Secunia Bulletins April 2008
Posted: Thu Apr 03, 2008 4:13 pm
[i][b][url=\"http://secunia.com/\"]Secunia[/url] Vulnerabilities Content Listing for the week of April 3 2008[/b][/i]
[b]Windows:--[/b]
[SA29620] XnView Slideshow "FontName" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31
Secunia Research has discovered a vulnerability in XnView, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29620/\"]http://secunia.com/advisories/29620/[/url]
--
[SA29629] NoticeWare Email Server IMAP Packet Handling Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02
Ray has discovered a vulnerability in NoticeWare Email Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29629/\"]http://secunia.com/advisories/29629/[/url]
--
[SA29614] SLMail Pro Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-31
Luigi Auriemma has discovered some vulnerabilities in SLMail Pro, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29614/\"]http://secunia.com/advisories/29614/[/url]
--
[SA29611] EfesTECH Video "catID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01
RMx has discovered a vulnerability in EfesTECH Video, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29611/\"]http://secunia.com/advisories/29611/[/url]
--
[SA29641] HP OpenView Network Node Manager Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-03
Mati Aharoni has discovered a vulnerability in HP OpenView Network Node Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29641/\"]http://secunia.com/advisories/29641/[/url]
--
[SA29660] Symantec Products AutoFix Support Tool ActiveX Control Two Vulnerabilities
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-04-03
Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29660/\"]http://secunia.com/advisories/29660/[/url]
--
[SA29581] Chilkat HTTP ActiveX Component ActiveX Controls "SaveLastError()" Insecure Method
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01
shinnai has discovered a vulnerability in Chilkat HTTP ActiveX Component, which can be exploited by malicious people to overwrite
arbitrary files.
Full Advisory:
[url=\"http://secunia.com/advisories/29581/\"]http://secunia.com/advisories/29581/[/url]
--
[SA29572] DigiDomain Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-28
Linux_Drox has reported some vulnerabilities in DigiDomain, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29572/\"]http://secunia.com/advisories/29572/[/url]
--
[SA29639] Novell eDirectory Host Environment HTTP Request Processing Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-03
Mati Aharoni has discovered a vulnerability in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29639/\"]http://secunia.com/advisories/29639/[/url]
--
[SA29590] 2X ThinClientServer 2XTFTPd Service Directory Traversal
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-31
Luigi Auriemma has discovered a vulnerability in 2X ThinClientServer, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29590/\"]http://secunia.com/advisories/29590/[/url]
--
[SA29605] avast! Home/Professional aavmker4.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
Tobias Klein has reported a vulnerability in avast! Home/Professional, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29605/\"]http://secunia.com/advisories/29605/[/url]
[b]UNIX/Linux:--[/b]
[SA29621] Comix Arbitrary Shell Command Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01
A vulnerability has been reported in Comix, which can be exploited by malicious people to compromise a user's sytem.
Full Advisory:
[url=\"http://secunia.com/advisories/29621/\"]http://secunia.com/advisories/29621/[/url]
--
[SA29618] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-04-02
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29618/\"]http://secunia.com/advisories/29618/[/url]
--
[SA29616] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure
of sensitive information, System access
Released: 2008-03-31
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29616/\"]http://secunia.com/advisories/29616/[/url]
--
[SA29601] Debian update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01
Debian has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29601/\"]http://secunia.com/advisories/29601/[/url]
--
[SA29600] Slackware update for xine-lib
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-02
Slackware has issued an update for xine-lib. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29600/\"]http://secunia.com/advisories/29600/[/url]
--
[SA29597] Fedora update for centerim
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-02
Fedora has issued an update for centerim. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29597/\"]http://secunia.com/advisories/29597/[/url]
--
[SA29596] Slackware update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-31
Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29596/\"]http://secunia.com/advisories/29596/[/url]
--
[SA29594] Slackware update for mozilla-firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Exposure of sensitive information, System access, Security Bypass
Released: 2008-03-31
Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29594/\"]http://secunia.com/advisories/29594/[/url]
--
[SA29582] SUSE update for Sun Java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-04-03
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29582/\"]http://secunia.com/advisories/29582/[/url]
--
[SA29578] Slackware update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31
Slackware has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29578/\"]http://secunia.com/advisories/29578/[/url]
--
[SA29649] rPath update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29649/\"]http://secunia.com/advisories/29649/[/url]
--
[SA29619] Fedora update for Perlbal
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31
Fedora has issued an update for Perlbal. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29619/\"]http://secunia.com/advisories/29619/[/url]
--
[SA29591] VMware ESX Server update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31
VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29591/\"]http://secunia.com/advisories/29591/[/url]
--
[SA29580] Debian update for exiftags
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28
Debian has issued an update for exiftags. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29580/\"]http://secunia.com/advisories/29580/[/url]
--
[SA29655] Mandriva update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03
Mandriva has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29655/\"]http://secunia.com/advisories/29655/[/url]
--
[SA29634] Gentoo update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02
Gentoo has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29634/\"]http://secunia.com/advisories/29634/[/url]
--
[SA29630] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-02
Red Hat has issued an update for cups. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29630/\"]http://secunia.com/advisories/29630/[/url]
--
[SA29603] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03
Ubuntu has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29603/\"]http://secunia.com/advisories/29603/[/url]
--
[SA29573] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02
Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29573/\"]http://secunia.com/advisories/29573/[/url]
--
[SA29656] Gentoo update for bzip2
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-03
Gentoo has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29656/\"]http://secunia.com/advisories/29656/[/url]
--
[SA29644] Apache-SSL Environment Variables Manipulation Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-03
Alexander Klink has reported a vulnerability in Apache-SSL, which can be exploited by malicious people to manipulate certain data or to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29644/\"]http://secunia.com/advisories/29644/[/url]
--
[SA29574] FreeBSD "strfmon()" Multiple Integer Overflows
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28
Maksymilian Arciemowicz has reported some vulnerabilities in FreeBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29574/\"]http://secunia.com/advisories/29574/[/url]
--
[SA29638] HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-04-02
HP has acknowledged some vulnerabilities in PostgreSQL, which can be exploited by malicious users to to gain escalated privileges or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29638/\"]http://secunia.com/advisories/29638/[/url]
--
[SA29570] SUSE update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-28
SUSE has issued an update for the kernel. This fixes some vulnerabilities and a security issue, which can be exploited by
malicious, local users to bypass certain security restrictions and disclose potentially sensitive information, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29570/\"]http://secunia.com/advisories/29570/[/url]
--
[SA29648] Fedora update for mod_suphp
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Fedora has issued an update for mod_suphp. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29648/\"]http://secunia.com/advisories/29648/[/url]
--
[SA29642] Red Hat lspp-eal4-config-ibm / capp-lspp-eal4-config-hp Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Red Hat has acknowledged a security issue in the lspp-eal4-config-ibm and capp-lspp-eal4-config-hp packages, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29642/\"]http://secunia.com/advisories/29642/[/url]
--
[SA29627] OpenBSD update for OpenSSH
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03
OpenBSD has issued an update for OpenSSH. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29627/\"]http://secunia.com/advisories/29627/[/url]
--
[SA29626] Ubuntu update for openssh
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02
Ubuntu has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29626/\"]http://secunia.com/advisories/29626/[/url]
--
[SA29617] Linux Audit "audit_log_user_command()" Buffer Overflow
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A vulnerability has been reported in Linux Audit, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29617/\"]http://secunia.com/advisories/29617/[/url]
--
[SA29615] suPHP Race Condition Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Some vulnerabilities have been reported in suPHP, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29615/\"]http://secunia.com/advisories/29615/[/url]
--
[SA29588] Fedora update for phpMyAdmin
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02
Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can potentially be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29588/\"]http://secunia.com/advisories/29588/[/url]
--
[SA29577] Eterm X11 Display Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A security issue has been reported in Eterm, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29577/\"]http://secunia.com/advisories/29577/[/url]
--
[SA29576] rxvt X11 Display Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
Bernhard R. Link has reported a security issue in rxvt, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29576/\"]http://secunia.com/advisories/29576/[/url]
--
[SA29666] Fedora update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03
Fedora has issued an update for gnome-screensaver. This fixes a weakness, which can be exploited by malicious people with physical access to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29666/\"]http://secunia.com/advisories/29666/[/url]
--
[SA29654] Solaris inetd Debug Logging Symlink Security Issue
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-03
Sun has acknowledged a security issue in Solaris, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29654/\"]http://secunia.com/advisories/29654/[/url]
--
[SA29609] OpenBSD OpenSSH ForceCommand Bypass Weakness
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31
A weakness has been reported in OpenBSD, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29609/\"]http://secunia.com/advisories/29609/[/url]
--
[SA29606] Red Hat update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-04-03
Red Hat has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with
physical access to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29606/\"]http://secunia.com/advisories/29606/[/url]
--
[SA29602] OpenSSH ForceCommand Bypass Weakness
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31
A weakness has been reported in OpenSSH, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29602/\"]http://secunia.com/advisories/29602/[/url]
--
[SA29595] gnome-screensaver Information Disclosure and Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-03
A weakness and a security issue have been reported in gnome-screensaver, which can be exploited by malicious people with
physical access to disclose potentially sensitive information or bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29595/\"]http://secunia.com/advisories/29595/[/url]
[b]Other:--[/b]
[SA29587] Novell NetWare iPrint Request Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-02
A vulnerability has been reported in Novell NetWare, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29587/\"]http://secunia.com/advisories/29587/[/url]
[b]Cross Platform:--[/b]
[SA29662] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-03
Some vulnerabilities have been reported in Opera, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29662/\"]http://secunia.com/advisories/29662/[/url]
--
[SA29650] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-03
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to disclose potentially sensitive information or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29650/\"]http://secunia.com/advisories/29650/[/url]
--
[SA29653] DaZPHPNews "prefixdir" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-03
w0cker has discovered a vulnerability in DaZPHPNews, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29653/\"]http://secunia.com/advisories/29653/[/url]
--
[SA29652] Writer's Block CMS "PostID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-03
katharsis has discovered a vulnerability in Writer's Block CMS, which can be exploited by malicious people to conduct SQL injection attacks
Full Advisory:
[url=\"http://secunia.com/advisories/29652/\"]http://secunia.com/advisories/29652/[/url]
--
[SA29647] IBM DB2 Content Manager AllowedTrustedLogin Security Issue
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-04-02
A security issue with an unknown impact has been reported in IBM DB2 Content Manager.
Full Advisory:
[url=\"http://secunia.com/advisories/29647/\"]http://secunia.com/advisories/29647/[/url]
--
[SA29628] Faphoto "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-02
IRCRASH has discovered a vulnerability in Faphoto, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29628/\"]http://secunia.com/advisories/29628/[/url]
--
[SA29624] EasyNews Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-02
Dr.Crash has discovered some vulnerabilities in EasyNews, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29624/\"]http://secunia.com/advisories/29624/[/url]
--
[SA29612] CuteFlow Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-03-31
Some vulnerabilities have been discovered in CuteFlow, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29612/\"]http://secunia.com/advisories/29612/[/url]
--
[SA29608] WordPress WP-Download Plugin "dl_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-01
BL4CK has reported a vulnerability in the WP-Download plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29608/\"]http://secunia.com/advisories/29608/[/url]
--
[SA29593] AuraCMS "country" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-02
NTOS-Team have discovered a vulnerability in AuraCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29593/\"]http://secunia.com/advisories/29593/[/url]
--
[SA29592] Sava's GuestBook "action" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-01
Dr. Crash has discovered a vulnerability in Sava's GuestBook, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29592/\"]http://secunia.com/advisories/29592/[/url]
--
[SA29589] Sava's Link Manager Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-01
Dr. Crash has discovered two vulnerabilities in Sava's Link Manager, which can be exploited by malicious people to disclose sensitive information and to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29589/\"]http://secunia.com/advisories/29589/[/url]
--
[SA29584] PowerDNS Recursor DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-03-31
Amit Klein has reported a vulnerability in PowerDNS Recursor, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/29584/\"]http://secunia.com/advisories/29584/[/url]
--
[SA29583] eggBlog "index.php" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-28
__GiReX__ has reported two vulnerabilities in eggBlog, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29583/\"]http://secunia.com/advisories/29583/[/url]
--
[SA29579] PHPkrm Unspecified Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
A vulnerability has been reported in PHPkrm, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29579/\"]http://secunia.com/advisories/29579/[/url]
--
[SA29575] Sympa Malformed "Content-Type" Header Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-01
A vulnerability has been reported in Sympa, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29575/\"]http://secunia.com/advisories/29575/[/url]
--
[SA29571] Smoothflash "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-31
S@BUN has reported a vulnerability in Smoothflash, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29571/\"]http://secunia.com/advisories/29571/[/url]
--
[SA29569] Wireshark Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-28
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29569/\"]http://secunia.com/advisories/29569/[/url]
--
[SA29658] Drupal Flickr Module Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Some vulnerabilities have been reported in the Flickr module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29658/\"]http://secunia.com/advisories/29658/[/url]
--
[SA29646] Simple Gallery "album" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Russ McRee has discovered a vulnerability in Simple Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29646/\"]http://secunia.com/advisories/29646/[/url]
--
[SA29643] HP Select Identity Unspecified Unauthorised Access Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure
of sensitive information
Released: 2008-04-02
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29643/\"]http://secunia.com/advisories/29643/[/url]
--
[SA29633] Drupal Webform Module Unspecified Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Some vulnerabilities have been reported in the Webform module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29633/\"]http://secunia.com/advisories/29633/[/url]
--
[SA29623] Smart Classified / Photo ADS Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Russ McRee has reported some vulnerabilities in Smart Classified ADS and Smart Photo ADS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29623/\"]http://secunia.com/advisories/29623/[/url]
--
[SA29610] InspIRCd Unspecified Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2008-03-31
A vulnerability with unknown impact has been reported in InspIRCd.
Full Advisory:
[url=\"http://secunia.com/advisories/29610/\"]http://secunia.com/advisories/29610/[/url]
--
[SA29599] JV2 Folder Gallery "image" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
Russ McRee has discovered a vulnerability in JV2 Folder Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29599/\"]http://secunia.com/advisories/29599/[/url]
--
[SA29598] JV2 Quick Gallery "f" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
Russ McRee has discovered a vulnerability in JV2 Quick Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29598/\"]http://secunia.com/advisories/29598/[/url]
--
[SA29613] phpMyAdmin Username/Password Session File Information Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-31
Jim Hermann has discovered a vulnerability in phpMyAdmin, which can potentially be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29613/\"]http://secunia.com/advisories/29613/[/url]
--
[SA29586] Nik Sharpener Pro Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A security issue has been discovered in Nik Sharpener Pro, which potentially can be exploited by malicious, local users to gain
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29586/\"]http://secunia.com/advisories/29586/[/url]
[b]Windows:--[/b]
[SA29620] XnView Slideshow "FontName" Buffer Overflow Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31
Secunia Research has discovered a vulnerability in XnView, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29620/\"]http://secunia.com/advisories/29620/[/url]
--
[SA29629] NoticeWare Email Server IMAP Packet Handling Denial of Service
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02
Ray has discovered a vulnerability in NoticeWare Email Server, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29629/\"]http://secunia.com/advisories/29629/[/url]
--
[SA29614] SLMail Pro Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-31
Luigi Auriemma has discovered some vulnerabilities in SLMail Pro, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29614/\"]http://secunia.com/advisories/29614/[/url]
--
[SA29611] EfesTECH Video "catID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01
RMx has discovered a vulnerability in EfesTECH Video, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29611/\"]http://secunia.com/advisories/29611/[/url]
--
[SA29641] HP OpenView Network Node Manager Buffer Overflow Vulnerability
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-03
Mati Aharoni has discovered a vulnerability in HP OpenView Network Node Manager, which can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29641/\"]http://secunia.com/advisories/29641/[/url]
--
[SA29660] Symantec Products AutoFix Support Tool ActiveX Control Two Vulnerabilities
Critical: Less critical
Where: From remote
Impact: System access
Released: 2008-04-03
Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29660/\"]http://secunia.com/advisories/29660/[/url]
--
[SA29581] Chilkat HTTP ActiveX Component ActiveX Controls "SaveLastError()" Insecure Method
Critical: Less critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-01
shinnai has discovered a vulnerability in Chilkat HTTP ActiveX Component, which can be exploited by malicious people to overwrite
arbitrary files.
Full Advisory:
[url=\"http://secunia.com/advisories/29581/\"]http://secunia.com/advisories/29581/[/url]
--
[SA29572] DigiDomain Multiple Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-28
Linux_Drox has reported some vulnerabilities in DigiDomain, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29572/\"]http://secunia.com/advisories/29572/[/url]
--
[SA29639] Novell eDirectory Host Environment HTTP Request Processing Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-03
Mati Aharoni has discovered a vulnerability in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29639/\"]http://secunia.com/advisories/29639/[/url]
--
[SA29590] 2X ThinClientServer 2XTFTPd Service Directory Traversal
Critical: Less critical
Where: From local network
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-03-31
Luigi Auriemma has discovered a vulnerability in 2X ThinClientServer, which can be exploited by malicious people to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29590/\"]http://secunia.com/advisories/29590/[/url]
--
[SA29605] avast! Home/Professional aavmker4.sys Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
Tobias Klein has reported a vulnerability in avast! Home/Professional, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29605/\"]http://secunia.com/advisories/29605/[/url]
[b]UNIX/Linux:--[/b]
[SA29621] Comix Arbitrary Shell Command Execution Vulnerability
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01
A vulnerability has been reported in Comix, which can be exploited by malicious people to compromise a user's sytem.
Full Advisory:
[url=\"http://secunia.com/advisories/29621/\"]http://secunia.com/advisories/29621/[/url]
--
[SA29618] Fedora update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-04-02
Fedora has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29618/\"]http://secunia.com/advisories/29618/[/url]
--
[SA29616] Debian update for iceweasel
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure
of sensitive information, System access
Released: 2008-03-31
Debian has issued an update for iceweasel. This fixes some vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29616/\"]http://secunia.com/advisories/29616/[/url]
--
[SA29601] Debian update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-01
Debian has issued an update for xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to
compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29601/\"]http://secunia.com/advisories/29601/[/url]
--
[SA29600] Slackware update for xine-lib
Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2008-04-02
Slackware has issued an update for xine-lib. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29600/\"]http://secunia.com/advisories/29600/[/url]
--
[SA29597] Fedora update for centerim
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-02
Fedora has issued an update for centerim. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29597/\"]http://secunia.com/advisories/29597/[/url]
--
[SA29596] Slackware update for seamonkey
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Spoofing, Exposure of sensitive information, System access
Released: 2008-03-31
Slackware has issued an update for seamonkey. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29596/\"]http://secunia.com/advisories/29596/[/url]
--
[SA29594] Slackware update for mozilla-firefox
Critical: Highly critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Exposure of sensitive information, System access, Security Bypass
Released: 2008-03-31
Slackware has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, conduct cross-site scripting and phishing attacks, and
potentially compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29594/\"]http://secunia.com/advisories/29594/[/url]
--
[SA29582] SUSE update for Sun Java
Critical: Highly critical
Where: From remote
Impact: Security Bypass, Manipulation of data, DoS, System access
Released: 2008-04-03
SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service), to bypass certain security restrictions, or to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29582/\"]http://secunia.com/advisories/29582/[/url]
--
[SA29578] Slackware update for xine-lib
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-03-31
Slackware has issued an update for xine-lib. This fixes a vulnerability, which can be exploited by malicious people to compromise
a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29578/\"]http://secunia.com/advisories/29578/[/url]
--
[SA29649] rPath update for lighttpd
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-02
rPath has issued an update for lighttpd. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29649/\"]http://secunia.com/advisories/29649/[/url]
--
[SA29619] Fedora update for Perlbal
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31
Fedora has issued an update for Perlbal. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29619/\"]http://secunia.com/advisories/29619/[/url]
--
[SA29591] VMware ESX Server update for libxml2
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-31
VMware has issued an update for VMware ESX Server. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29591/\"]http://secunia.com/advisories/29591/[/url]
--
[SA29580] Debian update for exiftags
Critical: Moderately critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28
Debian has issued an update for exiftags. This fixes some vulnerabilities, which potentially can be exploited by malicious people
to cause a DoS (Denial of Service) or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29580/\"]http://secunia.com/advisories/29580/[/url]
--
[SA29655] Mandriva update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03
Mandriva has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a
DoS (Denial of Service) and potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29655/\"]http://secunia.com/advisories/29655/[/url]
--
[SA29634] Gentoo update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02
Gentoo has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29634/\"]http://secunia.com/advisories/29634/[/url]
--
[SA29630] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: System access
Released: 2008-04-02
Red Hat has issued an update for cups. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29630/\"]http://secunia.com/advisories/29630/[/url]
--
[SA29603] Ubuntu update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-03
Ubuntu has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29603/\"]http://secunia.com/advisories/29603/[/url]
--
[SA29573] Red Hat update for cups
Critical: Moderately critical
Where: From local network
Impact: DoS, System access
Released: 2008-04-02
Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29573/\"]http://secunia.com/advisories/29573/[/url]
--
[SA29656] Gentoo update for bzip2
Critical: Less critical
Where: From remote
Impact: DoS
Released: 2008-04-03
Gentoo has issued an update for bzip2. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29656/\"]http://secunia.com/advisories/29656/[/url]
--
[SA29644] Apache-SSL Environment Variables Manipulation Vulnerability
Critical: Less critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-03
Alexander Klink has reported a vulnerability in Apache-SSL, which can be exploited by malicious people to manipulate certain data or to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29644/\"]http://secunia.com/advisories/29644/[/url]
--
[SA29574] FreeBSD "strfmon()" Multiple Integer Overflows
Critical: Less critical
Where: From remote
Impact: DoS, System access
Released: 2008-03-28
Maksymilian Arciemowicz has reported some vulnerabilities in FreeBSD, which potentially can be exploited by malicious people to compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29574/\"]http://secunia.com/advisories/29574/[/url]
--
[SA29638] HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities
Critical: Less critical
Where: From local network
Impact: Privilege escalation, DoS
Released: 2008-04-02
HP has acknowledged some vulnerabilities in PostgreSQL, which can be exploited by malicious users to to gain escalated privileges or to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29638/\"]http://secunia.com/advisories/29638/[/url]
--
[SA29570] SUSE update for kernel
Critical: Less critical
Where: From local network
Impact: Security Bypass, Exposure of sensitive information, DoS, System access
Released: 2008-03-28
SUSE has issued an update for the kernel. This fixes some vulnerabilities and a security issue, which can be exploited by
malicious, local users to bypass certain security restrictions and disclose potentially sensitive information, and by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29570/\"]http://secunia.com/advisories/29570/[/url]
--
[SA29648] Fedora update for mod_suphp
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Fedora has issued an update for mod_suphp. This fixes some vulnerabilities, which can be exploited by malicious, local users to
gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29648/\"]http://secunia.com/advisories/29648/[/url]
--
[SA29642] Red Hat lspp-eal4-config-ibm / capp-lspp-eal4-config-hp Privilege Escalation
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Red Hat has acknowledged a security issue in the lspp-eal4-config-ibm and capp-lspp-eal4-config-hp packages, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29642/\"]http://secunia.com/advisories/29642/[/url]
--
[SA29627] OpenBSD update for OpenSSH
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03
OpenBSD has issued an update for OpenSSH. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29627/\"]http://secunia.com/advisories/29627/[/url]
--
[SA29626] Ubuntu update for openssh
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02
Ubuntu has issued an update for openssh. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29626/\"]http://secunia.com/advisories/29626/[/url]
--
[SA29617] Linux Audit "audit_log_user_command()" Buffer Overflow
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A vulnerability has been reported in Linux Audit, which potentially can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29617/\"]http://secunia.com/advisories/29617/[/url]
--
[SA29615] suPHP Race Condition Vulnerabilities
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-02
Some vulnerabilities have been reported in suPHP, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29615/\"]http://secunia.com/advisories/29615/[/url]
--
[SA29588] Fedora update for phpMyAdmin
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-02
Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can potentially be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29588/\"]http://secunia.com/advisories/29588/[/url]
--
[SA29577] Eterm X11 Display Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A security issue has been reported in Eterm, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29577/\"]http://secunia.com/advisories/29577/[/url]
--
[SA29576] rxvt X11 Display Security Issue
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
Bernhard R. Link has reported a security issue in rxvt, which can be exploited by malicious, local users to gain escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29576/\"]http://secunia.com/advisories/29576/[/url]
--
[SA29666] Fedora update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-04-03
Fedora has issued an update for gnome-screensaver. This fixes a weakness, which can be exploited by malicious people with physical access to disclose potentially sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29666/\"]http://secunia.com/advisories/29666/[/url]
--
[SA29654] Solaris inetd Debug Logging Symlink Security Issue
Critical: Not critical
Where: Local system
Impact: Privilege escalation
Released: 2008-04-03
Sun has acknowledged a security issue in Solaris, which can be exploited by malicious, local users to perform certain actions with
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29654/\"]http://secunia.com/advisories/29654/[/url]
--
[SA29609] OpenBSD OpenSSH ForceCommand Bypass Weakness
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31
A weakness has been reported in OpenBSD, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29609/\"]http://secunia.com/advisories/29609/[/url]
--
[SA29606] Red Hat update for gnome-screensaver
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-04-03
Red Hat has issued an update for gnome-screensaver. This fixes a security issue, which can be exploited by malicious people with
physical access to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29606/\"]http://secunia.com/advisories/29606/[/url]
--
[SA29602] OpenSSH ForceCommand Bypass Weakness
Critical: Not critical
Where: Local system
Impact: Security Bypass
Released: 2008-03-31
A weakness has been reported in OpenSSH, which can be exploited by malicious, local users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29602/\"]http://secunia.com/advisories/29602/[/url]
--
[SA29595] gnome-screensaver Information Disclosure and Security Bypass
Critical: Not critical
Where: Local system
Impact: Security Bypass, Exposure of sensitive information
Released: 2008-04-03
A weakness and a security issue have been reported in gnome-screensaver, which can be exploited by malicious people with
physical access to disclose potentially sensitive information or bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29595/\"]http://secunia.com/advisories/29595/[/url]
[b]Other:--[/b]
[SA29587] Novell NetWare iPrint Request Denial of Service
Critical: Less critical
Where: From local network
Impact: DoS
Released: 2008-04-02
A vulnerability has been reported in Novell NetWare, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29587/\"]http://secunia.com/advisories/29587/[/url]
[b]Cross Platform:--[/b]
[SA29662] Opera Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: System access
Released: 2008-04-03
Some vulnerabilities have been reported in Opera, which potentially can be exploited by malicious people to compromise a user's system.
Full Advisory:
[url=\"http://secunia.com/advisories/29662/\"]http://secunia.com/advisories/29662/[/url]
--
[SA29650] Apple QuickTime Multiple Vulnerabilities
Critical: Highly critical
Where: From remote
Impact: Exposure of sensitive information, DoS, System access
Released: 2008-04-03
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to disclose potentially sensitive information or compromise a vulnerable system.
Full Advisory:
[url=\"http://secunia.com/advisories/29650/\"]http://secunia.com/advisories/29650/[/url]
--
[SA29653] DaZPHPNews "prefixdir" Local File Inclusion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-03
w0cker has discovered a vulnerability in DaZPHPNews, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29653/\"]http://secunia.com/advisories/29653/[/url]
--
[SA29652] Writer's Block CMS "PostID" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-03
katharsis has discovered a vulnerability in Writer's Block CMS, which can be exploited by malicious people to conduct SQL injection attacks
Full Advisory:
[url=\"http://secunia.com/advisories/29652/\"]http://secunia.com/advisories/29652/[/url]
--
[SA29647] IBM DB2 Content Manager AllowedTrustedLogin Security Issue
Critical: Moderately critical
Where: From remote
Impact: Unknown
Released: 2008-04-02
A security issue with an unknown impact has been reported in IBM DB2 Content Manager.
Full Advisory:
[url=\"http://secunia.com/advisories/29647/\"]http://secunia.com/advisories/29647/[/url]
--
[SA29628] Faphoto "id" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-02
IRCRASH has discovered a vulnerability in Faphoto, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29628/\"]http://secunia.com/advisories/29628/[/url]
--
[SA29624] EasyNews Multiple Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-02
Dr.Crash has discovered some vulnerabilities in EasyNews, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29624/\"]http://secunia.com/advisories/29624/[/url]
--
[SA29612] CuteFlow Cross-Site Scripting and SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2008-03-31
Some vulnerabilities have been discovered in CuteFlow, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting and SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29612/\"]http://secunia.com/advisories/29612/[/url]
--
[SA29608] WordPress WP-Download Plugin "dl_id" SQL Injection
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-04-01
BL4CK has reported a vulnerability in the WP-Download plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29608/\"]http://secunia.com/advisories/29608/[/url]
--
[SA29593] AuraCMS "country" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2008-04-02
NTOS-Team have discovered a vulnerability in AuraCMS, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29593/\"]http://secunia.com/advisories/29593/[/url]
--
[SA29592] Sava's GuestBook "action" Local File Inclusion
Critical: Moderately critical
Where: From remote
Impact: Exposure of system information, Exposure of sensitive information
Released: 2008-04-01
Dr. Crash has discovered a vulnerability in Sava's GuestBook, which can be exploited by malicious people to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29592/\"]http://secunia.com/advisories/29592/[/url]
--
[SA29589] Sava's Link Manager Two Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of system information, Exposure of sensitive information
Released: 2008-04-01
Dr. Crash has discovered two vulnerabilities in Sava's Link Manager, which can be exploited by malicious people to disclose sensitive information and to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29589/\"]http://secunia.com/advisories/29589/[/url]
--
[SA29584] PowerDNS Recursor DNS Cache Poisoning Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Spoofing
Released: 2008-03-31
Amit Klein has reported a vulnerability in PowerDNS Recursor, which can be exploited by malicious people to poison the DNS cache.
Full Advisory:
[url=\"http://secunia.com/advisories/29584/\"]http://secunia.com/advisories/29584/[/url]
--
[SA29583] eggBlog "index.php" SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-28
__GiReX__ has reported two vulnerabilities in eggBlog, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29583/\"]http://secunia.com/advisories/29583/[/url]
--
[SA29579] PHPkrm Unspecified Script Insertion Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
A vulnerability has been reported in PHPkrm, which can be exploited by malicious people to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29579/\"]http://secunia.com/advisories/29579/[/url]
--
[SA29575] Sympa Malformed "Content-Type" Header Denial of Service Vulnerability
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-04-01
A vulnerability has been reported in Sympa, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29575/\"]http://secunia.com/advisories/29575/[/url]
--
[SA29571] Smoothflash "cid" SQL Injection Vulnerability
Critical: Moderately critical
Where: From remote
Impact: Manipulation of data, Exposure of sensitive information
Released: 2008-03-31
S@BUN has reported a vulnerability in Smoothflash, which can be exploited by malicious people to conduct SQL injection attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29571/\"]http://secunia.com/advisories/29571/[/url]
--
[SA29569] Wireshark Multiple Denial of Service Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2008-03-28
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
Full Advisory:
[url=\"http://secunia.com/advisories/29569/\"]http://secunia.com/advisories/29569/[/url]
--
[SA29658] Drupal Flickr Module Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Some vulnerabilities have been reported in the Flickr module for Drupal, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29658/\"]http://secunia.com/advisories/29658/[/url]
--
[SA29646] Simple Gallery "album" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Russ McRee has discovered a vulnerability in Simple Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29646/\"]http://secunia.com/advisories/29646/[/url]
--
[SA29643] HP Select Identity Unspecified Unauthorised Access Vulnerability
Critical: Less critical
Where: From remote
Impact: Security Bypass, Exposure of system information, Exposure
of sensitive information
Released: 2008-04-02
A vulnerability has been reported in HP Select Identity, which can be exploited by malicious users to bypass certain security restrictions.
Full Advisory:
[url=\"http://secunia.com/advisories/29643/\"]http://secunia.com/advisories/29643/[/url]
--
[SA29633] Drupal Webform Module Unspecified Script Insertion
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Some vulnerabilities have been reported in the Webform module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29633/\"]http://secunia.com/advisories/29633/[/url]
--
[SA29623] Smart Classified / Photo ADS Cross-Site Scripting Vulnerabilities
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-04-03
Russ McRee has reported some vulnerabilities in Smart Classified ADS and Smart Photo ADS, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29623/\"]http://secunia.com/advisories/29623/[/url]
--
[SA29610] InspIRCd Unspecified Vulnerability
Critical: Less critical
Where: From remote
Impact: Unknown
Released: 2008-03-31
A vulnerability with unknown impact has been reported in InspIRCd.
Full Advisory:
[url=\"http://secunia.com/advisories/29610/\"]http://secunia.com/advisories/29610/[/url]
--
[SA29599] JV2 Folder Gallery "image" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
Russ McRee has discovered a vulnerability in JV2 Folder Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29599/\"]http://secunia.com/advisories/29599/[/url]
--
[SA29598] JV2 Quick Gallery "f" Cross-Site Scripting
Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2008-03-31
Russ McRee has discovered a vulnerability in JV2 Quick Gallery, which can be exploited by malicious people to conduct cross-site scripting attacks.
Full Advisory:
[url=\"http://secunia.com/advisories/29598/\"]http://secunia.com/advisories/29598/[/url]
--
[SA29613] phpMyAdmin Username/Password Session File Information Disclosure
Critical: Less critical
Where: Local system
Impact: Exposure of sensitive information
Released: 2008-03-31
Jim Hermann has discovered a vulnerability in phpMyAdmin, which can potentially be exploited by malicious users to disclose sensitive information.
Full Advisory:
[url=\"http://secunia.com/advisories/29613/\"]http://secunia.com/advisories/29613/[/url]
--
[SA29586] Nik Sharpener Pro Insecure File Permissions
Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2008-03-31
A security issue has been discovered in Nik Sharpener Pro, which potentially can be exploited by malicious, local users to gain
escalated privileges.
Full Advisory:
[url=\"http://secunia.com/advisories/29586/\"]http://secunia.com/advisories/29586/[/url]