Secunia Updates - November 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - November 2008

Post by Tami »

[b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 6 2008[/b]

[b]Windows:--[/b]

[SA32546] NOS Microsystems getPlus ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05

A vulnerability has been reported in the NOS Microsystems getPlus ActiveX control, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32546/\"]http://secunia.com/advisories/32546/[/url]

--

[SA32513] Chilkat Crypt ActiveX Component "WriteFile()" Insecure Method

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-04

shinnai has discovered a vulnerability in Chilkat Crypt ActiveX Component, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32513/\"]http://secunia.com/advisories/32513/[/url]


[b]UNIX/Linux:--[/b]

[SA32538] Gentoo update for opera

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-11-04

Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to disclose system and potentially sensitive information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32538/\"]http://secunia.com/advisories/32538/[/url]

--

[SA32514] Dns2tcp "dns_decode()" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-03

A vulnerability has been reported in Dns2tcp, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32514/\"]http://secunia.com/advisories/32514/[/url]

--

[SA32493] Mahara Multiple Command Execution Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05

Some vulnerabilities have been reported in Mahara, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32493/\"]http://secunia.com/advisories/32493/[/url]

--

[SA32489] Fedora update for openoffice.org

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-10-31

Fedora has issued an update for openoffice.org. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32489/\"]http://secunia.com/advisories/32489/[/url]

--

[SA32530] Ubuntu update for enscript

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-04

Ubuntu has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32530/\"]http://secunia.com/advisories/32530/[/url]

--

[SA32521] Fedora update for enscript

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-06

Fedora has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32521/\"]http://secunia.com/advisories/32521/[/url]

--

[SA32518] Fedora update for ktorrent

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-11-06

Fedora has issued an update for ktorrent. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system and malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32518/\"]http://secunia.com/advisories/32518/[/url]

--

[SA32512] Fedora update for uw-imap

Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-06

Fedora has issued an update for uw-imap. This fixes some vulnerabilities, which can be exploited by malicious, local users to potentially gain escalated privileges, and by malicious people to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32512/\"]http://secunia.com/advisories/32512/[/url]

--

[SA32509] Ubuntu update for kernel

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-05

Ubuntu has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32509/\"]http://secunia.com/advisories/32509/[/url]

--

[SA32496] Gentoo update for libspf2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-10-31

Gentoo has issued an update for libspf2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32496/\"]http://secunia.com/advisories/32496/[/url]

--

[SA32488] VMware ESX Server update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-10-31

VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32488/\"]http://secunia.com/advisories/32488/[/url]

--

[SA32483] UW-imapd "tmail" and "dmail" Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-03

Two vulnerabilities have been reported in UW-imapd, which can be exploited by malicious, local users to potentially gain escalated privileges, and by malicious people to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32483/\"]http://secunia.com/advisories/32483/[/url]

--

[SA32545] HP-UX Xserver Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS, System access
Released: 2008-11-04

HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious, local users to disclose potentially sensitive information or gain escalated privileges, and by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32545/\"]http://secunia.com/advisories/32545/[/url]

--

[SA32553] PTK Command Execution Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-06

A vulnerability has been reported in PTK, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32553/\"]http://secunia.com/advisories/32553/[/url]

--

[SA32543] Nagios Cross-Site Request Forgery Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05

A vulnerability has been reported in Nagios, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32543/\"]http://secunia.com/advisories/32543/[/url]

--

[SA32482] Fedora update for phpMyAdmin

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-10-31

Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32482/\"]http://secunia.com/advisories/32482/[/url]

--

[SA32560] Net-snmp GETBULK Integer Overflow Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-03

A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32560/\"]http://secunia.com/advisories/32560/[/url]

--

[SA32539] Red Hat update for net-snmp

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-04

Red Hat has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32539/\"]http://secunia.com/advisories/32539/[/url]

--

[SA32531] Fedora update for net-snmp

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-06

Fedora has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32531/\"]http://secunia.com/advisories/32531/[/url]

--

[SA32578] Debian update for mysql-dfsg-5.0

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-06

Debian has issued an update for mysql-dfsg-5.0. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32578/\"]http://secunia.com/advisories/32578/[/url]

--

[SA32554] Novell Access Manger Identity Server X509 Session Improper Termination

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-05

A security issue has been reported in Novell Access Manager Identity Server, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32554/\"]http://secunia.com/advisories/32554/[/url]

--

[SA32544] HP System Management Homepage Unspecified Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-04

A vulnerability has been reported in HP System Management Homepage (SMH), which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32544/\"]http://secunia.com/advisories/32544/[/url]

--

[SA32485] Red hat update for kernel

Critical: Less critical
Where: Local system
Impact: DoS, Privilege escalation, Exposure of sensitive information
Released: 2008-11-04

Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), to disclose potentially sensitive information, or to potentially gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32485/\"]http://secunia.com/advisories/32485/[/url]

--

[SA32566] Ubuntu update for system-tools-backends

Critical: Not critical
Where: From remote
Impact: Brute force
Released: 2008-11-06

Ubuntu has issued an update for system-tools-backend. This fixes a weakness, which can be exploited by malicious people to conduct brute force attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32566/\"]http://secunia.com/advisories/32566/[/url]

--

[SA32510] Linux Kernel "hfsplus_find_cat()" and "hfsplus_block_allocate()" Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-04

Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32510/\"]http://secunia.com/advisories/32510/[/url]

--

[SA32487] CrossFire Map Pack combine.pl Insecure Temporary Files

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-10-31

A security issue has been reported in CrossFire, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32487/\"]http://secunia.com/advisories/32487/[/url]


[b]Other:--[/b]

[SA32498] SonicWALL Products Content Filtering Service Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-10-31

A vulnerability has been reported in various SonicWALL products, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32498/\"]http://secunia.com/advisories/32498/[/url]

--

[SA32573] Cisco IOS / CatOS VLAN Trunking Protocol Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-06

A vulnerability has been reported in Cisco IOS/CatOS, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32573/\"]http://secunia.com/advisories/32573/[/url]


[b]Cross Platform:--
[/b]
[SA32569] VLC Media Player CUE and RealText Processing Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-06

Two vulnerabilities have been reported in VLC Media Player, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32569/\"]http://secunia.com/advisories/32569/[/url]

--

[SA32551] Joomla Dada Mail Manager Component "mosConfig_absolute_path" File Inclusion

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-06

NoGe has discovered a vulnerability in the Dada Mail Manager component for Joomla, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32551/\"]http://secunia.com/advisories/32551/[/url]

--

[SA32533] Joomla VirtueMart Google Base Component "mosConfig_absolute_path" File Inclusion

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-05

NoGe has discovered a vulnerability in the VirtueMart Google Base component for Joomla, which can be exploited by malicious people to compromise a vulnerable system

Full Advisory: [url=\"http://secunia.com/advisories/32533/\"]http://secunia.com/advisories/32533/[/url]

--

[SA32520] Joomla Flash Tree Gallery Component "mosConfig_live_site" File Inclusion

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-03

NoGe has reported a vulnerability in the Flash Tree Gallery component for Joomla!, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32520/\"]http://secunia.com/advisories/32520/[/url]

--

[SA32516] Simple Machines Forum Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information, System access
Released: 2008-11-05

Some vulnerabilities have been discovered in Simple Machines Forum, which can be exploited by malicious people to conduct cross-site request forgery attacks and by malicious users to disclose potentially sensitive information and compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32516/\"]http://secunia.com/advisories/32516/[/url]

--

[SA32515] Way Of The Warrior "plancia" File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-05

Some vulnerabilities have been discovered in Way Of The Warrior (WOTW), which can be exploited by malicious people to disclose sensitive information or compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32515/\"]http://secunia.com/advisories/32515/[/url]

--

[SA32579] Five Dollar Scripts Drinks Script "recid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06

Ex Tacy has reported a vulnerability in Five Dollar Scripts Drinks script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32579/\"]http://secunia.com/advisories/32579/[/url]

--

[SA32564] PHPX "news_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06

StAkeR has discovered a vulnerability in PHPX, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32564/\"]http://secunia.com/advisories/32564/[/url]

--

[SA32563] Pre Podcast Portal "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-06

G4N0K has reported a vulnerability in Pre Podcast Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32563/\"]http://secunia.com/advisories/32563/[/url]

--

[SA32559] GeSHi Unspecified Code Execution Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-03

A vulnerability has been reported in GeSHI, which can potentially be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32559/\"]http://secunia.com/advisories/32559/[/url]

--

[SA32558] SFS Multiple Products "cat_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

A vulnerability has been reported in multiple SFS products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32558/\"]http://secunia.com/advisories/32558/[/url]

--

[SA32557] PreProjects Products Cookie Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-06

G4N0K has reported a vulnerability in multiple PreProjects products, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32557/\"]http://secunia.com/advisories/32557/[/url]

--

[SA32556] nicLOR Sito Includefile "page_file" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-05

StAkeR has discovered a vulnerability in nicLOR Sito Includefile, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32556/\"]http://secunia.com/advisories/32556/[/url]

--

[SA32552] SFS EZ BIZ PRO "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

d3b4g has reported a vulnerability in SFS EZ BIZ PRO, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32552/\"]http://secunia.com/advisories/32552/[/url]

--

[SA32550] SFS EZ Webring "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

d3b4g has reported a vulnerability in SFS EZ Webring, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32550/\"]http://secunia.com/advisories/32550/[/url]

--

[SA32548] Tribiq CMS "template_path" Cross-Site Scripting and Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-11-03

Some vulnerabilities have been discovered in Tribiq CMS, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32548/\"]http://secunia.com/advisories/32548/[/url]

--

[SA32547] PHP Auto Listings "itemno" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-06

G4N0K has reported a vulnerability in PHP Auto Listings, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32547/\"]http://secunia.com/advisories/32547/[/url]

--

[SA32542] Logz CMS "art" SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-03

Some vulnerabilities have been discovered in Logz CMS, which can be
exploited by malicious people to conduct cross-site scripting and SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/32542/\"]http://secunia.com/advisories/32542/[/url]

--

[SA32540] U-Mail "edit.php" Arbitrary File Creation Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, System access
Released: 2008-11-05

Shennan Wang has reported a vulnerability in U-Mail, which can be exploited by malicious users to bypass certain security restrictions and potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32540/\"]http://secunia.com/advisories/32540/[/url]

--

[SA32536] SFS EZ Hotscripts-like Site Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

Some vulnerabilities have been reported in SFS EZ Hotscripts-like Site, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32536/\"]http://secunia.com/advisories/32536/[/url]

--

[SA32532] SFS EZ Hot ot Not "phid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

d3b4g has reported a vulnerability in SFS EZ Hot ot Not, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32532/\"]http://secunia.com/advisories/32532/[/url]

--

[SA32528] SFS EZ Auction "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Manipulation of data
Released: 2008-11-03

Mountassif Moad has reported a vulnerability in SFS EZ Auction, which can be exploited by malicious people to conduct SQL Injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32528/\"]http://secunia.com/advisories/32528/[/url]

--

[SA32527] SFS EZ Career "topic" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

Mountassif Moad has reported a vulnerability in SFS EZ Career, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32527/\"]http://secunia.com/advisories/32527/[/url]

--

[SA32526] SFS EZ Top Sites "ts" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

Mountassif Moad has reported a vulnerability in SFS EZ Top Sites, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32526/\"]http://secunia.com/advisories/32526/[/url]

--

[SA32525] SFS EZ e-store "where" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

ZoRLu has reported a vulnerability in SFS EZ e-store, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32525/\"]http://secunia.com/advisories/32525/[/url]

--

[SA32524] SFS EZ Pub Site "cat" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

Hakxer has reported a vulnerability in SFS EZ Pub Site, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32524/\"]http://secunia.com/advisories/32524/[/url]

--

[SA32523] Joomla Pro Desk Component "include_file" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-05

d3v1l has reported a vulnerability in the Pro Desk component for Joomla, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32523/\"]http://secunia.com/advisories/32523/[/url]

--

[SA32522] SFS EZ Gaming Cheats "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-03

ZoRLu has reported a vulnerability in SFS EZ Gaming Cheats, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32522/\"]http://secunia.com/advisories/32522/[/url]

--

[SA32519] Article Publisher Pro SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-03

Some vulnerabilities have been reported in Article Publisher Pro, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32519/\"]http://secunia.com/advisories/32519/[/url]

--

[SA32517] Acc Scripts Products "username_cookie" Cookie Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04

Hakxer has reported a vulnerability in multiple Acc Scripts products, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32517/\"]http://secunia.com/advisories/32517/[/url]

--

[SA32507] Acc PHP eMail "NEWSLETTERLOGIN" Cookie Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04

Hakxer has reported a vulnerability in Acc PHP eMail, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32507/\"]http://secunia.com/advisories/32507/[/url]

--

[SA32504] YourFreeWorld Products "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-03

Hussin X has reported a vulnerability in various YourFreeWorld products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32504/\"]http://secunia.com/advisories/32504/[/url]

--

[SA32503] ToursManager "cityid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-05

G4N0K has reported a vulnerability in ToursManager, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32503/\"]http://secunia.com/advisories/32503/[/url]

--

[SA32502] Simple Document Management System "login" and "pass" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-05

Yuri has discovered a vulnerability in Simple Document Management System (SDMS), which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32502/\"]http://secunia.com/advisories/32502/[/url]

--

[SA32500] PHP-Nuke BookCatalog Module "catid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-10-31

Ehsan_Hp200 has reported a vulnerability in the BookCatalog module for PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32500/\"]http://secunia.com/advisories/32500/[/url]

--

[SA32497] Apache Struts Security Bypass and Directory Traversal

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information
Released: 2008-11-04

Some vulnerabilities have been reported in Apache Struts, which can be exploited by malicious people to bypass certain security restrictions or to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32497/\"]http://secunia.com/advisories/32497/[/url]

--

[SA32495] XWork "ParameterInterceptor" Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-04

A vulnerability has been reported in XWork, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32495/\"]http://secunia.com/advisories/32495/[/url]

--

[SA32492] YourFreeWorld Shopping Cart Script "c" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-03

Hussin X has reported a vulnerability in YourFreeWorld Shopping Cart Script with Affiliate Program, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32492/\"]http://secunia.com/advisories/32492/[/url]

--

[SA32491] Joovili Multiple Cookie Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-03

ZoRLu has reported a vulnerability in Joovili, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32491/\"]http://secunia.com/advisories/32491/[/url]

--

[SA32484] NetRisk Cross-Site Scripting and SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-03

StAkeR has discovered some vulnerabilities in NetRisk, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32484/\"]http://secunia.com/advisories/32484/[/url]

--

[SA32572] Drupal Content Construction Kit Script Insertion Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-06

Some vulnerabilities have been reported in the Drupal Content Construction Kit (CCK), which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32572/\"]http://secunia.com/advisories/32572/[/url]

--

[SA32555] DHCart "order.php" Two Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05

Lostmon has reported two vulnerabilities in DHCart, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32555/\"]http://secunia.com/advisories/32555/[/url]

--

[SA32549] firmCHANNEL Digital Signage "action" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-05

Brad Antoniewicz has reported a vulnerability in firmCHANNEL Digital Signage, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32549/\"]http://secunia.com/advisories/32549/[/url]

--

[SA32511] RateMe Cross-Site Scripting and Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03

Russ McRee has reported some vulnerabilities in RateMe, which can be exploited by malicious people to conduct cross-site request forgery and cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32511/\"]http://secunia.com/advisories/32511/[/url]

--

[SA32506] SignMe "hash" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03

Russ McRee has discovered a vulnerability in SignMe, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32506/\"]http://secunia.com/advisories/32506/[/url]

--

[SA32505] MyGallery "mghash" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-03

Russ McRee has discovered a vulnerability in MyGallery, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32505/\"]http://secunia.com/advisories/32505/[/url]

--

[SA32567] Adobe ColdFusion Sandbox Security Bypass Vulnerability

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-06

A vulnerability has been reported in Adobe ColdFusion, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32567/\"]http://secunia.com/advisories/32567/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - November 2008

Post by Tami »

[b][url=\"http://secunia.com\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 13 2008[/b]

[b]Windows:--[/b]

[SA32698] ooVoo URI Handler Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-12

bruiser has discovered a vulnerability in ooVoo, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32698/\"]http://secunia.com/advisories/32698/[/url]

--

[SA32682] SAP GUI MDrmSap ActiveX Control Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-11

A vulnerability has been reported in SAPgui, which can be exploited by
malicious people to compromise a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/32682/\"]http://secunia.com/advisories/32682/[/url]

--

[SA32597] hMAilServer PHPWebAdmin File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-07

Nine:Situations:Group::strawdog has discovered some vulnerabilities in hMailServer PHPWebAdmin, which can be exploited by malicious people to
disclose potentially sensitive information and compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32597/\"]http://secunia.com/advisories/32597/[/url]

--

[SA32675] Dizi Film Portal "film" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-11

Kaan KAMIS has discovered a vulnerability in Dizi Film Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32675/\"]http://secunia.com/advisories/32675/[/url]

--

[SA32590] Arab Portal "file" File Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-11-10

IRCRASH has reported a vulnerability in Arab Portal, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32590/\"]http://secunia.com/advisories/32590/[/url]

--

[SA32633] Microsoft Windows SMB Authentication Credential Replay Vulnerability

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, Spoofing
Released: 2008-11-11

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security features.

Full Advisory: [url=\"http://secunia.com/advisories/32633/\"]http://secunia.com/advisories/32633/[/url]

--

[SA32618] Trend Micro ServerProtect Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-11-12

Some vulnerabilities have been reported in Trend Micro ServerProtect, which potentially can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32618/\"]http://secunia.com/advisories/32618/[/url]

--

[SA32683] IBM Metrica Products Cross-Site Scripting and Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13

Francesco Bianchino has reported a vulnerability in Metrica products, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32683/\"]http://secunia.com/advisories/32683/[/url]

--

[SA32592] Orb Networks Orb Directory Traversal Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-10

A vulnerability has been reported in Orb, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32592/\"]http://secunia.com/advisories/32592/[/url]

--

[SA32669] Anti-Trojan Elite Atepmon.sys IOCTL Handling Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-10

alex has discovered a vulnerability in Anti-Trojan Elite, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32669/\"]http://secunia.com/advisories/32669/[/url]

--

[SA32634] Anti-Keylogger Elite "AKEProtect.sys" IOCTL Handling Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-10

alex has discovered some vulnerabilities in Anti-Keylogger Elite, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32634/\"]http://secunia.com/advisories/32634/[/url]


[b]UNIX/Linux:--[/b]

[SA32714] Mozilla SeaMonkey Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13

Some vulnerabilities have been reported in Mozilla SeaMonkey, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32714/\"]http://secunia.com/advisories/32714/[/url]

--

[SA32713] Mozilla Firefox 3 Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32713/\"]http://secunia.com/advisories/32713/[/url]

--

[SA32708] Fedora update for optipng

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-13

Fedora has issued an update for optipng. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32708/\"]http://secunia.com/advisories/32708/[/url]

--

[SA32700] Red Hat update for acroread

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-13

Red Hat has issued an update for acroread. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32700/\"]http://secunia.com/advisories/32700/[/url]

--

[SA32695] Red Hat update for firefox

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13

Red Hat has issued an update for firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32695/\"]http://secunia.com/advisories/32695/[/url]

--

[SA32694] Red Hat update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13

Red Hat has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32694/\"]http://secunia.com/advisories/32694/[/url]

--

[SA32688] Apple iLife / Aperture Image Processing Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-12

Apple has acknowledged some vulnerabilities in Apple iLife and Aperture, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32688/\"]http://secunia.com/advisories/32688/[/url]

--

[SA32629] SUSE update for yelp

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07

SUSE has issued an update for yelp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32629/\"]http://secunia.com/advisories/32629/[/url]

--

[SA32702] Red Hat update for flash-plugin

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information
Released: 2008-11-13

Red Hat has issued an update for flash-plugin. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate certain data, conduct cross-site scripting attacks, or disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32702/\"]http://secunia.com/advisories/32702/[/url]

--

[SA32687] Red Hat update for gnutls

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-12

Red Hat has issued an update for gnutls. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32687/\"]http://secunia.com/advisories/32687/[/url]

--

[SA32681] Fedora update for gnutls

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-12

Fedora has issued an update for gnutls. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32681/\"]http://secunia.com/advisories/32681/[/url]

--

[SA32678] Debian update for libcdaudio

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-13

Debian has issued an update for libcdaudio. This fixes a vulnerability, which can be exploited by malicious people to compromise an application
using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32678/\"]http://secunia.com/advisories/32678/[/url]

--

[SA32677] Ubuntu update for dovecot

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-10

Ubuntu has issued an update for dovecot. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32677/\"]http://secunia.com/advisories/32677/[/url]

--

[SA32661] Gentoo update for faad2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-10

Gentoo has issued an update for faad2. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32661/\"]http://secunia.com/advisories/32661/[/url]

--

[SA32656] Gentoo update for graphviz

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-10

Gentoo has issued an update for graphviz. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32656/\"]http://secunia.com/advisories/32656/[/url]

--

[SA32625] Sun Solaris IP Filter DNS Cache Poisoning

Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-11-12

A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to poison the DNS cache.

Full Advisory: [url=\"http://secunia.com/advisories/32625/\"]http://secunia.com/advisories/32625/[/url]

--

[SA32619] GnuTLS X.509 Certificate Chain Validation Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-10

A vulnerability has been reported in GnuTLS, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32619/\"]http://secunia.com/advisories/32619/[/url]

--

[SA32614] Fedora update for ipsec-tools

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-07

Fedora has issued an update for ipsec-tools. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32614/\"]http://secunia.com/advisories/32614/[/url]

--

[SA32608] Ubuntu update for tk

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07

Ubuntu has issued an update for tk. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32608/\"]http://secunia.com/advisories/32608/[/url]

--

[SA32607] Ubuntu update for netpbm

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-07

Ubuntu has issued an update for netpbm. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise a
vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32607/\"]http://secunia.com/advisories/32607/[/url]

--

[SA32606] Sun Java System Identity Manager Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting
Released: 2008-11-12

Some vulnerabilities have been reported in Sun Java System Identity Manager, which can be exploited by malicious people to conduct cross-site scripting attacks and to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32606/\"]http://secunia.com/advisories/32606/[/url]

--

[SA32668] Sun Solaris DHCP Request Handling Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-11-10

Some vulnerabilities have been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32668/\"]http://secunia.com/advisories/32668/[/url]

--

[SA32685] Red Hat update for httpd

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-11-12

Red Hat has issued an update for httpd. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32685/\"]http://secunia.com/advisories/32685/[/url]

--

[SA32662] Gentoo update for gallery

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, Cross Site Scripting
Released: 2008-11-10

Gentoo has issued an update for gallery. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks and disclose potentially sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32662/\"]http://secunia.com/advisories/32662/[/url]

--

[SA32630] op5 Monitor Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-11

A vulnerability has been reported in op5 Monitor, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32630/\"]http://secunia.com/advisories/32630/[/url]

--

[SA32620] Fedora update for php-Smarty

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-07

Fedora has issued an update for php-Smarty. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32620/\"]http://secunia.com/advisories/32620/[/url]

--

[SA32615] Fedora update for drupal-cck

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07

Fedora has issued an update for drupal-cck. This fixes some vulnerabilities, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32615/\"]http://secunia.com/advisories/32615/[/url]

--

[SA32610] Nagios "cmd.cgi" Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07

Andreas Ericsson has discovered a vulnerability in Nagios, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/32610/\"]http://secunia.com/advisories/32610/[/url]

--

[SA32599] TestLink Multiple Script Insertion Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-07

Some vulnerabilities have been reported in TestLink, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32599/\"]http://secunia.com/advisories/32599/[/url]

--

[SA32711] rPath update for net-snmp

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-13

rPath has issued an update for net-snmp. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32711/\"]http://secunia.com/advisories/32711/[/url]

--

[SA32664] Debian update for net-snmp

Critical: Less critical
Where: From local network
Impact: Spoofing, DoS, System access
Released: 2008-11-10

Debian has issued an update for net-snmp. This fixes some vulnerabilities, which can be exploited by malicious people to spoof authenticated SNMPv3 packets, cause a DoS (Denial of Service), and compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32664/\"]http://secunia.com/advisories/32664/[/url]

--

[SA32709] rPath update for kernel

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13

rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32709/\"]http://secunia.com/advisories/32709/[/url]

--

[SA32701] Fedora update for blender

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12

Fedora has issued an update for blender. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32701/\"]http://secunia.com/advisories/32701/[/url]

--

[SA32679] smcFanControl "main()" Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12

KaiJern Lau has reported a vulnerability in smcFanControl, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32679/\"]http://secunia.com/advisories/32679/[/url]

--

[SA32674] Sun Logical Domains Authentication Bypass Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13

A vulnerability has been reported in Sun Logical Domains (LDoms), which can be exploited by malicious, local users to bypass certain security
restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32674/\"]http://secunia.com/advisories/32674/[/url]

--

[SA32627] CDRW-Taper "amlabel-cdrw" Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

A security issue has been reported in CDRW-Taper, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32627/\"]http://secunia.com/advisories/32627/[/url]

--

[SA32621] HP Tru64 UNIX AdvFS "showfile" Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

A vulnerability has been reported in HP Tru64 UNIX, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32621/\"]http://secunia.com/advisories/32621/[/url]

--

[SA32616] Fedora update for cman, gfs2-utils, and rgmanager

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

Fedora has issued an update for cman, gfs2-utils, and rgmanager. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32616/\"]http://secunia.com/advisories/32616/[/url]

--

[SA32605] Apertium Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-11

Some security issues have been reported in Apertium, which can be
exploited by malicious, local users to perform certain actions with
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/32605/\"]http://secunia.com/advisories/32605/[/url]

--

[SA32602] Cluster Project Unspecified Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

Some security issues have been reported in Cluster Project, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32602/\"]http://secunia.com/advisories/32602/[/url]

--

[SA32598] Scilab Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-10

Some security issues have been reported in Scilab, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32598/\"]http://secunia.com/advisories/32598/[/url]

--

[SA32589] DigitalDJ fest.pl Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

A security issue has been reported in DigitalDJ, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32589/\"]http://secunia.com/advisories/32589/[/url]

--

[SA32588] Rancid "getipacctg" Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

A security issue has been reported in Rancid, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32588/\"]http://secunia.com/advisories/32588/[/url]

--

[SA32587] lmbench Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

Some security issue have been reported in lmbench, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32587/\"]http://secunia.com/advisories/32587/[/url]

--

[SA32707] Fedora update for libpng10

Critical: Not critical
Where: From remote
Impact: DoS
Released: 2008-11-13

Fedora has issued an update for libpng10. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32707/\"]http://secunia.com/advisories/32707/[/url]

--

[SA32710] rPath update for initscripts

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-13

rPath has issued an update for initscripts. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/32710/\"]http://secunia.com/advisories/32710/[/url]

--

[SA32691] Ubuntu update for gnome-screensaver

Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-12

Ubuntu has issued an update for gnome-screensaver. This fixes a weakness and a security issue, which can be exploited by malicious people with physical access to disclose potentially sensitive information or bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32691/\"]http://secunia.com/advisories/32691/[/url]

--

[SA32671] WIMS "account.sh" Insecure Temporary Files

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-11

A security issue has been reported in WIMS, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32671/\"]http://secunia.com/advisories/32671/[/url]

--

[SA32667] Sun Solstice X.25 Local Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-10

A vulnerability has been reported in Solstice X.25, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32667/\"]http://secunia.com/advisories/32667/[/url]

--

[SA32655] Linux Kernel Denial of Service Vulnerabilities

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-11

Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32655/\"]http://secunia.com/advisories/32655/[/url]

[b]
Other:--[/b]

[SA32631] 2Wire Routers Denial of Service Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-11-12

hkm has reported a vulnerability in various 2Wire Routers, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32631/\"]http://secunia.com/advisories/32631/[/url]

--

[SA32635] Siemens SpeedStream 5200 "Host" Header Authentication Bypass

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-11-12

hkm has reported a vulnerability in Siemens SpeedStream 5200, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32635/\"]http://secunia.com/advisories/32635/[/url]

--

[SA32623] Sweex RO002 Router Undocumented Account Security Issue

Critical: Less critical
Where: From local network
Impact: Security Bypass
Released: 2008-11-11

Rob Stout has reported a security issue in the Sweex RO002 Router, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32623/\"]http://secunia.com/advisories/32623/[/url]

[b]
Cross Platform:--[/b]

[SA32715] Mozilla Thunderbird Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-11-13

Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32715/\"]http://secunia.com/advisories/32715/[/url]

--

[SA32693] Mozilla Firefox 2 Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-13

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32693/\"]http://secunia.com/advisories/32693/[/url]

--

[SA32666] AlstraSoft SendIt Pro File Upload Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-13

ZoRLu has reported a vulnerability in AlstraSoft SendIt Pro, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32666/\"]http://secunia.com/advisories/32666/[/url]

--

[SA32651] OptiPNG BMP Reader Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-11

A vulnerability has been reported in OptiPNG, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32651/\"]http://secunia.com/advisories/32651/[/url]

--

[SA32643] Sanusart Simple PHP Guestbook Script PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-11

GoLd_M has reported a vulnerability in Sanusart Simple PHP Guestbook Script, which can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32643/\"]http://secunia.com/advisories/32643/[/url]

--

[SA32628] Enthusiast "path" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-10

AmnPardaz Security Research Team has discovered a vulnerability in Enthusiast, which can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32628/\"]http://secunia.com/advisories/32628/[/url]

--

[SA32626] PHPStore Multiple Products File Upload Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-12

ZoRLu has reported a vulnerability in multiple PHPStore products, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32626/\"]http://secunia.com/advisories/32626/[/url]

--

[SA32712] HP Service Manager Unspecified Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-13

A vulnerability has been reported in HP Service Manager, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32712/\"]http://secunia.com/advisories/32712/[/url]

--

[SA32703] ActiveCampaign TrioLive "department_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-12

Russ McRee has reported a vulnerability in ActiveCampaign TrioLive, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32703/\"]http://secunia.com/advisories/32703/[/url]

--

[SA32673] MyioSoft Products "rsargs" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10

ZoRLu has discovered a vulnerability in multiple MyioSoft products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32673/\"]http://secunia.com/advisories/32673/[/url]

--

[SA32665] AlstraSoft Article Manager Pro "username" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-13

ZoRLu has reported a vulnerability in AlstraSoft Article Manager Pro, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32665/\"]http://secunia.com/advisories/32665/[/url]

--

[SA32663] ClamAV "get_unicode_name()" Off-By-One Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-10

Moritz Jodeit has reported a vulnerability in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32663/\"]http://secunia.com/advisories/32663/[/url]

--

[SA32660] AlstraSoft Web Host Directory "pwd" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-13

ZoRLu has reported a vulnerability in AlstraSoft Web Host Directory, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32660/\"]http://secunia.com/advisories/32660/[/url]

--

[SA32653] WOW Raid Manager "auth_phpbb3.php" Authentication Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-11

A vulnerability has been reported in WOW Raid Manager, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32653/\"]http://secunia.com/advisories/32653/[/url]

--

[SA32652] Trac Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS
Released: 2008-11-10

Some vulnerabilities have been reported in Trac, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct phishing attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32652/\"]http://secunia.com/advisories/32652/[/url]

--

[SA32647] PozScripts Business Directory Script "cid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-12

Hussin X has reported a vulnerability in PozScripts Business Directory Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32647/\"]http://secunia.com/advisories/32647/[/url]

--

[SA32646] Mole Group Rental Script "username" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-10

Cyber-Zone has reported a vulnerability in Mole Group Rental Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32646/\"]http://secunia.com/advisories/32646/[/url]


[SA32645] OTManager CMS "Tipo" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-13

colt7r has discovered a vulnerability in OTManager CMS, which can be exploited by malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32645/\"]http://secunia.com/advisories/32645/[/url]


[SA32644] TurnkeyForms Web Hosting Directory Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-13

G4N0K has reported some vulnerabilities in TurnkeyForms Web Hosting Directory, which can be exploited by malicious people to bypass certain
security restrictions and disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32644/\"]http://secunia.com/advisories/32644/[/url]


[SA32641] E-topbiz Online Store 1 "user" and "cat_id" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10

Some vulnerabilities have been reported in E-topbiz Online Store 1, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32641/\"]http://secunia.com/advisories/32641/[/url]


[SA32640] Mini Web Calendar Cross-Site Scripting and Local File Disclosure

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information
Released: 2008-11-10

ahmadbady has discovered two vulnerabilities in Mini Web Calendar, which can be exploited by malicious people to conduct cross-site scripting attacks or to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32640/\"]http://secunia.com/advisories/32640/[/url]


[SA32639] E-topbiz Number Links 1 "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10

Hussin X has reported a vulnerability in E-topbiz Number Links 1, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32639/\"]http://secunia.com/advisories/32639/[/url]


[SA32638] TYPO3 eluna_pagecomments Extension Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-10

Some vulnerabilities have been reported in the eluna_pagecomments extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32638/\"]http://secunia.com/advisories/32638/[/url]


[SA32637] Domain Seller Pro "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-10

TR-ShaRk has reported a vulnerability in Domain Seller Pro, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32637/\"]http://secunia.com/advisories/32637/[/url]


[SA32636] MyioSoft EasyBookMarker "Parent" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-10

G4N0K has discovered a vulnerability in MyioSoft EasyBookMarker, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32636/\"]http://secunia.com/advisories/32636/[/url]


[SA32632] MemHT Portal "title" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-12

Ams has discovered a vulnerability in MemHT Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32632/\"]http://secunia.com/advisories/32632/[/url]


[SA32622] Joomla! Script Insertion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-11

Some vulnerabilities have been reported in Joomla!, which can be exploited by malicious users and potentially malicious people to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32622/\"]http://secunia.com/advisories/32622/[/url]


[SA32617] Zeeways Shaadi Clone Authentication Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-11

G4N0K has reported a vulnerability in Zeeways Shaadi Clone, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32617/\"]http://secunia.com/advisories/32617/[/url]


[SA32613] Mole Group Pizza Online Ordering Script "manufacturers_id" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-07

Cyb3r-1sT has reported a vulnerability in Mole Group Pizza Online Ordering Script, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32613/\"]http://secunia.com/advisories/32613/[/url]


[SA32603] V3 Chat Products "admin" Cookie Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-10

Cyber-Zone has reported a vulnerability in multiple V3 Chat products, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32603/\"]http://secunia.com/advisories/32603/[/url]


[SA32601] Zeeways PhotoVideoTube Authentication Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-11

Mountassif Moad has reported a vulnerability in Zeeways PhotoVideoTube, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32601/\"]http://secunia.com/advisories/32601/[/url]


[SA32600] AJSquare Free Polling Script Authentication Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-12

G4N0K has discovered a vulnerability in AJ Square Free Polling Script, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32600/\"]http://secunia.com/advisories/32600/[/url]


[SA32596] DevelopItEasy Events Calendar Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Events Calendar, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32596/\"]http://secunia.com/advisories/32596/[/url]


[SA32595] DevelopItEasy News And Article System Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy News And Article System, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32595/\"]http://secunia.com/advisories/32595/[/url]


[SA32594] DevelopItEasy Membership System Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Membership System, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32594/\"]http://secunia.com/advisories/32594/[/url]


[SA32593] DevelopItEasy Photo Gallery Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Photo Gallery, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32593/\"]http://secunia.com/advisories/32593/[/url]


[SA32591] TurnkeyForms Local Classifieds SQL Injection and Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

A vulnerability and a security issue have been reported in TurnkeyForms Local Classifieds, which can be exploited by malicious people to conduct SQL injection attacks and bypass certain security restrictions

Full Advisory: [url=\"http://secunia.com/advisories/32591/\"]http://secunia.com/advisories/32591/[/url]


[SA32586] PHP Classifieds "admin_username" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-07

ZoRLu has reported a vulnerability in PHP Classifieds, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32586/\"]http://secunia.com/advisories/32586/[/url]


[SA32689] TYPO3 "file" Backend Module Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13

A vulnerability has been reported in TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32689/\"]http://secunia.com/advisories/32689/[/url]


[SA32670] Sun Java System Messaging Server Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13

A vulnerability has been reported in Sun Java System Messaging Server, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32670/\"]http://secunia.com/advisories/32670/[/url]


[SA32657] buymyscripts.net Lyrics Script "k" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12

A vulnerability has been reported in buymyscripts.net Lyrics Script, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32657/\"]http://secunia.com/advisories/32657/[/url]


[SA32654] TYPO3 phpMyAdmin Extension "db" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-10

A vulnerability has been reported in the phpMyAdmin extension for TYPO3, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32654/\"]http://secunia.com/advisories/32654/[/url]


[SA32650] buymyscripts.net Clickbank Portal "keyword" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12

A vulnerability has been reported in buymyscripts.net Clickbank Portal, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32650/\"]http://secunia.com/advisories/32650/[/url]


[SA32649] buymyscripts.net Recipe Website Script "keyword" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-12

A vulnerability has been reported in buymyscripts.net Recipe Website Script, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32649/\"]http://secunia.com/advisories/32649/[/url]


[SA32642] Fresh Email Script "Email" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-13

Don has reported a vulnerability in Fresh Email Script, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32642/\"]http://secunia.com/advisories/32642/[/url]


[SA32680] Blender Insecure Python Module Search Path Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-12

A vulnerability has been reported in Blender, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32680/\"]http://secunia.com/advisories/32680/[/url]


[SA32624] VMware ESX / ESXi Privilege Escalation and Directory Traversal Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

Some vulnerabilities have been reported in VMware ESX and ESXi, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32624/\"]http://secunia.com/advisories/32624/[/url]


[SA32612] VMware Products Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-07

A vulnerability has been reported in various VMware products, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32612/\"]http://secunia.com/advisories/32612/[/url]


[SA32686] MoinMoin Full Path Disclosure Weakness

Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-11-10

Xia Shing Zee has discovered a weakness in MoinMoin, which can be exploited by malicious people to disclose system information.

Full Advisory: [url=\"http://secunia.com/advisories/32686/\"]http://secunia.com/advisories/32686/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - November 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing For The Week of November 20 2008[/b][/i]

[b]Windows:--[/b]

[SA32772] Adobe AIR Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18

Some vulnerabilities have been reported in Adobe AIR, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32772/\"]http://secunia.com/advisories/32772/[/url]

--

[SA32743] GungHo LoadPrgAx ActiveX Control Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-17

A vulnerability has been reported in the GungHo LoadPrgAx ActiveX control, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32743/\"]http://secunia.com/advisories/32743/[/url]

--

[SA32729] Exodus Improper "im://" URI Handling Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18

strawdog has discovered a vulnerability in Exodus, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32729/\"]http://secunia.com/advisories/32729/[/url]

--

[SA32725] VeryDOC PDF Viewer ActiveX Control "OpenPDF()" Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-17

r0ut3r has discovered a vulnerability in the VeryDOC PDF Viewer ActiveX control, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32725/\"]http://secunia.com/advisories/32725/[/url]

--

[SA32785] Pre ASP Job Board "Username" and "Password" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-20

R3d-D3v!L has reported some vulnerabilities in Pre ASP Job Board, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32785/\"]http://secunia.com/advisories/32785/[/url]

--

[SA32750] Openasp "idpage" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

athos has discovered a vulnerability in Openasp, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32750/\"]http://secunia.com/advisories/32750/[/url]

--

[SA32810] Symantec Backup Exec for Windows Servers Multiple Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: Security Bypass, DoS, System access
Released: 2008-11-20

Some vulnerabilities have been reported in Symantec Backup Exec for Windows Servers, which can be exploited by malicious people to bypass certain security restrictions and by malicious users to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32810/\"]http://secunia.com/advisories/32810/[/url]

--

[SA32771] Flash Media Server Video Stream Capture Security Issue

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18

A security issue has been reported in Flash Media Server, which can be exploited by malicious people to capture content.

Full Advisory: [url=\"http://secunia.com/advisories/32771/\"]http://secunia.com/advisories/32771/[/url]

--

[SA32738] Chilkat Socket ActiveX Component "SaveLastError()" Insecure Method

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

Zigma has discovered a vulnerability in Chilkat Socket ActiveX Component, which can be exploited by malicious people to overwrite arbitrary files.

Full Advisory: [url=\"http://secunia.com/advisories/32738/\"]http://secunia.com/advisories/32738/[/url]

[b]
UNIX/Linux:--[/b]

[SA32798] Red Hat update for thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-20

Red Hat has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32798/\"]http://secunia.com/advisories/32798/[/url]

--

[SA32796] imlib2 XPM Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20

A vulnerability has been discovered in imlib2, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32796/\"]http://secunia.com/advisories/32796/[/url]

--

[SA32778] Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-19

Ubuntu has issued an update for firefox, firefox-3.0, and xulrunner-1.9. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32778/\"]http://secunia.com/advisories/32778/[/url]

--

[SA32766] Red Hat update for libxml2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18

Red Hat has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32766/\"]http://secunia.com/advisories/32766/[/url]

--

[SA32764] Ubuntu update for libxml2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-19

Ubuntu has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32764/\"]http://secunia.com/advisories/32764/[/url]

--

[SA32762] Debian update for libxml2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18

Debian has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32762/\"]http://secunia.com/advisories/32762/[/url]

--

[SA32749] Slackware update for mozilla-firefox

Critical: Highly critical
Where: From remote
Impact: System access, Exposure of sensitive information, Exposure of system information, Security Bypass
Released: 2008-11-17

Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32749/\"]http://secunia.com/advisories/32749/[/url]

--

[SA32748] Slackware update for seamonkey

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-17

Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32748/\"]http://secunia.com/advisories/32748/[/url]

--

[SA32721] Fedora update for firefox and xulrunner

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-14

Fedora has issued an update for firefox and xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to disclose
sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32721/\"]http://secunia.com/advisories/32721/[/url]

--

[SA32811] Slackware update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20

Slackware has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32811/\"]http://secunia.com/advisories/32811/[/url]

--

[SA32807] rPath update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20

rPath has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32807/\"]http://secunia.com/advisories/32807/[/url]

--

[SA32802] Fedora update for libxml2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-20

Fedora has issued an update for libxml2. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32802/\"]http://secunia.com/advisories/32802/[/url]

--

[SA32793] Debian update for python2.4

Critical: Moderately critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-11-20

Debian has issued an update for python2.4. This fixes some vulnerabilities, where some have unknown impact and others can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32793/\"]http://secunia.com/advisories/32793/[/url]

--

[SA32773] Libxml2 Two Integer Overflow Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18

Two vulnerabilities have been reported in Libxml2, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32773/\"]http://secunia.com/advisories/32773/[/url]

--

[SA32765] Ubuntu update for clamav

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-18

Ubuntu has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32765/\"]http://secunia.com/advisories/32765/[/url]

--

[SA32759] SUSE Update for Multiple Packages

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-11-17

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, or potentially gain escalated privileges, by malicious users to cause a DoS (Denial of Service), and by malicious people to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS, or potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32759/\"]http://secunia.com/advisories/32759/[/url]

--

[SA32753] rPath update for enscript

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-18

rPath has issued an update for enscript. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32753/\"]http://secunia.com/advisories/32753/[/url]

--

[SA32746] Gentoo update for php

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-11-17

Gentoo has issued an update for php. This fixes some vulnerabilities, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32746/\"]http://secunia.com/advisories/32746/[/url]

--

[SA32720] Astaro update for libspf2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-14

Astaro has issued an update for libspf2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32720/\"]http://secunia.com/advisories/32720/[/url]

--

[SA32805] Fedora update for roundup

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-20

Fedora has issued an update for roundup. This fixes a security issue, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32805/\"]http://secunia.com/advisories/32805/[/url]

--

[SA32803] Fedora update for grip

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-20

Fedora has issued an update for grip. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32803/\"]http://secunia.com/advisories/32803/[/url]

--

[SA32800] HP OpenView Network Node Manager Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-20

HP has acknowledged some vulnerabilities in OpenView Network Node Manager, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32800/\"]http://secunia.com/advisories/32800/[/url]

--

[SA32768] Dovecot ManageSieve Directory Traversal Security Issue

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18

A security issue has been reported in Dovecot ManageSieve, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32768/\"]http://secunia.com/advisories/32768/[/url]

--

[SA32761] No-IP Linux Dynamic Update Client Buffer Overflow Vulnerability

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-11-19

xenomuta has reported a vulnerability in No-IP Linux Dynamic Update Client (DUC), which potentially can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32761/\"]http://secunia.com/advisories/32761/[/url]

--

[SA32719] Linux Kernel "hfs_cat_find_brec()" Buffer Overflow Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-14

A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32719/\"]http://secunia.com/advisories/32719/[/url]

--

[SA32769] Ubuntu update for mysql-dfsg-5.0

Critical: Less critical
Where: From local network
Impact: Security Bypass, DoS
Released: 2008-11-18

Ubuntu has issued an update for mysql-dfsg-5.0. This fixes a security issue and a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and malicious users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32769/\"]http://secunia.com/advisories/32769/[/url]

--

[SA32760] OpenSSH CBC Mode Plaintext Recovery Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-17

A vulnerability has been reported in OpenSSH, which potentially can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32760/\"]http://secunia.com/advisories/32760/[/url]

--

[SA32820] SystemImager "si_mkbootserver" Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20

A security issue has been reported in SystemImager, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32820/\"]http://secunia.com/advisories/32820/[/url]

--

[SA32780] pam_mount "passwdehd" Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20

A security issue has been reported in pam_mount, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32780/\"]http://secunia.com/advisories/32780/[/url]

--

[SA32774] Citrix XenServer Ext2/Ext3 Processing Security Bypass Vulnerability

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-11-19

A vulnerability has been reported in Citrix XenServer, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32774/\"]http://secunia.com/advisories/32774/[/url]

--

[SA32730] MailScanner "trend-autoupdate" Insecure Temporary Files

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20

A security issue has been reported in MailScanner, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32730/\"]http://secunia.com/advisories/32730/[/url]

--

[SA32804] Fedora update for cobbler

Critical: Not critical
Where: From remote
Impact: Privilege escalation
Released: 2008-11-20

Fedora has issued an update for cobbler. This fixes a vulnerability, which can be exploited by malicious users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32804/\"]http://secunia.com/advisories/32804/[/url]

--

[SA32737] Cobbler Web Interface Privilege Escalation Vulnerability

Critical: Not critical
Where: From remote
Impact: Privilege escalation
Released: 2008-11-17

A vulnerability has been reported in Cobbler, which can be exploited by malicious users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32737/\"]http://secunia.com/advisories/32737/[/url]

--

[SA32818] P3nfs Insecure Temporary Files

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-20

A security issue has been reported in P3nfs, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32818/\"]http://secunia.com/advisories/32818/[/url]

--

[SA32799] Red Hat update for kernel

Critical: Not critical
Where: Local system
Impact: Privilege escalation, DoS
Released: 2008-11-20

Red Hat has issued an update for the kernel. This fixes a security issue and some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32799/\"]http://secunia.com/advisories/32799/[/url]

--

[SA32792] Ubuntu update for hplip

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-11-20

Ubuntu has issued an update for hplip. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32792/\"]http://secunia.com/advisories/32792/[/url]

[b]
Other:--[/b]

[SA32716] Netgear WGR614 Web Interface Request Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-11-18

sr. has reported a vulnerability in Netgear WGR614v9, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32716/\"]http://secunia.com/advisories/32716/[/url]

[b]
Cross Platform:--[/b]

[SA32745] Free Directory Script "API_HOME_DIR" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-19

Ghost Hacker has discovered a vulnerability in Free Directory Script, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32745/\"]http://secunia.com/advisories/32745/[/url]

--

[SA32734] phpFan "includepath" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-18

Ahmadbady has reported a vulnerability in phpFan, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32734/\"]http://secunia.com/advisories/32734/[/url]

--

[SA32783] W3matter Multiple Products "f[password]" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-20

Some vulnerabilities have been reported in multiple W3matter products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32783/\"]http://secunia.com/advisories/32783/[/url]

--

[SA32751] mxCamArchive Information Disclosure and PHP Code Execution

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, System access
Released: 2008-11-18

Ahmadbady has discovered some vulnerabilities in mxCamArchive, which can be exploited by malicious people to disclose sensitive information and malicious users to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32751/\"]http://secunia.com/advisories/32751/[/url]

--

[SA32747] E-topbiz AdManager "group" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

Hussin X has reported a vulnerability in E-topbiz AdManager, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32747/\"]http://secunia.com/advisories/32747/[/url]

--

[SA32744] ScriptsEz FREEze Greetings "pwd.txt" Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-11-18

cOndemned has discovered a security issue in ScriptsEz FREEze Greetings, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32744/\"]http://secunia.com/advisories/32744/[/url]

--

[SA32741] PHPStore Wholesales "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-17

Hussin X has reported a vulnerability in PHPStore Wholesales, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32741/\"]http://secunia.com/advisories/32741/[/url]

--

[SA32736] Pluck "g_pcltar_lib_dir" Local File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-18

Digital Security Research Group have reported a vulnerability in Pluck, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32736/\"]http://secunia.com/advisories/32736/[/url]

--

[SA32733] Jadu Galaxies "categoryID" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

ZoRLu has reported a vulnerability in Jadu Galaxies, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32733/\"]http://secunia.com/advisories/32733/[/url]

--

[SA32732] TurnkeyForms Text Link Sales SQL Injection and Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-17

Some vulnerabilities have been reported in TurnkeyForms Text Link Sales, which can be exploited by malicious people to bypass certain security restrictions and by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32732/\"]http://secunia.com/advisories/32732/[/url]

--

[SA32727] Simple Customer "email" and "password" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

d3b4g has discovered some vulnerabilities in Simple Customer, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32727/\"]http://secunia.com/advisories/32727/[/url]

--

[SA32726] SaturnCMS Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-18

Hussin X has reported some vulnerabilities in SaturnCMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32726/\"]http://secunia.com/advisories/32726/[/url]

--

[SA32724] Ultrastats "serverid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

eek has discovered a vulnerability in Ultrastats, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32724/\"]http://secunia.com/advisories/32724/[/url]

--

[SA32718] VideoScript "admin/cp.php" Security Bypass Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-11-18

G4N0K has reported a vulnerability in VideoScript, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32718/\"]http://secunia.com/advisories/32718/[/url]

--

[SA32717] PHPStore Yahoo Answers "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-17

Snakespc has reported a vulnerability in PHPStore Yahoo Answers, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32717/\"]http://secunia.com/advisories/32717/[/url]

--

[SA32815] refbase "headerMsg" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-20

A vulnerability has been reported in refbase, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32815/\"]http://secunia.com/advisories/32815/[/url]

--

[SA32788] MyTopix "send" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-11-20

cOndemned has discovered a vulnerability in MyTopix, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32788/\"]http://secunia.com/advisories/32788/[/url]

--

[SA32779] KimsON Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-19

md.r00t has reported a vulnerability in KimsON, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32779/\"]http://secunia.com/advisories/32779/[/url]

--

[SA32757] BoutikOne CMS "search_query" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-17

d3v1l has reported a vulnerability in BoutikOne CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32757/\"]http://secunia.com/advisories/32757/[/url]

--

[SA32739] Streber Unspecified Cross-Site Request Forgery Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-18

Some vulnerabilities have been reported in Streber, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32739/\"]http://secunia.com/advisories/32739/[/url]

--

[SA32740] SSH Tectia Products CBC Mode Plaintext Recovery Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-17

A vulnerability has been reported in multiple SSH Tectia products, which potentially can be exploited by malicious people to disclose sensitive nformation.

Full Advisory: [url=\"http://secunia.com/advisories/32740/\"]http://secunia.com/advisories/32740/[/url]

--

[SA32775] vBulletin SQL Injection Vulnerabilities

Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

Janek Vind has reported some vulnerabilities in vBulletin, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32775/\"]http://secunia.com/advisories/32775/[/url]

--

[SA32752] Opera "file://" URI Handling Buffer Overflow Vulnerability

Critical: Not critical
Where: From remote
Impact: System access
Released: 2008-11-18

send9 has discovered a vulnerability in Opera, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32752/\"]http://secunia.com/advisories/32752/[/url]

--

[SA32735] vBulletin Calender SQL Injection Vulnerability

Critical: Not critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-18

Janek Vind has reported some vulnerabilities in vBulletin, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32735/\"]http://secunia.com/advisories/32735/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Updates - November 2008

Post by Tami »

[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of November 27 2008[/b][/i]
[b]
Windows:--[/b]

[SA32881] K-Lite Codec Pack ffdshow URL Processing Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26

A vulnerability has been reported in K-Lite Codec Pack, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32881/\"]http://secunia.com/advisories/32881/[/url]

--

[SA32850] Nero ShowTime M3U Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-27

Gjoko 'LiquidWorm' Krstic has reported a vulnerability in Nero ShowTime, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32850/\"]http://secunia.com/advisories/32850/[/url]

--

[SA32846] ffdshow URL Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-24

A vulnerability has been reported in ffdshow, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32846/\"]http://secunia.com/advisories/32846/[/url]

--

[SA32829] FlexCell Grid ActiveX Control "HttpDownloadFile()" Arbitrary File Overwrite

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-24

Alfons Luja has discovered a vulnerability in the FlexCell Grid ActiveX control, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32829/\"]http://secunia.com/advisories/32829/[/url]

--

[SA32823] Quicksilver Forums "lang" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, Exposure of system information
Released: 2008-11-25

__GiReX__ has reported a vulnerability in Quicksilver Forums, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32823/\"]http://secunia.com/advisories/32823/[/url]

--

[SA32852] iPhone Configuration Web Utility for Windows Directory Traversal

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-24

A vulnerability has been discovered in iPhone Configuration Web Utility for Windows, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32852/\"]http://secunia.com/advisories/32852/[/url]


[b]UNIX/Linux:--[/b]

[SA32878] Ubuntu update for thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-26

Ubuntu has issued an update for mozilla-thunderbird and thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32878/\"]http://secunia.com/advisories/32878/[/url]

--

[SA32876] SUSE Update for Mozilla Products

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-26

SUSE has issued an update for MozillaFirefox, MozillaThunderbird, and seamonkey. This fixes some vulnerabilities, which can be exploited by
malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32876/\"]http://secunia.com/advisories/32876/[/url]

--

[SA32872] SUSE Update for Multiple Packages

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-11-25

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32872/\"]http://secunia.com/advisories/32872/[/url]

--

[SA32860] Ubuntu update for webkit

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-25

Ubuntu has issued an update for webkit. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32860/\"]http://secunia.com/advisories/32860/[/url]

--

[SA32856] Ubuntu update for openoffice.org

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, System access
Released: 2008-11-25

Ubuntu has issued an update for openoffice.org and openoffice.org-amd64. This fixes some vulnerabilities and a security issue, which potentially can be exploited by malicious people to compromise a user's system, and by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32856/\"]http://secunia.com/advisories/32856/[/url]

--

[SA32853] Debian update for iceweasel

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-25

Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32853/\"]http://secunia.com/advisories/32853/[/url]

--

[SA32845] Debian update for xulrunner

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, DoS, System access
Released: 2008-11-24

Debian has issued an update for xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, to disclose sensitive information, or to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32845/\"]http://secunia.com/advisories/32845/[/url]

--

[SA32843] Fedora update for imlib2

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26

Fedora has issued an update for imlib2. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.

Full Advisory: [url=\"http://secunia.com/advisories/32843/\"]http://secunia.com/advisories/32843/[/url]

--

[SA32835] Slackware update for mozilla-thunderbird

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-11-24

Slackware has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32835/\"]http://secunia.com/advisories/32835/[/url]

--

[SA32884] HP Secure Web Server/Internet Express for Tru64 UNIX PHP Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-26

HP has acknowledged a vulnerability in Secure Web Server for Tru64 UNIX and Internet Express for Tru64 UNIX, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32884/\"]http://secunia.com/advisories/32884/[/url]

--

[SA32879] Ubuntu update for GnuTLS

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-11-26

Ubuntu has issued an update for gnutls12, gnutls13, and gnutls26. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32879/\"]http://secunia.com/advisories/32879/[/url]

--

[SA32864] Red Hat update for vim

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25

Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32864/\"]http://secunia.com/advisories/32864/[/url]

--

[SA32863] Red Hat update for vim

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25

Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32863/\"]http://secunia.com/advisories/32863/[/url]

--

[SA32861] Ubuntu update for gaim

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-11-25

Ubuntu has issued an update for gaim. This fixes some vulnerabilities, which can be exploited by malicious people to potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32861/\"]http://secunia.com/advisories/32861/[/url]

--

[SA32859] Ubuntu update for pidgin

Critical: Moderately critical
Where: From remote
Impact: Spoofing, DoS, System access
Released: 2008-11-25

Ubuntu has issued an update for pidgin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct spoofing attacks and potentially compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32859/\"]http://secunia.com/advisories/32859/[/url]

--

[SA32858] Red Hat update for vim

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25

Red Hat has issued an update for vim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32858/\"]http://secunia.com/advisories/32858/[/url]

--

[SA32854] Debian update for enscript

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25

Debian has issued an update for enscript. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32854/\"]http://secunia.com/advisories/32854/[/url]

--

[SA32839] rPath update for vim, vim-minimal, and gvim

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-11-25

rPath has issued an update for vim, vim-minimal, and gvim. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32839/\"]http://secunia.com/advisories/32839/[/url]

--

[SA32834] SUSE update for phpMyAdmin and lighttpd

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS
Released: 2008-11-25

SUSE has issued an update for phpMyAdmin and lighttpd. This fixes some vulnerabilities, which can be exploited by malicious, local users to conduct cross-site scripting attacks, and by malicious users to disclose system and potentially sensitive information, and by malicious people to conduct spoofing attacks, conduct SQL injection attacks, disclose system and potentially sensitive information, and cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32834/\"]http://secunia.com/advisories/32834/[/url]

--

[SA32871] FreeBSD "arc4random()" Insufficient Entropy Sources Security Issue

Critical: Less critical
Where: From remote
Impact: Brute force
Released: 2008-11-25

FreeBSD has acknowledged a security issue, which can be exploited by malicious people to conduct brute force attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32871/\"]http://secunia.com/advisories/32871/[/url]

--

[SA32838] rPath update for httpd

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-11-24

rPath has issued an update for httpd. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32838/\"]http://secunia.com/advisories/32838/[/url]

--

[SA32862] Red Hat update for tog-pegasus

Critical: Less critical
Where: From local network
Impact: Security Bypass, Brute force
Released: 2008-11-25

Red Hat has issued an update for tog-pegasus. This fixes a security issues and a weakness, which can be exploited by people to conduct brute force attacks and malicious users to bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32862/\"]http://secunia.com/advisories/32862/[/url]

--

[SA32916] IBM AIX Multiple Privilege Escalation Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-27

Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32916/\"]http://secunia.com/advisories/32916/[/url]

--

[SA32855] Debian update for hf

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-24

Debian has issued an update for hf. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32855/\"]http://secunia.com/advisories/32855/[/url]

--

[SA32832] SUSE update for yast2-backup

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25

SUSE has issued an update for yast2-backup. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32832/\"]http://secunia.com/advisories/32832/[/url]

--

[SA32831] hf "hfkernel" Privilege Escalation Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-24

Steve Kemp has reported a security issue in hf, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32831/\"]http://secunia.com/advisories/32831/[/url]

--

[SA32875] Fedora update for geda-gnetlist

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25

Fedora has issued an update for geda-gnetlist. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32875/\"]http://secunia.com/advisories/32875/[/url]

--

[SA32851] VirtualBox "AcquireDaemonLock()" Insecure Temporary Files

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-11-25

A security issue has been reported in VirtualBox, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory: [url=\"http://secunia.com/advisories/32851/\"]http://secunia.com/advisories/32851/[/url]


[b]Other:--[/b]

[SA32827] Siemens C450IP / C475IP Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-27

A vulnerability has been reported in Siemens C450IP / C475IP, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32827/\"]http://secunia.com/advisories/32827/[/url]

--

[SA32836] I-O DATA HDL-F Series Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-26

A vulnerability has been reported in I-O DATA HDL-F series, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32836/\"]http://secunia.com/advisories/32836/[/url]


[b]Cross Platform:--[/b]

[SA32848] Amaya Two Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-25

r0ut3r has discovered two vulnerabilities in Amaya, which can be exploited by malicious people to compromise a user's system.

Full Advisory: [url=\"http://secunia.com/advisories/32848/\"]http://secunia.com/advisories/32848/[/url]

--

[SA32825] LoveCMS Download Manager Module File Upload Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-26

cOndemned has discovered a vulnerability in the Download Manager module for LoveCMS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32825/\"]http://secunia.com/advisories/32825/[/url]

--

[SA32824] MODx CMS "reflect_base" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-11-24

RoMaNcYxHaCkEr has discovered a vulnerability in MODx CMS, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory: [url=\"http://secunia.com/advisories/32824/\"]http://secunia.com/advisories/32824/[/url]

--

[SA32887] Star Articles "subcatid" and "artid" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-27

b3hz4d has reported some vulnerabilities in Star Articles, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32887/\"]http://secunia.com/advisories/32887/[/url]

--

[SA32874] WebStudio eHotel "pageid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26

Hussin X has reported a vulnerability in WebStudio eHotel, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32874/\"]http://secunia.com/advisories/32874/[/url]

--

[SA32873] WebStudio eCatalogue "pageid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26

Hussin X has reported a vulnerability in WebStudio eCatalogue, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32873/\"]http://secunia.com/advisories/32873/[/url]

--

[SA32868] FAQ Manager SQL Injection and File Inclusion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-11-26

Some vulnerabilities have been discovered in FAQ Manager, which can be exploited by malicious people to disclose sensitive information and conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32868/\"]http://secunia.com/advisories/32868/[/url]

--

[SA32866] Clean CMS "id" Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-26

ZoRLu has discovered a vulnerability in Clean CMS, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32866/\"]http://secunia.com/advisories/32866/[/url]

--

[SA32865] fuzzylime (cms) "p" File Inclusion Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-11-26

Alfons Luja has discovered a vulnerability in Fuzzylime CMS, which can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32865/\"]http://secunia.com/advisories/32865/[/url]

--

[SA32844] Cars Portal "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-26

Snakespc has reported a vulnerability in Cars Portal, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32844/\"]http://secunia.com/advisories/32844/[/url]

--

[SA32841] PG Multiple Products "login_lg" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Manipulation of data
Released: 2008-11-24

ZoRLu has reported a vulnerability in multiple PG products, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32841/\"]http://secunia.com/advisories/32841/[/url]

--

[SA32840] Wireshark SMTP Processing Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-11-24

A vulnerability has been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory: [url=\"http://secunia.com/advisories/32840/\"]http://secunia.com/advisories/32840/[/url]

--

[SA32837] PG Job Site Pro "poll_view_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-24

ZoRLu has reported a vulnerability in PG Job Site Pro, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32837/\"]http://secunia.com/advisories/32837/[/url]

--

[SA32830] xt:Commerce SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-21

A vulnerability has been reported in xt:Commerce, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32830/\"]http://secunia.com/advisories/32830/[/url]

--

[SA32826] Red Hat update for java-1.4.2-ibm

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure of sensitive information
Released: 2008-11-25

Red Hat has issued an update for java-1.4.2-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to disclose system and potentially sensitive information and bypass certain security restrictions.

Full Advisory: [url=\"http://secunia.com/advisories/32826/\"]http://secunia.com/advisories/32826/[/url]

--

[SA32822] Easyedit CMS Multiple SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-21

d3v1l has reported some vulnerabilities in Easyedit CMS, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32822/\"]http://secunia.com/advisories/32822/[/url]

--

[SA32905] Drupal Comment Mail Module Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-27

A vulnerability has been reported in the Comment Mail module for Drupal, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32905/\"]http://secunia.com/advisories/32905/[/url]

--

[SA32904] Drupal User Karma Module Cross-Site Scripting and SQL Injection

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-11-27

Some vulnerabilities have been reported in the User Karma module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32904/\"]http://secunia.com/advisories/32904/[/url]

--

[SA32898] Post Affiliate Pro "umprof_status" SQL Injection Vulnerability

Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-11-27

XaDoS has reported a vulnerability in Post Affiliate Pro, which can be exploited by malicious users to conduct SQL injection attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32898/\"]http://secunia.com/advisories/32898/[/url]

--

[SA32882] WordPress "Host" Header RSS Feed Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-26

Jeremias Reith has reported a vulnerability in WordPress, which can be exploited by malicious people to conduct script insertion attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32882/\"]http://secunia.com/advisories/32882/[/url]

--

[SA32880] MyBB "Referer" Header "my_post_key" Token Disclosure

Critical: Less critical
Where: From remote
Impact: Hijacking, Cross Site Scripting, Exposure of sensitive information
Released: 2008-11-26

NBBN has discovered some vulnerabilities in MyBB, which can be exploited can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32880/\"]http://secunia.com/advisories/32880/[/url]

--

[SA32867] COMS "q" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-25

Pouya_Server has reported a vulnerability in COMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32867/\"]http://secunia.com/advisories/32867/[/url]

--

[SA32828] Softbiz Classifieds Script "msg" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-11-21

Vahid Ezraeil has reported a vulnerability in Softbiz Classifieds Script, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory: [url=\"http://secunia.com/advisories/32828/\"]http://secunia.com/advisories/32828/[/url]

--

[SA32833] Attachmate Products SSH CBC Mode Plaintext Recovery Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-11-24

A vulnerability has been reported in various Attachmate products, which potentially can be exploited by malicious people to disclose sensitive information.

Full Advisory: [url=\"http://secunia.com/advisories/32833/\"]http://secunia.com/advisories/32833/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”