SecurityFocus Newsletter #456

[email protected] 4 Jun 2008 19:26:02 -0000
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #456
----------------------------------------

This issue is sponsored by Black Hat USA:

Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
 Network with 4,000 delegates from 50 nations.  Visit product displays by=
 30 top sponsors in a relaxed setting.=20
www.blackhat.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Anti-Social Networking
       2. Thinking Beyond the Ivory Towers
II.   BUGTRAQ SUMMARY
       1. ikiwiki Blank Password Authentication Bypass Vulnerability
       2. Linux Kernel 'fcntl_setlk()' SMP Ordering Local Denial of Servi=
ce Vulnerability
       3. International Components for Unicode Library (libicu) Multiple =
Memory Corruption Vulnerabilities
       4. Xerox DocuShare Multiple Cross-Site Scripting Vulnerabilities
       5. dvbbs 'login.asp' Multiple SQL Injection Vulnerabilities
       6. Adobe Flash Player Multimedia File Remote Buffer Overflow Vulne=
rability
       7. PicoFlat CMS 'pagina' Parameter Local File Include and Director=
y Traversal Vulnerabilities
       8. SyntaxCMS 'upload.php' Arbitrary File Upload Vulnerability
       9. Pan '.nzb' File Parsing Heap Overflow Vulnerability
       10. Adobe Acrobat Reader Unspecified Remote Denial Of Service Vuln=
erability
       11. Wikiwig WK_lang.PHP Remote File Include Vulnerability
       12. QEMU Multiple Local Vulnerabilities
       13. Stunnel OCSP Certificate Validation Security Bypass Vulnerabil=
ity
       14. KAME Project IPv6 IPComp Header Denial Of Service Vulnerabilit=
y
       15. MPlayer 'sdpplin_parse()' RTSP Integer Overflow Vulnerability
       16. Mongrel 'DirHandler' Class Directory Traversal Information Dis=
closure Vulnerability
       17. Libpng Library ICC Profile Chunk Off-By-One Denial of Service =
Vulnerability
       18. Libpng Library Multiple Remote Denial of Service Vulnerabiliti=
es
       19. Microsoft Jet Database Engine MDB File Parsing Remote Buffer O=
verflow Vulnerability
       20. Apple Mac OS X ubc_subr.c Local Denial of Service Vulnerabilit=
y
       21. Adobe Flash Player Unspecified DNS Rebinding Vulnerability
       22. Adobe Flash Player SWF File 'DeclareFunction2' ActionScript Ta=
g Remote Code Execution Vulnerability
       23. Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross=
-Site Scripting Vulnerability
       24. Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerab=
ility
       25. Apache HTTP Server Mod_Cache Denial of Service Vulnerability
       26. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
       27. Apple Mac OS X Image Capture Local Arbitrary File Overwrite Vu=
lnerability
       28. RETIRED: Apple Mac OS X 2008-003 Multiple Security Vulnerabili=
ties
       29. Apple Mac OS X Single Sign-On 'sso_util' Local Information Dis=
closure Vulnerability
       30. Linux Kernel 'dnotify.c' Local Race Condition Vulnerability
       31. Linux Kernel PowerPC 'chrp/setup.c' NULL Pointer Dereference D=
enial of Serviced Vulnerability
       32. Linux Kernel Tehuti Network Driver 'BDX_OP_WRITE' Memory Corru=
ption Vulnerability
       33. Computer Associates eTrust Secure Content Manager Multiple Vul=
nerabilities
       34. Gnome Evolution iCalendar Multiple Buffer Overflow Vulnerabili=
ties
       35. DotNetNuke Prior to 4.8.3 Multiple Remote Vulnerabilites
       36. Apple Mac OS X ImageIO JPEG2000 Handling Remote Code Execution=
 Vulnerability
       37. Apple Mac OS X ImageIO BMP/GIF Image Information Disclosure Vu=
lnerability
       38. libxslt XSL File Processing Buffer Overflow Vulnerability
       39. mtr 'split.c' Remote Stack Buffer Overflow Vulnerability
       40. Libpng Library Unknown Chunk Handler Vulnerability
       41. 'imlib2' Library Multiple Buffer Overflow Vulnerabilities
       42. libvorbis Multiple Remote Vulnerabilities
       43. RETIRED: Microsoft May 2008 Advance Notification Multiple Vuln=
erabilities
       44. SiteXS CMS 'upload.php' Arbitrary File Upload Vulnerability
       45. Apple Mac OS X Mail Memory Corruption Vulnerability
       46. TotalECommerce SQL Injection Vulnerability
       47. Apple Mac OS X Image Capture Webserver Directory Traversal Vul=
nerability
       48. Apple Mac OS X Apple Type Services PDF Handling Code Execution=
 Vulnerability
       49. Apple Mac OS X CFNetwork SSL Client Certificate Handling Infor=
mation Disclosure Vulnerability
       50. Apple Mac OS X CoreFoundation CFData Object Handling Code Exec=
ution Vulnerability
       51. Apple Mac OS X AFP Server File Sharing Unauthorized File Acces=
s Vulnerability
       52. Apple Mac OS X AppKit Malformed File Remote Code Execution Vul=
nerability
       53. Apple Mac OS X iCal '.ics' File Handling Remote Code Execution=
 Vulnerability
       54. Apple Mac OS X CUPS Debug Logging Information Disclosure Vulne=
rability
       55. RETIRED: SiteXS CMS 'adm/visual/upload.php' Arbitrary File Upl=
oad Vulnerability
       56. Apple Mac OS X Pixlet Video Multiple Unspecified Memory Corrup=
tion Vulnerabilities
       57. Apple Mac OS X International Components for Unicode Informatio=
n Disclosure Vulnerability
       58. Apple Mac OS X Help Viewer 'help:topic' URI Buffer Overflow Vu=
lnerability
       59. Apple Mac OS X CoreTypes Unsafe Content Warning Weakness
       60. Booby 'renderer' Parameter Multiple Local and Remote File Incl=
ude Vulnerabilities
       61. HP Instant Support ActiveX Control in 'HPISDataManager.dll' Ar=
bitrary File Download Vulnerability
       62. HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspe=
cified Code Execution Vulnerabilities
       63. QuickerSite Multiple Vulnerabilities
       64. LimeSurvey Prior to 1.71 Multiple Remote Vulnerabilities
       65. meBiblio Multiple Input Validation Vulnerabilities
       66. ComicShout 'news.php' SQL Injection Vulnerability
       67. Phoenix View CMS 'admin_frame.php' Cross-Site Scripting Vulner=
ability
       68. Apple Mac OS X CoreGraphics PDF Handling Code Execution Vulner=
ability
       69. BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Mul=
tiple Vulnerabilities
       70. CMSimple Multiple Input Validation Vulnerabilities
       71. OpenSSL Multiple Denial of Service Vulnerabilities
       72. BP Blog Multiple SQL Injection Vulnerabilities
       73. Linux Kernel 'ipip6_rcv()' Remote Denial of Service Vulnerabil=
ity
       74. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow=
 Vulnerabilities
       75. Linux Kernel SPARC 'mmap()' Denial Of Service Vulnerability
       76. Sun Cluster Global File System Unspecified Security Vulnerabil=
ity
       77. Apple Safari and Microsoft Windows Client-side Code Execution =
Vulnerability
       78. freeSSHd SFTP 'opendir' Buffer Overflow Vulnerability
       79. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overfl=
ow Vulnerability
       80. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
       81. ASUS Remote Console DPC Proxy Buffer Overflow Vulnerability
       82. Samba Send_MailSlot Stack-Based Buffer Overflow Vulnerability
       83. Sun Solaris Print Service Unspecified Remote Code Execution Vu=
lnerability
       84. Debian OpenSSL Package Random Number Generator Weakness
       85. GnuTLS Prior to 2.2.5 Multiple Remote Vulnerabilities
       86. Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
       87. Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
       88. Linux Kernel 'hrtimer_forward()' Local Denial of Service Vulne=
rability
       89. TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
       90. PsychoStats Multiple SQL Injection Vulnerabilities
       91. LokiCMS 'admin.php' Security Bypass Vulnerability
       92. Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remo=
te Code Execution Vulnerability
       93. Apache Tomcat Host Manager Cross Site Scripting Vulnerability
       94. Alt-N MDaemon IMAP Server FETCH Command Remote Buffer Overflow=
 Vulnerability
       95. VMware VMCI Arbitrary Code Execution Vulnerability
       96. DotNetNuke 'Default.aspx' Cross-Site Scripting Vulnerability
       97. Joomla! and Mambo MambAds Component 'ma_cat' Parameter SQL Inj=
ection Vulnerability
       98. TCL/TK Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulne=
rability
       99. TCL/TK Tk Toolkit TKIMGGIF.C Buffer Overflow Vulnerability
       100. Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
III.  SECURITYFOCUS NEWS
       1. Hired gun blamed for business outage
       2. Legal experts wary of MySpace hacking charges
       3. Admins warned of brute-force SSH attacks
       4. Groups warn travelers to limit laptop data
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Security Engineer, San Antonio
       2. [SJ-JOB] Security Consultant, Dallas
       3. [SJ-JOB] Security Auditor, San Antonio
       4. [SJ-JOB] Technical Support Engineer, Alpharetta
       5. [SJ-JOB] Sales Engineer, Chicago
       6. [SJ-JOB] Manager, Information Security, Chicago
       7. [SJ-JOB] Application Security Architect, San Fransisco
       8. [SJ-JOB] Certification & Accreditation Engineer, San Antonio
       9. [SJ-JOB] Management, Newark
       10. [SJ-JOB] Sr. Security Analyst, Seattle/Bellevue
       11. [SJ-JOB] Security Consultant, Any City
       12. [SJ-JOB] Information Assurance Analyst, Information Risk Analy=
st
       13. [SJ-JOB] Sales Representative, Chicago
       14. [SJ-JOB] Sr. Security Analyst, San Antonio
       15. [SJ-JOB] Threat Analyst, Washington
       16. [SJ-JOB] Penetration Engineer, Washington
       17. [SJ-JOB] Security Engineer, Linthicum Heights
       18. [SJ-JOB] Instructor, any
       19. [SJ-JOB] Security Engineer, Pune
       20. [SJ-JOB] Sales Engineer, Alpharetta
       21. [SJ-JOB] Forensics Engineer, London
       22. [SJ-JOB] Penetration Engineer, sydney
       23. [SJ-JOB] Security Auditor, Chennai
       24. [SJ-JOB] Sales Engineer, San Francisco
V.    INCIDENTS LIST SUMMARY
       1. Unusual entry in Apache logs
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. ISA as a proxy
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
       1. ARP handler Inspection tool released
       2. Spam sent through server using authid=3Dapache or mysql
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Anti-Social Networking
By Mark Rasch
On May 15, 2008, a federal grand jury Los Angeles indicted 49-year-old Lo=
ri Drew of O.Fallon, Missouri, on charges of unauthorized access to a com=
puter, typically used in hacking cases. Yet, Drew's alleged actions had l=
ittle to do with computer intrusions.=20
http://www.securityfocus.com/columnists/473

2. Thinking Beyond the Ivory Towers
By Dave Aitel
In the information-security industry, there are clear and vast gaps in th=
e way academia interacts with professional researchers. While these gaps =
will be filled in due time, their existence means that security professio=
nals outside the hallowed halls of colleges and universities need to be a=
ware of the differences in how researchers and professionals think.=20
http://www.securityfocus.com/columnists/472


II.  BUGTRAQ SUMMARY
--------------------
1. ikiwiki Blank Password Authentication Bypass Vulnerability
BugTraq ID: 29479
Remote: Yes
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29479
Summary:
The 'ikiwiki' program is prone to an authentication-bypass vulnerability.

An attacker can exploit this issue to gain unauthorized access to the aff=
ected application.=20

Versions between ikiwiki 1.34 and 2.47 are vulnerable.

2. Linux Kernel 'fcntl_setlk()' SMP Ordering Local Denial of Service Vuln=
erability
BugTraq ID: 29076
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29076
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to trigger kernel crashes, denying servi=
ce to legitimate users.

Versions prior to Linux kernel 2.6.25.2 and 2.4.36.4 are vulnerable.

3. International Components for Unicode Library (libicu) Multiple Memory =
Corruption Vulnerabilities
BugTraq ID: 27455
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/27455
Summary:
The International Components for Unicode library (libicu) is prone to mul=
tiple memory-corruption vulnerabilities.

Successfully exploiting these issues allows remote attackers to corrupt a=
nd overflow memory and possibly execute remote code. Failed exploit attem=
pts will likely crash applications.

These issues affect libicu 3.8.1 and prior versions.

4. Xerox DocuShare Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 29430
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29430
Summary:
Xerox DocuShare is prone to multiple cross-site scripting vulnerabilities=
.

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may help the attacker steal cookie-based authentication credentials=
 and launch other attacks.

Xerox DocuShare 6 and prior versions are vulnerable.

5. dvbbs 'login.asp' Multiple SQL Injection Vulnerabilities
BugTraq ID: 29429
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29429
Summary:
The 'dvbbs' program is prone to multiple SQL-injection vulnerabilities be=
cause it fails to sufficiently sanitize user-supplied data before using i=
t in an SQL query.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

These issues affect dvbbs 8.2; other versions may also be affected.

6. Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerabilit=
y
BugTraq ID: 28695
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/28695
Summary:
Adobe Flash Player is prone to a remote  buffer-overflow vulnerability wh=
en handling multimedia files with certain tags.

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in denial-of-service conditions.

Adobe Flash Player 9.0.115.0 and earlier versions are affected.

NOTE: This issue has been fixed in all versions of Adobe Flash Player 9.0=
.124.0.

Initial investigations suggested that the vulnerability had not been patc=
hed in the standalone Adobe Flash Player version 9.0.124.0 for Linux and =
the standalone Adobe Flash Player version 9.0.124.0 with debug capabiliti=
es for Microsoft Windows. The observed behavior that led to this initial =
conclusion has since been confirmed by Adobe as intended by design.

7. PicoFlat CMS 'pagina' Parameter Local File Include and Directory Trave=
rsal Vulnerabilities
BugTraq ID: 29424
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29424
Summary:
PicoFlat CMS is prone to a local file-include vulnerability and a directo=
ry-traversal vulnerability because it fails to properly sanitize user-sup=
plied input.

An attacker can exploit these vulnerabilities using directory-traversal s=
trings to include local scripts in the context of the application. This m=
ay allow the attacker to access sensitive information that may aid in fur=
ther attacks.

PicoFlat CMS 0.5.9 is vulnerable; other versions may also be affected.

8. SyntaxCMS 'upload.php' Arbitrary File Upload Vulnerability
BugTraq ID: 29422
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29422
Summary:
SyntaxCMS is prone to a vulnerability that lets remote attackers upload a=
nd execute arbitrary script code because the application fails to sanitiz=
e user-supplied input. =20

An attacker can leverage this issue to execute arbitrary script code on a=
n affected computer with the privileges of the webserver process.

SyntaxCMS 1.3 is vulnerable; other versions may also be affected.

9. Pan '.nzb' File Parsing Heap Overflow Vulnerability
BugTraq ID: 29421
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29421
Summary:
Pan is prone to a heap-based buffer-overflow vulnerability because it fai=
ls to properly bounds-check user-supplied input. The vulnerability occurs=
 when handling malformed '.nzb' files.

Successfully exploiting this issue allows attackers to execute arbitrary =
code with the privileges of a user running the application. Failed exploi=
t attempts will result in a denial-of-service condition.

10. Adobe Acrobat Reader Unspecified Remote Denial Of Service Vulnerabili=
ty
BugTraq ID: 29420
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29420
Summary:
Acrobat Reader is prone to a remote denial-of-service vulnerability.  The=
 cause of this issue is unknown.
=20
Exploiting this issue allows remote attackers to crash the application an=
d trigger denial-of-service conditions, denying further service to legiti=
mate users. Given the nature of this issue, code execution may be possibl=
e, but this has not been confirmed.

11. Wikiwig WK_lang.PHP Remote File Include Vulnerability
BugTraq ID: 18291
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/18291
Summary:
Wikiwig is prone to a remote file-include vulnerability. This issue is du=
e to a failure in the application to properly sanitize user-supplied inpu=
t.

An attacker can exploit this issue to include an arbitrary remote file co=
ntaining malicious PHP code and execute it in the context of the webserve=
r process. This may allow the attacker to compromise the application and =
the underlying system; other attacks are also possible.

Versions prior to Wikiwig 4.3 are vulnerable.

12. QEMU Multiple Local Vulnerabilities
BugTraq ID: 23731
Remote: No
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/23731
Summary:
QEMU is prone to multiple locally exploitable buffer-overflow and denial-=
of-service vulnerabilities. The buffer-overflow issues occur because the =
software fails to properly check boundaries of user-supplied input when c=
opying it to insufficiently sized memory buffers. The denial-of-service i=
ssues stem from design errors.

Attackers may be able to exploit these issues to escalate privileges, exe=
cute arbitrary code, or trigger denial-of-service conditions in the conte=
xt of the affected applications.

13. Stunnel OCSP Certificate Validation Security Bypass Vulnerability
BugTraq ID: 29309
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/29309
Summary:
Stunnel is prone to a security-bypass vulnerability because the OCSP func=
tionality fails to properly check revoked certificates.

Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks by impersonating trusted servers and authenticating with =
a revoked certificate. This will aid in further attacks.

This issue affects versions prior to Stunnel 4.24.

14. KAME Project IPv6 IPComp Header Denial Of Service Vulnerability
BugTraq ID: 27642
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/27642
Summary:
The KAME project is prone to a denial-of-service vulnerability.

Successfully exploiting this issue allows remote attackers to crash affec=
ted computers, denying service to legitimate users.

Operating systems that have IPv6 networking derived from the KAME project=
's IPv6 implementation may be vulnerable to this issue. Please see the re=
ferences for a list of vendors that may be affected by this issue.

15. MPlayer 'sdpplin_parse()' RTSP Integer Overflow Vulnerability
BugTraq ID: 28851
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/28851
Summary:
MPlayer is prone to an interger-overflow vulnerability because it fails t=
o perform adequate checks on externally supplied input.

Attackers can leverage this vulnerability to execute arbitrary code in th=
e context of the application. Failed attacks will cause denial-of-service=
 conditions.

16. Mongrel 'DirHandler' Class Directory Traversal Information Disclosure=
 Vulnerability
BugTraq ID: 27133
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/27133
Summary:
Mongrel is prone to an information-disclosure vulnerability because it fa=
ils to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to view sensitive files within the con=
text of the webserver process. Information obtained may lead to other att=
acks.

 This issue affects Mongrel 1.0.4 and versions prior to 1.1.3.

17. Libpng Library ICC Profile Chunk Off-By-One Denial of Service Vulnera=
bility
BugTraq ID: 25957
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/25957
Summary:
The 'libpng' library is prone to a remote denial-of-service vulnerability=
 because the library fails to handle malicious PNG files.=20

Successful exploits may allow remote attackers to cause denial-of-service=
 conditions on computers running the affected library.

This issue affects 'libpng' 1.2.21 and prior versions.

18. Libpng Library Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 25956
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/25956
Summary:
The 'libpng' library is prone to multiple remote denial-of-service vulner=
abilities because the library fails to handle malicious PNG files.=20

Successful exploits may allow remote attackers to cause denial-of-service=
 conditions on computers running the affected library.

These issues affect 'libpng' 1.2.20 and prior versions.

19. Microsoft Jet Database Engine MDB File Parsing Remote Buffer Overflow=
 Vulnerability
BugTraq ID: 26468
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/26468
Summary:
Microsoft Jet Database Engine is prone to a buffer-overflow vulnerability=
 because it fails to properly bounds-check user-supplied data.

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of a user running the application. Successful exploits wi=
ll compromise the affected application and possibly the underlying comput=
er. Failed attacks will likely cause denial-of-service conditions.

NOTE: Further details report that attackers are using malicious Word file=
s to load specially crafted MDB files. Microsoft has released a knowledge=
 base article (950627) documenting this attack vector.

This issue does not affect Windows Server 2003 Service Pack 2, Windows XP=
 Service Pack 3, Windows XP x64 edition Server Pack 2, Windows Vista, Win=
dows Vista Service Pack 1 and Windows Server 2008 because they run a vers=
ion of the Jet Database Engine that isn't vulnerable.
 =20
  This issue does affect the Jet Database Engine, Microsoft Word 2000 Ser=
vice Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Serv=
ice Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007, and =
Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP,=
 or Windows Server 2003 Service Pack 1.

20. Apple Mac OS X ubc_subr.c Local Denial of Service Vulnerability
BugTraq ID: 26840
Remote: No
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/26840
Summary:
Apple Mac OS X is prone to a local denial-of-service vulnerability becaus=
e the kernel fails to properly handle exceptional conditions.

Exploiting this issue allows local, unprivileged users to crash affected =
kernels, denying further service to legitimate users.

21. Adobe Flash Player Unspecified DNS Rebinding Vulnerability
BugTraq ID: 28697
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/28697
Summary:
Adobe Flash Player is prone to a vulnerability with an unspecified impact=
. The issue can be exploited by DNS rebinding.=20

Successfully exploiting this issue could allow the attacker to bypass the=
 application's same-origin policy; other attacks are also possible.
=20
NOTE: This issue may be a variant of the issue described in BID 26930, bu=
t currently not enough details are available to verify this. We will upda=
te this BID as more information emerges.
=20
Adobe Flash Player 9.0.115.0 and earlier versions are affected.

22. Adobe Flash Player SWF File 'DeclareFunction2' ActionScript Tag Remot=
e Code Execution Vulnerability
BugTraq ID: 28694
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/28694
Summary:
Adobe Flash Player is prone to a remote code-execution vulnerability when=
 handling certain embedded ActionScript objects.

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in denial-of-service conditions.

Adobe Flash Player 9.0.115.0 and earlier versions are affected.

23. Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site S=
cripting Vulnerability
BugTraq ID: 27237
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/27237
Summary:
The Apache HTTP Server 'mod_status' module is prone to a cross-site scrip=
ting vulnerability because the application fails to properly sanitize use=
r-supplied input.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may allow the attacker to steal cookie-based authentication credentia=
ls and to launch other attacks. Reportedly, attackers can also use this i=
ssue to redirect users' browsers to  arbitrary locations, which may aid i=
n phishing attacks.

The issue affects versions       prior to Apache 2.2.7-dev, 2.0.62-dev, a=
nd 1.3.40-dev.

24. Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability
BugTraq ID: 26838
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/26838
Summary:
Apache is prone to a cross-site scripting vulnerability because the appli=
cation fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

This issue affects the following:

- The 'mod_imagemap' module in Apache 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, =
and 2.2.0=20

- The 'mod_imap' module in Apache 1.3.39, 1.3.37, 1.3.36, 1.3.35, 1.3.34,=
 1.3.33, 1.3.32, 1.3.31, 1.3.29, 1.3.28, 1.3.27, 1.3.26, 1.3.24, 1.3.22, =
1.3.20, 1.3.19, 1.3.17, 1.3.14, 1.3.12, 1.3.11, 1.3.9, 1.3.6, 1.3.4, 1.3.=
3, 1.3.2, 1.3.1, and 1.3.0.

25. Apache HTTP Server Mod_Cache Denial of Service Vulnerability
BugTraq ID: 24649
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/24649
Summary:
The Apache mod_cache module is prone to a denial-of-service vulnerability=
.

A remote attacker may be able to exploit this issue to crash the child pr=
ocess. This could lead to denial-of-service conditions if the server is u=
sing a multithreaded Multi-Processing Module (MPM).

26. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 19204
Remote: Yes
Last Updated: 2008-05-29
Relevant URL: http://www.securityfocus.com/bid/19204
Summary:
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition.=20

The vulnerability arising in the mod_rewrite module's ldap scheme handlin=
g allows for potential memory corruption when an attacker exploits certai=
n rewrite rules.=20

An attacker may exploit this issue to trigger a denial-of-service conditi=
on. Reportedly, arbitrary code execution may be possible as well.

27. Apple Mac OS X Image Capture Local Arbitrary File Overwrite Vulnerabi=
lity
BugTraq ID: 29521
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29521
Summary:
Apple Mac OS X Image Capture is prone to a vulnerability that allows loca=
l attackers to overwrite arbitrary files.=20

A local attacker can exploit this issue to overwrite files with the privi=
leges of another user running the affected application.

This issue affects Mac OS X 10.4.11 and Mac OS X Server 10.4.11.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

28. RETIRED: Apple Mac OS X 2008-003 Multiple Security Vulnerabilities
BugTraq ID: 29412
Remote: Yes
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29412
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities that have be=
en addressed in Security Update 2008-003 and Mac OS X/Mac OS X Server 10.=
5.3.

The security update addresses a total of 19 new vulnerabilities that affe=
ct the AFP Server, AppKit, Apple Pixlet Video, ATS, CFNetwork, CoreFounda=
tion, CoreGraphics, CoreTypes, CUPS, Help Viewer, iCal, International Com=
ponents for Unicode, Image Capture, ImageIO, Kernel, Mail, Single Sign-On=
, and Wiki Server components of Mac OS X.

NOTE: This BID is being retired; the following individual records have be=
en created to better document the issues:

29480 Apple Mac OS X CoreGraphics PDF Handling Code Execution Vulnerabili=
ty
29481 Apple Mac OS X CoreTypes Unsafe Content Warning Weakness     =20
29483 Apple Mac OS X Help Viewer 'help:topic' URI Buffer Overflow Vulnera=
bility   =20
29484 Apple Mac OS X CUPS Debug Logging Information Disclosure Vulnerabil=
ity
29486 Apple Mac OS X iCal '.ics' File Handling Remote Code Execution Vuln=
erability
29487 Apple Mac OS X AppKit Malformed File Remote Code Execution Vulnerab=
ility
29488 Apple Mac OS X International Components for Unicode Information Dis=
closure Vulnerability=20
29489 Apple Mac OS X Pixlet Video Multiple Unspecified Memory Corruption =
Vulnerabilities=20
29490 Apple Mac OS X AFP Server File Sharing Unauthorized File Access Vul=
nerability
29491 Apple Mac OS X CoreFoundation CFData Object Handling Code Execution=
 Vulnerability
29492 Apple Mac OS X Apple Type Services PDF Handling Code Execution Vuln=
erability         =20
29493 Apple Mac OS X CFNetwork SSL Client Certificate Handling Informatio=
n Disclosure Vulnerability
29500 Apple Mac OS X Mail Memory Corruption Vulnerability         =20
29501 Apple Mac OS X Image Capture Webserver Directory Traversal Vulnerab=
ility
29511 Apple Mac OS X Wiki Server User Name Enumeration Weakness
29513 Apple Mac OS X ImageIO BMP/GIF Image Information Disclosure Vulnera=
bility
29514 Apple Mac OS X ImageIO JPEG2000 Handling Remote Code Execution Vuln=
erability
29520 Apple Mac OS X Single Sign-On 'sso_util' Local Information Disclosu=
re Vulnerability
29521 Apple Mac OS X Image Capture Local Arbitrary File Overwrite Vulnera=
bility

29. Apple Mac OS X Single Sign-On 'sso_util' Local Information Disclosure=
 Vulnerability
BugTraq ID: 29520
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29520
Summary:
Apple Mac OS X is prone to a local information-disclosure vulnerability t=
hat affects the Single Sign-On 'sso_util' utility.

Local attackers can leverage this issue to gain access to sensitive infor=
mation that will aid in further attacks.

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

30. Linux Kernel 'dnotify.c' Local Race Condition Vulnerability
BugTraq ID: 29003
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29003
Summary:
The Linux kernel is prone to a local race-condition vulnerability.

A local attacker may exploit this issue to crash the computer or to gain =
elevated privileges on the affected computer.

31. Linux Kernel PowerPC 'chrp/setup.c' NULL Pointer Dereference Denial o=
f Serviced Vulnerability
BugTraq ID: 27555
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/27555
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.=20

Attackers can exploit this issue to crash the affected kernel, denying se=
rvice to legitimate users.

This issue affects Linux kernel 2.4.21 through 2.6.18-53 running on the P=
owerPC architecture.

32. Linux Kernel Tehuti Network Driver 'BDX_OP_WRITE' Memory Corruption V=
ulnerability
BugTraq ID: 29014
Remote: No
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29014
Summary:
The Linux kernel is prone to a memory-corruption vulnerability because of=
 insufficient boundary checks in the Tehuti network driver.

Local attackers could exploit this issue to cause denial-of-service condi=
tions, bypass certain security restrictions, and potentially access sensi=
tive information or gain elevated privileges.

These issues affect versions prior to Linux 2.6.25.1.

33. Computer Associates eTrust Secure Content Manager Multiple Vulnerabil=
ities
BugTraq ID: 29528
Remote: Yes
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29528
Summary:
Computer Associates eTrust Secure Content Manages is prone to multiple vu=
lnerabilities due to unspecified boundary condition errors.

Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code in the context of the application or cause denial-of-service=
 conditions.

These issues affect Computer Associates eTrust Secure Content Manager 8.0=
.

34. Gnome Evolution iCalendar Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 29527
Remote: Yes
Last Updated: 2008-06-04
Relevant URL: http://www.securityfocus.com/bid/29527
Summary:
Gnome Evolution is prone to multiple buffer-overflow vulnerabilities beca=
use it fails to adequately bounds-check user-supplied input before copyin=
g it to insufficiently sized buffers. The issues arise when the applicati=
on handles the iCalendar attachments.

Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code in the context of the application. Failed exploit attempts w=
ill likely crash the application.

Gnome Evolution 2.21.1 is vulnerable to these issues; other versions may =
also be affected.

35. DotNetNuke Prior to 4.8.3 Multiple Remote Vulnerabilites
BugTraq ID: 29482
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29482
Summary:
DotNetNuke is prone to multiple remote issues:

- A denial-of-service vulnerability=20
- A security-bypass vulnerability
- An information-disclosure weakness.=20

An attacker can exploit these issues to cause the application to stop res=
ponding, to upload arbitrary 'safe' files to restricted folders, and to o=
btain sensitive information.

These issues affect DotNetNuke 3.0 to 4.8.2.

36. Apple Mac OS X ImageIO JPEG2000 Handling Remote Code Execution Vulner=
ability
BugTraq ID: 29514
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29514
Summary:
Apple Mac OS X is prone to a vulnerability that lets attackers run arbitr=
ary code because the ImageIO component fails to properly handle certain i=
mage files.

Successful exploits will allow an attacker to run arbitrary code in the c=
ontext of the affected application. Failed exploit attempts will likely r=
esult in denial-of-service conditions.

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.
 =20
NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

37. Apple Mac OS X ImageIO BMP/GIF Image Information Disclosure Vulnerabi=
lity
BugTraq ID: 29513
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29513
Summary:
Apple Mac OS X is prone to an information-disclosure vulnerability that o=
ccurs in ImageIO.

An attacker can exploit this issue to obtain sensitive information that m=
ay lead to further attacks.

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

38. libxslt XSL File Processing Buffer Overflow Vulnerability
BugTraq ID: 29312
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29312
Summary:
The 'libxslt' library is prone to a buffer-overflow vulnerability because=
 the software fails to perform adequate boundary checks on user-supplied =
data.=20

An attacker may exploit this issue to execute arbitrary code with the pri=
vileges of the user running an application that relies on the affected li=
brary. Failed exploit attempts will likely result in denial-of-service co=
nditions.
=20
 This issue affects libxslt 1.1.23 and prior versions.

39. mtr 'split.c' Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 29290
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29290
Summary:
The 'mtr' utility is prone to a remote stack-based buffer-overflow vulner=
ability because the application fails to perform adequate boundary checks=
 on user-supplied data.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges. Successfully exploiting this issue will result in the comp=
lete compromise of affected computers. Failed exploit attempts will resul=
t in a denial-of-service condition.

40. Libpng Library Unknown Chunk Handler Vulnerability
BugTraq ID: 28770
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/28770
Summary:
The 'libpng' library is prone to a vulnerability that causes denial-of-se=
rvice conditions or may allow code to run. The issue occurs because the s=
oftware fails to properly handle unexpected chunk data in PNG files.

Successfully exploiting this issue allows remote attackers to trigger den=
ial-of-service conditions or to possibly execute arbitrary machine code i=
n the context of applications that use the library.

The following versions are affected:

libpng 1.0.6 through 1.0.32
libpng 1.2.0 through 1.2.26
libpng 1.4.0beta01 through 1.4.0beta19

41. 'imlib2' Library Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 29417
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29417
Summary:
The 'imlib2' library is prone to multiple buffer-overflow vulnerabilities=
 because the software fails to properly bounds-check user-supplied data.

An attacker can exploit these issues to execute arbitrary machine code in=
 the context of applications using the vulnerable library. Failed exploit=
 attempts will likely cause denial-of-service conditions.

The issues affect imlib2 1.4.0; other versions may also be affected.

42. libvorbis Multiple Remote Vulnerabilities
BugTraq ID: 29206
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29206
Summary:
Applications that use the libvorbis library are prone to multiple remote =
vulnerabilities, including a heap-overflow issue and multiple integer-ove=
rflow issues.

An attacker can exploit these issues to execute arbitrary code within the=
 context of an affected application or cause the application to crash.=20

These issues affect libvorbis 1.2.0; other versions of the library may al=
so be affected.

43. RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabili=
ties
BugTraq ID: 29108
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29108
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing four security bulletins on May 13, 2008. The highest severity rating=
 for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

NOTE: The following individual records have been created to document thes=
e vulnerabilities:

29104 Microsoft Word RTF Malformed String Handling Memory Corruption Remo=
te Code Execution Vulnerability
29105 Microsoft Word CSS Handling Memory Corruption Remote Code Execution=
 Vulnerability
29158 Microsoft Publisher Memory Object Handler Data Execution Vulnerabil=
ity
26468 Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer Overfl=
ow Vulnerability
29060 Microsoft Malware Protection Engine File Processing Remote Denial O=
f Service Vulnerability
29073 Microsoft Malware Protection Engine Disk Space Exhaustion Remote De=
nial Of Service Vulnerability

44. SiteXS CMS 'upload.php' Arbitrary File Upload Vulnerability
BugTraq ID: 29029
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29029
Summary:
SiteXS is prone to a vulnerability that lets remote attackers upload and =
execute arbitrary script code because the application fails to sanitize u=
ser-supplied input. =20

An attacker can leverage this issue to execute arbitrary code on an affec=
ted computer with the privileges of the webserver process.

SiteXS CMS 0.1.1 Pre-Alpha is vulnerable; other versions may also be affe=
cted.

45. Apple Mac OS X Mail Memory Corruption Vulnerability
BugTraq ID: 29500
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29500
Summary:
Apple Mac OS X is prone to a memory-corruption vulnerability that affects=
 the Mail application.

Successful exploits may allow attackers to execute arbitrary code in the =
context of the affected application, cause denial-of-service conditions, =
or obtain potentially sensitive information.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

This issue affects Mac OS X v10.4.11 and Mac OS X Server 10.4.11. Compute=
rs running Mac OS X v10.5 or later are not affected by this issue.

46. TotalECommerce SQL Injection Vulnerability
BugTraq ID: 16960
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/16960
Summary:
TotalECommerce is prone to an SQL-injection vulnerability. This issue is =
due to a failure in the application to properly sanitize user-supplied in=
put before using it in an SQL query.=20
=20
Successful exploitation could allow an attacker to compromise the applica=
tion, access or modify data, or exploit vulnerabilities in the underlying=
 database implementation.
=20
Version 1.0 is vulnerable; other versions may also be affected.

47. Apple Mac OS X Image Capture Webserver Directory Traversal Vulnerabil=
ity
BugTraq ID: 29501
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29501
Summary:
Apple's Image Capture is prone to a directory-traversal vulnerability bec=
ause the application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to gain access to arbitrary files in t=
he context of the affected server. Information gathered may lead to other=
 attacks.

This vulnerability affects Mac OS X 10.4.11 and Mac OS X Server 10.4.11.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

48. Apple Mac OS X Apple Type Services PDF Handling Code Execution Vulner=
ability
BugTraq ID: 29492
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29492
Summary:
Apple Mac OS X is prone to a remote code-execution vulnerability affectin=
g Apple Type Services (ATS). =20

Successful exploits will allow attackers to execute arbitrary code in the=
 context of the affected application. Failed exploit attempts will likely=
 result in denial-of-service conditions.=20

This issue affects Mac OS X 10.5 - 10.5.2 and Mac OS X Server 10.5 - 10.5=
.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

49. Apple Mac OS X CFNetwork SSL Client Certificate Handling Information =
Disclosure Vulnerability
BugTraq ID: 29493
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29493
Summary:
Apple Mac OS X is prone to an information-disclosure vulnerability becaus=
e it improperly responds to client certificate requests from webservers.

An attacker could leverage this vulnerability to obtain potentially sensi=
tive information that may aid in further attacks.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

50. Apple Mac OS X CoreFoundation CFData Object Handling Code Execution V=
ulnerability
BugTraq ID: 29491
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29491
Summary:
Apple Mac OS X is prone to a remote code-execution vulnerability affectin=
g CoreFoundation. =20

Successful exploits will allow attackers to execute arbitrary code in the=
 context of the affected component. Failed exploit attempts will likely r=
esult in denial-of-service conditions.=20

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

51. Apple Mac OS X AFP Server File Sharing Unauthorized File Access Vulne=
rability
BugTraq ID: 29490
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29490
Summary:
Apple Mac OS X is prone to an unauthorized file-access vulnerability that=
 occurs in the AFP Server.=20

Successfully exploiting this issue will allow attackers to obtain potenti=
ally sensitive information that may lead to other attacks.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

52. Apple Mac OS X AppKit Malformed File Remote Code Execution Vulnerabil=
ity
BugTraq ID: 29487
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29487
Summary:
Apple Mac OS X is prone to a remote code-execution vulnerability that occ=
urs in AppKit.=20

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application.=20

This issue affects Mac OS X 10.4.11 and Mac OS X Server 10.4.11.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

53. Apple Mac OS X iCal '.ics' File Handling Remote Code Execution Vulner=
ability
BugTraq ID: 29486
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29486
Summary:
Apple Mac OS X iCal is prone to a remote code-execution vulnerability whe=
n handling malicious iCalendar files.

Attackers can leverage this issue to execute arbitrary code with the priv=
ileges of the affected application. Successful exploits will compromise t=
he application and possibly the underlying computer. Failed attacks will =
likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

54. Apple Mac OS X CUPS Debug Logging Information Disclosure Vulnerabilit=
y
BugTraq ID: 29484
Remote: No
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29484
Summary:
Apple Mac OS X is prone to an information-disclosure vulnerability that a=
ffects the CUPS scheduler daemon.  This issue may be triggered when print=
ing to a password-protected printer while debug logging is enabled.

Attackers can exploit this issue to harvest sensitive information that ca=
n aid in further attacks.

This issue affects Mac OS X 10.5 - 10.5.2 and Mac OS X Server 10.5 - 10.5=
.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

55. RETIRED: SiteXS CMS 'adm/visual/upload.php' Arbitrary File Upload Vul=
nerability
BugTraq ID: 29497
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29497
Summary:
SiteXS CMS is prone to a vulnerability that lets remote attackers upload =
and execute arbitrary script code because the application fails to saniti=
ze user-supplied input. =20

An attacker can leverage this issue to execute arbitrary script code on a=
n affected computer with the privileges of the webserver process.

SiteXS CMS 0.1.1 Pre-Alpha and prior versions are vulnerable.

RETIRED: This BID is being retired because the issue is already covered i=
n BID 29029.

56. Apple Mac OS X Pixlet Video Multiple Unspecified Memory Corruption Vu=
lnerabilities
BugTraq ID: 29489
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29489
Summary:
Apple Mac OS X is prone to multiple memory-corruption vulnerabilities tha=
t occur in Apple Pixlet Video.

An attacker can exploit these issues to execute arbitrary code with the p=
rivileges of the user running the affected application.=20

These issues affect Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 1=
0.5 - 10.5.2,  and Mac OS X Server 10.5 - 10.5.2.

NOTE: These issues were previously covered in BID 29412 (Apple Mac OS X 2=
008-003 Multiple Security Vulnerabilities) but have been given this recor=
d to better document them.

57. Apple Mac OS X International Components for Unicode Information Discl=
osure Vulnerability
BugTraq ID: 29488
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29488
Summary:
Apple Mac OS X is prone to an information-disclosure vulnerability becaus=
e it fails to adequately sanitize user-supplied input.

An attacker could leverage this vulnerability to bypass content filters a=
nd perform cross-site scripting attacks or obtain sensitive information t=
hat could aid in further attacks.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

58. Apple Mac OS X Help Viewer 'help:topic' URI Buffer Overflow Vulnerabi=
lity
BugTraq ID: 29483
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29483
Summary:
Apple Mac OS X Help Viewer is prone to a buffer-overflow vulnerability be=
cause it fails to perform adequate boundary checks before copying user-su=
pplied data to an insufficiently-sized buffer.

Attackers can leverage this issue to execute arbitrary code with the priv=
ileges of the affected application. Successful exploits will compromise t=
he application and possibly the underlying computer. Failed attacks will =
likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

59. Apple Mac OS X CoreTypes Unsafe Content Warning Weakness
BugTraq ID: 29481
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29481
Summary:
Apple Mac OS X is prone to a security weakness in CoreTypes; it may not p=
revent users from opening unsafe file types.

This issue can lead to a false sense of security, potentially aiding in n=
etwork-based attacks.=20

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

60. Booby 'renderer' Parameter Multiple Local and Remote File Include Vul=
nerabilities
BugTraq ID: 29469
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29469
Summary:
Booby is prone to multiple local and remote file-include vulnerabilities =
because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow a remote attacker to obtain sensitive i=
nformation or compromise the application and the underlying system; other=
 attacks are also possible.

The issue affects Booby 1.0.1; other versions may also be vulnerable.

61. HP Instant Support ActiveX Control in 'HPISDataManager.dll' Arbitrary=
 File Download Vulnerability
BugTraq ID: 29530
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29530
Summary:
HP Instant Support ActiveX control in 'HPISDataManager.dll' is prone to a=
n arbitrary file-download vulnerability.=20

An attacker may exploit this issue by enticing victims into visiting a ma=
liciously crafted webpage.
=20
Successful exploits will allow remote attackers to download files from ar=
bitrary locations to the affected computer.  The attacker can also specif=
y arbitrary download locations on the target system.

62. HP Instant Support 'HPISDataManager.dll' ActiveX Control Unspecified =
Code Execution Vulnerabilities
BugTraq ID: 29526
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29526
Summary:
HP Instant Support 'HPISDataManager.dll' ActiveX control is prone to mult=
iple unspecified vulnerabilities that allow remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
 (typically Internet Explorer).=20

Failed exploit attempts likely result in denial-of-service conditions.

HP Instant Support 1.0.0.22 and earlier versions are affected.

63. QuickerSite Multiple Vulnerabilities
BugTraq ID: 29524
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29524
Summary:
QuickerSite is prone to multiple vulnerabilities, including an SQL-inject=
ion issue, an authentication-bypass issue, multiple cross-site scripting =
issues and a file upload vulnerability.

Successful exploit may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- gain unauthorized access to the affected application
- upload arbitrary files and execute arbitrary server-side script code
- execute arbitrary script code in the browser of an unsuspecting user in=
 the context of the affected site

This will compromise the application and may help in further attacks.

The issues affects QuickerSite 1.8.5; other versions may also be vulnerab=
le.

64. LimeSurvey Prior to 1.71 Multiple Remote Vulnerabilities
BugTraq ID: 29506
Remote: Yes
Last Updated: 2008-06-03
Relevant URL: http://www.securityfocus.com/bid/29506
Summary:
LimeSurvey is prone to multiple remote vulnerabilities, including:=20

- An input-validation vulnerability
- Multiple unspecified vulnerabilities=20

An attacker can exploit the input-validation issue to modify quota settin=
gs. Very little information is known about the unspecified issues. We wil=
l update this BID as soon as more information becomes available.=20

LimeSurvey versions prior to 1.71 are vulnerable.

65. meBiblio Multiple Input Validation Vulnerabilities
BugTraq ID: 29465
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29465
Summary:
meBiblio is prone to multiple input-validation vulnerabilities, including=
 an SQL injection issue, an arbitrary-file-upload issue, and multiple cro=
ss-site scripting issues.

Successful exploits will allow attackers to execute arbitrary script code=
 in the context of the application or the browser of an unsuspecting user=
 and compromise the application. Attackers can also access or modify data=
 or exploit latent vulnerabilities in the underlying database. This may h=
elp the attacker steal cookie-based authentication credentials and launch=
 other attacks.

meBiblio 0.4.7 is vulnerable; other versions may also be affected.

66. ComicShout 'news.php' SQL Injection Vulnerability
BugTraq ID: 29464
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29464
Summary:
ComicShout is prone to an SQL-injection vulnerability because it fails to=
 sufficiently sanitize user-supplied data before using it in an SQL query=
.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

ComicShout 2.8 is vulnerable; other versions may also be affected.

67. Phoenix View CMS 'admin_frame.php' Cross-Site Scripting Vulnerability
BugTraq ID: 29130
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29130
Summary:
Phoenix View CMS is prone to a cross-site scripting vulnerability because=
 the application fails to properly sanitize user-supplied input.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

Phoenix View CMS Pre Alpha2 is vulnerable; other versions may also be aff=
ected.

 UPDATE (June 2, 2008): The vendor reports that the application is not vu=
lnerable to the issue, but this has not been confirmed.

68. Apple Mac OS X CoreGraphics PDF Handling Code Execution Vulnerability
BugTraq ID: 29480
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29480
Summary:
Apple Mac OS X is prone to a remote code-execution vulnerability affectin=
g CoreGraphics. =20

Successful exploits will allow the attacker to execute arbitrary code in =
the context of the affected application. Failed exploit attempts will lik=
ely result in denial-of-service conditions.=20

This issue affects Mac OS X 10.4.11, Mac OS X Server 10.4.11, Mac OS X 10=
.5 - 10.5.2, and Mac OS X Server 10.5 - 10.5.2.

NOTE: This issue was previously covered in BID 29412 (Apple Mac OS X 2008=
-003 Multiple Security Vulnerabilities) but has been given its own record=
 to better document the vulnerability.

69. BEA Systems Multiple Products BEA08-183.00 to BEA08-200.00 Multiple V=
ulnerabilities
BugTraq ID: 27893
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/27893
Summary:
BEA has released 17 advisories identifying various vulnerabilities affect=
ing WebLogic Server, WebLogic Portal, WebLogic Workshop, AquaLogic Intera=
ction, BEA Plumtree Foundation, AquaLogic Collaboration, and BEA Plumtree=
 Collaboration. These issues present remote and local threats and may fac=
ilitate attacks affecting the integrity, confidentiality, and availabilit=
y of vulnerable computers.

70. CMSimple Multiple Input Validation Vulnerabilities
BugTraq ID: 29450
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29450
Summary:
CMSimple is prone to two input-validation vulnerabilities, including a lo=
cal file-include vulnerability and an arbitrary-file-upload vulnerability=
.

An attacker can exploit these issues to retrieve webserver-readable files=
 from the computer or to upload arbitrary files to the computer. The atta=
cker may be able to execute files that have been uploaded, for example, i=
f the attacker uploads a malicious PHP script.

71. OpenSSL Multiple Denial of Service Vulnerabilities
BugTraq ID: 29405
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29405
Summary:
OpenSSL is prone to multiple denial-of-service vulnerabilities.

Attackers can leverage these issues to cause a client or server applicati=
on to crash. Successful exploits will deny service to legitimate users.

OpenSSL 0.9.8f and 0.9.8g are reported vulnerable. Other versions may be =
affected as well.

72. BP Blog Multiple SQL Injection Vulnerabilities
BugTraq ID: 29460
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29460
Summary:
BP Blog is prone to multiple SQL-injection vulnerabilities because it fai=
ls to sufficiently sanitize user-supplied input before using it in an SQL=
 query.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

BP Blog 6.0 and prior versions are vulnerable.

73. Linux Kernel 'ipip6_rcv()' Remote Denial of Service Vulnerability
BugTraq ID: 29235
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29235
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to crash the affected computer, denyin=
g service to legitimate users.

This issue affects the Linux Kernel 2.6.25.2; other versions may also be =
affected.

74. Linux Kernel Multiple Local MOXA Serial Driver Buffer Overflow Vulner=
abilities
BugTraq ID: 12195
Remote: No
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/12195
Summary:
The MOXA serial driver in the Linux kernel is reported prone to multiple =
buffer-overflow vulnerabilities. The driver fails to perform proper bound=
s checks before copying user-supplied data to fixed-size memory buffers.=20

These vulnerabilities reside in the 'drivers/char/moxa.c' file.=20

The vulnerable functions perform a 'copy_from_user()' call to copy user-s=
upplied, user-space data to a fixed-size, static kernel memory buffer (mo=
xaBuff) of 10240 bytes in length while using the user-supplied length arg=
ument as passed from 'MoxaDriverIoctl()'. This reportedly results in impr=
operly bounded operations, potentially causing locally exploitable buffer=
 overflows.=20

Linux kernels from 2.2 through 2.4 and 2.6 are all reported prone to thes=
e vulnerabilities.

75. Linux Kernel SPARC 'mmap()' Denial Of Service Vulnerability
BugTraq ID: 29397
Remote: No
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29397
Summary:
The Linux kernel is prone to a denial-of-service vulnerability when mappi=
ng memory addresses on SPARC-based computers.

Local attackers can leverage the issue to crash the kernel and deny servi=
ce to legitimate users.

Linux kernels prior to 2.6.25.3 are vulnerable.

76. Sun Cluster Global File System Unspecified Security Vulnerability
BugTraq ID: 29458
Remote: No
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29458
Summary:
Sun Cluster is prone to an unspecified vulnerability that affects the 'Gl=
obal File System'

Local unprivileged attackers may exploit this issue to read data from del=
eted files owned by other users.=20

This issue affects these versions:

Sun Cluster 3.1 for Solaris 8, 9, and 10 on SPARC
Sun Cluster 3.1 for Solaris 9 and 10 on x86.

77. Apple Safari and Microsoft Windows Client-side Code Execution Vulnera=
bility
BugTraq ID: 29445
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29445
Summary:
A vulnerability in Apple Safari on the Microsoft Windows operating system=
 stems from a combination of security issues in Safari and all versions o=
f Microsoft XP and Vista that will allow executables to be downloaded to =
a user's computer and run without prompting.

Third-party sources have indicated that the vulnerability in Safari is th=
e "carpet-bombing" issue reported by Nitesh Dhanjani. If the issue is exp=
loited, attacked-specified content is downloaded to the user's desktop wi=
thout prompting. However, the Safari issue alone does not let an attacker=
 execute the content. Presumably, an additional issue in Microsoft Window=
s can be exploited in tandem with this issue to run the content that is d=
ownloaded to the user's desktop.

78. freeSSHd SFTP 'opendir' Buffer Overflow Vulnerability
BugTraq ID: 29453
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29453
Summary:
freeSSHd is prone to a buffer-overflow vulnerability because the applicat=
ion fails to properly bounds-check user-supplied data before storing it i=
n a finite-sized buffer.=20

An attacker may exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial of service.

 This issue affects freeSSHd 1.2.1; other versions may also be affected.

79. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overflow Vuln=
erability
BugTraq ID: 26455
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/26455
Summary:
Samba is prone to a remote stack-based buffer-overflow vulnerability beca=
use it fails to properly bounds-check user-supplied data before copying i=
t to an insufficiently sized memory buffer.

NOTE: This issue occurs only when Samba is configured with the 'wins supp=
ort' option enabled in the host's 'smb.conf' file.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Successful attacks will completely compro=
mise affected computers. Failed exploit attempts will result in a denial =
of service.

Samba 3.0.0 through 3.0.26a are vulnerable.

80. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
BugTraq ID: 26454
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/26454
Summary:
Samba is prone to a buffer-overflow vulnerability because it fails to per=
form adequate boundary checks on user-supplied data.

This issue occurs only when Samba is configured as a Primary or Backup Do=
main Controller.

Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of this issue, attackers may also be able to execute remo=
te code, but the vendor doesn't think that this is possible.

Samba 3.0.0 through 3.0.26a are vulnerable.

81. ASUS Remote Console DPC Proxy Buffer Overflow Vulnerability
BugTraq ID: 28394
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/28394
Summary:
ASUS Remote Console is prone to a buffer-overflow vulnerability because i=
t fails to adequately bounds-check user-supplied data before copying it t=
o an insufficiently sized buffer.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected application. Failed exploit attempts will result in =
a denial-of-service condition.

ASUS Remote Console 2.0.0.19 is vulnerable; other versions may also be af=
fected.

82. Samba Send_MailSlot Stack-Based Buffer Overflow Vulnerability
BugTraq ID: 26791
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/26791
Summary:
Samba is prone to a remote stack-based buffer-overflow vulnerability beca=
use it fails to properly bounds-check user-supplied data before copying i=
t to an insufficiently sized memory buffer.

NOTE: This issue occurs only when the 'domain logons' option is enabled.

An attacker can exploit this issue to execute arbitrary code with superus=
er privileges. Successful attacks will completely compromise affected com=
puters. Failed exploit attempts will result in a denial of service.

83. Sun Solaris Print Service Unspecified Remote Code Execution Vulnerabi=
lity
BugTraq ID: 29135
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29135
Summary:
Sun Solaris Print Service is prone to an unspecified remote code-executio=
n vulnerability.

This issue allows remote attackers to execute arbitrary machine code with=
 SYSTEM-level privileges on affected computers. Failed exploit attempts w=
ill result in denial-of-service conditions.

No further technical details are currently available. We will update this=
 BID as more information emerges.

84. Debian OpenSSL Package Random Number Generator Weakness
BugTraq ID: 29179
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29179
Summary:
The Debian OpenSSL package is prone to a random-number-generator weakness=
.

Attackers can exploit this issue to predict random data used to generate =
encryption keys by certain applications. This may help attackers compromi=
se encryption keys and gain access to sensitive data.

This issue affects only a modified OpenSSL package for Debian prior to ve=
rsion 0.9.8c-4etch3.

85. GnuTLS Prior to 2.2.5 Multiple Remote Vulnerabilities
BugTraq ID: 29292
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29292
Summary:
GnuTLS is prone to multiple remote vulnerabilities, including:

- A buffer-overflow vulnerability=20
- Multiple denial-of-service vulnerabilities

An attacker can exploit these issues to execute arbitrary code within the=
 context of the affected application or crash the application, denying se=
rvice to legitimate users.=20

Versions prior to GnuTLS 2.2.5 are vulnerable.

86. Samba 'receive_smb_raw()' Buffer Overflow Vulnerability
BugTraq ID: 29404
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29404
Summary:
Samba is prone to a remote heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied data before copying it=
 to an insufficiently sized memory buffer. The issue occurs when the appl=
ication processes SMB packets in a client context.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in a denial of service.

The issue affects Samba 3.0.28a and 3.0.29; other versions may also be af=
fected.

NOTE:  This BID was originally titled 'Samba 'lib/util_sock.c' Buffer Ove=
rflow Vulnerability'.  The title was changed to better identify the issue=
.

87. Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
BugTraq ID: 29086
Remote: No
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29086
Summary:
The Linux kernel is prone to a denial-of-service vulnerability when proce=
ss traces are performed on 64-bit computers.

Local attackers can leverage the issue to crash the kernel and deny servi=
ce to legitimate users.

88. Linux Kernel 'hrtimer_forward()' Local Denial of Service Vulnerabilit=
y
BugTraq ID: 29294
Remote: No
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29294
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability beca=
use it fails to properly handle certain large timer expiry values.

Attackers can exploit this issue to cause the application to enter an inf=
inite loop, denying service to legitimate users.=20

This issue affects the Linux kernel 2.6.21-rc4 and prior version srunning=
 on 64-bit architectures.

89. TorrentTrader Classic 'scrape.php' SQL Injection Vulnerability
BugTraq ID: 29451
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29451
Summary:
TorrentTrader Classic is prone to an SQL-injection vulnerability because =
it fails to sufficiently sanitize user-supplied data before using it in a=
n SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

90. PsychoStats Multiple SQL Injection Vulnerabilities
BugTraq ID: 29449
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29449
Summary:
PsychoStats is prone to multiple SQL-injection vulnerabilities because it=
 fails to sufficiently sanitize user-supplied data before using it in an =
SQL query.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

91. LokiCMS 'admin.php' Security Bypass Vulnerability
BugTraq ID: 29448
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29448
Summary:
LokiCMS is prone to a vulnerability that may allow users to bypass authen=
tication to access administrative facilities of the application.

This issue may be related to BID 28985 (LokiCMS 'admin.php' Arbitrary Fil=
e Deletion Vulnerability).

 This issue was reported to affect LokiCMS 0.3.4. Other versions may also=
 be affected.

92. Ourgame 'GLIEDown2.dll' ServerList Method ActiveX Control Remote Code=
 Execution Vulnerability
BugTraq ID: 29446
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29446
Summary:
Ourgame 'GLIEDown2.dll' ActiveX control is prone to a remote code-executi=
on vulnerability because it fails to sufficiently verify user-supplied in=
put.

An attacker can exploit this issue to run arbitrary attacker-supplied cod=
e in the context of the currently logged-in user. Failed exploits attempt=
s will trigger denial-of-service conditions.

Note that GlobalLink 2.8.1.2 beta is also affected by this issue.

93. Apache Tomcat Host Manager Cross Site Scripting Vulnerability
BugTraq ID: 29502
Remote: Yes
Last Updated: 2008-06-02
Relevant URL: http://www.securityfocus.com/bid/29502
Summary:
Apache Tomcat is prone to a cross-site scripting vulnerability because th=
e application fails to properly sanitize user-supplied input.  The issue =
affects the Host Manager web application.
=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

The issue affects the following versions:

Tomcat 5.5.9 to 5.5.26
Tomcat 6.0.0 to 6.0.16

94. Alt-N MDaemon IMAP Server FETCH Command Remote Buffer Overflow Vulner=
ability
BugTraq ID: 28245
Remote: Yes
Last Updated: 2008-05-31
Relevant URL: http://www.securityfocus.com/bid/28245
Summary:
Alt-N MDaemon IMAP Server is affected by a remote buffer-overflow vulnera=
bility because the application fails to perform adequate boundary checks =
on user-supplied data before copying it into an insufficiently sized buff=
er.

Attackers may leverage this issue to execute arbitrary code with SYSTEM-l=
evel privileges. Successful exploits will completely compromise affected =
computers.
=20
Alt-N MDaemon 9.64 is vulnerable; other versions may also be affected.

95. VMware VMCI Arbitrary Code Execution Vulnerability
BugTraq ID: 29443
Remote: No
Last Updated: 2008-05-31
Relevant URL: http://www.securityfocus.com/bid/29443
Summary:
Multiple VMware hosted products with VMCI enabled are prone to a vulnerab=
ility that lets attackers execute arbitrary code. This issue affects Micr=
osoft Windows-based hosts only.

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue can completely compr=
omise affected computers. Failed exploit attempts will result in a denial=
-of-service condition.

This issue affects the following VMware products:

VMware Workstation prior to 6.0.4 build 93057
VMware Player prior to 2.0.4 build 93057
VMware ACE prior to 2.0.2 build 93057

96. DotNetNuke 'Default.aspx' Cross-Site Scripting Vulnerability
BugTraq ID: 29437
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/29437
Summary:
DotNetNuke is prone to a cross-site scripting vulnerability because the a=
pplication fails to properly sanitize user-supplied input.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

DotNetNuke 4.8.3 is vulnerable; other versions may also be affected.

97. Joomla! and Mambo MambAds Component 'ma_cat' Parameter SQL Injection =
Vulnerability
BugTraq ID: 29433
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/29433
Summary:
The MambAds component for Joomla! and Mambo is prone to an SQL-injection =
vulnerability because it fails to sufficiently sanitize user-supplied dat=
a before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

The issue affects MamAds 1.0 RC1 and 1.0 RC1 Beta. Other versions may als=
o be vulnerable.

98. TCL/TK Tk Toolkit 'ReadImage()' GIF File Buffer Overflow Vulnerabilit=
y
BugTraq ID: 27655
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/27655
Summary:
TCL/TK Tk Toolkit is prone to a buffer-overflow vulnerability because it =
fails to perform adequate boundary checks on user-supplied GIF image data=
 before copying it to an insufficiently sized buffer.

Successful exploits may allow attackers to execute arbitrary code in the =
context of applications that use the affected toolkit. Failed exploit att=
empts likely result in denial-of-service conditions.

Versions prior to TCL/TK 8.5.1 are vulnerable to this issue.

99. TCL/TK Tk Toolkit TKIMGGIF.C Buffer Overflow Vulnerability
BugTraq ID: 26056
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/26056
Summary:
TCL/TK Tk Toolkit is prone to a buffer-overflow vulnerability because it =
fails to perform adequate boundary checks on user-supplied data before co=
pying it to an insufficiently sized buffer.

An attacker can exploit this issue to cause denial-of-service conditions.=
 Given the nature of this issue, remote code execution may also be possib=
le but has not been confirmed.

Versions prior to TCL/TK 8.4.13 are vulnerable to this issue.

100. Now SMS/MMS Gateway Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 27896
Remote: Yes
Last Updated: 2008-05-30
Relevant URL: http://www.securityfocus.com/bid/27896
Summary:
Now SMS/MMS Gateway is prone to multiple buffer-overflow vulnerabilities =
because it fails to adequately bounds-check user-supplied input before co=
pying it to insufficiently sized buffers.=20

Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code with the privileges of the user running the affected applica=
tion. Failed exploit attempts will likely crash the application.

These issues affect Now SMS/MMS Gateway 2007.06.27 and prior versions.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Hired gun blamed for business outage
By: Robert Lemos
Video-content firm Revision3 accuses anti-piracy company MediaDefender --=
 known for its aggressive tactics against file sharers -- of attacking it=
s servers over the weekend.
http://www.securityfocus.com/news/11521

2. Legal experts wary of MySpace hacking charges
By: Robert Lemos
Federal prosecutors charge the parent who allegedly badgered a girl to su=
icide with three counts of computer crime, but law experts worry about a =
dangerous precedent.
http://www.securityfocus.com/news/11519

3. Admins warned of brute-force SSH attacks
By: Robert Lemos
Normally considered a low-level threat on the Internet, scans for default=
-configured secure shell servers spiked this week.
http://www.securityfocus.com/news/11518

4. Groups warn travelers to limit laptop data
By: Robert Lemos
In a letter to Congress, nearly three dozen organizations protest the sei=
zures of electronic devices by U.S. customs officials, an act upheld by a=
 federal appeals court in a recent ruling.
http://www.securityfocus.com/news/11516

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, San Antonio
http://www.securityfocus.com/archive/77/492865

2. [SJ-JOB] Security Consultant, Dallas
http://www.securityfocus.com/archive/77/492871

3. [SJ-JOB] Security Auditor, San Antonio
http://www.securityfocus.com/archive/77/492870

4. [SJ-JOB] Technical Support Engineer, Alpharetta
http://www.securityfocus.com/archive/77/492872

5. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/492873

6. [SJ-JOB] Manager, Information Security, Chicago
http://www.securityfocus.com/archive/77/492858

7. [SJ-JOB] Application Security Architect, San Fransisco
http://www.securityfocus.com/archive/77/492860

8. [SJ-JOB] Certification & Accreditation Engineer, San Antonio
http://www.securityfocus.com/archive/77/492866

9. [SJ-JOB] Management, Newark
http://www.securityfocus.com/archive/77/492867

10. [SJ-JOB] Sr. Security Analyst, Seattle/Bellevue
http://www.securityfocus.com/archive/77/492855

11. [SJ-JOB] Security Consultant, Any City
http://www.securityfocus.com/archive/77/492857

12. [SJ-JOB] Information Assurance Analyst, Information Risk Analyst
http://www.securityfocus.com/archive/77/492861

13. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/492862

14. [SJ-JOB] Sr. Security Analyst, San Antonio
http://www.securityfocus.com/archive/77/492864

15. [SJ-JOB] Threat Analyst, Washington
http://www.securityfocus.com/archive/77/492856

16. [SJ-JOB] Penetration Engineer, Washington
http://www.securityfocus.com/archive/77/492859

17. [SJ-JOB] Security Engineer, Linthicum Heights
http://www.securityfocus.com/archive/77/492863

18. [SJ-JOB] Instructor, any
http://www.securityfocus.com/archive/77/492843

19. [SJ-JOB] Security Engineer, Pune
http://www.securityfocus.com/archive/77/492845

20. [SJ-JOB] Sales Engineer, Alpharetta
http://www.securityfocus.com/archive/77/492846

21. [SJ-JOB] Forensics Engineer, London
http://www.securityfocus.com/archive/77/492853

22. [SJ-JOB] Penetration Engineer, sydney
http://www.securityfocus.com/archive/77/492854

23. [SJ-JOB] Security Auditor, Chennai
http://www.securityfocus.com/archive/77/492842

24. [SJ-JOB] Sales Engineer, San Francisco
http://www.securityfocus.com/archive/77/492844

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Unusual entry in Apache logs
http://www.securityfocus.com/archive/75/492775

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. ISA as a proxy
http://www.securityfocus.com/archive/88/492690

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. ARP handler Inspection tool released
http://www.securityfocus.com/archive/91/492905

2. Spam sent through server using authid=3Dapache or mysql
http://www.securityfocus.com/archive/91/492810

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
 body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Black Hat USA:

Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
 Network with 4,000 delegates from 50 nations.  Visit product displays by=
 30 top sponsors in a relaxed setting.=20
www.blackhat.com