Secunia Bulletins January 2008

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 0
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins January 2008

Post by Tami »

Secunia Vulnerabilities Content Listing For The Week of January 3 2008

Windows:--

[SA28307] Georgia SoftWorks SSH2 Server Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-03

Luigi Auriemma has reported some vulnerabilities in Georgia SoftWorks SSH2 Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28307/

--

[SA28276] RealPlayer Unspecified Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-03

Evgeny Legerov has reported a vulnerability in RealPlayer, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28276/


UNIX/Linux:--

[SA28290] Gentoo update for opera

Critical: Highly critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information, System access
Released: 2008-01-02

Gentoo has issued an update for opera. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28290/

--

[SA28286] Gentoo update for openoffice, openoffice-bin, and hsqldb

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-02

Gentoo has issued an update for openoffice, openoffice-bin, and hsqldb. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28286/

--

[SA28278] Gentoo update for clamav

Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-02

Gentoo has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and
others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28278/

--

[SA28277] Gentoo update for mozilla-firefox/-bin and seamonkey/-bin

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, DoS, System access
Released: 2008-01-02

Gentoo has issued an update for mozilla-firefox, mozilla-firefox-bin, seamonkey, and seamonkey-bin. This fixes a security issue and some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks and potentially compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28277/

--

[SA28260] Debian update for peercast

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02

Debian has issued an update for peercast. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28260/

--

[SA28325] Mandriva update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-03

Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28325/

--

[SA28312] Asterisk "BYE/Also" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-03

A vulnerability has been reported in Asterisk, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28312/

--

[SA28309] AGENCY4NET WEBFTP "file" Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-03

GoLd_M has discovered a vulnerability in AGENCY4NET WEBFTP, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28309/

--

[SA28289] Gentoo update for emul-linux-x86-gtklibs

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-02

Gentoo has issued an update for emul-linux-x86-gtklibs. This fixes a vulnerability, which can be exploited by malicious people to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28289/

--

[SA28288] Gentoo update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-02

Gentoo has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28288/

--

[SA28268] Gentoo update for exiftags

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02

Gentoo has issued an update for exiftags. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28268/

--

[SA28267] Gentoo update for exiv2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02

Gentoo has issued an update for exiv2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28267/

--

[SA28266] Gentoo update for libexif

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-02

Gentoo has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28266/

--

[SA28265] Debian update for libsndfile

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-02

Debian has issued an update for libsndfile. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28265/

--

[SA28253] Netembryo "Url_init()" Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-12-28

Luigi Auriemma has reported a vulnerability in Netembryo, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28253/

--

[SA28269] Gentoo update for mt-daapd

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-02

Gentoo has acknowledged some vulnerabilities mt-daapd, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28269/

--

[SA28321] Fedora update for qt

Critical: Less critical
Where: From remote
Impact: Security Bypass, Spoofing
Released: 2008-01-03

Fedora has issued an update for qt. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28321/

--

[SA28320] Avaya Products openssh Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-03

Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to disclose certain system information and to inject certain data.

Full Advisory:
http://secunia.com/advisories/28320/

--

[SA28319] Avaya Products pam Vulnerability and Security Issue

Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-03

Avaya has acknowledged a vulnerability and a security issue in various Avaya products, which can be exploited by malicious, local users to disclose sensitive information and by malicious users to inject certain data.

Full Advisory:
http://secunia.com/advisories/28319/

--

[SA28310] Fedora update for wordpress

Critical: Less critical
Where: From remote
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information
Released: 2008-01-03

Fedora has issued an update for wordpress. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, and conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28310/

--

[SA28271] Dovecot LDAP Auth Cache Security Bypass

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-02

A security issue has been reported in Dovecot, which can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28271/

--

[SA28255] Debian update for tar

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-02

Debian has issued an update for tar. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28255/

--

[SA28279] Gentoo update for syslog-ng

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-02

Gentoo has issued an update for syslog-ng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28279/


Other:

none

Cross Platform:--

[SA28287] White_dune Format String and Buffer Overflow Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-03

Luigi Auriemma has reported some vulnerabilities in White_dune, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28287/

--

[SA28318] PHP Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass
Released: 2008-01-03

Some vulnerabilities have been reported in PHP, where some have unknown impact and others can be exploited by malicious users to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28318/

--

[SA28295] Joomla PU Arcade Component "fid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03

HouSSamix has reported a vulnerability in the PU Arcade component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28295/

--

[SA28293] Plone LiveSearch Module News Item Script Insertion

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-02

ilmila has discovered a vulnerability in Plone, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
http://secunia.com/advisories/28293/

--

[SA28285] CMS Made Simple "templateid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03

EgiX has reported a vulnerability in CMS Made Simple, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28285/

--

[SA28281] zenphoto "albumnr" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03

Silentz has discovered a vulnerability in zenphoto, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28281/

--

[SA28280] MyPHP Forum SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-03

x0kster has reported some vulnerabilities in MyPHP Forum, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28280/

--

[SA28263] Logaholic Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-03

malibu.r has reported some vulnerabilities in Logaholic, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28263/

--

[SA28258] PHCDownload "string" Cross-Site Scripting and SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-03

lostmon has discovered some vulnerabilities in PHCDownload, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28258/

--

[SA28306] milliscripts Redirection "cat" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-03

Jose Luis Góngora Fernández has reported a vulnerability in milliscripts Redirection, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28306/

--

[SA28303] phpWebSite "search" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-03

Audun Larsen has discovered a vulnerability in phpWebSite, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28303/

--

[SA28274] Apache Tomcat JULI Logging Component Security Bypass

Critical: Less critical
Where: Local system
Impact: Security Bypass
Released: 2008-01-02

A security issue has been reported in Apache Tomcat, which can be exploited by malicious, local users to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28274/
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 0
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins January 2008

Post by Tami »

Secunia Vulnerabilities Content Listing For The Week of January 10 2008

Windows:--

[SA28399] AOL Radio AOLMediaPlaybackControl.exe Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-10

Will Dormann has reported a vulnerability in AOL Radio, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28399/

--

[SA28379] Gateway CWebLaunchCtl ActiveX Control "DoWebLaunch()" Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09

Some vulnerabilities have been discovered in Gateway CWebLaunchCtl ActiveX control, which can be exploited by malicious people to
compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28379/

--

[SA28411] IBM Lotus Domino Unspecified Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10

A vulnerability has been reported in IBM Lotus Domino, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28411/

--

[SA28337] PortalApp Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-09

r3dm0v3 has reported some vulnerabilities in PortalApp, which can be exploited by malicious people to conduct cross-site scripting and SQL
injection attacks or bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28337/

--

[SA28408] McAfee E-Business Server Authentication Packet Handling Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access, DoS
Released: 2008-01-10

Leon Juranic has reported a vulnerability in McAfee E-Business Server, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28408/

--

[SA28396] Novell Client nicm.sys Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10

A vulnerability has been reported in Novell Client, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28396/

--

[SA28366] Motorola netOctopus Agent nantsys.sys Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08

A vulnerability has been reported in Motorola netOctopus, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28366/

--

[SA28351] Novell ZENworks Endpoint Security Management Privilege Escalation

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07

A vulnerability has been reported in Novell ZENworks Endpoint Security Management, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28351/

--

[SA28341] Microsoft Windows LSASS Privilege Escalation Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08

A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28341/


UNIX/Linux:--

[SA28412] SUSE Update for Multiple Packages

Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-10

SUSE has issued an update for multiple packages. This fixes some vulnerabilities, where one vulnerability has unknown impacts and others
can be exploited by malicious, local users to disclose and manipulate sensitive information and cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to cause a DoS and compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28412/

--

[SA28398] HP-UX update for Firefox

Critical: Highly critical
Where: From remote
Impact: Spoofing, Manipulation of data, Exposure of sensitive information, System access
Released: 2008-01-09

HP has issued an update for Firefox. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive
information, conduct phishing and cross-site scripting attacks, manipulate certain data, and potentially compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28398/

--

[SA28406] Gentoo update for R

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10

Gentoo has issued an update for R. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service), disclose sensitive information, or potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28406/

--

[SA28403] Gentoo update for squid

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10

Gentoo has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28403/

--

[SA28400] Mandriva update for libexif

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10

Mandriva has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28400/

--

[SA28387] Avaya Products Perl Regular Expressions Unicode Data Buffer Overflow

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09

Avaya has acknowledged a vulnerability in various Avaya products, which potentially can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory:
http://secunia.com/advisories/28387/

--

[SA28384] xine-lib SDP Attributes Buffer Overflow Vulnerability

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-09

Luigi Auriemma has discovered a vulnerability in xine-lib, which potentially can be exploited by malicious people to compromise a user's
system.

Full Advisory:
http://secunia.com/advisories/28384/

--

[SA28381] Ubuntu update for squid

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10

Ubuntu has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28381/

--

[SA28380] Ubuntu update for opal

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09

Ubuntu has issued an update for opal. This fixes a vulnerability, which can potentially be exploited by malicious people to compromise an
application using the library.

Full Advisory:
http://secunia.com/advisories/28380/

--

[SA28377] Debian update for libarchive

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-09

Debian has issued an update for libarchive. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28377/

--

[SA28374] Debian update for fail2ban

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10

Debian has issued an update for fail2ban. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28374/

--

[SA28373] FlexBB "flexbb_temp_id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-08

Eugene Minaev has discovered a vulnerability in FlexBB, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28373/

--

[SA28353] Fedora update for python-cherrypy

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07

Fedora has issued an update for python-cherrypy. This fixes a vulnerability, which can be exploited by malicious people to bypass
certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28353/

--

[SA28350] Mandriva update for squid

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-07

Mandriva has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28350/

--

[SA28347] Debian update for eggdrop

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07

Debian has issued an update for eggdrop. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
http://secunia.com/advisories/28347/

--

[SA28346] rPath update for libexif

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07

rPath has issued an update for libexif. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of
Service) or to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28346/

--

[SA28345] rPath update for tetex

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-07

rPath has issued an update for tetex, tetex-afm, tetex-dvips, tetex-fonts, tetex-latex, and tetex-xdvi. This fixes a vulnerability,
which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28345/

--

[SA28342] Debian update for wzdftpd

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-07

Debian has issued an update for wzdftpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) or potentially to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28342/

--

[SA28334] Debian update for maradns

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04

Debian has issued an update for maradns. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28334/

--

[SA28333] Debian update for freetype

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08

Debian has issued an update for freetype. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service) and potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28333/

--

[SA28329] MaraDNS CNAME Record Resource Rotation Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-04

A vulnerability has been reported in MaraDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28329/

--

[SA28386] Ubuntu update for cups

Critical: Moderately critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-09

Ubuntu has issued an update for cups. This fixes a vulnerability which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system, and a security issue which can be exploited by malicious, local users to perform certain actions with escalated privileges.

Full Advisory:
http://secunia.com/advisories/28386/

--

[SA28338] Red Hat update for tog-pegasus

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08

Red Hat has issued an update for tog-pegasus. This fixes a vulnerability, which can potentially be exploited by malicious people
to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28338/

--

[SA28404] Debian update for dovecot

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10

Debian has issued an update for dovecot. This fixes a security issue, which can be exploited by malicious users to bypass certain security
restrictions.

Full Advisory:
http://secunia.com/advisories/28404/

--

[SA28388] Gentoo update for unp

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-09

Gentoo has issued an update for unp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28388/

--

[SA28385] Ubuntu update for pwlib

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-09

Ubuntu has issued an update for pwlib. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28385/

--

[SA28375] IBM WebSphere Application Server for z/OS HTTP Server Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09

IBM has acknowledged a vulnerability in IBM Websphere Application Server for z/OS, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28375/

--

[SA28361] Debian update for tomcat5

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-08

Debian has issued an update for tomcat5. This fixes some vulnerabilities, which can be exploited by malicious people and
malicious users to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28361/

--

[SA28360] Red Hat update for e2fsprogs

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-08

Red Hat has issued an update for e2fsprogs. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28360/

--

[SA28352] Fedora update for mantis

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07

Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion
attacks.

Full Advisory:
http://secunia.com/advisories/28352/

--

[SA28413] Ubuntu update for Net-SNMP

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10

Ubuntu has issued an update for Net-SNMP. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28413/

--

[SA28401] Gentoo update for openafs

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-10

Gentoo has issued an update for openafs. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of
Service).

Full Advisory:
http://secunia.com/advisories/28401/

--

[SA28376] Mandriva update for postgresql

Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-10

Mandriva has issued an update for postgresql. This fixes some vulnerabilities, which can be exploited by malicious users to gain
escalated privileges or to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28376/

--

[SA28344] rPath update for cups

Critical: Less critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-07

rPath has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service)
or to potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28344/

--

[SA28343] Debian update for mysql-dfsg-5.0

Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, DoS
Released: 2008-01-07

Debian has issued an update for mysql-dfsg-5.0. This fixes some security issues and a vulnerability, which can be exploited by
malicious users to bypass certain security restrictions, manipulate data, and cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28343/

--

[SA28327] OpenAFS File Server Denial of Service Vulnerability

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-04

A vulnerability has been reported in OpenAFS, which can be exploited by malicious users to cause a DoS (Denial od Service).

Full Advisory:
http://secunia.com/advisories/28327/

--

[SA28402] Gentoo update for claws-mail

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-10

Gentoo has issued an update for claws-mail. This fixes a security issue, which can be exploited by malicious, local users to perform
certain actions with escalated privileges.

Full Advisory:
http://secunia.com/advisories/28402/

--

[SA28405] Xen DR7 and CR4 Register Handling Denial of Service Vulnerabilities

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2008-01-10

Some vulnerabilities have been reported in Xen, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28405/

--

[SA28349] Debian update for loop-aes-utils

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07

Debian has issued an update for loop-aes-utils. This fixes a vulnerability, which can be exploited by malicious, local users to
perform certain actions with escalated privileges.

Full Advisory:
http://secunia.com/advisories/28349/

--

[SA28348] Debian update for util-linux

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-07

Debian has issued an update for util-linux. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain
actions with escalated privileges.

Full Advisory:
http://secunia.com/advisories/28348/

--

[SA28339] Ubuntu update for tomboy

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-08

Ubuntu has issued an update for tomboy. This fixes a security issue, which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
http://secunia.com/advisories/28339/


Other:--

[SA28394] Ingate Firewall and SIParator Port Exhaustion Denial of Service

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-10

Ingate has acknowledged a vulnerability in Ingate Firewall and SIParator, which can be exploited by malicious people to cause a DoS
(Denial of Service).

Full Advisory:
http://secunia.com/advisories/28394/

--

[SA28357] Aruba Mobility Controller LDAP User Authentication Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07

A security issue has been reported in Aruba Mobility Controller, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
http://secunia.com/advisories/28357/

--

[SA28364] Linksys WRT54GL Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-09

Tomaz Bratusa has reported a vulnerability in Linksys WRT54GL, which can be exploited by malicious people to conduct cross-site request
forgery attacks.

Full Advisory:
http://secunia.com/advisories/28364/


Cross Platform:--

[SA28421] Kolab Server ClamAV Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-10

Some vulnerabilities have been reported in Kolab Server, where one vulnerability has an unknown impact and others can be exploited by
malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28421/

--

[SA28420] osDate "php121dir" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-10

Cold z3ro has discovered a vulnerability in osDate, which can be exploited by malicious people to disclose sensitive information or to
compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28420/

--

[SA28383] VLC Media Player SDP Processing Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-10

Luigi Auriemma has reported a vulnerability in VLC Media Player, which can potentially be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28383/

--

[SA28368] VMware ESX Server Multiple Security Updates

Critical: Highly critical
Where: From remote
Impact: Privilege escalation, DoS, System access
Released: 2008-01-08

VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
perform actions with escalated privileges and by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28368/

--

[SA28365] VMware ESX Server and VirtualCenter Multiple Security Updates

Critical: Highly critical
Where: From remote
Impact: Security Bypass, DoS, System access
Released: 2008-01-08

VMware has issued updates for VMware ESX Server and VirtualCenter. These fix some vulnerabilities, which can be exploited by malicious
people to bypass certain security restrictions, to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28365/

--

[SA28363] HP-UX update for Thunderbird

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-09

HP has issued an update for Thunderbird. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28363/

--

[SA28355] SAM Broadcaster samPHPweb "commonpath" File Inclusion Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07

Crackers_Child has discovered a vulnerability in the samPHPweb template included in SAM Broadcaster, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28355/

--

[SA28336] Loudblog "template" Code Execution Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07

Eugene Minaev has discovered a vulnerability in Loudblog, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28336/

--

[SA28330] Strawberry "text" PHP Code Execution

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-07

Eugene Minaev has discovered a vulnerability in Strawberry, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28330/

--

[SA28328] NetRisk Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Manipulation of data, System access
Released: 2008-01-07

hadihadi and S.W.A.T. have discovered some vulnerabilities in NetRisk, which can be exploited by malicious people to conduct SQL injection
attacks and to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28328/

--

[SA28414] R PCRE Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-01-10

Some vulnerabilities have been reported in R, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose sensitive information, or potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28414/

--

[SA28393] DomPHP "mail" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10

j0j0 has discovered a vulnerability in DomPHP, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28393/

--

[SA28382] Multiple Horde Products Security Bypass

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-10

Some vulnerabilities have been reported in various Horde products, which can be exploited by malicious people to bypass certain security
restrictions.

Full Advisory:
http://secunia.com/advisories/28382/

--

[SA28378] Docebo "Accept-Language" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-10

EgiX has discovered a vulnerability in Docebo, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28378/

--

[SA28371] Eggblog "eggblogpassword" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09

gemaglabin and Elekt have discovered a vulnerability in eggblog, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28371/

--

[SA28370] vtiger CRM File Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-10

A vulnerability has been reported in vtiger CRM, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
http://secunia.com/advisories/28370/

--

[SA28362] Tribisur "id" and "cat" SQL Injection Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-07

x0kster has discovered some vulnerabilities in Tribisur, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28362/

--

[SA28354] CherryPy Session Id Directory Traversal Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-07

A vulnerability has been reported in CherryPy, which can be exploited by malicious people to bypass certain security settings.

Full Advisory:
http://secunia.com/advisories/28354/

--

[SA28340] RunCms newbb_plus "Client-IP" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-09

gemaglabin and Elekt have discovered a vulnerability in RunCms, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28340/

--

[SA28331] eTicket Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-04

Some vulnerabilities have been discovered in eTicket, which can be exploited by malicious people to conduct script insertion, cross-site
scripting, and SQL injection attacks, and by malicious users to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28331/

--

[SA28409] MaxDB DBM Command Processing Command Execution Vulnerability

Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-01-10

Luigi Auriemma has discovered a vulnerability in MaxDB, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28409/

--

[SA28358] OpenPegasus PAM Module Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-08

Some vulnerabilities have been reported in OpenPegasus, which can potentially be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28358/

--

[SA28369] NetRisk "page" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-07

hadihadi has discovered a vulnerability in NetRisk, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28369/

--

[SA28356] Sun Java System Identity Manager Unspecified Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-10

Some vulnerabilities have been reported in Sun Java System Identity Manager, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28356/

--

[SA28335] PRO-Search Multiple Cross-Site Scripting Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-04

MustLive has reported some vulnerabilities in PRO-Search, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28335/

--

[SA28359] PostgreSQL Multiple Vulnerabilities

Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-01-07

Some vulnerabilities have been reported in PostgreSQL, which can be exploited by malicious users to gain escalated privileges or to cause a
DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28359/
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Tami
Administrator
Administrator
Posts: 0
Joined: Sun Apr 25, 2004 1:05 pm

Secunia Bulletins January 2008

Post by Tami »

Secunia Vulnerabilities Content Listing For The Week of January 24 2008

Windows:--

[SA28599] Lycos FileUploader Module File Upload Component ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-23

Elazar Broad has discovered a vulnerability in Lycos FileUploader Module, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28599/

--

[SA28595] HP Virtual Rooms Install HPVirtualRooms14 Class ActiveX Control Buffer Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22

Elazar Broad has discovered a vulnerability in HP Virtual Rooms Install, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28595/

--

[SA28557] Toshiba Surveillix RecordSend Class ActiveX Control Buffer Overflows

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-21

retrogod has discovered two vulnerabilities in the Toshiba Surveillix RecordSend Class ActiveX control, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28557/

--

[SA28563] Microsoft Visual Basic ".dsr" File Handling Buffer Overflows

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21

shinnai has discovered two vulnerabilities in Microsoft Visual Basic, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28563/

--

[SA28639] Web Wiz Rich Text Editor "sub" Directory Traversal Vulnerability

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24

AmnPardaz Security Research Team has reported a vulnerability in Web Wiz Rich Text Editor, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28639/

--

[SA28601] Web Wiz Forums Directory Traversal Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24

AmnPardaz Security Research Team has reported some vulnerabilities in Web Wiz Forums, which can be exploited by malicious users and malicious people to disclose potentially sensitive information.

Full Advisory:
http://secunia.com/advisories/28601/

--

[SA28586] IBM WebSphere Business Modeler Repository Deletion Security Issue

Critical: Less critical
Where: From local network
Impact: Manipulation of data
Released: 2008-01-22

A security issue has been reported in IBM WebSphere Business Modeler, which can be exploited by malicious users to manipulate certain data.

Full Advisory:
http://secunia.com/advisories/28586/

--

[SA28578] BitDefender Update Server HTTP Server Directory Traversal Vulnerability

Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-21

Oliver Karow has discovered a vulnerability in BitDefender Update Server, which can be exploited by malicious people to disclose
sensitive information.

Full Advisory:
http://secunia.com/advisories/28578/


UNIX/Linux:--

[SA28590] Citadel SMTP "makeuserkey()" Buffer Overflow Vulnerability

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-01-22

prdelka has discovered a vulnerability in Citadel, which can be exploited by malicious people to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28590/

--

[SA28587] Fedora update for clamav

Critical: Highly critical
Where: From remote
Impact: Unknown, DoS, System access
Released: 2008-01-23

Fedora has issued an update for clamav. This fixes some vulnerabilities, where one vulnerability has an unknown impact and
others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28587/

--

[SA28570] Gentoo update for netscape-flash

Critical: Highly critical
Where: From remote
Impact: Unknown, Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege
escalation, DoS, System access
Released: 2008-01-21

Gentoo has issued an update for netscape-flash. This fixes some vulnerabilities, where one vulnerability has an unknown impact and others can be exploited by malicious, local users to gain escalated privileges and by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP request splitting attacks, disclose sensitive information, cause a Denial of Service (DoS), or to potentially compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28570/

--

[SA28631] HTTP File Server Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Exposure of system information, DoS, System access
Released: 2008-01-24

Felipe Aragon and Alec Storm have reported some vulnerabilities and security issues in HTTP File Server, which can be exploited by malicious people to disclose system information, conduct spoofing and cross-site scripting attacks, bypass certain security restrictions, manipulate data, and potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28631/

--

[SA28614] Debian update for libvorbis

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-22

Debian has issued an update for libvorbis. This fixes some vulnerabilties, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28614/

--

[SA28612] HP-UX ARPA Transport Unspecified Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24

A vulnerability has been reported in HP-UX, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28612/

--

[SA28610] Debian update for exiv2

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24

Debian has issued an update for exiv2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28610/

--

[SA28602] Gentoo update for tikiwiki

Critical: Moderately critical
Where: From remote
Impact: Unknown, Cross Site Scripting
Released: 2008-01-24

Gentoo has issued an update for tikiwiki. This fixes some vulnerabilities, where some have unknown impacts and others can be
exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28602/

--

[SA28583] Red Hat update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21

Red Hat has issued an update for wireshark. This fixes some
vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28583/

--

[SA28564] Red Hat update for wireshark

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-21

Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28564/

--

[SA28555] Mandriva update for cairo

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-22

Mandriva has issued an update for cairo. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28555/

--

[SA28548] Debian update for flac

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2008-01-21

Debian has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28548/

--

[SA28546] Debian update for horde3

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data
Released: 2008-01-21

Debian has issued an update for horde3. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and manipulate data.

Full Advisory:
http://secunia.com/advisories/28546/

--

[SA28607] Avaya Products httpd Multiple Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-22

Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28607/

--

[SA28591] Fedora update for mantis

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-23

Fedora has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
http://secunia.com/advisories/28591/

--

[SA28589] ELOG Script Insertion and Denial of Service Vulnerabilities

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22

Some vulnerabilities have been reported in ELOG, which can be exploited by malicious users to cause a DoS (Denial of Service) and conduct script insertion attacks.

Full Advisory:
http://secunia.com/advisories/28589/

--

[SA28569] Gentoo update for libcdio

Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-01-21

Gentoo has issued an update for libcdio. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.

Full Advisory:
http://secunia.com/advisories/28569/

--

[SA28551] Debian update for mantis

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21

Debian has issued an update for mantis. This fixes a vulnerability, which can be exploited by malicious users to conduct script insertion attacks, and a security issue, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28551/

--

[SA28549] Debian update for tomcat5.5

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting, Exposure of sensitive information
Released: 2008-01-21

Debian has issued an update for tomcat5.5. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks, and a security issue, which can be exploited by malicious people to disclose potentially sensitive information.

Full Advisory:
http://secunia.com/advisories/28549/

--

[SA28545] Fedora update for boost

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-01-23

Fedora has issued an update for boost. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28545/

--

[SA28541] Fedora update for e2fsprogs

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21

Fedora has issued an update for e2fsprogs. This fixes a some vulnerabilities, which potentially can be exploited by malicious people
to compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28541/

--

[SA28643] Red Hat update for kernel

Critical: Less critical
Where: From local network
Impact: Security Bypass, Manipulation of data, Exposure of sensitive information, DoS, System access
Released: 2008-01-24

Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a Denial of Service (DoS), disclose potentially sensitive information, bypass certain security restrictions, and corrupt a file
system, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28643/

--

[SA28592] Fedora update for xorg-x11-server

Critical: Less critical
Where: From local network
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-23

Fedora has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28592/

--

[SA28616] Mandriva update for x11-server-xgl

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-24

Mandriva has issued an update for x11-server-xgl. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28616/

--

[SA28609] IBM AIX Multiple Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Manipulation of data, Exposure of sensitive information, Privilege escalation
Released: 2008-01-24

Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain files, or gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28609/

--

[SA28571] Mandriva update for libxfont

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-24

Mandriva has issued an update for libxfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28571/

--

[SA28559] rPath update for mysql

Critical: Less critical
Where: Local system
Impact: Manipulation of data
Released: 2008-01-18

rPath has issued an update for mysql. This fixes a vulnerability, which can be exploited by malicious, local users to manipulate certain data.

Full Advisory:
http://secunia.com/advisories/28559/

--

[SA28558] rPath update for kernel

Critical: Less critical
Where: Local system
Impact: Security Bypass, Manipulation of data
Released: 2008-01-18

rPath has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions and corrupt a file system.

Full Advisory:
http://secunia.com/advisories/28558/

--

[SA28550] Sun Solaris X Window System and X Server Multiple
Vulnerabilities

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18

Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, or to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28550/

--

[SA28544] Red Hat update for libXfont

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-18

Red Hat has issued an update for libXfont. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28544/

--

[SA28543] Red Hat update for xorg-x11-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18

Red Hat has issued an update for xorg-x11-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28543/

--

[SA28542] Red Hat update for XFree86

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18

Red Hat has issued an update for XFree86. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28542/

--

[SA28540] SUSE update for Xorg and XFree

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18

SUSE has issued an update for Xorg and XFree. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information, or gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28540/

--

[SA28539] Debian update for xorg-server

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation, DoS
Released: 2008-01-18

Debian has issued an update for xorg-server. This fixes some vulnerabilities, which can be exploited by malicious, local users to
cause a DoS (Denial of Service), disclose potentially sensitive information or to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28539/

--

[SA28574] Ubuntu update for apt-listchanges

Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-01-21

Ubuntu has issued an update for apt-listchanges. This fixes a security issue, which can be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
http://secunia.com/advisories/28574/


Other:--

[SA28625] Cisco PIX and ASA Time-To-Live Denial of Service Vulnerability

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-01-24

Cisco has acknowledged a vulnerability in Cisco PIX and ASA appliances, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28625/

--

[SA28553] OKI C5510MFP Configuration Interface Security Issues

Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-01-18

Compass Security AG has reported two security issues in OKI C5510MFP, which can be exploited by malicious people to disclose sensitive information and to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28553/


Cross Platform:--

[SA28580] phpAutoVideo File Inclusion and Cross-Site Scripting

Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21

H-T Team have reported two vulnerabilities in phpAutoVideo, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, or to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28580/

--

[SA28568] Small Axe Weblog linkbar.php File Inclusion Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information, System access
Released: 2008-01-21

Two vulnerabilities have been reported in Small Axe Weblog, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28568/

--

[SA28556] HP Oracle for OpenView Multiple Vulnerabilities

Critical: Highly critical
Where: From remote
Impact: Unknown
Released: 2008-01-18

HP has acknowledged some vulnerabilities with unknown impacts in HP OfO (Oracle for Openview), which can be exploited by malicious users and malicious people.

Full Advisory:
http://secunia.com/advisories/28556/

--

[SA28640] SDL_image Two Buffer Overflow Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-24

Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

Full Advisory:
http://secunia.com/advisories/28640/

--

[SA28624] PHP-Nuke "modules/Search/index.php" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-23

Foster & 1dt.w0lf have discovered a vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28624/

--

[SA28619] Liquid-Silver CMS "update" Local File Inclusion

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-01-24

Stack-Terrorist has discovered a vulnerability in Liquid-Silver CMS, which can be exploited by malicious people to disclose sensitive
information.

Full Advisory:
http://secunia.com/advisories/28619/

--

[SA28617] aconon Mail "template" Information Disclosure

Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive
information
Released: 2008-01-24

Arno Töll has reported a vulnerability in aconon Mail, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28617/

--

[SA28606] Interstage HTTP Server Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, DoS
Released: 2008-01-22

Fujitsu has acknowledged some vulnerabilities in Interstage HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28606/

--

[SA28605] PacerCMS Multiple Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Cross Site Scripting
Released: 2008-01-22

Some vulnerabilities have been reported in PacerCMS, which can be exploited by malicious people to conduct script insertion attacks and by malicious users to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28605/

--

[SA28594] aflog SQL Injection and Script Insertion Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-23

shinmai has discovered some vulnerabilities in aflog, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28594/

--

[SA28588] WebSphere Application Server Two Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-22

Some vulnerabilities with unknown impact have been reported in WebSphere Application Server.

Full Advisory:
http://secunia.com/advisories/28588/

--

[SA28581] AlstraSoft Forum Pay Per Post Exchange "catid" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-22

t0pP8uZz & xprog have reported a vulnerability in AlstraSoft Forum Pay Per Post Exchange, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28581/

--

[SA28576] IBM WebSphere Application Server serveServletsByClassnameEnabled Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-01-21

A vulnerability has been reported in IBM WebSphere Application Server, which has an unknown impact.

Full Advisory:
http://secunia.com/advisories/28576/

--

[SA28572] MyBB SQL Injection and Cross-Site Request Forgery
Vulnerabilities

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-21

Some vulnerabilities have been reported in MyBB, which can be exploited by malicious users to conduct SQL injection or cross-site request forgery attacks.

Full Advisory:
http://secunia.com/advisories/28572/

--

[SA28567] WordPress WP-Forum Plugin "user" SQL Injection

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-01-21

websec Team have discovered a vulnerability in the WP-Forum plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28567/

--

[SA28566] Famp3 "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18

IRCRASH has discovered a vulnerability in Famp3, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28566/

--

[SA28565] FaPersianHack "id" SQL Injection Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-01-18

IRCRASH has discovered a vulnerability in FaPersianHack, which can be exploited by malicious people to conduct SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28565/

--

[SA28560] Clever Copy SQL Injection and Cross-Site Scripting

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-01-18

hadihadi has discovered some vulnerabilities in Clever Copy, which can be exploited by malicious people to conduct cross-site scripting attacks and SQL injection attacks.

Full Advisory:
http://secunia.com/advisories/28560/

--

[SA28547] Openfire Jetty Information Disclosure Vulnerability

Critical: Moderately critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-18

A vulnerability has been reported in Openfire, which can be exploited by malicious people to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28547/

--

[SA28562] AXIGEN Mail Server AXIMilter Format String Vulnerability

Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-01-21

hempel has discovered a vulnerability in the AXIGEN Mail Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28562/

--

[SA28633] Drupal Workflow Module Workflow Message Script Insertion

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24

A vulnerability has been reported in the Workflow module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
http://secunia.com/advisories/28633/

--

[SA28632] Drupal Archive Module Unspecified Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24

Some vulnerabilities have been reported in the Archive module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28632/

--

[SA28629] MediaWiki Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24

A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28629/

--

[SA28622] Mozilla Firefox "chrome:" Directory Traversal Security Issue

Critical: Less critical
Where: From remote
Impact: Security Bypass
Released: 2008-01-24

Gerry Eisenhaur has discovered a security issue in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions.

Full Advisory:
http://secunia.com/advisories/28622/

--

[SA28593] WordPress Permalinks Migration Plugin Cross-Site Request Forgery

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-24

g30rg3_x has discovered a vulnerability in the Permalinks Migration plugin for WordPress, which can be exploited by malicious people to conduct cross-site request forgery attacks.

Full Advisory:
http://secunia.com/advisories/28593/

--

[SA28582] OZJournals "id" Information Disclosure Vulnerability

Critical: Less critical
Where: From remote
Impact: Exposure of sensitive information
Released: 2008-01-22

shinmai has discovered a vulnerability in OZJournals, which can be exploited by malicious people to disclose potentially sensitive
information.

Full Advisory:
http://secunia.com/advisories/28582/

--

[SA28579] ISC BIND libbind "inet_network()" Off-By-One Vulnerability

Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-01-21

A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service) or to
potentially compromise a vulnerable system.

Full Advisory:
http://secunia.com/advisories/28579/

--

[SA28577] Mantis "Most Active" Script Insertion Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21

A vulnerability has been reported in Mantis, which can be exploited by malicious users to conduct script insertion attacks.

Full Advisory:
http://secunia.com/advisories/28577/

--

[SA28573] singapore "gallery" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-21

Rubén Ventura Piña has discovered a vulnerability in singapore, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28573/

--

[SA28561] cPanel Leech Protect "rurl" Cross-Site Scripting

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-01-18

Aria-Security Team have reported a vulnerability in cPanel, which can be exploited by malicious people to conduct cross-site scripting attacks.

Full Advisory:
http://secunia.com/advisories/28561/

--

[SA28604] IBM Tivoli Provisioning Manager for OS Deployment HTTP Server Denial of Service

Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-01-22

A vulnerability has been reported in IBM Tivoli Provisioning Manager for OS Deployment, which can be exploited by malicious people to cause a DoS (Denial of Service).

Full Advisory:
http://secunia.com/advisories/28604/

--

[SA28603] IBM Tivoli Business Service Manager Password Disclosure

Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-01-22

Some security issues have been reported in IBM Tivoli Business Service Manager, which potentially can be exploited by malicious, local users to disclose sensitive information.

Full Advisory:
http://secunia.com/advisories/28603/

--

[SA28613] Kayako SupportSuite "syncml/index.php" Information Disclosure

Critical: Not critical
Where: From remote
Impact: Exposure of system information
Released: 2008-01-22

Janek Vind has reported a vulnerability in Kayako SupportSuite, which can be exploited by malicious people to disclose system information.

Full Advisory:
http://secunia.com/advisories/28613/

--

[SA28552] Apache Tomcat SingleSignOn Information Disclosure

Critical: Not critical
Where: From local network
Impact: Exposure of sensitive information
Released: 2008-01-21

A security issue has been reported in Apache Tomcat, which can be exploited by malicious people to disclose potentially sensitive
information.

Full Advisory:
http://secunia.com/advisories/28552/
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”