This issue affects Linux kernel 2.4.21 through 2.6.18-53 running on the P=
owerPC architecture.
83. Linux Kernel VFS Unauthorized File Access Vulnerability
BugTraq ID: 27280
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27280
Summary:
The Linux kernel is prone to an unauthorized file-access vulnerability af=
fecting the VFS (Virtual Filesystem) module.
A local attacker can exploit this issue to access arbitrary files on the =
affected computer. Successfully exploiting this issue may grant the attac=
ker elevated privileges on affected computers. Other attacks are also pos=
sible.
This issue affects kernel versions prior to 2.6.23.14.
84. Linux Kernel DO_COREDUMP Local Information Disclosure Vulnerability
BugTraq ID: 26701
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/26701
Summary:
The Linux kernel is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information =
that may aid in further attacks.
Versions of the Linux kernel prior to 2.6.24-rc4 are vulnerable.
85. Liferay Enterprise Portal Admin Portlet Shutdown Message HTML Injecti=
on Vulnerability
BugTraq ID: 27554
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27554
Summary:
Liferay Enterprise Portal is prone to an HTML-injection vulnerability bec=
ause the application fails to properly sanitize user-supplied input befor=
e using it in dynamically generated content.=20
Attacker-supplied HTML and script code would execute in the context of th=
e affected site, potentially allowing the attacker to steal cookie-based =
authentication credentials or to control how the site is rendered to the =
user; other attacks are also possible.
This issue affects versions prior to Liferay Enterprise Portal 4.4.0 and =
4.3.7.
86. Joomla! and Mambo com_restaurant Component 'id' Parameter SQL Injecti=
on Vulnerability
BugTraq ID: 27551
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27551
Summary:
The Joomla! and Mambo 'com_restaurant' component is prone to an SQL-injec=
tion vulnerability because it fails to sufficiently sanitize user-supplie=
d data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
87. Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection V=
ulnerability
BugTraq ID: 27550
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27550
Summary:
Liferay Enterprise Portal is prone to a script-code-injection vulnerabili=
ty because the application fails to properly sanitize user-supplied input=
.
An attacker may leverage this issue to inject arbitrary script code into =
'Forgot Password' emails sent by the affected application. This may help =
the attacker obtain potentially sensitive information that can aid in oth=
er attacks.
Versions prior to Liferay Enterprise Portal 4.4.0 and 4.3.7 are vulnerabl=
e.
88. Liferay Enterprise Portal User-Agent HTTP Header Cross Site Scripting=
Vulnerability
BugTraq ID: 27547
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27547
Summary:
Liferay Enterprise Portal is prone to a cross-site scripting vulnerabilit=
y because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in =
the browser of an unsuspecting user in the context of the affected site. =
This may help the attacker steal cookie-based authentication credentials =
and launch other attacks.
This issue affects Liferay Enterprise Portal 4.3.6.
89. Liferay Enterprise Portal User Profile Greeting HTML Injection Vulner=
ability
BugTraq ID: 27546
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27546
Summary:
Liferay Enterprise Portal is prone to an HTML-injection vulnerability bec=
ause the application fails to properly sanitize user-supplied input befor=
e using it in dynamically generated content.=20
Attacker-supplied HTML and script code would execute in the context of th=
e affected site, potentially allowing the attacker to steal cookie-based =
authentication credentials or to control how the site is rendered to the =
user; other attacks are also possible.
This issue affects versions prior to Liferay Enterprise Portal 4.4.0 and =
4.3.7.
90. Linux Kernel 'isdn_common.c' Local Buffer Overflow Vulnerability
BugTraq ID: 27497
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27497
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability becaus=
e it fails to properly bounds-check user-supplied input before copying it=
into an insufficiently sized buffer.=20
An attacker can exploit this issue to cause denial-of-service conditions.=
Given the nature of this issue, the attacker may also be able to execute=
arbitrary code, but this has not been confirmed.
This issue affects versions prior to Linux kernel 2.6.25.
91. Linux Kernel ISDN_Net.C Local Buffer Overflow Vulnerability
BugTraq ID: 26605
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/26605
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability becaus=
e it fails to properly bounds-check user-supplied input before copying it=
into an insufficiently sized buffer.=20
An attacker can exploit this issue to cause denial-of-service conditions.=
Given the nature of this issue, the attacker may also be able to execute=
arbitrary code, but this has not been confirmed.
This issue affects the Linux kernel versions prior to 2.6.23.10.
92. Linux Kernel wait_task_stopped Local Denial of Service Vulnerability
BugTraq ID: 26477
Remote: No
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/26477
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly handle certain process-exit conditions.
Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users.
Linux kernel versions prior to 2.6.23.8 as well as 2.6.24-rc1 and 2.6.24=
-rc1 are vulnerable.
93. ImageMagick Image Filename Remote Command Execution Vulnerability
BugTraq ID: 16093
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/16093
Summary:
ImageMagick is prone to a remote shell command-execution vulnerability.=20
Successful exploitation can allow arbitrary commands to be executed in th=
e context of the affected user. Note that attackers could exploit this is=
sue through other applications that use ImageMagick as the default image =
viewer.=20
ImageMagick 6.2.4.5 is reportedly vulnerable. Other versions may be affec=
ted as well.
94. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.=20
Reportedly, this issue arises when the application handles malformed file=
names. An attacker can exploit this vulnerability by crafting a malicious=
file with a name that contains format specifiers and sending the file to=
an unsuspecting user.=20
Note that there are other attack vectors that may not require user intera=
ction, since the application can be used with custom printing systems and=
web applications.=20
A successful attack may crash the application or lead to arbitrary code e=
xecution.=20
All versions of ImageMagick are considered vulnerable at the moment.
95. Sun Java System Access Manager Multiple Vulnerabilities
BugTraq ID: 25842
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/25842
Summary:
Sun Java System Access Manager is prone to multiple remote vulnerabilitie=
s that result from configuration errors.
Exploiting these issues can allow remote attackers to gain unauthorized a=
ccess to the application or execute arbitrary code in the context of the =
application.
Sun Java System Access Manager 7.1 is affected by these issues.
96. sflog! 'index.php' Multiple Local File Include Vulnerabilities
BugTraq ID: 27541
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27541
Summary:
The 'sflog!' program is prone to multiple local file-include vulnerabilit=
ies because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensi=
tive information in the context of the affected application.
These issues affect sflog! 0.96; other versions may also be affected.
97. Livelink ECM UTF-7 Cross Site Scripting Vulnerability
BugTraq ID: 27537
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27537
Summary:
Livelink ECM is prone to a cross-site scripting vulnerability because it =
fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in =
the browser of an unsuspecting user in the context of the affected site. =
This may help the attacker steal cookie-based authentication credentials =
and launch other attacks.
This issue affects versions up to and including Livelink ECM 9.7.0.
98. Mindmeld 'MM_GLOBALS['home']' Multiple Remote File Include Vulnerabil=
ities
BugTraq ID: 27538
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27538
Summary:
Mindmeld is prone to multiple remote file-include vulnerabilities because=
it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the applicati=
on and the underlying system; other attacks are also possible.
This issue affects Mindmeld 1.2.0.10; other versions may also be affected=
.
99. Drupal Project Issue Tracking Module Multiple Input Validation Vulner=
abilities
BugTraq ID: 27545
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27545
Summary:
The Project Issue Tracking module for Drupal is prone to multiple input-v=
alidation vulnerabilities because it fails to adequately sanitize user-su=
pplied input. These issues include a cross-site scripting vulnerability =
as well as a vulnerability that allows attacker to upload arbitrary code.
Successfully exploiting these issues can allow an attacker to upload and =
execute arbitrary code in the context of the application. This may help t=
he attacker steal cookie-based authentication credentials, and launch add=
itional attacks.
Note that Drupal Core without this module is not affected by these issues=
.
100. Drupal Comment Upload Module Upload Validation Function Arbitrary Fi=
le Upload Vulnerability
BugTraq ID: 27544
Remote: Yes
Last Updated: 2008-01-31
Relevant URL: http://www.securityfocus.com/bid/27544
Summary:
The Drupal Comment Upload module is prone to an arbitrary-file-upload vul=
nerability because the application fails to sufficiently sanitize user-su=
pplied input.
Exploiting this issue could allow an attacker to upload and execute arbit=
rary script code in the context of the affected webserver process.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Universities fend off phishing attacks
By: Robert Lemos
Online fraudsters send e-mail messages that masquerade as help-desk reque=
sts for usernames and passwords.
http://www.securityfocus.com/news/11504
2. Antivirus firms, test labs to form standards group
By: Robert Lemos
The makers of antivirus software as well as independent and media-sponsor=
ed testing labs have agreed to create an industry group to standardize on=
methods of evaluating anti-malware programs.
http://www.securityfocus.com/news/11502
3. Legitimate sites serving up stealthy attacks
By: Robert Lemos
The Random JS infection kit serves up malicious code that hides itself by=
attempting to compromise each visitor only once and using a different fi=
le name each time.
http://www.securityfocus.com/news/11501
4. Malware hitches a ride on digital devices
By: Robert Lemos
Some consumers reported that their holiday gifts came with an unwelcome p=
assenger, a Trojan horse. Infections at the factory and in retail stores =
will likely become more common.
http://www.securityfocus.com/news/11499
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, Cleveland
http://www.securityfocus.com/archive/77/487201
2. [SJ-JOB] Customer Service, Atlanta
http://www.securityfocus.com/archive/77/487211
3. [SJ-JOB] Account Manager, Columbia
http://www.securityfocus.com/archive/77/487212
4. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/487214
5. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/487198
6. [SJ-JOB] Sales Engineer, Sunnyvale
http://www.securityfocus.com/archive/77/487199
7. [SJ-JOB] Jr. Security Analyst, London
http://www.securityfocus.com/archive/77/487200
8. [SJ-JOB] Security Engineer, Washington DC
http://www.securityfocus.com/archive/77/487202
9. [SJ-JOB] Jr. Security Analyst, London
http://www.securityfocus.com/archive/77/487213
10. [SJ-JOB] Forensics Engineer, London
http://www.securityfocus.com/archive/77/487188
11. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/487189
12. [SJ-JOB] Sr. Security Engineer, Long Island
http://www.securityfocus.com/archive/77/487190
13. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/487179
14. [SJ-JOB] Security Researcher, San Jose
http://www.securityfocus.com/archive/77/487185
15. [SJ-JOB] Security Engineer, Bethlehem
http://www.securityfocus.com/archive/77/487215
V. INCIDENTS LIST SUMMARY
---------------------------
1. DNS CACHE POISONING? - Our Portal is redirecting to our first competit=
ion
http://www.securityfocus.com/archive/75/486799
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Fwd: Centralizing Event Viewer Logs
http://www.securityfocus.com/archive/88/487366
2. Centralizing Event Viewer Logs
http://www.securityfocus.com/archive/88/487262
3. Under the hood question about Remote Desktop Connection
http://www.securityfocus.com/archive/88/487023
4. FTP on IIS
http://www.securityfocus.com/archive/88/486644
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat Europe
Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content. Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com