SecurityFocus Newsletter #511
[email protected] Fri, 25 Sep 2009 11:21:27 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #511
----------------------------------------
This issue is sponsored by Entrust
Go Green for Less Green
Give your customers the highest level of assurance=20
Give your customers the green address bar
Entrust EV SSL Certificates - Now from only $199 per year
http://www.entrust.net/securityfocus-ev
------------------------------------------------------------------
I. FRONT AND CENTER
1.Lazy Workers May Be Deemed Hackers
2.The Scale of Security
II. BUGTRAQ SUMMARY
1. Xen pygrub Local Authentication Bypass Vulnerability
2. Cisco Application Control Engine (ACE) XML Gateway IP Address I=
nformation Disclosure Vulnerability
3. Check Point Connectra '/Login/Login' Arbitrary Script Injection=
Vulnerability
4. FFmpeg Version 0.5 Multiple Remote Vulnerabilities
5. Joomla! 'com_jinc' Component 'newsid' Parameter SQL Injection V=
ulnerability
6. Joomla! MyRemote Video Gallery 'user_id' Parameter SQL Injectio=
n Vulnerability
7. Changetrack Local Privilege Escalation Vulnerability
8. Mambo MOStlyCE Module Image Manager Utility Arbitrary File Uplo=
ad Vulnerability
9. DCI-Designs Dawaween Poems.PHP SQL Injection Vulnerability
10. moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
11. Squid Web Proxy Cache Authentication Header Parsing Remote Den=
ial of Service Vulnerability
12. ISC BIND 9 Remote Dynamic Update Message Denial of Service Vul=
nerability
13. OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denia=
l of Service Vulnerability
14. OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denia=
l of Service Vulnerability
15. OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulne=
rability
16. Snort Unified1 Output Remote Denial Of Service Vulnerability
17. Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulner=
ability
18. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerabilit=
y
19. Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Esc=
alation Vulnerability
20. Linux kernel 'O_EXCL' NFSv4 Privilege Escalation Vulnerability
21. Debian and Ubuntu Postfix Insecure Temporary File Creation Vul=
nerability
22. HP-UX RBAC Unspecified Local Unauthorized Access Vulnerability
23. Apache Tomcat 'RequestDispatcher' Information Disclosure Vulne=
rability
24. Apache Tomcat Cookie Quote Handling Remote Information Disclos=
ure Vulnerability
25. Apache Tomcat Form Authentication Existing/Non-Existing Userna=
me Enumeration Weakness
26. Apache Tomcat Java AJP Connector Invalid Header Denial of Serv=
ice Vulnerability
27. Drupal Bibliography Module Biblio Item HTML Injection Vulnerab=
ility
28. Joomla! Fastball Component SQL Injection Vulnerability
29. Code-Crafters Ability Mail Server IMAP FETCH Request Remote De=
nial Of Service Vulnerability
30. RETIRED: Mereo Malformed URI Remote Denial Of Service Vulnerab=
ility
31. OpenSAML 'use' Key Certificate Validation Security Bypass Vuln=
erability
32. OpenSAML URI Handling Remote Buffer Overflow Vulnerability
33. Samba Format String And Security Bypass Vulnerabilities
34. ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Use=
rname SQL Injection Vulnerability
35. Newt Text Box Content Processing Remote Buffer Overflow Vulner=
ability
36. Kaspersky Online Scanner Security Bypass Vulnerability
37. e107 News Email Referer Header Cross Site Scripting Vulnerabil=
ity
38. Serendipity Freetag Plugin SQL Injection Vulnerability
39. Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vuln=
erabilities
40. Extended Module Player (xmp) 'oxm.c' And 'dtt_load.c' Multiple=
Local Buffer Overflow Vulnerabilities
41. Ruby on Rails Form Helpers Unicode String Handling Cross Site =
Scripting Vulnerability
42. ProFTPD 'mod_sql' Username SQL Injection Vulnerability
43. PHP 'exif_read_data()' JPEG Image Processing Denial Of Service=
Vulnerability
44. FreeType Multiple Integer Overflow Vulnerabilities
45. PostgreSQL Multiple Security Vulnerabilities
46. MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
47. MySQL Command Line Client HTML Special Characters HTML Injecti=
on Vulnerability
48. Lyris ListManager Multiple Remote Vulnerabilities
49. Drupal Devel Module Variable Editor HTML Injection Vulnerabili=
ty
50. Drupal Markdown Preview Module Live Preview HTML Injection Vul=
nerability
51. OSSIM SQL Injection, Cross Site Scripting and Unauthorized Acc=
ess Vulnerabilities
52. Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerabi=
lity
53. Xfig Multiple Insecure Temporary File Creation Vulnerabilities
54. Adobe RoboHelp Server Authentication Bypass Vulnerability
55. WebKit Numeric Character References Remote Memory Corruption V=
ulnerability
56. WebKit 'Attr' DOM Objects Remote Code Execution Vulnerability
57. WebKit Java Applet Remote Code Execution Vulnerability
58. WebKit CSS 'Attr' Function Remote Code Execution Vulnerability
59. WebKit SVGList Objects Remote Memory Corruption Vulnerability
60. WebKit JavaScript Garbage Collector Memory Corruption Vulnerab=
ility
61. WebKit DOM Event Handler Remote Memory Corruption Vulnerabilit=
y
62. GNOME GLib Symbolic Link Arbitrary File Access Vulnerability
63. Apache APR and APR-util Multiple Integer Overflow Vulnerabilit=
ies
64. Apache mod_proxy_ftp Remote Command Injection Vulnerability
65. Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of=
Service Vulnerability
66. Joomla!/Mambo Tupinambis Component SQL Injection Vulnerability
67. Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Ser=
vice Vulnerability
68. Sun Solaris Trusted Extensions Common Desktop Environment Loca=
l Privilege Escalation Vulnerability
69. IBM Lotus Connections 'simpleSearch.do' Cross Site Scripting V=
ulnerability
70. Drupal Meta tags (Nodewords) Module Unauthorized Access Vulner=
ability
71. Avast! Antivirus 'aswMon2.sys' Driver Local Privilege Escalati=
on Vulnerability
72. BakBone NetVault Backup 'npvmgr.exe' Remote Denial Of Service =
Vulnerability
73. TCP/IP Protocol Stack Multiple Remote Denial Of Service Vulner=
abilities
74. Vastal I-Tech Agent Zone SQL Injection Vulnerability
75. Vastal I-Tech DVD Zone 'mag_id' Parameter Cross Site Scripting=
and SQL Injection Vulnerabilities
76. Vastal I-Tech Cosmetics Zone 'view_products.php' SQL Injection=
Vulnerability
77. Vastal I-Tech MMORPG 'view_news.php' SQL Injection Vulnerabili=
ty
78. Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerab=
ility
79. Cisco IOS Specially Crafted Encryption Packet Denial of Servic=
e Vulnerability
80. Cisco IOS Zone-Based Policy Firewall SIP Inspection Denial of =
Service Vulnerability
81. Cisco IOS Software Tunnels Multiple Denial of Service Vulnerab=
ilities
82. Cisco IOS Software Internet Key Exchange Resource Exhaustion D=
enial of Service Vulnerability
83. Cisco IOS SIP Message Denial of Service Vulnerability
84. Cisco Unified Communications Manager Express Extension Mobilit=
y Buffer Overflow Vulnerability
85. Cisco Unified Communications Manager SIP Message Denial of Ser=
vice Vulnerability
86. Cisco IOS Object Group Access Control List Bypass Vulnerabilit=
y
87. VLC Media Player Multiple Remote Stack Buffer Overflow Vulnera=
bilities
88. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerabil=
ity
89. Cisco IOS H.323 Denial of Service Vulnerability
90. Cisco IOS Authentication Proxy for HTTP(S) Authentication Bypa=
ss Vulnerability
91. nginx WebDAV Multiple Directory Traversal Vulnerabilities
92. Joomla! JoomlaFacebook Component SQL Injection Vulnerability
93. Joomla! SportFusion Component SQL Injection Vulnerability
94. Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilit=
ies
95. MaxWebPortal 'forum.asp' SQL Injection Vulnerability
96. Google Chrome NULL Character CA SSL Certificate Validation Sec=
urity Bypass Vulnerability
97. Sun Solaris XScreenSaver X Resize and Rotate Local Information=
Disclosure Vulnerability
98. Sun Solaris Cluster Local Privilege Escalation Vulnerability
99. Apple iTunes '.pls' File Buffer Overflow Vulnerability
100. NetCitadel Firewall Builder Script Generation Insecure Tempor=
ary File Creation Vulnerability
III. SECURITYFOCUS NEWS
1. Popular apps need better patching, says report
2. Hacker charged with Heartland, other breaches
3. Web attacks hit U.S., South Korean sites
4. FTC persuades court to shutter rogue ISP
IV. SECURITY JOBS LIST SUMMARY
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Lazy Workers May Be Deemed Hackers
By Mark Rasch
From his office job at the Shelby City (Ohio) Wastewater Treatment plant,=
he was browsing adult Web sites, including one called Adult Friend Finde=
r to meet women. When some of the women asked Wolf for nude pictures, he =
bought a digital camera, took pictures, and e-mailed them using his work =
computer.
http://www.securityfocus.com/columnists/504
2.The Scale of Security
By Adam O'Donnell
Human beings do not naturally understand scale. While we speak of financi=
al transactions in the hundreds of billions of dollars as being something=
as routine as brushing our teeth, we question the value of programs that=
cost in the single-digit millions and quibble with friends over dollars.=
Similarly, there are many problems in our industry that, when explained =
to an outsider, sound like they should have been solved decades ago. It i=
s only when we relate the number of systems that need to be considered in=
the repair that we truly communicate the difficulty of the problem.
http://www.securityfocus.com/columnists/503
II. BUGTRAQ SUMMARY
--------------------
1. Xen pygrub Local Authentication Bypass Vulnerability
BugTraq ID: 36523
Remote: No
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/36523
Summary:
Xen is prone to a local authentication-bypass vulnerability.
A local attacker with physical access to an affected host can exploit thi=
s issue to bypass authentication and modify the 'grub.conf' file. This ma=
y aid in a complete compromise of the affected system.
Xen 3.0.3, 3.3.0, and 3.3.1 are affected; other versions may also be vuln=
erable.
2. Cisco Application Control Engine (ACE) XML Gateway IP Address Informat=
ion Disclosure Vulnerability
BugTraq ID: 36522
Remote: Yes
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/36522
Summary:
Cisco Application Control Engine (ACE) XML Gateway is prone to an informa=
tion-disclosure vulnerability.=20
Attackers can exploit this issue to obtain sensitive information that can=
aid in further attacks.
This issue is being tracked by Cisco Bug CSCtb82159.
Versions prior to ACE XML Gateway 6.1 and ACE Web Application Firewall 6.=
1 are vulnerable.
3. Check Point Connectra '/Login/Login' Arbitrary Script Injection Vulner=
ability
BugTraq ID: 36466
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36466
Summary:
Check Point Connectra is prone to an arbitrary-script-injection vulnerabi=
lity because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in th=
e context of the webserver. Successful exploits can compromise the applic=
ation.
4. FFmpeg Version 0.5 Multiple Remote Vulnerabilities
BugTraq ID: 36465
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36465
Summary:
FFmpeg is prone to multiple remote vulnerabilities.=20
Attackers may leverage these issues to execute arbitrary code in the cont=
ext of the application or crash the application.
FFmpeg 0.5 is affected; other versions may also be vulnerable.
5. Joomla! 'com_jinc' Component 'newsid' Parameter SQL Injection Vulnerab=
ility
BugTraq ID: 36471
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36471
Summary:
The 'com_jinc' component for Joomla! is prone to an SQL-injection vulnera=
bility because it fails to sufficiently sanitize user-supplied data befor=
e using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
6. Joomla! MyRemote Video Gallery 'user_id' Parameter SQL Injection Vulne=
rability
BugTraq ID: 36470
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36470
Summary:
The MyRemote Video Gallery component for Joomla! is prone to an SQL-injec=
tion vulnerability because it fails to sufficiently sanitize user-supplie=
d data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
MyRemote Video Gallery 1.0 Beta is vulnerable; other versions may also be=
affected.
7. Changetrack Local Privilege Escalation Vulnerability
BugTraq ID: 36420
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36420
Summary:
Changetrack is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to run arbitrary commands with root pr=
ivileges.
Changetrack 4.3 is vulnerable; other versions may also be affected.
8. Mambo MOStlyCE Module Image Manager Utility Arbitrary File Upload Vuln=
erability
BugTraq ID: 27472
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/27472
Summary:
The MOStlyCE module for Mambo is prone to an arbitrary-file-upload vulner=
ability because the application fails to sufficiently sanitize user-suppl=
ied input.
Exploiting this issue could allow an attacker to upload and execute arbit=
rary script code in the context of the affected webserver process.
MOStlyCE 2.4 included with Mambo 4.6.3 is vulnerable; other versions may =
also be affected.
9. DCI-Designs Dawaween Poems.PHP SQL Injection Vulnerability
BugTraq ID: 16909
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/16909
Summary:
Dawaween is prone to an SQL-injection vulnerability because it fails to p=
roperly sanitize user-supplied input before using it in an SQL query.=20
Successful exploits could allow a remote attacker to compromise the appli=
cation, access or modify data, or exploit vulnerabilities in the underlyi=
ng database.
Dawaween 1.03 is affected by this issue.
10. moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
BugTraq ID: 31495
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/31495
Summary:
moziloCMS is prone to multiple vulnerabilities, including a session-fixat=
ion issue, multiple directory-traversal issues, and multiple cross-site s=
cripting issues.
An attacker may leverage these issues to view arbitrary local files withi=
n the context of the webserver, to execute arbitrary script code in the b=
rowser of an unsuspecting user, or to hijack a valid user's session.
Versions prior to moziloCMS 1.10.3 are vulnerable.
UPDATE (September 22, 2009): Further reports indicate that some or all of=
these issues may have been re-introduced in versions prior to moziloCMS =
1.11.2.
11. Squid Web Proxy Cache Authentication Header Parsing Remote Denial of =
Service Vulnerability
BugTraq ID: 36091
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36091
Summary:
Squid is prone to a remote denial-of-service vulnerability because the pr=
oxy server fails to properly parse certain external authentication header=
s that contain comma delimiters.
Successfully exploiting this issue allows remote attackers to trigger an =
infinite loop and consume system resources, denying further service to le=
gitimate users.
12. ISC BIND 9 Remote Dynamic Update Message Denial of Service Vulnerabil=
ity
BugTraq ID: 35848
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35848
Summary:
ISC BIND is prone to a remote denial-of-service vulnerability because the=
software fails to properly handle specially crafted dynamic update reque=
sts.
Successfully exploiting this issue allows remote attackers to crash affec=
ted DNS servers, denying further service to legitimate users. Other attac=
ks are also possible.
Versions prior to BIND 9.4.3-P3, 9.5.1-P3, and 9.6.1-P3 are vulnerable.
13. OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Se=
rvice Vulnerability
BugTraq ID: 35138
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35138
Summary:
OpenSSL is prone to a vulnerability that may allow attackers to cause de=
nial-of-service conditions.
OpenSSL 1.0.0 Beta 2 is vulnerable; other versions may also be affected.
14. OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Remote Denial of Se=
rvice Vulnerability
BugTraq ID: 35417
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35417
Summary:
OpenSSL is prone to a denial-of-service vulnerability caused by a NULL-po=
inter dereference.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
Versions prior to OpenSSL 1.0.0 Beta 2 are vulnerable.
15. OpenSSL 'ChangeCipherSpec' DTLS Packet Denial of Service Vulnerabilit=
y
BugTraq ID: 35174
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35174
Summary:
OpenSSL is prone to a denial-of-service vulnerability caused by a NULL-po=
inter dereference condition.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
Versions prior to OpenSSL 0.9.8i are vulnerable.
16. Snort Unified1 Output Remote Denial Of Service Vulnerability
BugTraq ID: 36473
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36473
Summary:
Snort is affected by a denial-of-service vulnerability because the applic=
ation fails to properly process unified1 output.
=20
Attackers can leverage this issue by sending malformed network packets th=
at will produce corrupted logs and alerts, causing denial-of-service cond=
itions.
Snort 2.8.1 through 2.8.4 are affected.
17. Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability
BugTraq ID: 36038
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36038
Summary:
The Linux kernel is prone to a local NULL-pointer dereference vulnerabili=
ty.
A local attacker can exploit this issue to execute arbitrary code with su=
peruser privileges or crash an affected kernel, denying service to legiti=
mate users.
Versions prior to the Linux kernel 2.4.37.5 and 2.6.31-rc6 are vulnerable=
.
18. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
BugTraq ID: 35281
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35281
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the system, denying service t=
o legitimate users.=20
Given the nature of this issue, the attacker may also be able to run arbi=
trary code, but this has not been confirmed.
Versions prior to Linux Kernel 2.6.30 are vulnerable.
19. Linux Kernel 'udp_sendmsg()' MSG_MORE Flag Local Privilege Escalation=
Vulnerability
BugTraq ID: 36108
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36108
Summary:
The Linux kernel is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with su=
peruser privileges, resulting in a complete compromise of the affected co=
mputer. Failed exploit attempts may cause denial-of-service conditions.
Versions prior to the Linux Kernel 2.6.19 are vulnerable.
20. Linux kernel 'O_EXCL' NFSv4 Privilege Escalation Vulnerability
BugTraq ID: 36472
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36472
Summary:
The Linux kernel is prone to a privilege-escalation vulnerability.
Local attackers may be able to exploit this issue to execute arbitrary co=
de with the privileges of another user and compromise the affected comput=
er.
Versions prior to Linux kernel 2.6.19-rc6 are vulnerable.
21. Debian and Ubuntu Postfix Insecure Temporary File Creation Vulnerabil=
ity
BugTraq ID: 36469
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36469
Summary:
Postfix on Debian and Ubuntu creates temporary files in an insecure manne=
r.
An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks, overwriting arbitrary files in the context of=
the affected application.=20
Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
attacks may also be possible.
This issue affects the following:
Postfix 2.5.5 on Debian 4.0 (and later)
Postfix 2.5.5 on Ubuntu 6.06 LTS (and later)
Other versions may also be affected.
22. HP-UX RBAC Unspecified Local Unauthorized Access Vulnerability
BugTraq ID: 36476
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36476
Summary:
HP-UX is prone to a local unspecified unauthorized-access vulnerability.
This issue affects the following versions running Role-Based Access Contr=
ol (RBAC):
HP-UX B.11.23
HP-UX B.11.31
23. Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerabilit=
y
BugTraq ID: 35263
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35263
Summary:
Apache Tomcat is prone to a remote information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may=
lead to further attacks.
The following versions of Apache Tomcat are vulnerable:=20
6.0.0-6.0.18
5.5.0-5.5.27
4.1.0-4.1.39
24. Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vul=
nerability
BugTraq ID: 27706
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/27706
Summary:
Apache Tomcat is prone to an information-disclosure vulnerability because=
it fails to adequately sanitize user-supplied data.
Attackers can exploit this issue to access potentially sensitive data tha=
t may aid in further attacks.
Versions prior to Apache Tomcat 6.0.16 and 5.5.26 are vulnerable.
NOTE: This vulnerability is caused by an incomplete fix for BID 25316 - A=
pache Tomcat Multiple Remote Information Disclosure Vulnerabilities (CVE-=
2007-3385).
25. Apache Tomcat Form Authentication Existing/Non-Existing Username Enum=
eration Weakness
BugTraq ID: 35196
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35196
Summary:
Apache Tomcat is prone to a username-enumeration weakness because it disp=
lays different responses to login attempts, depending on whether or not =
the username exists.
Attackers may exploit this weakness to discern valid usernames. This may =
aid them in brute-force password cracking or other attacks.
The following are vulnerable:
=20
Tomcat 4.1.x (prior to 4.1.40)
Tomcat 5.5x (prior to 5.5.28)
Tomcat 6.0.x (prior to 6.0.20)
26. Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vul=
nerability
BugTraq ID: 35193
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/35193
Summary:
Apache Tomcat is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause the server to end up in an erro=
r state, denying service to legitimate users.=20
The following versions of Apache Tomcat are vulnerable:=20
6.0.0-6.0.18
5.5.0-5.5.27
4.1.0-4.1.39
27. Drupal Bibliography Module Biblio Item HTML Injection Vulnerability
BugTraq ID: 36521
Remote: Yes
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/36521
Summary:
The Bibliography module for Drupal is prone to an HTML-injection vulnerab=
ility because the application fails to properly sanitize user-supplied in=
put before using it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
Note that to exploit this issue, the attacker must have sufficient privil=
eges to create content displayed by the Bibliography module.
The issue affects Bibliography 6.x-1.6; other versions may also be affect=
ed.
=20
NOTE: This issue may be related to the vulnerability described in BID 35=
865 (Drupal Bibliography Module 'title' HTML Injection Vulnerability). We=
will update or retire this BID when more information becomes available.
28. Joomla! Fastball Component SQL Injection Vulnerability
BugTraq ID: 36520
Remote: Yes
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/36520
Summary:
The Fastball component ('com_fastball') for Joomla! is prone to an SQL-in=
jection vulnerability because it fails to sufficiently sanitize user-supp=
lied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
The issue affects Fastball 1.2; other versions may also be affected.
29. Code-Crafters Ability Mail Server IMAP FETCH Request Remote Denial Of=
Service Vulnerability
BugTraq ID: 36519
Remote: Yes
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/36519
Summary:
Ability Mail Server is prone to a denial-of-service vulnerability because=
it fails to adequately handle IMAP requests.
Attackers can exploit this issue to cause the affected application to cra=
sh, denying service to legitimate users.=20
Versions prior to Ability Mail Server 2.70 are affected.
30. RETIRED: Mereo Malformed URI Remote Denial Of Service Vulnerability
BugTraq ID: 35014
Remote: Yes
Last Updated: 2009-09-25
Relevant URL: http://www.securityfocus.com/bid/35014
Summary:
Mereo is prone to a denial-of-service vulnerability because it fails to a=
dequately sanitize user-supplied input.
Attackers can exploit this issue to crash the affected application, denyi=
ng service to legitimate users.=20
Mereo 1.8.0 is vulnerable; other versions may also be affected.
UPDATE (September 24, 2009): The vendor refutes this issue, stating that =
they can't trigger the vulnerability.
NOTE: This BID is being retired because the application is not vulnerable=
as described.
31. OpenSAML 'use' Key Certificate Validation Security Bypass Vulnerabili=
ty
BugTraq ID: 36516
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36516
Summary:
OpenSAML is prone to a security-bypass vulnerability because of an error =
in verifying website certificates.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
32. OpenSAML URI Handling Remote Buffer Overflow Vulnerability
BugTraq ID: 36514
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36514
Summary:
OpenSAML is prone to a remote buffer-overflow vulnerability because it fa=
ils to perform adequate boundary checks on user-supplied input before cop=
ying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context=
of an application that uses the library. Failed attacks may cause denial=
-of-service conditions.
Versions prior to OpenSAML 1.1.3 are vulnerable.
33. Samba Format String And Security Bypass Vulnerabilities
BugTraq ID: 35472
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35472
Summary:
Samba is prone to multiple vulnerabilities.
Attackers can leverage these issues to execute arbitrary code within the =
context of the vulnerable application or to bypass certain security restr=
ictions.
Samba 3.0.31 through 3.3.5 are affected.
34. ActiveCampaign 1-2-All Broadcast Email Admin Control Panel Username S=
QL Injection Vulnerability
BugTraq ID: 15400
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/15400
Summary:
ActiveCampaign 1-2-All Broadcast Email is prone to an SQL-injection vulne=
rability. This is an input-validation issue related to data that will be=
used in SQL queries, allowing a remote user to influence the structure a=
nd logic of a query.=20
=20
Successful attacks could compromise the software. Depending on the datab=
ase implementation and the nature of the affected query, the attacker may=
be able to gain unauthorized access to the database.
35. Newt Text Box Content Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 36515
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36515
Summary:
The Newt library is prone to a remote buffer-overflow vulnerability becau=
se the software fails to perform adequate boundary checks on user-supplie=
d data.=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running an application that relies on the affected li=
brary. Failed exploit attempts will result in a denial-of-service conditi=
on.
36. Kaspersky Online Scanner Security Bypass Vulnerability
BugTraq ID: 36243
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36243
Summary:
Kaspersky Online Scanner is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
Online Scanner 7.0 is affected; other versions may also be vulnerable.
37. e107 News Email Referer Header Cross Site Scripting Vulnerability
BugTraq ID: 36517
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36517
Summary:
The 'e107' program is prone to a cross-site scripting vulnerability becau=
se it fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may let the attacker steal cookie-based authentication credentials an=
d launch other attacks.
38. Serendipity Freetag Plugin SQL Injection Vulnerability
BugTraq ID: 36376
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36376
Summary:
Serendipity Freetag plugin is prone to an SQL-injection vulnerability bec=
ause it fails to sufficiently sanitize user-supplied data before using it=
in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects versions prior to Serendipity Freetag 3.08.
39. Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabili=
ties
BugTraq ID: 36377
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36377
Summary:
Dovecot Sieve plugin is prone to multiple buffer-overflow vulnerabilities=
.
Successful exploits may allow attackers to execute arbitrary code within =
the context of the affected application or to cause denial-of-service con=
ditions.
No further details are currently available. We will update this BID as mo=
re information emerges.
These issues affect versions prior to Dovecot Sieve 1.1.7 and 1.0.4.
40. Extended Module Player (xmp) 'oxm.c' And 'dtt_load.c' Multiple Local =
Buffer Overflow Vulnerabilities
BugTraq ID: 27047
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/27047
Summary:
Extended Module Player (xmp) is prone to multiple local buffer-overflow v=
ulnerabilities because it fails to perform adequate boundary checks befor=
e copying user-supplied input into an insufficiently sized buffer.
These issues occur when the application handles specially crafted OXM and=
DTT files.
Attackers can exploit these issues to execute arbitrary code that could c=
ompromise the affected computer. Failed attacks will likely cause denial-=
of-service conditions.
Extended Media Player 2.5.1 is vulnerable; other versions may also be aff=
ected.
41. Ruby on Rails Form Helpers Unicode String Handling Cross Site Scripti=
ng Vulnerability
BugTraq ID: 36278
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36278
Summary:
Ruby on Rails is prone to a cross-site scripting vulnerability because it=
fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may let the attacker steal cookie-based authentication credentials an=
d launch other attacks
NOTE: The vendor has reported that this issue may also lead to HTML-injec=
tion attacks in some configurations.
Ruby on Rails 2.x.x (prior to 2.3.4 and 2.2.3) are affected.
42. ProFTPD 'mod_sql' Username SQL Injection Vulnerability
BugTraq ID: 33722
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/33722
Summary:
ProFTPD is prone to an SQL-injection vulnerability because it fails to su=
fficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to manipulate SQL queries, =
modify data, or exploit latent vulnerabilities in the underlying database=
. This may result in unauthorized access and a compromise of the applicat=
ion; other attacks are also possible.
ProFTPD 1.3.1 through 1.3.2 rc 2 are vulnerable.
43. PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulner=
ability
BugTraq ID: 35440
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35440
Summary:
PHP is prone to a denial-of-service vulnerability in its 'exif_read_data(=
)' function.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions in applications that use the vulnerable function.
=20
Versions prior to PHP 5.2.10 are affected.
44. FreeType Multiple Integer Overflow Vulnerabilities
BugTraq ID: 34550
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/34550
Summary:
FreeType is prone to multiple integer-overflow vulnerabilities because it=
fails to properly validate user-supplied input.=20
Successful exploits may allow attackers to execute arbitrary code in the =
context of applications that use the affected library. Failed exploit att=
empts will likely result in denial-of-service conditions.
These issues affect FreeType 2.3.9; other versions may also be affected.
45. PostgreSQL Multiple Security Vulnerabilities
BugTraq ID: 36314
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36314
Summary:
PostgreSQL is prone to multiple security vulnerabilities, including a den=
ial-of-service issue, a privilege-escalation issue, and an authentication=
-bypass issue.
Attackers can exploit these issues to shut down affected servers, perform=
certain actions with elevated privileges, and bypass authentication mech=
anisms to perform unauthorized actions. Other attacks may also be possib=
le.
46. MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
BugTraq ID: 35609
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35609
Summary:
MySQL is prone to multiple format-string vulnerabilities.
Attackers can leverage these issues to execute arbitrary code within the =
context of the vulnerable application. Failed attacks will likely cause d=
enial-of-service conditions.
MySQL 4.0.0 through 5.0.75 are vulnerable; other versions may also be aff=
ected.
47. MySQL Command Line Client HTML Special Characters HTML Injection Vuln=
erability
BugTraq ID: 31486
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/31486
Summary:
MySQL is prone to an HTML-injection vulnerability because the application=
's command-line client fails to properly sanitize user-supplied input bef=
ore using it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
48. Lyris ListManager Multiple Remote Vulnerabilities
BugTraq ID: 36509
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36509
Summary:
Lyris ListManager is prone to multiple vulnerabilities:
- An information-disclosure weakness
- Information-disclosure vulnerabilities
- SQL-injection vulnerabilities
- HTML-injection vulnerabilities
- Cross-site scripting vulnerabilities
Exploiting these issues could allow an attacker to steal cookie-based au=
thentication credentials, compromise the application, obtain sensitive in=
formation, access or modify data, or exploit latent vulnerabilities in th=
e underlying database.
49. Drupal Devel Module Variable Editor HTML Injection Vulnerability
BugTraq ID: 36508
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36508
Summary:
The Devel module for Drupal is prone to an HTML-injection vulnerability b=
ecause the application fails to properly sanitize user-supplied input bef=
ore using it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
Versions prior to Devel 6.x-1.18 and 5.x-1.2 are affected.
50. Drupal Markdown Preview Module Live Preview HTML Injection Vulnerabil=
ity
BugTraq ID: 36505
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36505
Summary:
The Markdown Preview module for Drupal is prone to an HTML-injection vuln=
erability because the application fails to properly sanitize user-supplie=
d input before using it in dynamically generated content.=20
Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how the site is rendered to the u=
ser. Other attacks are also possible.
Markdown 6.x is vulnerable; other versions may also be affected.
51. OSSIM SQL Injection, Cross Site Scripting and Unauthorized Access Vul=
nerabilities
BugTraq ID: 36504
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36504
Summary:
OSSIM is prone to multiple input-validation vulnerabilities, including SQ=
L-injection issues, a cross-site scripting issue, and unauthorized-acces=
s issues.
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, compromise the application, access or modify dat=
a, or exploit latent vulnerabilities in the underlying database.
Versions prior to OSSIM 2.1.2 are affected.
52. Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
BugTraq ID: 36296
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36296
Summary:
Cyrus IMAP Server is prone to a buffer-overflow vulnerability because it =
fails to perform adequate boundary checks on user-supplied data.=20
A local attacker can exploit this issue to execute arbitrary code as the =
affected process, possibly resulting in elevated privileges. Failed explo=
it attempts will likely cause denial-of-service conditions.
Cryus IMAP Server 2.2.13 is vulnerable; other versions may also be affect=
ed.
53. Xfig Multiple Insecure Temporary File Creation Vulnerabilities
BugTraq ID: 34328
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/34328
Summary:
Xfig creates temporary files in an insecure manner.
An attacker with local access could potentially exploit these issues to p=
erform symbolic-link attacks, overwriting arbitrary files in the context =
of the affected application.=20
Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
attacks may also be possible.
54. Adobe RoboHelp Server Authentication Bypass Vulnerability
BugTraq ID: 36245
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36245
Summary:
Adobe RoboHelp Server is prone to an authentication-bypass vulnerability.=
An attacker can exploit this issue to upload and execute arbitrary code =
with SYSTEM-level privileges.
RoboHelp Server 8.0 is affected; other versions may also be vulnerable.
55. WebKit Numeric Character References Remote Memory Corruption Vulnerab=
ility
BugTraq ID: 35607
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35607
Summary:
WebKit is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application. Failed exploit attempts will result in a denial-o=
f-service condition.
56. WebKit 'Attr' DOM Objects Remote Code Execution Vulnerability
BugTraq ID: 35310
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35310
Summary:
WebKit is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code in the context=
of the application. Failed exploit attempts will result in a denial-of-s=
ervice condition.
NOTE: This issue was previously covered in BID 35260 (Apple Safari Prior =
to 4.0 Multiple Security Vulnerabilities), but has been assigned its own =
record to better document it.
57. WebKit Java Applet Remote Code Execution Vulnerability
BugTraq ID: 35350
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35350
Summary:
WebKit is prone to a remote code-execution vulnerability.=20
Successfully exploiting this issue will allow attackers to execute arbitr=
ary code or obtain sensitive information.
NOTE: This issue was previously covered in BID 35260 (Apple Safari Prior =
to 4.0 Multiple Security
Vulnerabilities), but has been assigned its own record to better document=
it.
58. WebKit CSS 'Attr' Function Remote Code Execution Vulnerability
BugTraq ID: 35318
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35318
Summary:
WebKit is prone to a remote code-execution vulnerability.
Attackers may exploit this issue to execute arbitrary code in the context=
of the application. Failed exploit attempts will result in a denial-of-s=
ervice condition.
NOTE: This issue was previously covered in BID 35260 (Apple Safari Prior =
to 4.0 Multiple Security Vulnerabilities), but has been assigned its own =
record to better document it.
59. WebKit SVGList Objects Remote Memory Corruption Vulnerability
BugTraq ID: 34924
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/34924
Summary:
WebKit is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application. Failed exploit attempts will result in a denial-o=
f-service condition.
The issue also affects the following:
Apple Safari prior to 3.2.3
Apple Mac OS X v10.5 through v10.5.6,
Apple Mac OS X Server v10.5 through v10.5.6
Google Chrome prior to 1.0.154.65
60. WebKit JavaScript Garbage Collector Memory Corruption Vulnerability
BugTraq ID: 35309
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35309
Summary:
WebKit is prone to a memory-corruption vulnerability.
Attackers may exploit this issue to execute arbitrary code in the context=
of the application. Failed attack attempts will result in a denial-of-se=
rvice condition.
NOTE: This issue was previously covered in BID 35260 (Apple Safari Prior =
to 4.0 Multiple Security Vulnerabilities), but has been assigned its own =
record to better document it.
61. WebKit DOM Event Handler Remote Memory Corruption Vulnerability
BugTraq ID: 35271
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35271
Summary:
WebKit is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application. Failed exploit attempts will result in a denial-o=
f-service condition.
NOTE: This issue was previously covered in BID 35260 (Apple Safari Prior =
to 4.0 Multiple Security Vulnerabilities), but has been assigned its own =
record to better document it.
62. GNOME GLib Symbolic Link Arbitrary File Access Vulnerability
BugTraq ID: 36313
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36313
Summary:
GNOME GLib is prone to an arbitrary-file-access vulnerability.=20
Local attackers can exploit this issue to obtain sensitive information or=
overwrite files on the affected computer. Successful exploits may lead t=
o other attacks.
63. Apache APR and APR-util Multiple Integer Overflow Vulnerabilities
BugTraq ID: 35949
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/35949
Summary:
Apache APR (Apache Portable Runtime) and 'APR-util' are prone to multiple=
integer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the conte=
xt of an application that uses the affected library. Successful exploits =
will compromise the affected application and possibly the computer. Faile=
d attacks will cause denial-of-service conditions.
64. Apache mod_proxy_ftp Remote Command Injection Vulnerability
BugTraq ID: 36254
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36254
Summary:
The Apache mod_proxy_ftp module is prone to a remote command-injection vu=
lnerability because it fails to adequately sanitize user-supplied input d=
ata.
Attackers can exploit this issue to execute arbitrary commands within the=
context of the affected application.
65. Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Servic=
e Vulnerability
BugTraq ID: 36260
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36260
Summary:
The Apache 'mod_proxy_ftp' module is prone to a denial-of-service vulnera=
bility because of a NULL-pointer dereference.
Successful exploits may allow remote attackers to cause denial-of-service=
conditions. Given the nature of this issue, attackers may also be able t=
o run arbitrary code, but this has not been confirmed.
66. Joomla!/Mambo Tupinambis Component SQL Injection Vulnerability
BugTraq ID: 36511
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36511
Summary:
The Tupinambis component ('com_tupinambis') for Joomla! and Mambo is pron=
e to an SQL-injection vulnerability because it fails to sufficiently sani=
tize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Tupinambis 1.0 is affected; other versions may also be vulnerable.
67. Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vu=
lnerability
BugTraq ID: 36512
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36512
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability that=
affects the Kernel-based Virtual Machine (KVM).
Attackers can exploit this issue to crash a guest kernel or potentially g=
ain read or write access to guest kernel memory.
Linux kernel 2.6.25-rc1 through 2.6.30 are affected. Kernel 2.6.31 is not=
affected by this issue.
68. Sun Solaris Trusted Extensions Common Desktop Environment Local Privi=
lege Escalation Vulnerability
BugTraq ID: 36510
Remote: No
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36510
Summary:
Sun Solaris Trusted Extensions Common Desktop Environment (CDE) is prone =
to a local privilege-escalation vulnerability. This issue may also allow =
attackers to bypass the Mandatory Access Control (MAC) policy.
A local attacker can exploit this vulnerability to run arbitrary code wi=
th superuser privileges or gain access to restricted data.
Computers that have Solaris Trusted Extensions installed and configured o=
n Solaris 10 running on x86 or SPARC platforms are affected.
69. IBM Lotus Connections 'simpleSearch.do' Cross Site Scripting Vulnerab=
ility
BugTraq ID: 36513
Remote: Yes
Last Updated: 2009-09-24
Relevant URL: http://www.securityfocus.com/bid/36513
Summary:
IBM Lotus Connections is prone to a cross-site scripting vulnerability be=
cause it fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may let the attacker steal cookie-based authentication credentials an=
d launch other attacks
IBM Lotus Connections 2.0.1 is affected; other versions may be vulnerable=
as well.
70. Drupal Meta tags (Nodewords) Module Unauthorized Access Vulnerability
BugTraq ID: 36506
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36506
Summary:
The Drupal Meta tags (Nodewords) module is prone to an unauthorized-acces=
s vulnerability because it fails to adequately enforce access permissions=
.
An attacker can exploit this vulnerability to gain unauthorized access to=
the application; other attacks may also possible.=20
Versions prior to Meta tags (Nodewords) 6.x-1.1 are vulnerable.
71. Avast! Antivirus 'aswMon2.sys' Driver Local Privilege Escalation Vuln=
erability
BugTraq ID: 36507
Remote: No
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36507
Summary:
Avast! Antivirus is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with sup=
eruser privileges and completely compromise the affected computer. Failed=
exploit attempts will result in a denial-of-service condition.
Avast! Antivirus 4.8.1351.0 is vulnerable; other versions may also be aff=
ected.
72. BakBone NetVault Backup 'npvmgr.exe' Remote Denial Of Service Vulnera=
bility
BugTraq ID: 36489
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36489
Summary:
BakBone NetVault Backup is affected by a remote denial-of-service vulnera=
bility.
=20
Attackers can leverage this issue by sending specially crafted network pa=
ckets.
NetVault Backup 8.22 Build 29 is vulnerable; other versions may be affect=
ed as well.
73. TCP/IP Protocol Stack Multiple Remote Denial Of Service Vulnerabiliti=
es
BugTraq ID: 31545
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/31545
Summary:
The core TCP/IP protocol is prone to multiple remote denial-of-service vu=
lnerabilities.
=20
The issues are tracked by Cisco Bug IDs CSCsv04836, CSCsv07712, CSCsv6616=
9, CSCsv02768, CSCsv08325, and CSCsv08579.
These issues are reported to affect multiple vendors' implementations of =
the TCP/IP stack.
74. Vastal I-Tech Agent Zone SQL Injection Vulnerability
BugTraq ID: 36503
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36503
Summary:
Agent Zone is prone to an SQL-injection vulnerability because it fails to=
sufficiently sanitize user-supplied data before using it in an SQL query=
.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
75. Vastal I-Tech DVD Zone 'mag_id' Parameter Cross Site Scripting and SQ=
L Injection Vulnerabilities
BugTraq ID: 36487
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36487
Summary:
DVD Zone is prone to an SQL-injection vulnerability and a cross-site scri=
pting vulnerability because it fails to sufficiently sanitize user-suppli=
ed data.=20
Exploiting these issues could allow an attacker to steal cookie-based aut=
hentication credentials, compromise the application, access or modify dat=
a, or exploit latent vulnerabilities in the underlying database.
76. Vastal I-Tech Cosmetics Zone 'view_products.php' SQL Injection Vulner=
ability
BugTraq ID: 36485
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36485
Summary:
Cosmetics Zone is prone to an SQL-injection vulnerability because it fail=
s to sufficiently sanitize user-supplied data before using it in an SQL q=
uery.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
77. Vastal I-Tech MMORPG 'view_news.php' SQL Injection Vulnerability
BugTraq ID: 36483
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36483
Summary:
MMORPG is prone to an SQL-injection vulnerability because it fails to suf=
ficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
78. Cisco IOS NTPv4 Reply Packet Remote Denial of Service Vulnerability
BugTraq ID: 36502
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36502
Summary:
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload,=
denying service to legitimate users.
This issue is being tracked by Cisco Bug IDs CSCsu24505 and CSCsv75948.
79. Cisco IOS Specially Crafted Encryption Packet Denial of Service Vulne=
rability
BugTraq ID: 36493
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36493
Summary:
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload,=
denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsq24002.http://tools.cisco=
.com/Support/BugToolKit/search/getBugDetails.do?method=3DfetchBugDetails&=
amp;bugId=3DCSCsq24002
80. Cisco IOS Zone-Based Policy Firewall SIP Inspection Denial of Service=
Vulnerability
BugTraq ID: 36492
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36492
Summary:
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload,=
denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsr18691.
81. Cisco IOS Software Tunnels Multiple Denial of Service Vulnerabilities
BugTraq ID: 36500
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36500
Summary:
Cisco IOS is prone to multiple remote denial-of-service vulnerabilities.
An attacker can exploit these issues to cause an affected device to reloa=
d, denying service to legitimate users.
These issues are being tracked by Cisco Bug IDs CSCsh97579, CSCsq31776, a=
nd CSCsx70889.
82. Cisco IOS Software Internet Key Exchange Resource Exhaustion Denial o=
f Service Vulnerability
BugTraq ID: 36497
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36497
Summary:
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to consume all available Phase 1 secur=
ity associations, which may prevent new IPSec sessions from being establi=
shed.
This issue is being tracked by Cisco Bug IDs CSCsy07555 and CSCee72997.
83. Cisco IOS SIP Message Denial of Service Vulnerability
BugTraq ID: 36499
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36499
Summary:
Cisco IOS is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to crash a=
nd reload, denying service to legitimate users.
=20
This issue is tracked by Cisco Bug ID CSCsx25880.
84. Cisco Unified Communications Manager Express Extension Mobility Buffe=
r Overflow Vulnerability
BugTraq ID: 36498
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36498
Summary:
Cisco IOS devices configured for Unified Communications Manager Express a=
nd the Extension Mobility feature are prone to a buffer-overflow vulnerab=
ility.
Attackers can exploit this issue to execute arbitrary code or to cause de=
nial-of-service conditions.=20
This issue is documented by Cisco Bug ID CSCsq58779.
85. Cisco Unified Communications Manager SIP Message Denial of Service Vu=
lnerability
BugTraq ID: 36496
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36496
Summary:
Cisco Unified Communications Manager is prone to a denial-of-service vuln=
erability.
An attacker can exploit this issue to cause an interruption in voice se=
rvices, denying service to legitimate users.
=20
This issue is tracked by Cisco Bug ID CSCsz95423.
86. Cisco IOS Object Group Access Control List Bypass Vulnerability
BugTraq ID: 36495
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36495
Summary:
Cisco IOS is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass access control lists (ACLs),=
which may aid in further attacks.
This issue is documented by the following Cisco Bug IDs:
CSCsx07114
CSCsu70214
CSCsw47076
CSCsv48603
CSCsy54122
CSCsu50252
87. VLC Media Player Multiple Remote Stack Buffer Overflow Vulnerabilitie=
s
BugTraq ID: 36439
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36439
Summary:
VLC media player is prone to multiple stack-based buffer-overflow vulnera=
bilities.
Attackers can exploit these issues to execute arbitrary code in the conte=
xt of the affected application or crash the application, denying service =
to legitimate users.=20
VLC media player 1.0.1 is vulnerable; prior versions may also be affected=
.
88. LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
BugTraq ID: 35451
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/35451
Summary:
LibTIFF is prone to a remote buffer-underflow vulnerability because it fa=
ils to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary malicious code i=
n the context of a user running an application that uses the affected lib=
rary. Failed exploit attempts will likely crash the application.
LibTIFF 3.8.2 is vulnerable; other versions may be affected as well.
89. Cisco IOS H.323 Denial of Service Vulnerability
BugTraq ID: 36494
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36494
Summary:
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to reload=
, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsz38104.
90. Cisco IOS Authentication Proxy for HTTP(S) Authentication Bypass Vuln=
erability
BugTraq ID: 36491
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36491
Summary:
Cisco IOS is prone to a remote authentication-bypass vulnerability.
Successfully exploiting this issue allows remote attackers to gain access=
to vulnerable devices without requiring successful authentication.
This issue is being tracked by Cisco bug ID CSCsy15227.
91. nginx WebDAV Multiple Directory Traversal Vulnerabilities
BugTraq ID: 36490
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36490
Summary:
The 'nginx' program is prone to multiple directory-traversal vulnerabilit=
ies because the software fails to sufficiently sanitize user-supplied inp=
ut.
An attacker can exploit these issues using directory-traversal strings ('=
../') to overwrite arbitrary files outside the root directory.
These issues affect nginx 0.7.61 and 0.7.62; other versions may also be a=
ffected.
92. Joomla! JoomlaFacebook Component SQL Injection Vulnerability
BugTraq ID: 36484
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36484
Summary:
The JoomlaFacebook component ('com_facebook') for Joomla! is prone to an =
SQL-injection vulnerability because it fails to sufficiently sanitize use=
r-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
93. Joomla! SportFusion Component SQL Injection Vulnerability
BugTraq ID: 36481
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36481
Summary:
The SportFusion component ('com_sportfusion') for Joomla! is prone to an =
SQL-injection vulnerability because it fails to sufficiently sanitize use=
r-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
SportFusion 0.2.2 and 0.2.3 are affected; other versions may also be vuln=
erable.
94. Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities
BugTraq ID: 36328
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36328
Summary:
Apple QuickTime is prone to multiple vulnerabilities that may allow remot=
e attackers to execute arbitrary code.
These issues arise when the application handles specially crafted H.264, =
MPEG-4, and FlashPix video files. Successful exploits may allow attacker=
s to execute arbitrary code in the context of the currently logged-in use=
r; failed exploit attempts will cause denial-of-service conditions.
Versions prior to QuickTime 7.6.4 are vulnerable on Windows 7, Vista, XP,=
and Mac OS X platforms.
95. MaxWebPortal 'forum.asp' SQL Injection Vulnerability
BugTraq ID: 36480
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36480
Summary:
MaxWebPortal is prone to an SQL-injection vulnerability because it fails =
to sufficiently sanitize user-supplied data before using it in an SQL que=
ry.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
96. Google Chrome NULL Character CA SSL Certificate Validation Security B=
ypass Vulnerability
BugTraq ID: 36479
Remote: Yes
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36479
Summary:
Google Chrome is prone to a security-bypass vulnerability because it fail=
s to properly validate the domain name in a signed CA certificate, allowi=
ng attackers to substitute malicious SSL certificates for trusted ones.
Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
attacks.
97. Sun Solaris XScreenSaver X Resize and Rotate Local Information Disclo=
sure Vulnerability
BugTraq ID: 36488
Remote: No
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36488
Summary:
Solaris XScreenSaver is prone to a local information-disclosure vulnerabi=
lity.=20
A local attacker can exploit this issue to obtain sensitive information t=
hat may lead to further attacks.
This issue affects the following on both SPARC and x86 platforms:
Solaris 10
OpenSolaris based on builds snv_01 through snv_111
98. Sun Solaris Cluster Local Privilege Escalation Vulnerability
BugTraq ID: 36486
Remote: No
Last Updated: 2009-09-23
Relevant URL: http://www.securityfocus.com/bid/36486
Summary:
Sun Solaris Cluster is prone to a local privilege-escalation vulnerabilit=
y.
A local attacker can exploit this vulnerability to run arbitrary code wi=
th superuser privileges.
Solaris Cluster 3.2 is vulnerable.
99. Apple iTunes '.pls' File Buffer Overflow Vulnerability
BugTraq ID: 36478
Remote: Yes
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36478
Summary:
Apple iTunes is prone to a buffer-overflow vulnerability because the sof=
tware fails to bounds-check user-supplied data before copying it into an =
insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20
Versions prior to Apple iTunes 9.0.1 are vulnerable.
100. NetCitadel Firewall Builder Script Generation Insecure Temporary Fil=
e Creation Vulnerability
BugTraq ID: 36468
Remote: No
Last Updated: 2009-09-22
Relevant URL: http://www.securityfocus.com/bid/36468
Summary:
Firewall Builder creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symbolic-link attacks, overwriting arbitrary files in the context of=
the affected application.=20
Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files or to execute arbitrary code with elevated priv=
ileges.
Firewall Builder 3.0.4, 3.0.5, and 3.0.6 are vulnerable; other versions m=
ay also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Popular apps need better patching, says report
By: Robert Lemos
A report using data from two security vendors finds that ubiquitous appli=
cations, such as Apple's QuickTime and Adobe Flash, are not patched fast =
enough by their users.
http://www.securityfocus.com/news/11560
2. Hacker charged with Heartland, other breaches
By: Robert Lemos
A federal grand jury indicts a Florida man already charged with stealing =
data from TJX with allegedly helping breach five more companies.
http://www.securityfocus.com/news/11557
3. Web attacks hit U.S., South Korean sites
By: Robert Lemos
In its fourth day, a widespread distributed denial-of-service attack cont=
inued to inundate U.S. government and South Korean Web sites with network=
traffic.
http://www.securityfocus.com/news/11554
4. FTC persuades court to shutter rogue ISP
By: Robert Lemos
A federal district court shuts down Triple Fiber Network, after the Feder=
al Trade Commission documents the Internet service provider's cooperation=
with online criminals and child pornographers.
http://www.securityfocus.com/news/11552
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is sponsored by Entrust
Go Green for Less Green
Give your customers the highest level of assurance=20
Give your customers the green address bar
Entrust EV SSL Certificates - Now from only $199 per year
http://www.entrust.net/securityfocus-ev