SecurityFocus Newsletter #509
[email protected] Wed, 12 Aug 2009 17:19:10 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #509
----------------------------------------
This issue is sponsored by SC World Congress
Make plans now to attend the second annual SC World Congress - Enterprise=
Data Security, October 13-14 in New York City. The Congress features a c=
omprehensive, two-day program presented in four tracks-including the uniq=
ue Editors Choice sessions-and the industry's largest fall product expo s=
howcasing IT security solutions from the leading vendors and hot start-up=
s. Emphasizing quality content, innovative formats and sessions, global =
perspectives and ROI, this is the one event you can't afford to miss. Reg=
ister by August 31 for big savings. www.scworldcongress.com
------------------------------------------------------------------
I. FRONT AND CENTER
1.The Scale of Security
2.Hacker-Tool Law Still Does Little
II. BUGTRAQ SUMMARY
1. Microsoft Message Queuing Service NULL Pointer Dereference Loca=
l Privilege Escalation Vulnerability
2. Apple Mac OS X 2009-003 Multiple Security Vulnerabilities
3. Adobe Flash Player and AIR (CVE-2009-1866) Stack Buffer Overflo=
w Vulnerability
4. Adobe Flash Player and AIR NULL Pointer Exception Remote Code E=
xecution Vulnerability
5. TGS Content Management HTML-Injection and Multiple Cross-Site S=
cripting Vulnerabilities
6. Adobe Flash Player and AIR Sandbox Bypass Information Disclosur=
e Vulnerability
7. Novell Privileged User Manager Remote Library Injection Vulnera=
bility
8. Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection=
Vulnerability
9. Pidgin OSCAR Protocol Web Message Denial of Service Vulnerabili=
ty
10. Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerabilit=
y
11. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerabil=
ity
12. Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
13. Pidgin Multiple Buffer Overflow Vulnerabilities
14. libsndfile VOC and AIFF Processing Buffer Overflow Vulnerabili=
ties
15. Apache Geronimo Application Server Multiple Remote Vulnerabili=
ties
16. Memcached and MemcacheDB ASLR Information Disclosure Weakness
17. Memcached Multiple Heap Based Buffer Overflow Vulnerability
18. Apache APR-util 'apr_strmatch_precompile()' Integer Underflow =
Vulnerability
19. Adobe Flash Player and AIR URI Parsing Heap Buffer Overflow Vu=
lnerability
20. Adobe Flash Player and AIR 'intf_count' Integer Overflow Vulne=
rability
21. Sun Java Runtime Environment Audio System Privilege Escalation=
Vulnerability
22. Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulner=
abilities
23. Sun Java Runtime Environment JPEG Image Handling Integer Overf=
low Vulnerability
24. Sun Java Runtime Environment Proxy Mechanism Implementation Pr=
ivilege Escalation Vulnerabilities
25. JNLPAppletLauncher Arbitrary File Creation Vulnerability
26. Sun Java Runtime Environment Unpack200 JAR Unpacking Utility I=
nteger Overflow Vulnerability
27. CamlImages PNG Image Parsing Multiple Integer Overflow Vulnera=
bilities
28. Fetchmail NULL Character CA SSL Certificate Validation Securit=
y Bypass Vulnerability
29. ISC BIND 9 Remote Dynamic Update Message Denial of Service Vul=
nerability
30. Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vuln=
erability
31. Ruby BigDecimal Library Denial Of Service Vulnerability
32. phpGroupWare Multiple Input Validation Vulnerabilities
33. NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
34. Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of =
Service Vulnerabilities
35. Gallarific Cross Site Scripting and Authentication Bypass Vuln=
erabilities
36. Avant Browser 'browser:home' Multiple HTML Injection Vulnerabi=
lities
37. NTP 'ntpq' Stack Buffer Overflow Vulnerability
38. BoonEx Orca Topic Title HTML Injection Vulnerability
39. Mozilla Firefox and Seamonkey Regular Expression Parsing Heap =
Buffer Overflow Vulnerability
40. Mozilla NSS NULL Character CA SSL Certificate Validation Secur=
ity Bypass Vulnerability
41. libxml2 Multiple Memory Corruption Vulnerabilities
42. Pixaria Gallery 'file' Parameter Directory Traversal Vulnerabi=
lity
43. WordPress 'wp-login.php' Admin Password Reset Security Bypass =
Vulnerability
44. strongSwan Crafted X.509 Certificate Multiple Remote Denial Of=
Service Vulnerabilities
45. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Co=
rruption Vulnerability
46. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap=
Buffer Overflow Vulnerability
47. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remo=
te Heap Buffer Overflow Vulnerability
48. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
49. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow V=
ulnerability
50. Adobe Reader and Acrobat TrueType Font Handling Memory Corrupt=
ion Vulnerability
51. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote=
Heap Buffer Overflow Vulnerability
52. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overf=
low Vulnerability
53. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corru=
ption Vulnerability
54. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
55. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflo=
w Vulnerability
56. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnera=
bility
57. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buff=
er Overflow Vulnerabilities
58. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulne=
rabilities
59. WS_FTP Server Manager Authentication Bypass and Information Di=
sclosure Vulnerabilities
60. Ipswitch FTP Log Server Denial of Service Vulnerability
61. Ipswitch WS_FTP SFTP Opendir Command Buffer Overflow Vulnerabi=
lity
62. Apple Safari Top Site Feature Website Promotion Security Vulne=
rability
63. ViewVC Cross Site Scripting and Unspecified Security Vulnerabi=
lities
64. SAP NetWeaver Application Server 'uddiclient/process' HTML Inj=
ection Vulnerability
65. cURL / libcURL NULL Character CA SSL Certificate Validation Se=
curity Bypass Vulnerability
66. 2Wire Routers 'CD35_SETUP_01' Access Validation Vulnerability
67. Sun OpenSSO Enterprise XML Document Processing Unspecified Mem=
ory Corruption Vulnerability
68. IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation=
Vulnerability
69. Sun Java SE Multiple Security Vulnerabilities
70. libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerabi=
lity
71. libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
72. Microsoft Windows Malformed AVI File Parsing Remote Integer Ov=
erflow Vulnerability
73. Microsoft Windows Malformed AVI File Header Parsing Remote Cod=
e Execution Vulnerability
74. PulseAudio setuid Local Privilege Escalation Vulnerability
75. Motorola Timbuktu Pro 'PlughNTCommand' Named Pipe Remote Stack=
Buffer Overflow Vulnerability
76. Microsoft Active Template Library Object Type Mismatch Remote =
Code Execution Vulnerability
77. FreeBSD 'mount(2)' and 'nmount(2)' Multiple Stack Buffer Overf=
low Vulnerabilities
78. SafeNet SoftRemote IKE Service Remote Stack Buffer Overflow Vu=
lnerability
79. Unisys Business Information Server Remote Stack Buffer Overflo=
w Vulnerability
80. IETF and W3C XML Digital Signature Specification HMAC Truncati=
on Authentication Bypass Vulnerability
81. Microsoft Visual Studio Active Template Library COM Object Rem=
ote Code Execution Vulnerability
82. Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execu=
tion Vulnerability=20
83. Microsoft Active Template Library 'IPersistStreamInit' Remote =
Code Execution Vulnerability
84. Microsoft Active Template Library Header Data Remote Code Exec=
ution Vulnerability
85. Microsoft Windows WINS Server Network Buffer Length Integer Ov=
erflow Vulnerability
86. Sun Solaris XScreenSaver Popup Windows Local Information Discl=
osure Vulnerability
87. Microsoft OWC ActiveX Control 'BorderAround()' Heap Corruption=
Remote Code Execution Vulnerability
88. Microsoft Remote Desktop Connection Client Heap Based Buffer O=
verflow Vulnerability
89. Samba Arbitrary Memory Contents Information Disclosure Vulnera=
bility
90. Microsoft Office Web Components ActiveX Control 'msDataSourceO=
bject()' Code Execution Vulnerability
91. Microsoft Windows WINS Server Network Packet Remote Heap Buffe=
r Overflow Vulnerability
92. Microsoft Office Web Components ActiveX Control Memory Alloca=
tion Code Execution Vulnerability
93. CoreGraphics Font Glyph Rendering Library Remote Code Executio=
n Vulnerability
94. Microsoft ASP.NET Request Scheduling Denial Of Service Vulnera=
bility
95. Microsoft Windows Embedded OpenType Font Engine Integer Overfl=
ow Vulnerability
96. Microsoft Windows Embedded OpenType Font Engine Heap Overflow =
Vulnerability
97. Microsoft Visual Studio Active Template Library NULL String In=
formation Disclosure Vulnerability
98. libxml XML Entity Name Heap Buffer Overflow Vulnerability
99. Sun Java Runtime Environment XML Parsing Denial of Service Vul=
nerability
100. Adobe Flash Player and AIR Unspecified Privilege Escalation V=
ulnerability
III. SECURITYFOCUS NEWS
1. Web attacks hit U.S., South Korean sites
2. FTC persuades court to shutter rogue ISP
3. Obama launches cybersecurity initiative
4. Browsers bashed first in hacking contest
IV. SECURITY JOBS LIST SUMMARY
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.The Scale of Security
By Adam O'Donnell
Human beings do not naturally understand scale. While we speak of financi=
al transactions in the hundreds of billions of dollars as being something=
as routine as brushing our teeth, we question the value of programs that=
cost in the single-digit millions and quibble with friends over dollars.=
Similarly, there are many problems in our industry that, when explained =
to an outsider, sound like they should have been solved decades ago. It i=
s only when we relate the number of systems that need to be considered in=
the repair that we truly communicate the difficulty of the problem.
http://www.securityfocus.com/columnists/503
2. Hacker-Tool Law Still Does Little
By Mark Rasch
On August 10, 2007, a new section of the German Penal code went into effe=
ct. The statute, intended to implement certain provisions of the Council =
of Europe Treaty on Cybercrime, could be interpreted to make the creation=
or distribution of computer security software a criminal offense.=20
http://www.securityfocus.com/columnists/502
II. BUGTRAQ SUMMARY
--------------------
1. Microsoft Message Queuing Service NULL Pointer Dereference Local Privi=
lege Escalation Vulnerability
BugTraq ID: 35969
Remote: No
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35969
Summary:
The Microsoft Message Queuing service is prone to a local privilege-escal=
ation vulnerability because it fails to adequately handle user-supplied i=
nput.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploits will cause a d=
enial of service.
2. Apple Mac OS X 2009-003 Multiple Security Vulnerabilities
BugTraq ID: 35954
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35954
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities that have be=
en addressed in Security Update 2009-003.
The security update addresses new vulnerabilities that affect the CFNetwo=
rk, ColorSync, CoreTypes, Dock, Image RAW, ImageIO, launchd, Login Window=
, MobileMe, Kernel and XQuery components of Mac OS X. The advisory also c=
ontains security updates for seven previously reported issues.
3. Adobe Flash Player and AIR (CVE-2009-1866) Stack Buffer Overflow Vulne=
rability
BugTraq ID: 35901
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35901
Summary:
Adobe Flash Player and Adobe AIR are prone to a stack-based buffer-overfl=
ow vulnerability.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attacks may cause a denial-of-service conditi=
on.
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
4. Adobe Flash Player and AIR NULL Pointer Exception Remote Code Executio=
n Vulnerability
BugTraq ID: 35906
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35906
Summary:
Adobe Flash Player and Adobe AIR are prone to a remote code-execution vul=
nerability.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attacks may cause a denial-of-service conditi=
on.
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
5. TGS Content Management HTML-Injection and Multiple Cross-Site Scriptin=
g Vulnerabilities
BugTraq ID: 30157
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/30157
Summary:
TGS Content Management is prone to an HTML-injection vulnerability and mu=
ltiple cross-site scripting vulnerabilities because it fails to properly =
sanitize user-supplied input.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may allow the attacker to steal cookie-based authentication credent=
ials or control how the site is rendered to the user; other attacks are a=
lso possible.
TGS Content Management 0.3.2r2 is vulnerable; other versions may also be =
affected.
6. Adobe Flash Player and AIR Sandbox Bypass Information Disclosure Vulne=
rability
BugTraq ID: 35908
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35908
Summary:
Adobe Flash Player and Adobe AIR are prone to an information-disclosure v=
ulnerability.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
Attackers can exploit this issue to obtain sensitive information that may=
aid in launching further attacks.
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
7. Novell Privileged User Manager Remote Library Injection Vulnerability
BugTraq ID: 35752
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35752
Summary:
Novell Privileged User Manager is prone to a vulnerability that allows a =
remote attacker to inject a malicious library.=20
The attacker can exploit this issue to inject and execute arbitrary malic=
ious code in the context of the vulnerable application. Successful explo=
its can compromise the application and possibly the computer; other attac=
ks are also possible.
Novell Privileged User Manager 2.2.0 is vulnerable.
8. Nagios 'statuswml.cgi' Remote Arbitrary Shell Command Injection Vulner=
ability
BugTraq ID: 35464
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35464
Summary:
Nagios is prone to a remote command-injection vulnerability because it fa=
ils to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell comman=
ds with the privileges of the user running the application.
Note that, for an exploit to succeed, access to the WAP interface's ping =
feature must be allowed.
Versions prior to Nagios 3.1.1 are vulnerable.
9. Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability
BugTraq ID: 35530
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35530
Summary:
Pidgin is prone to a denial-of-service vulnerability because it fails to =
properly validate user-supplied input.
Successful exploits will cause the affected application to crash, effecti=
vely denying service to legitimate users.
Pidgin 2.4.0 through 2.5.7 are vulnerable.
10. Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
BugTraq ID: 35253
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35253
Summary:
Apache 'APR-util' is prone to a vulnerability that may allow attackers t=
o cause an affected application to consume memory, resulting in a denial-=
of-service condition.
Versions prior to 'APR-util' 1.3.7 are vulnerable.
11. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
BugTraq ID: 35451
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35451
Summary:
LibTIFF is prone to a remote buffer-underflow vulnerability because it fa=
ils to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary malicious code i=
n the context of a user running an application that uses the affected lib=
rary. Failed exploit attempts will likely crash the application.
LibTIFF 3.8.2 is vulnerable; other versions may be affected as well.
12. Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
BugTraq ID: 35251
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35251
Summary:
Apache 'APR-util' is prone to an off-by-one vulnerability that may allow =
attackers to obtain sensitive information or trigger a denial-of-service =
condition.
Given the nature of this issue, attackers may also be able to execute arb=
itrary code in the context of an application that uses the affected libra=
ry, but this has not been confirmed.
Versions prior to 'APR-util' 1.3.5 on big-endian platforms are vulnerable=
.
13. Pidgin Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 35067
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35067
Summary:
Pidgin is prone to multiple buffer-overflow vulnerabilities because it fa=
ils to perform adequate boundary checks on user-supplied data.
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of a user running the software or cause denial-of-service co=
nditions.
Versions prior to Pidgin 2.5.6 are vulnerable.
14. libsndfile VOC and AIFF Processing Buffer Overflow Vulnerabilities
BugTraq ID: 34978
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/34978
Summary:
The 'libsndfile' library is prone to multiple buffer-overflow vulnerabili=
ties because it fails to perform adequate boundary checks on user-supplie=
d data.
Attackers can exploit these issues to execute arbitrary code in the conte=
xt of an application using the library. This can compromise the affected =
application and possibly the computer. Failed attacks will likely cause d=
enial-of-service conditions.
=20
These issues affect versions prior to libsndfile 1.0.20.
15. Apache Geronimo Application Server Multiple Remote Vulnerabilities
BugTraq ID: 34562
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/34562
Summary:
Apache Geronimo Application Server is prone to multiple remote vulnerabil=
ities:=20
- Multiple directory-traversal vulnerabilities=20
- A cross-site scripting vulnerability
- Multiple HTML-injection vulnerabilities=20
- A cross-site request-forgery vulnerability=20
Attackers can exploit these issues to obtain sensitive information, uploa=
d arbitrary files, execute arbitrary script code, steal cookie-based auth=
entication credentials, and perform certain administrative actions.
Apache Geronimo 2.1 through 2.1.3 are vulnerable.
16. Memcached and MemcacheDB ASLR Information Disclosure Weakness
BugTraq ID: 34756
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/34756
Summary:
Memcached and MemcacheDB are prone to an information-disclosure weakness =
that may aid attackers in bypassing Address Space Layout Randomization (A=
SLR) protections.
Attackers can exploit this weakness to gain access to sensitive informati=
on such as stack, heap, and shared-library memory locations. Information=
obtained may aid in other attacks.=20
memcached v1.2.7 and MemcacheDB v1.2.0 are vulnerable.
17. Memcached Multiple Heap Based Buffer Overflow Vulnerability
BugTraq ID: 35989
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35989
Summary:
Memcached is prone to multiple heap-based buffer-overflow vulnerabilities=
because the application fails to perform adequate boundary-checks on use=
r-supplied data.
Attackers can exploit these issues to execute arbitrary code with superus=
er privileges. Successfully exploiting this issue will compromise the aff=
ected application. Failed exploit attempts will result in a denial-of-ser=
vice condition.
18. Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnera=
bility
BugTraq ID: 35221
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35221
Summary:
Apache 'APR-util' is prone to an integer-underflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context=
of an affected application. Successful exploits will compromise the affe=
cted application and possibly the computer. Failed attacks will cause den=
ial-of-service conditions.
Versions prior to 'APR-util' 1.3.5 are vulnerable.
19. Adobe Flash Player and AIR URI Parsing Heap Buffer Overflow Vulnerabi=
lity
BugTraq ID: 35902
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35902
Summary:
Adobe Flash Player and Adobe AIR are prone to a heap-based buffer overflo=
w vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attacks may cause a denial-of-service conditi=
on.
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
20. Adobe Flash Player and AIR 'intf_count' Integer Overflow Vulnerabilit=
y
BugTraq ID: 35907
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35907
Summary:
Adobe Flash Player and Adobe AIR are prone to an integer-overflow vulnera=
bility.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attacks may cause a denial-of-service conditi=
on.
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
21. Sun Java Runtime Environment Audio System Privilege Escalation Vulner=
ability
BugTraq ID: 35939
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35939
Summary:
Sun Java Runtime Environment (JRE) is prone to a privilege-escalation vul=
nerability.
Successful exploits may allow attackers to access the 'java.lang.System' =
properties and perform actions with elevated privileges on affected compu=
ters.
This issue affects the following:
=20
JDK and JRE 6 Update 14 and prior
JDK and JRE 5.0 Update 19 and prior
NOTE: This issue was previously covered in BID 35922 (Sun Java SE Multipl=
e Security Vulnerabilities), but has been assigned its own record to bett=
er document it.
22. Mozilla Firefox 3.5.1/3.0.12 Multiple Memory Corruption Vulnerabiliti=
es
BugTraq ID: 35927
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35927
Summary:
Mozilla Firefox is prone to multiple remote memory-corruption vulnerabili=
ties.
An attacker can exploit these issues to corrupt memory on the affected co=
mputer and potentially run arbitrary code in the context of the user runn=
ing the affected application. Failed exploit attempts will cause denial-o=
f-service conditions.
Mozilla Firefox versions prior to 3.5.2 and 3.0.13 are affected.
23. Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vul=
nerability
BugTraq ID: 35942
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35942
Summary:
Sun Java Runtime Environment (JRE) is prone to an integer-overflow vulner=
ability.
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the affected application. Failed attempts may result in d=
enial-of-service conditions.
This issue affects the following:
=20
JDK and JRE 6 Update 14 and prior
NOTE: This issue was previously covered in BID 35922 (Sun Java SE Multipl=
e Security Vulnerabilities), but has been assigned its own record to bett=
er document it.
24. Sun Java Runtime Environment Proxy Mechanism Implementation Privilege=
Escalation Vulnerabilities
BugTraq ID: 35943
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35943
Summary:
Sun Java Runtime Environment (JRE) is prone to multiple privilege-escalat=
ion vulnerabilities.
Successful exploits may allow attackers to perform actions with elevated =
privileges and gain access to sensitive information, hijack sessions, and=
violate the same-origin policy.
These issues affect the following:
=20
JDK and JRE 6 Update 14 and prior
JDK and JRE 5.0 Update 19 and prior
NOTE: These issues were previously covered in BID 35922 (Sun Java SE Mult=
iple Security Vulnerabilities), but have been assigned their own record t=
o better document them.
25. JNLPAppletLauncher Arbitrary File Creation Vulnerability
BugTraq ID: 35946
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35946
Summary:
JNLPAppletLauncher is prone to a vulnerability that allows attackers to w=
rite arbitrary files on the vulnerable system.
An attacker may exploit this issue to create arbitrary files on the syste=
m running the affected application. This may aid in further attacks.
26. Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer =
Overflow Vulnerability
BugTraq ID: 35944
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35944
Summary:
Sun Java Runtime Environment (JRE) is prone to an integer-overflow vulner=
ability.
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the affected application. Failed attempts may result in d=
enial-of-service conditions.
This issue affects the following:
=20
JDK and JRE 6 Update 14 and prior
JDK and JRE 5.0 Update 19 and prior
NOTE: This issue was previously covered in BID 35922 (Sun Java SE Multipl=
e Security Vulnerabilities), but has been assigned its own record to bett=
er document it.
27. CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilitie=
s
BugTraq ID: 35556
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35556
Summary:
CamlImages is prone to multiple integer-overflow vulnerabilities because =
it fails to properly validate user-supplied input.=20
Successful exploits may allow attackers to execute arbitrary code in the =
context of applications that use the affected library. Failed exploit att=
empts will likely result in denial-of-service conditions.
CamlImages 2.2 and prior are vulnerable; other versions may also be affec=
ted.
28. Fetchmail NULL Character CA SSL Certificate Validation Security Bypas=
s Vulnerability
BugTraq ID: 35951
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35951
Summary:
Fetchmail is prone to a security-bypass vulnerability because the applica=
tion fails to properly validate the domain name in a signed CA certificat=
e, allowing attackers to substitute malicious SSL certificates for truste=
d ones.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
Versions prior to Fetchmail 6.3.11 are vulnerable.
29. ISC BIND 9 Remote Dynamic Update Message Denial of Service Vulnerabil=
ity
BugTraq ID: 35848
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35848
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the=
software fails to properly handle specially crafted dynamic update reque=
sts.
Successfully exploiting this issue allows remote attackers to crash affec=
ted DNS servers, denying further service to legitimate users. Other attac=
ks are also possible.
Versions prior to BIND 9.4.3-P3, 9.5.1-P3, and 9.6.1-P3 are vulnerable.
30. Ruby 'OCSP_basic_verify()' X.509 Certificate Verification Vulnerabili=
ty
BugTraq ID: 33769
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/33769
Summary:
Ruby is prone to an X.509 certificate-verification vulnerability.
Exploiting this issue may allow an attacker to have a revoked x.509 certi=
ficate accepted as valid. This may allow the attacker to conduct phishing=
attacks or to impersonate legitimate sites. Other attacks are also possi=
ble.
=20
Ruby 1.8.7 and 1.9.1 are vulnerable; other versions may also be affected=
.
31. Ruby BigDecimal Library Denial Of Service Vulnerability
BugTraq ID: 35278
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35278
Summary:
Ruby is prone to a denial-of-service vulnerability in its BigDecimal libr=
ary.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions in applications that use the vulnerable module.
=20
Versions prior to Ruby 1.8.6-p369 and 1.8.7-p173 are affected.
32. phpGroupWare Multiple Input Validation Vulnerabilities
BugTraq ID: 35761
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35761
Summary:
phpGroupWare is prone to multiple input-validation vulnerabilities becaus=
e it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to obtain sensitive infor=
mation, steal cookie-based authentication credentials, compromise the app=
lication, access or modify data, or exploit latent vulnerabilities in the=
underlying database.
phpGroupWare 0.9.16.12 is affected; other versions may also be vulnerable=
.
33. NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
BugTraq ID: 35017
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35017
Summary:
The 'ntpd' daemon is prone to a stack-based buffer-overflow vulnerability=
when it is configured to use the 'autokey' OpenSSL protocol.
Attackers can exploit this issue to execute arbitrary code in the context=
of the application. Failed attempts will likely crash the application, =
causing denial-of-service conditions.
34. Asterisk SIP Channel Driver 'scanf' Multiple Remote Denial of Service=
Vulnerabilities
BugTraq ID: 36015
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36015
Summary:
Asterisk is prone to multiple remote denial-of-service vulnerabilities.
Successful exploits can crash the SIP channel driver, resulting in denial=
-of-service conditions for legitimate users.
The issues affect the Asterisk 1.6.1.
=20
Please note that other versions may also include the affected code but m=
ay not be exploitable as they do not allow SIP packets to exceed 1500 byt=
es total.
35. Gallarific Cross Site Scripting and Authentication Bypass Vulnerabili=
ties
BugTraq ID: 28163
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/28163
Summary:
Gallarific is prone to a cross-site scripting vulnerability and multiple =
authentication-bypass vulnerabilities.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site,=
steal cookie-based authentication credentials, add new categories, add n=
ew users, and modify existing users. Other attacks are also possible.=20
These issues affect both the commercial and the free versions of Gallarif=
ic.
36. Avant Browser 'browser:home' Multiple HTML Injection Vulnerabilities
BugTraq ID: 35898
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35898
Summary:
Avant Browser is prone to multiple HTML-injection vulnerabilities because=
the application fails to properly sanitize user-supplied input before us=
ing it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected application, potentially allowing the attacker to steal cookie-bas=
ed authentication credentials or to control how the site is rendered to t=
he user. Other attacks are also possible.
Avant Browser 11.7 build 35 is vulnerable; other versions may also be aff=
ected.
37. NTP 'ntpq' Stack Buffer Overflow Vulnerability
BugTraq ID: 34481
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/34481
Summary:
The 'ntpq' command is prone to a stack-based buffer-overflow vulnerabilit=
y.=20
Successful exploits will crash the affected utility. Code execution may a=
lso be possible, but has not been confirmed.
38. BoonEx Orca Topic Title HTML Injection Vulnerability
BugTraq ID: 33545
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/33545
Summary:
BoonEx Orca is prone to an HTML-injection vulnerability because the appli=
cation fails to properly sanitize user-supplied input before using it in =
dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
Orca 2.0.2 is vulnerable; other versions may also be affected.
39. Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer =
Overflow Vulnerability
BugTraq ID: 35891
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35891
Summary:
Mozilla Firefox and Seamonkey are prone to a heap-based buffer-overflow v=
ulnerability in the regular expression parser used to match common names =
in SSL certificates.
Successfully exploiting this issue can allow attackers to execute arbitra=
ry code in the context of the application. Failed attempts will likely c=
ause denial-of-service conditions.
Note that attackers need to exploit this issue with a crafted certificate=
that SeaMonkey trusts; otherwise, a warning message will be presented to=
the user.
SeaMonkey 1.09 and Firefox 3.0.x are vulnerable; other versions may also =
be affected.
This issue is related to the vulnerability described by BID 35888 (Mozill=
a Firefox NULL Character CA SSL Certificate Validation Security Bypass Vu=
lnerability).
40. Mozilla NSS NULL Character CA SSL Certificate Validation Security Byp=
ass Vulnerability
BugTraq ID: 35888
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35888
Summary:
Mozilla Network Security Services (NSS) is prone to a security-bypass vul=
nerability because the applications fail to properly validate the domain =
name in a signed CA certificate, allowing attackers to substitute malicio=
us SSL certificates for trusted ones.
The NSS library is used by a number of applications, including Mozilla Fi=
refox, Thunderbird and SeaMonkey.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
NOTE (6 August 2009): This BID was updated to include a similar issue in =
Fetchmail; that issue has been documented in BID 35951 (Fetchmail NULL Ch=
aracter CA SSL Certificate Validation Security Bypass Vulnerability) in o=
rder to better describe the vulnerability.
41. libxml2 Multiple Memory Corruption Vulnerabilities
BugTraq ID: 36010
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36010
Summary:
libxml2 is prone to multiple memory-corruption vulnerabilities.
An attacker can exploit these issues by tricking a victim into opening a =
specially crafted XML file.
A successful attack can allow attacker-supplied code to run in the contex=
t of the application using the vulnerable library or cause a denial-of-se=
rvice condition.
42. Pixaria Gallery 'file' Parameter Directory Traversal Vulnerability
BugTraq ID: 35802
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35802
Summary:
Pixaria Gallery is prone to a directory-traversal vulnerability because i=
t fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive informatio=
n that could aid in further attacks.
Pixaria 2.3.5 is vulnerable; other versions may also be affected.
43. WordPress 'wp-login.php' Admin Password Reset Security Bypass Vulnera=
bility
BugTraq ID: 36014
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36014
Summary:
WordPress is prone to a security-bypass vulnerability because it fails to=
adequately restrict access to the password-reset feature.
An attacker can exploit this issue to reset the administrator password of=
the application. Repeated attacks may allow the attacker to cause persis=
tent denial-of-service conditions.
WordPress version 2.8.3 is affected; other versions may also be vulnerabl=
e.
44. strongSwan Crafted X.509 Certificate Multiple Remote Denial Of Servic=
e Vulnerabilities
BugTraq ID: 35452
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35452
Summary:
strongSwan is prone to multiple remote denial-of-service vulnerabilities.
Attackers can exploit these issues to crash the application, denying acce=
ss to legitimate users.
Versions prior to strongSwan 2.8.10, 4.3.2, and 4.2.16 are vulnerable.
UPDATE (July 27, 2009): Additional corrective measures were added to add=
ress these issues in strongSwan 2.8.11. 4.2.17, and 4.3.3.
45. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corruptio=
n Vulnerability
BugTraq ID: 35303
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35303
Summary:
Adobe Reader and Acrobat are prone to a memory corruption vulnerability.
An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
46. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buffer=
Overflow Vulnerability
BugTraq ID: 35299
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35299
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
47. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remote Heap=
Buffer Overflow Vulnerability
BugTraq ID: 35300
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35300
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
48. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35301
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35301
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
49. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow Vulnerab=
ility
BugTraq ID: 35294
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35294
Summary:
Adobe Reader and Acrobat are prone to an integer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
50. Adobe Reader and Acrobat TrueType Font Handling Memory Corruption Vul=
nerability
BugTraq ID: 35296
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35296
Summary:
Adobe Reader and Acrobat are prone to a memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
51. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap B=
uffer Overflow Vulnerability
BugTraq ID: 35291
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35291
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
52. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow Vul=
nerability
BugTraq ID: 35302
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35302
Summary:
Adobe Reader and Acrobat are prone to a heap-based buffer-overflow vulner=
ability.
An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
53. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption V=
ulnerability
BugTraq ID: 35298
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35298
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
54. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35293
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35293
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
55. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulne=
rability
BugTraq ID: 35282
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35282
Summary:
Adobe Reader and Acrobat are prone to a remote stack-based buffer-overflo=
w vulnerability because they fail to adequately bounds-check user-supplie=
d data.
An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.
56. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerability
BugTraq ID: 35289
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35289
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.=20
Exploiting this issue will allow remote attackers to execute arbitrary co=
de within the context of the affected application or crash the applicatio=
n.
NOTE: This issue was previously covered in BID 35274 (Adobe Reader and A=
crobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been ass=
igned its own record to better document it.
57. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Over=
flow Vulnerabilities
BugTraq ID: 35295
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35295
Summary:
Adobe Reader and Acrobat are prone to multiple remote heap-based buffer-o=
verflow vulnerabilities because they fail to sufficiently sanitize user-s=
upplied input.
An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.
NOTE: These issues were previously covered in BID 35274 (Adobe Reader and=
Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been a=
ssigned their own record to better document the issues.
58. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilit=
ies
BugTraq ID: 35274
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/35274
Summary:
Adobe Reader and Acrobat are prone to multiple remote vulnerabilities.
An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.
The following individual records have been created to better document som=
e of these issues:
35298 Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption=
Vulnerability
35295 Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Ov=
erflow Vulnerabilities
35294 Adobe Reader and Acrobat 9.1.1 and Prior Integer Overflow Vulnerabi=
lity
35296 Adobe Reader and Acrobat 9.1.1 and Prior Unspecified Memory Corrupt=
ion Vulnerability
35289 Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerabilit=
y
35293 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35291 Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap=
Buffer Overflow Vulnerability
35282 Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vul=
nerability
35299 Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buff=
er Overflow Vulnerability
35300 Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remot=
e Heap Buffer Overflow Vulnerability
35301 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35302 Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow V=
ulnerability
35303 Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corrupt=
ion Vulnerability
The vendor reports other unspecified security issues have also been addre=
ssed. Information regarding these issues is currently not available. We w=
ill update this BID as more information emerges.
59. WS_FTP Server Manager Authentication Bypass and Information Disclosur=
e Vulnerabilities
BugTraq ID: 27654
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/27654
Summary:
WS_FTP Server Manager is prone to an authentication-bypass vulnerability =
and an information-disclosure vulnerability.
An attacker can exploit these issues to gain unauthorized access to the a=
ffected application and gain access to potentially sensitive information.=
=20
These issues affect WS_FTP Server Manager 6.1.0.0; prior versions may als=
o be affected.
60. Ipswitch FTP Log Server Denial of Service Vulnerability
BugTraq ID: 27612
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/27612
Summary:
WS_FTP Log Server shipped with WS_FTP is prone to a remote denial-of-serv=
ice vulnerability.
=20
Successfully exploiting this issue allows remote attackers to crash the a=
ffected application, denying service to legitimate users.
This issue affects WS_FTP running FTP Log Server 7.9.14.0; other versions=
may also be affected.
61. Ipswitch WS_FTP SFTP Opendir Command Buffer Overflow Vulnerability
BugTraq ID: 27573
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/27573
Summary:
Ipswitch WS_FTP is prone to a buffer-overflow vulnerability because the a=
pplication fails to bounds-check user-supplied data before copying it int=
o an insufficiently sized buffer.=20
An attacker may exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial of service.
This issue affects WS_FTP 6.1.0.0; other versions may also be affected.
62. Apple Safari Top Site Feature Website Promotion Security Vulnerabilit=
y
BugTraq ID: 36022
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36022
Summary:
Apple Safari is prone to a vulnerability that may aid in phishing-style a=
ttacks.
An attacker may exploit this issue to promote arbitrary sites into the To=
p Site views through automated actions. Successfully exploiting this issu=
e will lead to other attacks.
Versions prior to Apple Safari 4.0.3 are vulnerable.
63. ViewVC Cross Site Scripting and Unspecified Security Vulnerabilities
BugTraq ID: 36035
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36035
Summary:
ViewVC is prone to multiple security vulnerabilities, including:=20
- A cross-site scripting vulnerability.=20
- An unspecified security vulnerability that may allow attackers to prin=
t illegal parameter names and values.
An attacker may leverage theses issue to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site =
and steal cookie-based authentication credentials. Other attacks are als=
o possible.
Versions prior to ViewVC 1.0.9 are vulnerable.
64. SAP NetWeaver Application Server 'uddiclient/process' HTML Injection =
Vulnerability
BugTraq ID: 36034
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36034
Summary:
SAP NetWeaver Application Server is prone to an HTML-injection vulnerabil=
ity because the application's UDDI client fails to properly sanitize user=
-supplied input before using it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
This issue is documented by SAP Note 1322098.
65. cURL / libcURL NULL Character CA SSL Certificate Validation Security =
Bypass Vulnerability
BugTraq ID: 36032
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36032
Summary:
cURL and libcURL are prone to a security-bypass vulnerability because the=
y fail to properly validate the domain name in a signed CA certificate, a=
llowing attackers to substitute malicious SSL certificates for trusted on=
es.
This issue affects cURL and libcURL when compiled against OpenSSL.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
cURL and libcURL 7.4 through 7.19.5 are vulnerable. Additional applicatio=
ns which use the affected library may also be vulnerable.
66. 2Wire Routers 'CD35_SETUP_01' Access Validation Vulnerability
BugTraq ID: 36031
Remote: Yes
Last Updated: 2009-08-12
Relevant URL: http://www.securityfocus.com/bid/36031
Summary:
Multiple 2Wire routers are prone to an access-validation vulnerability be=
cause they fail to adequately authenticate users before performing certai=
n actions.
Unauthenticated attackers can leverage this issue to change the administr=
ative password of the router. Successful attacks will completely compromi=
se affected devices.
2Wire routers prior to Firmware version 5.29.135.5 are vulnerable.
67. Sun OpenSSO Enterprise XML Document Processing Unspecified Memory Cor=
ruption Vulnerability
BugTraq ID: 35977
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35977
Summary:
Sun OpenSSO Enterprise (formerly Sun Java System Access Manager and Sun J=
ava System Identity Server) is prone to a memory-corruption vulnerability=
because it fails to properly handle specially crafted XML documents.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the vulnerable application. Failed exploit attempts will result=
in a denial-of-service condition.
68. IBM AIX '_LIB_INIT_DBG' and '_LIB_INIT_DBG_FILE' File Creation Vulner=
ability
BugTraq ID: 35934
Remote: No
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35934
Summary:
IBM AIX is prone to multiple file-creation vulnerabilities.=20
An attacker with local access can exploit these issues to create arbitrar=
y files and execute arbitrary files with superuser privileges. Successful=
ly exploiting this issue will completely compromise affected computers.
AIX 5.3 and 6.1 are vulnerable.
69. Sun Java SE Multiple Security Vulnerabilities
BugTraq ID: 35922
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35922
Summary:
Sun has released updates to address multiple vulnerabilities in Java SE.
Very little technical information is currently available on these issues.=
This BID will be updated as the vendor advisories are released.
These issues are addressed in the following releases:
JDK and JRE 6 Update 15
JDK and JRE 5.0 Update 20
SDK and JRE 1.4.2_22
SDK and JRE 1.3.1_26
70. libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerability
BugTraq ID: 32331
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/32331
Summary:
The 'libxml2' library is prone to a remote denial-of-service vulnerabilit=
y.=20
Attackers can exploit this issue to cause the affected application using =
the library to fall into an infinite loop, denying service to legitimate =
users.
This issue affects libxml2-2.7.2; other versions may also be affected.
71. libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
BugTraq ID: 32326
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/32326
Summary:
The 'libxml2' library is prone to an integer-overflow vulnerability becau=
se it fails to properly verify user-supplied data when handling XML files=
.
Successful exploits of this vulnerability allow remote attackers to execu=
te arbitrary machine code in the context of an affected application. Fail=
ed exploits may crash the application.
This issue affects libxml2-2.7.2; other versions may also be affected.
72. Microsoft Windows Malformed AVI File Parsing Remote Integer Overflow =
Vulnerability
BugTraq ID: 35970
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35970
Summary:
Microsoft Windows is prone to a remote integer-overflow vulnerability.
This issue arises when an affected Windows component handles a malicious =
Audio Video Interleave (AVI) file.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the affected user. Failed exploit attempts will result in a de=
nial-of-service condition.
NOTE: The affected Windows operating system component is independent of W=
indows Media Player therefore this issue does not specifically affect Win=
dows Media Player.
73. Microsoft Windows Malformed AVI File Header Parsing Remote Code Execu=
tion Vulnerability
BugTraq ID: 35967
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35967
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability.
This issue arises when an affected Windows component handles a malicious =
Audio Video Interleave (AVI) file.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the affected user. Failed exploit attempts will result in a de=
nial-of-service condition.
NOTE: The affected Windows operating system component is independent of W=
indows Media Player therefore this issue does not specifically affect Win=
dows Media Player.
74. PulseAudio setuid Local Privilege Escalation Vulnerability
BugTraq ID: 35721
Remote: No
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35721
Summary:
PulseAudio is prone to a local privilege-escalation vulnerability caused =
by a race-condition error.
Exploiting this issue could allow attackers to perform actions with super=
user privileges, resulting in a complete compromise of affected computers=
.
75. Motorola Timbuktu Pro 'PlughNTCommand' Named Pipe Remote Stack Buffer=
Overflow Vulnerability
BugTraq ID: 35496
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35496
Summary:
Motorola Timbuktu Pro for Windows is prone to a remote stack-based buffer=
-overflow vulnerability because it fails to properly bounds-check user-su=
pplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Failed exploit attempts will result in denial-of-servic=
e conditions.
Versions prior to Timbuktu Pro 8.6.7 for Windows are vulnerable.
76. Microsoft Active Template Library Object Type Mismatch Remote Code Ex=
ecution Vulnerability
BugTraq ID: 35982
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35982
Summary:
The Microsoft Active Template Library is prone to a remote code-execution=
vulnerability.
This issue affects a private version of the ATL used internally by Micros=
oft; components written by other vendors are unlikely to be affected.
Remote attackers can exploit this issue to execute arbitrary code with th=
e privileges of the user running an application built against the affecte=
d library. Failed exploit attempts will result in a denial-of-service con=
dition.
77. FreeBSD 'mount(2)' and 'nmount(2)' Multiple Stack Buffer Overflow Vul=
nerabilities
BugTraq ID: 31002
Remote: No
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/31002
Summary:
FreeBSD is prone to multiple stack-based buffer-overflow vulnerabilities =
because the kernel fails to perform adequate boundary checks on user-supp=
lied data.
A local attacker can exploit these issues to execute arbitrary code with =
kernel-level privileges. Successfully exploiting these issues will result=
in the complete compromise of affected computers. Failed exploit attempt=
s will cause a denial-of-service condition.
FreeBSD 7.0-RELEASE and 7.0-STABLE are vulnerable.
78. SafeNet SoftRemote IKE Service Remote Stack Buffer Overflow Vulnerabi=
lity
BugTraq ID: 35154
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35154
Summary:
SafeNet SoftRemote is prone to a remote stack-based buffer-overflow vulne=
rability because it fails to properly bounds-check user-supplied data bef=
ore copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.
Versions prior to SoftRemote 10.8.6 are vulnerable.
79. Unisys Business Information Server Remote Stack Buffer Overflow Vulne=
rability
BugTraq ID: 35494
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35494
Summary:
Unisys Business Information Server (formerly known as MAPPER) is prone to=
a remote stack-based buffer-overflow vulnerability because it fails to p=
roperly bounds-check user-supplied data before copying it into an insuffi=
ciently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of an affected server, possibly with SYSTEM-level privileges. Fail=
ed exploit attempts will result in denial-of-service conditions.
Business Information Server 10 and 10.1 are vulnerable; other versions ma=
y also be affected.
80. IETF and W3C XML Digital Signature Specification HMAC Truncation Auth=
entication Bypass Vulnerability
BugTraq ID: 35671
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35671
Summary:
The IETF and W3C XML Digital Signature Specification is prone to an authe=
ntication-bypass vulnerability.
Attackers may exploit this issue to forge signatures to arbitrary XML dat=
a. This may lead to further attacks.
=20
Note that the specification doesn't require implementations to accept all=
truncation length values. As a result, not all implementations of the XM=
L Digital Signature Specification will be affected by this issue.
81. Microsoft Visual Studio Active Template Library COM Object Remote Cod=
e Execution Vulnerability
BugTraq ID: 35828
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35828
Summary:
Microsoft Visual Studio is prone to a remote code-execution vulnerability=
in the Active Template Library (ATL).
Remote attackers can exploit this issue to execute arbitrary code with th=
e privileges of the user running an application built against the affecte=
d library. Failed exploit attempts will result in a denial-of-service con=
dition.
82. Microsoft Visual Studio ATL 'VariantClear()' Remote Code Execution Vu=
lnerability=20
BugTraq ID: 35832
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35832
Summary:
Microsoft Visual Studio is prone to a remote code-execution vulnerability=
in the Active Template Library (ATL).
Remote attackers can exploit this issue to execute arbitrary code with th=
e privileges of the user running an application built with the affected l=
ibrary.
83. Microsoft Active Template Library 'IPersistStreamInit' Remote Code Ex=
ecution Vulnerability
BugTraq ID: 35585
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35585
Summary:
The Microsoft Active Template Library is prone to a remote code-execution=
vulnerability.
This issue affects a private version of the ATL used internally by Micros=
oft; components written by other vendors are unlikely to be affected.
Remote attackers can exploit this issue to execute arbitrary code with th=
e privileges of the user running an application built against the affecte=
d library. Failed exploit attempts will result in a denial-of-service con=
dition.
NOTE: This BID was previously titled "Microsoft Windows 'msvidctl.dll' Ac=
tiveX Control Unspecified Remote Memory Corruption Vulnerability". It has=
been updated to better document the underlying issue.
84. Microsoft Active Template Library Header Data Remote Code Execution V=
ulnerability
BugTraq ID: 35558
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35558
Summary:
The Microsoft Active Template Library is prone to a remote code-execution=
vulnerability.
This issue affects a private version of the ATL used internally by Micros=
oft; components written by other vendors are unlikely to be affected.
Remote attackers can exploit this issue to execute arbitrary code with th=
e privileges of the user running an application built against the affecte=
d library. Failed exploit attempts will result in a denial-of-service con=
dition.
NOTE: This BID was previously titled "Microsoft Windows 'MPEG2TuneRequest=
' ActiveX Control Remote Code Execution Vulnerability". It has been updat=
ed to better reflect the underlying issue.
85. Microsoft Windows WINS Server Network Buffer Length Integer Overflow =
Vulnerability
BugTraq ID: 35981
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35981
Summary:
The Microsoft Windows WINS Server is prone to a remote integer-overflow v=
ulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will completely comp=
romise affected computers. Failed exploit attempts will result in a denia=
l-of-service condition.
86. Sun Solaris XScreenSaver Popup Windows Local Information Disclosure V=
ulnerability
BugTraq ID: 35964
Remote: No
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35964
Summary:
Solaris XScreenSaver is prone to a local information-disclosure vulnerabi=
lity.=20
A local attacker can exploit this issue to obtain sensitive information t=
hat may lead to further attacks.
NOTE: This issue may be related to the vulnerability described in BID 344=
21 but this could not be confirmed. We will update this BID when more inf=
ormation becomes available.
This issue affects the following on both SPARC and x86 platforms:
Solaris 8=20
Solaris 9=20
Solaris 10=20
OpenSolaris builds snv_01 through snv_119
87. Microsoft OWC ActiveX Control 'BorderAround()' Heap Corruption Remote=
Code Execution Vulnerability
BugTraq ID: 35991
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35991
Summary:
Microsoft Office Web Components ActiveX control is prone to a remote code=
-execution vulnerability.
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted webpage.
Successfully exploiting this issue will allow attackers to execute arbitr=
ary code within the context of the affected application that uses the Act=
iveX control (typically Internet Explorer). Failed exploit attempts will =
result in a denial-of-service condition.
88. Microsoft Remote Desktop Connection Client Heap Based Buffer Overflow=
Vulnerability
BugTraq ID: 35971
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35971
Summary:
Microsoft Remote Desktop Connection client is prone to a heap-based buffe=
r-overflow vulnerability when processing certain parameters returned by a=
malicious RDP (Remote Desktop Protocol) server.
Successfully exploiting this issue would allow an attacker to corrupt hea=
p memory and execute arbitrary code in the context of the currently logge=
d-in user. Failed exploit attempts will likely cause denial-of-service co=
nditions.
89. Samba Arbitrary Memory Contents Information Disclosure Vulnerability
BugTraq ID: 32494
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/32494
Summary:
Samba is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain arbitrary memory conte=
nts.
This issue affects Samba 3.0.29 through 3.2.4.
90. Microsoft Office Web Components ActiveX Control 'msDataSourceObject()=
' Code Execution Vulnerability
BugTraq ID: 35642
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35642
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability that affects the OWC10.Spreadsheet ActiveX control. The control =
is identified by the following CLSIDs:
0002E541-0000-0000-C000-000000000046
0002E559-0000-0000-C000-000000000046
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted site.
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
91. Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overf=
low Vulnerability
BugTraq ID: 35980
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35980
Summary:
The Microsoft Windows WINS Server is prone to a remote heap-based buffer-=
overflow vulnerability because the application fails to perform adequate =
boundary-checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will completely comp=
romise affected computers. Failed exploit attempts will result in a denia=
l-of-service condition.
92. Microsoft Office Web Components ActiveX Control Memory Allocation Co=
de Execution Vulnerability
BugTraq ID: 35990
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35990
Summary:
Microsoft Office Web Components OWC10 ActiveX control is prone to a remot=
e code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted webpage.
Successfully exploiting this issue will allow attackers to execute arbitr=
ary code within the context of the affected application that uses the Act=
iveX control (typically Internet Explorer). Failed exploit attempts will =
result in a denial-of-service condition.
93. CoreGraphics Font Glyph Rendering Library Remote Code Execution Vulne=
rability
BugTraq ID: 35774
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35774
Summary:
CoreGraphics is prone to a remote code-execution vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running an affected application. Failed attempts wi=
ll likely result in denial-of-service conditions.
This issue is related to the issue described in BID 34870 (Pango 'pango_g=
lyph_string_set_size()' Integer Overflow Vulnerability).
=20
NOTE: This issue was previously covered in BID 35758 (Mozilla Firefox MF=
SA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities) but has bee=
n assigned its own record to better document the issue.
94. Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
BugTraq ID: 35985
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35985
Summary:
Microsoft ASP.NET is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the application pool on the a=
ffected webserver to become unresponsive, denying service to legitimate u=
sers.
NOTE: This issue only affects ASP.NET on webservers running IIS 7 in inte=
grated mode.
95. Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vuln=
erability
BugTraq ID: 35187
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35187
Summary:
Microsoft Windows is prone to a remotely exploitable integer-overflow vul=
nerability because it fails to properly bounds-check user-supplied input =
before copying it into an insufficiently sized memory buffer.=20
Remote attackers can exploit this issue to execute arbitrary machine code=
in the context of the vulnerable software on the targeted user's compute=
r.
96. Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnera=
bility
BugTraq ID: 35186
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35186
Summary:
Microsoft Windows is prone to a remotely exploitable heap-overflow vulner=
ability because the software fails to properly bounds-check user-supplied=
input before copying it into an insufficiently sized memory buffer.=20
Remote attackers can exploit this issue to execute arbitrary machine code=
in the context of the vulnerable software on the targeted user's compute=
r.
97. Microsoft Visual Studio Active Template Library NULL String Informati=
on Disclosure Vulnerability
BugTraq ID: 35830
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35830
Summary:
Microsoft Visual Studio is prone to an information-disclosure vulnerabili=
ty.
An attacker can exploit this issue to read local memory, which may help t=
he attacker obtain sensitive information or launch further attacks.
98. libxml XML Entity Name Heap Buffer Overflow Vulnerability
BugTraq ID: 31126
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/31126
Summary:
The 'libxml' library is prone to a heap-based buffer-overflow vulnerabili=
ty because the software fails to perform adequate boundary checks on user=
-supplied data.=20
An attacker can exploit this issue to execute arbitrary within the contex=
t of an application using the affected library. Failed exploit attempts =
will result in a denial-of-service vulnerability.
99. Sun Java Runtime Environment XML Parsing Denial of Service Vulnerabil=
ity
BugTraq ID: 35958
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35958
Summary:
Sun Java Runtime Environment (JRE) is prone to a denial-of-service vulner=
ability.
Attackers may exploit this issue to cause denial-of-service conditions in=
applications that use the vulnerable environment.
This issue affects the following:
=20
JDK and JRE 6 Update 14 and prior
JDK and JRE 5.0 Update 19 and prior
NOTE: This issue was previously covered in BID 35922 (Sun Java SE Multipl=
e Security Vulnerabilities), but has been assigned its own record to bett=
er document it.
100. Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerab=
ility
BugTraq ID: 35900
Remote: Yes
Last Updated: 2009-08-11
Relevant URL: http://www.securityfocus.com/bid/35900
Summary:
Adobe Flash Player and Adobe AIR are prone to an unspecified privilege-es=
calation vulnerability.
Very few details are available regarding this issue. We will update this =
BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code with elevated =
privileges. Successfully exploiting this issue will compromise the affec=
ted application and possibly the computer.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
This issue was previously covered in BID 35890 (Adobe Flash Player and AI=
R Multiple Security Vulnerabilities) but has been given its own record to=
better document it.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Web attacks hit U.S., South Korean sites
By: Robert Lemos
In its fourth day, a widespread distributed denial-of-service attack cont=
inued to inundate U.S. government and South Korean Web sites with network=
traffic.
http://www.securityfocus.com/news/11554
2. FTC persuades court to shutter rogue ISP
By: Robert Lemos
A federal district court shuts down Triple Fiber Network, after the Feder=
al Trade Commission documents the Internet service provider's cooperation=
with online criminals and child pornographers.
http://www.securityfocus.com/news/11552
3. Obama launches cybersecurity initiative
By: Robert Lemos
The U.S. president announces that the nation's networks will be considere=
d a "strategic national asset" and creates a top position in the White Ho=
use to formulate a better cybersecurity policy.
http://www.securityfocus.com/news/11551
4. Browsers bashed first in hacking contest
By: Robert Lemos
A security researcher keeps a vulnerability on ice for an entire year, be=
fore using it at the Pwn2Own contest to exploit Apple's browser. Microsof=
t's Internet Explorer 8 falls soon after.=20
http://www.securityfocus.com/news/11549
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is sponsored by SC World Congress
Make plans now to attend the second annual SC World Congress - Enterprise=
Data Security, October 13-14 in New York City. The Congress features a c=
omprehensive, two-day program presented in four tracks-including the uniq=
ue Editors Choice sessions-and the industry's largest fall product expo s=
howcasing IT security solutions from the leading vendors and hot start-up=
s. Emphasizing quality content, innovative formats and sessions, global =
perspectives and ROI, this is the one event you can't afford to miss. Reg=
ister by August 31 for big savings. www.scworldcongress.com