SecurityFocus Newsletter #507

[email protected] Tue, 14 Jul 2009 17:20:55 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #507
----------------------------------------

This issue is sponsored by Ironkey

INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
 while strong AES 256-bit hardware encryption and active malware defenses=
 safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
 of drives and even remotely destroy drives in the field.=20

Learn more at https://www.ironkey.com/S200_Launch


------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Hacker-Tool Law Still Does Little
       2. A Botnet by Any Other Name
II.   BUGTRAQ SUMMARY
       1. Oracle Database CVE-2009-0987 Remote Upgrade Vulnerability
       2. Oracle Secure Backup CVE-2009-1977 Remote Oracle Secure Backup =
Vulnerability
       3. Irssi 'WALLOPS' Message Off By One Heap Memory Corruption Vulne=
rability
       4. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerab=
ility
       5. Adobe Reader 'getAnnots()' JavaScript Function Remote Code Exec=
ution Vulnerability
       6. Joomla! 'com_category' Component SQL Injection Vulnerability
       7. RunCMS 'upload.php' Arbitrary File Upload Vulnerability
       8. FreeBSD ATA Device Local Denial of Service Vulnerability
       9. Linux Kernel 'PER_CLEAR_ON_SETID' Incomplete Personality List A=
ccess Validation Vulnerability
       10. Joomla! and Mambo gigCalendar Component 'venuedetails.php' SQL=
 Injection Vulnerability
       11. Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulne=
rability
       12. Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbi=
trary Code Execution Vulnerability
       13. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 an=
d -11 Multiple Remote Vulnerabilities
       14. Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Esca=
lation Vulnerability
       15. Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Constructio=
n Memory Corruption Vulnerability
       16. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine =
Memory Corruption Vulnerabilities
       17. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -01 to -06 Mul=
tiple Remote Vulnerabilities
       18. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -2=
2 Multiple Remote Vulnerabilities
       19. phpScheduleIt 'reserve.php' Remote Code Execution Vulnerabilit=
y
       20. Mozilla Firefox International Domain Name Subdomain URI Spoofi=
ng Vulnerability
       21. eEye Retina WiFi Scanner '.rws' File Buffer Overflow Vulnerabi=
lity
       22. WebKit SVGList Objects Remote Memory Corruption Vulnerability
       23. Computer Associates BrightStor ARCserve Backup UniversalAgent =
Remote Buffer Overflow Vulnerability
       24. Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
       25. Mumbles Firefox Plugin Remote Arbitrary Shell Command Injectio=
n Vulnerability
       26. strongSwan Crafted X.509 Certificate Multiple Remote Denial Of=
 Service Vulnerabilities
       27. Oracle WebLogic Server CVE-2009-1974 Remote Vulnerability
       28. Oracle Config Management CVE-2009-1966 Unspecified Security Vu=
lnerability
       29. Oracle Weblogic Server CVE-2009-1975 Remote Vulnerability
       30. ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation V=
ulnerability
       31. ISC DHCP 'dhclient' 'script_write_params()' Stack Buffer Overf=
low Vulnerability
       32. Apache 'mod_proxy' Remote Denial Of Service Vulnerability
       33. Apache 'Options' and 'AllowOverride' Directives Security Bypas=
s Vulnerability
       34. Apache 'mod_deflate' Remote Denial Of Service Vulnerability
       35. Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
       36. Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vul=
nerability
       37. Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Over=
flow Vulnerability
       38. Linux Kernel 'splice(2)' Double Lock Local Denial of Service V=
ulnerability
       39. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerabilit=
y
       40. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execut=
ion Vulnerability
       41. ISC DHCP Server Host Definition Remote Denial Of Service Vulne=
rability
       42. Oracle July 2009 Critical Patch Update Multiple Vulnerabilitie=
s
       43. Microsoft DirectX DirectShow Length Record Remote Code Executi=
on Vulnerability
       44. Sun Java Runtime Environment and Java Development Kit Multiple=
 Security Vulnerabilities
       45. Microsoft Virtual PC and Virtual Server Privilege Escalation V=
ulnerability
       46. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerab=
ility=20
       47. Microsoft Windows Embedded OpenType Font Engine Integer Overfl=
ow Vulnerability
       48. Microsoft Windows Embedded OpenType Font Engine Heap Overflow =
Vulnerability
       49. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Co=
de Execution Vulnerability
       50. Microsoft DirectX DirectShow Pointer Validation Remote Code Ex=
ecution  Vulnerability
       51. Microsoft Publisher Object Handler Data Pointer Dereference Re=
mote Code Execution Vulnerability
       52. Microsoft DirectX DirectShow QuickTime Video Remote Code Execu=
tion Vulnerability
       53. Hitachi Web Server Client SSL Certificate Handling Unspecified=
 Vulnerability
       54. Hitachi Web Server Reverse Proxy Remote Denial of Service Vuln=
erability
       55. Sun Fire V215 Servers Remote Denial Of Service Vulnerability
       56. Novell eDirectory Multiple Vulnerabilities
       57. Microsoft Office Web Components ActiveX Control 'msDataSourceO=
bject' Code Execution Vulnerability
       58. Wyse Thin Client 'hagent.exe' Unspecified Buffer Overflow Vuln=
erability
       59. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnera=
bility
       60. djbdns Long Response Packet Remote Cache Poisoning Vulnerabili=
ty
       61. Horde 'Passwd' Module Cross Site Scripting Vulnerability
       62. Openswan IPsec Livetest Insecure Temporary File Creation Vulne=
rability
       63. Oracle Config Management CVE-2009-1967 Remote Unspecified Vuln=
erability
       64. Oracle Database CVE-2009-1973 Remote Virtual Private Database =
Vulnerability
       65. Oracle E-Business Suite CVE-2009-1980 Remote Vulnerability
       66. Oracle Advanced Replication CVE-2009-1021 Remote Unspecified V=
ulnerability
       67. Oracle Database CVE-2009-1970 Remote Listener Vulnerability
       68. Oracle Database CVE-2009-1015 Remote Core RDBMS Vulnerability
       69. Oracle Database CVE-2009-1968 Remote Secure Enterprise Search =
Vulnerability
       70. Oracle Database CVE-2009-1019 Remote Network Authentication Vu=
lnerability
       71. Oracle Secure Backup CVE-2009-1978 Remote Oracle Secure Backup=
 Vulnerability
       72. Oracle Database CVE-2009-1963 Remote Network Foundation=20
       73. Oracle Complex Event Processing CVE-2009-1523 Remote Vulnerabi=
lity
       74. IETF and W3C XML Digital Signature Specification HMAC Truncati=
on Authentication Bypass Vulnerability
       75. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
       76. Git Parameter Processing Remote Denial Of Service Vulnerabilit=
y
       77. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Co=
rruption Vulnerability
       78. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow V=
ulnerability
       79. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap=
 Buffer Overflow Vulnerability
       80. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
       81. Adobe Reader and Acrobat TrueType Font Handling Memory Corrupt=
ion Vulnerability
       82. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote=
 Heap Buffer Overflow Vulnerability
       83. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overf=
low Vulnerability
       84. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corru=
ption Vulnerability
       85. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerabil=
ity
       86. Novell NetIdentity Agent 'XTIERRPCPIPE' Remote Code Execution =
Vulnerability
       87. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
       88. Microsoft Windows Print Spooler Local Information Disclosure V=
ulnerability
       89. HP ProCurve Threat Management Services zl Module VPN Remote De=
nial of Service Vulnerability
       90. HP ProCurve Threat Management Services zl Module CRL Security =
Bypass Vulnerability
       91. HP ProCurve Threat Management Services zl Module 'httpd' Denia=
l of Service Vulnerability
       92. CamlImages PNG Image Parsing Multiple Integer Overflow Vulnera=
bilities
       93. HP ProCurve Threat Management Services zl Module DNS Remote De=
nial of Service Vulnerability
       94. Adobe Reader 'spell.customDictionaryOpen()' JavaScript Functio=
n Remote Code Execution Vulnerability
       95. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remo=
te Heap Buffer Overflow Vulnerability
       96. D-Bus 'dbus_signature_validate()' Type Signature Denial of Ser=
vice Vulnerability
       97. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflo=
w Vulnerability
       98. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buff=
er Overflow Vulnerabilities
       99. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
       100. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vuln=
erabilities
III.  SECURITYFOCUS NEWS
       1. Web attacks hit U.S., South Korean sites
       2. FTC persuades court to shutter rogue ISP
       3. Obama launches cybersecurity initiative
       4. Browsers bashed first in hacking contest
IV.   SECURITY JOBS LIST SUMMARY
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Hacker-Tool Law Still Does Little
By Mark Rasch
On August 10, 2007, a new section of the German Penal code went into effe=
ct. The statute, intended to implement certain provisions of the Council =
of Europe Treaty on Cybercrime, could be interpreted to make the creation=
 or distribution of computer security software a criminal offense.=20
http://www.securityfocus.com/columnists/502

2. A Botnet by Any Other Name
By Gubter Ollmann
The news has been awash the last few weeks with fears over globe-spanning=
 botnets and their criminal intent: Conficker managed to hog the limeligh=
t for well over a month, and then came Finjan's disclosure of a previousl=
y unknown - and currently unnamed - botnet consisting of some 1.9 million=
 malicious agents.=20
http://www.securityfocus.com/columnists/501


II.  BUGTRAQ SUMMARY
--------------------
1. Oracle Database CVE-2009-0987 Remote Upgrade Vulnerability
BugTraq ID: 35679
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35679
Summary:
Oracle Database is prone to a remote vulnerability affecting the 'Upgrade=
' component.
=20
An attacker with 'Create Session' privileges can exploit the vulnerabilit=
y over the 'Oracle Net' protocol.

The following are vulnerable:

Oracle Oracle9i 9.2.0.8 and 9.2.0.8DV
 Oracle Oracle10g 10.1.0.5 and 10.2.0.3

 Other versions may also be affected.

2. Oracle Secure Backup CVE-2009-1977 Remote Oracle Secure Backup Vulnera=
bility
BugTraq ID: 35672
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35672
Summary:
Oracle Secure Backup is prone to a remote vulnerability that can be explo=
ited over the 'HTTP' protocol. An attacker doesn't require privileges to =
exploit this vulnerability.=20

This vulnerability affects versions prior to Oracle Secure Backup 10.2.0.=
3.

3. Irssi 'WALLOPS' Message Off By One Heap Memory Corruption Vulnerabilit=
y
BugTraq ID: 35399
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35399
Summary:
Irssi is prone to an off-by-one, heap-based, memory-corruption vulnerabil=
ity because it fails to properly bounds-check user-supplied data before c=
opying it into a memory buffer.

Attackers can exploit this issue to crash the vulnerable client, resultin=
g in a denial-of-service condition. Given the nature of this issue, attac=
kers may also be able to run arbitrary code within the context of the vul=
nerable application, but this has not been confirmed.

Iirssi 0.8.13 is vulnerable; other versions may also be affected.

4. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerability
BugTraq ID: 35289
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35289
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.=20

Exploiting this issue will allow remote attackers to execute arbitrary co=
de within the context of the affected application or crash the applicatio=
n.

 NOTE: This issue was previously covered in BID 35274 (Adobe Reader and A=
crobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been ass=
igned its own record to better document it.

5. Adobe Reader 'getAnnots()' JavaScript Function Remote Code Execution V=
ulnerability
BugTraq ID: 34736
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34736
Summary:
Adobe Reader is prone to a remote code-execution vulnerability.

 An attacker can exploit this issue to execute arbitrary code with the pr=
ivileges of the user running the application or crash the application, de=
nying service to legitimate users.

Reader 8.1.4 and 9.1 for Linux are vulnerable; other versions or platform=
s may also be affected.

UPDATE (April 28, 2009): The vendor is investigating this issue. We will =
update this BID as more  information emerges.

UPDATE (May 1, 2009): The vendor indicates that fixes will be available b=
y May 12, 2009.  Please see the referenced advisory for more information.

UPDATE (May 18, 2009): The vendor indicates that fixes for Adobe Reader 7=
 for Apple Mac OS X will be available by the end of June, 2009. Please se=
e the updated advisory for more information.

6. Joomla! 'com_category' Component SQL Injection Vulnerability
BugTraq ID: 35638
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35638
Summary:
The 'com_category' component for Joomla! is prone to an SQL-injection vul=
nerability because it fails to sufficiently sanitize user-supplied data b=
efore using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

7. RunCMS 'upload.php' Arbitrary File Upload Vulnerability
BugTraq ID: 35646
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35646
Summary:
RunCMS is prone to a vulnerability that lets attackers upload arbitrary f=
iles. The issue occurs because the application fails to adequately valida=
te user-supplied input.=20

An attacker can exploit this vulnerability to upload arbitrary code and e=
xecute it in the context of the webserver process. This may facilitate un=
authorized access or privilege escalation; other attacks are also possibl=
e.

RunCMS 1.6.3 is vulnerable; other versions may also be affected.

8. FreeBSD ATA Device Local Denial of Service Vulnerability
BugTraq ID: 35645
Remote: No
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35645
Summary:
FreeBSD is prone to a local denial-of-service vulnerability when the kern=
el handles a specially crafted IOCTL request to an ATA device.
=20
Exploiting this issue allows attackers with local, interactive access to =
affected computers to trigger kernel panics, which will deny further serv=
ice to legitimate users.

9. Linux Kernel 'PER_CLEAR_ON_SETID' Incomplete Personality List Access V=
alidation Vulnerability
BugTraq ID: 35647
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35647
Summary:
The Linux Kernel is prone to an unauthorized-access vulnerability because=
 of an error in the definition of the 'PER_CLEAR_ON_SETID' personalities =
mask. These masks are defined in the 'include/linux/personality.h' source=
 file.

An attacker can exploit this issue to perform privileged operations on a =
vulnerable computer, which may aid in further attacks.

10. Joomla! and Mambo gigCalendar Component 'venuedetails.php' SQL Inject=
ion Vulnerability
BugTraq ID: 33863
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/33863
Summary:
The gigCalendar component for Joomla! and Mambo is prone to an SQL-inject=
ion vulnerability because it fails to sufficiently sanitize user-supplied=
 data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

gigCalendar 1.0 is vulnerable; other versions may also be affected.

11. Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulnerabilit=
y
BugTraq ID: 35380
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35380
Summary:
Multiple web browsers are prone to a man-in-the-middle vulnerability.

Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how sites are rendered to the use=
r. Other attacks are also possible.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

UPDATE (June 17, 2009): This BID had been updated to reflect that the iss=
ue affects multiple browsers, not just Mozilla products.

12. Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbitrary C=
ode Execution Vulnerability
BugTraq ID: 35383
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35383
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote code-ex=
ecution vulnerability.

Attackers can exploit this issue to execute arbitrary JavaScript code wit=
h chrome privileges. This may result in elevated privileges or lead to a =
denial-of-service condition. Other attacks may also be possible.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

13. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 M=
ultiple Remote Vulnerabilities
BugTraq ID: 33990
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/33990
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.

Attackers can exploit these issues to bypass same-origin restrictions, ob=
tain potentially sensitive information, and execute arbitrary script code=
 with elevated privileges; other attacks are also possible.

14. Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Escalation =
Vulnerability
BugTraq ID: 35373
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35373
Summary:
Mozilla Firefox and SeaMonkey are prone to a privilege-escalation vulnera=
bility in the browser's sidebar and FeedWriter.

Attackers can exploit this issue to execute arbitrary code with the objec=
t's chrome privileges.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

15. Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Construction Memor=
y Corruption Vulnerability
BugTraq ID: 35371
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35371
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote memory-=
corruption vulnerability.

An attacker can exploit these issues to corrupt memory on the affected co=
mputer and run arbitrary code in the context of the user running the affe=
cted application. Failed exploit attempts will cause denial-of-service co=
nditions.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

16. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine Memory =
Corruption Vulnerabilities
BugTraq ID: 35370
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35370
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to multiple remote =
memory-corruption vulnerabilities.

An attacker can exploit these issues to corrupt memory on the affected co=
mputer and run arbitrary code in the context of the user running the affe=
cted application. Failed exploit attempts will cause denial-of-service co=
nditions.

NOTE: In some cases, arbitrary code execution may not be possible.

NOTE: These issues were previously covered in BID 35326 (Mozilla Firefox/=
Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabil=
ities), but have been assigned their own record to better document them.

17. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -01 to -06 Multiple R=
emote Vulnerabilities
BugTraq ID: 33598
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/33598
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Mozilla Firefox, Thunderbird, and SeaMonkey=
.

Attackers can exploit these issues to bypass same-origin restrictions, ob=
tain potentially sensitive information, bypass certain security settings,=
 and execute arbitrary script code with elevated privileges; other attack=
s are also possible.

18. Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multi=
ple Remote Vulnerabilities
BugTraq ID: 34656
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34656
Summary:
The Mozilla Foundation has released multiple security advisories specifyi=
ng various vulnerabilities in Firefox, Thunderbird, and SeaMonkey.

Attackers can exploit these issues to bypass same-origin restrictions, ob=
tain potentially sensitive information, and execute arbitrary script code=
 with elevated privileges; other attacks are also possible.

19. phpScheduleIt 'reserve.php' Remote Code Execution Vulnerability
BugTraq ID: 31520
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/31520
Summary:
phpScheduleIt is prone to a vulnerability that lets remote attackers exec=
ute arbitrary code because the application fails to sanitize user-supplie=
d input.

An attacker can leverage this issue to execute arbitrary PHP code on an a=
ffected computer with the privileges of the webserver process.=20

phpScheduleIt 1.2.10 is vulnerable; other versions may also be affected.

20. Mozilla Firefox International Domain Name Subdomain URI Spoofing Vuln=
erability
BugTraq ID: 33837
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/33837
Summary:
Mozilla Firefox is affected by a URI-spoofing vulnerability because it fa=
ils to adequately handle specific characters in international domain name=
 (IDN) subdomains.

An attacker may leverage this issue to spoof the source URI of a site pre=
sented to an unsuspecting user. This may lead to a false sense of trust b=
ecause the user may be presented with a source URI of a trusted site whil=
e interacting with the attacker's malicious site.

Firefox 3.0.6 is vulnerable; other versions may also be affected.

21. eEye Retina WiFi Scanner '.rws' File Buffer Overflow Vulnerability
BugTraq ID: 35624
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35624
Summary:
eEye Retina WiFi Scanner is prone to a buffer-overflow vulnerability beca=
use the application fails to perform adequate boundary checks on user-sup=
plied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

eEye Retina WiFi Scanner 1.0.8.68 is vulnerable; other versions may also =
be affected.

22. WebKit SVGList Objects Remote Memory Corruption Vulnerability
BugTraq ID: 34924
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34924
Summary:
WebKit is prone to a remote memory-corruption vulnerability.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application.  Failed exploit attempts will result in a denial-o=
f-service condition.

The issue also affects the following:

Apple Safari prior to 3.2.3
 Apple Mac OS X v10.5 through v10.5.6,
Apple Mac OS X Server v10.5 through v10.5.6
Google Chrome prior to 1.0.154.65

23. Computer Associates BrightStor ARCserve Backup UniversalAgent Remote =
Buffer Overflow Vulnerability
BugTraq ID: 13102
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/13102
Summary:
A remote buffer-overflow vulnerability affects BrightStor ARCserve and AR=
Cserve Enterprise agent because the application fails to securely copy da=
ta from the network.=20
=20
A remote attacker may exploit this issue to execute arbitrary code on a v=
ulnerable computer, potentially facilitating unauthorized superuser acces=
s. A denial-of-service condition may arise as well.=20
=20
BrightStor ARCserve Backup v11 for Win32 platforms is vulnerable; other v=
ersions may also be affected.

24. Apache 'mod_proxy_ajp' Information Disclosure Vulnerability
BugTraq ID: 34663
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34663
Summary:
The 'mod_proxy_ajp' module for Apache is prone to a remote information-di=
sclosure vulnerability.

Attackers can exploit this issue to obtain sensitive information that may=
 lead to further attacks.

This issue affects 'mod_proxy_ajp' 2.2.1; other versions may also be affe=
cted.

25. Mumbles Firefox Plugin Remote Arbitrary Shell Command Injection Vulne=
rability
BugTraq ID: 35640
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35640
Summary:
Mumbles is prone to a remote command-injection vulnerability because it f=
ails to adequately sanitize user-supplied input data. The issue affects t=
he Firefox plugin.

Remote attackers may be able to exploit this issue to execute arbitrary s=
hell commands with the privileges of the user running the application.

Mumbles 0.4 is vulnerable; other versions may also be affected.

26. strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Servic=
e Vulnerabilities
BugTraq ID: 35452
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35452
Summary:
strongSwan is prone to multiple remote denial-of-service vulnerabilities.

Attackers can exploit these issues to crash the application, denying acce=
ss to legitimate users.

Versions prior to strongSwan 2.8.10,  4.3.2, and 4.2.16 are vulnerable.

27. Oracle WebLogic Server CVE-2009-1974 Remote Vulnerability
BugTraq ID: 35674
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35674
Summary:
Oracle WebLogic Server is prone to a remote vulnerability that can be exp=
loited over the 'HTTP' protocol. A successful exploit can occur if the at=
tacker has 'Servlet Container Package' privileges.=20

This vulnerability affects the following supported versions:

10.3
10.0 MP1
9.2 MP3
9.1
9.0
8.1 SP6
7.0 SP7

28. Oracle Config Management CVE-2009-1966 Unspecified Security Vulnerabi=
lity
BugTraq ID: 35676
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35676
Summary:
Oracle Config Management is prone to an unspecified remote vulnerability.
=20
An attacker with 'Valid Session' privileges can exploit this issue over t=
he 'HTTP' protocol.

29. Oracle Weblogic Server CVE-2009-1975 Remote Vulnerability
BugTraq ID: 35673
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35673
Summary:
Oracle WebLogic Server is prone to a remote vulnerability that can be exp=
loited over the 'HTTP' protocol. A successful exploit can occur if the at=
tacker has 'WLS Console Package' privileges.=20

This vulnerability affects Oracle WebLogic Server 10.3.

30. ISC DHCP 'dhcpd -t' Command Insecure Temporary File Creation Vulnerab=
ility
BugTraq ID: 35670
Remote: No
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35670
Summary:
ISC DHCP creates temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to per=
form symbolic link attacks to overwrite arbitrary attacker-specified file=
s.

31. ISC DHCP 'dhclient' 'script_write_params()' Stack Buffer Overflow Vul=
nerability
BugTraq ID: 35668
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35668
Summary:
The ISC DHCP client 'dhclient' is prone to a remote stack-based buffer-ov=
erflow vulnerability because it fails to properly bounds-check user-suppl=
ied input before copying it into a fixed-length buffer.

Successfully exploiting this issue allows a remote attacker to execute ar=
bitrary code with superuser privileges, resulting in a complete compromis=
e of the affected computer.

32. Apache 'mod_proxy' Remote Denial Of Service Vulnerability
BugTraq ID: 35565
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35565
Summary:
The Apache 'mod_proxy' module is prone to a denial-of-service vulnerabili=
ty.

Successful exploits may allow remote attackers to cause denial-of-service=
 conditions and prevent legitimate users from accessing the services.

33. Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulne=
rability
BugTraq ID: 35115
Remote: No
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35115
Summary:
Apache HTTP server is prone to a security-bypass vulnerability related to=
 the handling of specific configuration directives.=20

 A local attacker may exploit this issue to execute arbitrary code within=
 the context of the webserver process. This may result in elevated privil=
eges or aid in further attacks.

Versions prior to Apache 2.2.11 are vulnerable.

34. Apache 'mod_deflate' Remote Denial Of Service Vulnerability
BugTraq ID: 35623
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35623
Summary:
The Apache 'mod_deflate' module is prone to a denial-of-service vulnerabi=
lity.

Successful exploits may allow remote attackers to cause denial-of-service=
 conditions and prevent legitimate users from accessing the services.

35. Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
BugTraq ID: 34934
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/34934
Summary:
The Linux Kernel is prone to an security-bypass vulnerability that affect=
s the NFS (Network File System) implementation.

An attacker can exploit this issue to perform privileged operations on a =
vulnerable computer, which may aid in further attacks.

36. Linux Kernel 'e1000/e1000_main.c' Remote Denial of Service Vulnerabil=
ity
BugTraq ID: 35185
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35185
Summary:
The Linux kernel is prone to a remote denial-of-service vulnerability.

Attackers can exploit this issue via crafted packets to cause a kernel pa=
nic, denying service to legitimate users.

37. Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Overflow Vu=
lnerability
BugTraq ID: 34612
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/34612
Summary:
The Linux Kernel is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

38. Linux Kernel 'splice(2)' Double Lock Local Denial of Service Vulnerab=
ility
BugTraq ID: 35143
Remote: No
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35143
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

Attackers can exploit this issue to cause an affected process to hang, de=
nying service to legitimate users. Other denial-of-service attacks are al=
so possible.

This issue was introduced in Linux Kernel 2.6.19.  The following versions=
 have been fixed:

Linux Kernel 2.6.30-rc3
Linux Kernel 2.6.27.24
Linux Kernel 2.6.29.4

39. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
BugTraq ID: 35281
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35281
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to crash the system, denying service t=
o legitimate users.=20
Given the nature of this issue, the attacker may also be able to run arbi=
trary code, but this has not been confirmed.

Versions prior to Linux Kernel 2.6.30 are vulnerable.

40. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vul=
nerability
BugTraq ID: 35660
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35660
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability.=20

Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running the affected application. Failed attempts w=
ill likely result in denial-of-service conditions.

The issue affects Firefox 3.5; other versions may also be vulnerable.

NOTE: Remote code execution was confirmed in Firefox 3.5 running on Micro=
soft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP=
3.

41. ISC DHCP Server Host Definition Remote Denial Of Service Vulnerabilit=
y
BugTraq ID: 35669
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35669
Summary:
ISC DHCP Server is prone to a remote denial-of-service vulnerability beca=
use it fails to adequately handle specially crafted DHCP requests.

Attackers can exploit this issue to cause the server to terminate, thus d=
enying service to legitimate users.

42. Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
BugTraq ID: 35618
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35618
Summary:
Oracle has released the July 2009 critical patch update, which addresses =
the following 30 vulnerabilities:

Application Server is vulnerable to the following two issues:

CVE-2009-0217 - This issue affects the Oracle Security Developer Tools co=
mponent and requires HTTP access. No authentication is required. Successf=
ul attacks may compromise the integrity of the server.

CVE-2009-1976 - This issue affects the HTTP Server component and requires=
 HTTP access. No authentication is required. Successful attacks may compr=
omise the integrity of the server.


Oracle E-Business Suite is vulnerable to the following five issues:

CVE-2009-1980 - This issue affects the Oracle Application Object Library =
component and requires HTTP access. Successful authentication is required=
. Successful attacks may compromise the confidentiality, integrity, and a=
vailability of the server.

CVE-2009-1982 - This issue affects the Oracle Applications Framework comp=
onent and requires HTTP access. No authentication is required. Successful=
 attacks may compromise the integrity of the server.

CVE-2009-1983 - This issue affects the Oracle iStore component and requir=
es HTTP access. No authentication is required. Successful attacks may com=
promise the integrity of the server.

CVE-2009-1984 - This issue affects the Application Install component and =
requires local access. No authentication is required. Successful attacks =
may compromise the confidentiality, integrity, and availability of the se=
rver.

CVE-2009-1986 - This issue affects the Oracle Applications Manager compon=
ent and requires HTTP access. No authentication is required. Successful a=
ttacks may compromise the confidentiality of the server.


BEA Products Suite is vulnerable to the following five issues:

CVE-2009-1094 - This issue affects the JRockit component and requires HTT=
P access. No authentication is required. Successful attacks may compromis=
e the confidentiality, integrity, and availability of the server.

CVE-2009-1523 - This issue affects the Oracle Complex Event Processing co=
mponent and requires HTTP access. No authentication is required. Successf=
ul attacks may compromise the confidentiality of the server.

CVE-2009-1974 - This issue affects the WebLogic Server component and requ=
ires HTTP access. No authentication is required. Successful attacks may c=
ompromise the confidentiality, integrity, and availability of the server.

CVE-2009-1975 - This issue affects the WebLogic Server  component and req=
uires HTTP access. No authentication is required. Successful attacks may =
compromise the confidentiality, integrity, and availability of the server=
.


Oracle Database is vulnerable to the following 10 issues:

CVE-2009-0987 - This issue affects the Upgrade component and requires Ora=
cle Net access. Successful authentication is required. Successful attacks=
 may compromise the confidentiality and integrity of the server.

CVE-2009-1015 - This issue affects the Core RDBMS component and requires =
Oracle Net access. Successful authentication is required. Successful atta=
cks may compromise the integrity of the server.

CVE-2009-1019 - This issue affects the Network Authentication component a=
nd requires Oracle Net access. No authentication is required. Successful =
attacks may compromise the confidentiality, integrity, and availability o=
f the server.

CVE-2009-1020 - This issue affects the Network Foundation component and r=
equires Oracle Net access. Successful authentication is required. Success=
ful attacks may compromise the confidentiality, integrity, and availabili=
ty of the server.

CVE-2009-1021 - This issue affects the Advanced Replication component and=
 requires Oracle Net access. Successful authentication is required. Succe=
ssful attacks may compromise the confidentiality and integrity of the ser=
ver.

CVE-2009-1963 - This issue affects the Network Foundation component and r=
equires Oracle Net access. Successful authentication is required. Success=
ful attacks may compromise the integrity and availability of the server.

CVE-2009-1968 - This issue affects the Secure Enterprise Search component=
 and requires HTTP access. No authentication is required. Successful atta=
cks may compromise the integrity of the server.

CVE-2009-1969 - This issue affects the Auditing component and requires Or=
acle Net access. Successful authentication is required. Successful attack=
s may compromise the confidentiality of the server.

CVE-2009-1970 - This issue affects the Listener component and requires Or=
acle Net access. No authentication is required. Successful attacks may co=
mpromise the availability of the server.

CVE-2009-1973 - This issue affects the Virtual Private Database component=
 and requires Oracle Net access. Successful authentication is required. S=
uccessful attacks may compromise the confidentiality and integrity of the=
 server.


Oracle Enterprise Manager is vulnerable to the following two issues:

CVE-2009-1966 - This issue affects the Config Management component and re=
quires HTTP access. Successful authentication is required. Successful att=
acks may compromise the confidentiality and integrity of the server.

CVE-2009-1967 - This issue affects the Config Management component and re=
quires HTTP access. Successful authentication is required. Successful att=
acks may compromise the confidentiality and integrity of the server.


Oracle Secure Backup is vulnerable to the following two issues:

CVE-2009-1977 - This issue affects the Oracle Secure Backup component and=
 requires HTTP access. No authentication is required. Successful attacks =
may compromise the confidentiality, integrity, and availability of the se=
rver.

CVE-2009-1978 - This issue affects the Oracle Secure Backup component and=
 requires HTTP access. Successful authentication is required. Successful =
attacks may compromise the confidentiality, integrity, and availability o=
f the server.


Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne are vulnerable =
to the following three issues:

CVE-2009-1987 - This issue affects the PeopleSoft Enterprise PeopleTools =
- Enterprise Portal component and requires HTTP access. No authentication=
 is required. Successful attacks may compromise the integrity of the serv=
er.

CVE-2009-1988 - This issue affects the PeopleSoft  Enterprise HRMS eProfi=
le Manager component and requires HTTP access. Successful authentication =
is required. Successful attacks may compromise the confidentiality of the=
 server.

CVE-2009-1989 - This issue affects the PeopleSoft Enterprise FMS componen=
t and requires HTTP access. Successful authentication is required. Succes=
sful attacks may compromise the confidentiality and integrity of the serv=
er.


Siebel Products Suite is vulnerable to the following issue:

CVE-2009-1981 - This issue affects the Highly Interactive Client componen=
t and requires HTTP access. Successful authentication is required. Succes=
sful attacks may compromise the confidentiality and integrity of the serv=
er.

43. Microsoft DirectX DirectShow Length Record Remote Code Execution Vuln=
erability
BugTraq ID: 35616
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35616
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.

Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.

44. Sun Java Runtime Environment and Java Development Kit Multiple Securi=
ty Vulnerabilities
BugTraq ID: 34240
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/34240
Summary:
Sun Java Runtime Environment and Java Development Kit are prone to multip=
le security vulnerabilities.

Successful exploits may allow attackers to violate the same-origin policy=
, obtain sensitive information, bypass security restrictions, run untrust=
ed applets with elevated privileges, and cause denial-of-service conditio=
ns. This may result in a compromise of affected computers.

These issues affect versions *prior to* the following:

JDK and JRE 6 Update 13
JDK and JRE 5.0 Update 18
SDK and JRE 1.4.2_20
SDK and JRE 1.3.1_25

45. Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerab=
ility
BugTraq ID: 35601
Remote: No
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35601
Summary:
Microsoft Virtual PC and Virtual Server are prone to a privilege-escalati=
on vulnerability caused by an error in decoding privileged instructions.

Note that this issue affects only systems that do not use hardware-assist=
ed virtualization.

Successful exploits may allow local attackers to elevate privileges withi=
n a guest operating system.

46. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability=20
BugTraq ID: 35631
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35631
Summary:
Microsoft ISA Server is prone to an authentication-bypass vulnerability.

An attacker with knowledge of a valid account name can exploit this issue=
 to bypass authentication and gain access to arbitrary resources within t=
he context of the selected account.

47. Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vuln=
erability
BugTraq ID: 35187
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35187
Summary:
Microsoft Windows is prone to a remotely exploitable integer-overflow vul=
nerability because it fails to properly bounds-check user-supplied input =
before copying it into an insufficiently sized memory buffer.=20

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of the vulnerable software on the targeted user's compute=
r.

48. Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnera=
bility
BugTraq ID: 35186
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35186
Summary:
Microsoft Windows is prone to a remotely exploitable heap-overflow vulner=
ability because the software fails to properly bounds-check user-supplied=
 input before copying it into an insufficiently sized memory buffer.=20

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of the vulnerable software on the targeted user's compute=
r.

49. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Code Exec=
ution Vulnerability
BugTraq ID: 35558
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35558
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability that =
affects the TV Tuner library.

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

Windows XP SP3 and Windows Server 2003 are vulnerable; other versions may=
 also be affected.

50. Microsoft DirectX DirectShow Pointer Validation Remote Code Execution=
  Vulnerability
BugTraq ID: 35600
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35600
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.

Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.

51. Microsoft Publisher Object Handler Data Pointer Dereference Remote Co=
de Execution Vulnerability
BugTraq ID: 35599
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35599
Summary:
Microsoft Publisher is prone to a remote code-execution vulnerability.

An attacker can exploit this issue by enticing a victim to open a malicio=
us Publisher file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

52. Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vu=
lnerability
BugTraq ID: 35139
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35139
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability becau=
se the DirectShow component fails to properly handle QuickTime media file=
s.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application that uses =
DirectX. Failed exploit attempts will result in a denial-of-service condi=
tion.

53. Hitachi Web Server Client SSL Certificate Handling Unspecified Vulner=
ability
BugTraq ID: 35665
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35665
Summary:
Hitachi Web Server is prone to an unspecified vulnerability when handling=
 client SSL certificates.

Attackers may exploit this issue to manipulate certain environment variab=
les and potentially gain unauthorized access to the vulnerable server.

54. Hitachi Web Server Reverse Proxy Remote Denial of Service Vulnerabili=
ty
BugTraq ID: 35663
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35663
Summary:
Hitachi Web Server is prone to a denial-of-service vulnerability because =
the reverse proxy function fails to properly handle invalid responses fro=
m a remote backend server.

Attackers may exploit this issue to cause denial-of-service conditions.

55. Sun Fire V215 Servers Remote Denial Of Service Vulnerability
BugTraq ID: 35661
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35661
Summary:
Sun Fire V215 servers are prone to a remote denial-of-service vulnerabili=
ty.

An attacker may exploit this issue to panic the system, denying services =
to legitimate users.

56. Novell eDirectory Multiple Vulnerabilities
BugTraq ID: 35666
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35666
Summary:
Novell eDirectory is prone to multiple buffer-overflow and denial-of-serv=
ice vulnerabilities.

Successful exploits may allow attackers to execute arbitrary code within =
the context of the affected application or cause denial-of-service condit=
ions.

These issues affect eDirectory 8.8 SP3 and 8.8 SP3 FTF3.

57. Microsoft Office Web Components ActiveX Control 'msDataSourceObject' =
Code Execution Vulnerability
BugTraq ID: 35642
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35642
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability that affects the OWC Spreadsheet ActiveX control. The control is=
 identified by the following CLSIDs:

0002E541-0000-0000-C000-000000000046
0002E559-0000-0000-C000-000000000046

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted site.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

58. Wyse Thin Client 'hagent.exe' Unspecified Buffer Overflow Vulnerabili=
ty
BugTraq ID: 35650
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35650
Summary:
Wyse Thin Client is prone to a buffer-overflow vulnerability because it f=
ails to perform adequate boundary checks on user-supplied data before cop=
ying it to insufficiently sized buffers.

Exploiting this issue will allow an attacker to execute arbitrary code in=
 the context of the application, corrupt memory, or to cause denial-of-se=
rvice conditions.

This issue affects unknown versions of Wyse Thin Client.  This BID will b=
e updated when more details become available.

59. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 35649
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35649
Summary:
Wyse Device Manager is prone to a remote buffer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

60. djbdns Long Response Packet Remote Cache Poisoning Vulnerability
BugTraq ID: 33937
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/33937
Summary:
The 'djbdns' package is prone to a remote cache-poisoning vulnerability.
=20
An attacker may leverage this issue to manipulate cache data, potentially=
 facilitating man-in-the-middle, site-impersonation, or denial-of-service=
 attacks.

This issue affects djbdns 1.05; other versions may also be vulnerable.

61. Horde 'Passwd' Module Cross Site Scripting Vulnerability
BugTraq ID: 35573
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35573
Summary:
The Horde 'Passwd' module is prone to a cross-site scripting vulnerabilit=
y because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may let the attacker steal cookie-based authentication credentials an=
d launch other attacks.

Versions prior to Horde 'Passwd' 3.1.1 are vulnerable.

62. Openswan IPsec Livetest Insecure Temporary File Creation Vulnerabilit=
y
BugTraq ID: 31243
Remote: No
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/31243
Summary:
Openswan creates temporary files in an insecure manner.

An attacker with local access could potentially exploit these issues to p=
erform symbolic-link attacks, overwriting arbitrary files in the context =
of the affected application.

Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
 attacks may also be possible.

UPDATE (March 9, 2009): The vendor disputes the validity of this issue, s=
tating that the vulnerable code was incomplete and never run from within =
the application. The vendor also reports that the latest version of Opens=
wan has disabled the offending code.

63. Oracle Config Management CVE-2009-1967 Remote Unspecified Vulnerabili=
ty
BugTraq ID: 35692
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35692
Summary:
Oracle Config Management is prone to a remote unspecified vulnerability.
=20
The vulnerability can be exploited over the 'HTTP' protocol. A successful=
 exploit can occur if the attacker has 'Valid Session' privileges.

64. Oracle Database CVE-2009-1973 Remote Virtual Private Database Vulnera=
bility
BugTraq ID: 35687
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35687
Summary:
Oracle Database is prone to a remote vulnerability affecting the 'Virtual=
 Private Database' component.
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. A succ=
essful exploit can occur if the attacker has privileges to access tables =
with VPD (Virtual Private Database) policies.

The following are vulnerable; other versions may also be affected:

Oracle10g 10.1.0.5 and 10.2.0.4
Oracle11g 11.1.0.7

65. Oracle E-Business Suite CVE-2009-1980 Remote Vulnerability
BugTraq ID: 35686
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35686
Summary:
Oracle E-Business Suite is prone to a remote vulnerability in the Applica=
tion Object Library component.
=20
The vulnerability can be exploited over the 'HTTP' protocol. An attacker =
does not require privileges to exploit this vulnerability.=20

This vulnerability affects the following versions of E-Business Suite:

11.5.10.2,  12.0.6 and  12.1

66. Oracle Advanced Replication CVE-2009-1021 Remote Unspecified Vulnerab=
ility
BugTraq ID: 35685
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35685
Summary:
Oracle Advanced Replication is prone to a remote unspecified vulnerabilit=
y.
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. A succ=
essful exploit can occur if the attacker has 'Create Session' privileges.

67. Oracle Database CVE-2009-1970 Remote Listener Vulnerability
BugTraq ID: 35683
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35683
Summary:
Oracle Database is prone to a remote vulnerability affecting the 'Listene=
r' component.=20
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. An att=
acker does not require privileges to exploit this vulnerability.=20

The following are vulnerable; other versions may also be affected:

Oracle9i 9.2.0.8 and 9.2.0.8DV
Oracle10g 10.1.0.5 and 10.2.0.4
Oracle11g 11.1.0.7

68. Oracle Database CVE-2009-1015 Remote Core RDBMS Vulnerability
BugTraq ID: 35682
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35682
Summary:
Oracle Database is prone to a remote vulnerability in Core RDBMS.=20
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. A succ=
essful exploit can occur if the attacker has 'Create Session' privileges.

69. Oracle Database CVE-2009-1968 Remote Secure Enterprise Search Vulnera=
bility
BugTraq ID: 35681
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35681
Summary:
Oracle Database is prone to a remote vulnerability in Secure Enterprise S=
earch.=20
=20
The vulnerability can be exploited over the 'HTTP' protocol. An attacker =
does not require privileges to exploit this vulnerability.

70. Oracle Database CVE-2009-1019 Remote Network Authentication Vulnerabi=
lity
BugTraq ID: 35680
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35680
Summary:
Oracle Database is prone to a remote vulnerability in Network Authenticat=
ion.=20
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. An att=
acker does not require privileges to exploit this vulnerability.=20

This vulnerability affects the following supported versions:
9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7

71. Oracle Secure Backup CVE-2009-1978 Remote Oracle Secure Backup Vulner=
ability
BugTraq ID: 35678
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35678
Summary:
Oracle Secure Backup is prone to a remote vulnerability.=20
=20
The vulnerability can be exploited over the 'HTTP' protocol. A successful=
 exploit can occur if the attacker has 'Valid Session' privileges.

72. Oracle Database CVE-2009-1963 Remote Network Foundation=20
BugTraq ID: 35677
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35677
Summary:
Oracle Database is prone to a remote vulnerability in Network Foundation.=
=20
=20
The vulnerability can be exploited over the 'Oracle Net' protocol. An att=
acker does not require privileges to exploit this vulnerability.

73. Oracle Complex Event Processing CVE-2009-1523 Remote Vulnerability
BugTraq ID: 35675
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35675
Summary:
Oracle Complex Event Processing is prone to a remote vulnerability.
=20
The vulnerability can be exploited over the 'HTTP' protocol. A successful=
 exploit can occur if the attacker has 'Jetty Server Package' privileges.=
=20

This vulnerability affects the following supported versions:

Complex Event Processing 10.3
WebLogic Event Server (EVS) 2.0

74. IETF and W3C XML Digital Signature Specification HMAC Truncation Auth=
entication Bypass Vulnerability
BugTraq ID: 35671
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35671
Summary:
The IETF and W3C XML Digital Signature Specification is prone to an authe=
ntication-bypass vulnerability.

Attackers may exploit this issue to forge signatures to arbitrary XML dat=
a. This may lead to further attacks.
=20
Note that the specification does not require implementations to accept al=
l truncation length values. As a result not all implementations of the XM=
L Digital Signature Specification will be affected by this issue.

75. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 35667
Remote: Yes
Last Updated: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35667
Summary:
Icarus is prone to a remote stack-based buffer-overflow vulnerability bec=
ause the application fails to perform adequate boundary checks on user-su=
pplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Icarus 2.0 is vulnerable; other versions may also be affected.

76. Git Parameter Processing Remote Denial Of Service Vulnerability
BugTraq ID: 35338
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35338
Summary:
Git is prone to a denial-of-service vulnerability because it fails to pro=
perly handle some client requests.

Attackers can exploit this issue to cause a daemon process to enter an in=
finite loop. Repeated exploits may consume excessive system resources, re=
sulting in a denial-of-service condition.

Git 1.4.4.5 through 1.6.3.2 are vulnerable; other versions may also be af=
fected.

77. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corruptio=
n Vulnerability
BugTraq ID: 35303
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35303
Summary:
Adobe Reader and Acrobat are prone to a memory corruption vulnerability.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

78. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow Vulnerab=
ility
BugTraq ID: 35294
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35294
Summary:
Adobe Reader and Acrobat are prone to an integer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

79. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buffer=
 Overflow Vulnerability
BugTraq ID: 35299
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35299
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

80. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35301
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35301
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

81. Adobe Reader and Acrobat TrueType Font Handling Memory Corruption Vul=
nerability
BugTraq ID: 35296
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35296
Summary:
Adobe Reader and Acrobat are prone to a memory-corruption vulnerability.

An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

82. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap B=
uffer Overflow Vulnerability
BugTraq ID: 35291
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35291
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

83. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow Vul=
nerability
BugTraq ID: 35302
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35302
Summary:
Adobe Reader and Acrobat are prone to a heap-based buffer-overflow vulner=
ability.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

84. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption V=
ulnerability
BugTraq ID: 35298
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35298
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

85. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
BugTraq ID: 35451
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35451
Summary:
LibTIFF is prone to a remote buffer-underflow vulnerability because it fa=
ils to perform adequate boundary checks on user-supplied data.

 An attacker can exploit this issue to execute arbitrary malicious code i=
n the context of a user running an application that uses the affected lib=
rary. Failed exploit attempts will likely crash the application.

LibTIFF 3.8.2 is vulnerable; other versions may be affected as well.

86. Novell NetIdentity Agent 'XTIERRPCPIPE' Remote Code Execution Vulnera=
bility
BugTraq ID: 34400
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34400
Summary:
Novell NetIdentity Agent is prone to a remote code-execution vulnerabilit=
y.
=20
Attackers could exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Failed exploit attempts will likely cause denial-of-ser=
vice conditions.

Novell NetIdentity Agent 1.2.3 is vulnerable; other versions may be affec=
ted as well.

87. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
BugTraq ID: 35652
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35652
Summary:
LibTIFF is prone to multiple remote integer-overflow vulnerabilities beca=
use it fails to perform adequate boundary checks on user-supplied data.

 An attacker can exploit these issues to execute arbitrary malicious code=
 in the context of a user running an application that uses the affected l=
ibrary. Failed exploit attempts will likely crash the application.

LibTIFF 3.8.2,  3.9, and 4.0 are vulnerable; other versions may also be a=
ffected.

88. Microsoft Windows Print Spooler Local Information Disclosure Vulnerab=
ility
BugTraq ID: 35208
Remote: No
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35208
Summary:
Microsoft Windows Messenger is prone to a local information-disclosure vu=
lnerability that affects the Print Spooler service.

Successfully exploiting this issue allows attackers to obtain sensitive i=
nformation that may aid in further attacks.

89. HP ProCurve Threat Management Services zl Module VPN Remote Denial of=
 Service Vulnerability
BugTraq ID: 35654
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35654
Summary:
HP ProCurve Threat Management Services zl Module is prone to a denial-of-=
service vulnerability.

Attackers can exploit this issue to crash the affected application, denyi=
ng service to legitimate users.

HP ProCurve Threat Management Services zl Module J9155A running vST.1.0.0=
90213 firmware or prior is vulnerable.

90. HP ProCurve Threat Management Services zl Module CRL Security Bypass =
Vulnerability
BugTraq ID: 35659
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35659
Summary:
HP ProCurve Threat Management Services zl Module is prone to a security-b=
ypass vulnerability.

Successful exploits may allow attackers to bypass certain security restri=
ctions, which may aid in launching further attacks.

ProCurve Threat Management Services zl Module J9155A running vST.1.0.0902=
13 firmware or prior is vulnerable.

91. HP ProCurve Threat Management Services zl Module 'httpd' Denial of Se=
rvice Vulnerability
BugTraq ID: 35653
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35653
Summary:
HP ProCurve Threat Management Services zl Module is prone to a denial-of-=
service vulnerability because the device's webserver fails to automatical=
ly restart if it is stopped.

An attacker may leverage this issue cause a denial of service to the devi=
ce's management interface.

ProCurve Threat Management Services zl Module J9155A running vST.1.0.0902=
13 firmware or prior is vulnerable.

92. CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilitie=
s
BugTraq ID: 35556
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35556
Summary:
CamlImages is prone to multiple integer-overflow vulnerabilities because =
it fails to properly validate user-supplied input.=20

Successful exploits may allow attackers to execute arbitrary code in the =
context of applications that use the affected library. Failed exploit att=
empts will likely result in denial-of-service conditions.

CamlImages 2.2 and prior are vulnerable; other versions may also be affec=
ted.

93. HP ProCurve Threat Management Services zl Module DNS Remote Denial of=
 Service Vulnerability
BugTraq ID: 35655
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35655
Summary:
HP ProCurve Threat Management Services zl Module is prone to a denial-of-=
service vulnerability when handling specially crafted DNS requests or res=
ponses.

An attacker can exploit this issue to cause a denial-of-service condition=
.

ProCurve Threat Management Services z1 Module J9155A running vST.1.0.0902=
13 firmware or prior is vulnerable.

94. Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remot=
e Code Execution Vulnerability
BugTraq ID: 34740
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/34740
Summary:
Adobe Reader is prone to a remote code-execution vulnerability.

 An attacker can exploit this issue to execute arbitrary code with the pr=
ivileges of the user running the application or crash the application, de=
nying service to legitimate users.

Reader 8.1.4 for Linux is vulnerable; other versions or platforms may als=
o be affected.

UPDATE (April 30, 2009): Further information from the reporter states tha=
t the issue does not affect Reader 9.1; only 8.1.4 is affected.

UPDATE (May 1, 2009): The vendor indicates that fixes will be available b=
y May 12, 2009.  Please see the referenced advisory for more information.

UPDATE (May 18, 2009): The vendor indicates that fixes for Adobe Reader 7=
 for Apple Mac OS X will be available by the end of June, 2009. Please se=
e the updated advisory for more information.

95. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remote Heap=
 Buffer Overflow Vulnerability
BugTraq ID: 35300
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35300
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

96. D-Bus 'dbus_signature_validate()' Type Signature Denial of Service Vu=
lnerability
BugTraq ID: 31602
Remote: No
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/31602
Summary:
D-Bus is prone to a local denial-of-service vulnerability because it fail=
s to handle malformed signatures contained in messages.=20

Local attackers can exploit this issue to crash an application that uses =
the affected library, denying service to legitimate users.=20

This issue affects D-BUS 1.2.1; other versions may also be affected.

97. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulne=
rability
BugTraq ID: 35282
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35282
Summary:
Adobe Reader and Acrobat are prone to a remote stack-based buffer-overflo=
w vulnerability because they fail to adequately bounds-check user-supplie=
d data.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

98. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Over=
flow Vulnerabilities
BugTraq ID: 35295
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35295
Summary:
Adobe Reader and Acrobat are prone to multiple remote heap-based buffer-o=
verflow vulnerabilities because they fail to sufficiently sanitize user-s=
upplied input.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: These issues were previously covered in BID 35274 (Adobe Reader and=
 Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been a=
ssigned their own record to better document the issues.

99. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35293
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35293
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

100. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabili=
ties
BugTraq ID: 35274
Remote: Yes
Last Updated: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35274
Summary:
Adobe Reader and Acrobat are prone to multiple remote vulnerabilities.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

The following individual records have been created to better document som=
e of these issues:

35298 Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption=
 Vulnerability
35295 Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Ov=
erflow Vulnerabilities
35294 Adobe Reader and Acrobat 9.1.1 and Prior Integer Overflow Vulnerabi=
lity
35296 Adobe Reader and Acrobat 9.1.1 and Prior Unspecified Memory Corrupt=
ion Vulnerability
35289 Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerabilit=
y
35293 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35291 Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap=
 Buffer Overflow Vulnerability
35282 Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vul=
nerability
35299 Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buff=
er Overflow Vulnerability
35300 Adobe Reader &amp; Acrobat JBIG Pattern Dictionary Allocation Remot=
e Heap Buffer Overflow Vulnerability
35301 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35302 Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow V=
ulnerability
35303 Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corrupt=
ion Vulnerability

The vendor reports other unspecified security issues have also been addre=
ssed. Information regarding these issues is currently not available. We w=
ill update this BID as more information emerges.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Web attacks hit U.S., South Korean sites
By: Robert Lemos
In its fourth day, a widespread distributed denial-of-service attack cont=
inued to inundate U.S. government and South Korean Web sites with network=
 traffic.
http://www.securityfocus.com/news/11554

2. FTC persuades court to shutter rogue ISP
By: Robert Lemos
A federal district court shuts down Triple Fiber Network, after the Feder=
al Trade Commission documents the Internet service provider's cooperation=
 with online criminals and child pornographers.
http://www.securityfocus.com/news/11552

3. Obama launches cybersecurity initiative
By: Robert Lemos
The U.S. president announces that the nation's networks will be considere=
d a "strategic national asset" and creates a top position in the White Ho=
use to formulate a better cybersecurity policy.
http://www.securityfocus.com/news/11551

4. Browsers bashed first in hacking contest
By: Robert Lemos
A security researcher keeps a vulnerability on ice for an entire year, be=
fore using it at the Pwn2Own contest to exploit Apple's browser. Microsof=
t's Internet Explorer 8 falls soon after.=20
http://www.securityfocus.com/news/11549

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
 body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Ironkey

INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
 while strong AES 256-bit hardware encryption and active malware defenses=
 safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
 of drives and even remotely destroy drives in the field.=20
=20
.	Always-On AES 256-bit Hardware Encryption
=20
.	FIPS 140-2 Level 3 Validated
=20
.	Hardened Case.Waterproof Beyond MIL-STD-810F
=20
.	Remote Management Software
=20
Research for the IronKey architecture was funded in part by the U.S. Depa=
rtment of Homeland Security. In addition, IronKey maintains a trusted sup=
ply chain: all research and development is performed in the USA, and all =
boards are built and all drives are assembled in secure facilities in the=
 USA.
=20
IronKey Basic S200 drives will also be available in high-capacity 16GB mo=
dels.

https://www.ironkey.com/S200_Launch?ik_c=3Ds200_launch&ik_s=3Dsecurity_fo=
cus&ik_t=3Dnewsletter