Secunia Bulletins April 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins April 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of April 3 2008[/b][/i]

[b]Windows:--[/b]

[SA29620] XnView Slideshow "FontName" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31

Secunia Research has discovered a vulnerability in XnView, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29620/\"]http://secunia.com/advisories/29620/[/url]

--

[SA29629] NoticeWare Email Server IMAP Packet Handling Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02

Ray has discovered a vulnerability in NoticeWare Email Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29629/\"]http://secunia.com/advisories/29629/[/url]

--

[SA29614] SLMail Pro Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-31

Luigi Auriemma has discovered some vulnerabilities in SLMail Pro, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29614/\"]http://secunia.com/advisories/29614/[/url]

--

[SA29611] EfesTECH Video "catID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01

RMx has discovered a vulnerability in EfesTECH Video, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29611/\"]http://secunia.com/advisories/29611/[/url]

--

[SA29641] HP OpenView Network Node Manager Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-03

Mati Aharoni has discovered a vulnerability in HP OpenView Network Node Manager, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29641/\"]http://secunia.com/advisories/29641/[/url]

--

[SA29660] Symantec Products AutoFix Support Tool ActiveX Control Two Vulnerabilities

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-04-03

Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29660/\"]http://secunia.com/advisories/29660/[/url]

--

[SA29581] Chilkat HTTP ActiveX Component ActiveX Controls "SaveLastError()" Insecure Method

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01

shinnai has discovered a vulnerability in Chilkat HTTP ActiveX Component, which can be exploited by malicious people to overwrite
arbitrary files.

Full Advisory:
[url=\"http://secunia.com/advisories/29581/\"]http://secunia.com/advisories/29581/[/url]

--

[SA29572] DigiDomain Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-28

Linux_Drox has reported some vulnerabilities in DigiDomain, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29572/\"]http://secunia.com/advisories/29572/[/url]

--

[SA29639] Novell eDirectory Host Environment HTTP Request Processing Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-03

Mati Aharoni has discovered a vulnerability in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29639/\"]http://secunia.com/advisories/29639/[/url]

--

[SA29590] 2X ThinClientServer 2XTFTPd Service Directory Traversal

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-31

Luigi Auriemma has discovered a vulnerability in 2X ThinClientServer, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29590/\"]http://secunia.com/advisories/29590/[/url]

--

[SA29605] avast! Home/Professional aavmker4.sys Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31

Tobias Klein has reported a vulnerability in avast! Home/Professional, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29605/\"]http://secunia.com/advisories/29605/[/url]


[b]UNIX/Linux:--[/b]

[SA29621] Comix Arbitrary Shell Command Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01

A vulnerability has been reported in Comix, which can be exploited by malicious people to compromise a user's sytem.

Full Advisory:
[url=\"http://secunia.com/advisories/29621/\"]http://secunia.com/advisories/29621/[/url]

--

[SA29618] Fedora update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-04-02

Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29618/\"]http://secunia.com/advisories/29618/[/url]

--

[SA29616] Debian update for iceweasel

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure
of sensitive information, System access
Released: 2008-03-31

Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29616/\"]http://secunia.com/advisories/29616/[/url]

--

[SA29601] Debian update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01

Debian has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29601/\"]http://secunia.com/advisories/29601/[/url]

--

[SA29600] Slackware update for xine-lib

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-02

Slackware has issued an update for xine-lib. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29600/\"]http://secunia.com/advisories/29600/[/url]

--

[SA29597] Fedora update for centerim

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-02

Fedora has issued an update for centerim. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29597/\"]http://secunia.com/advisories/29597/[/url]

--

[SA29596] Slackware update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-31

Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29596/\"]http://secunia.com/advisories/29596/[/url]

--

[SA29594] Slackware update for mozilla-firefox

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Exposure of sensitive information, System access, Security Bypass
Released: 2008-03-31

Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29594/\"]http://secunia.com/advisories/29594/[/url]

--

[SA29582] SUSE update for Sun Java

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-04-03

SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29582/\"]http://secunia.com/advisories/29582/[/url]

--

[SA29578] Slackware update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31

Slackware has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29578/\"]http://secunia.com/advisories/29578/[/url]

--

[SA29649] rPath update for lighttpd

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02

rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29649/\"]http://secunia.com/advisories/29649/[/url]

--

[SA29619] Fedora update for Perlbal

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31

Fedora has issued an update for Perlbal. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29619/\"]http://secunia.com/advisories/29619/[/url]

--

[SA29591] VMware ESX Server update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31

VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29591/\"]http://secunia.com/advisories/29591/[/url]

--

[SA29580] Debian update for exiftags

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28

Debian has issued an update for exiftags. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29580/\"]http://secunia.com/advisories/29580/[/url]

--

[SA29655] Mandriva update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03

Mandriva has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29655/\"]http://secunia.com/advisories/29655/[/url]

--

[SA29634] Gentoo update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02

Gentoo has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29634/\"]http://secunia.com/advisories/29634/[/url]

--

[SA29630] Red Hat update for cups

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-02

Red Hat has issued an update for cups. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29630/\"]http://secunia.com/advisories/29630/[/url]

--

[SA29603] Ubuntu update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03

Ubuntu has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29603/\"]http://secunia.com/advisories/29603/[/url]

--

[SA29573] Red Hat update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02

Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29573/\"]http://secunia.com/advisories/29573/[/url]

--

[SA29656] Gentoo update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-03

Gentoo has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29656/\"]http://secunia.com/advisories/29656/[/url]

--

[SA29644] Apache-SSL Environment Variables Manipulation Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-03

Alexander Klink has reported a vulnerability in Apache-SSL, which can be exploited by malicious people to manipulate certain data or to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29644/\"]http://secunia.com/advisories/29644/[/url]

--

[SA29574] FreeBSD "strfmon()" Multiple Integer Overflows

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28

Maksymilian Arciemowicz has reported some vulnerabilities in FreeBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29574/\"]http://secunia.com/advisories/29574/[/url]

--

[SA29638] HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-04-02

HP has acknowledged some vulnerabilities in PostgreSQL, which can be exploited by malicious users to to gain escalated privileges or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29638/\"]http://secunia.com/advisories/29638/[/url]

--

[SA29570] SUSE update for kernel

Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-28

SUSE has issued an update for the kernel. This fixes some vulnerabilities and a security issue, which can be exploited by
malicious, local users to bypass certain security restrictions and disclose potentially sensitive information, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29570/\"]http://secunia.com/advisories/29570/[/url]

--

[SA29648] Fedora update for mod_suphp

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02

Fedora has issued an update for mod_suphp. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29648/\"]http://secunia.com/advisories/29648/[/url]

--

[SA29642] Red Hat lspp-eal4-config-ibm / capp-lspp-eal4-config-hp Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02

Red Hat has acknowledged a security issue in the lspp-eal4-config-ibm and capp-lspp-eal4-config-hp packages, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29642/\"]http://secunia.com/advisories/29642/[/url]

--

[SA29627] OpenBSD update for OpenSSH

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03

OpenBSD has issued an update for OpenSSH. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29627/\"]http://secunia.com/advisories/29627/[/url]

--

[SA29626] Ubuntu update for openssh

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02

Ubuntu has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29626/\"]http://secunia.com/advisories/29626/[/url]

--

[SA29617] Linux Audit "audit_log_user_command()" Buffer Overflow

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31

A vulnerability has been reported in Linux Audit, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29617/\"]http://secunia.com/advisories/29617/[/url]

--

[SA29615] suPHP Race Condition Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02

Some vulnerabilities have been reported in suPHP, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29615/\"]http://secunia.com/advisories/29615/[/url]

--

[SA29588] Fedora update for phpMyAdmin

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02

Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can potentially be exploited by malicious users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29588/\"]http://secunia.com/advisories/29588/[/url]

--

[SA29577] Eterm X11 Display Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31

A security issue has been reported in Eterm, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29577/\"]http://secunia.com/advisories/29577/[/url]

--

[SA29576] rxvt X11 Display Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31

Bernhard R. Link has reported a security issue in rxvt, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29576/\"]http://secunia.com/advisories/29576/[/url]

--

[SA29666] Fedora update for gnome-screensaver

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03

Fedora has issued an update for gnome-screensaver. This fixes a weakness, which can be exploited by malicious people with physical access to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29666/\"]http://secunia.com/advisories/29666/[/url]

--

[SA29654] Solaris inetd Debug Logging Symlink Security Issue

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-03

Sun has acknowledged a security issue in Solaris, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29654/\"]http://secunia.com/advisories/29654/[/url]

--

[SA29609] OpenBSD OpenSSH ForceCommand Bypass Weakness

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31

A weakness has been reported in OpenBSD, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29609/\"]http://secunia.com/advisories/29609/[/url]

--

[SA29606] Red Hat update for gnome-screensaver

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-04-03

Red Hat has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with
physical access to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29606/\"]http://secunia.com/advisories/29606/[/url]

--

[SA29602] OpenSSH ForceCommand Bypass Weakness

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31

A weakness has been reported in OpenSSH, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29602/\"]http://secunia.com/advisories/29602/[/url]

--

[SA29595] gnome-screensaver Information Disclosure and Security Bypass

Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-03

A weakness and a security issue have been reported in gnome-screensaver, which can be exploited by malicious people with
physical access to disclose potentially sensitive information or bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29595/\"]http://secunia.com/advisories/29595/[/url]


[b]Other:--[/b]

[SA29587] Novell NetWare iPrint Request Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-02

A vulnerability has been reported in Novell NetWare, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29587/\"]http://secunia.com/advisories/29587/[/url]


[b]Cross Platform:--[/b]

[SA29662] Opera Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-03

Some vulnerabilities have been reported in Opera, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29662/\"]http://secunia.com/advisories/29662/[/url]

--

[SA29650] Apple QuickTime Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-03

Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to disclose potentially sensitive information or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29650/\"]http://secunia.com/advisories/29650/[/url]

--

[SA29653] DaZPHPNews "prefixdir" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-03

w0cker has discovered a vulnerability in DaZPHPNews, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29653/\"]http://secunia.com/advisories/29653/[/url]

--

[SA29652] Writer's Block CMS "PostID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-03

katharsis has discovered a vulnerability in Writer's Block CMS, which can be exploited by malicious people to conduct SQL injection attacks

Full Advisory:
[url=\"http://secunia.com/advisories/29652/\"]http://secunia.com/advisories/29652/[/url]

--

[SA29647] IBM DB2 Content Manager AllowedTrustedLogin Security Issue

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-04-02

A security issue with an unknown impact has been reported in IBM DB2 Content Manager.

Full Advisory:
[url=\"http://secunia.com/advisories/29647/\"]http://secunia.com/advisories/29647/[/url]

--

[SA29628] Faphoto "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-02

IRCRASH has discovered a vulnerability in Faphoto, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29628/\"]http://secunia.com/advisories/29628/[/url]

--

[SA29624] EasyNews Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-02

Dr.Crash has discovered some vulnerabilities in EasyNews, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29624/\"]http://secunia.com/advisories/29624/[/url]

--

[SA29612] CuteFlow Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-03-31

Some vulnerabilities have been discovered in CuteFlow, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29612/\"]http://secunia.com/advisories/29612/[/url]

--

[SA29608] WordPress WP-Download Plugin "dl_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-01

BL4CK has reported a vulnerability in the WP-Download plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29608/\"]http://secunia.com/advisories/29608/[/url]

--

[SA29593] AuraCMS "country" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-02

NTOS-Team have discovered a vulnerability in AuraCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29593/\"]http://secunia.com/advisories/29593/[/url]

--

[SA29592] Sava's GuestBook "action" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-01

Dr. Crash has discovered a vulnerability in Sava's GuestBook, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29592/\"]http://secunia.com/advisories/29592/[/url]

--

[SA29589] Sava's Link Manager Two Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-01

Dr. Crash has discovered two vulnerabilities in Sava's Link Manager, which can be exploited by malicious people to disclose sensitive information and to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29589/\"]http://secunia.com/advisories/29589/[/url]

--

[SA29584] PowerDNS Recursor DNS Cache Poisoning Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-03-31

Amit Klein has reported a vulnerability in PowerDNS Recursor, which can be exploited by malicious people to poison the DNS cache.

Full Advisory:
[url=\"http://secunia.com/advisories/29584/\"]http://secunia.com/advisories/29584/[/url]

--

[SA29583] eggBlog "index.php" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-28

__GiReX__ has reported two vulnerabilities in eggBlog, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29583/\"]http://secunia.com/advisories/29583/[/url]

--

[SA29579] PHPkrm Unspecified Script Insertion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31

A vulnerability has been reported in PHPkrm, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29579/\"]http://secunia.com/advisories/29579/[/url]

--

[SA29575] Sympa Malformed "Content-Type" Header Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-01

A vulnerability has been reported in Sympa, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29575/\"]http://secunia.com/advisories/29575/[/url]

--

[SA29571] Smoothflash "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-31

S@BUN has reported a vulnerability in Smoothflash, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29571/\"]http://secunia.com/advisories/29571/[/url]

--

[SA29569] Wireshark Multiple Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-28

Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29569/\"]http://secunia.com/advisories/29569/[/url]

--

[SA29658] Drupal Flickr Module Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03

Some vulnerabilities have been reported in the Flickr module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29658/\"]http://secunia.com/advisories/29658/[/url]

--

[SA29646] Simple Gallery "album" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03

Russ McRee has discovered a vulnerability in Simple Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29646/\"]http://secunia.com/advisories/29646/[/url]

--

[SA29643] HP Select Identity Unspecified Unauthorised Access Vulnerability

Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure
of sensitive information
Released: 2008-04-02

A vulnerability has been reported in HP Select Identity, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29643/\"]http://secunia.com/advisories/29643/[/url]

--

[SA29633] Drupal Webform Module Unspecified Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03

Some vulnerabilities have been reported in the Webform module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29633/\"]http://secunia.com/advisories/29633/[/url]

--

[SA29623] Smart Classified / Photo ADS Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03

Russ McRee has reported some vulnerabilities in Smart Classified ADS and Smart Photo ADS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29623/\"]http://secunia.com/advisories/29623/[/url]

--

[SA29610] InspIRCd Unspecified Vulnerability

Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2008-03-31

A vulnerability with unknown impact has been reported in InspIRCd.

Full Advisory:
[url=\"http://secunia.com/advisories/29610/\"]http://secunia.com/advisories/29610/[/url]

--

[SA29599] JV2 Folder Gallery "image" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31

Russ McRee has discovered a vulnerability in JV2 Folder Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29599/\"]http://secunia.com/advisories/29599/[/url]

--

[SA29598] JV2 Quick Gallery "f" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31

Russ McRee has discovered a vulnerability in JV2 Quick Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29598/\"]http://secunia.com/advisories/29598/[/url]

--

[SA29613] phpMyAdmin Username/Password Session File Information Disclosure

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-31

Jim Hermann has discovered a vulnerability in phpMyAdmin, which can potentially be exploited by malicious users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29613/\"]http://secunia.com/advisories/29613/[/url]

--

[SA29586] Nik Sharpener Pro Insecure File Permissions

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31

A security issue has been discovered in Nik Sharpener Pro, which potentially can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29586/\"]http://secunia.com/advisories/29586/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins April 2008

Post by Tami »

[i][b][url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of April 10 2008[/b][/i]

[b]Windows:--[/b]

[SA29733] Interwoven WorkSite Web TransferCtrl Class ActiveX Control Double-Free Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

J Fitzpatrick has reported a vulnerability in Interwoven WorkSite, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29733/\"]http://secunia.com/advisories/29733/[/url]

--

[SA29717] Tumbleweed SecureTransport FileTransfer ActiveX Control "TransferFile()" Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-10

Patrick Webster has reported a vulnerability in Tumbleweed SecureTransport, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29717/\"]http://secunia.com/advisories/29717/[/url]

--

[SA29714] Microsoft Windows hxvz.dll ActiveX Control Memory Corruption

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29714/\"]http://secunia.com/advisories/29714/[/url]

--

[SA29712] Microsoft VBScript/JScript Script Decoding Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29712/\"]http://secunia.com/advisories/29712/[/url]

--

[SA29704] Microsoft Windows GDI Image Parsing Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29704/\"]http://secunia.com/advisories/29704/[/url]

--

[SA29692] CDNetworks Nefficient Download NeffyLauncher ActiveX Control Directory Traversal

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-10

Simon Ryeo has reported a vulnerability in CDNetworks Nefficient Download, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29692/\"]http://secunia.com/advisories/29692/[/url]

--

[SA29691] Microsoft Visio Two File Processing Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

Two vulnerabilities have been reported in Microsoft Visio, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29691/\"]http://secunia.com/advisories/29691/[/url]

--

[SA29690] Microsoft Project Unspecified Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-08

A vulnerability has been reported in Microsoft Project, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29690/\"]http://secunia.com/advisories/29690/[/url]

--

[SA29669] Orbit Downloader URL Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-04

Diego Juarez has reported a vulnerability in Orbit Downloader, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29669/\"]http://secunia.com/advisories/29669/[/url]

--

[SA29732] SmarterMail Web Server Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-08

Matteo Memelli has reported a vulnerability in SmarterMail, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29732/\"]http://secunia.com/advisories/29732/[/url]

--

[SA29696] Microsoft Windows DNS Client Predictable Transaction ID Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-04-08

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to poison the DNS cache.

Full Advisory:
[url=\"http://secunia.com/advisories/29696/\"]http://secunia.com/advisories/29696/[/url]

--

[SA29713] HP OpenView Network Node Manager ovspmd.exe Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-09

Luigi Auriemma has discovered a vulnerability in HP OpenView Network Node Manager, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29713/\"]http://secunia.com/advisories/29713/[/url]

--

[SA29758] IBiz E-Banking Integrator ActiveX Control "WriteOFXDataFile()" Insecure Method

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-10

shinnai has discovered a vulnerability in IBiz E-Banking Integrator, which can be exploited by malicious people to overwrite arbitrary files.

Full Advisory:
[url=\"http://secunia.com/advisories/29758/\"]http://secunia.com/advisories/29758/[/url]

--

[SA29720] Microsoft Windows Kernel Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-08

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29720/\"]http://secunia.com/advisories/29720/[/url]


[b]UNIX/Linux:--[/b]

[SA29768] Ubuntu update for ghostscript

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-10

Ubuntu has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29768/\"]http://secunia.com/advisories/29768/[/url]

--

[SA29766] Debian update for vlc

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-10

Debian has issued an update for vlc. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29766/\"]http://secunia.com/advisories/29766/[/url]

--

[SA29756] Fedora update for xine-lib

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-09

Fedora has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29756/\"]http://secunia.com/advisories/29756/[/url]

--

[SA29740] Fedora update for xine-lib

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-09

Fedora has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29740/\"]http://secunia.com/advisories/29740/[/url]

--

[SA29731] Fedora update for comix

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-09

Fedora has issued an update for comix. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29731/\"]http://secunia.com/advisories/29731/[/url]

--

[SA29680] Debian update for alsaplayer

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-07

Debian has issued an update for alsaplayer. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29680/\"]http://secunia.com/advisories/29680/[/url]

--

[SA29767] Debian update for libcairo

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-10

Debian has issued an update for libcairo. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29767/\"]http://secunia.com/advisories/29767/[/url]

--

[SA29764] Debian update for pdns-recursor

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-04-10

Debian has issued an update for pdns-recursor. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.

Full Advisory:
[url=\"http://secunia.com/advisories/29764/\"]http://secunia.com/advisories/29764/[/url]

--

[SA29745] Gentoo update for pecl-apc

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-09

Gentoo has issued an update for pecl-apc. This fixes a vulnerability, which can be exploited by malicious users to bypass certain security restrictions and potentially by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29745/\"]http://secunia.com/advisories/29745/[/url]

--

[SA29737] Fedora update for pdns-recursor

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-04-09

Fedora has issued an update for pdns-recursor. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.

Full Advisory:
[url=\"http://secunia.com/advisories/29737/\"]http://secunia.com/advisories/29737/[/url]

--

[SA29736] Fedora update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-09

Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29736/\"]http://secunia.com/advisories/29736/[/url]

--

[SA29705] Site Sift Listings "id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-07

S@BUN has reported a vulnerability in Site Sift Listings, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29705/\"]http://secunia.com/advisories/29705/[/url]

--

[SA29703] PIGMy-SQL "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-07

t0pP8uZz has reported a vulnerability in PIGMy-SQL, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29703/\"]http://secunia.com/advisories/29703/[/url]

--

[SA29695] rPath update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-07

rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29695/\"]http://secunia.com/advisories/29695/[/url]

--

[SA29688] Debian update for mapserver

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-04-07

Debian has issued an update for mapserver. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29688/\"]http://secunia.com/advisories/29688/[/url]

--

[SA29681] Gentoo update for unzip

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-07

Gentoo has issued an update for unzip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29681/\"]http://secunia.com/advisories/29681/[/url]

--

[SA29750] Fedora update for cups

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-09

Fedora has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29750/\"]http://secunia.com/advisories/29750/[/url]

--

[SA29670] Cisco Unified Communications Disaster Recovery Framework Command Execution

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, System access
Released: 2008-04-04

A vulnerability has been reported in various Cisco products, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29670/\"]http://secunia.com/advisories/29670/[/url]

--

[SA29752] Fedora update for konversation

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-09

Fedora has issued an update for konversation. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29752/\"]http://secunia.com/advisories/29752/[/url]

--

[SA29729] Slackware update for m4

Critical: Less critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-04-08

Slackware has issued an update for m4. This fixes a security issue and a vulnerability, which can be exploited by malicious people to manipulate certain data or to potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29729/\"]http://secunia.com/advisories/29729/[/url]

--

[SA29706] Gentoo update for mysql

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Privilege escalation, DoS
Released: 2008-04-07

Gentoo has issued an update for mysql. This fixes a security issue and two vulnerabilities, which can be exploited by malicious users to gain escalated privileges, manipulate certain data, or to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29706/\"]http://secunia.com/advisories/29706/[/url]

--

[SA29698] Fedora update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-09

Fedora has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29698/\"]http://secunia.com/advisories/29698/[/url]

--

[SA29682] Debian update for openldap2.3

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-09

Debian has issued an update for openldap2.3. This fixes some vulnerabilities, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29682/\"]http://secunia.com/advisories/29682/[/url]

--

[SA29677] Slackware update for bzip2

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-08

Slackware has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29677/\"]http://secunia.com/advisories/29677/[/url]

--

[SA29671] GNU M4 Format String Vulnerability and Security Issue

Critical: Less critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-04-08

A vulnerability and a security issue have been reported in GNU M4, which can be exploited by malicious people to manipulate certain data or to potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29671/\"]http://secunia.com/advisories/29671/[/url]

--

[SA29718] HP Integrity Servers iLO-2 Management Processors Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-08

A vulnerability has been reported in HP Integrity Servers, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29718/\"]http://secunia.com/advisories/29718/[/url]

--

[SA29755] Fedora update for PolicyKit

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-04-09

Fedora has issued an update for PolicyKit. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29755/\"]http://secunia.com/advisories/29755/[/url]

--

[SA29754] Fedora update for audit

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-09

Fedora has issued an update for audit. This fixes a vulnerability, which potentially can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29754/\"]http://secunia.com/advisories/29754/[/url]

--

[SA29721] Globus Toolkit GSI-OpenSSH Information Disclosure

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-07

Globus has acknowledged a vulnerability in GSI-OpenSSH, which can be exploited by malicious, local users to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29721/\"]http://secunia.com/advisories/29721/[/url]

--

[SA29707] Gentoo update for nxnode and nx

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-04-07

Gentoo has issued an update for nxnode and nx. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29707/\"]http://secunia.com/advisories/29707/[/url]

--

[SA29686] cwRsync OpenSSH Security Bypass and Information Disclosure

Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-07

A vulnerability and a weakness have been reported in cwRsync, which can be exploited by malicious, local users to bypass certain security restrictions or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29686/\"]http://secunia.com/advisories/29686/[/url]

--

[SA29683] Gentoo update for openssh

Critical: Less critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-07

Gentoo has issued an update for openssh. This fixes a weakness and a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29683/\"]http://secunia.com/advisories/29683/[/url]

--

[SA29676] Slackware update for openssh

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-07

Slackware has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29676/\"]http://secunia.com/advisories/29676/[/url]

--

[SA29742] Fedora update for gnome-screensaver

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-04-09

Fedora has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with physical access to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29742/\"]http://secunia.com/advisories/29742/[/url]

--

[SA29693] rPath update for OpenSSH

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-04-07

rPath has issued an update for OpenSSH. This fixes a weakness, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29693/\"]http://secunia.com/advisories/29693/[/url]


[b]Other:--[/b]

[SA29744] Avaya SIP Enablement Services Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-04-09

Some vulnerabilities have been reported in Avaya SIP Enablement Services, which can be exploited by malicious users and malicious people to conduct SQL injection attacks, bypass certain security restrictions, and potentially to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29744/\"]http://secunia.com/advisories/29744/[/url]

--

[SA29708] WatchGuard Firebox Products User Enumeration Weakness

Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-04-08

Luke Jennings has reported a weakness in some WatchGuard Firebox products, which can be exploited by malicious people to determine valid usernames.

Full Advisory:
[url=\"http://secunia.com/advisories/29708/\"]http://secunia.com/advisories/29708/[/url]


[b]Cross Platform:--[/b]

[SA29749] LokiCMS "default" PHP Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-09

__GiReX__ has discovered a vulnerability in LokiCMS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29749/\"]http://secunia.com/advisories/29749/[/url]

--

[SA29739] ExBB Italia "modules/threadstop/threadstop.php" File Inclusion

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-04-09

The:Paradox has discovered some vulnerabilities in ExBB Italia, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29739/\"]http://secunia.com/advisories/29739/[/url]

--

[SA29684] Blogator-script File Inclusion and SQL Injection

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-04-07

Some vulnerabilities have been discovered in Blogator-script, which can be exploited by malicious people to conduct SQL injection attacks, to disclose sensitive information, or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29684/\"]http://secunia.com/advisories/29684/[/url]

--

[SA29772] Drupal Simple Access Module Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-10

A security issue has been reported in the Simple Access module for Drupal, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29772/\"]http://secunia.com/advisories/29772/[/url]

--

[SA29762] Drupal Menu System Security Bypass Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-10

Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29762/\"]http://secunia.com/advisories/29762/[/url]

--

[SA29751] Openfire Unspecified Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-10

A vulnerability has been reported in Openfire, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29751/\"]http://secunia.com/advisories/29751/[/url]

--

[SA29748] Adobe ColdFusion CFC Methods Access Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-09

A security issue has been reported in Adobe ColdFusion 8, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29748/\"]http://secunia.com/advisories/29748/[/url]

--

[SA29746] Gallery Script Lite "path" Information Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-04-10

jiko has discovered a vulnerability in Gallery Script Lite, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29746/\"]http://secunia.com/advisories/29746/[/url]

--

[SA29727] libfishsound Speex Header Processing Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-08

A vulnerability has been reported in libfishsound, which can potentially be exploited by malicious people to compromise an
application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29727/\"]http://secunia.com/advisories/29727/[/url]

--

[SA29725] iScripts SocialWare SQL Injection and File Upload Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information, System access
Released: 2008-04-10

t0pP8uZz has reported two vulnerabilities in iScripts SocialWare, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29725/\"]http://secunia.com/advisories/29725/[/url]

--

[SA29724] LinPHA "maps_type" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-08

A vulnerability has been discovered in LinPHA, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29724/\"]http://secunia.com/advisories/29724/[/url]

--

[SA29723] Prozilla Freelancers "project" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-09

t0pP8uZz has reported a vulnerability in Prozilla Freelancers, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29723/\"]http://secunia.com/advisories/29723/[/url]

--

[SA29716] KnowledgeQuest SQL Injection and Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-04-10

Some vulnerabilities have been discovered in KnowledgeQuest, which can be exploited by malicious people to conduct SQL injection attacks or to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29716/\"]http://secunia.com/advisories/29716/[/url]

--

[SA29715] Prozilla Entertainers "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-09

t0pP8uZz and xprog have reported a vulnerability in Prozilla Entertainers, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29715/\"]http://secunia.com/advisories/29715/[/url]

--

[SA29710] Links Directory "cat_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-07

t0pP8uZz and xprog have reported a vulnerability in Links Directory, which can be exploited by malicious people to conduct SQL Injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29710/\"]http://secunia.com/advisories/29710/[/url]

--

[SA29709] Software Index Script "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-07

t0pP8uZz and xprog have reported a vulnerability in Software Index Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29709/\"]http://secunia.com/advisories/29709/[/url]

--

[SA29701] Prozilla Cheats "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-09

t0pP8uZz has reported a vulnerability in Prozilla Cheats, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29701/\"]http://secunia.com/advisories/29701/[/url]

--

[SA29699] Wikepage "wiki" Information Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-08

A.Nosrati has discovered a vulnerability in Wikepage, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29699/\"]http://secunia.com/advisories/29699/[/url]

--

[SA29697] Comdev News Publisher "arcmonth" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-07

t0pP8uZz & xprog have discovered a vulnerability in Comdev News Publisher, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29697/\"]http://secunia.com/advisories/29697/[/url]

--

[SA29689] Prozilla Topsites Security Bypass Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-09

t0pP8uZz has reported some vulnerabilities in Prozilla Topsites, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29689/\"]http://secunia.com/advisories/29689/[/url]

--

[SA29685] Mole "viewsource.php" Information Disclosure Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-08

GoLd_M has discovered two vulnerabilities in Mole (Make Our Life Easy), which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29685/\"]http://secunia.com/advisories/29685/[/url]

--

[SA29667] PHP Photo Gallery "photo_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-07

t0pP8uZz & xprog have reported a vulnerability in PHP Photo Gallery (Advanced Web Photo Gallery), which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29667/\"]http://secunia.com/advisories/29667/[/url]

--

[SA29775] TIBCO Enterprise Message Service Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-10

Some vulnerabilities have been reported in TIBCO products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29775/\"]http://secunia.com/advisories/29775/[/url]

--

[SA29774] TIBCO Rendezvous Multiple Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: System access, DoS, Exposure of sensitive information
Released: 2008-04-10

Some vulnerabilities have been reported in multiple TIBCO products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29774/\"]http://secunia.com/advisories/29774/[/url]

--

[SA29722] Prozilla Reviews "DeleteUser.php" Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-09

t0pP8uZz has reported a vulnerability in Prozilla Reviews, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29722/\"]http://secunia.com/advisories/29722/[/url]

--

[SA29719] WoltLab Burning Board WCF Error Printing Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-04-08

Jessica Hope has reported a vulnerability in WoltLab Burning Board, which can be exploited by malicious people to disclose potentially sensitive information or to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29719/\"]http://secunia.com/advisories/29719/[/url]

--

[SA29700] Xpoze "reed" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-07

t0pP8uZz has reported a vulnerability in Xpoze, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29700/\"]http://secunia.com/advisories/29700/[/url]

--

[SA29673] e-Classifieds Corporate Edition "db" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-04

Russ McRee has reported a vulnerability in e-Classifieds, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29673/\"]http://secunia.com/advisories/29673/[/url]

--

[SA29674] Webwasher URL Processing Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-04

A vulnerability has been reported in Webwasher, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29674/\"]http://secunia.com/advisories/29674/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins April 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url][/b][/i] Vulnerabilities Content Listing for the week of April 17 2008

[b]Windows:--[/b]

[SA29837] CA Products DSM gui_cm_ctrls ActiveX Control Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-17

A vulnerability has been reported in various CA products, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29837/\"]http://secunia.com/advisories/29837/[/url]

--

[SA29831] BigAnt Messenger AntServer Module Directory Traversal and Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-04-16

Two vulnerabilities have been discovered in BigAnt Messenger, which can be exploited by malicious people to disclose certain information or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29831/\"]http://secunia.com/advisories/29831/[/url]

--

[SA29829] Oracle Products Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, DoS, System access
Released: 2008-04-16

Multiple vulnerabilities have been reported for various Oracle products. Some vulnerabilities have unknown impacts while others can be exploited by malicious users to bypass certain security restrictions, conduct SQL injection attacks, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29829/\"]http://secunia.com/advisories/29829/[/url]

--

[SA29827] Carbon Communities Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-04-17

AmnPardaz Security Research Team have reported a vulnerability in Carbon Communities, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29827/\"]http://secunia.com/advisories/29827/[/url]

--

[SA29808] Nero MediaHome Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-14

Luigi Auriemma has discovered a vulnerability in Nero MediaHome, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29808/\"]http://secunia.com/advisories/29808/[/url]

--

[SA29805] Novell eDirectory "Connection" HTTP Header Processing Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-14

A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29805/\"]http://secunia.com/advisories/29805/[/url]

--

[SA29796] HP OpenView Network Node Manager Multiple Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-04-14

Some vulnerabilities have been reported in HP OpenView Network Node Manager, which can be exploited by malicious people to disclose certain information or cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29796/\"]http://secunia.com/advisories/29796/[/url]


[b]UNIX/Linux:--[/b]

[SA29864] Debian update for openoffice.org

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-17

Debian has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to
potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29864/\"]http://secunia.com/advisories/29864/[/url]

--

[SA29863] Kolab Server ClamAV Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29863/\"]http://secunia.com/advisories/29863/[/url]

--

[SA29850] xine-lib NSF Demuxer Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-17

Guido Landi has discovered a vulnerability in xine-lib, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29850/\"]http://secunia.com/advisories/29850/[/url]

--

[SA29828] Red Hat update for seamonkey

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Red Hat has issued an update for seamonkey. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29828/\"]http://secunia.com/advisories/29828/[/url]

--

[SA29793] Red Hat update for firefox

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Red Hat has issued an update for firefox. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29793/\"]http://secunia.com/advisories/29793/[/url]

--

[SA29862] Fedora update for nagios / nagios-plugins

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-04-17

Fedora has issued an update for nagios and nagios-plugins. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29862/\"]http://secunia.com/advisories/29862/[/url]

--

[SA29861] Gentoo update for rsync

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Gentoo has issued an update for rsync. This fixes a vulnerability, which can potentially be exploited by malicious users to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29861/\"]http://secunia.com/advisories/29861/[/url]

--

[SA29859] Fedora update for otrs

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-17

Fedora has issued an update for otrs. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29859/\"]http://secunia.com/advisories/29859/[/url]

--

[SA29856] Fedora update for rsync

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Fedora has issued an update for rsync. This fixes a vulnerability, which can potentially be exploited by malicious users to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29856/\"]http://secunia.com/advisories/29856/[/url]

--

[SA29854] Fedora update for speex

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Fedora has issued an update for speex. This fixes a security issue,
which can potentially be exploited by malicious people to compromise an
application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29854/\"]http://secunia.com/advisories/29854/[/url]

--

[SA29845] Fedora update for libfishsound

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Fedora has issued an update for libfishsound. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29845/\"]http://secunia.com/advisories/29845/[/url]

--

[SA29840] AutoTutorials "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-17

cO2 has discovered a vulnerability in AutoTutorials, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29840/\"]http://secunia.com/advisories/29840/[/url]

--

[SA29835] Red Hat update for speex

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

Red Hat has issued an update for speex. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29835/\"]http://secunia.com/advisories/29835/[/url]

--

[SA29813] Ubuntu update for squid

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-15

Ubuntu has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/29813/\"]http://secunia.com/advisories/29813/[/url]

--

[SA29785] VMware ESX Server Multiple Security Updates

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-16

VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29785/\"]http://secunia.com/advisories/29785/[/url]

--

[SA29809] CUPS PNG Filter Integer Overflow Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-15

Thomas Pollet has reported a vulnerability in CUPS, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29809/\"]http://secunia.com/advisories/29809/[/url]

--

[SA29839] Fedora update for gallery2

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-17

Fedora has issued an update for gallery2. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29839/\"]http://secunia.com/advisories/29839/[/url]

--

[SA29823] WORK system e-commerce main.php Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-15

Russ McRee has discovered some vulnerabilities in WORK system e-commerce, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29823/\"]http://secunia.com/advisories/29823/[/url]

--

[SA29806] IBM HTTP Server mod_imap and mod_status Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-14

IBM has acknowledged some vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29806/\"]http://secunia.com/advisories/29806/[/url]

--

[SA29803] MirBSD Korn Shell TTY Attachment Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-14

A vulnerability has been reported in MirBSD Korn Shell, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29803/\"]http://secunia.com/advisories/29803/[/url]

--

[SA29832] Cecilia "/tmp/csvers" Insecure Temporary File Handling

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-16

Felipe Sateler has discovered a security issue in Cecilia, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/29832/\"]http://secunia.com/advisories/29832/[/url]


[b]Other:--[/b]

[SA29798] OmniPCX Office Information Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-04-14

A vulnerability has been reported in OmniPCX Office, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29798/\"]http://secunia.com/advisories/29798/[/url]

--

[SA29822] Cisco Network Admission Control Information Disclosure Security Issue

Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-04-17

A security issue has been reported in Cisco Network Admission Control (NAC), which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29822/\"]http://secunia.com/advisories/29822/[/url]

[b]
Cross Platform:--[/b]

[SA29860] Mozilla SeaMonkey Javascript Garbage Collector Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

A vulnerability has been reported in Mozilla SeaMonkey, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29860/\"]http://secunia.com/advisories/29860/[/url]

--

[SA29852] OpenOffice Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-17

Some vulnerabilities have been reported in OpenOffice, which can be exploited by malicious people to potentially compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29852/\"]http://secunia.com/advisories/29852/[/url]

--

[SA29846] Safari Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-04-17

Some vulnerabilities have been reported in Safari, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29846/\"]http://secunia.com/advisories/29846/[/url]

--

[SA29841] BEA JRockit Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-04-17

Some vulnerabilities have been reported in BEA JRockit, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/29841/\"]http://secunia.com/advisories/29841/[/url]

--

[SA29797] NewsOffice "newsoffice_directory" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-04-14

RoMaNcYxHaCkEr has discovered a vulnerability in NewsOffice, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29797/\"]http://secunia.com/advisories/29797/[/url]

--

[SA29790] eGroupWare File Upload Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-17

A vulnerability has been reported in eGroupWare, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29790/\"]http://secunia.com/advisories/29790/[/url]

--

[SA29787] Mozilla Firefox Javascript Garbage Collector Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-17

A vulnerability has been reported in Mozilla Firefox, which can potentially be exploited by malicious people to compromise a user's
system.

Full Advisory:
[url=\"http://secunia.com/advisories/29787/\"]http://secunia.com/advisories/29787/[/url]

--

[SA29825] phpHotResources SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-15

The-0utl4w has reported a vulnerability in phpHotResources, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29825/\"]http://secunia.com/advisories/29825/[/url]

--

[SA29820] Joomla Jom Comment Component Unspecified SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-17

Security Assurance Team of the National Australia Bank have reported a vulnerability in the Jom Comment component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29820/\"]http://secunia.com/advisories/29820/[/url]

--

[SA29815] Dating Club "age_to" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-15

The-0utl4w has reported a vulnerability in Dating Club, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29815/\"]http://secunia.com/advisories/29815/[/url]

--

[SA29812] CcMail "this_cookie" Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-04-14

t0pP8uZz has discovered a vulnerability in CcMail, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29812/\"]http://secunia.com/advisories/29812/[/url]

--

[SA29810] 1024 CMS SQL Injection and File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-14

__GiReX__ has discovered some vulnerabilities in 1024 CMS, which can be exploited by malicious people to conduct SQL injection attacks or to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29810/\"]http://secunia.com/advisories/29810/[/url]

--

[SA29807] cpCommerce Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-14

AmnPardaz Security Research Team have discovered some vulnerabilities in cpCommerce, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29807/\"]http://secunia.com/advisories/29807/[/url]

--

[SA29799] BosClassifieds Classified Ads System "cat" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-15

SoSo H H has reported a vulnerability in BosClassifieds Classified Ads System, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29799/\"]http://secunia.com/advisories/29799/[/url]

--

[SA29794] Ruby WEBrick Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-16

Luigi Auriemma has reported a vulnerability in Ruby, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
[url=\"http://secunia.com/advisories/29794/\"]http://secunia.com/advisories/29794/[/url]

--

[SA29792] libpng Unknown Chunk Processing Uninitialized Memory Access

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-14

Tavis Ormandy has reported a vulnerability in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.

Full Advisory:
[url=\"http://secunia.com/advisories/29792/\"]http://secunia.com/advisories/29792/[/url]

--

[SA29791] phpkb Knowledge Base "ID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-14

parad0x has reported a vulnerability in phpkb Knowledge Base, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29791/\"]http://secunia.com/advisories/29791/[/url]

--

[SA29789] Koobi "poll_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-17

S@BUN has reported a vulnerability in Koobi, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29789/\"]http://secunia.com/advisories/29789/[/url]

--

[SA29788] cwRsync "xattr" Integer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-14

A vulnerability has been reported in cwRsync, which can potentially be exploited by malicious users to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29788/\"]http://secunia.com/advisories/29788/[/url]

--

[SA29849] HP OpenView Network Node Manager Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Cross Site Scripting, DoS, System access
Released: 2008-04-17

HP has acknowledged some vulnerabilities in OpenView Network Node Manager, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29849/\"]http://secunia.com/advisories/29849/[/url]

--

[SA29819] DotClear "ecrire/images.php" File Upload Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-04-16

Morgan ARMAND has discovered a vulnerability in DotClear, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/29819/\"]http://secunia.com/advisories/29819/[/url]

--

[SA29804] BusinessObjects XI "cms" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-17

Sebastien gioria has reported a vulnerability in BusinessObjects XI, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29804/\"]http://secunia.com/advisories/29804/[/url]

--

[SA29801] phpBB Two Security Bypass Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-15

Two vulnerabilities have been reported in phpBB, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/29801/\"]http://secunia.com/advisories/29801/[/url]

--

[SA29795] Coppermine Photo Gallery "upload.php" SQL Injection

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-14

A vulnerability has been discovered in Coppermine Photo Gallery, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/29795/\"]http://secunia.com/advisories/29795/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”