SecurityFocus Linux Newsletter #441

[email protected] Thu, 18 Jun 2009 16:29:22 -0600
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #441
----------------------------------------

This issue is sponsored by VeriSign

VeriSign EV SSL Certificates for your sites' security turn the address ba=
r in high security browsers green which helps your customers know they ar=
e safe on your site.

http://ad.doubleclick.net/clk;215510129;37701658;c


------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Hacker-Tool Law Still Does Little
       2. A Botnet by Any Other Name
II.  LINUX VULNERABILITY SUMMARY
       1. Rasterbar Software libtorrent Arbitrary File Overwrite Vulnerab=
ility
       2. Apache Tomcat 'RequestDispatcher' Information Disclosure Vulner=
ability
       3. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulner=
abilities
       4. MoinMoin Hierarchical ACL Security Bypass Vulnerability
       5. Mozilla Firefox Large GIF File Background Denial of Service Vul=
nerability
       6. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
       7. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow=
 Vulnerability
       8. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerab=
ility
       9. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote =
Heap Buffer Overflow Vulnerability
       10. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
       11. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow V=
ulnerability
       12. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buff=
er Overflow Vulnerabilities
       13. Adobe Reader and Acrobat TrueType Font Handling Memory Corrupt=
ion Vulnerability
       14. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corru=
ption Vulnerability
       15. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap=
 Buffer Overflow Vulnerability
       16. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remo=
te Heap Buffer Overflow Vulnerability
       17. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Bu=
ffer Overflow Vulnerability
       18. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overf=
low Vulnerability
       19. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Co=
rruption Vulnerability
       20. Multiple Symantec Products RAR/TAR/ZIP File Scan Evasion Vulne=
rability
       21. Multiple F-PROT Products TAR File Scan Evasion Vulnerability
       22. Multiple Norman Products RAR/CAB File Scan Evasion Vulnerabili=
ty
       23. Mozilla Firefox 'NPObject' Access Remote Code Execution Vulner=
ability
       24. SugarCRM Email Attachment Arbitrary File Upload Vulnerability
       25. Multiple Kaspersky Products PDF File Scan Evasion Vulnerabilit=
y
       26. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine =
Memory Corruption Vulnerabilities
       27. Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Constructio=
n Memory Corruption Vulnerability
       28. Mozilla Firefox/Thunderbird/SeaMonkey Multiple JavaScript Engi=
ne Memory Corruption Vulnerabilities
       29. Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Esca=
lation Vulnerability
       30. Mozilla Firefox/Thunderbird/SeaMonkey XUL Scripts Content-Poli=
cy Check Security Bypass Vulnerability
       31. Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulne=
rability
       32. Sun Java Runtime Environment Aqua Look and Feel Privilege Esca=
lation Vulnerability
       33. Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbi=
trary Code Execution Vulnerability
       34. Mozilla Firefox/Thunderbird/SeaMonkey 'file://' URI Security B=
ypass Vulnerability
       35. Mozilla Firefox and SeaMonkey Address Bar URI Spoofing Vulnera=
bility
       36. Mozilla Firefox/SeaMonkey 'file://' URI Information Disclosure=
 Vulnerability
       37. Computer Associates ARCserve Backup Message Engine Denial of S=
ervice Vulnerability
       38. RETIRED: Sun Java Runtime Environment Aqua Look and Feel Privi=
lege Escalation Vulnerability
       39. Multiple Sophos Products CAB File Scan Evasion Vulnerability
       40. Multiple Browsers Cached Certificate HTTP Site Spoofing Vulner=
ability
       41. Mozilla Firefox 'nsViewManager.cpp' Denial of Service Vulnerab=
ility
       42. Multiple F-PROT Products RAR/ARJ/LHA/LZH File Scan Evasion Vul=
nerability
III. LINUX FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Hacker-Tool Law Still Does Little
By Mark Rasch
On August 10, 2007, a new section of the German Penal code went into effe=
ct. The statute, intended to implement certain provisions of the Council =
of Europe Treaty on Cybercrime, could be interpreted to make the creation=
 or distribution of computer security software a criminal offense.=20
http://www.securityfocus.com/columnists/502

2. A Botnet by Any Other Name
By Gubter Ollmann
The news has been awash the last few weeks with fears over globe-spanning=
 botnets and their criminal intent: Conficker managed to hog the limeligh=
t for well over a month, and then came Finjan's disclosure of a previousl=
y unknown - and currently unnamed - botnet consisting of some 1.9 million=
 malicious agents.=20
http://www.securityfocus.com/columnists/501


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Rasterbar Software libtorrent Arbitrary File Overwrite Vulnerability
BugTraq ID: 35262
Remote: Yes
Date Published: 2009-06-08
Relevant URL: http://www.securityfocus.com/bid/35262
Summary:
The 'libtorrent' library is prone to a vulnerability that may allow remot=
e attackers to overwrite arbitrary local files. This may result in a deni=
al-of-service condition or aid in further attacks.

This issue affects versions prior to libtorrent 0.14.4.

2. Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
BugTraq ID: 35263
Remote: Yes
Date Published: 2009-06-08
Relevant URL: http://www.securityfocus.com/bid/35263
Summary:
Apache Tomcat is prone to a remote information-disclosure vulnerability.

Attackers can exploit this issue to obtain sensitive information that may=
 lead to further attacks.

The following versions of Apache Tomcat are vulnerable:=20

6.0.0-6.0.18
 5.5.0-5.5.27
4.1.0-4.1.39

3. Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabiliti=
es
BugTraq ID: 35274
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35274
Summary:
Adobe Reader and Acrobat are prone to multiple remote vulnerabilities.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

The following individual records have been created to better document som=
e of these issues:

35298 Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption=
 Vulnerability
35295 Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Ov=
erflow Vulnerabilities
35294 Adobe Reader and Acrobat 9.1.1 and Prior Integer Overflow Vulnerabi=
lity
35296 Adobe Reader and Acrobat 9.1.1 and Prior Unspecified Memory Corrupt=
ion Vulnerability
35289 Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerabilit=
y
35293 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35291 Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap=
 Buffer Overflow Vulnerability
35282 Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vul=
nerability
35299 Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buff=
er Overflow Vulnerability
35300 Adobe Reader &amp; Acrobat JBIG Pattern Dictionary Allocation Remot=
e Heap Buffer Overflow Vulnerability
35301 Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer =
Overflow Vulnerability
35302 Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow V=
ulnerability
35303 Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corrupt=
ion Vulnerability

The vendor reports other unspecified security issues have also been addre=
ssed. Information regarding these issues is currently not available. We w=
ill update this BID as more information emerges.

4. MoinMoin Hierarchical ACL Security Bypass Vulnerability
BugTraq ID: 35277
Remote: Yes
Date Published: 2009-06-10
Relevant URL: http://www.securityfocus.com/bid/35277
Summary:
MoinMoin is prone to a security-bypass vulnerability.

Successful exploits will allow attackers to bypass certain security restr=
ictions and gain unauthorized access to restricted sub-pages. This may ai=
d in further attacks.

This issue affects MoinMoin 1.8.3; other versions may also be affected.

5. Mozilla Firefox Large GIF File Background Denial of Service Vulnerabil=
ity
BugTraq ID: 35280
Remote: Yes
Date Published: 2009-06-10
Relevant URL: http://www.securityfocus.com/bid/35280
Summary:
Mozilla Firefox is prone to a remote denial-of-service vulnerability.=20

Successful exploits can allow attackers to crash the affected browser, re=
sulting in denial-of-service conditions.

Firefox 3.0.10 is affected; other versions mat also be vulnerable.

6. Linux Kernel RTL8169 NIC Remote Denial of Service Vulnerability
BugTraq ID: 35281
Remote: Yes
Date Published: 2009-06-10
Relevant URL: http://www.securityfocus.com/bid/35281
Summary:
The Linux Kernel is prone to a remote denial-of-service vulnerability.

An attacker can exploit this issue to crash the system, denying service t=
o legitimate users.=20
Given the nature of this issue, the attacker may also be able to run arbi=
trary code, but this has not been confirmed.

Versions prior to Linux Kernel 2.6.30 are vulnerable.

7. Adobe Reader and Acrobat U3D Model Remote Stack Buffer Overflow Vulner=
ability
BugTraq ID: 35282
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35282
Summary:
Adobe Reader and Acrobat are prone to a remote stack-based buffer-overflo=
w vulnerability because they fail to adequately bounds-check user-supplie=
d data.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

8. Adobe Reader and Acrobat Unspecified Memory Corruption Vulnerability
BugTraq ID: 35289
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35289
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.=20

Exploiting this issue will allow remote attackers to execute arbitrary co=
de within the context of the affected application or crash the applicatio=
n.

 NOTE: This issue was previously covered in BID 35274 (Adobe Reader and A=
crobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been ass=
igned its own record to better document it.

9. Adobe Reader and Acrobat JBIG Halftone Region Grid Area Remote Heap Bu=
ffer Overflow Vulnerability
BugTraq ID: 35291
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35291
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

10. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35293
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35293
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

11. Adobe Reader and Acrobat FlateDecode Filter Integer Overflow Vulnerab=
ility
BugTraq ID: 35294
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35294
Summary:
Adobe Reader and Acrobat are prone to an integer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

12. Adobe Reader and Acrobat Multiple Unspecified Remote Heap Buffer Over=
flow Vulnerabilities
BugTraq ID: 35295
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35295
Summary:
Adobe Reader and Acrobat are prone to multiple remote heap-based buffer-o=
verflow vulnerabilities because they fail to sufficiently sanitize user-s=
upplied input.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: These issues were previously covered in BID 35274 (Adobe Reader and=
 Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been a=
ssigned their own record to better document the issues.

13. Adobe Reader and Acrobat TrueType Font Handling Memory Corruption Vul=
nerability
BugTraq ID: 35296
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35296
Summary:
Adobe Reader and Acrobat are prone to a memory-corruption vulnerability.

An attacker can exploit this issue to execute arbitrary code. Failed expl=
oit attempts will likely cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

14. Adobe Reader and Acrobat JBIG2 Filter Unspecified Memory Corruption V=
ulnerability
BugTraq ID: 35298
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35298
Summary:
Adobe Reader and Acrobat are prone to an unspecified memory-corruption vu=
lnerability.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

15. Adobe Reader and Acrobat JBIG 'Pattern Dictionary' Remote Heap Buffer=
 Overflow Vulnerability
BugTraq ID: 35299
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35299
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

16. Adobe Reader & Acrobat JBIG Pattern Dictionary Allocation Remote Heap=
 Buffer Overflow Vulnerability
BugTraq ID: 35300
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35300
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

17. Adobe Reader and Acrobat JBIG 'Halftone Region' Remote Heap Buffer Ov=
erflow Vulnerability
BugTraq ID: 35301
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35301
Summary:
Adobe Reader and Acrobat are prone to a remote heap-based buffer-overflow=
 vulnerability because they fail to sufficiently sanitize user-supplied i=
nput.

An attacker can exploit this issue by tricking a victim into opening a ma=
licious file to execute arbitrary code and to cause denial-of-service con=
ditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

18. Adobe Reader and Acrobat Huffman-encoded JBIG2 Text Heap Overflow Vul=
nerability
BugTraq ID: 35302
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35302
Summary:
Adobe Reader and Acrobat are prone to a heap-based buffer-overflow vulner=
ability.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

19. Adobe Reader and Acrobat JBIG Segments 'Text Region' Memory Corruptio=
n Vulnerability
BugTraq ID: 35303
Remote: Yes
Date Published: 2009-06-09
Relevant URL: http://www.securityfocus.com/bid/35303
Summary:
Adobe Reader and Acrobat are prone to a memory corruption vulnerability.

An attacker can exploit these issues by tricking a victim into opening a =
malicious file to execute arbitrary code and to cause denial-of-service c=
onditions.

NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Ac=
robat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assi=
gned its own record to better document it.

20. Multiple Symantec Products RAR/TAR/ZIP File Scan Evasion Vulnerabilit=
y
BugTraq ID: 35354
Remote: Yes
Date Published: 2009-06-12
Relevant URL: http://www.securityfocus.com/bid/35354
Summary:
Multiple Symantec products are prone to a vulnerability that may allow ce=
rtain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

The following products are affected:

Symantec Mail Security for Domino=20
Symantec Mail Security for Microsoft Exchange=20
Symantec Mail Security for SMTP=20
Symantec Brightmail Gateway=20
Symantec AntiVirus for Network Attached Storage=20
Symantec AntiVirus for Caching=20
Symantec AntiVirus for Messaging=20
Symantec Protection for SharePoint Servers=20
Symantec Protection Suite=20
Symantec Scan Engine=20
Symantec Client Security=20
Symantec Endpoint Protection=20
Symantec AntiVirus Corporate Edition=20
Norton Internet Security=20
Norton 360=20
Norton AntiVirus=20
Norton Systemworks

21. Multiple F-PROT Products TAR File Scan Evasion Vulnerability
BugTraq ID: 35355
Remote: Yes
Date Published: 2009-06-14
Relevant URL: http://www.securityfocus.com/bid/35355
Summary:
Multiple F-PROT products are prone to a vulnerability that may allow cert=
ain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

22. Multiple Norman Products RAR/CAB File Scan Evasion Vulnerability
BugTraq ID: 35357
Remote: Yes
Date Published: 2009-06-08
Relevant URL: http://www.securityfocus.com/bid/35357
Summary:
Multiple Norman products are prone to a vulnerability that may allow cert=
ain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

The following products are affected:

Norman Virus Control single user and corporate versions
Norman Internet Control
Norman Virus Control E-mail plugins
Norman Endpoint Protection
Norman Secuirty Suite
Norman Network Protection

23. Mozilla Firefox 'NPObject' Access Remote Code Execution Vulnerability
BugTraq ID: 35360
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35360
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability.=20

Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running the affected application or to obtain sensi=
tive information.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

24. SugarCRM Email Attachment Arbitrary File Upload Vulnerability
BugTraq ID: 35361
Remote: Yes
Date Published: 2009-06-13
Relevant URL: http://www.securityfocus.com/bid/35361
Summary:
SugarCRM is prone to a vulnerability that lets attackers upload arbitrary=
 files. The issue occurs because the application fails to adequately vali=
date user-supplied input.=20

An attacker can exploit this vulnerability to upload arbitrary code and e=
xecute it in the context of the webserver process. This may facilitate un=
authorized access or privilege escalation; other attacks are also possibl=
e.

The issue affects SugarCRM 5.2.0e; prior versions may also be vulnerable.

25. Multiple Kaspersky Products PDF File Scan Evasion Vulnerability
BugTraq ID: 35365
Remote: Yes
Date Published: 2009-06-13
Relevant URL: http://www.securityfocus.com/bid/35365
Summary:
Multiple Kaspersky products are prone to a vulnerability that may allow c=
ertain PDF files to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

26. Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine Memory =
Corruption Vulnerabilities
BugTraq ID: 35370
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35370
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to multiple remote =
memory-corruption vulnerabilities.

An attacker can exploit these issues to corrupt memory on the affected co=
mputer and run arbitrary code in the context of the user running the affe=
cted application. Failed exploit attempts will cause denial-of-service co=
nditions.

NOTE: In some cases, arbitrary code execution may not be possible.

NOTE: These issues were previously covered in BID 35326 (Mozilla Firefox/=
Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabil=
ities), but have been assigned their own record to better document them.

27. Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Construction Memor=
y Corruption Vulnerability
BugTraq ID: 35371
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35371
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote memory-=
corruption vulnerability.

An attacker can exploit these issues to corrupt memory on the affected co=
mputer and run arbitrary code in the context of the user running the affe=
cted application. Failed exploit attempts will cause denial-of-service co=
nditions.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

28. Mozilla Firefox/Thunderbird/SeaMonkey Multiple JavaScript Engine Memo=
ry Corruption Vulnerabilities
BugTraq ID: 35372
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35372
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to multiple remote =
memory-corruption vulnerabilities.

An attacker can exploit these issues to corrupt memory on the affected co=
mputer and run arbitrary code in the context of the user running the affe=
cted application. Failed exploit attempts will cause denial-of-service co=
nditions.

NOTE: These issues were previously covered in BID 35326 (Mozilla Firefox/=
Thunderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabil=
ities), but have been assigned their own record to better document them.

29. Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Escalation =
Vulnerability
BugTraq ID: 35373
Remote: Yes
Date Published: 2009-06-15
Relevant URL: http://www.securityfocus.com/bid/35373
Summary:
Mozilla Firefox and SeaMonkey are prone to a privilege-escalation vulnera=
bility in the browser's sidebar and FeedWriter.

Attackers can exploit this issue to execute arbitrary code with the objec=
t's chrome privileges.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

30. Mozilla Firefox/Thunderbird/SeaMonkey XUL Scripts Content-Policy Chec=
k Security Bypass Vulnerability
BugTraq ID: 35377
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35377
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a security-bypas=
s vulnerability.

Attackers can exploit this issue to bypass the content-loading policies. =
 The impact of this issue will depend on the reasons behind the content c=
heck.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

31. Multiple Browser Malicious Proxy HTTPS Man In The Middle Vulnerabilit=
y
BugTraq ID: 35380
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35380
Summary:
Multiple web browsers are prone to a man-in-the-middle vulnerability.

Attacker-supplied HTML and script code would run in the context of the af=
fected browser, potentially allowing the attacker to steal cookie-based a=
uthentication credentials or to control how sites are rendered to the use=
r. Other attacks are also possible.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

UPDATE (June 17, 2009): This BID had been updated to reflect that the iss=
ue affects multiple browsers, not just Mozilla products.

32. Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation =
Vulnerability
BugTraq ID: 35381
Remote: Yes
Date Published: 2009-06-15
Relevant URL: http://www.securityfocus.com/bid/35381
Summary:
Sun Java Runtime Environment (JRE) is prone to a privilege-escalation vul=
nerability.

Successful exploits may allow attackers to execute arbitrary code with el=
evated privileges on affected computers.=20

This issue affects JRE 1.5 running on Mac OS X 10.5.

33. Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbitrary C=
ode Execution Vulnerability
BugTraq ID: 35383
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35383
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a remote code-ex=
ecution vulnerability.

Attackers can exploit this issue to execute arbitrary JavaScript code wit=
h chrome privileges. This may result in elevated privileges or lead to a =
denial-of-service condition. Other attacks may also be possible.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

34. Mozilla Firefox/Thunderbird/SeaMonkey 'file://' URI Security Bypass V=
ulnerability
BugTraq ID: 35386
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35386
Summary:
Mozilla Firefox, Thunderbird, and SeaMonkey are prone to a security-bypas=
s vulnerability.

Attackers can exploit this issue to bypass restrictions on reading local =
files, which may allow them to obtain sensitive information or launch oth=
er attacks.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

35. Mozilla Firefox and SeaMonkey Address Bar URI Spoofing Vulnerability
BugTraq ID: 35388
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35388
Summary:
Mozilla Firefox and SeaMonkey are affected by a URI-spoofing vulnerabilit=
y because they fail to adequately handle user-supplied data.
=20
 An attacker may leverage this issue by inserting arbitrary content to sp=
oof a URI presented to an unsuspecting user. This may lead to a false sen=
se of trust because the victim may be presented with a URI of a seemingly=
 trusted site while interacting with the attacker's malicious site.

 Versions *prior to* the following are affected:

Firefox 3.0.11
SeaMonkey 1.1.17

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

36. Mozilla Firefox/SeaMonkey 'file://' URI Information Disclosure Vulner=
ability
BugTraq ID: 35391
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35391
Summary:
Mozilla Firefox and SeaMonkey are prone to an information-disclosure vuln=
erability.

Attackers can exploit this issue to bypass certain security restrictions =
and gain access to potentially sensitive information that may aid in furt=
her attacks.

NOTE: This issue was previously covered in BID 35326 (Mozilla Firefox/Thu=
nderbird/SeaMonkey MFSA 2009-24 through -32 Multiple Remote Vulnerabiliti=
es), but has been assigned its own record to better document it.

37. Computer Associates ARCserve Backup Message Engine Denial of Service =
Vulnerability
BugTraq ID: 35396
Remote: Yes
Date Published: 2009-06-16
Relevant URL: http://www.securityfocus.com/bid/35396
Summary:
Computer Associates ARCserve Backup is prone to multiple denial-of-servic=
e vulnerabilities.=20

Attackers can exploit these issues to crash the affected application, den=
ying service to legitimate users.

The following applications are affected:
=20
CA ARCserve Backup r12.0 Windows
CA ARCserve Backup r12.0 SP 1 Windows

38. RETIRED: Sun Java Runtime Environment Aqua Look and Feel Privilege Es=
calation Vulnerability
BugTraq ID: 35401
Remote: Yes
Date Published: 2009-06-16
Relevant URL: http://www.securityfocus.com/bid/35401
Summary:
Sun Java Runtime Environment (JRE) is prone to a privilege-escalation vul=
nerability.

Successful exploits may allow attackers to execute arbitrary code with el=
evated privileges on affected computers.=20

This issue affects JRE 1.5 running on Mac OS X 10.5.

NOTE: This BID is being retied because the vulnerability was previously d=
ocumented in BID 35381 (Sun Java Runtime Environment Aqua Look and Feel P=
rivilege Escalation Vulnerability).

39. Multiple Sophos Products CAB File Scan Evasion Vulnerability
BugTraq ID: 35402
Remote: Yes
Date Published: 2009-06-16
Relevant URL: http://www.securityfocus.com/bid/35402
Summary:
Multiple Sophos products are prone to a vulnerability that may allow cert=
ain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

 Versions prior to the following are vulnerable:
=20
 Sophos Anti-Virus for Windows 7.6.8
 Sophos Anti-Virus for Windows 4.7.23
 Sophos Anti-Virus for OS X 4.9.23/7.02
 Sophos Anti-Virus for Linux 6.6.3
 Sophos Anti-Virus for UNIX 7.0.10
 Sophos Anti-Virus for Unix 4.42.0
 Sophos Anti-Virus for Netware 4.42.0
 Sophos Email Appliance 3.1.4.1
 Sophos Web Appliance 3.0.0
 Pure Message for Unix 5.5.5

40. Multiple Browsers Cached Certificate HTTP Site Spoofing Vulnerability
BugTraq ID: 35411
Remote: Yes
Date Published: 2009-06-17
Relevant URL: http://www.securityfocus.com/bid/35411
Summary:
Multiple browsers are prone to a vulnerability that may allow attackers t=
o spoof arbitrary HTTPS sites.

Attackers may exploit this vulnerability via a malicious webpage to spoof=
 the origin of an HTTPS site. Successful exploits will lead to a false se=
nsitive security since the victim is visiting a site that is assumed to b=
e legitimate.

41. Mozilla Firefox 'nsViewManager.cpp' Denial of Service Vulnerability
BugTraq ID: 35413
Remote: Yes
Date Published: 2009-06-11
Relevant URL: http://www.securityfocus.com/bid/35413
Summary:
Mozilla Firefox is prone to a remote denial-of-service vulnerability.

Successful exploits can allow attackers to crash the affected browser, re=
sulting in denial-of-service conditions.

Firefox 3.0.2 through 3.0.10 are vulnerable.

42. Multiple F-PROT Products RAR/ARJ/LHA/LZH File Scan Evasion Vulnerabil=
ity
BugTraq ID: 35427
Remote: Yes
Date Published: 2009-06-18
Relevant URL: http://www.securityfocus.com/bid/35427
Summary:
Multiple F-PROT products are prone to a vulnerability that may allow cert=
ain compressed archives to bypass the scan engine.

Successful exploits will allow attackers to distribute files containing m=
alicious code that the antivirus application will fail to detect.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by VeriSign

VeriSign EV SSL Certificates for your sites' security turn the address ba=
r in high security browsers green which helps your customers know they ar=
e safe on your site.

http://ad.doubleclick.net/clk;215510129;37701658;c