Secunia Bulletins March 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins March 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For March 7 2008[/b][/i]

[b]Windows:--[/b]

[SA29233] Programmer's Notepad ctags Processing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06

A vulnerability has been discovered in Programmer's Notepad, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29233/\"]http://secunia.com/advisories/29233/[/url]

--

[SA29195] Learn2 STRunner ActiveX Control Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03

Will Dormann has reported some vulnerabilities in Learn2 STRunner ActiveX control, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29195/\"]http://secunia.com/advisories/29195/[/url]

--

[SA29230] Versant Object Database Command Execution Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05

Luigi Auriemma has discovered a vulnerability in Versant Object Database, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29230/\"]http://secunia.com/advisories/29230/[/url]

--

[SA29213] Borland VisiBroker Smart Agent Packet Handling
Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-04

Luigi Auriemma has reported some vulnerabilities in Borland VisiBroker, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29213/\"]http://secunia.com/advisories/29213/[/url]

--

[SA29208] Borland StarTeam StarTeamMPX and StarTeam Server Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03

Luigi Auriemma has reported some vulnerabilities in Borland StarTeam, which can be exploited by malicious users or malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29208/\"]http://secunia.com/advisories/29208/[/url]

--

[SA29207] PacketTrap pt360 TFTP Server Two Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-05

Two vulnerabilities have been reported in the PacketTrap pt360, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29207/\"]http://secunia.com/advisories/29207/[/url]

--

[SA29246] eScan Corporate Edition eScan Management Console FTP Server Arbitrary File Download

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06

Luigi Auriemma has discovered a vulnerability in eScan Corporate Edition, which can be exploited by malicious people to disclose
sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29246/\"]http://secunia.com/advisories/29246/[/url]

--

[SA29231] Perforce Server Denial of Service Vulnerabilities

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06

Luigi Auriemma has discovered some vulnerabilities in Perforce Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29231/\"]http://secunia.com/advisories/29231/[/url]


[b]UNIX/Linux:--[/b]

[SA29258] Gentoo update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06

Gentoo has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29258/\"]http://secunia.com/advisories/29258/[/url]

--

[SA29244] Debian update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06

Debian has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29244/\"]http://secunia.com/advisories/29244/[/url]

--

[SA29214] Red Hat update for java-1.5.0-bea

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-03-05

Red Hat has issued an update for java-1.5.0-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data, or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29214/\"]http://secunia.com/advisories/29214/[/url]

--

[SA29211] Slackware update for mozilla-thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-03

Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29211/\"]http://secunia.com/advisories/29211/[/url]

--

[SA29210] Ubuntu update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-06

Ubuntu has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29210/\"]http://secunia.com/advisories/29210/[/url]

--

[SA29205] Gentoo update for acroread

Critical: Highly critical
Where: From remote
Impact: Unknown, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-03



Full Advisory:
[url=\"http://secunia.com/advisories/29205/\"]http://secunia.com/advisories/29205/[/url]

--

[SA29196] Slackware update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-03

Slackware has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29196/\"]http://secunia.com/advisories/29196/[/url]

--

[SA29182] Gentoo update for win32codecs

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05

Gentoo has issued an update for win32codecs. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29182/\"]http://secunia.com/advisories/29182/[/url]

--

[SA29181] Gentoo update for sword

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-04

Gentoo has issued an update for sword. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29181/\"]http://secunia.com/advisories/29181/[/url]

--

[SA29169] Mandriva update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-02-29

Mandriva has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29169/\"]http://secunia.com/advisories/29169/[/url]

--

[SA29167] Fedora update for thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-02-29

Fedora has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or potentially to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29167/\"]http://secunia.com/advisories/29167/[/url]

--

[SA29164] rPath update for thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, DoS, System access
Released: 2008-03-03

rPath has issued an update for thunderbird. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks, disclose potentially sensitive information, bypass certain security restrictions and compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29164/\"]http://secunia.com/advisories/29164/[/url]

--

[SA29163] Red Hat update for evolution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-05

Red Hat has issued an update for evolution. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29163/\"]http://secunia.com/advisories/29163/[/url]

--

[SA29248] Mandriva update for tcl

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-06

Mandriva has issued an update for tcl. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29248/\"]http://secunia.com/advisories/29248/[/url]

--

[SA29223] Mandriva update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04

Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29223/\"]http://secunia.com/advisories/29223/[/url]

--

[SA29209] Gentoo update for lighttpd

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-03-06

Gentoo has issued an update for lighttpd. This fixes a security issue and a vulnerability, which can be exploited by malicious people to
disclose potentially sensitive information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29209/\"]http://secunia.com/advisories/29209/[/url]

--

[SA29194] Debian update for libicu

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-04

Debian has issued an update for libicu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29194/\"]http://secunia.com/advisories/29194/[/url]

--

[SA29188] rPath update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-03

rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29188/\"]http://secunia.com/advisories/29188/[/url]

--

[SA29186] Fedora update for horde

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29

Fedora has issued an update for horde. This fixes a security issue and a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/29186/\"]http://secunia.com/advisories/29186/[/url]

--

[SA29185] Fedora update for imp

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29

Fedora has issued an update for imp. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions, and by malicious people to bypass certain security restrictions and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/29185/\"]http://secunia.com/advisories/29185/[/url]

--

[SA29184] Fedora update for turba

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-02-29

Fedora has issued an update for turba. This fixes a security issue and a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to bypass certain security restrictions and manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/29184/\"]http://secunia.com/advisories/29184/[/url]

--

[SA29180] NetBSD FAST_IPSEC "ipsec4_get_ulp()" Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29

A security issue has been reported in NetBSD, which can potentially be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29180/\"]http://secunia.com/advisories/29180/[/url]

--

[SA29178] SUSE update for opera

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-02-29

SUSE has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site
scripting attacks, disclose sensitive information, or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29178/\"]http://secunia.com/advisories/29178/[/url]

--

[SA29175] rPath update for pcre

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29

rPath has issued an update for pcre. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29175/\"]http://secunia.com/advisories/29175/[/url]

--

[SA29166] rPath update for lighttpd

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-02-29

rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29166/\"]http://secunia.com/advisories/29166/[/url]

--

[SA29251] SUSE update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-06

SUSE has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29251/\"]http://secunia.com/advisories/29251/[/url]

--

[SA29219] Linux Kiss Server "log_message()" Format String Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-05

vashnukad has discovered a vulnerability in Linux Kiss Server, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29219/\"]http://secunia.com/advisories/29219/[/url]

--

[SA29203] Gentoo update for firebird

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-03

Gentoo has issued an update for firebird. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29203/\"]http://secunia.com/advisories/29203/[/url]

--

[SA29257] Mandriva update for joomla

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06

Mandriva has issued an update for joomla. This fixes some vulnerabilities, which can be exploited by malicious users to conduct
script insertion attacks and by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29257/\"]http://secunia.com/advisories/29257/[/url]

--

[SA29235] lighttpd mod_cgi Information Disclosure Security Issue

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-05

A security issue has been reported in lighttpd, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29235/\"]http://secunia.com/advisories/29235/[/url]

--

[SA29224] VMware ESX Server update for e2fsprogs

Critical: Less critical
Where: From remote
Impact: System access, DoS
Released: 2008-03-04

VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29224/\"]http://secunia.com/advisories/29224/[/url]

--

[SA29202] Fedora update for viewvc

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03

Fedora has issued an update for viewvc. This fixes some security issues, which can be exploited by malicious people to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29202/\"]http://secunia.com/advisories/29202/[/url]

--

[SA29198] Gentoo update for mantisbt

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04

Gentoo has issued an update for mantisbt. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29198/\"]http://secunia.com/advisories/29198/[/url]

--

[SA29179] NetBSD file "file_printf()" Integer Underflow Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-02-29

A vulnerability has been reported in NetBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29179/\"]http://secunia.com/advisories/29179/[/url]

--

[SA29176] ViewVC Multiple Security Issues

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29

Some security issues have been reported in ViewVC, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29176/\"]http://secunia.com/advisories/29176/[/url]

--

[SA29168] Gentoo update for paramiko

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-04

Gentoo has issued an update for paramiko. This fixes a weakness, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29168/\"]http://secunia.com/advisories/29168/[/url]

--

[SA29256] Ubuntu update for openldap

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06

Ubuntu has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29256/\"]http://secunia.com/advisories/29256/[/url]

--

[SA29225] Mandriva update for openldap

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06

Mandriva has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29225/\"]http://secunia.com/advisories/29225/[/url]

--

[SA29189] rPath update for cups

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-03

rPath has issued an update for cups. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29189/\"]http://secunia.com/advisories/29189/[/url]

--

[SA29240] user-ppp "command_Expand_Interpret()" Buffer Overflow Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06

sipher has reported a vulnerability in user-ppp, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29240/\"]http://secunia.com/advisories/29240/[/url]

--

[SA29238] FreeBSD ppp Buffer Overflow Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06

A vulnerability has been reported in FreeBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29238/\"]http://secunia.com/advisories/29238/[/url]

--

[SA29236] Red Hat update for kernel

Critical: Less critical
Where: Local system
Impact: Unknown, Security Bypass, DoS
Released: 2008-03-06

Red Hat has issued an update for the kernel. This fixes a security issue and some vulnerabilities, where one has an unknown impact and others can be exploited by malicious, local users to bypass certain security restrictions or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29236/\"]http://secunia.com/advisories/29236/[/url]

--

[SA29234] OpenBSD ppp Buffer Overflow Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06

A vulnerability has been reported in OpenBSD, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29234/\"]http://secunia.com/advisories/29234/[/url]

--

[SA29229] Adobe Reader for Linux Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04

A security issue has been reported in Adobe Reader, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29229/\"]http://secunia.com/advisories/29229/[/url]

--

[SA29206] Gentoo update for audacity

Critical: Less critical
Where: Local system
Impact: Manipulation of data, DoS
Released: 2008-03-03

Gentoo has issued an update for audacity. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.

Full Advisory:
[url=\"http://secunia.com/advisories/29206/\"]http://secunia.com/advisories/29206/[/url]

--

[SA29190] Gentoo update for splitvt

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-04

Gentoo has issued an update for splitvt. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29190/\"]http://secunia.com/advisories/29190/[/url]

--

[SA29187] rPath update for am-utils

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-02-29

rPath has issued an update for am-utils. This fixes a security issue, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29187/\"]http://secunia.com/advisories/29187/[/url]

--

[SA29173] Fedora update for dbus

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29

Fedora has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29173/\"]http://secunia.com/advisories/29173/[/url]

--

[SA29171] Mandriva update for dbus

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29

Mandriva has issued an update for dbus. This fixes a security issue, which can be exploited by malicious, local users to bypass certain
security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29171/\"]http://secunia.com/advisories/29171/[/url]

--

[SA29259] Gentoo update for vobcopy

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-06

Gentoo has issued an update for vobcopy. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29259/\"]http://secunia.com/advisories/29259/[/url]

--

[SA29253] Sun Solaris 10 ipsecah Denial of Service Vulnerability

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-06

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29253/\"]http://secunia.com/advisories/29253/[/url]

--

[SA29217] Sun Solaris 8 Directory Functions Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-03

A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29217/\"]http://secunia.com/advisories/29217/[/url]

--

[SA29172] Fedora update for xen

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-02-29

Fedora has issued an update for xen. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29172/\"]http://secunia.com/advisories/29172/[/url]


[b]Other:--[/b]

[SA29199] Livebox TP Router ADI Convergence Galaxy FTP Server Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-04

0in has reported a vulnerability in Livebox TP routers, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29199/\"]http://secunia.com/advisories/29199/[/url]

--

[SA29243] Check Point VPN-1 UTM Edge Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06

Henri Lindberg has reported a vulnerability in Check Point VPN-1 UTM Edge, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29243/\"]http://secunia.com/advisories/29243/[/url]

--

[SA29165] Juniper Networks Secure Access 2000 "delivery_mode" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04

A vulnerability has been reported in Juniper Networks Secure Access 2000, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29165/\"]http://secunia.com/advisories/29165/[/url]


[b]Cross Platform:--[/b]

[SA29254] Dokeos Code Execution and Cross-Site Scripting

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-03-06

Some vulnerabilities have been reported in Dokeos, which can be exploited by malicious people to conduct cross-site scripting attacks
or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29254/\"]http://secunia.com/advisories/29254/[/url]

--

[SA29239] Sun Java JDK / JRE Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-03-05

Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to cause a DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29239/\"]http://secunia.com/advisories/29239/[/url]

--

[SA29232] Ruby WEBrick Information Disclosure Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-06

Some vulnerabilities have been reported in Ruby, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29232/\"]http://secunia.com/advisories/29232/[/url]

--

[SA29218] KC Wiki "page" Information Disclosure and Manipulation

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-03-04

Two vulnerabilities have been discovered in KC Wiki, which can be exploited by malicious people to disclose sensitive information or to manipulate data.

Full Advisory:
[url=\"http://secunia.com/advisories/29218/\"]http://secunia.com/advisories/29218/[/url]

--

[SA29216] MediaWiki JSON Callback Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-03-03

A vulnerability has been reported in MediaWiki, which can potentially be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29216/\"]http://secunia.com/advisories/29216/[/url]

--

[SA29212] Dynamic Photo Gallery "albumID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03

Aria-Security Team has reported a vulnerability in Dynamic Photo Gallery, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29212/\"]http://secunia.com/advisories/29212/[/url]

--

[SA29193] netOffice Dwins Authentication Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03

dB has reported a security issue in netOffice Dwins, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29193/\"]http://secunia.com/advisories/29193/[/url]

--

[SA29183] dream4 Koobi Forum Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-02-29

A vulnerability has been reported in Koobi, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29183/\"]http://secunia.com/advisories/29183/[/url]

--

[SA29174] SILC Toolkit "silc_fingerprint()" Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-05

A vulnerability has been reported in SILC (Secure Internet Live Conferencing) Toolkit, which potentially can be exploited by malicious
people to compromise an application using the toolkit.

Full Advisory:
[url=\"http://secunia.com/advisories/29174/\"]http://secunia.com/advisories/29174/[/url]

--

[SA29162] Urulu "connectionId" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-02-29

Daniel Roethlisberger has reported a vulnerability in Urulu, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29162/\"]http://secunia.com/advisories/29162/[/url]

--

[SA29255] BosDates Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06

Russ McRee has reported some vulnerabilities in BosDates, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29255/\"]http://secunia.com/advisories/29255/[/url]

--

[SA29252] Sun Java System Access Manager Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06

A vulnerability has been reported in Sun Java System Access Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29252/\"]http://secunia.com/advisories/29252/[/url]

--

[SA29241] Smarty "regex_replace" Modifier Template Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-05

A vulnerability has been reported in Smarty, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29241/\"]http://secunia.com/advisories/29241/[/url]

--

[SA29222] Xitex WebContent M1 Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-06

Russ McRee has reported a vulnerability in Xitex WebContent M1, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29222/\"]http://secunia.com/advisories/29222/[/url]

--

[SA29221] Eye-Fi Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, DoS
Released: 2008-03-04

Seth Fogie has reported some vulnerabilities in Eye-Fi, which can be exploited by malicious people to conduct spoofing and cross-site
request forgery attacks, or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29221/\"]http://secunia.com/advisories/29221/[/url]

--

[SA29220] TorrentTrader Classic "msg" Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-04

Dominus has discovered a vulnerability in TorrentTrader Classic, which can be exploited by malicious users to conduct script insertion
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29220/\"]http://secunia.com/advisories/29220/[/url]

--

[SA29215] Flyspray Cross-Site Scripting and User Enumeration

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information
Released: 2008-03-03

A vulnerability and a weakness have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks or identify valid user accounts.

Full Advisory:
[url=\"http://secunia.com/advisories/29215/\"]http://secunia.com/advisories/29215/[/url]

--

[SA29201] Crafty Syntax Live Help Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-03

Some vulnerabilities have been reported in Crafty Syntax Live Help, which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29201/\"]http://secunia.com/advisories/29201/[/url]

--

[SA29200] phpMyAdmin "$_REQUEST" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-03

A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29200/\"]http://secunia.com/advisories/29200/[/url]

--

[SA29192] h2desk Support System Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-03

joseph.giron13 has reported a security issue in h2desk Support System, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29192/\"]http://secunia.com/advisories/29192/[/url]

--

[SA29191] Ariadne PINP Annotate Command Execution Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-03-04

A vulnerability has been reported in Ariadne, which potentially can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29191/\"]http://secunia.com/advisories/29191/[/url]

--

[SA29177] XRMS CRM "msg" Cross Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-02-29

vijayv has reported a vulnerability in XRMS CRM, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29177/\"]http://secunia.com/advisories/29177/[/url]

--

[SA29250] Fujitsu Interstage Smart Repository Denial of Service Vulnerabilities

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-06

Some vulnerabilities have been reported in various Fujitsu products, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29250/\"]http://secunia.com/advisories/29250/[/url]

--

[SA29170] IBM WebSphere MQ Queue Manager Security Bypass

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-02-29

A security issue has been reported in IBM WebSphere MQ, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29170/\"]http://secunia.com/advisories/29170/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins March 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing - March 13 2008[/b][/i]

[b]Windows:--[/b]

[SA29351] Cisco User-Changeable Password Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-03-13

Some vulnerabilities have been reported in Cisco User-Changeable Password (UCP), which can be exploited by malicious people to conduct cross-site scripting attacks or potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29351/\"]http://secunia.com/advisories/29351/[/url]

--

[SA29330] Adobe Form Designer/Form Client Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-12

Some vulnerabilities have been reported in Adobe Form Designer and Form Client, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29330/\"]http://secunia.com/advisories/29330/[/url]

--

[SA29328] Microsoft Office Web Components Two Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-11

Two vulnerabilities have been reported in Microsoft Office Web Components, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29328/\"]http://secunia.com/advisories/29328/[/url]

--

[SA29321] Microsoft Office Two Code Execution Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-11

Two vulnerabilities have been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29321/\"]http://secunia.com/advisories/29321/[/url]

--

[SA29320] Microsoft Outlook "mailto:" URI Handling Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-11

A vulnerability has been reported in Microsoft Outlook, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29320/\"]http://secunia.com/advisories/29320/[/url]

--

[SA29315] RealPlayer ActiveX Control "Console" Property Memory Corruption

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-11

Elazar Broad has discovered a vulnerability in RealPlayer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29315/\"]http://secunia.com/advisories/29315/[/url]

--

[SA29326] StoreFront "CategoryId" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-13

Nick Merritt has reported a vulnerability in StoreFront, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29326/\"]http://secunia.com/advisories/29326/[/url]

--

[SA29300] MailEnable SMTP Service EXPN/VRFY Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-10

Some vulnerabilities have been reported in MailEnable, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29300/\"]http://secunia.com/advisories/29300/[/url]

--

[SA29337] McAfee ePolicy Orchestrator Framework Service Format String Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-13

Luigi Auriemma has discovered a vulnerability in McAfee ePolicy Orchestrator, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29337/\"]http://secunia.com/advisories/29337/[/url]

--

[SA29346] Internet Explorer FTP Command Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-12

Derek Abdine has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct FTP command injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29346/\"]http://secunia.com/advisories/29346/[/url]

--

[SA29331] Adobe LiveCycle Workflow Web Management Login Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-12

Dave Lewis has reported a vulnerability in Adobe LiveCycle Workflow, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29331/\"]http://secunia.com/advisories/29331/[/url]

--

[SA29308] PacketTrap pt360 TFTP Filename Handling Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-10

Luigi Auriemma has reported a vulnerability in PacketTrap pt360 TFTP server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29308/\"]http://secunia.com/advisories/29308/[/url]

--

[SA29306] Acronis True Image Echo Group Server and Windows Agent Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-03-10

Luigi Auriemma has reported some vulnerabilities in Acronis True Image Echo, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29306/\"]http://secunia.com/advisories/29306/[/url]

--

[SA29305] Acronis Snap Deploy PXE Server TFTP Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, DoS
Released: 2008-03-10

Luigi Auriemma has reported some vulnerabilities in Acronis Snap Deploy, which can be exploited by malicious people to disclose
sensitive information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29305/\"]http://secunia.com/advisories/29305/[/url]

--

[SA29302] Argon Client Management Services TFTP Server Directory Traversal

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-10

Luigi Auriemma has discovered a vulnerability in Argon Client Management Services, which can be exploited by malicious people to
disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29302/\"]http://secunia.com/advisories/29302/[/url]

--

[SA29296] RemotelyAnywhere Web Interface Multiple Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Cross Site Scripting, DoS
Released: 2008-03-10

Luigi Auriemma and Patrick have reported some vulnerabilities in RemotelyAnywhere, which can be exploited by malicious people to conduct cross-site scripting attacks or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29296/\"]http://secunia.com/advisories/29296/[/url]

--

[SA29319] Symantec Altiris Deployment Solution Server Agent Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-11

A vulnerability has been reported in Symantec Altiris Deployment Solution, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29319/\"]http://secunia.com/advisories/29319/[/url]

--

[SA29311] Panda Products cpoint.sys Privilege Escalation Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-03-10

Tobias Klein has reported some vulnerabilities in Panda products, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29311/\"]http://secunia.com/advisories/29311/[/url]


[b]UNIX/Linux:--[/b]

[SA29340] Red Hat update for java-1.4.2-bea

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-12

Red Hat has issued an update for java-1.4.2-bea. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive/system information, cause a DoS (Denial of Service), manipulate data, or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29340/\"]http://secunia.com/advisories/29340/[/url]

--

[SA29329] Mapbender SQL and PHP Code Injection

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-03-13

RedTeam Pentesting has reported some vulnerabilities in Mapbender, which can be exploited by malicious people to conduct SQL injection attacks or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29329/\"]http://secunia.com/advisories/29329/[/url]

--

[SA29314] Gentoo update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-10

Gentoo has issued an update for ghostscript-esp, ghostscript-gpl, and ghostscript-gnu. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29314/\"]http://secunia.com/advisories/29314/[/url]

--

[SA29309] Gentoo update for sarg

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-03-13

Gentoo has issued an update for sarg. This fixes some vulnerabilities, which can be exploited by malicious people to conduct script insertion attacks or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29309/\"]http://secunia.com/advisories/29309/[/url]

--

[SA29307] Gentoo update for mplayer

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-11

Gentoo has issued an update for mplayer. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29307/\"]http://secunia.com/advisories/29307/[/url]

--

[SA29375] Fedora update for roundup

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2008-03-13

Fedora has issued an update for roundup. This fixes some vulnerabilities with unknown impacts, and a security issue, which can
be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29375/\"]http://secunia.com/advisories/29375/[/url]

--

[SA29374] Fedora update for horde

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-13

Fedora has issued an update for horde. This fixes a vulnerability, which can be exploited by malicious users to to disclose sensitive
information and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29374/\"]http://secunia.com/advisories/29374/[/url]

--

[SA29371] UnixWare update for openssh

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-13

SCO has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29371/\"]http://secunia.com/advisories/29371/[/url]

--

[SA29364] rPath update for dovecot

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-13

rPath has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29364/\"]http://secunia.com/advisories/29364/[/url]

--

[SA29358] XOOPS Tutorials Module "tid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-13

S@BUN has discovered a vulnerability in the Tutorials module for XOOPS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29358/\"]http://secunia.com/advisories/29358/[/url]

--

[SA29357] Fedora update for ruby

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-13

Fedora has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information.

Full Advisory:
[url=\"http://secunia.com/advisories/29357/\"]http://secunia.com/advisories/29357/[/url]

--

[SA29336] Roundup Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2008-03-13

Multiple vulnerabilities and a security issue have been reported in Roundup, some of which have unknown impacts, while others can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29336/\"]http://secunia.com/advisories/29336/[/url]

--

[SA29333] Gentoo update for icu

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-12

Gentoo has issued an update for icu. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29333/\"]http://secunia.com/advisories/29333/[/url]

--

[SA29299] QuickTicket "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-10

croconile has discovered a vulnerability in QuickTicket, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29299/\"]http://secunia.com/advisories/29299/[/url]

--

[SA29295] Dovecot Authentication Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-10

A vulnerability has been reported in Dovecot, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29295/\"]http://secunia.com/advisories/29295/[/url]

--

[SA29291] Sun Solaris ICU Regular Expressions Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-10

Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the ICU library.

Full Advisory:
[url=\"http://secunia.com/advisories/29291/\"]http://secunia.com/advisories/29291/[/url]

--

[SA29288] QuickTalk forum "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-12

t0pP8uZz & xprog have discovered a vulnerability in QuickTalk forum, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29288/\"]http://secunia.com/advisories/29288/[/url]

--

[SA29341] HP-UX HP CIFS Server Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-12

HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29341/\"]http://secunia.com/advisories/29341/[/url]

--

[SA29285] Fedora update for vdccm

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-07

Fedora has issued an update for vdccm. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29285/\"]http://secunia.com/advisories/29285/[/url]

--

[SA29354] Debian update for libnet-dns-perl

Critical: Less critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-03-12

Debian has issued an update for libnet-dns-perl. This fixes some vulnerabilities, which can be exploited by malicious people to poison
the DNS cache or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29354/\"]http://secunia.com/advisories/29354/[/url]

--

[SA29348] Gentoo update for apache

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-03-12

Gentoo has issued an update for apache. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks and by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29348/\"]http://secunia.com/advisories/29348/[/url]

--

[SA29327] Sun Java Server Faces Input Handling Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-11

Sun has acknowledged a vulnerability in Java Server Faces, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29327/\"]http://secunia.com/advisories/29327/[/url]

--

[SA29318] rPath update for lighttpd

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-13

rPath has issued an update for lighttpd. This fixes some security issues, which can be exploited by malicious people to disclose
potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29318/\"]http://secunia.com/advisories/29318/[/url]

--

[SA29313] Red Hat update for tomcat

Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-03-11

Red Hat has issued an update for tomcat. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious users to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29313/\"]http://secunia.com/advisories/29313/[/url]

--

[SA29304] Gentoo update for pdflib

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-11

Gentoo has issued an update for pdflib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29304/\"]http://secunia.com/advisories/29304/[/url]

--

[SA29303] Ubuntu update for python

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-11

Ubuntu has issued an update for python. This fixes two security issues, which can be exploited by malicious people to disclose potentially sensitive information, to cause a DoS (Denial of Service), or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29303/\"]http://secunia.com/advisories/29303/[/url]

--

[SA29290] Sun Java Web Console Information Disclosure Security Issue

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-10

A security issue has been reported in Sun Java Web Console, which can be exploited by malicious people to disclose certain information.

Full Advisory:
[url=\"http://secunia.com/advisories/29290/\"]http://secunia.com/advisories/29290/[/url]

--

[SA29287] Gentoo update for phpmyadmin

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-10

Gentoo has issued an update for phpmyadmin. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29287/\"]http://secunia.com/advisories/29287/[/url]

--

[SA29370] UnixWare "pkgadd" Directory Traversal Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-13

A vulnerability has been reported in UnixWare, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29370/\"]http://secunia.com/advisories/29370/[/url]

--

[SA29360] IBM WebSphere MQ for HP NonStop Missing Authentication

Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-03-13

A security issue has been reported in IBM WebSphere MQ for HP NonStop, which can be exploited by malicious, local users to bypass certain security restrictions or manipulate certain data.

Full Advisory:
[url=\"http://secunia.com/advisories/29360/\"]http://secunia.com/advisories/29360/[/url]

--

[SA29350] Red Hat Directory Server Insecure Directory Permissions

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-12

A vulnerability has been reported in Red Hat Directory Server, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29350/\"]http://secunia.com/advisories/29350/[/url]

--

[SA29349] IBM AIX Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-03-12

Some vulnerabilities are reported in IBM AIX, which can be exploited by malicious, local users to cause a DoS (Denial of Service), bypass certain security restrictions, disclose sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29349/\"]http://secunia.com/advisories/29349/[/url]

--

[SA29347] IBM AIX "reboot" Buffer Overflow Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-12

A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29347/\"]http://secunia.com/advisories/29347/[/url]

--

[SA29301] AIX "man" Insecure Program Execution Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-10

A vulnerability has been reported in AIX, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29301/\"]http://secunia.com/advisories/29301/[/url]

--

[SA29368] Sun Solaris JDS XscreenSaver Authentication Bypass

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-13

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29368/\"]http://secunia.com/advisories/29368/[/url]

--

[SA29352] Sun Solaris 10 Inter-Process Communication Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-03-12

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29352/\"]http://secunia.com/advisories/29352/[/url]


[b]Other:


Cross Platform:--[/b]

[SA29316] Motorola Timbuktu Pro Denial of Service and Directory Traversal Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-11

Some vulnerabilities have been discovered in Motorola Timbuktu Pro, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29316/\"]http://secunia.com/advisories/29316/[/url]

--

[SA29312] MaxDB Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-03-11

Some vulnerabilities have been reported in MaxDB, which can be exploited by malicious, local users to gain escalated privileges, and
by malicious people to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29312/\"]http://secunia.com/advisories/29312/[/url]

--

[SA29373] EasyCalendar SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-03-13

JosS has discovered some vulnerabilities in EasyCalendar, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29373/\"]http://secunia.com/advisories/29373/[/url]

--

[SA29372] EasyGallery SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-03-13

JosS has discovered some vulnerabilities in EasyGallery, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29372/\"]http://secunia.com/advisories/29372/[/url]

--

[SA29362] eXV2 bamaGalerie "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-13

A vulnerability has been discovered in eXV2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29362/\"]http://secunia.com/advisories/29362/[/url]

--

[SA29359] eXV2 Bama Galerie Module "cid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-13

S@BUN has discovered a vulnerability in the Bama Galerie module for eXV2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29359/\"]http://secunia.com/advisories/29359/[/url]

--

[SA29339] Fully Modded phpBB "k" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-13

TurkishWarriorr has discovered a vulnerability in Fully Modded phpBB, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29339/\"]http://secunia.com/advisories/29339/[/url]

--

[SA29338] Bloo Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-12

MhZ91 has reported some vulnerabilities in Bloo, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29338/\"]http://secunia.com/advisories/29338/[/url]

--

[SA29335] IBM WebSphere Application Server Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, Exposure of sensitive information
Released: 2008-03-12

Some vulnerabilities and security issues have been reported in IBM WebSphere Application Server, some of which have unknown impacts while others can potentially be exploited by malicious, local users to gain knowledge of sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29335/\"]http://secunia.com/advisories/29335/[/url]

--

[SA29322] PHP-Nuke Hadith Module "cat" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-11

Lovebug has reported a vulnerability in the Hadith module for PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29322/\"]http://secunia.com/advisories/29322/[/url]

--

[SA29297] BM Classifieds Two SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-10

xcorpitx has reported two vulnerabilities in BM Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29297/\"]http://secunia.com/advisories/29297/[/url]

--

[SA29292] Joomla! eWriting Component "cat" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-11

breaker_unit & Don have discovered a vulnerability in the eWriting component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29292/\"]http://secunia.com/advisories/29292/[/url]

--

[SA29286] Horde "theme" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-10

A vulnerability has been reported in various Horde products, which can be exploited by malicious users to disclose sensitive information and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29286/\"]http://secunia.com/advisories/29286/[/url]

--

[SA29289] ASG-Sentry Network Manager Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-03-11

Luigi Auriemma has reported some vulnerabilities and a security issue in ASG-Sentry Network Manager, which can be exploited by malicious people to manipulate certain data, bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a
vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29289/\"]http://secunia.com/advisories/29289/[/url]

--

[SA29355] Polymita BPM-Suite / CollagePortal Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-13

Russ McRee has reported some vulnerabilities in Polymita BPM-Suite and CollagePortal, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29355/\"]http://secunia.com/advisories/29355/[/url]

--

[SA29343] Perl Net::DNS Module DNS Response Denial of Service

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-12

Beyond Security has reported a vulnerability in the Net::DNS Perl module, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29343/\"]http://secunia.com/advisories/29343/[/url]

--

[SA29332] Adobe ColdFusion Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-03-12

Some vulnerabilities and a weakness have been reported in Adobe ColdFusion, which can be exploited by malicious people to bypass
certain security restrictions and to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29332/\"]http://secunia.com/advisories/29332/[/url]

--

[SA29310] ManageEngine ServiceDesk Plus Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-11

Yogesh Kulkarni has discovered a vulnerability in ManageEngine ServiceDesk Plus, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29310/\"]http://secunia.com/advisories/29310/[/url]

--

[SA29298] Savvy Content Manager "searchterms" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-11

Russ McRee has reported a vulnerability in Savvy Content Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29298/\"]http://secunia.com/advisories/29298/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins March 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing - Week of March 20th 2008[/b][/i]

[b]Windows:--[/b]

[SA29437] BusinessObjects "RptViewerAX" ActiveX Control Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-19

Will Dormann has reported a vulnerability in BusinessObjects, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29437/\"]http://secunia.com/advisories/29437/[/url]

--

[SA29408] CA BrightStor ARCserve Backup "ListCtrl" ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-17

Krystian Kloskowski has reported a vulnerability in CA BrightStor ARCserve Backup for Laptops & Desktops, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29408/\"]http://secunia.com/advisories/29408/[/url]

--

[SA29407] WinRAR Multiple Unspecified Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-19

Some vulnerabilities have been reported in WinRAR, which can potentially be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29407/\"]http://secunia.com/advisories/29407/[/url]

--

[SA29433] KAPhotoservice "albumid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-19

JosS has reported a vulnerability in KAPhotoservice, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29433/\"]http://secunia.com/advisories/29433/[/url]

--

[SA29419] Home FTP Server Passive Mode Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-18

0in has discovered a vulnerability in Home FTP Server, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29419/\"]http://secunia.com/advisories/29419/[/url]

--

[SA29382] MDaemon IMAP Server "FETCH" Command Buffer Overflow

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-14

Matteo Memelli has discovered a vulnerability in MDaemon, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29382/\"]http://secunia.com/advisories/29382/[/url]

--

[SA29404] BootManage TFTP Server Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-17

Luigi Auriemma has discovered a vulnerability in BootManage TFTP Server, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29404/\"]http://secunia.com/advisories/29404/[/url]

[b]
UNIX/Linux:--[/b]

[SA29451] Red Hat update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Red Hat has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29451/\"]http://secunia.com/advisories/29451/[/url]

--

[SA29450] Red Hat update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Red Hat has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29450/\"]http://secunia.com/advisories/29450/[/url]

--

[SA29444] Gentoo update for moinmoin

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Released: 2008-03-19

Gentoo has issued an update for moinmoin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting attacks, bypass security restrictions, manipulate certain data, or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29444/\"]http://secunia.com/advisories/29444/[/url]

--

[SA29438] Ubuntu update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Ubuntu has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29438/\"]http://secunia.com/advisories/29438/[/url]

--

[SA29435] Debian update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Debian has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29435/\"]http://secunia.com/advisories/29435/[/url]

--

[SA29428] Kerberos Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Some vulnerabilities have been reported in Kerberos, which can be exploited by malicious people to disclose potentially sensitive
information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29428/\"]http://secunia.com/advisories/29428/[/url]

--

[SA29426] Asterisk Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-03-19

Some vulnerabilities have been reported in Asterisk, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29426/\"]http://secunia.com/advisories/29426/[/url]

--

[SA29424] SUSE update for krb5

Critical: Highly critical
Where: From remote
Impact: System access, DoS, Exposure of sensitive information
Released: 2008-03-19

SUSE has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29424/\"]http://secunia.com/advisories/29424/[/url]

--

[SA29423] Red Hat update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-19

Red Hat has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29423/\"]http://secunia.com/advisories/29423/[/url]

--

[SA29420] Mac OS X Security Update Fixes Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-03-19

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

Full Advisory:
[url=\"http://secunia.com/advisories/29420/\"]http://secunia.com/advisories/29420/[/url]

--

[SA29393] Apple Safari Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-03-19

Some vulnerabilities have been reported in Safari, which can be exploited by malicious people to bypass certain security restrictions,
conduct cross-site scripting attacks, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29393/\"]http://secunia.com/advisories/29393/[/url]

--

[SA29440] Red Hat update for unzip

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-19

Red Hat has issued an update for unzip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29440/\"]http://secunia.com/advisories/29440/[/url]

--

[SA29432] Debian update for unzip

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-18

Debian has issued an update for unzip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29432/\"]http://secunia.com/advisories/29432/[/url]

--

[SA29427] Mandriva update for unzip

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-19

Mandriva has issued an update for unzip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29427/\"]http://secunia.com/advisories/29427/[/url]

--

[SA29415] UnZip "inflate_dynamic()" Uninitialized Pointers Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-18

A vulnerability has been reported in UnZip, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29415/\"]http://secunia.com/advisories/29415/[/url]

--

[SA29400] Debian update for horde3

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information, System access
Released: 2008-03-17

Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious users to disclose sensitive
information and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29400/\"]http://secunia.com/advisories/29400/[/url]

--

[SA29396] Gentoo update for dovecot

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-18

Gentoo has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29396/\"]http://secunia.com/advisories/29396/[/url]

--

[SA29385] Debian update for dovecot

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-17

Debian has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29385/\"]http://secunia.com/advisories/29385/[/url]

--

[SA29379] Avaya CMS Solaris Firewall Security Bypass and Denial of Service

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS
Released: 2008-03-17

Avaya has acknowledged a vulnerability in Avaya CMS, which can be exploited by malicious people to bypass certain security restrictions and cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29379/\"]http://secunia.com/advisories/29379/[/url]

--

[SA29448] SUSE update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-19

SUSE has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29448/\"]http://secunia.com/advisories/29448/[/url]

--

[SA29431] CUPS CGI Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-19

A vulnerability has been reported in CUPS, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29431/\"]http://secunia.com/advisories/29431/[/url]

--

[SA29405] Debian update for smarty

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-17

Debian has issued an update for smarty. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29405/\"]http://secunia.com/advisories/29405/[/url]

--

[SA29403] Debian update for lighttpd

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-17

Debian has issued an update for lighttpd. This fixes a security issue, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29403/\"]http://secunia.com/advisories/29403/[/url]

--

[SA29388] Ubuntu update for mailman

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-17

Ubuntu has issued an update for mailman. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29388/\"]http://secunia.com/advisories/29388/[/url]

--

[SA29383] ZABBIX "vfs.file.cksum" Denial of Service Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-14

Milen Rangelov has discovered a vulnerability in ZABBIX, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29383/\"]http://secunia.com/advisories/29383/[/url]

--

[SA29387] Red Hat update for kernel

Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-14

Red Hat has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29387/\"]http://secunia.com/advisories/29387/[/url]

--

[SA29442] HP StorageWorks Library and Tape Tools (LTT) on HP-UX Security Bypass

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-19

HP has acknowledged a vulnerability in HP StorageWorks Library and Tape Tools (LTT), which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29442/\"]http://secunia.com/advisories/29442/[/url]

--

[SA29425] Gentoo update for acroread

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-19

Gentoo has issued an update for acroread. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29425/\"]http://secunia.com/advisories/29425/[/url]

--

[SA29395] Debian update for ldapscripts

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-17

Debian has issued an update for ldapscripts. This fixes a security issue, which can be exploited by malicious, local users to disclose
sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29395/\"]http://secunia.com/advisories/29395/[/url]

--

[SA29449] Asterisk Predictable HTTP Manager ID Weakness

Critical: Not critical
Where: From local network
Impact: Hijacking
Released: 2008-03-19

Dino A. Dai Zovi has reported a weakness in Asterisk, which can be exploited by malicious people to hijack a user session.

Full Advisory:
[url=\"http://secunia.com/advisories/29449/\"]http://secunia.com/advisories/29449/[/url]

--

[SA29418] Sun Solaris "rpc.metad" Denial of Service

Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-03-18

Kingcope has reported a vulnerability in Solaris, which can be
exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29418/\"]http://secunia.com/advisories/29418/[/url]


[b]Other:--[/b]

[SA29394] CheckPoint VPN-1 IP Address Collision Security Issue

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, DoS
Released: 2008-03-18

Robert Mitchell has reported a security issue in CheckPoint VPN-1, which can lead to a DoS (Denial of Service) or disclosure of sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29394/\"]http://secunia.com/advisories/29394/[/url]

--

[SA29401] RaidSonic ICY BOX NAS-4220-B Insecure Storage of Encryption Key

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-19

Collin Mulliner has reported a security issue in RaidSonic NAS-4220-B, which can be exploited by malicious people with physical access to the device to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29401/\"]http://secunia.com/advisories/29401/[/url]

[b]
Cross Platform:--[/b]

[SA29422] PHPauction GPL "include_path" File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-18

RoMaNcYxHaCkEr has discovered some vulnerabilities in PHPauction GPL, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29422/\"]http://secunia.com/advisories/29422/[/url]

--

[SA29417] fuzzylime (cms) "admindir" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-17

irk4z has discovered a vulnerability in fuzzylime (cms), which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29417/\"]http://secunia.com/advisories/29417/[/url]

--

[SA29397] F-Secure Archives Handling Unspecified Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-17

Some vulnerabilities have been reported in various F-Secure products, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29397/\"]http://secunia.com/advisories/29397/[/url]

--

[SA29430] Easy-Clanpage "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-19

n3w7u has discovered a vulnerability in Easy-Clanpage, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29430/\"]http://secunia.com/advisories/29430/[/url]

--

[SA29429] Joomla Acajoom PRO Component "mailingid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-19

fataku has reported a vulnerability in the Acajoom PRO component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29429/\"]http://secunia.com/advisories/29429/[/url]

--

[SA29421] MG-SOFT Net Inspector Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-03-17

Luigi Auriemma has discovered some vulnerabilities in MG-SOFT Net Inspector, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29421/\"]http://secunia.com/advisories/29421/[/url]

--

[SA29411] phpBP "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-17

irk4z has reported a vulnerability in phpBP, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29411/\"]http://secunia.com/advisories/29411/[/url]

--

[SA29398] Serendipity Security Bypass and Script Insertion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-03-18

Two vulnerabilities have been reported in Serendipity, which can be exploited by malicious people to conduct script insertion attacks and bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29398/\"]http://secunia.com/advisories/29398/[/url]

--

[SA29390] eXV2 WebChat Module "roomid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-17

S@BUN has discovered a vulnerability in the WebChat module for eXV2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29390/\"]http://secunia.com/advisories/29390/[/url]

--

[SA29389] eXV2 Viso Module "kid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-17

S@BUN has discovered a vulnerability in the Viso (Industry Book) module for eXV2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29389/\"]http://secunia.com/advisories/29389/[/url]

--

[SA29384] eXV2 myannonces Module "lid" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-17

S@BUN has discovered a vulnerability in the myannonces module for eXV2, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29384/\"]http://secunia.com/advisories/29384/[/url]

--

[SA29441] ManageEngine SupportCenter Plus "searchText" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-19

Yogesh Kulkarni has reported a vulnerability in ManageEngine SupportCenter Plus, which can be exploited by malicious people to
conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29441/\"]http://secunia.com/advisories/29441/[/url]

--

[SA29416] Multiple Time Sheets "tab" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-17

JosS has discovered a vulnerability in Multiple Time Sheets (MTS), which can be exploited by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29416/\"]http://secunia.com/advisories/29416/[/url]

--

[SA29413] VMware Products Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Privilege escalation, DoS
Released: 2008-03-17

Some vulnerabilities have been reported in VMware products, which can be exploited by malicious, local users to gain escalated privileges or to cause a DoS (Denial of Service), and potentially by malicious people to bypass certain security restrictions or to cause a DoS.

Full Advisory:
[url=\"http://secunia.com/advisories/29413/\"]http://secunia.com/advisories/29413/[/url]

--

[SA29412] VMware Server Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, Privilege escalation, DoS
Released: 2008-03-17

Some vulnerabilities have been reported in VMware Server, which can be exploited by malicious, local users to gain escalated privileges or to cause a DoS (Denial of Service), and potentially by malicious people to bypass certain security restrictions or to cause a DoS.

Full Advisory:
[url=\"http://secunia.com/advisories/29412/\"]http://secunia.com/advisories/29412/[/url]

--

[SA29409] Novell GroupWise Windows Client API Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-03-17

A vulnerability has been reported in Novell GroupWise, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29409/\"]http://secunia.com/advisories/29409/[/url]

--

[SA29380] eForum "busca.php" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-18

Omni has discovered two vulnerabilities in eForum, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29380/\"]http://secunia.com/advisories/29380/[/url]

--

[SA29378] Invision Power Board Nested BBCodes Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-14

A vulnerability has been reported in Invision Power Board, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29378/\"]http://secunia.com/advisories/29378/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins March 2008

Post by Tami »

[i][b][url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of March 27th[/b][/i]

[b]Windows:--[/b]

[SA29483] Safari Address Bar Spoofing and Memory Corruption Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Spoofing, System access
Released: 2008-03-24

Juan Pablo Lopez Yacubian has discovered two vulnerabilities in Safari, which can be exploited by malicious people to conduct spoofing attacks or potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29483/\"]http://secunia.com/advisories/29483/[/url]

--

[SA29540] File Transfer Request File Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

teeed has reported a vulnerability in File Transfer, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29540/\"]http://secunia.com/advisories/29540/[/url]

--

[SA29533] Aeries Browser Interface Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-03-26

Arsalan Emamjomehkashan has reported some vulnerabilities in Aeries Browser Interface, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29533/\"]http://secunia.com/advisories/29533/[/url]

--

[SA29499] Efestech E-Kontör "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-25

RMx has reported a vulnerability in Efestech E-Kontör, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29499/\"]http://secunia.com/advisories/29499/[/url]

--

[SA29488] DotNetNuke Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, System access
Released: 2008-03-25

Some vulnerabilities and a security issue have been reported in DotNetNuke, which can be exploited by malicious users to gain escalated privileges or to compromise a vulnerable system, and by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29488/\"]http://secunia.com/advisories/29488/[/url]

--

[SA29455] Adobe Flash FLA File Parsing Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-20

cocoruder has reported some vulnerabilities in Adobe Flash, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29455/\"]http://secunia.com/advisories/29455/[/url]

--

[SA29508] TFTP Server SP Long Filename Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-27

Mati Aharoni has discovered a vulnerability in TFTP Server SP, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29508/\"]http://secunia.com/advisories/29508/[/url]

--

[SA29494] Quick Tftp Server Pro Long Mode Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-27

Mati Aharoni has discovered a vulnerability in Quick Tftp Server Pro, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29494/\"]http://secunia.com/advisories/29494/[/url]

--

[SA29538] LEADTOOLS Multimedia Library ActiveX Controls "SaveSettingsToFile()" Insecure Method

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-26

shinnai has discovered some vulnerabilities in LEADTOOLS Multimedia, which can be exploited by malicious people to overwrite arbitrary files.

Full Advisory:
[url=\"http://secunia.com/advisories/29538/\"]http://secunia.com/advisories/29538/[/url]

--

[SA29524] ManageEngine EventLog Analyzer "searchText" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-25

Yogesh Kulkarni has reported a vulnerability in ManageEngine EventLog Analyzer, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29524/\"]http://secunia.com/advisories/29524/[/url]

--

[SA29467] IBM Rational ClearQuest Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-20

sasquatch has reported some vulnerabilities in IBM Rational ClearQuest, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29467/\"]http://secunia.com/advisories/29467/[/url]

--

[SA29453] Internet Explorer HTTP Request Smuggling/Splitting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-03-24

Stefano Di Paola has reported some vulnerabilities in Internet Explorer, which can be exploited by malicious people to conduct HTTP request smuggling/splitting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29453/\"]http://secunia.com/advisories/29453/[/url]

--

[SA29458] Windows Vista "NoDriveTypeAutoRun" Security Issue

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-21

CERT/CC has reported a security issue in Windows Vista, which can be exploited by malicious people to bypass certain security settings.

Full Advisory:
[url=\"http://secunia.com/advisories/29458/\"]http://secunia.com/advisories/29458/[/url]


[b]UNIX/Linux:--[/b]

[SA29563] Fedora update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, System access
Released: 2008-03-27

Fedora has issued an update for firefox. This fixes some vulnerabilities and a weakness, which can be exploited by malicious
people to conduct cross-site scripting and phishing attacks, bypass certain security restrictions, and potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29563/\"]http://secunia.com/advisories/29563/[/url]

--

[SA29550] Red Hat update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-03-27

Red Hat has issued an update for firefox. This fixes some vulnerabilities and a weakness, which can be exploited to conduct
cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29550/\"]http://secunia.com/advisories/29550/[/url]

--

[SA29541] Ubuntu update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-27

Ubuntu has issued an update for firefox. This fixes some vulnerabilities and weaknesses, which can be exploited by malicious
people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing
attacks, and potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29541/\"]http://secunia.com/advisories/29541/[/url]

--

[SA29516] Gentoo update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-25

Gentoo has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29516/\"]http://secunia.com/advisories/29516/[/url]

--

[SA29515] MPlayer "sdpplin_parse()" Integer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-26

k`sOSe has discovered a vulnerability in MPlayer, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29515/\"]http://secunia.com/advisories/29515/[/url]

--

[SA29489] CenterIM URL Parsing Command Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-21

Brian Fonfara has discovered a vulnerability in CenterIM, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29489/\"]http://secunia.com/advisories/29489/[/url]

--

[SA29484] xine-lib Multiple Integer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-21

Luigi Auriemma has reported some vulnerabilities in xine-lib, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29484/\"]http://secunia.com/advisories/29484/[/url]

--

[SA29472] Fedora update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-24

Fedora has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29472/\"]http://secunia.com/advisories/29472/[/url]

--

[SA29470] Fedora update for asterisk

Critical: Highly critical
Where: From remote
Impact: Hijacking, Security Bypass, DoS, System access
Released: 2008-03-24

Fedora has issued an update for asterisk. This fixes a weakness and some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), hijack a user session, and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29470/\"]http://secunia.com/advisories/29470/[/url]

--

[SA29469] Apple Aperture/iPhoto DNG Image Parsing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-21

A vulnerability has been reported in Aperture and iPhoto, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29469/\"]http://secunia.com/advisories/29469/[/url]

--

[SA29464] Fedora update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-24

Fedora has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29464/\"]http://secunia.com/advisories/29464/[/url]

--

[SA29462] Mandriva update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-20

Mandriva has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29462/\"]http://secunia.com/advisories/29462/[/url]

--

[SA29457] rPath update for krb5

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-03-20

rPath has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29457/\"]http://secunia.com/advisories/29457/[/url]

--

[SA29557] Ubuntu update for dovecot

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-27

Ubuntu has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29557/\"]http://secunia.com/advisories/29557/[/url]

--

[SA29552] HP Tru64 UNIX SSH SFTP Server Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-27

HP has acknowledged a vulnerability in HP Tru64 UNIX, which potentially can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29552/\"]http://secunia.com/advisories/29552/[/url]

--

[SA29546] Mandriva update for perl-Tk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-27

Mandriva has issued an update for perl-Tk. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29546/\"]http://secunia.com/advisories/29546/[/url]

--

[SA29542] Ubuntu update for sdl-image

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-27

Ubuntu has issued an update for sdl-image. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29542/\"]http://secunia.com/advisories/29542/[/url]

--

[SA29511] Gentoo update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-25

Gentoo has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29511/\"]http://secunia.com/advisories/29511/[/url]

--

[SA29502] Debian update for serendipity

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-03-25

Debian has issued an update for serendipity. This fixes some vulnerabilities, which can be exploited by malicious people to conduct
cross-site scripting and script-insertion attacks or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29502/\"]http://secunia.com/advisories/29502/[/url]

--

[SA29497] rPath update for bzip2

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-03-24

rPath has issued an update for bzip2. This fixes a vulnerability with unknown impact.

Full Advisory:
[url=\"http://secunia.com/advisories/29497/\"]http://secunia.com/advisories/29497/[/url]

--

[SA29495] rPath update for unzip

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-03-24

rPath has issued an update for unzip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29495/\"]http://secunia.com/advisories/29495/[/url]

--

[SA29492] Apache::AuthCAS Session ID SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-25

Matthias Bethke has reported a vulnerability in Apache::AuthCAS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29492/\"]http://secunia.com/advisories/29492/[/url]

--

[SA29486] Undernet ircu "send_user_mode" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-24

Chris Porter has reported a vulnerability in Undernet ircu, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29486/\"]http://secunia.com/advisories/29486/[/url]

--

[SA29481] snircd "send_user_mode" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-24

Chris Porter has reported a vulnerability in snircd, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29481/\"]http://secunia.com/advisories/29481/[/url]

--

[SA29485] Debian update for cupsys

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-26

Debian has issued an update for cupsys. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29485/\"]http://secunia.com/advisories/29485/[/url]

--

[SA29454] Sun Solaris rpc.ypupdated Arbitrary Command Execution

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-03-21

kcope has discovered a vulnerability in Solaris, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29454/\"]http://secunia.com/advisories/29454/[/url]

--

[SA29562] Fedora update for php-pear-PhpDocumentor

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-27

Fedora has issued an update for php-pear-PhpDocumentor. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29562/\"]http://secunia.com/advisories/29562/[/url]

--

[SA29561] Fedora update for namazu

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-27

Fedora has issued an update for namazu. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29561/\"]http://secunia.com/advisories/29561/[/url]

--

[SA29556] Ubuntu update for ruby

Critical: Less critical
Where: From remote
Impact: Spoofing
Released: 2008-03-27

Ubuntu has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29556/\"]http://secunia.com/advisories/29556/[/url]

--

[SA29555] Ubuntu update for libnet-dns-perl

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-27

Ubuntu has issued an update for libnet-dns-perl. This fixes a vulnerability, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29555/\"]http://secunia.com/advisories/29555/[/url]

--

[SA29536] rPath update for ruby

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

rPath has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to disclose sensitive
information.

Full Advisory:
[url=\"http://secunia.com/advisories/29536/\"]http://secunia.com/advisories/29536/[/url]

--

[SA29534] ClanSphere Unspecified Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-27

Some vulnerabilities have been reported in ClanSphere, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29534/\"]http://secunia.com/advisories/29534/[/url]

--

[SA29529] Sun SPARC Enterprise T5120 and T5220 Servers Insecure Configuration

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-03-26

A security issue has been reported in some Sun SPARC Enterprise T5120 and T5220 Servers, which can be exploited by malicious users to bypass certain security restrictions

Full Advisory:
[url=\"http://secunia.com/advisories/29529/\"]http://secunia.com/advisories/29529/[/url]

--

[SA29506] Ubuntu update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-25

Ubuntu has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29506/\"]http://secunia.com/advisories/29506/[/url]

--

[SA29504] IBM WebSphere Application Server for z/OS HTTP Server mod_status Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-25

IBM has acknowledged a vulnerability in IBM WebSphere Application Server for z/OS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29504/\"]http://secunia.com/advisories/29504/[/url]

--

[SA29475] Mandriva update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-25

Mandriva has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29475/\"]http://secunia.com/advisories/29475/[/url]

--

[SA29465] Fedora update for libsilc

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-26

Fedora has issue an update for libsilc. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29465/\"]http://secunia.com/advisories/29465/[/url]

--

[SA29461] Gentoo update for openldap

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-03-20

Gentoo has issued an update for openldap. This fixes some vulnerabilities, which can be exploited by malicious users to cause a
DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29461/\"]http://secunia.com/advisories/29461/[/url]

--

[SA29460] Gentoo update for viewvc

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-20

Gentoo has issued an update for viewvc. This fixes some security issues, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29460/\"]http://secunia.com/advisories/29460/[/url]

--

[SA29456] Debian update for asterisk

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-21

Debian has issued an update for asterisk. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29456/\"]http://secunia.com/advisories/29456/[/url]

--

[SA29554] Mandriva update for openssh

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-27

Mandriva has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29554/\"]http://secunia.com/advisories/29554/[/url]

--

[SA29537] rPath update for gnome-ssh-askpass and openssh

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-26

rPath has issued an update for gnome-ssh-askpass and openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29537/\"]http://secunia.com/advisories/29537/[/url]

--

[SA29522] OpenSSH X11 Forwarding Information Disclosure Vulnerability

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-26

A vulnerability has been discovered in OpenSSH, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29522/\"]http://secunia.com/advisories/29522/[/url]

--

[SA29518] IBM AIX "usr/sbin/chnfsmnt" Vulnerability

Critical: Less critical
Where: Local system
Impact: Unknown
Released: 2008-03-25

A vulnerability with an unknown impact has been reported in IBM AIX.

Full Advisory:
[url=\"http://secunia.com/advisories/29518/\"]http://secunia.com/advisories/29518/[/url]

--

[SA29482] Red Hat Directory Server Insecure File Permissions

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-25

A vulnerability has been reported in Red Hat Directory Server, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29482/\"]http://secunia.com/advisories/29482/[/url]


[b]Other:--[/b]

[SA29559] Cisco IOS Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-27

A vulnerability has been reported in certain Cisco devices, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29559/\"]http://secunia.com/advisories/29559/[/url]

--

[SA29507] Cisco IOS Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, DoS
Released: 2008-03-27

Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29507/\"]http://secunia.com/advisories/29507/[/url]

--

[SA29531] D-Link DI-604 "rf" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-25

Jonas has reported a vulnerability in D-Link DI-604, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29531/\"]http://secunia.com/advisories/29531/[/url]

--

[SA29530] D-Link DSL-G604T "var:category" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-25

Gareth Heyes has reported a vulnerability in D-Link DSL-G604T, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29530/\"]http://secunia.com/advisories/29530/[/url]


[b]Cross Platform:--[/b]

[SA29548] Mozilla Thunderbird Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, System access
Released: 2008-03-26

Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, or potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29548/\"]http://secunia.com/advisories/29548/[/url]

--

[SA29547] Mozilla SeaMonkey Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-26

Some vulnerabilities and weaknesses have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29547/\"]http://secunia.com/advisories/29547/[/url]

--

[SA29526] Mozilla Firefox Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-26

Some vulnerabilities and weaknesses have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29526/\"]http://secunia.com/advisories/29526/[/url]

--

[SA29520] Joomla Custompages Component "cpage" File Inclusion

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-25

Sniper456 has discovered a vulnerability in the Custompages component for Joomla!, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29520/\"]http://secunia.com/advisories/29520/[/url]

--

[SA29503] VLC Media Player "MP4_ReadBox_rdrf()" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-25

A vulnerability has been reported in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29503/\"]http://secunia.com/advisories/29503/[/url]

--

[SA29463] SILC "silc_pkcs1_decode" Integer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-26

A vulnerability has been reported in SILC Client, Server, and Toolkit, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29463/\"]http://secunia.com/advisories/29463/[/url]

--

[SA29535] BolinOS Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

Digital Security Research Group have discovered some vulnerabilities in BolinOS, which can be exploited by malicious people to conduct cross-site scripting attacks and to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29535/\"]http://secunia.com/advisories/29535/[/url]

--

[SA29514] phpAddressBook Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive
information
Released: 2008-03-25

Some vulnerabilities have been discovered in phpAddressBook, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks and to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29514/\"]http://secunia.com/advisories/29514/[/url]

--

[SA29513] RunCMS Photo Module "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-03-26

S@BUN has reported a vulnerability in the RunCMS Photo module, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29513/\"]http://secunia.com/advisories/29513/[/url]

--

[SA29510] Joomla rekry!Joom Component "op_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-25

Sniper456 has discovered a vulnerability in the rekry!Joom component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29510/\"]http://secunia.com/advisories/29510/[/url]

--

[SA29509] PECL Alternative PHP Cache "apc_search_paths" Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-03-26

Daniel Papasian has reported a vulnerability in the PECL Alternative PHP Cache (APC) extension, which can be exploited by malicious users to bypass certain security restrictions and potentially by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29509/\"]http://secunia.com/advisories/29509/[/url]

--

[SA29496] Elastic Path Multiple Directory Traversal Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-03-27

Daniel Martin Gomez has reported some vulnerabilities in Elastic Path, which can be exploited by malicious users to disclose sensitive information or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29496/\"]http://secunia.com/advisories/29496/[/url]

--

[SA29493] e107 my_gallery Plugin "file" Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

Jerome Athias has discovered a vulnerability in the my_gallery plugin for e107, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29493/\"]http://secunia.com/advisories/29493/[/url]

--

[SA29487] phpBB eXtreme Styles Module "phpEx" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-25

bd0rk has discovered a vulnerability in the eXtreme Styles module (XS-Mod) for phpBB, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29487/\"]http://secunia.com/advisories/29487/[/url]

--

[SA29480] PowerBook "page" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

Digital Security Research Group has discovered a vulnerability in PowerBook, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29480/\"]http://secunia.com/advisories/29480/[/url]

--

[SA29479] XLPortal "query" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-26

c0ndemned has reported a vulnerability in XLPortal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29479/\"]http://secunia.com/advisories/29479/[/url]

--

[SA29478] HIS-Webshop "t" Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-26

Zero X has reported a vulnerability in HIS-Webshop, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29478/\"]http://secunia.com/advisories/29478/[/url]

--

[SA29474] Joomla Joovideo Component "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-20

S@BUN has discovered a vulnerability in the Joovideo component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29474/\"]http://secunia.com/advisories/29474/[/url]

--

[SA29473] Joomla Alberghi Component "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-20

S@BUN has discovered a vulnerability in the Alberghi component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29473/\"]http://secunia.com/advisories/29473/[/url]

--

[SA29471] Joomla Restaurante Component "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-20

S@BUN has discovered a vulnerability in the Restaurante component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29471/\"]http://secunia.com/advisories/29471/[/url]

--

[SA29466] PEEL Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-03-21

Charles "real" F. has reported some vulnerabilities in PEEL, which can be exploited by malicious people to conduct SQL injection attacks and by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29466/\"]http://secunia.com/advisories/29466/[/url]

--

[SA29459] SILC Server "NEW_CLIENT" Packet Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-26

A vulnerability has been reported in SILC Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29459/\"]http://secunia.com/advisories/29459/[/url]

--

[SA29512] IBM solidDB Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-27

Luigi Auriemma has discovered some vulnerabilities in IBM solidDB, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29512/\"]http://secunia.com/advisories/29512/[/url]

--

[SA29476] Novell eDirectory LDAP delRequest Message Processing Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-03-25

A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29476/\"]http://secunia.com/advisories/29476/[/url]

--

[SA29532] CubeCart Two Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-26

Russ McRee has discovered two vulnerabilities in CubeCart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29532/\"]http://secunia.com/advisories/29532/[/url]

--

[SA29528] GNB DesignForm Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-27

A vulnerability has been reported in GNB DesignForm, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29528/\"]http://secunia.com/advisories/29528/[/url]

--

[SA29525] LinPHA Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-26

Some vulnerabilities have been reported in LinPHA, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29525/\"]http://secunia.com/advisories/29525/[/url]

--

[SA29517] PerlMailer Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-27

A vulnerability has been reported in PerlMailer, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29517/\"]http://secunia.com/advisories/29517/[/url]

--

[SA29491] eGroupWare HTML Filter Bypass Vulnerability

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-03-24

A vulnerability has been reported in eGroupWare, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29491/\"]http://secunia.com/advisories/29491/[/url]

--

[SA29490] Photo Cart "amessage" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-25

Russ McRee has reported a vulnerability in Photo Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29490/\"]http://secunia.com/advisories/29490/[/url]

--

[SA29468] CS-Cart "q" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-20

sasquatch has discovered a vulnerability in CS-Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29468/\"]http://secunia.com/advisories/29468/[/url]

--

[SA29527] Novell eDirectory eMBox Utility Unspecified Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-03-25

A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to disclose potentially sensitive
information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29527/\"]http://secunia.com/advisories/29527/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”