Secunia Alerts - September 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Alerts - September 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of September 4 2008[/b][/i]

[b]Windows:--[/b]

[b][SA31710] VMware ACE Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware ACE, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31710/\"]http://secunia.com/advisories/31710/[/url]


[b][SA31666] Acoustica MP3 CD Burner ASX Playlist Buffer Overflow[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-01

n00b has discovered a vulnerability in Acoustica MP3 CD Burner, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31666/\"]http://secunia.com/advisories/31666/[/url]


[b][SA31660] Acoustica Beatcraft Project File Buffer Overflow Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-01

Koshi has discovered a vulnerability in Acoustica Beatcraft, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31660/\"]http://secunia.com/advisories/31660/[/url]


[b][SA31727] @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-03

C1c4Tr1Z has discovered some vulnerabilities in @Mail WebMail, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31727/\"]http://secunia.com/advisories/31727/[/url]


[b][SA31715] Softalk Mail Server IMAP Denial of Service Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-03

João Antunes has discovered a vulnerability in Softalk Mail Server, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31715/\"]http://secunia.com/advisories/31715/[/url]


[b][SA31693] PageR Enterprise Directory Traversal Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-04

A vulnerability has been reported in PageR Enterprise, which can be exploited by malicious users to disclose potentially sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31693/\"]http://secunia.com/advisories/31693/[/url]


[b]UNIX/Linux:--[/b]

[b][SA31736] SUSE update for IBMJava5-JRE and java-1_5_0-ibm [/b]

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-04

SUSE has issued an update for IBMJava5-JRE and java-1_5_0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31736/\"]http://secunia.com/advisories/31736/[/url]


[b][SA31711] VMware Fusion Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware Fusion, which can be exploited by malicious people to cause a DoS (Denial of Service)
and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31711/\"]http://secunia.com/advisories/31711/[/url]


[b][SA31687] SUSE Update for Multiple Packages
[/b]
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, Privilege escalation, DoS, System access
Released: 2008-09-01

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose potentially sensitive information, gain escalated privileges, and bypass certain security restrictions, by malicious users to conduct script insertion attacks and cause a DoS (Denial of Service), and by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, cause a DoS, poison the DNS cache, and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31687/\"]http://secunia.com/advisories/31687/[/url]


[b][SA31671] Najdi.si Toolbar Buffer Overflow Vulnerability[/b]

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-04

shinnai has discovered a vulnerability in Najdi.si Toolbar, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31671/\"]http://secunia.com/advisories/31671/[/url]


[b][SA31745] FreeBSD ICMPv6 "Packet Too Big" MTU Denial of Service Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-04

FreeBSD has acknowledged a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31745/\"]http://secunia.com/advisories/31745/[/url]


[b][SA31742] Astaro Security Gateway DNS Cache Poisoning[/b]

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-09-04

Astaro has acknowledged a vulnerability in Astaro Security Gateway, which can be exploited by malicious people to poison the DNS cache.

Full Advisory: [url=\"http://secunia.com/advisories/31742/\"]http://secunia.com/advisories/31742/[/url]


[b][SA31738] Slackware update for php[/b]

Critical: Moderately critical
Where: From remote
Impact: Unknown, Exposure of sensitive information, DoS, System access
Released: 2008-09-04

Slackware has issued an update for php. This fixes some vulnerabilities, where some have an unknown impact and others can potentially be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31738/\"]http://secunia.com/advisories/31738/[/url]


[b][SA31728] Ubuntu update for libxml2[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-04

Ubuntu has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31728/\"]http://secunia.com/advisories/31728/[/url]


[b][SA31725] ClamAV CHM Processing Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-03

A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31725/\"]http://secunia.com/advisories/31725/[/url]


[b][SA31722] eliteCMS "page" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-03

e.wiZz! has discovered a vulnerability in eliteCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31722/\"]http://secunia.com/advisories/31722/[/url]


[b][SA31712] VMware ESX Server Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware ESX Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31712/\"]http://secunia.com/advisories/31712/[/url]


[b][SA31702] HP-UX update for Netscape / Red Hat Directory Server[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-09-02

HP has issued an update for Netscape / Red Hat Directory Server. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31702/\"]http://secunia.com/advisories/31702/[/url]


[b][SA31699] PHP Coupon Script "id" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-03

Hussin X has reported a vulnerability in PHP Coupon Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31699/\"]http://secunia.com/advisories/31699/[/url]


[b][SA31698] Ubuntu update for tiff[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-03

Ubuntu has issued an update for tiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31698/\"]http://secunia.com/advisories/31698/[/url]


[b][SA31697] rPath update for ruby[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing, DoS
Released: 2008-09-01

rPath has issued an update for ruby. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and conduct spoofing attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31697/\"]http://secunia.com/advisories/31697/[/url]


[b][SA31676] Newsbeuter URL Processing Shell Command Execution[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-02

A vulnerability has been reported in Newsbeuter, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31676/\"]http://secunia.com/advisories/31676/[/url]


[b][SA31670] Red Hat update for libtiff[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-29

Red Hat has issued an update for libtiff. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31670/\"]http://secunia.com/advisories/31670/[/url]


[b][SA31668] Red Hat update for libtiff[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-08-29

Red Hat has issued an update for libtiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31668/\"]http://secunia.com/advisories/31668/[/url]


[b][SA31720] @Mail Multiple Cross-Site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-03

C1c4Tr1Z has discovered some vulnerabilities in @Mail, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31720/\"]http://secunia.com/advisories/31720/[/url]


[b][SA31713] VMware ESX / ESXi Server Multiple Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-01

VMware has acknowledged a weakness and a vulnerability in VMware ESX Server, which can be exploited by malicious users to disclose potentially sensitive information and by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31713/\"]http://secunia.com/advisories/31713/[/url]


[b][SA31691] Debian update for slash[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-09-02

Debian has issued an update for slash. This fixes some vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31691/\"]http://secunia.com/advisories/31691/[/url]


[b][SA31743] FreeBSD AMD64 General Protection Fault Privilege Escalation[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-04

FreeBSD has acknowledged a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31743/\"]http://secunia.com/advisories/31743/[/url]

--

[b][SA31685] Avaya Products Linux Kernel Multiple Vulnerabilities[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-09-01

Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial
of Service) and potentially gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31685/\"]http://secunia.com/advisories/31685/[/url]


[b][SA31663] Slackware update for amarok[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-29

Slackware has issued an update for amarok. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31663/\"]http://secunia.com/advisories/31663/[/url]


[b][SA31739] IBM AIX "swcons" Command Privilege Escalation Vulnerability[/b]

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-04

A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31739/\"]http://secunia.com/advisories/31739/[/url]


[b][SA31716] Postfix epoll File Descriptor Leak Security Issue[/b]

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-09-03

A security issue has been reported in Postfix, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31716/\"]http://secunia.com/advisories/31716/[/url]


[b][SA31694] GpsDrive "geo-code" Insecure Temporary Files[/b]

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-08-29

A security issue has been reported in GpsDrive, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31694/\"]http://secunia.com/advisories/31694/[/url]


[b][SA31689] Avaya Products Linux Kernel Local Denial of Service[/b]

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-09-01

Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31689/\"]http://secunia.com/advisories/31689/[/url]


[b][SA31667] Sun Solaris Kernel Covert Channel Security Bypass[/b]

Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-08-29

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31667/\"]http://secunia.com/advisories/31667/[/url]


[b]Other:--[/b]

[b][SA31730] Cisco ASA and PIX Security Appliances Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS
Released: 2008-09-04

Some vulnerabilities have been reported in Cisco ASA and PIX appliances, which can be exploited by malicious people to disclose sensitive information, and by malicious users and malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31730/\"]http://secunia.com/advisories/31730/[/url]


[b][SA31673] IBM WebSphere Application Server for z/OS HTTP Server mod_proxy_ftp Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-29

IBM has acknowledged a vulnerability in IBM WebSphere Application Server for z/OS, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31673/\"]http://secunia.com/advisories/31673/[/url]


[b][SA31680] Kyocera FS-118MFP Command Center Directory Traversal Vulnerability[/b]

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-09-02

Francesco Tornieri has reported a vulnerability in Kyocera FS-118MFP, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31680/\"]http://secunia.com/advisories/31680/[/url]


[b][SA31665] Belkin Wireless G Router Web Interface Authentication Bypass[/b]

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-09-03

noensr has reported a vulnerability in Belkin Wireless G F5D7632-4V6, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31665/\"]http://secunia.com/advisories/31665/[/url]


[b]Cross Platform:--[/b]

[b][SA31709] VMware Player Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware Player, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31709/\"]http://secunia.com/advisories/31709/[/url]


[b][SA31708] VMware Server Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware Server, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31708/\"]http://secunia.com/advisories/31708/[/url]


[b][SA31707] VMware Workstation Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-09-01

VMware has acknowledged some vulnerabilities in VMware Workstation, which can be exploited by malicious, local users to gain escalated
privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31707/\"]http://secunia.com/advisories/31707/[/url]


[b][SA31723] Ruby on Rails REXML Denial of Service Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-03

A vulnerability has been reported in Ruby on Rails, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31723/\"]http://secunia.com/advisories/31723/[/url]


[b][SA31703] Reciprocal Links Manager "site" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-02

Hussin X has discovered a vulnerability in Reciprocal Links Manager, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31703/\"]http://secunia.com/advisories/31703/[/url]


[b][SA31696] Living Local Website "r" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-04

Hussin X has reported a vulnerability in Living Local Website, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31696/\"]http://secunia.com/advisories/31696/[/url]


[b][SA31683] Invision Power Board Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Hijacking, Manipulation of data, Exposure of sensitive information, System access
Released: 2008-09-03

DarkFig has reported some vulnerabilities in Invision Power Board (IP.Board), which can be exploited by malicious users to disclose sensitive information and compromise a vulnerable system, and by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31683/\"]http://secunia.com/advisories/31683/[/url]


[b][SA31682] EasyClassifields "go" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-01

e.wiZz! has discovered a vulnerability in EasyClassifields, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31682/\"]http://secunia.com/advisories/31682/[/url]


[b][SA31678] Novell IDM Cross-Site Scripting and Script Insertion[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-01

Some vulnerabilities have been reported in Novell User Application and Novell Identity Manager Roles Based Provisioning Module, which can be
exploited by malicious people to conduct script insertion and cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31678/\"]http://secunia.com/advisories/31678/[/url]

[b]
[SA31674] Wireshark Denial of Service Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-04

Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31674/\"]http://secunia.com/advisories/31674/[/url]


[b][SA31669] CMSbright "id_rub_page" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-04

BorN To K!LL has reported a vulnerability in CMSbright, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31669/\"]http://secunia.com/advisories/31669/[/url]


[b][SA31664] Spice Classifieds "cat_path" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-03

Cyb3r-1sT has reported a vulnerability in Spice Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31664/\"]http://secunia.com/advisories/31664/[/url]


[b][SA31684] Novell eDirectory Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From local network
Impact: Unknown, Cross Site Scripting, DoS, System access
Released: 2008-08-29

Multiple vulnerabilities have been reported in Novell eDirectory, where some have an unknown impact and others can be exploited by malicious
people to conduct cross-site scripting attacks or to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31684/\"]http://secunia.com/advisories/31684/[/url]


[SA31735] Celerondude Uploader "username" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-04

A vulnerability has been discovered in Celerondude Uploader, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31735/\"]http://secunia.com/advisories/31735/[/url]


[b][SA31729] Django Authentication Cross-Site Request Forgery[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-09-04

A vulnerability has been reported in Django, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31729/\"]http://secunia.com/advisories/31729/[/url]


[b][SA31719] Open Media Collectors Database Cross-Site Scripting and Request Forgery[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-03

Some vulnerabilities have been discovered in Open Media Collectors Database (OpenDb), which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31719/\"]http://secunia.com/advisories/31719/[/url]

[b]
[SA31681] dotProject SQL Injection and Cross-Site Scripting[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-08-29

C1c4Tr1Z has discovered some vulnerabilities in dotProject, which can be exploited by malicious users to conduct SQL injection attacks, and by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31681/\"]http://secunia.com/advisories/31681/[/url]


[b][SA31679] vtiger CRM Multiple Cross-Site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-02

Fabian Fingerle has discovered some vulnerabilities in vtiger CRM, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31679/\"]http://secunia.com/advisories/31679/[/url]


[b][SA31662] Blogn Cross-Site Scripting and Cross-Site Request Forgery[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-08-29

Two vulnerabilities have been reported in Blogn, which can be exploited by malicious people to conduct cross-site scripting and cross-site
request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31662/\"]http://secunia.com/advisories/31662/[/url]


[b][SA31661] Brim SQL Injection and Script Insertion Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-09-01

Fisher762 has discovered two vulnerabilities in Brim, which can be exploited by malicious users to conduct script insertion and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31661/\"]http://secunia.com/advisories/31661/[/url]


[b][SA31731] Cisco Secure ACS EAP Packet Denial of Service[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-04

A vulnerability has been reported in Cisco Secure Access Control Server (ACS), which can be exploited by malicious people to cause a DoS (Denial
of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31731/\"]http://secunia.com/advisories/31731/[/url]


[b][SA31688] HP OpenView Network Node Manager Denial of Service[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-03

Some vulnerabilities have been reported in HP OpenView Network Node Manager, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31688/\"]http://secunia.com/advisories/31688/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Alerts - September 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of September 11 2008[/b][/i]

[b]Windows:--[/b]

[SA31821] [b]Apple QuickTime Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-10

Multiple vulnerabilities have been reported in QuickTime, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31821/\"]http://secunia.com/advisories/31821/[/url]


[SA31819] [b]Creator CMS "sideid" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-11

ThE X-HaCkEr has reported a vulnerability in Creator CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31819/\"]http://secunia.com/advisories/31819/[/url]


[SA31750] [b]Simple Machines Forum Password Reset Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-09-08

A vulnerability has been reported in Simple Machines Forum, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31750/\"]http://secunia.com/advisories/31750/[/url]


[SA31822] [b]Apple Bonjour for Windows mDNSResponder Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-09-10

Two vulnerabilities have been reported in Apple Bonjour for Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or spoof DNS responses.

Full Advisory: [url=\"http://secunia.com/advisories/31822/\"]http://secunia.com/advisories/31822/[/url]


[SA31765] [b]X-Spam for SMTP Servers Insecure File Permissions[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-08

Edi Strosar has reported a security issue in X-Spam for SMTP Servers, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31765/\"]http://secunia.com/advisories/31765/[/url]


[SA31764] [b]HP OpenView Select Identity Connectors Information Disclosure[/b]

Critical: Less critical
Where: Local system
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-05

A vulnerability has been reported in various HP OpenView Select Identity Connectors, which can be exploited by malicious, local users to disclose potentially sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31764/\"]http://secunia.com/advisories/31764/[/url]


[b]UNIX/Linux:--[/b]

[SA31834] [b]Fedora update for yelp[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-10

Fedora has issued an update for yelp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's
system.

Full Advisory: [url=\"http://secunia.com/advisories/31834/\"]http://secunia.com/advisories/31834/[/url]


[SA31827] [b]Fedora update for xine-lib[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-10

Fedora has issued an update for xine-lib. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31827/\"]http://secunia.com/advisories/31827/[/url]


[SA31756] [b]Gentoo update for realplayer[/b]

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-05

Gentoo has issued an update for realplayer. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31756/\"]http://secunia.com/advisories/31756/[/url]


[SA31753][b] Gentoo update for yelp[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-05

Gentoo has issued an update for yelp. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31753/\"]http://secunia.com/advisories/31753/[/url]


[SA31838] [b]Fedora update for libtiff[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-10

Fedora has issued an update for libtiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31838/\"]http://secunia.com/advisories/31838/[/url]


[SA31825] [b]Fedora update for drupal[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, System access
Released: 2008-09-10

Fedora has issued an update for drupal. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks and compromise a vulnerable system, and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31825/\"]http://secunia.com/advisories/31825/[/url]


[SA31799] [b]Debian update for freetype[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-11

Debian has issued an update for freetype. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31799/\"]http://secunia.com/advisories/31799/[/url]


[SA31797] [b]Gentoo update for tiff[/b]

Critical: Moderately critical
Where: From remote
Impact: System access, DoS
Released: 2008-09-09

Gentoo has issued an update for tiff. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31797/\"]http://secunia.com/advisories/31797/[/url]


[SA31793] [b]phpAdultSite CMS SQL Injection And Cross-Site Scripting[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-09-08

David Sopas has reported a vulnerability in phpAdultSite CMS, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31793/\"]http://secunia.com/advisories/31793/[/url]


[SA31792] [b]NetBSD Malformed ICMPv6 "MLD-QUERY" Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-08

A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31792/\"]http://secunia.com/advisories/31792/[/url]


[SA31790] [b]Gentoo update for courier-authlib[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-08

Gentoo has issued an update for courier-authlib. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31790/\"]http://secunia.com/advisories/31790/[/url]


[SA31785] [b]Gentoo update for VLC[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-08

Gentoo has issued an update for VLC. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31785/\"]http://secunia.com/advisories/31785/[/url]


[SA31778] [b]Fedora update for openoffice.org
[/b]
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-10

Fedora has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31778/\"]http://secunia.com/advisories/31778/[/url]


[SA31766] [b]Sun Solaris 10 GNU Tar PAX Extended Headers Handling Buffer Overflow[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-09

Sun has acknowledged a vulnerability in GNU Tar in Solaris, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) and to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31766/\"]http://secunia.com/advisories/31766/[/url]


[SA31763] [b]rPath update for libtiff[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-05

rPath has issued an update for libtiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31763/\"]http://secunia.com/advisories/31763/[/url]


[SA31754] [b]Gentoo update for dnsmasq[/b]

Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-09-05

Gentoo has issued an update for dnsmasq. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and poison the DNS cache.

Full Advisory: [url=\"http://secunia.com/advisories/31754/\"]http://secunia.com/advisories/31754/[/url]


[SA31836] [b]SUSE update for kernel[/b]

Critical: Moderately critical
Where: From local network
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-09-11

SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and disclose potentially sensitive information, and by malicious people to cause a DoS and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31836/\"]http://secunia.com/advisories/31836/[/url]


[SA31833] [b]Fedora update for bluez-utils and bluez-libs[/b]

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-09-10

Fedora has issued an update for bluez-utils and bluez-libs. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31833/\"]http://secunia.com/advisories/31833/[/url]


[SA31777] [b]Fedora update for adminutil[/b]

Critical: Moderately critical
Where: From local network
Impact: Cross Site Scripting, DoS, System access
Released: 2008-09-10

Fedora has issued an update for adminutil. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31777/\"]http://secunia.com/advisories/31777/[/url]


[SA31837] [b]Fedora update for Django[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-09-10

Fedora has issued an update for Django. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31837/\"]http://secunia.com/advisories/31837/[/url]


[SA31806] [b]Movable Type Multiple Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-09

Some vulnerabilities have been reported in Movable Type, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31806/\"]http://secunia.com/advisories/31806/[/url]


[SA31759] [b]Fedora update for awstats[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-10

Fedora has issued an update for awstats. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31759/\"]http://secunia.com/advisories/31759/[/url]


[SA31791] [b]Red Hat Enterprise IPA Information Disclosure and Denial of Service[/b]

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, DoS
Released: 2008-09-11

Some vulnerabilities have been reported in Red Hat Enterprise IPA, which can be exploited by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31791/\"]http://secunia.com/advisories/31791/[/url]


[SA31839] [b]Fedora update for amarok[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-10

Fedora has released an update for amarok.This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31839/\"]http://secunia.com/advisories/31839/[/url]


[SA31831][b] Fedora update for R and rpy[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-10

Fedora has issued an update for R and rpy. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31831/\"]http://secunia.com/advisories/31831/[/url]


[SA31798] [b]Gentoo update for Amarok[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-09

Gentoo has issued an update for Amarok. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31798/\"]http://secunia.com/advisories/31798/[/url]


[SA31783] [b]Linux Kernel "listxattr" Memory Corruption and CHRP Denial of Service[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-09-08

A security issue and a vulnerability have been reported in the Linux Kernel, which potentially can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31783/\"]http://secunia.com/advisories/31783/[/url]


[SA31771][b] Fedora update for xastir[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-05

Fedora has issued an update for xastir. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31771/\"]http://secunia.com/advisories/31771/[/url]


[SA31755] [b]Gentoo update for mysql[/b]

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-09-05

Gentoo has issued an update for mysql. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31755/\"]http://secunia.com/advisories/31755/[/url]


[SA31800] [b]Ubuntu update for postfix[/b]

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-09-11

Ubuntu has issued an update for postfix. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31800/\"]http://secunia.com/advisories/31800/[/url]


[b]Other:--[/b]

[SA31823] [b]Apple iPod Touch Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Hijacking, Security Bypass, Spoofing, Exposure of sensitive information, System access
Released: 2008-09-10

Multiple vulnerabilities have been reported in Apple iPod touch, which can be exploited by malicious applications to bypass certain security features and by malicious people to poison the DNS cache, spoof TCP connections, or potentially compromise a user's device.

Full Advisory: [url=\"http://secunia.com/advisories/31823/\"]http://secunia.com/advisories/31823/[/url]


[SA31840] [b]Ingate Firewall and SIParator DNS Cache Poisoning[/b]

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-09-10

Ingate has acknowledged a security issue in Ingate Firewall and SIParator, which can potentially be exploited by malicious people to poison the DNS cache.

Full Advisory: [url=\"http://secunia.com/advisories/31840/\"]http://secunia.com/advisories/31840/[/url]


[SA31802] [b]Linksys WRT350N Denial of Service Vulnerability
[/b]
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-09

A vulnerability has been reported in Linksys WRT350N, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31802/\"]http://secunia.com/advisories/31802/[/url]


[SA31770] [b]Netgear WN802T Wireless Access Point Two Vulnerabilities[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-05

Laurent Butti and Julien Tinnes have reported some vulnerabilities in Netgear WN802T Wireless Access Point, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31770/\"]http://secunia.com/advisories/31770/[/url]


[SA31767] [b]D-Link DIR-100 Ethernet Broadband Router URL Filtering Bypass[/b]

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-09-09

Marc Ruef has reported a vulnerability in D-Link DIR-100 Ethernet Broadband Router, which can be exploited by malicious people to bypass the URL filtering functionality.

Full Advisory: [url=\"http://secunia.com/advisories/31767/\"]http://secunia.com/advisories/31767/[/url]


[SA31752] [b]Samsung DVR SHR2040 Denial of Service Vulnerability[/b]

Critical: Not critical
Where: From local network
Impact: DoS
Released: 2008-09-10

Alex Hernandez has reported a vulnerability in Samsung DVR SHR2040, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory: [url=\"http://secunia.com/advisories/31752/\"]http://secunia.com/advisories/31752/[/url]

[b]
Cross Platform:--[/b]

[SA31776] [b]DevalCMS Cross-Site Scripting and Code Execution Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-09-10

IRCRASH has discovered some vulnerabilities in DevalCMS, which can be exploited to conduct cross-site scripting attacks and compromise a
vulnerable user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31776/\"]http://secunia.com/advisories/31776/[/url]


[SA31842] [b]Horde Products MIME Library and HTML Message Script Insertion Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-10

Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31842/\"]http://secunia.com/advisories/31842/[/url]


[SA31818] [b]Stash Multiple SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-09-11

IRCRASH has discovered multiple vulnerabilities in Stash, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31818/\"]http://secunia.com/advisories/31818/[/url]


[SA31817] [b]CMS Buzz "id" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-10

security fears team has reported a vulnerability in CMS Buzz, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31817/\"]http://secunia.com/advisories/31817/[/url]


[SA31816] [b]AvailScript Article Script "aIDS" Cross-Site Scripting and SQL Injection[/b]

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-09-11

sl4x.xuz has reported some vulnerabilities in AvailScript Article Script, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31816/\"]http://secunia.com/advisories/31816/[/url]


[SA31814] AvailScript Photo Album "sid" and "a" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-11

sl4x.xuz has reported some vulnerabilities in AvailScript Photo Album, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31814/\"]http://secunia.com/advisories/31814/[/url]


[SA31813] [b]AvailScript Classmate Script "p" SQL Injection[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-11

Stack has reported a vulnerability in AvailScript Classmate Script, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31813/\"]http://secunia.com/advisories/31813/[/url]


[SA31811] [b]Libera CMS Multiple SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-09-10

Some vulnerabilities have been discovered in Libera CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31811/\"]http://secunia.com/advisories/31811/[/url]


[SA31810] [b]AvailScript Jobs Portal Script "jid" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-11

Cyb3r-1sT has reported a vulnerability in AvailScript Jobs Portal Script, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31810/\"]http://secunia.com/advisories/31810/[/url]


[SA31795] [b]E-Php B2B Trading Marketplace Script "cid" SQL Injection[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-09

r45c4l has reported a vulnerability in E-Php B2B Trading Marketplace Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31795/\"]http://secunia.com/advisories/31795/[/url]


[SA31789][b] Joomla! Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Unknown, Brute force
Released: 2008-09-10

Some vulnerabilities and a security issue have been reported in Joomla!, where some have an unknown impact and others can potentially be exploited by malicious people to conduct brute force attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31789/\"]http://secunia.com/advisories/31789/[/url]


[SA31787] [b]IBM DB2 Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Unknown, Privilege escalation, DoS, System access
Released: 2008-09-08

Some vulnerabilities have been reported in DB2, where some have an unknown impact and others can be exploited by malicious users to perform certain actions with escalated privileges, and by malicious people to cause a DoS or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31787/\"]http://secunia.com/advisories/31787/[/url]


[SA31782] [b]Thyme "uname_search" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-09

Omer Singer has reported a vulnerability in Thyme, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31782/\"]http://secunia.com/advisories/31782/[/url]


[SA31772] [b]Live TV Script "mid" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-11

Cyb3r-1sT has reported a vulnerability in Live TV Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31772/\"]http://secunia.com/advisories/31772/[/url]


[SA31760] [b]MyBB Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-09-10

Some vulnerabilities with unknown impacts have been reported in MyBB.

Full Advisory: [url=\"http://secunia.com/advisories/31760/\"]http://secunia.com/advisories/31760/[/url]


[SA31758][b] Zen Cart Two SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-08

James Bercegay has reported two vulnerabilities in Zen Cart, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31758/\"]http://secunia.com/advisories/31758/[/url]


[SA31751] [b]MemHT Portal "stats_res" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-08

Ams has reported a vulnerability in MemHT Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31751/\"]http://secunia.com/advisories/31751/[/url]


[SA31846] [b]DeluxeBB Cross-Site Scripting Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-11

A vulnerability has been reported in DeluxeBB, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31846/\"]http://secunia.com/advisories/31846/[/url]


[SA31845] [b]phpMyFAQ Cross-Site Scripting Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-11

A vulnerability has been reported in phpMyFAQ, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31845/\"]http://secunia.com/advisories/31845/[/url]


[SA31843] [b]LedgerSMB Denial of Service and SQL Injection Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Manipulation of data, DoS
Released: 2008-09-11

Some vulnerabilities have been reported in LedgerSMB, which can be exploited by malicious users to conduct SQL injection attacks and malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31843/\"]http://secunia.com/advisories/31843/[/url]


[SA31835] [b]Tor World CGI Scripts Cross-Site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-11

Some vulnerabilities have been reported in various Tor World CGI Scripts, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31835/\"]http://secunia.com/advisories/31835/[/url]


[SA31807] [b]Movable Type Multiple Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-09

Some vulnerabilities have been reported in Movable Type, which can be exploited by malicious people to conduct cross-site scripting and
cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31807/\"]http://secunia.com/advisories/31807/[/url]


[SA31805] [b]High Norm Sound Master 2nd Cross-Site Scripting Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-09

A vulnerability has been reported in High Norm Sound Master 2nd, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31805/\"]http://secunia.com/advisories/31805/[/url]


[SA31804] [b]UBB.threads "Forum[]" SQL Injection Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2008-09-09

James Bercegay has reported a vulnerability in UBB.threads, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31804/\"]http://secunia.com/advisories/31804/[/url]


[SA31803] [b]phpAuction "phpinfo.php" Information Disclosure
[/b]
Critical: Less critical
Where: From remote
Impact: Exposure of system information
Released: 2008-09-08

Beenu Arora has discovered a vulnerability in phpAuction, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31803/\"]http://secunia.com/advisories/31803/[/url]

--

[SA31801] [b]Silentum LoginSys Multiple Cross-site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-08

Multiple vulnerabilities have been discovered in Silentum LoginSys, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31801/\"]http://secunia.com/advisories/31801/[/url]


[SA31781] [b]libpng "png_push_read_zTXt()" Off-By-One Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-08

A vulnerability has been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31781/\"]http://secunia.com/advisories/31781/[/url]


[SA31768] [b]Avactis Shopping Cart "checkout.php" Cross-Site Scripting[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-08

Russ McRee has discovered two vulnerabilities in Avactis Shopping Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31768/\"]http://secunia.com/advisories/31768/[/url]


[SA31757] [b]Drupal Content Construction Kit Script Insertion Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-05

Some vulnerabilities have been reported in the Drupal Content Construction Kit (CCK), which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31757/\"]http://secunia.com/advisories/31757/[/url]


[SA31769] [b]MySQL Empty Bit-String Literal Denial of Service[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-11

A vulnerability has been reported in MySQL, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31769/\"]http://secunia.com/advisories/31769/[/url]


[SA31824] [b]Apple iTunes Privilege Escalation Vulnerability[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-10

A vulnerability has been reported in Apple iTunes, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31824/\"]http://secunia.com/advisories/31824/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Alerts - September 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of September 18 2008[/b][/i]

[u][b]Windows:--[/b][/u]

[b][SA31888] LANDesk Multiple Products Buffer Overflow Vulnerability[/b]

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-09-16

A vulnerability has been reported in multiple LANDesk products, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31888/\"]http://secunia.com/advisories/31888/[/url]


[b][SA31852] Personal FTP Server "RETR" Denial of Service Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-17

Shinnok raydenxy has discovered a vulnerability in Personal FTP Server, which can be exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31852/\"]http://secunia.com/advisories/31852/[/url]


[b][SA31883] Microsoft Windows "WRITE_ANDX" SMB Packet Handling Denial of Service[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-16

A vulnerability has been reported in Microsoft Windows Vista, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31883/\"]http://secunia.com/advisories/31883/[/url]


[u][b]UNIX/Linux:--[/b][/u]

[b][SA31939] SUSE update for gnutls[/b]

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-18

SuSE has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31939/\"]http://secunia.com/advisories/31939/[/url]


[b][SA31902] Adobe Illustrator Unspecified Code Execution Vulnerabilities
[/b]
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-17

Some vulnerabilities have been reported in Adobe Illustrator, which can potentially be exploited by malicious people to compromise a vulnerable
system.

Full Advisory: [url=\"http://secunia.com/advisories/31902/\"]http://secunia.com/advisories/31902/[/url]


[b][SA31894] Data Dynamics ActiveReports ARViewer2 ActiveX Control Insecure Methods[/b]

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-09-18

Tan Chew Keong has reported some vulnerabilities in Data Dynamics ActiveReports, which can be exploited by malicious people to overwrite
arbitrary files and compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31894/\"]http://secunia.com/advisories/31894/[/url]


[b][SA31882] Apple Mac OS X Security Update Fixes Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-16

Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

Full Advisory: [url=\"http://secunia.com/advisories/31882/\"]http://secunia.com/advisories/31882/[/url]


[b][SA31906] Kolab Server ClamAV Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-15

A vulnerability has been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31906/\"]http://secunia.com/advisories/31906/[/url]


[b][SA31891] Fedora update for tomcat5[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-09-17

Fedora has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31891/\"]http://secunia.com/advisories/31891/[/url]

[b]
[SA31890] NetBSD IPsec-Tools racoon Phase 1 Handler Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-16

A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31890/\"]http://secunia.com/advisories/31890/[/url]


[b][SA31886] rPath update for wireshark[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-18

rPath has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31886/\"]http://secunia.com/advisories/31886/[/url]


[b][SA31885] Debian update for openssh[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-17

Debian has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31885/\"]http://secunia.com/advisories/31885/[/url]


[b][SA31870] Fedora update for wordpress[/b]

Critical: Moderately critical
Where: From remote
Impact: Brute force
Released: 2008-09-12

Fedora has issued an update for wordpress. This fixes a vulnerability, which can be exploited by malicious people to guess automatically generated passwords.

Full Advisory: [url=\"http://secunia.com/advisories/31870/\"]http://secunia.com/advisories/31870/[/url]


[b][SA31868] Red Hat update for libxml2[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-12

Red Hat has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31868/\"]http://secunia.com/advisories/31868/[/url]


[b][SA31865] Fedora update for tomcat6[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-09-12

Fedora has issued an update for tomcat6. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31865/\"]http://secunia.com/advisories/31865/[/url]


[b][SA31864] Fedora update for wireshark[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-12

Fedora has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31864/\"]http://secunia.com/advisories/31864/[/url]


[b][SA31860] Red Hat update for libxml2[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-12

Red Hat has issued an update for libxml2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31860/\"]http://secunia.com/advisories/31860/[/url]


[b][SA31856] Ubuntu update for freetype[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-12

Ubuntu has issued an update for freetype. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31856/\"]http://secunia.com/advisories/31856/[/url]


[b][SA31855] Ubuntu update for libxml2[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-12

Ubuntu has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/31855/\"]http://secunia.com/advisories/31855/[/url]


[b][SA31847] pdnsd DNS Cache Poisoning and Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-16

Some vulnerabilities have been reported in pdnsd, which can be exploited by malicious people to poison the DNS cache and cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31847/\"]http://secunia.com/advisories/31847/[/url]


[b][SA31878] Sun Solaris update for bzip2[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-15

Sun has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31878/\"]http://secunia.com/advisories/31878/[/url]

[b]
[SA31869] Red Hat update for bzip2[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-16

Red Hat has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31869/\"]http://secunia.com/advisories/31869/[/url]

[b]
[SA31866] Fedora update for httrack[/b]

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-09-12

Fedora has issued an update for httrack. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31866/\"]http://secunia.com/advisories/31866/[/url]


[b][SA31863] cPanel Fantastico De Luxe "fantasticopath" Local File Inclusion[/b]

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-16

joker_1 has reported a vulnerability in the Fantastico De Luxe module for cPanel, which can be exploited by malicious users to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31863/\"]http://secunia.com/advisories/31863/[/url]


[b][SA31913] Fedora Directory Server Denial of Service Vulnerabilities[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-18

Some vulnerabilities have been reported in Fedora Directory Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31913/\"]http://secunia.com/advisories/31913/[/url]


[b][SA31867] Fedora update for fedora-ds-base[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-12

Fedora has issued an update for fedora-ds-base. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31867/\"]http://secunia.com/advisories/31867/[/url]


[b][SA31861] Fedora update for ipa[/b]

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-09-12

Fedora has issued an update for ipa. This fixes a vulnerability, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31861/\"]http://secunia.com/advisories/31861/[/url]


[b][SA31895] Sun Solaris Editors Tag File Handling Privilege Escalation Vulnerability[/b]

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-18

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31895/\"]http://secunia.com/advisories/31895/[/url]


[b][SA31881] Debian update for linux-2.6.24[/b]

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-09-12

Debian has issued an update for linux-2.6.24. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and disclose potentially sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31881/\"]http://secunia.com/advisories/31881/[/url]


[u][b]Other:--[/b][/u]

[b][SA31900] Apple iPhone Multiple Vulnerabilities[/b]

Critical: Highly critical
Where: From remote
Impact: Hijacking, Security Bypass, Spoofing, Exposure of sensitive information, System access
Released: 2008-09-15

Multiple vulnerabilities have been reported in Apple iPhone, which can be exploited by malicious applications to bypass certain security features, and by malicious people to poison the DNS cache, spoof TCP connections, or potentially compromise a user's device.

Full Advisory: [url=\"http://secunia.com/advisories/31900/\"]http://secunia.com/advisories/31900/[/url]


[b][SA31848] Accellion File Transfer Appliance "api_error_email.html" Security Bypass[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-09-18

Eric BEAULIEU has reported a vulnerability in Accellion File Transfer Appliance, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31848/\"]http://secunia.com/advisories/31848/[/url]


[b][SA31905] Nortel Switched Firewall Products SNMPv3 HMAC Authentication Bypass[/b]

Critical: Less critical
Where: From local network
Impact: Spoofing
Released: 2008-09-15

Nortel has acknowledged a vulnerability in Nortel Switched Firewall products, which can be exploited by malicious people to spoof authenticated SNMPv3 packets.

Full Advisory: [url=\"http://secunia.com/advisories/31905/\"]http://secunia.com/advisories/31905/[/url]


[b][SA31857] Nokia E90 Communicator Denial of Service Vulnerability[/b]

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-16

wins.mallow has reported a vulnerability in Nokia E90 Communicator, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31857/\"]http://secunia.com/advisories/31857/[/url]


[u][b]Cross Platform:--[/b][/u]

[b][SA31916] TECHNOTE "shop_this_skin_path" File Inclusion Vulnerability[/b]

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-18

webDEViL has reported a vulnerability in TECHNOTE, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31916/\"]http://secunia.com/advisories/31916/[/url]


[b][SA31874] phpRealty "INC" File Inclusion Vulnerability[/b]

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-17

ka0x has discovered a vulnerability in phpRealty, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31874/\"]http://secunia.com/advisories/31874/[/url]


[b][SA31923] E-Php Content Management System "es_id" SQL Injection[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-18

HaCker_Egy has reported a vulnerability in E-Php Content Management System, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31923/\"]http://secunia.com/advisories/31923/[/url]


[b][SA31918] TYPO3 phpMyAdmin Extension PHP Code Execution Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-18

A vulnerability has been reported in the phpMyAdmin extension for TYPO3, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31918/\"]http://secunia.com/advisories/31918/[/url]


[SA31910] Ruby on Rails ":offset" and ":limit" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-15

Some vulnerabilities have been reported in Ruby on Rails, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31910/\"]http://secunia.com/advisories/31910/[/url]


[b][SA31909] Ruby on Rails ":offset" and ":limit" SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-15

Some vulnerabilities have been reported in Ruby on Rails, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31909/\"]http://secunia.com/advisories/31909/[/url]


[b][SA31893] DotNetNuke Multiple Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Privilege escalation, System access
Released: 2008-09-12

Some vulnerabilities have been reported in DotNetNuke, which can be exploited by malicious users to gain escalated privileges and by malicious people to bypass certain security restrictions and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31893/\"]http://secunia.com/advisories/31893/[/url]


[b][SA31892] WebSphere Application Server Unspecified Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-09-15

A vulnerability with an unknown impact has been reported in WebSphere Application Server.

Full Advisory: [url=\"http://secunia.com/advisories/31892/\"]http://secunia.com/advisories/31892/[/url]


[b][SA31884] phpMyAdmin "sort_by" PHP Code Execution[/b]

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-16

Norman Hippert has reported a vulnerability in phpMyAdmin, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31884/\"]http://secunia.com/advisories/31884/[/url]


[b][SA31879] TalkBack "language" Local File Inclusion[/b]

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-09-15

SirGod has discovered a vulnerability in TalkBack, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31879/\"]http://secunia.com/advisories/31879/[/url]


[b][SA31876] OSADS Unspecified Security Issue
[/b]
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-09-16

A security issue with an unknown impact has been reported in OSADS.

Full Advisory: [url=\"http://secunia.com/advisories/31876/\"]http://secunia.com/advisories/31876/[/url]


[b][SA31875] Ruby on Rails ":offset" and ":limit" SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-15

Some vulnerabilities have been reported in Ruby on Rails, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31875/\"]http://secunia.com/advisories/31875/[/url]


[b][SA31873] Pre Real Estate Listings "c" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-16

JosS has reported a vulnerability in Pre Real Estate Listings, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31873/\"]http://secunia.com/advisories/31873/[/url]


[b][SA31872] PSCRIPT Forum "showprofil.php" SQL Injection[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-15

-tmh- has reported a vulnerability in Powies PSCRIPT Forum (pForum), which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31872/\"]http://secunia.com/advisories/31872/[/url]


[b][SA31871] iBoutique "cat" SQL Injection Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-16

r45c4l and h4x0r have reported a vulnerability in iBoutique, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31871/\"]http://secunia.com/advisories/31871/[/url]


[b][SA31854] Unreal Engine Format String Vulnerabilities and Denial of Service[/b]

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-12

Luigi Auriemma has reported some vulnerabilities in the Unreal Engine, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31854/\"]http://secunia.com/advisories/31854/[/url]


[b][SA31853] Link Bid Two SQL Injection Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-16

SirGod has discovered two vulnerabilities in Link Bid, which can be exploited by malicious people or users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31853/\"]http://secunia.com/advisories/31853/[/url]


[b][SA31851] YourOwnBux Security Bypass Vulnerability[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-09-15

Tec-n0x has reported a vulnerability in YourOwnBux, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31851/\"]http://secunia.com/advisories/31851/[/url]


[b][SA31850] Free PHP VX Guestbook Security Bypass Vulnerabilities[/b]

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-09-16

Two vulnerabilities have been reported in Free PHP VX Guestbook, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31850/\"]http://secunia.com/advisories/31850/[/url]


[b][SA31938] Quick.Cart "admin.php" Cross-Site Scripting[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-18

John Cobb has discovered a vulnerability in Quick.Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31938/\"]http://secunia.com/advisories/31938/[/url]


[b][SA31914] Drupal Link To Us Module "Link page header" Script Insertion[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-18

Justin C. Klein Keane has reported a vulnerability in the Link To Us module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31914/\"]http://secunia.com/advisories/31914/[/url]


[b][SA31912] Gallery Symlink ZIP Archive Information Disclosure[/b]

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-18

A vulnerability has been reported in Gallery, which can be exploited by malicious users to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31912/\"]http://secunia.com/advisories/31912/[/url]


[b][SA31908] Drupal Talk Module Script Insertion and Security Bypass[/b]

Critical: Less critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Released: 2008-09-18

Two vulnerabilities have been reported in the Talk module for Drupal, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31908/\"]http://secunia.com/advisories/31908/[/url]


[b][SA31904] IBM HTTP Server mod_proxy Interim Responses Denial of Service[/b]

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-09-17

IBM has acknowledged a vulnerability in IBM HTTP Server, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31904/\"]http://secunia.com/advisories/31904/[/url]


[b][SA31896] FlexNET Connect Insecure Script Execution Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-09-18

Brian Dowling has reported a vulnerability in FlexNET Connect, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31896/\"]http://secunia.com/advisories/31896/[/url]


[b][SA31889] Drupal Mailsave Module MIME Type Script Insertion[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-18

A vulnerability has been reported in the Mailsave module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31889/\"]http://secunia.com/advisories/31889/[/url]


[b][SA31877] Drupal Mailhandler Module Unspecified SQL Injection[/b]

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Privilege escalation
Released: 2008-09-18

A vulnerability has been reported in the Mailhandler module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31877/\"]http://secunia.com/advisories/31877/[/url]


[b][SA31859] NooMS Two Cross-Site Scripting Vulnerabilities[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-16

Khashayar Fereidani has discovered two vulnerabilities in NooMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31859/\"]http://secunia.com/advisories/31859/[/url]

[b]
[SA31858] Gallery Flash Animation Script Insertion Vulnerability[/b]

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-18

A vulnerability has been reported in Gallery, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31858/\"]http://secunia.com/advisories/31858/[/url]

[b]
[SA31899] FFmpeg libavformat gifdec.c GIF Processing Denial of Service[/b]

Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-09-18

A vulnerability has been reported in FFmpeg, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31899/\"]http://secunia.com/advisories/31899/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Alerts - September 2008

Post by Tami »

[url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Listings

[b]Windows:--[/b]

[SA31950] BurnAware NMSDVDX ActiveX Control Insecure Methods

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-24

A vulnerability has been reported in BurnAware, which can be exploited by malicious people to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31950/\"]http://secunia.com/advisories/31950/[/url]


[SA31949] CDBurnerXP Pro NMSDVDX ActiveX Control Insecure Methods

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-23

bruiser has reported a vulnerability in CDBurnerXP, which can be exploited by malicious people to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31949/\"]http://secunia.com/advisories/31949/[/url]


[SA32026] Symantec Veritas NetBackup Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, System access
Released: 2008-09-25

Some vulnerabilities have been reported in Symantec Veritas NetBackup, which can be exploited by malicious users to bypass certain security
restrictions and by malicious people to overwrite arbitrary files or compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32026/\"]http://secunia.com/advisories/32026/[/url]


[SA31999] Dataspade Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-23

r0t has reported some vulnerabilities in Dataspade, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31999/\"]http://secunia.com/advisories/31999/[/url]


[SA31983] Vignette VCM Unspecified Security Bypass Vulnerability

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-09-23

A vulnerability has been reported in Vignette, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/31983/\"]http://secunia.com/advisories/31983/[/url]


[SA31941] G DATA Products GDTdiIcpt.sys Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-19

Tobias Klein has reported a vulnerability in various G DATA products, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31941/\"]http://secunia.com/advisories/31941/[/url]


[b]UNIX/Linux:--[/b]

[SA32018] Mac OS X Java Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-25

Some vulnerabilities have been reported and acknowledged in Java for Mac OS X, which can be exploited by malicious people to cause a DoS (Denial of Service), to bypass certain security restrictions, disclose system information or potentially sensitive information, or to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32018/\"]http://secunia.com/advisories/32018/[/url]


[SA32012] Ubuntu update for firefox and xulrunner

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Ubuntu has issued an update for firefox, firefox-3.0, and xulrunner-1.9. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32012/\"]http://secunia.com/advisories/32012/[/url]


[SA31987] Red Hat update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Red Hat has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31987/\"]http://secunia.com/advisories/31987/[/url]


[SA31985] Red Hat update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31985/\"]http://secunia.com/advisories/31985/[/url]


[SA31982] SUSE Update for Multiple Packages

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-22

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), and by malicious people to cause a DoS (Denial of Service), conduct cross-site scripting attacks, bypass certain security restrictions, disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31982/\"]http://secunia.com/advisories/31982/[/url]


[SA32034] Fedora update for phpMyAdmin

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-09-25

Fedora has issued an update for phpMyAdmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32034/\"]http://secunia.com/advisories/32034/[/url]


[SA32006] Faad2 "decodeMP4file()" Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-09-24

A vulnerability has been reported in Faad2, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32006/\"]http://secunia.com/advisories/32006/[/url]


[SA31995] Gentoo update for newsbeuter

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-09-23

Gentoo has issued an update for newsbeuter. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31995/\"]http://secunia.com/advisories/31995/[/url]


[SA31994] MailWatch for MailScanner "doc" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-25

dun has discovered a vulnerability in MailWatch for MailScanner, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31994/\"]http://secunia.com/advisories/31994/[/url]


[SA31972] Gentoo update for mantisbt

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, System access
Released: 2008-09-22

Gentoo has issued an update for mantisbt. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system and malicious people to conduct cross-site scripting and cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31972/\"]http://secunia.com/advisories/31972/[/url]


[SA31971] Gentoo update for havp

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-22

Gentoo has issued an update for havp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31971/\"]http://secunia.com/advisories/31971/[/url]


[SA31963] strongSwan IKEv2 Daemon Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-22

A vulnerability has been reported in strongSwan, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31963/\"]http://secunia.com/advisories/31963/[/url]


[SA31960] Debian update for phpmyadmin

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, System access
Released: 2008-09-22

Debian has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious, local users to conduct cross-site scripting attacks, by malicious users to compromise a vulnerable system, and by malicious people to conduct spoofing and cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31960/\"]http://secunia.com/advisories/31960/[/url]


[SA31959] Debian update for horde3

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-22

Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31959/\"]http://secunia.com/advisories/31959/[/url]


[SA31942] VMware ESX / ESXi openwsman HTTP Basic Authentication Buffer Overflow

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-09-19

VMware has issued an update for openwsman. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31942/\"]http://secunia.com/advisories/31942/[/url]


[SA31991] Gentoo update for bitlbee

Critical: Less critical
Where: From remote
Impact: Hijacking, Security Bypass
Released: 2008-09-24

Gentoo has issued an update for bitlbee. This fixes some security issues, which can be exploited by malicious people to bypass certain security restrictions and hijack accounts.

Full Advisory: [url=\"http://secunia.com/advisories/31991/\"]http://secunia.com/advisories/31991/[/url]


[SA31964] Debian update for twiki

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-09-22

Debian has issued an update for twiki. This fixes a security issue, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/31964/\"]http://secunia.com/advisories/31964/[/url]


[SA31961] Debian update for python-django

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, DoS
Released: 2008-09-22

Debian has issued an update for python-django. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site request forgery attacks or to potentially cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31961/\"]http://secunia.com/advisories/31961/[/url]


[SA32002] HP-UX rpcbind Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-09-23

A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32002/\"]http://secunia.com/advisories/32002/[/url]


[SA31996] Gentoo update for R

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-23

Gentoo has issued an update for R. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31996/\"]http://secunia.com/advisories/31996/[/url]


[SA31970] Aegis "aegis.cgi" Insecure Temporary Files

Critical: Not critical
Where: From remote
Impact: Privilege escalation
Released: 2008-09-25

A security issue has been reported in Aegis, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/31970/\"]http://secunia.com/advisories/31970/[/url]


[SA32037] Fedora update for initscripts

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-09-25

Fedora has issued an update for initscripts. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32037/\"]http://secunia.com/advisories/32037/[/url]


[SA32023] Red Hat update for kernel

Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information, DoS
Released: 2008-09-25

Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, to disclose potentially sensitive information, or to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32023/\"]http://secunia.com/advisories/32023/[/url]


[SA31986] Gentoo update for postfix

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-09-22

Gentoo has issued an update for postfix. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/31986/\"]http://secunia.com/advisories/31986/[/url]


[b]Other:--[/b]

[SA32013] Cisco Unified Communications Manager SIP Denial of Service Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-09-25

Some vulnerabilities have been reported in Cisco Unified Communications Manager, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32013/\"]http://secunia.com/advisories/32013/[/url]


[SA31990] Cisco IOS Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-09-25

Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31990/\"]http://secunia.com/advisories/31990/[/url]


[b]Cross Platform:--[/b]

[SA32011] Mozilla Firefox 3 Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32011/\"]http://secunia.com/advisories/32011/[/url]


[SA32010] Mozilla SeaMonkey Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Some vulnerabilities have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32010/\"]http://secunia.com/advisories/32010/[/url]


[SA32007] Mozilla Thunderbird Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32007/\"]http://secunia.com/advisories/32007/[/url]


[SA31984] Mozilla Firefox 2 Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-09-24

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31984/\"]http://secunia.com/advisories/31984/[/url]


[SA31978] Advanced Electron Forum PHP Code Execution Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-22

James Bercegay has discovered some vulnerabilities in Advanced Electron Forum (AEF), which can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31978/\"]http://secunia.com/advisories/31978/[/url]


[SA31951] Chilkat XML ActiveX Component Insecure Methods

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-09-23

shinnai has discovered some vulnerabilities in Chilkat XML ActiveX Component, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/31951/\"]http://secunia.com/advisories/31951/[/url]


[SA31947] Basebuilder "mj_config[src_path]" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-09-24

dun has discovered a vulnerability in Basebuilder, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/31947/\"]http://secunia.com/advisories/31947/[/url]


[SA32000] InterTech WCMS "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-24

GeNiUs IrAQI has reported a vulnerability in InterTech WCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32000/\"]http://secunia.com/advisories/32000/[/url]


[SA31993] PHPcounter "l" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-25

dun has discovered a vulnerability in PHPcounter, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31993/\"]http://secunia.com/advisories/31993/[/url]


[SA31981] PHP Pro Bid Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-23

Jan van Niekerk has reported some vulnerabilities in PHP Pro Bid, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31981/\"]http://secunia.com/advisories/31981/[/url]


[SA31979] web-cp "filelocation" File Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-25

GoLd_M has discovered a vulnerability in web-cp, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31979/\"]http://secunia.com/advisories/31979/[/url]


[SA31975] Arcadem "articlecat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-23

A vulnerability has been reported in Arcadem, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31975/\"]http://secunia.com/advisories/31975/[/url]


[SA31967] BlueCUBE "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-23

r45c4l has reported a vulnerability is BlueCUBE CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31967/\"]http://secunia.com/advisories/31967/[/url]


[SA31965] ClanSphere Unspecified Information Disclosure Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-09-22

Some vulnerabilities have been reported in ClanSphere, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31965/\"]http://secunia.com/advisories/31965/[/url]


[SA31957] easyLink "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-09-22

Egypt Coder has reported a vulnerability in easyLink, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31957/\"]http://secunia.com/advisories/31957/[/url]


[SA31956] Barcode Generator "code" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-25

dun has discovered a vulnerability in Barcode Generator, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31956/\"]http://secunia.com/advisories/31956/[/url]


[SA31954] MyFWB "page" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-22

0x90 has reported a vulnerability in MyFWB, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31954/\"]http://secunia.com/advisories/31954/[/url]


[SA31953] OpenElec "obj" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-09-25

dun has reported a vulnerability in OpenElec, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/31953/\"]http://secunia.com/advisories/31953/[/url]


[SA31952] Plaincart "p" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-23

r45c4l has discovered a vulnerability in Plaincart, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31952/\"]http://secunia.com/advisories/31952/[/url]


[SA31945] 6rbScript SQL Injection and Local File Disclosure

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-09-24

Two vulnerabilities have been reported in 6rbScript, which can be exploited by malicious people to disclose sensitive information or to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31945/\"]http://secunia.com/advisories/31945/[/url]


[SA31940] NetArt Media Real Estate Portal "ad" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-22

!R4Q!4N H4CK3R has reported a vulnerability in NetArt Media Real Estate Portal, which can be exploited by malicious people to conduct SQL
injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31940/\"]http://secunia.com/advisories/31940/[/url]


[SA32022] Drupal Simplenews Module Newsletter Categories Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-25

A vulnerability has been reported in the Simplenews module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32022/\"]http://secunia.com/advisories/32022/[/url]


[SA32015] Drupal Brilliant Gallery Module "bgchecklist/save" SQL Injection

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-09-25

Justin C. Klein Keane has reported a vulnerability in the Brilliant Gallery module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32015/\"]http://secunia.com/advisories/32015/[/url]


[SA32014] bitweaver Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-25

Michael Schratt has discovered some vulnerabilities in bitweaver, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32014/\"]http://secunia.com/advisories/32014/[/url]


[SA32009] Drupal Ajax Checklist Module SQL Injection and Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-09-25

Two vulnerabilities have been reported in the Ajax Checklist module for Drupal, which can be exploited by malicious users to conduct script
insertion and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32009/\"]http://secunia.com/advisories/32009/[/url]


[SA31998] DataLife Engine "admin.php" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-24

A vulnerability has been reported in DataLife Engine, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31998/\"]http://secunia.com/advisories/31998/[/url]


[SA31992] TYPO3 phpMyAdmin Extension Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-24

A vulnerability has been reported in the phpMyAdmin extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31992/\"]http://secunia.com/advisories/31992/[/url]


[SA31980] fuzzylime (cms) "user" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-23

Fabian Fingerle has reported a vulnerability in Fuzzylime CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31980/\"]http://secunia.com/advisories/31980/[/url]


[SA31974] phpMyAdmin Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-23

A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31974/\"]http://secunia.com/advisories/31974/[/url]


[SA31973] Achievo "atkaction" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-23

A vulnerability has been discovered in Achievo, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31973/\"]http://secunia.com/advisories/31973/[/url]


[SA31968] BluePage CMS Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-25

David Vieira-Kurz has reported some vulnerabilities in BluePage CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31968/\"]http://secunia.com/advisories/31968/[/url]


[SA31948] phpShop Session Fixation Vulnerability

Critical: Less critical
Where: From remote
Impact: Hijacking
Released: 2008-09-19

Michael Schratt has discovered a vulnerability in phpShop, which can be exploited by malicious people to conduct session fixation attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31948/\"]http://secunia.com/advisories/31948/[/url]


[SA31946] TYPO3 sr_freecap Extension Unspecified Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-09-24

A vulnerability has been reported in the freeCap CAPTCHA (sr_freecap) extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/31946/\"]http://secunia.com/advisories/31946/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”