SecurityFocus Newsletter #442
[email protected] 27 Feb 2008 18:26:39 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #442
----------------------------------------
This issue is Sponsored by: CISO Executive Summit & Roundtable-Middle Eas=
t, 12th-14th May, Bahrain, Ritz-Carlton=20
Over 20 speakers from across The Middle East, Europe, U.S & Asia will gat=
her together for the MIS training.s CISO Executive Summit Middle East, Sh=
eraton Bahrain Hotel, Kingdom of Bahrain 12-14 May 2008. This dynamic int=
ernational speaker line up will provide a broad perspective on the securi=
ty threats faced today and in the future. Take away actionable strategies=
that will enable you to limit the risk within your organisation. Interna=
tional case studies from the industries leading associations and organisa=
tions will provide you with the knowledge to identify the warning signs o=
f key threats to your company.=20
Register now at www.mistieruope.com/CISOME
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. The Laws of Full Disclosure
2. Tweaking Social Security to Combat Fraud
II. BUGTRAQ SUMMARY
1. Symantec Decomposer RAR File Remote Buffer Overflow Vulnerabili=
ty
2. Double-Take Denial of Service and Information Disclosure Vulner=
abilities
3. phpProfiles 'body_comm.inc.php' Remote File Include Vulnerabili=
ty
4. Linux Kernel Sbus PROM Driver Multiple Integer Overflow Vulnera=
bilities
5. CruxCMS 'search.php' Cross-Site Scripting Vulnerability
6. Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection =
Vulnerability
7. VMware Products Shared Folders 'MultiByteToWideChar()' Variant =
Directory Traversal Vulnerability
8. PADL 'nss_ldap' Race Condition Security Vulnerability
9. Mozilla Firefox Domain Extensions Insecure Cookie Access Vulner=
ability
10. xdg-utils 'xdg-open' and 'xdg-email' Multiple Remote Command E=
xecution Vulnerabilities
11. ClamAV Heap Corruption and Integer Overflow Vulnerabilities
12. Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vuln=
erability
13. ImageMagick Blob.C Off-By-One Buffer Overflow Vulnerability
14. ImageMagick ReadDIBImage Integer Overflow Vulnerability
15. ImageMagick ReadBlob Multiple Remote Denial Of Service Vulnera=
bilities
16. ImageMagick DCM, DIB, XBM, XCF, and XWD Image Files Multiple I=
nteger Overflow Vulnerabilities
17. BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Mul=
tiple Vulnerabilities
18. Wireshark 0.99.6 Multiple Remote Vulnerabilities
19. Wireshark 0.99.6 Multiple Denial of Service Vulnerabilities
20. Multiple Horde Products Security Bypass Vulnerability
21. BestWebApp Dating Site Multiple Input Validation Vulnerabiliti=
es
22. PCRE Character Class Buffer Overflow Vulnerability
23. PCRE Regular Expression Library Multiple Integer and Buffer Ov=
erflow Vulnerabilities
24. Linux Kernel ALSA snd-page-alloc Local Proc File Information D=
isclosure Vulnerability
25. Linux Kernel IPv6 TCP Sockets Local Denial of Service Vulnerab=
ility
26. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vuln=
erability
27. Symantec Decomposer Resource Consumption Denial of Service Vul=
nerability
28. Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote=
Vulnerabilities
29. QEMU Translation Block Local Denial of Service Vulnerability
30. QEMU Multiple Local Vulnerabilities
31. Mozilla Firefox chrome:// URI JavaScript File Request Informat=
ion Disclosure Vulnerability
32. MPlayer 'demux_audio.c' Remote Stack Based Buffer Overflow Vul=
nerability
33. Asterisk IAX2 Channel Driver IAX2_Write Function Remote Stack =
Buffer Overflow Vulnerability
34. Nukedit 'email' Parameter SQL Injection Vulnerability
35. Multiple Web Browser BMP Partial Palette Information Disclosur=
e and Denial Of Service Vulnerability
36. ZyXEL Gateway Products Multiple Vulnerabilities
37. Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Ov=
erflow Vulnerability
38. Ghostscript Unspecified Buffer Overflow Vulnerability
39. InterVideo WinDVD Media Center Remote Denial of Service Vulner=
abilities
40. activePDF Server Packet Processing Remote Heap Overflow Vulner=
ability
41. Spyce Sample Scripts Multiple Input Validation Vulnerabilities
42. CUPS Multiple Remote Denial of Service Vulnerabilities
43. Asterisk Multiple Remote Denial of Service Vulnerabilities
44. CUPS 'process_browse_data()' Remote Double Free Denial of Serv=
ice Vulnerability
45. Softbiz Jokes and Funny Pictures Script 'sbcat_id' Parameter S=
QL Injection Vulnerability
46. Xpdf Multiple Remote Stream.CC Vulnerabilities
47. Aeries Browser Interface 'LostPwd.asp' SQL Injection Vulnerabi=
lity
48. The SWORD Project Diatheke Unspecified Remote Command Executio=
n Vulnerability
49. Rising Web Scan Object 'OL2005.dll' ActiveX Control Remote Cod=
e Execution Vulnerability
50. Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX=
Control Buffer Overflow Vulnerability
51. DrBenHur.com DBHcms 'mod.extmanager.php' Remote File Include V=
ulnerability
52. SurgeFTP 'Content-Length' Parameter NULL Pointer Denial Of Ser=
vice Vulnerability
53. SurgeMail Real CGI executables Remote Buffer Overflow Vulnerab=
ility
54. SurgeMail and WebMail 'Page' Command Remote Format String Vuln=
erability
55. PORAR Webboard 'question.asp' SQL Injection Vulnerability
56. Alkacon OpenCms 'tree_files.jsp' Cross-Site Scripting Vulnerab=
ility
57. phpRaider Resistance Field HTML Injection Vulnerability
58. H-Sphere SiteStudio Unspecified Vulnerability
59. WordPress Sniplets Plugin Multiple Input Validation Vulnerabil=
ities
60. KAME Project IPv6 IPComp Header Denial Of Service Vulnerabilit=
y
61. Galore Simple Shop 'section' Parameter SQL Injection Vulnerabi=
lity
62. MyServer Mutltiple HTTP Methods '204 Not Content' Error Remote=
Denial of Service Vulnerabilities
63. Matt's Whois 'mwhois.php' Cross-Site Scripting Vulnerability
64. wyrd Insecure Temporary File Creation Vulnerability
65. PHP-Nuke Kose_Yazilari Module 'artid' Parameter Multiple SQL I=
njection Vulnerabilities
66. XOOPS XM-Memberstats Module 'letter' and 'sortby' Parameters M=
ultiple SQL Injection Vulnerabilities
67. PHP-Nuke Sell Module 'cid' Parameter SQL Injection Vulnerabili=
ty
68. Joomla! and Mambo 'com_wines' Component 'id' Parameter SQL Inj=
ection Vulnerability
69. Joomla! and Mambo 'com_inter' Component 'id' Parameter SQL Inj=
ection Vulnerability
70. Gary's Cookbook 'id' Parameter SQL Injection Vulnerability
71. Joomla! and Mambo 'com_blog' Component 'pid' Parameter SQL Inj=
ection Vulnerability
72. Multiple Vendor PEAP Certificate Verification Security Bypass =
Vulnerability
73. Linux Kernel Prior to 2.6.24.1 'copy_from_user_mmap_sem()' Mem=
ory Access Vulnerability
74. IncrediMail IMMenuShellExt ActiveX Control Remote Buffer Overf=
low Vulnerability
75. Pagetool Index.PHP SQL Injection Vulnerability
76. F5 BIG-IP Application Security Manager 'report_type' Cross-Sit=
e Scripting Vulnerability
77. Symark PowerBroker Client Multiple Local Buffer Overflow Vulne=
rabilities
78. Mozilla Thunderbird External-Body MIME Remote Heap Buffer Over=
flow Vulnerability
79. Microsoft Word Unspecified Remote Code Execution Vulnerability
80. Various IP Security Camera ActiveX Controls 'url' Attribute Bu=
ffer Overflow Vulnerability
81. VideoLAN VLC Media Player MP4 Demuxer Remote Code Execution Vu=
lnerability
82. Nortel UNIStim IP Phone Remote Ping Denial of Service Vulnerab=
ility
83. S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
84. KVM Block Device Backend Local Security Bypass Vulnerability
85. MiniNuke 'members.asp' SQL Injection Vulnerability
86. Joomla! and Mambo 'com_publication' Component 'pid' Parameter =
SQL Injection Vulnerability
87. Sun Solaris Internet Protocol 'ip(7P)' Security Bypass and Den=
ial Of Service Vulnerability
88. TikiWiki 'tiki-edit_article.php' Cross-Site Scripting Vulnerab=
ility
89. Fujitsu Interstage Application Server Single Sign-On Buffer Ov=
erflow Vulnerability
90. OpenBSD IPv6 Routing Headers Remote Denial of Service Vulnerab=
ility
91. Portail Web Php Multiple Remote And Local File Include Vulnera=
bilities
92. LWS php User Base 'unverified.inc.php' Local File Include Vuln=
erability
93. LWS php User Base 'header.inc.php' Remote File Include Vulnera=
bility
94. LWS php Download Manager 'body.inc.php' Local File Include Vul=
nerability
95. PHPEcho CMS 'Smarty.class.php' Remote File Include Vulnerabili=
ty
96. auraCMS 'lihatberita' Module 'id' Parameter SQL Injection Vuln=
erability
97. Joomla! and Mambo 'com_hello_world' Component 'id' Parameter S=
QL Injection Vulnerability
98. PHP-Nuke Gallery Module 'aid' Parameter SQL Injection Vulnerab=
ility
99. PHP-Nuke Sections Module 'artid' Parameter SQL Injection Vulne=
rability
100. PHP-Nuke Recipe Module 'recipeid' Parameter SQL Injection Vul=
nerability
III. SECURITYFOCUS NEWS
1. Worries over "good worms" rise again
2. Federal agencies miss deadline on secure configs
3. Universities fend off phishing attacks
4. Antivirus firms, test labs to form standards group
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Technical Support Engineer, San Mateo
2. [SJ-JOB] Disaster Recovery Coordinator, Kansas City
3. [SJ-JOB] Penetration Engineer, Redmond
4. [SJ-JOB] Security Consultant, New York
5. [SJ-JOB] Sales Engineer, San Jose
6. [SJ-JOB] Customer Support, South Plainfield
7. [SJ-JOB] Security Consultant, Copenhagen
8. [SJ-JOB] Sales Engineer, Reston
9. [SJ-JOB] Sales Engineer, Alpharetta
10. [SJ-JOB] Customer Support, South Plainfield
11. [SJ-JOB] Sales Engineer, Reston
12. [SJ-JOB] Software Engineer, Alpharetta
13. [SJ-JOB] Sales Engineer, San Jose
14. [SJ-JOB] Sales Engineer, Philadelphia
15. [SJ-JOB] Customer Support, South Plainfield
16. [SJ-JOB] Security Engineer, Canberra
17. [SJ-JOB] Sales Engineer, Canberra
18. [SJ-JOB] Sales Engineer, Ottawa
19. [SJ-JOB] Security Researcher, South Plainfield
20. [SJ-JOB] Certification & Accreditation Engineer, Arlinton
21. [SJ-JOB] Information Assurance Analyst, Herndon
22. [SJ-JOB] Security Architect, South Plainfield
23. [SJ-JOB] Certification & Accreditation Engineer, Arlington
24. [SJ-JOB] Sr. Security Engineer, South Plainfield
25. [SJ-JOB] Sr. Security Analyst, Arlington
26. [SJ-JOB] Sr. Security Engineer, South Plainfield
27. [SJ-JOB] Senior Software Engineer, South Plainfield
28. [SJ-JOB] Security Consultant, Copenhagen
29. [SJ-JOB] Sr. Security Engineer, South Plainfield
30. [SJ-JOB] Sales Engineer, Deerfield Beach
31. [SJ-JOB] Sr. Security Engineer, South Plainfield
32. [SJ-JOB] Security Consultant, Boston
33. [SJ-JOB] Sr. Security Engineer, South Plainfield
34. [SJ-JOB] Application Security Architect, South Plainfield
35. [SJ-JOB] Security Consultant, Dallas
36. [SJ-JOB] Principal Software Engineer, Deerfield Beach
37. [SJ-JOB] Security Architect, LONDON
38. [SJ-JOB] Sales Engineer, Dallas
39. [SJ-JOB] Sales Engineer, Chicago
40. [SJ-JOB] Security Engineer, Chicago
41. [SJ-JOB] Management, Pentagon City
42. [SJ-JOB] Jr. Security Analyst, Washington, DC
43. [SJ-JOB] Manager, Information Security, Chicago
44. [SJ-JOB] Management, Reston
45. [SJ-JOB] Security Engineer, Reston
46. [SJ-JOB] Director, Computer Security, New Jersey
47. [SJ-JOB] Management, San Mateo
48. [SJ-JOB] Training / Awareness Specialist, San Mateo
49. [SJ-JOB] Security Engineer, New Jersey
50. [SJ-JOB] Security Engineer, Arlington
51. [SJ-JOB] Management, Alpharetta
52. [SJ-JOB] Security Consultant, Los Angeles
53. [SJ-JOB] Sales Engineer, New York
54. [SJ-JOB] Auditor, Columbia
55. [SJ-JOB] Application Security Engineer, Ottawa
56. [SJ-JOB] Sales Representative, Boston
57. [SJ-JOB] Software Engineer, Palm Beach Gardens
58. [SJ-JOB] Sales Representative, Atlanta
59. [SJ-JOB] Database Security Architect, Houston
60. [SJ-JOB] Technology Risk Consultant, Various
61. [SJ-JOB] Information Assurance Analyst, London
62. [SJ-JOB] Sales Representative, Chicago
63. [SJ-JOB] Security Consultant, Thousand Oaks
64. [SJ-JOB] Security Engineer, Huntsville
65. [SJ-JOB] Forensics Engineer, Various
66. [SJ-JOB] Application Security Engineer, Dover
67. [SJ-JOB] Security Consultant, Various
68. [SJ-JOB] Security Engineer, Arlington
69. [SJ-JOB] Penetration Engineer, Dallas
70. [SJ-JOB] Threat Analyst, Huntsville
71. [SJ-JOB] Sr. Security Engineer, Stamford
72. [SJ-JOB] Sr. Security Engineer, Washington, DC Metro Area
73. [SJ-JOB] Chief Scientist, Huntsville
74. [SJ-JOB] Chief Scientist, Huntsville
75. [SJ-JOB] Security Engineer, Huntsville
76. [SJ-JOB] Security Engineer, Kansas City
77. [SJ-JOB] Security Engineer, San Francisco
78. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
79. [SJ-JOB] Security Consultant, Thousand Oaks
80. [SJ-JOB] Security Engineer, Seattle
81. [SJ-JOB] Sr. Security Engineer, Austin/Richardson
82. [SJ-JOB] Security Consultant, Thousand Oaks
83. [SJ-JOB] Security Engineer, Arlington
84. [SJ-JOB] Information Assurance Engineer, Annapolis Junction
85. [SJ-JOB] Senior Software Engineer, St. Paul
86. [SJ-JOB] Management, Phoenix
87. [SJ-JOB] Management, New York
88. [SJ-JOB] CISO, London
89. [SJ-JOB] Application Security Architect, Washington
90. [SJ-JOB] Software Engineer, Columbia
V. INCIDENTS LIST SUMMARY
1. CanSecWest 2008 Mar 26-28
2. Possible Mail server compromise ?
VI. VULN-DEV RESEARCH LIST SUMMARY
1. GNU objdump 2.15 [FreeBSD] 2004-05-23 shows: ... "BFD: Please r=
eport this bug." While analyzing crafted ELF.
VII. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. CanSecWest 2008 Mar 26-28
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.The Laws of Full Disclosure
By Federico Biancuzzi
Full disclosure has a long tradition in the security community worldwide,=
yet different European countries have different views on the legality of=
vulnerability research. SecurityFocus contributor Federico Biancuzzi inv=
estigates the subject of full disclosure and the law by interviewing lawy=
ers from twelve EU countries: Belgium, Denmark, Finland, France, Germany,=
Greece, Hungary, Ireland, Italy, Poland, Romania, and the UK.
http://www.securityfocus.com/columnists/466
2. Tweaking Social Security to Combat Fraud
By Tim Mullen
Americans lost over 45 billion dollars in identity-related fraud in 2007.=
Reports are so commonplace that we've actually become de-sensitized to t=
hem. "200,000 victims reported..." "500,000 victims reported..." Even fig=
ures into the millions don't seem to faze us anymore. And that is a Bad T=
hing.=20
http://www.securityfocus.com/columnists/465
II. BUGTRAQ SUMMARY
--------------------
1. Symantec Decomposer RAR File Remote Buffer Overflow Vulnerability
BugTraq ID: 27913
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27913
Summary:
Symantec Decomposer is prone to a remote buffer-overflow vulnerability be=
cause the application fails to properly bounds-check user-supplied input =
before copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary machine code with=
the privileges of the user running the affected application. Failed expl=
oit attempts will result in a denial-of-service condition.
The following products are affected:
- Symantec Scan Engine 5.1.4.24 and prior
- Symantec AntiVirus Scan Engine 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS ISA 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS SharePoint 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Messaging 4.3.16.39 and prior
- Symantec AntiVirus for Network Attached Storage 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Clearswift 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Caching 4.3.16.39 and prior
- Symantec AntiVirus/Filtering for Domino MPE(AIX, Linux, Solaris) prior =
to 3.2.2
- Symantec Mail Security for Microsoft Exchange 4.6.5.12 and prior as wel=
l as 5.0.4.363.and prior
2. Double-Take Denial of Service and Information Disclosure Vulnerabiliti=
es
BugTraq ID: 27951
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27951
Summary:
Double-Take is prone to multiple remote multiple denial-of-service and in=
formation-disclosure vulnerabilities.
An attacker can exploit these issues to obtain sensitive information or c=
rash the affected application, denying service to legitimate users.
These issues affect Double-Take 5.0.0.2865 and 4.5; other versions may a=
lso be affected.
3. phpProfiles 'body_comm.inc.php' Remote File Include Vulnerability
BugTraq ID: 27952
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27952
Summary:
phpProfiles is prone to a remote file-include vulnerability because it fa=
ils to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may facilitate a compromise of the application and the un=
derlying system; other attacks are also possible.
phpProfiles 4.5.2 is vulnerable; other versions may also be affected.
4. Linux Kernel Sbus PROM Driver Multiple Integer Overflow Vulnerabilitie=
s
BugTraq ID: 10632
Remote: No
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/10632
Summary:
The OpenPROM Linux kernel driver contains multiple integer-overflow vulne=
rabilities.=20
=20
Two vulnerabilities reside in the OpenPROM driver; both involve overflowi=
ng an integer value. These values are used to allocate kernel memory and =
then to copy data into the kernel. Attackers could exploit this to overwr=
ite large amounts of kernel memory.=20
=20
Exploits could crash the system or possibly execute code in the context o=
f the kernel.=20
=20
NOTE: Some versions of the Linux kernel are vulnerable to both overflows;=
other versions are prone to only one. Kernel version 2.6.6 does not appe=
ar to be vulnerable.
5. CruxCMS 'search.php' Cross-Site Scripting Vulnerability
BugTraq ID: 27588
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27588
Summary:
CruxCMS is prone to a cross-site scripting vulnerability because it fails=
to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks.
CruxCMS 3.0 is vulnerable; other versions may also be affected.
6. Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnera=
bility
BugTraq ID: 27907
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27907
Summary:
hwdVideoShare is prone to an SQL-injection vulnerability because it fails=
to sufficiently sanitize user-supplied data before using it in an SQL qu=
ery.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
7. VMware Products Shared Folders 'MultiByteToWideChar()' Variant Directo=
ry Traversal Vulnerability
BugTraq ID: 27944
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27944
Summary:
Multiple VMware products are prone to a directory-traversal vulnerability=
that affects shared folders.
Attackers who can access a guest operating system can exploit this issue =
to gain full read and write access to the filesystem of the host operatin=
g system. Successful attacks could compromise the affected host OS. Other=
attacks are possible.
NOTE: This vulnerability occurs only on Windows hosts when 'Shared Folder=
s' is enabled and when a shared folder exists.
The issue affects the following:
VMware Workstation 6.0.2, 5.5.4, and earlier
VMware Player 2.0.2, 1.0.4, and earlier
VMware ACE 2.0.2, 1.0.2, and earlier.
NOTE: This issue occurs because of a fix that was introduced to address a=
similar issue (CVE-2007-1744) that is documented in BID 23721 (VMware Wo=
rkstation Shared Folders Directory Traversal Vulnerability).
8. PADL 'nss_ldap' Race Condition Security Vulnerability
BugTraq ID: 26452
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/26452
Summary:
PADL 'nss_ldap' is prone to a race-condition security vulnerability; fixe=
s are available.
An attacker may exploit this condition to obtain potentially sensitive da=
ta or to launch other attacks against an application that employs the vul=
nerable function.
The issue affects versions prior to PADL 'nss_ldap' Build 259.
9. Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
BugTraq ID: 27950
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27950
Summary:
Mozilla Firefox is prone to a vulnerability that allows attackers to set =
cookies for certain domain extensions.
The browser does not have any security provisions to prevent cookies from=
being set for extensions with embedded dots. Attackers can leverage this=
issue to set cookies in a manner that could aid in other web-based attac=
ks.
Mozilla Firefox 2.x is vulnerable; other versions may also be affected.
10. xdg-utils 'xdg-open' and 'xdg-email' Multiple Remote Command Executio=
n Vulnerabilities
BugTraq ID: 27528
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27528
Summary:
The 'xdg-utils' package is prone to a remote command-execution vulnerabil=
ities.
An attacker could exploit this issue by enticing an unsuspecting victim t=
o open a malicious file.=20
Successful exploits will allow attackers to execute arbitrary commands wi=
th the privileges of the user running the affected application.
11. ClamAV Heap Corruption and Integer Overflow Vulnerabilities
BugTraq ID: 27751
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27751
Summary:
ClamAV is prone to a heap-corruption vulnerability and an integer-overflo=
w vulnerability.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers. Failed exploit att=
empts likely result in application crashes.
Versions prior to ClamAV 0.92.1 are affected by these issues.
12. Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerabili=
ty
BugTraq ID: 27842
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27842
Summary:
The 'Quran' component for Joomla!, Mambo, and PHP-Nuke is prone to an SQL=
-injection vulnerability because the application fails to properly saniti=
ze user-supplied input before using it in an SQL query.=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.
This issue affects Quran 1.1 and prior versions.
13. ImageMagick Blob.C Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 25766
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/25766
Summary:
ImageMagick is prone to an off-by-one buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows attackers to execute arbitrary =
code with the privileges of a user running the application.
Versions prior to ImageMagick 6.3.5-9 are vulnerable.
14. ImageMagick ReadDIBImage Integer Overflow Vulnerability
BugTraq ID: 25765
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/25765
Summary:
ImageMagick is prone to an integer-overflow vulnerability because it fail=
s to properly validate user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application. Failed exploit attempts will likely cause denial-o=
f-service conditions.
Versions prior to ImageMagick 6.3.5-9 are vulnerable to this issue.
15. ImageMagick ReadBlob Multiple Remote Denial Of Service Vulnerabilitie=
s
BugTraq ID: 25764
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/25764
Summary:
ImageMagick is prone to multiple remote denial-of-service vulnerabilities=
.
An attacker could exploit these issues by enticing an unsuspecting victim=
to open a malicious image file.=20
Successfully exploiting these issues will allow the attacker to consume e=
xcessive amounts of CPU resources on affected computers, denying service =
to legitimate users.=20
These issues affect ImageMagick 6.3.4; prior versions are also affected.
16. ImageMagick DCM, DIB, XBM, XCF, and XWD Image Files Multiple Integer =
Overflow Vulnerabilities
BugTraq ID: 25763
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/25763
Summary:
ImageMagick is prone to multiple integer-overflow vulnerabilities because=
it fails to adequately handle user-supplied data.
An attacker can exploit these issues to execute arbitrary code in the con=
text of the application. Failed exploit attempts will likely cause denial=
-of-service conditions.
These issues affect versions prior to ImageMagick 6.3.5-9.
17. BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple V=
ulnerabilities
BugTraq ID: 27893
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27893
Summary:
BEA has released 17 advisories identifying various vulnerabilities affect=
ing WebLogic Server, WebLogic Portal, WebLogic Workshop, AquaLogic Intera=
ction, BEA Plumtree Foundation, AquaLogic Collaboration, and BEA Plumtree=
Collaboration. These issues present remote and local threats and may fac=
ilitate attacks affecting the integrity, confidentiality, and availabilit=
y of vulnerable computers.
18. Wireshark 0.99.6 Multiple Remote Vulnerabilities
BugTraq ID: 26532
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/26532
Summary:
Wireshark is prone to multiple denial-of-service and buffer-overflow vuln=
erabilities.
Exploiting these issues may allow attackers to cause crashes and deny ser=
vice to legitimate users of the application. Attackers may be able to lev=
erage some of these vulnerabilities to execute arbitrary code, but this h=
as not been confirmed.
Versions prior to Wireshark 0.99.7 are affected.
19. Wireshark 0.99.6 Multiple Denial of Service Vulnerabilities
BugTraq ID: 27071
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27071
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may allow attackers to cause crashes and deny ser=
vice to legitimate users of the application. Attackers may be able to lev=
erage some of these vulnerabilities to execute arbitrary code, but this h=
as not been confirmed.
Versions prior to Wireshark 0.99.7 are affected.
20. Multiple Horde Products Security Bypass Vulnerability
BugTraq ID: 27844
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27844
Summary:
Horde products are prone to a security-bypass vulnerability.
Attackers can use this issue to bypass certain security restrictions and =
edit arbitrary contacts in shared and personal address books. This may ai=
d in further attacks.
This issue affects Horde Groupware 1.0.3, Horde Groupware Webmail Edition=
1.0.4, and Turba Contact Manager 2.1.6; other versions may also be vulne=
rable.
21. BestWebApp Dating Site Multiple Input Validation Vulnerabilities
BugTraq ID: 21158
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/21158
Summary:
BestWebApp Dating Site is prone to multiple input-validation vulnerabilit=
ies, including cross-site scripting and SQL-injection issues, because it =
fails to sufficiently sanitize user-supplied input.
An attacker could exploit these issues to steal cookie-based authenticati=
on credentials, compromise the application, access or modify data, or exp=
loit latent vulnerabilities in the underlying database implementation.
22. PCRE Character Class Buffer Overflow Vulnerability
BugTraq ID: 27786
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27786
Summary:
PCRE regular-expression library is prone to a buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of an application using the library. Failed exploit attempts will likel=
y cause denial-of-service conditions.
The issue affects versions prior to PCRE 7.6.
23. PCRE Regular Expression Library Multiple Integer and Buffer Overflow =
Vulnerabilities
BugTraq ID: 26462
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/26462
Summary:
PCRE regular-expression library is prone to multiple integer- and buffer-=
overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.
24. Linux Kernel ALSA snd-page-alloc Local Proc File Information Disclosu=
re Vulnerability
BugTraq ID: 25807
Remote: No
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/25807
Summary:
The Linux kernel is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain portions of kernel mem=
ory. Information harvested may aid in further attacks.
Versions of the Linux kernel prior to 2.6.22.8 are vulnerable.
25. Linux Kernel IPv6 TCP Sockets Local Denial of Service Vulnerability
BugTraq ID: 23104
Remote: No
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/23104
Summary:
The Linux kernel is prone to a denial-of-service vulnerability.
Exploiting this issue allows local attackers to cause the kernel to crash=
, effectively denying service to legitimate users. Attackers may also be =
able to execute arbitrary code with elevated privileges, but this has not=
been confirmed.
This issue affects the Linux kernel 2.6 series.
26. Linux Kernel Bluetooth CAPI Packet Remote Buffer Overflow Vulnerabili=
ty
BugTraq ID: 21604
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/21604
Summary:
The Linux kernel is prone to a remote buffer-overflow vulnerability becau=
se the kernel fails to bounds-check user-supplied data before copying it =
into an insufficiently sized buffer.=20
An attacker may exploit this issue to execute arbitrary code with kernel-=
level privileges, facilitating the complete compromise of affected comput=
ers. Failed exploit attempts will result in denial-of-service conditions.=
=20
Versions prior to 2.4.33.5 are vulnerable to this issue.
27. Symantec Decomposer Resource Consumption Denial of Service Vulnerabil=
ity
BugTraq ID: 27911
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27911
Summary:
Symantec Decomposer is prone to a denial-of-service vulnerability because=
it fails to adequately parse certain user-supplied input.
Attackers can exploit this issue to exhaust memory resources and cause de=
nial-of-service conditions.
The following products are affected:
- Symantec Scan Engine 5.1.4.24 and prior
- Symantec AntiVirus Scan Engine 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS ISA 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS SharePoint 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Messaging 4.3.16.39 and prior
- Symantec AntiVirus for Network Attached Storage 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Clearswift 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Caching 4.3.16.39 and prior
- Symantec AntiVirus/Filtering for Domino MPE(AIX, Linux, Solaris) prior=
to 3.2.2
- Symantec Mail Security for Microsoft Exchange 4.6.5.12 and prior as wel=
l as 5.0.4.363.and prior
28. Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulner=
abilities
BugTraq ID: 27683
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27683
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox 2.0.0.11 and prior versions.
Exploiting these issues can allow attackers to:
- remotely execute arbitrary code=20
- cause denial-of-service conditions
- hide contents of security warnings
- access sensitive information=20
- escape sandbox and execute scripts with chrome privileges
- inject script code into other sites and violate the same-origin policy
Other attacks are possible.
These issues are present in Firefox 2.0.0.11 and prior versions. Mozilla =
Thunderbird 2.0.0.9 and prior versions as well as SeaMonkey 1.1.7 and pri=
or versions are also affected by many of these vulnerabilities.
29. QEMU Translation Block Local Denial of Service Vulnerability
BugTraq ID: 26666
Remote: No
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/26666
Summary:
QEMU is prone to a local denial-of-service vulnerability because it fails=
to perform adequate boundary checks when handling user-supplied input.
Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of the issue, attackers may also be able to execute arbit=
rary code, but this has not been confirmed.
QEMU 0.9.0 is vulnerable; other versions may also be affected.
30. QEMU Multiple Local Vulnerabilities
BugTraq ID: 23731
Remote: No
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/23731
Summary:
QEMU is prone to multiple locally exploitable buffer-overflow and denial-=
of-service vulnerabilities. The buffer-overflow issues occur because the =
software fails to properly check boundaries of user-supplied input when c=
opying it to insufficiently sized memory buffers. The denial-of-service i=
ssues stem from design errors.
Attackers may be able to exploit these issues to escalate privileges, exe=
cute arbitrary code, or trigger denial-of-service conditions in the conte=
xt of the affected applications.
31. Mozilla Firefox chrome:// URI JavaScript File Request Information Dis=
closure Vulnerability
BugTraq ID: 27406
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27406
Summary:
Mozilla Firefox is prone to an information-disclosure vulnerability becau=
se it fails to restrict access to local JavaScript, images and stylesheet=
s files.
Attackers can exploit this issue to gain access to potentially sensitive =
information that could aid in further attacks.
Firefox 2.0.0.11 is vulnerable; other versions may also be affected.
NOTE: For an exploit to succeed, a user must have an addon installed that=
does not store its contents in a '.jar' file. The attacker would have to=
target a specific addon that uses "flat" packaging.
32. MPlayer 'demux_audio.c' Remote Stack Based Buffer Overflow Vulnerabil=
ity
BugTraq ID: 27441
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27441
Summary:
MPlayer is prone to a remote stack-based buffer-overflow vulnerability be=
cause it fails to perform adequate boundary checks on user-supplied input=
before copying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attacks will cause denial-of-service conditio=
ns.
MPlayer 1.0 rc2 is vulnerable; other versions may also be affected.
33. Asterisk IAX2 Channel Driver IAX2_Write Function Remote Stack Buffer =
Overflow Vulnerability
BugTraq ID: 24949
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/24949
Summary:
Asterisk is prone to a remote stack-based buffer-overflow vulnerability b=
ecause the application fails to bounds-check user-supplied data before co=
pying it into an insufficiently sized buffer.
Successful exploits may allow an attacker to execute arbitrary machine co=
de to compromise an affected computer or to cause a denial-of-service con=
dition.
34. Nukedit 'email' Parameter SQL Injection Vulnerability
BugTraq ID: 28009
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28009
Summary:
Nukedit is prone to an SQL-injection vulnerability because it fails to su=
fficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
35. Multiple Web Browser BMP Partial Palette Information Disclosure and D=
enial Of Service Vulnerability
BugTraq ID: 27826
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27826
Summary:
Firefox and Opera browsers are prone to a vulnerability that can result i=
n information disclosure or a denial of service.
An attacker can exploit this issue to harvest sensitive information that =
may be used to launch further attacks or to crash the affected applicatio=
n, denying service to legitimate users.=20
Mozilla Firefox 2.0.0.11 and Opera 9.50 Beta are affected.
36. ZyXEL Gateway Products Multiple Vulnerabilities
BugTraq ID: 27918
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27918
Summary:
ZyXEL gateway products are prone to multiple vulnerabilities, including p=
rivilege-escalation, unauthorized-access, HTML-injection, session-hijacki=
ng, and information-disclosure issues.
Attackers can exploit these issues to gain elevated privileges, execute H=
TML or script code in the context of vulnerable sections of the web inter=
face, and perform other attacks that may facilitate a complete compromise=
of the affected device.
37. Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow =
Vulnerability
BugTraq ID: 27741
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/27741
Summary:
Novell Client is prone to a buffer-overflow vulnerability.
A remote attacker may exploit this issue to execute arbitrary code with S=
YSTEM-level privileges, facilitating the compromise of affected computers=
. Failed exploit attempts will likely crash the application, denying ser=
vice to legitimate users.
NOTE: This issue may have been caused by an incomplete patch for the vuln=
erability documented in BID 25092 ('Novell Client NWSPOOL.DLL Unspecified=
Buffer Overflow Vulnerability').
Novell Client 4.91 SP2 through SP4 are vulnerable; other versions may als=
o be affected.
38. Ghostscript Unspecified Buffer Overflow Vulnerability
BugTraq ID: 28017
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28017
Summary:
Ghostscript is prone to an unspecified buffer-overflow vulnerability beca=
use it fails to perform adequate boundary checks on user-supplied input.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of the application. Failed exploit attempt=
s will cause denial-of-service conditions.
39. InterVideo WinDVD Media Center Remote Denial of Service Vulnerabiliti=
es
BugTraq ID: 28016
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28016
Summary:
InterVideo WinDVD Media Center is prone to multiple remote denial-of-serv=
ice vulnerabilities arising from NULL-pointer dereference errors.
Successful attacks will deny service to legitimate users.
InterVideo WinDVD Media Center 2.11.15.0 is vulnerable; other versions ma=
y be affected as well.
40. activePDF Server Packet Processing Remote Heap Overflow Vulnerability
BugTraq ID: 28013
Remote: Yes
Last Updated: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28013
Summary:
activePDF Server is prone to a remote heap-overflow vulnerability because=
it fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the affected application. Failed attacks will likely cause denial-of=
-service conditions.
This issue affects the activePDF Server 3.8.4 and 3.8.5.14; other version=
s may be affected as well.
41. Spyce Sample Scripts Multiple Input Validation Vulnerabilities
BugTraq ID: 27898
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27898
Summary:
Spyce is prone to multiple input-validation vulnerabilities that can lead=
to information disclosure or client-side script execution.
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks. The attacker can also obtain a server's=
webroot path.
The issues affect Spyce 2.1.3; other versions may also be vulnerable.
42. CUPS Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 27988
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27988
Summary:
CUPS is prone to two remote denial-of-service vulnerabilities.
Attackers may exploit these issues to crash the application, denying serv=
ice to legitimate users. Remote code execution may also be possible, but =
this has not been confirmed.
CUPS 1.1.17 and 1.1.22 are vulnerable to these issues; other versions may=
also be affected.
43. Asterisk Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 24950
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/24950
Summary:
Asterisk is prone to multiple remote denial-of-service vulnerabilities.
Exploiting these issues allows remote attackers to cause the application =
to crash, effectively denying service to legitimate users.
44. CUPS 'process_browse_data()' Remote Double Free Denial of Service Vul=
nerability
BugTraq ID: 27906
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27906
Summary:
CUPS is prone to a remote denial-of-service vulnerability because it fail=
s to protect against a double-free condition.
Attackers may exploit this issue to crash the application, denying servic=
e to legitimate users. Remote code execution may also be possible, but th=
is has not been confirmed.
CUPS 1.3.5 is vulnerable to this issue; other versions may also be affect=
ed.
45. Softbiz Jokes and Funny Pictures Script 'sbcat_id' Parameter SQL Inje=
ction Vulnerability
BugTraq ID: 27973
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27973
Summary:
The Jokes and Funny Pictures script from Softbiz is prone to an SQL-injec=
tion vulnerability because it fails to sufficiently sanitize user-supplie=
d data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
46. Xpdf Multiple Remote Stream.CC Vulnerabilities
BugTraq ID: 26367
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/26367
Summary:
Xpdf is prone to multiple remote vulnerabilities because of flaws in vari=
ous functions in the 'Stream.cc' source file.
Attackers exploit these issues by coercing users to view specially crafte=
d PDF files with the affected application.
Successfully exploiting these issues allows attackers to execute arbitrar=
y machine code in the context of the vulnerable application. This facilit=
ates the remote compromise of affected computers.
Xpdf 3.02pl1 is vulnerable to these issues; other versions may also be af=
fected.
47. Aeries Browser Interface 'LostPwd.asp' SQL Injection Vulnerability
BugTraq ID: 26962
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/26962
Summary:
Aeries Browser Interface is prone to an SQL-injection vulnerability becau=
se it fails to sufficiently sanitize user-supplied data before using it i=
n an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
48. The SWORD Project Diatheke Unspecified Remote Command Execution Vulne=
rability
BugTraq ID: 27987
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27987
Summary:
The SWORD Project's Diatheke front-end is prone to a vulnerability that c=
an allow arbitrary shell commands to run.
Successful exploits will compromise the application and possibly the unde=
rlying webserver.
SWORD 1.5.9 is vulnerable; other versions may also be affected.
49. Rising Web Scan Object 'OL2005.dll' ActiveX Control Remote Code Execu=
tion Vulnerability
BugTraq ID: 27997
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27997
Summary:
Rising Web Scan Object 'OL2005.dll' ActiveX control is prone to a remote =
code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code on a victim'=
s computer in the context of the vulnerable application using the ActiveX=
control (typically Internet Explorer).
This issue affects Rising Web Scan Object 'OL2005.dll' 18.0.0.7; other ve=
rsions may also be affected.
50. Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Contro=
l Buffer Overflow Vulnerability
BugTraq ID: 27995
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27995
Summary:
Move Media Player Quantum Streaming 'qsp2ie07074039.dll' ActiveX control =
is prone to a remote buffer-overflow vulnerability because the applicatio=
n fails to properly bounds-check user-supplied data before copying it int=
o insufficiently sized memory buffers.
Exploiting this issue may allow remote attackers to execute arbitrary cod=
e in the context of applications using the affected ActiveX control (typi=
cally Internet Explorer) and to compromise affected computers. Failed att=
empts will likely result in denial-of-service conditions.
This issue affects Quantum Streaming 'qsp2ie07074039.dll' ActiveX control=
7.7.4.39; other versions may also be vulnerable.
51. DrBenHur.com DBHcms 'mod.extmanager.php' Remote File Include Vulnerab=
ility
BugTraq ID: 27996
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27996
Summary:
DrBenHur.com DBHcms is prone to a remote file-include vulnerability becau=
se it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may facilitate a compromise of the application and the un=
derlying system; other attacks are also possible.
This issue affects DBHcms 1.1.4 and prior versions.
52. SurgeFTP 'Content-Length' Parameter NULL Pointer Denial Of Service Vu=
lnerability
BugTraq ID: 27993
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27993
Summary:
SurgeFTP is prone to a remote denial-of-service vulnerability because it =
fails to perform adequately boundary checks on user-supplied input.
Exploiting this issue will cause the server to copy data to a NULL pointe=
r, which will crash the server, denying access to legitimate users.
SurgeFTP 2.3a2 is vulnerable; other versions may also be affected.
53. SurgeMail Real CGI executables Remote Buffer Overflow Vulnerability
BugTraq ID: 27992
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27992
Summary:
SurgeMail is prone to a remote buffer-overflow vulnerability because it f=
ails to properly bounds-check user-supplied input.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected service. Failed exploi=
t attempts likely result in denial-of-service conditions.
SurgeMail 38k4 and prior versions are vulnerable.
54. SurgeMail and WebMail 'Page' Command Remote Format String Vulnerabili=
ty
BugTraq ID: 27990
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27990
Summary:
SurgeMail and WebMail are prone to a remote format-string vulnerability b=
ecause the applications fail to properly sanitize user-supplied input bef=
ore including it in the format-specifier argument of a formatted-printing=
function.
A remote attacker may execute arbitrary code with the privileges of the u=
ser running the affected application. Failed exploit attempts will result=
in a denial of service.
=20
This issue affects the following:
SurgeMail 38k4, beta 39a and earlier
Netwin WebMail 3.1s and earlier
55. PORAR Webboard 'question.asp' SQL Injection Vulnerability
BugTraq ID: 27989
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27989
Summary:
PORAR Webboard is prone to an SQL-injection vulnerability because it fail=
s to sufficiently sanitize user-supplied data before using it in an SQL q=
uery.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
56. Alkacon OpenCms 'tree_files.jsp' Cross-Site Scripting Vulnerability
BugTraq ID: 27986
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27986
Summary:
Alkacon OpenCms is prone to a cross-site scripting vulnerability because =
the application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
OpenCms 7.0.3 is vulnerable; other versions may also be affected.
57. phpRaider Resistance Field HTML Injection Vulnerability
BugTraq ID: 27976
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27976
Summary:
phpRaider is prone to an HTML-injection vulnerability because it fails to=
sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script co=
de in the context of the affected site, to steal cookie-based authenticat=
ion credentials, or to control how the site is rendered to the user; othe=
r attacks are also possible.
phpRaider 1.0.7 is vulnerable; other versions may also be affected.
58. H-Sphere SiteStudio Unspecified Vulnerability
BugTraq ID: 28002
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28002
Summary:
H-Sphere SiteStudio is prone to an unspecified vulnerability.
Very few technical details are currently available. We will update this B=
ID as more information emerges.
Successful attacks can compromise the application.
Versions prior to H-Sphere SiteStudio 1.8b are affected.
59. WordPress Sniplets Plugin Multiple Input Validation Vulnerabilities
BugTraq ID: 27985
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27985
Summary:
WordPress Sniplets plugin is prone to multiple input-validation vulnerabi=
lities because the application fails to sanitize user-supplied input. The=
se issues include multiple cross-site scripting vulnerabilities, a remote=
file-include vulnerability, and a remote command-execution vulnerability=
.
A successful exploit may allow an attacker to compromise the application,=
steal cookie-based authentication credentials, and execute arbitrary cod=
e and commands within the context of the webserver process.=20
WordPress Sniplets 1.1.2 is vulnerable; other versions may also be affect=
ed.
60. KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
BugTraq ID: 27642
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27642
Summary:
The KAME project is prone to a denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to crash affec=
ted computers, denying service to legitimate users.
Operating systems that have IPv6 networking derived from the KAME project=
's IPv6 implementation may be vulnerable to this issue. Please see the re=
ferences for a list of vendors that may be affected by this issue.
61. Galore Simple Shop 'section' Parameter SQL Injection Vulnerability
BugTraq ID: 27977
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27977
Summary:
Simple Shop component for Joomla! and Mambo is prone to an SQL-injection =
vulnerability because it fails to sufficiently sanitize user-supplied dat=
a before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
62. MyServer Mutltiple HTTP Methods '204 Not Content' Error Remote Denial=
of Service Vulnerabilities
BugTraq ID: 27981
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27981
Summary:
MyServer is prone to multiple remote denial-of-service vulnerabilities be=
cause it fails to adequately handle HTTP method requests that return a '2=
04 No Content' error.
Successful attacks will deny service to legitimate users.
MyServer 0.8.11 is vulnerable; other versions may also be affected.
63. Matt's Whois 'mwhois.php' Cross-Site Scripting Vulnerability
BugTraq ID: 27974
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27974
Summary:
Matt's Whois is prone to a cross-site scripting vulnerability because it =
fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
64. wyrd Insecure Temporary File Creation Vulnerability
BugTraq ID: 27848
Remote: No
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27848
Summary:
The 'wyrd' program is prone to a security vulnerability that allows attac=
kers to create temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks, overwriting arbitrary files in the context of=
the affected application.=20
Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
attacks may also be possible.
This issue affects wyrd 1.4.3-b3; other versions may also be vulnerable.
65. PHP-Nuke Kose_Yazilari Module 'artid' Parameter Multiple SQL Injectio=
n Vulnerabilities
BugTraq ID: 27991
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27991
Summary:
The Kose_Yazilari module for PHP-Nuke is prone to multiple SQL-injection =
vulnerabilities because it fails to sufficiently sanitize user-supplied d=
ata before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
66. XOOPS XM-Memberstats Module 'letter' and 'sortby' Parameters Multiple=
SQL Injection Vulnerabilities
BugTraq ID: 27979
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27979
Summary:
XOOPS XM-Memberstats is prone to multiple SQL-injection vulnerabilities b=
ecause it fails to sufficiently sanitize user-supplied data before using =
it in an SQL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
These issues affect XOOPS XM-Memberstats 2.0e; other versions may also be=
affected.
67. PHP-Nuke Sell Module 'cid' Parameter SQL Injection Vulnerability
BugTraq ID: 27980
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27980
Summary:
The 'Sell' module for PHP-Nuke is prone to an SQL-injection vulnerability=
because it fails to sufficiently sanitize user-supplied data before usin=
g it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
68. Joomla! and Mambo 'com_wines' Component 'id' Parameter SQL Injection =
Vulnerability
BugTraq ID: 27975
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27975
Summary:
The 'com_wines' component for Joomla! and Mambo is prone to an SQL-inject=
ion vulnerability because it fails to sufficiently sanitize user-supplied=
data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
69. Joomla! and Mambo 'com_inter' Component 'id' Parameter SQL Injection =
Vulnerability
BugTraq ID: 27994
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27994
Summary:
The Joomla! and Mambo 'com_inter' component is prone to an SQL-injection =
vulnerability because it fails to sufficiently sanitize user-supplied dat=
a before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
70. Gary's Cookbook 'id' Parameter SQL Injection Vulnerability
BugTraq ID: 27972
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27972
Summary:
Gary's Cookbook module for Joomla! and Mambo is prone to an SQL-injection=
vulnerability because it fails to sufficiently sanitize user-supplied da=
ta before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
71. Joomla! and Mambo 'com_blog' Component 'pid' Parameter SQL Injection =
Vulnerability
BugTraq ID: 27971
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27971
Summary:
The 'com_blog' component for Joomla! and Mambo is prone to an SQL-injecti=
on vulnerability because it fails to sufficiently sanitize user-supplied =
data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
72. Multiple Vendor PEAP Certificate Verification Security Bypass Vulnera=
bility
BugTraq ID: 27935
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27935
Summary:
Multiple VoIP products are prone to a security-bypass vulnerability in th=
eir PEAP implementation because their software fails to properly validate=
server certificates.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks by impersonating trusted authentication servers. This wil=
l aid in further attacks.
The following products are prone to this issue:
- Vocera Communications System badges
- Cisco Wireless IP Phone 7921
Other devices and packages may also be affected.
73. Linux Kernel Prior to 2.6.24.1 'copy_from_user_mmap_sem()' Memory Acc=
ess Vulnerability
BugTraq ID: 27796
Remote: No
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27796
Summary:
The Linux kernel is prone to a memory-access vulnerability because it fai=
ls to adequately validate a user-supplied pointer value.=20
A local attacker can exploit this issue to read arbitrary memory location=
s on the affected computer.
This issue affects Linux Kernel 2.6.22 through 2.6.24.
74. IncrediMail IMMenuShellExt ActiveX Control Remote Buffer Overflow Vul=
nerability
BugTraq ID: 23674
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/23674
Summary:
IncrediMail is prone to a stack-based buffer-overflow vulnerability becau=
se it fails to sufficiently check boundaries of user-supplied input befor=
e copying it to an insufficiently sized memory buffer.
An attacker may exploit this issue by enticing victims into opening a m=
alicious webpage or HTML email that invokes the affected control.
=20
Successful exploits will corrupt process memory, allowing attacker-supp=
lied arbitrary code to run in the context of the client application using=
the affected ActiveX control.
75. Pagetool Index.PHP SQL Injection Vulnerability
BugTraq ID: 24640
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/24640
Summary:
Pagetool is prone to an SQL-injection vulnerability because it fails to s=
ufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Pagetool 1.07 is vulnerable to this issue; other versions may also be vul=
nerable.
76. F5 BIG-IP Application Security Manager 'report_type' Cross-Site Scrip=
ting Vulnerability
BugTraq ID: 27462
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27462
Summary:
F5 BIG-IP Application Security Manager is prone to a cross-site scripting=
vulnerability because the web management interface fails to properly san=
itize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected device.=
This may help the attacker steal cookie-based authentication credentials=
and launch other attacks.
This issue affects F5 BIG-IP Application Security Manager 9.4.3; other ve=
rsions may also be vulnerable.
77. Symark PowerBroker Client Multiple Local Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 28015
Remote: No
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28015
Summary:
Symark PowerBroker Client is prone to multiple local buffer-overflow vuln=
erabilities because it fails to perform adequate boundary checks on user-=
supplied input. The issues affect the following setuid binaries: 'pbksh',=
'pbsh' and 'pbrun'.
Attackers can exploit these issues to execute arbitrary code with superus=
er privileges. Successful exploits will completely compromise affected co=
mputers.
These issues affect versions 2.8 2.8 upto and including 5.0.1
78. Mozilla Thunderbird External-Body MIME Remote Heap Buffer Overflow Vu=
lnerability
BugTraq ID: 28012
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28012
Summary:
Mozilla Thunderbird is prone to a remote heap-based buffer-overflow vulne=
rability because it fails to properly bounds-check user-supplied data.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary machine code in the context of the vulnerable application; fail=
ed exploit attempts will likely crash the application. This may facilitat=
e the remote compromise of affected computers.
The issue affects Mozilla Thunderbird versions prior to 2.0.0.12.
79. Microsoft Word Unspecified Remote Code Execution Vulnerability
BugTraq ID: 28011
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28011
Summary:
Microsoft Word is prone to an unspecified remote code-execution vulnerabi=
lity.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
It is unknown at this time which specific versions of the application ar=
e affected.
80. Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Ov=
erflow Vulnerability
BugTraq ID: 28010
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28010
Summary:
Various IP Security Camera ActiveX controls are prone to a remote buffer-=
overflow vulnerability because the applications fail to properly bounds-c=
heck user-supplied data before copying it into insufficiently sized memor=
y buffers.
Exploiting this issue may allow remote attackers to execute arbitrary cod=
e in the context of applications using the affected ActiveX control (typi=
cally Internet Explorer) and to compromise affected computers. Failed att=
empts will likely result in denial-of-service conditions.
This issue affects the following ActiveX controls:
- D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5.
- 4xem VatCtrl Class ('VATDecoder.dll') 1.0.0.51.
- Vivotek RTSP MPEG4 SP Control ('RtspVapgDecoderNew.dll') 2.0.0.39.
81. VideoLAN VLC Media Player MP4 Demuxer Remote Code Execution Vulnerabi=
lity
BugTraq ID: 28007
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28007
Summary:
VideoLAN VLC media player is prone to a remote code-execution vulnerabili=
ty because it fails to adequately parse specially crafted MP4 files.
An attacker can exploit this issue to execute arbitrary code, which can r=
esult in the complete compromise of the computer. Failed exploit attempt=
s will result in a denial-of-service condition.=20
VideoLAN VLC media player versions prior to 0.8.6e are vulnerable.
82. Nortel UNIStim IP Phone Remote Ping Denial of Service Vulnerability
BugTraq ID: 28004
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28004
Summary:
Nortel UNIStim IP Phone products are prone to a remote denial-of-service =
vulnerability because the software fails to properly handle unexpected ne=
twork datagrams.
Successfully exploiting this issue allows remote attackers to crash affec=
ted phones, denying service to legitimate users.
Phones with firmware 0604DAS is vulnerable to this issue; other versions =
are also reportedly affected, but specific version information is not cur=
rently available.
83. S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
BugTraq ID: 28003
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28003
Summary:
Serendipity is prone to an HTML-injection vulnerability because it fails =
to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script co=
de in the context of the affected site, to steal cookie-based authenticat=
ion credentials, or to control how the site is rendered to the user; othe=
r attacks are also possible.
Serendipity versions prior to 1.3-beta1 are vulnerable.
84. KVM Block Device Backend Local Security Bypass Vulnerability
BugTraq ID: 28001
Remote: No
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28001
Summary:
KVM (Kernel-based Virtual Machine) is prone to a local security-bypass vu=
lnerability because it fails to validate user-supplied input.
Local attackers can leverage this issue to access memory outside of the v=
irtualization jail. This could allow attackers to write to arbitrary hos=
t memory locations or crash the underlying KVM host. Other attacks may a=
lso be possible.
85. MiniNuke 'members.asp' SQL Injection Vulnerability
BugTraq ID: 28000
Remote: Yes
Last Updated: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28000
Summary:
MiniNuke is prone to an SQL-injection vulnerability because it fails to s=
ufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
86. Joomla! and Mambo 'com_publication' Component 'pid' Parameter SQL Inj=
ection Vulnerability
BugTraq ID: 27970
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27970
Summary:
The Joomla! and Mambo 'com_publication' component is prone to an SQL-inje=
ction vulnerability because it fails to sufficiently sanitize user-suppli=
ed data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
87. Sun Solaris Internet Protocol 'ip(7P)' Security Bypass and Denial Of =
Service Vulnerability
BugTraq ID: 27967
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27967
Summary:
Sun Solaris is prone to a security-bypass and denial-of-service vulnerabi=
lity because of an unspecified error in the Internet Protocol implementat=
ion.
A successful attack of this issue will allow privileged remote users to b=
ypass firewall rules or create denial-of-service conditions.
This issue affects Solaris 8, 9, and 10 for SPARC and x86 platforms.
88. TikiWiki 'tiki-edit_article.php' Cross-Site Scripting Vulnerability
BugTraq ID: 27968
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27968
Summary:
TikiWiki is prone a cross-site scripting vulnerability because it fails t=
o sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
=20
The issue affects versions prior to TikiWiki 1.9.10.1.
89. Fujitsu Interstage Application Server Single Sign-On Buffer Overflow =
Vulnerability
BugTraq ID: 27966
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27966
Summary:
Fujitsu Interstage Application Server is prone to a remote buffer-overflo=
w vulnerability because it fails to perform adequate boundary checks on u=
ser-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the affected application. Failed attacks will likely cause denial-of=
-service conditions.
This issue affects the following applications:
Interstage Application Server Enterprise Edition 8.0.0, 8.0.1, 8.0.2, 8.0=
.3, 9.0.0, and 9.0.0A
Interstage Application Server Standard-J Edition 8.0.0, 8.0.1, 8.0.2, 8.0=
.3, 9.0.0, and 9.0.0A
Interstage Apworks Enterprise Edition 8.0.0
Interstage Apworks Standard-J Edition 8.0.0
Interstage Studio Enterprise Edition 8.0.1 and 9.0.0
Interstage Studio Standard-J Edition 8.0.1 and 9.0.0
90. OpenBSD IPv6 Routing Headers Remote Denial of Service Vulnerability
BugTraq ID: 27965
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27965
Summary:
OpenBSD is prone to a remote denial-of-service vulnerability because of a=
flaw in the affected kernel when processing certain TCP packets.
=20
Exploiting this issue allows remote attackers to trigger kernel panics, d=
enying further service to legitimate users.
OpenBSD 4.2 is vulnerable to this issue; other versions may also be affec=
ted.
91. Portail Web Php Multiple Remote And Local File Include Vulnerabilitie=
s
BugTraq ID: 27962
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27962
Summary:
Portail Web Php is prone to multiple remote and local file-include vulner=
abilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to execute arbitrary local =
and remote scripts in the context of the webserver process or access pote=
ntially sensitive information. This may result in a compromise of the app=
lication and the underlying system; other attacks are also possible.
These issues affect Portail Web Php 2.5.1.1 and prior versions.
92. LWS php User Base 'unverified.inc.php' Local File Include Vulnerabili=
ty
BugTraq ID: 27964
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27964
Summary:
LWS php User Base is prone to a local file-include vulnerability because =
it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to access potentially sensiti=
ve information and execute arbitrary local scripts in the context of the =
affected application.
This issue affects php User Base 1.3 BETA; other versions may also be vul=
nerable.
93. LWS php User Base 'header.inc.php' Remote File Include Vulnerability
BugTraq ID: 27963
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27963
Summary:
LWS php User Base is prone to a remote file-include vulnerability because=
it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may facilitate a compromise of the application and the un=
derlying system; other attacks are also possible.
php User Base 1.3 BETA is vulnerable; other versions may also be affected=
.
94. LWS php Download Manager 'body.inc.php' Local File Include Vulnerabil=
ity
BugTraq ID: 27961
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27961
Summary:
LWS php Download Manager is prone to a local file-include vulnerability b=
ecause it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to access potentially sensiti=
ve information and execute arbitrary local scripts in the context of the =
affected application.
This issue affects php Download Manager 1.1 and 1.0; other versions may a=
lso be vulnerable.
95. PHPEcho CMS 'Smarty.class.php' Remote File Include Vulnerability
BugTraq ID: 27960
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27960
Summary:
PHPEcho CMS is prone to a remote file-include vulnerability because it fa=
ils to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may facilitate a compromise of the application and the un=
derlying system; other attacks are also possible.
PHPEcho CMS 2.0-rc3 is vulnerable; other versions may also be affected.
96. auraCMS 'lihatberita' Module 'id' Parameter SQL Injection Vulnerabili=
ty
BugTraq ID: 27959
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27959
Summary:
auraCMS is prone to an SQL-injection vulnerability because it fails to su=
fficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
97. Joomla! and Mambo 'com_hello_world' Component 'id' Parameter SQL Inje=
ction Vulnerability
BugTraq ID: 27956
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27956
Summary:
The Joomla! and Mambo 'com_hello_world' component is prone to an SQL-inje=
ction vulnerability because it fails to sufficiently sanitize user-suppli=
ed data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
98. PHP-Nuke Gallery Module 'aid' Parameter SQL Injection Vulnerability
BugTraq ID: 27957
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27957
Summary:
The Gallery module for PHP-Nuke is prone to an SQL-injection vulnerabilit=
y because it fails to sufficiently sanitize user-supplied data before usi=
ng it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Gallery 1.3 is vulnerable; other versions may also be affected.
99. PHP-Nuke Sections Module 'artid' Parameter SQL Injection Vulnerabilit=
y
BugTraq ID: 27958
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27958
Summary:
The Sections module for PHP-Nuke is prone to an SQL-injection vulnerabili=
ty because it fails to sufficiently sanitize user-supplied data before us=
ing it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
100. PHP-Nuke Recipe Module 'recipeid' Parameter SQL Injection Vulnerabil=
ity
BugTraq ID: 27955
Remote: Yes
Last Updated: 2008-02-25
Relevant URL: http://www.securityfocus.com/bid/27955
Summary:
The Recipe module for PHP-Nuke is prone to an SQL-injection vulnerability=
because it fails to sufficiently sanitize user-supplied data before usin=
g it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Recipe 1.3 is vulnerable; other versions may also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Worries over "good worms" rise again
By: Robert Lemos
A Microsoft researcher studies the use of self-propagation for patching, =
but for most of the security industry, any worm is a bad worm.
http://www.securityfocus.com/news/11506
2. Federal agencies miss deadline on secure configs
By: Robert Lemos
The U.S. government has made progress on moving to a standard configurati=
on for Windows XP and Windows Vista systems, but work remains.
http://www.securityfocus.com/news/11505
3. Universities fend off phishing attacks
By: Robert Lemos
Online fraudsters send e-mail messages that masquerade as help-desk reque=
sts for usernames and passwords.
http://www.securityfocus.com/news/11504
4. Antivirus firms, test labs to form standards group
By: Robert Lemos
The makers of antivirus software as well as independent and media-sponsor=
ed testing labs have agreed to create an industry group to standardize on=
methods of evaluating anti-malware programs.
http://www.securityfocus.com/news/11502
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Technical Support Engineer, San Mateo
http://www.securityfocus.com/archive/77/488605
2. [SJ-JOB] Disaster Recovery Coordinator, Kansas City
http://www.securityfocus.com/archive/77/488619
3. [SJ-JOB] Penetration Engineer, Redmond
http://www.securityfocus.com/archive/77/488578
4. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/488604
5. [SJ-JOB] Sales Engineer, San Jose
http://www.securityfocus.com/archive/77/488610
6. [SJ-JOB] Customer Support, South Plainfield
http://www.securityfocus.com/archive/77/488566
7. [SJ-JOB] Security Consultant, Copenhagen
http://www.securityfocus.com/archive/77/488574
8. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/488577
9. [SJ-JOB] Sales Engineer, Alpharetta
http://www.securityfocus.com/archive/77/488603
10. [SJ-JOB] Customer Support, South Plainfield
http://www.securityfocus.com/archive/77/488557
11. [SJ-JOB] Sales Engineer, Reston
http://www.securityfocus.com/archive/77/488575
12. [SJ-JOB] Software Engineer, Alpharetta
http://www.securityfocus.com/archive/77/488580
13. [SJ-JOB] Sales Engineer, San Jose
http://www.securityfocus.com/archive/77/488582
14. [SJ-JOB] Sales Engineer, Philadelphia
http://www.securityfocus.com/archive/77/488559
15. [SJ-JOB] Customer Support, South Plainfield
http://www.securityfocus.com/archive/77/488561
16. [SJ-JOB] Security Engineer, Canberra
http://www.securityfocus.com/archive/77/488562
17. [SJ-JOB] Sales Engineer, Canberra
http://www.securityfocus.com/archive/77/488563
18. [SJ-JOB] Sales Engineer, Ottawa
http://www.securityfocus.com/archive/77/488558
19. [SJ-JOB] Security Researcher, South Plainfield
http://www.securityfocus.com/archive/77/488564
20. [SJ-JOB] Certification & Accreditation Engineer, Arlinton
http://www.securityfocus.com/archive/77/488565
21. [SJ-JOB] Information Assurance Analyst, Herndon
http://www.securityfocus.com/archive/77/488573
22. [SJ-JOB] Security Architect, South Plainfield
http://www.securityfocus.com/archive/77/488581
23. [SJ-JOB] Certification & Accreditation Engineer, Arlington
http://www.securityfocus.com/archive/77/488549
24. [SJ-JOB] Sr. Security Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488554
25. [SJ-JOB] Sr. Security Analyst, Arlington
http://www.securityfocus.com/archive/77/488555
26. [SJ-JOB] Sr. Security Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488556
27. [SJ-JOB] Senior Software Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488576
28. [SJ-JOB] Security Consultant, Copenhagen
http://www.securityfocus.com/archive/77/488579
29. [SJ-JOB] Sr. Security Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488550
30. [SJ-JOB] Sales Engineer, Deerfield Beach
http://www.securityfocus.com/archive/77/488552
31. [SJ-JOB] Sr. Security Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488560
32. [SJ-JOB] Security Consultant, Boston
http://www.securityfocus.com/archive/77/488544
33. [SJ-JOB] Sr. Security Engineer, South Plainfield
http://www.securityfocus.com/archive/77/488546
34. [SJ-JOB] Application Security Architect, South Plainfield
http://www.securityfocus.com/archive/77/488547
35. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/488548
36. [SJ-JOB] Principal Software Engineer, Deerfield Beach
http://www.securityfocus.com/archive/77/488541
37. [SJ-JOB] Security Architect, LONDON
http://www.securityfocus.com/archive/77/488542
38. [SJ-JOB] Sales Engineer, Dallas
http://www.securityfocus.com/archive/77/488543
39. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/488545
40. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/488553
41. [SJ-JOB] Management, Pentagon City
http://www.securityfocus.com/archive/77/488534
42. [SJ-JOB] Jr. Security Analyst, Washington, DC
http://www.securityfocus.com/archive/77/488536
43. [SJ-JOB] Manager, Information Security, Chicago
http://www.securityfocus.com/archive/77/488538
44. [SJ-JOB] Management, Reston
http://www.securityfocus.com/archive/77/488539
45. [SJ-JOB] Security Engineer, Reston
http://www.securityfocus.com/archive/77/488540
46. [SJ-JOB] Director, Computer Security, New Jersey
http://www.securityfocus.com/archive/77/488518
47. [SJ-JOB] Management, San Mateo
http://www.securityfocus.com/archive/77/488519
48. [SJ-JOB] Training / Awareness Specialist, San Mateo
http://www.securityfocus.com/archive/77/488520
49. [SJ-JOB] Security Engineer, New Jersey
http://www.securityfocus.com/archive/77/488533
50. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/488523
51. [SJ-JOB] Management, Alpharetta
http://www.securityfocus.com/archive/77/488526
52. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/488530
53. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/488537
54. [SJ-JOB] Auditor, Columbia
http://www.securityfocus.com/archive/77/488535
55. [SJ-JOB] Application Security Engineer, Ottawa
http://www.securityfocus.com/archive/77/488513
56. [SJ-JOB] Sales Representative, Boston
http://www.securityfocus.com/archive/77/488516
57. [SJ-JOB] Software Engineer, Palm Beach Gardens
http://www.securityfocus.com/archive/77/488521
58. [SJ-JOB] Sales Representative, Atlanta
http://www.securityfocus.com/archive/77/488527
59. [SJ-JOB] Database Security Architect, Houston
http://www.securityfocus.com/archive/77/488529
60. [SJ-JOB] Technology Risk Consultant, Various
http://www.securityfocus.com/archive/77/488504
61. [SJ-JOB] Information Assurance Analyst, London
http://www.securityfocus.com/archive/77/488508
62. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/488517
63. [SJ-JOB] Security Consultant, Thousand Oaks
http://www.securityfocus.com/archive/77/488522
64. [SJ-JOB] Security Engineer, Huntsville
http://www.securityfocus.com/archive/77/488507
65. [SJ-JOB] Forensics Engineer, Various
http://www.securityfocus.com/archive/77/488510
66. [SJ-JOB] Application Security Engineer, Dover
http://www.securityfocus.com/archive/77/488512
67. [SJ-JOB] Security Consultant, Various
http://www.securityfocus.com/archive/77/488524
68. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/488505
69. [SJ-JOB] Penetration Engineer, Dallas
http://www.securityfocus.com/archive/77/488509
70. [SJ-JOB] Threat Analyst, Huntsville
http://www.securityfocus.com/archive/77/488532
71. [SJ-JOB] Sr. Security Engineer, Stamford
http://www.securityfocus.com/archive/77/488501
72. [SJ-JOB] Sr. Security Engineer, Washington, DC Metro Area
http://www.securityfocus.com/archive/77/488525
73. [SJ-JOB] Chief Scientist, Huntsville
http://www.securityfocus.com/archive/77/488528
74. [SJ-JOB] Chief Scientist, Huntsville
http://www.securityfocus.com/archive/77/488531
75. [SJ-JOB] Security Engineer, Huntsville
http://www.securityfocus.com/archive/77/488503
76. [SJ-JOB] Security Engineer, Kansas City
http://www.securityfocus.com/archive/77/488506
77. [SJ-JOB] Security Engineer, San Francisco
http://www.securityfocus.com/archive/77/488511
78. [SJ-JOB] Certification & Accreditation Engineer, Washington DC
http://www.securityfocus.com/archive/77/488497
79. [SJ-JOB] Security Consultant, Thousand Oaks
http://www.securityfocus.com/archive/77/488498
80. [SJ-JOB] Security Engineer, Seattle
http://www.securityfocus.com/archive/77/488499
81. [SJ-JOB] Sr. Security Engineer, Austin/Richardson
http://www.securityfocus.com/archive/77/488500
82. [SJ-JOB] Security Consultant, Thousand Oaks
http://www.securityfocus.com/archive/77/488502
83. [SJ-JOB] Security Engineer, Arlington
http://www.securityfocus.com/archive/77/488487
84. [SJ-JOB] Information Assurance Engineer, Annapolis Junction
http://www.securityfocus.com/archive/77/488488
85. [SJ-JOB] Senior Software Engineer, St. Paul
http://www.securityfocus.com/archive/77/488491
86. [SJ-JOB] Management, Phoenix
http://www.securityfocus.com/archive/77/488494
87. [SJ-JOB] Management, New York
http://www.securityfocus.com/archive/77/488496
88. [SJ-JOB] CISO, London
http://www.securityfocus.com/archive/77/488489
89. [SJ-JOB] Application Security Architect, Washington
http://www.securityfocus.com/archive/77/488490
90. [SJ-JOB] Software Engineer, Columbia
http://www.securityfocus.com/archive/77/488495
V. INCIDENTS LIST SUMMARY
---------------------------
1. CanSecWest 2008 Mar 26-28
http://www.securityfocus.com/archive/75/488624
2. Possible Mail server compromise ?
http://www.securityfocus.com/archive/75/487488
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. GNU objdump 2.15 [FreeBSD] 2004-05-23 shows: ... "BFD: Please report t=
his bug." While analyzing crafted ELF.
http://www.securityfocus.com/archive/82/488729
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter
http://www.securityfocus.com/archive/88/488429
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. CanSecWest 2008 Mar 26-28
http://www.securityfocus.com/archive/91/488611
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: CISO Executive Summit & Roundtable-Middle Eas=
t, 12th-14th May, Bahrain, Ritz-Carlton=20
Over 20 speakers from across The Middle East, Europe, U.S & Asia will gat=
her together for the MIS training.s CISO Executive Summit Middle East, Sh=
eraton Bahrain Hotel, Kingdom of Bahrain 12-14 May 2008. This dynamic int=
ernational speaker line up will provide a broad perspective on the securi=
ty threats faced today and in the future. Take away actionable strategies=
that will enable you to limit the risk within your organisation. Interna=
tional case studies from the industries leading associations and organisa=
tions will provide you with the knowledge to identify the warning signs o=
f key threats to your company.=20
Register now at www.mistieruope.com/CISOME