SecurityFocus Newsletter #502

[email protected] Thu, 7 May 2009 17:01:52 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #502
----------------------------------------

This issue is sponsored by Thawte

Extended Validation SSL Certificates: Inspire Trust, Improve Confidence a=
nd Increase Sales

Extended Validation SSL delivers the acknowledged industry standard for t=
he highest level of online identity assurance processes for SSL certifica=
te issuance. Find out how the EV standard increases the visibility of aut=
hentication status through the use of a green address bar in the latest h=
igh security web browsers.

http://www.dinclinx.com/Redirect.aspx?36;5004;25;1371;0;3;946;54442f0f214=
c470a


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. A Botnet by Any Other Name
       2. Projecting Borders into Cyberspace
II.   BUGTRAQ SUMMARY
       1. Linux Kernel Cloned Process 'CLONE_PARENT' Local Origin Validat=
ion Weakness
       2. Linux Kernel 'keyctl_join_session_keyring()' Denial of Service =
Vulnerability
       3. Bmxplay 'BMX' File Remote Buffer Overflow Vulnerability
       4. Million Dollar Text Links Administrative Interface Authenticati=
on Bypass Vulnerability
       5. EW-MusicPlayer '.m3u' File Remote Stack Buffer Overflow Vulnera=
bility
       6. Openfire jabber:iq:auth 'passwd_change' Remote Password Change =
Vulnerability
       7. Cscope Multiple Stack Based Buffer Overflow Vulnerabilities
       8. pecio cms 'index.php' Local File Include Vulnerability=20
       9. Memcached and MemcacheDB ASLR Information Disclosure Weakness
       10. iPassConnect Local Privilege Escalation Vulnerability
       11. Jetty Cross Site Scripting and Information Disclosure Vulnerab=
ilities
       12. pam_ssh Existing/Non-Existing Username Enumeration Weakness
       13. Mercury Audio Player 'm3u/b4s/pls' File Multiple Remote Stack =
Buffer Overflow Vulnerabilities
       14. BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer=
 Overflow Vulnerability
       15. Linux Kernel 'ecryptfs_write_metadata_to_contents()' Informati=
on Disclosure Vulnerability
       16. LibTIFF Multiple Buffer Overflow Vulnerabilities
       17. LibTIFF Heap Corruption Integer Overflow Vulnerabilities
       18. ClamAV 'clamav-milter' Initscript File Permission Vulnerabilit=
y
       19. IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service V=
ulnerabilities
       20. PHP 'mbstring.func_overload' Webserver Denial Of Service Vulne=
rability
       21. PHP 5.2.8 and Prior Versions Multiple Vulnerabilities
       22. PHP 'mbstring' Extension Buffer Overflow Vulnerability
       23. PHP SAPI 'php_getuid()' Safe Mode Restriction-Bypass Vulnerabi=
lity
       24. PHP ZipArchive::extractTo() '.zip' Files Directory Traversal V=
ulnerability
       25. PHP 5.2.5 and Prior Versions Multiple Vulnerabilities
       26. eLitius Arbitrary File Upload and Authentication Bypass Vulner=
abilities
       27. Linux Kernel 'parisc_show_stack()' Local Denial of Service Vul=
nerability
       28. Linux Kernel Frame Size Integer Overflow Remote Information Di=
sclosure Vulnerability
       29. Linux Kernel 'NFS filename' Local Denial of Service Vulnerabil=
ity
       30. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerabil=
ity
       31. Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
       32. Linux Kernel 'locks_remove_flock()' Local Race Condition Vulne=
rability
       33. Linux Kernel '/ipc/shm.c' Local Denial of Service Vulnerabilit=
y
       34. Linux Kernel Audit System 'audit_syscall_entry()' System Call =
Security Bypass Vulnerability
       35. Linux Kernel MIPS Untrusted User Application Local Denial of S=
ervice Vulnerability
       36. Linux Kernel CIFS Remote Buffer Overflow Vulnerability
       37. Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privi=
lege Escalation Vulnerability
       38. Linux Kernel 64 Bit ABI System Call Parameter Privilege Escala=
tion Vulnerability
       39. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerabili=
ty
       40. Linux Kernel 'drivers/char/agp/generic.c' Local Information Di=
sclosure Vulnerability
       41. ldns 'rr.c' Remote Buffer Overflow Vulnerability
       42. acpid Local Denial of Service Vulnerability
       43. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -2=
2 Multiple Remote Vulnerabilities
       44. Mozilla Firefox 'nsTextFrame::ClearTextRun()' Remote Memory Co=
rruption Vulnerability
       45. FreePBX Multiple Cross Site Scripting and Information Disclosu=
re Vulnerabilities
       46. Cscope 'find.c' Stack Based Buffer Overflow Vulnerability
       47. SilverStripe 'AjaxUniqueTextField' Parameter SQL Injection Vul=
nerability
       48. ReVou 'adminlogin/password.php' Remote Password Change Vulnera=
bility
       49. Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerab=
ility
       50. FunGamez Local File Include and SQL Injection Vulnerabilities
       51. Flatchat 'pmscript.php' Local File Include Vulnerability
       52. Sun Solaris DTrace Handler IOCTL Request Multiple Local Denial=
 of Service Vulnerabilities
       53. Coccinelle Insecure Temporary File Creation Vulnerability
       54. SMA-DB Cross Site Scripting and Remote File Include Vulnerabil=
ities
       55. FreeType Multiple Integer Overflow Vulnerabilities
       56. libwmf WMF Image File Remote Code Execution Vulnerability
       57. Drupal HTML Injection and Information Disclosure Vulnerabiliti=
es
       58. CUPS and Xpdf JBIG2 Symbol Dictionary Processing Heap Buffer O=
verflow Vulnerability
       59. CUPS Insufficient 'Host' Header Validation Weakness
       60. SunGard Banner Student 'twbkwbis.P_SecurityQuestion' HTML Inje=
ction Vulnerability
       61. MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer=
 Memory Corruption Vulnerability
       62. Google Chrome 'chromehtml:' Protocol Handler Same Origin Polic=
y Bypass Vulnerability
       63. Nucleus Kernel Recovery for Mac and Novell Multiple Buffer Ove=
rflow Vulnerabilities
       64. VerliAdmin 'index.php' Multiple Cross-Site Scripting Vulnerabi=
lities
       65. LinkBase Users Menu HTML Injection Vulnerability
       66. 32bit FTP 'CWD' Response Remote Buffer Overflow Vulnerability
       67. Cisco Subscriber Edge Services Manager Cross Site Scripting An=
d HTML Injection Vulnerabilities
       68. Almond Classifieds for Joomla! 'id' Parameter SQL Injection Vu=
lnerability
       69. TemaTres SQL Injection and Cross Site Scripting Vulnerabilitie=
s
       70. Xpdf JBIG2 Processing Multiple Security Vulnerabilities
       71. CUPS '_cupsImageReadTIFF()' Integer Overflow Vulnerability
       72. xvfb-run Insecure Magic Cookie Local Information Disclosure Vu=
lnerability
       73. Woodstock 404 Error Page Cross Site Scripting Vulnerability
       74. 32bit FTP 'banner' Remote Buffer Overflow Vulnerability
       75. GlassFish Enterprise Server Multiple Cross Site Scripting Vuln=
erabilities
       76. Grabit 'NZB' File Remote Stack Buffer Overflow Vulnerability
       77. IceWarp Merak Mail Server 'item.php' Cross-Site Scripting Vuln=
erability
       78. IceWarp Merak Mail Server 'Forgot Password' Input Validation V=
ulnerability
       79. IceWarp Merak Mail Server 'cleanHTML()' Function Cross-Site Sc=
ripting Vulnerability
       80. IceWarp Merak Mail Server Groupware Component Multiple SQL Inj=
ection Vulnerabilities
       81. Mitel NuPoint Messenger Authentication Credentials Information=
 Disclosure Vulnerability
       82. MoinMoin 'AttachFile.py' Multiple Cross Site Scripting Vulnera=
bilities
       83. Nagios External Commands and Adaptive Commands Unspecified Vul=
nerability=20
       84. Nagios Web Interface Privilege Escalation Vulnerability
       85. Adobe Flash Player Unspecified Remote Denial of Service Vulner=
ability
       86. Adobe Flash Player Invalid Object Reference Remote Code Execut=
ion Vulnerability
       87. Verlihub Control Panel Multiple Cross-Site Scripting Vulnerabi=
lities
       88. Kayako SupportSuite Ticket Notes HTML Injection Vulnerability
       89. Sorinara Streaming Audio Player '.m3u' File Remote Stack Buffe=
r Overflow Vulnerability
       90. Sun Glassfish 'name' Parameter Cross Site Scripting Vulnerabil=
ity
       91. schroot '/tmp/shm' Local Denial of Service Vulnerability
       92. MyBB 1.4.5 Multiple Security Vulnerabilities
       93. ProjectCMS Multiple Input Validation Vulnerabilities
       94. Quagga Autonomous System Number Remote Denial Of Service Vulne=
rability
       95. aMule 'wxExecute()' Arbitrary Command Execution Vulnerability
       96. CoolPlayer M3U File Buffer Overflow Vulnerability
       97. CoolPlayer Skin File Buffer Overflow Vulnerability
       98. Quick 'n Easy Mail Server SMTP Request Remote Denial Of Servic=
e Vulnerability
       99. AGTC MyShop Insecure Cookie Authentication Bypass Vulnerabilit=
y
       100. BluSky CMS 'index.php' SQL Injection Vulnerability
III.  SECURITYFOCUS NEWS
       1. Browsers bashed first in hacking contest
       2. Experts: U.S. needs to defend its "cyber turf"
       3. Advisor: U.S. needs policy to defend cyberspace
       4. Cabal forms to fight Conficker, offers bounty
IV.   SECURITY JOBS LIST SUMMARY
V.    INCIDENTS LIST SUMMARY
       1. EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/=
5) Tokyo CFP deadline: June 1 2009
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #442
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
       1. EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/=
5) Tokyo CFP deadline: June 1 2009
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. A Botnet by Any Other Name
By Gubter Ollmann
The news has been awash the last few weeks with fears over globe-spanning=
 botnets and their criminal intent: Conficker managed to hog the limeligh=
t for well over a month, and then came Finjan's disclosure of a previousl=
y unknown - and currently unnamed - botnet consisting of some 1.9 million=
 malicious agents.=20
http://www.securityfocus.com/columnists/501

2. Projecting Borders into Cyberspace
By Jeffrey Carr
Two recent stories of significant cyber attacks come close to blaming the=
 Chinese for the intrusions but stop short.=20
http://www.securityfocus.com/columnists/500


II.  BUGTRAQ SUMMARY
--------------------
1. Linux Kernel Cloned Process 'CLONE_PARENT' Local Origin Validation Wea=
kness
BugTraq ID: 33906
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33906
Summary:
The Linux kernel is prone to an origin-validation weakness when dealing w=
ith signal handling.

This weakness occurs when a privileged process calls attacker-supplied pr=
ocesses as children. Attackers may exploit this to send arbitrary signals=
 to the privileged parent process.

 A local attacker may exploit this issue to kill vulnerable processes, re=
sulting in a denial-of-service condition. In some cases, other attacks ma=
y also be possible.

Linux kernel 2.6.28 is vulnerable; other versions may also be affected.

2. Linux Kernel 'keyctl_join_session_keyring()' Denial of Service Vulnera=
bility
BugTraq ID: 33339
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33339
Summary:
The Linux kernel is prone to a denial-of-service vulnerability because it=
 fails to manage memory in a proper manner.

Attackers can exploit this issue to cause a crash by exhausting memory re=
sources.=20

This issue affects Linux kernel 2.6.x.

3. Bmxplay 'BMX' File Remote Buffer Overflow Vulnerability
BugTraq ID: 34810
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34810
Summary:
Bmxplay is prone to a remote buffer-overflow vulnerability because the ap=
plication fails to perform adequate boundary checks on user-supplied inpu=
t.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Bmxplay 0.4 is vulnerable; other versions may also be affected.

4. Million Dollar Text Links Administrative Interface Authentication Bypa=
ss Vulnerability
BugTraq ID: 34809
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34809
Summary:
Million Dollar Text Links is prone to an authentication-bypass vulnerabil=
ity.

Attackers can exploit this issue to obtain sensitive information or to ga=
in administrative access to the affected application. Other attacks are p=
ossible.

Million Dollar Text Links 1.0 is vulnerable; other versions may also be a=
ffected.

5. EW-MusicPlayer '.m3u' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 34806
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34806
Summary:
EW-MusicPlayer is prone to a remote stack-based buffer-overflow vulnerabi=
lity because the application fails to perform adequate boundary checks on=
 user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

EW-MusicPlayer 0.8 is vulnerable; other versions may also be affected.

6. Openfire jabber:iq:auth 'passwd_change' Remote Password Change Vulnera=
bility
BugTraq ID: 34804
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34804
Summary:
Openfire is prone to a vulnerability that can permit an attacker to chang=
e the password of arbitrary users.

Exploiting this issue can allow the attacker to gain unauthorized access =
to the affected application and to completely compromise victims' account=
s.

Versions prior to Openfire 3.6.4 are vulnerable.

7. Cscope Multiple Stack Based Buffer Overflow Vulnerabilities
BugTraq ID: 34805
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34805
Summary:
Cscope is prone to multiple stack-based buffer-overflow vulnerabilities b=
ecause the application fails to perform adequate boundary checks on user-=
supplied input.

Attackers may leverage these issues to execute arbitrary code in the cont=
ext of the application. Failed attacks will cause denial-of-service condi=
tions.

Versions prior to Cscope 15.7a are vulnerable.

8. pecio cms 'index.php' Local File Include Vulnerability=20
BugTraq ID: 34802
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34802
Summary:
The 'pecio cms' program is prone to a local file-include vulnerability be=
cause it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to view files and execute loca=
l scripts in the context of the webserver process. This may aid in furthe=
r attacks.

This issue affects pecio cms  1.1.5; other versions may also be affected.

9. Memcached and MemcacheDB ASLR Information Disclosure Weakness
BugTraq ID: 34756
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34756
Summary:
Memcached and MemcacheDB are prone to an information-disclosure weakness =
that may aid attackers in bypassing Address Space Layout Randomization (A=
SLR) protections.

Attackers can exploit this weakness to gain access to sensitive informati=
on such as  stack, heap, and shared-library memory locations. Information=
 obtained may aid in other attacks.=20

memcached v1.2.7 and MemcacheDB v1.2.0 are vulnerable.

10. iPassConnect Local Privilege Escalation Vulnerability
BugTraq ID: 34801
Remote: No
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34801
Summary:
iPassConnect is prone to a local privilege-escalation vulnerability.

Attackers can exploit this issue to execute arbitrary programs with the p=
rivileges of another user.=20

iPassConnect 3.51, 3.60, and 3.66 are vulnerable. Other versions may also=
 be affected.

11. Jetty Cross Site Scripting and Information Disclosure Vulnerabilities
BugTraq ID: 34800
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34800
Summary:
Jetty is prone to a cross-site scripting vulnerability and an information=
-disclosure vulnerability.

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site,=
 steal cookie-based authentication credentials, and obtain sensitive info=
rmation.

Jetty 6.1.16 and prior versions are affected.

12. pam_ssh Existing/Non-Existing Username Enumeration Weakness
BugTraq ID: 34333
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34333
Summary:
The 'pam_ssh' module is prone to a username-enumeration weakness because =
it displays different responses to login attempts, depending on whether  =
or not the username exists.

Attackers may exploit this weakness to discern valid usernames. This may =
aid them in brute-force password cracking or other attacks.

This issue affects pam_ssh 1.92; other versions may also be affected.

13. Mercury Audio Player 'm3u/b4s/pls' File Multiple Remote Stack Buffer =
Overflow Vulnerabilities
BugTraq ID: 34788
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34788
Summary:
Mercury Audio Player is prone to multiple remote stack-based buffer-overf=
low vulnerabilities because the application fails to perform adequate bou=
ndary checks on user-supplied input.

Attackers may leverage these issues to execute arbitrary code in the cont=
ext of the application. Failed attacks will cause denial-of-service condi=
tions.

Mercury Audio Player 1.21 is vulnerable; other versions may also be affec=
ted.

14. BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer Overfl=
ow Vulnerability
BugTraq ID: 34789
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34789
Summary:
BaoFeng Storm ActiveX control is prone to a buffer-overflow vulnerability=
 because the application fails to adequately check boundaries on user-sup=
plied input.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application using the ActiveX control (typically Internet Explo=
rer).  Failed attacks will likely cause denial-of-service conditions.

15. Linux Kernel 'ecryptfs_write_metadata_to_contents()' Information Disc=
losure Vulnerability
BugTraq ID: 34216
Remote: No
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34216
Summary:
The Linux Kernel is prone to an information-disclosure vulnerability beca=
use it fails to properly initialize certain memory before using it in a u=
ser-accessible operation.

Successful exploits will allow attackers to view portions of kernel memor=
y. Information harvested may be used in further attacks.

The Linux Kernel 2.6.28 through 2.6.28.8 are vulnerable.

16. LibTIFF Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 11406
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/11406
Summary:
LibTIFF is affected by multiple buffer-overflow vulnerabilities because t=
he software fails to properly perform boundary checks before copying user=
-supplied strings into finite process buffers.=20
=20
An attacker may leverage these issues to execute arbitrary code on a vuln=
erable computer with the privileges of the user running a vulnerable appl=
ication, facilitating unauthorized access.  The attacker may also leverag=
e these issues to crash the affected application.

17. LibTIFF Heap Corruption Integer Overflow Vulnerabilities
BugTraq ID: 12075
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/12075
Summary:
LibTIFF is affected by two heap-corruption vulnerabilities caused by inte=
ger-overflow errors that can be triggered when handling malicious or malf=
ormed image files. An attacker could exploit the vulnerabilities to execu=
te arbitrary code  when TIFF image data is processed (i.e. displayed).  T=
he code would run in the context of an application linked to the library.=
 Since image data is often external in origin, these vulnerabilities are =
remotely exploitable.

18. ClamAV 'clamav-milter' Initscript File Permission Vulnerability
BugTraq ID: 34818
Remote: No
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34818
Summary:
ClamAV is prone to a file-permission security issue.

An attacker can exploit this issue to modify files in certain directories=
, which could affect system integrity and lead to other attacks.

ClamAV 0.95.1 is vulnerable; other versions may also be affected.

19. IPsec-Tools Prior to 0.7.2 Multiple Remote Denial Of Service Vulnerab=
ilities
BugTraq ID: 34765
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34765
Summary:
IPsec-Tools is affected by multiple remote denial-of-service vulnerabilit=
ies because the software fails to properly handle certain network packets=
.

A successful attack allows a remote attacker to cause the application to =
crash or to consume excessive memory, denying further service to legitima=
te users.

Versions prior to IPsec-Tools 0.7.2 are vulnerable.

20. PHP 'mbstring.func_overload' Webserver Denial Of Service Vulnerabilit=
y
BugTraq ID: 33542
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/33542
Summary:
PHP is prone to a denial-of-service vulnerability because it fails to lim=
it global scope for certain settings relating to Unicode text operations.

Attackers can exploit this issue to crash the affected webserver, denying=
 service to legitimate users.

21. PHP 5.2.8 and Prior Versions Multiple Vulnerabilities
BugTraq ID: 33927
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/33927
Summary:
PHP is prone to multiple security vulnerabilities. Successful exploits co=
uld allow an attacker to cause a denial-of-service condition. An unspecif=
ied issue with an unknown impact was also reported.

These issues affect PHP 5.2.8 and prior versions.

22. PHP 'mbstring' Extension Buffer Overflow Vulnerability
BugTraq ID: 32948
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/32948
Summary:
PHP is prone to a buffer-overflow vulnerability because it fails to perfo=
rm boundary checks before copying user-supplied data to insufficiently si=
zed memory buffers. The issue affects the 'mbstring' extension included i=
n the standard distribution.

An attacker can exploit this issue to execute arbitrary machine code in t=
he context of the affected webserver. Failed exploit attempts will likely=
 crash the webserver, denying service to legitimate users.=20

PHP 4.3.0 through 5.2.6 are vulnerable.

23. PHP SAPI 'php_getuid()' Safe Mode Restriction-Bypass Vulnerability
BugTraq ID: 32688
Remote: No
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/32688
Summary:
PHP is prone to a 'safe_mode' restriction-bypass vulnerability. Successfu=
l exploits could allow an attacker to bypass some safe-mode restrictions.

This vulnerability would be an issue in shared-hosting configurations whe=
re multiple users can create and execute arbitrary PHP script code, with =
the 'safe_mode' restrictions assumed to isolate the users from each other=
.

Versions prior to PHP 5.2.8 are vulnerable.

24. PHP ZipArchive::extractTo() '.zip' Files Directory Traversal Vulnerab=
ility
BugTraq ID: 32625
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/32625
Summary:
PHP is prone to a directory-traversal vulnerability because the applicati=
on fails to adequately sanitize user-supplied input.=20

    =20
A successful attack may allow an attacker to create or overwrite arbitrar=
y files on the system. This may allow arbitrary script code to run in the=
 context of the webserver.

PHP 5.2.6 and prior versions are vulnerable.

25. PHP 5.2.5 and Prior Versions Multiple Vulnerabilities
BugTraq ID: 29009
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/29009
Summary:
PHP 5.2.5 and prior versions are prone to multiple security vulnerabiliti=
es.=20

Successful exploits could allow an attacker to bypass security restrictio=
ns, cause a denial-of-service condition, and potentially execute code.

These issues are reported to affect PHP 5.2.5 and prior versions.

26. eLitius Arbitrary File Upload and Authentication Bypass Vulnerabiliti=
es
BugTraq ID: 34813
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34813
Summary:
eLitius is prone to a vulnerability that lets remote attackers upload and=
 execute arbitrary code because it fails to properly sanitize user-suppli=
ed files. The application is also prone to an authentication-bypass vulne=
rability.
=20
 An attacker can leverage these issues to execute arbitrary code on an af=
fected computer with the privileges of the webserver process or to perfor=
m administrative actions without proper authentication.

eLitius 1.0 is vulnerable; other versions may also be affected.

27. Linux Kernel 'parisc_show_stack()' Local Denial of Service Vulnerabil=
ity
BugTraq ID: 32636
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/32636
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this issue to crash the affected computer, de=
nying service to legitimate users.=20

Versions prior to Linux kernel 2.6.28-rc7 are vulnerable.

Note that this issue applies to PA-RISC 32-bit and 64-bit architectures.

28. Linux Kernel Frame Size Integer Overflow Remote Information Disclosur=
e Vulnerability
BugTraq ID: 34654
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34654
Summary:
The Linux Kernel is prone to a remote information-disclosure vulnerabilit=
y.=20

Remote attackers can exploit this issue to obtain sensitive information t=
hat may lead to further attacks.=20

Versions prior to Linux Kernel 2.6.30-rc1 are vulnerable.

29. Linux Kernel 'NFS filename' Local Denial of Service Vulnerability
BugTraq ID: 34390
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34390
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to trigger a kernel oops, resulting in a=
 denial-of-service condition.

30. Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
BugTraq ID: 33113
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33113
Summary:
The Linux Kernel is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

The issue affects Linux Kernel 2.6.28; other versions may also be vulnera=
ble.

31. Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
BugTraq ID: 33003
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33003
Summary:
The Linux kernel is prone to a buffer-underflow vulnerability because it =
fails to perform adequate boundary checks on user-supplied data.=20

A local attacker can exploit this issue to execute arbitrary code with ke=
rnel-level privileges or crash the affected computer, denying service to =
legitimate users.=20

Versions prior to Linux kernel 2.6.28-rc1 are vulnerable.

32. Linux Kernel 'locks_remove_flock()' Local Race Condition Vulnerabilit=
y
BugTraq ID: 33237
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33237
Summary:
The Linux kernel is prone to a local race-condition vulnerability because=
 it fails to properly handle POSIX locks.

A local attacker may exploit this issue to crash the computer or gain ele=
vated privileges.

33. Linux Kernel '/ipc/shm.c' Local Denial of Service Vulnerability
BugTraq ID: 34020
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34020
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to cause the Linux kernel to lock up, re=
sulting in a denial-of-service condition.

Versions prior to Linux kernel 2.6.28.5 are vulnerable.

34. Linux Kernel Audit System 'audit_syscall_entry()' System Call Securit=
y Bypass Vulnerability
BugTraq ID: 33951
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33951
Summary:
The Linux kernel is prone to a local security-bypass vulnerability.

A local attacker may be able to exploit this issue to bypass audit mechan=
isms imposed on system calls. This may allow malicious behavior to escape=
 notice.

35. Linux Kernel MIPS Untrusted User Application Local Denial of Service =
Vulnerability
BugTraq ID: 32716
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/32716
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability affe=
cting 64-bit MIPS architectures.

Attackers can exploit this issue to cause the kernel to crash, denying se=
rvice to legitimate users.

36. Linux Kernel CIFS Remote Buffer Overflow Vulnerability
BugTraq ID: 34453
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34453
Summary:
The Linux Kernel is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

The issue affects Linux Kernel 2.6.29; other versions may also be vulnera=
ble.

37. Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Es=
calation Vulnerability
BugTraq ID: 34405
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34405
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability.

A local attacker can exploit this issue to execute arbitrary code with su=
peruser privileges, resulting in a complete compromise of the affected co=
mputer.

 Versions prior to Linux kernel 2.6.29-git14 are vulnerable.

38. Linux Kernel 64 Bit ABI System Call Parameter Privilege Escalation Vu=
lnerability
BugTraq ID: 33275
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/33275
Summary:
The Linux Kernel is prone to a local privilege-escalation vulnerability.

A local attacker may be able to exploit this issue to read or write to un=
intended address spaces. This may result in denial-of-service conditions,=
 the disclosure of sensitive information, or privilege escalation.

This issue affects versions prior to Linux 2.6.28.6 on some 64-bit archit=
ectures, including s390, PowerPC, SPARC64, and MIPS. Additional architect=
ures may also be affected.

39. Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerability
BugTraq ID: 32985
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/32985
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Local attackers can exploit this issue to cause a soft lockup, denying se=
rvice to legitimate users.

Versions prior to Linux kernel 2.6.25 are vulnerable.

40. Linux Kernel 'drivers/char/agp/generic.c' Local Information Disclosur=
e Vulnerability
BugTraq ID: 34673
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34673
Summary:
The Linux kernel is prone to a local information-disclosure vulnerability=
.=20

Local attackers can exploit this issue to obtain sensitive information th=
at may lead to further attacks.

Versions prior to the Linux kernel 2.6.30-rc3 are vulnerable.

41. ldns 'rr.c' Remote Buffer Overflow Vulnerability
BugTraq ID: 34233
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34233
Summary:
The 'ldns' library is prone to a buffer-overflow vulnerability because it=
 fails to properly bounds-check user-supplied data before copying it into=
 an insufficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of an application using the affected library. Failed exploit attem=
pts will result in denial-of-service conditions.

Versions prior to ldns 1.5.0 are vulnerable.

42. acpid Local Denial of Service Vulnerability
BugTraq ID: 34692
Remote: No
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34692
Summary:
The 'acpid' daemon is prone to a local denial-of-service vulnerability.

Successful exploits will allow attackers to make the daemon unresponsive,=
 resulting in denial-of-service conditions.

The issue affects versions prior to acpid 1.0.10.

43. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multi=
ple Remote Vulnerabilities
BugTraq ID: 34656
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34656
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.

Attackers can exploit these issues to bypass same-origin restrictions, ob=
tain potentially sensitive information, and execute arbitrary script code=
 with elevated privileges; other attacks are also possible.

44. Mozilla Firefox 'nsTextFrame::ClearTextRun()' Remote Memory Corruptio=
n Vulnerability
BugTraq ID: 34743
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34743
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability.=20

Successful exploits will allow remote attackers to execute arbitrary code=
 within the context of the affected browser or crash the browser, denying=
 service to legitimate users.

45. FreePBX Multiple Cross Site Scripting and Information Disclosure Vuln=
erabilities
BugTraq ID: 34857
Remote: Yes
Last Updated: 2009-05-07
Relevant URL: http://www.securityfocus.com/bid/34857
Summary:
FreePBX is prone to multiple cross-site scripting and information-disclos=
ure vulnerabilities.

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may help the attacker steal cookie-based authentication credentials=
 and launch other attacks. An attacker may also exploit these issues to g=
ain access to sensitive information.

FreePBX 2.4, 2.5 and trunk are affected.

46. Cscope 'find.c' Stack Based Buffer Overflow Vulnerability
BugTraq ID: 34832
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34832
Summary:
Cscope is prone to a stack-based buffer-overflow vulnerability because th=
e application fails to perform adequate boundary checks on user-supplied =
input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Versions prior to Cscope 15.6 are vulnerable.

47. SilverStripe 'AjaxUniqueTextField' Parameter SQL Injection Vulnerabil=
ity
BugTraq ID: 34852
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34852
Summary:
SilverStripe is prone to an SQL-injection vulnerability because it fails =
to sufficiently sanitize user-supplied data before using it in an SQL que=
ry.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

Versions prior to SilverStripe 2.3.3-rc2 are vulnerable.

48. ReVou 'adminlogin/password.php' Remote Password Change Vulnerability
BugTraq ID: 34851
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34851
Summary:
ReVou is prone to a vulnerability that may permit an attacker to change t=
he password of arbitrary users.

Exploiting this issue may allow the attacker to gain unauthorized access =
to the affected application. Successful exploits will completely compromi=
se victims' accounts.

49. Multiple F-Secure Products RAR/ZIP Files Scan Evasion Vulnerability
BugTraq ID: 34849
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34849
Summary:
Multiple F-Secure products are prone to a vulnerability that may allow ce=
rtain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

50. FunGamez Local File Include and SQL Injection Vulnerabilities
BugTraq ID: 34610
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34610
Summary:
FunGamez is prone to a local file-include vulnerability and multiple SQL-=
injection vulnerabilities because it fails to properly sanitize user-supp=
lied input.

An attacker can exploit the local file-include vulnerability using direct=
ory-traversal strings to view and execute arbitrary local files within th=
e context of the webserver process. Information harvested may aid in furt=
her attacks.

The attacker can exploit the SQL-injection vulnerabilities to compromise =
the application, access or modify data, or exploit latent vulnerabilities=
 in the underlying database.

51. Flatchat 'pmscript.php' Local File Include Vulnerability
BugTraq ID: 34734
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34734
Summary:
Flatchat is prone to a local file-include vulnerability because it fails =
to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to view files and execute loca=
l scripts in the context of the webserver process. This may aid in furthe=
r attacks.

Flatchat 3.0 is vulnerable; other versions may also be affected.

52. Sun Solaris DTrace Handler IOCTL Request Multiple Local Denial of Ser=
vice Vulnerabilities
BugTraq ID: 34753
Remote: No
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34753
Summary:
Sun Solaris is prone to multiple local denial-of-service vulnerabilities.=
=20

An attacker can exploit these issues to cause a system panic, denying ser=
vice to legitimate users.

Very few technical details are currently available. We will update this B=
ID as more information emerges.

These issues affect Solaris 10 and OpenSolaris builds snv_01 through snv_=
113.

53. Coccinelle Insecure Temporary File Creation Vulnerability
BugTraq ID: 34848
Remote: No
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34848
Summary:
Coccinelle creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symbolic link attacks to overwrite arbitrary attacker-specified file=
s.

Versions prior to Coccinelle 0.1.7 are vulnerable.

54. SMA-DB Cross Site Scripting and Remote File Include Vulnerabilities
BugTraq ID: 33562
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/33562
Summary:
SMA-DB is prone to a cross-site scripting vulnerability and a remote file=
-include vulnerability because it fails to sufficiently sanitize user-sup=
plied data.

An attacker can exploit these issues to execute malicious PHP code in the=
 context of the webserver process. This may allow the attacker to comprom=
ise the application and the underlying system. Attackers may also execute=
 script code in an unsuspecting user's browser or steal cookie-based auth=
entication credentials; other attacks are also possible.

SMA-DB 0.3.12 is vulnerable; other versions may also be affected.

55. FreeType Multiple Integer Overflow Vulnerabilities
BugTraq ID: 34550
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34550
Summary:
FreeType is prone to multiple integer-overflow vulnerabilities because it=
 fails to properly validate user-supplied input.=20

Successful exploits may allow attackers to execute arbitrary code in the =
context of applications that use the affected library. Failed exploit att=
empts will likely result in denial-of-service conditions.

These issues affect FreeType 2.3.9; other versions may also be affected.

56. libwmf WMF Image File Remote Code Execution Vulnerability
BugTraq ID: 34792
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34792
Summary:
The 'libwmf' library is prone to a buffer-overflow vulnerability because =
the vector graphics linked library improperly allocates memory when parsi=
ng WMF image files.

Successfully exploiting this issue would allow an attacker to corrupt mem=
ory and execute arbitrary code in the context of the currently logged-in =
user.

57. Drupal HTML Injection and Information Disclosure Vulnerabilities
BugTraq ID: 34779
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34779
Summary:
Drupal is prone to a cross-site scripting vulnerability and an informatio=
n-disclosure vulnerability.

An attacker may leverage these issues to obtain potentially sensitive inf=
ormation, execute arbitrary script code in the browser of an unsuspecting=
 user in the context of the affected site, steal cookie-based authenticat=
ion credentials, or control how the site is rendered to the user; other a=
ttacks are also possible.=20

These issues affect the following:

Drupal 5.x (prior to 5.17)
Drupal 6.x (prior to 6.11)

58. CUPS and Xpdf JBIG2 Symbol Dictionary Processing Heap Buffer Overflow=
 Vulnerability
BugTraq ID: 34791
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34791
Summary:
CUPS and Xpdf are prone to a remote buffer-overflow vulnerability because=
 they fail to properly bounds-check user-supplied input before copying it=
 into a finite-sized buffer.

Exploiting this issue may allow remote attackers to execute arbitrary cod=
e in the context of the affected application. Failed exploit attempts wil=
l likely cause denial-of-service conditions.

The following are vulnerable; other applications or versions may also be =
affected:

Xpdf 3.02pl2 and earlier
CUPS 1.3.9 and earlier

NOTE: This vulnerability may already be covered in BID 34568 (Xpdf JBIG2 =
Processing Multiple Security Vulnerabilities). We will update (or possibl=
y retire) this BID as more information emerges.

59. CUPS Insufficient 'Host' Header Validation Weakness
BugTraq ID: 34665
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34665
Summary:
CUPS is prone to an insufficient 'Host' header validation weakness.

An attacker can use this weakness to carry out certain attacks such as DN=
S rebinding against the vulnerable server.

60. SunGard Banner Student 'twbkwbis.P_SecurityQuestion' HTML Injection V=
ulnerability
BugTraq ID: 34620
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34620
Summary:
SunGard Banner Student is prone to an HTML-injection vulnerability becaus=
e it fails to sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the=
 affected site, potentially allowing the attacker to steal cookie-based a=
uthentication credentials and to control how the site is rendered to the =
user; other attacks are also possible.

Banner Student 7.4 is vulnerable; other versions may also be affected.

61. MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory=
 Corruption Vulnerability
BugTraq ID: 34409
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34409
Summary:
MIT Kerberos is prone to a memory-corruption vulnerability because it fai=
ls to properly initialize data structures.

Successful exploits may allow remote attackers to crash Kerberos servers,=
 including the 'kadmind' administration daemon. Given the nature of this =
issue, attackers may also be able to execute arbitrary code with SYSTEM-l=
evel or superuser privileges, but this has not been confirmed.

Versions prior to Kerberos 5.17 and 5.1.6.4 are vulnerable.

62. Google Chrome 'chromehtml:' Protocol Handler Same Origin Policy Bypas=
s Vulnerability
BugTraq ID: 34704
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34704
Summary:
Google Chrome is prone to a vulnerability that allows attackers to bypass=
 the same-origin policy and obtain sensitive information, including the e=
xistence of local files and authentication credentials for web applicatio=
ns. Other attacks are also possible.

Google Chrome 1.0.154.55 and prior versions are vulnerable.

63. Nucleus Kernel Recovery for Mac and Novell Multiple Buffer Overflow V=
ulnerabilities
BugTraq ID: 34846
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34846
Summary:
Multiple Nucleus Kernel Recovery products are prone to remote stack-based=
 buffer-overflow vulnerabilities because the software fails to perform ad=
equate boundary checks on user-supplied input.

Attackers may leverage these issues to execute arbitrary code in the cont=
ext of the application. Failed attacks will cause denial-of-service condi=
tions.

These issues affect the following:

Kernel Recovery for Novell 4.03
  Kernel Recovery for Macintosh 4.04

Other versions may also be affected.

64. VerliAdmin 'index.php' Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 34845
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34845
Summary:
VerliAdmin is prone to multiple cross-site scripting vulnerabilities beca=
use the application fails to properly sanitize user-supplied input.=20

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may help the attacker steal cookie-based authentication credentials=
 and launch other attacks.

The issues affect VerliAdmin 0.3.7 and 0.3.8; other versions may also be =
affected.

65. LinkBase Users Menu HTML Injection Vulnerability
BugTraq ID: 34844
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34844
Summary:
LinkBase is prone to an HTML-injection vulnerability because it fails to =
sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the=
 affected site, potentially allowing the attacker to steal cookie-based a=
uthentication credentials and to control how the site is rendered to the =
user; other attacks are also possible.

LinkBase 2.0 is vulnerable; other versions may also be affected.

66. 32bit FTP 'CWD' Response Remote Buffer Overflow Vulnerability
BugTraq ID: 34838
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34838
Summary:
32bit FTP is prone to a buffer-overflow vulnerability because it fails to=
 properly perform adequate boundary checks on user-supplied data.=20

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the vulnerable application. Failed exploit attempts will likely res=
ult in a denial-of-service condition.

32bit FTP 09.04.24 is vulnerable; other versions may also be affected.

67. Cisco Subscriber Edge Services Manager Cross Site Scripting And HTML =
Injection Vulnerabilities
BugTraq ID: 34454
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34454
Summary:
Cisco Subscriber Edge Services Manager is prone to a cross-site scripting=
 vulnerability and an HTML-injection vulnerability because it fails to su=
fficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the=
 affected site, potentially allowing the attacker to steal cookie-based a=
uthentication credentials and to control how the site is rendered to the =
user; other attacks are also possible.

We don't know which versions of Subscriber Edge Services Manager are affe=
cted. We will update this BID as more information emerges.

68. Almond Classifieds for Joomla! 'id' Parameter SQL Injection Vulnerabi=
lity
BugTraq ID: 34843
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34843
Summary:
Almond Classifieds for Joomla! is prone to an SQL-injection vulnerability=
 because it fails to sufficiently sanitize user-supplied data before usin=
g it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

Almond Classifieds for Joomla! 5.6.2 is vulnerable; other versions may al=
so be affected.

69. TemaTres SQL Injection and Cross Site Scripting Vulnerabilities
BugTraq ID: 34830
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34830
Summary:
TemaTres is prone to multiple SQL-injection and cross-site scripting vuln=
erabilities because it fails to sufficiently sanitize user-supplied data.=
=20

Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, compromise the application, access or modify dat=
a, or  exploit latent vulnerabilities in the underlying database.

TemaTres 1.0.3 is vulnerable; other versions may also be affected.

70. Xpdf JBIG2 Processing Multiple Security Vulnerabilities
BugTraq ID: 34568
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34568
Summary:
Xpdf is prone to multiple security vulnerabilities.

Exploiting these issues may allow remote attackers to execute arbitrary c=
ode in the context of an  affected application. Failed exploit attempts w=
ill likely cause denial-of-service conditions.

These issues affect multiple applications on multiple platforms that use =
the affected library.

71. CUPS '_cupsImageReadTIFF()' Integer Overflow Vulnerability
BugTraq ID: 34571
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34571
Summary:
CUPS is prone to an integer-overflow vulnerability because it fails to pe=
rform adequate boundary checks on user-supplied TIFF image sizes before u=
sing them to allocate memory buffers.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of a user running the utilities. Failed exploit attempts lik=
ely cause denial-of-service conditions.

Versions prior to CUPS 1.3.10 are vulnerable.

72. xvfb-run Insecure Magic Cookie Local Information Disclosure Vulnerabi=
lity
BugTraq ID: 34828
Remote: No
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34828
Summary:
The 'xvfb-run' command is prone to an information-disclosure vulnerabilit=
y.

Exploiting this issue may allow a local attacker to obtain sensitive info=
rmation that may lead to further attacks.

73. Woodstock 404 Error Page Cross Site Scripting Vulnerability
BugTraq ID: 34829
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34829
Summary:
Woodstock is prone to a cross-site scripting vulnerability because it fai=
ls to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site an=
d to steal cookie-based authentication credentials.

Woodstock 4.2 is vulnerable; other versions may also be affected.

74. 32bit FTP 'banner' Remote Buffer Overflow Vulnerability
BugTraq ID: 34822
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34822
Summary:
32bit FTP is prone to a buffer-overflow vulnerability because it fails to=
 properly perform adequate boundary checks on user-supplied data.=20

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the vulnerable application. Failed exploit attempts will likely res=
ult in a denial-of-service condition.

32bit FTP 09.04.24 is vulnerable; other versions may also be affected.

75. GlassFish Enterprise Server Multiple Cross Site Scripting Vulnerabili=
ties
BugTraq ID: 34824
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34824
Summary:
GlassFish Enterprise Server is prone to multiple cross-site scripting vul=
nerabilities because it fails to sufficiently sanitize user-supplied inpu=
t.

Attacker-supplied HTML and script code would run in the context of the af=
fected site, potentially allowing the attacker to steal cookie-based auth=
entication credentials.

GlassFish Enterprise Server 2.1 is vulnerable; other versions may also be=
 affected.

76. Grabit 'NZB' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 34807
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34807
Summary:
Grabit is prone to a remote stack-based buffer-overflow vulnerability bec=
ause the application fails to perform adequate boundary checks on user-su=
pplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Grabit 1.7.2 beta 3 is vulnerable; other versions may also be affected.

77. IceWarp Merak Mail Server 'item.php' Cross-Site Scripting Vulnerabili=
ty
BugTraq ID: 34825
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34825
Summary:
IceWarp Merak Mail Server is prone to a cross-site scripting vulnerabilit=
y because the application fails to properly sanitize user-supplied input.=
=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal potentially sensitive information and lau=
nch other attacks.

78. IceWarp Merak Mail Server 'Forgot Password' Input Validation Vulnerab=
ility
BugTraq ID: 34827
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34827
Summary:
IceWarp Merak Mail Server is prone to an input-validation vulnerability b=
ecause it uses client-supplied data when performing a 'Forgot Password' f=
unction.=20

Attackers can exploit this issue via social-engineering techniques to obt=
ain valid users' login credentials; other attacks may also be possible.

79. IceWarp Merak Mail Server 'cleanHTML()' Function Cross-Site Scripting=
 Vulnerability
BugTraq ID: 34823
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34823
Summary:
IceWarp Merak Mail Server is prone to a cross-site scripting vulnerabilit=
y because the application fails to properly sanitize user-supplied input.=
=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal potentially sensitive information and lau=
nch other attacks.

80. IceWarp Merak Mail Server Groupware Component Multiple SQL Injection =
Vulnerabilities
BugTraq ID: 34820
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34820
Summary:
IceWarp Merak Mail Server is prone to multiple SQL-injection vulnerabilit=
ies because it fails to sufficiently sanitize user-supplied data before u=
sing it in an SQL query.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

IceWarp Merak Mail Server 9.4.1 is affected; other versions may be vulner=
able as well.

81. Mitel NuPoint Messenger Authentication Credentials Information Disclo=
sure Vulnerability
BugTraq ID: 34847
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34847
Summary:
Mitel NuPoint Messenger is prone to an information-disclosure vulnerabili=
ty.

Exploiting this issue can allow a remote attacker to harvest sensitive in=
formation that can aid in further attacks.

Mitel NuPoint Messenger R3 and R11 are affected.

82. MoinMoin 'AttachFile.py' Multiple Cross Site Scripting Vulnerabilitie=
s
BugTraq ID: 34631
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34631
Summary:
MoinMoin is prone to multiple cross-site scripting vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data.

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks.

MoinMoin 1.8.2 is vulnerable; other versions may also be affected.

83. Nagios External Commands and Adaptive Commands Unspecified Vulnerabil=
ity=20
BugTraq ID: 32611
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/32611
Summary:
Nagios is prone to an unspecified vulnerability related to the CGI submis=
sion of external commands and the processing of adaptive commands.=20

Very little information is known about this issue. We will update this BI=
D as soon as more information becomes available.

The issue affects versions prior to Nagios 3.0.6.

84. Nagios Web Interface Privilege Escalation Vulnerability
BugTraq ID: 32156
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/32156
Summary:
Nagios is prone to an unspecified privilege-escalation scripting vulnerab=
ility.

An attacker with low-level privileges may exploit this issue to bypass au=
thorization and cause arbitrary commands to run within the context of the=
 Nagios server. This may aid in further attacks.

 Few technical details are available at this time; we will update this BI=
D as more information emerges.

The issue affects versions prior to Nagios 3.0.5.

85. Adobe Flash Player Unspecified Remote Denial of Service Vulnerability
BugTraq ID: 33890
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/33890
Summary:
Adobe Flash Player is prone to a remote denial-of-service vulnerability b=
ecause it fails to properly validate user-supplied input.

Exploiting this issue allows remote attackers to crash the application an=
d possibly to execute code, but this has not been confirmed.

Versions prior to Flash Player 10.0.22.87 are vulnerable.

86. Adobe Flash Player Invalid Object Reference Remote Code Execution Vul=
nerability
BugTraq ID: 33880
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/33880
Summary:
Adobe Flash Player is prone to a remote code-execution vulnerability.

 An attacker can exploit this issue to execute arbitrary code with the pr=
ivileges of the user running the application.  Failed exploit attempts wi=
ll likely crash the application, denying service to legitimate users.

Versions prior to Flash Player 10.0.12.36 are vulnerable.

87. Verlihub Control Panel Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 34856
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34856
Summary:
Verlihub Control Panel is prone to multiple cross-site scripting vulnerab=
ilities because the application fails to properly sanitize user-supplied =
input.=20

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site.=
 This may help the attacker steal cookie-based authentication credentials=
 and launch other attacks.

The issues affect Verlihub Control Panel 1.7e; other versions may also be=
 affected.

88. Kayako SupportSuite Ticket Notes HTML Injection Vulnerability
BugTraq ID: 34853
Remote: Yes
Last Updated: 2009-05-06
Relevant URL: http://www.securityfocus.com/bid/34853
Summary:
Kayako SupportSuite is prone to an HTML-injection vulnerability because i=
t fails to sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the=
 affected site, potentially allowing the attacker to steal cookie-based a=
uthentication credentials and to control how the site is rendered to the =
user; other attacks are also possible.

SupportSuite 3.04.10 is vulnerable; other versions may also be affected.

89. Sorinara Streaming Audio Player '.m3u' File Remote Stack Buffer Overf=
low Vulnerability
BugTraq ID: 34842
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34842
Summary:
Sorinara Streaming Audio Player is prone to a remote stack-based buffer-o=
verflow vulnerability because the application fails to perform adequate b=
oundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Sorinara Streaming Audio Player 0.9 is vulnerable; other version may also=
 be affected.

90. Sun Glassfish 'name' Parameter Cross Site Scripting Vulnerability
BugTraq ID: 29646
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/29646
Summary:
Sun Glassfish is prone to a cross-site scripting vulnerability because th=
e application fails to sufficiently sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may let the attacker steal cookie-based authentication credentials an=
d launch other attacks.

91. schroot '/tmp/shm' Local Denial of Service Vulnerability
BugTraq ID: 34819
Remote: No
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34819
Summary:
The 'schroot' program is prone to a local denial-of-service vulnerability=
.

Attackers can exploit this issue to exhaust all available memory and cras=
h a system, resulting in a denial-of-service condition.

This issue affects schroot 1.2.2; other versions may also be affected.

92. MyBB 1.4.5 Multiple Security Vulnerabilities
BugTraq ID: 34798
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34798
Summary:
MyBB is prone to multiple security vulnerabilities, including an HTML-inj=
ection issue and an unspecified issue.

An attacker may leverage the HTML-injection issue to execute arbitrary sc=
ript code in the browser of an unsuspecting user in the context of the af=
fected site. This may allow the attacker to steal cookie-based authentica=
tion credentials, control how the site is rendered to the user, and to la=
unch other attacks.

MyBB 1.4.5 is vulnerable; other versions may also be affected.

93. ProjectCMS Multiple Input Validation Vulnerabilities
BugTraq ID: 34816
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34816
Summary:
ProjectCMS is prone to multiple input-validation vulnerabilities:

- An arbitrary-file-upload vulnerability
- An information-disclosure vulnerability
- A security-bypass vulnerability

An attacker can exploit these issues to upload and execute arbitrary PHP =
code in the context of the webserver process, obtain sensitive informatio=
n, or delete an arbitrary directory.  Other attacks are also possible.

Versions prior to ProjectCMS 1.2 Beta are vulnerable.

94. Quagga Autonomous System Number Remote Denial Of Service Vulnerabilit=
y
BugTraq ID: 34817
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34817
Summary:
Quagga is prone to a remote denial-of-service vulnerability.

Exploiting this issue allows remote attackers to cause the vulnerable pro=
cess to crash, denying further service to legitimate users.

Quagga 0.99.11 is vulnerable; other versions may also be affected.

95. aMule 'wxExecute()' Arbitrary Command Execution Vulnerability
BugTraq ID: 34683
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34683
Summary:
aMule is prone to a vulnerability that lets attackers execute arbitrary c=
ommands in the context of the vulnerable application.

This issue affects aMule 2.2.4; other versions may also be vulnerable.

96. CoolPlayer M3U File Buffer Overflow Vulnerability
BugTraq ID: 30418
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/30418
Summary:
CoolPlayer is prone a buffer-overflow vulnerability because the applicati=
on fails to perform adequate boundary checks on user-supplied data.=20

The issue occurs when handling specially crafted M3U files.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application. Failed exploit attempts li=
kely result in denial-of-service conditions.

We don't know which versions of CoolPlayer are affected. We will update t=
his BID as more information emerges.

97. CoolPlayer Skin File Buffer Overflow Vulnerability
BugTraq ID: 32947
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/32947
Summary:
CoolPlayer is prone a buffer-overflow vulnerability because the applicati=
on fails to perform adequate boundary checks on user-supplied data.=20

The issue occurs when handling specially crafted skin files.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application. Failed exploit attempts li=
kely result in denial-of-service conditions.

This issue affects CoolPlayer 219; other versions may be vulnerable as we=
ll.

98. Quick 'n Easy Mail Server SMTP Request Remote Denial Of Service Vulne=
rability
BugTraq ID: 34814
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34814
Summary:
Quick 'n Easy Mail Server is prone to a denial-of-service vulnerability b=
ecause it fails to adequately handle multiple socket requests.

Attackers can exploit this issue to cause the affected application to rej=
ect SMTP requests, denying service to legitimate users.=20

The demonstration release of Quick 'n Easy Mail Server 3.3 is vulnerable;=
 other versions may also be affected.

99. AGTC MyShop Insecure Cookie Authentication Bypass Vulnerability
BugTraq ID: 34808
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34808
Summary:
AGTC MyShop is prone to an authentication-bypass vulnerability because it=
 fails to adequately verify user-supplied input used for cookie-based aut=
hentication.

Attackers can exploit this vulnerability to gain administrative access to=
 the affected application, which may aid in further attacks.

AGTC MyShop 3.2b is vulnerable; other versions may also be affected.

100. BluSky CMS 'index.php' SQL Injection Vulnerability
BugTraq ID: 34811
Remote: Yes
Last Updated: 2009-05-05
Relevant URL: http://www.securityfocus.com/bid/34811
Summary:
BluSky CMS is prone to an SQL-injection vulnerability because it fails to=
 sufficiently sanitize user-supplied data before using it in an SQL query=
.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Browsers bashed first in hacking contest
By: Robert Lemos
A security researcher keeps a vulnerability on ice for an entire year, be=
fore using it at the Pwn2Own contest to exploit Apple's browser. Microsof=
t's Internet Explorer 8 falls soon after.=20
http://www.securityfocus.com/news/11549

2. Experts: U.S. needs to defend its "cyber turf"
By: Robert Lemos
The United States must develop a Monroe Doctrine for the Internet, defini=
ng what constitutes its cyberspace and pledging to defend its virtual bor=
ders, security experts told Congress.
http://www.securityfocus.com/news/11548

3. Advisor: U.S. needs policy to defend cyberspace
By: Robert Lemos
An Obama transition-team member argues that any future cyber policy needs=
 to deal with the role of the intelligence community, the militarization =
of cyberspace and designating a lead disaster agency.
http://www.securityfocus.com/news/11547

4. Cabal forms to fight Conficker, offers bounty
By: Robert Lemos
Microsoft offers $250,000 for information leading to the arrest of the au=
thor and, along with security firms and Internet service providers, pledg=
es to work to prevent the prolific worm from spreading further.
http://www.securityfocus.com/news/11546

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
V.   INCIDENTS LIST SUMMARY
---------------------------
1. EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/5) Toky=
o CFP deadline: June 1 2009
http://www.securityfocus.com/archive/75/503338

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #442
http://www.securityfocus.com/archive/88/503195

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/5) Toky=
o CFP deadline: June 1 2009
http://www.securityfocus.com/archive/91/503313

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
 body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Thawte

Extended Validation SSL Certificates: Inspire Trust, Improve Confidence a=
nd Increase Sales

Extended Validation SSL delivers the acknowledged industry standard for t=
he highest level of online identity assurance processes for SSL certifica=
te issuance. Find out how the EV standard increases the visibility of aut=
hentication status through the use of a green address bar in the latest h=
igh security web browsers.

http://www.dinclinx.com/Redirect.aspx?36;5004;25;1371;0;3;946;54442f0f214=
c470a