Contents
Cal Poly Pomona

Latest Unix and Other Bulletins

Report date: January 20, 2009  Date posted: January 20, 2009

This report combines relevant bulletins from SANS, Secunia and CERT. The wording is original with some "back" links added where needed. The CERT index lists vulnerabilities with and without solutions. Click the link for specific information.

At a very minimum, look at the SANS bulletins as they include the top issues on a weekly basis. Next, review Secunia for a more complete listing with well structured bulletins avaiable as external links. Finally, the CERT section contains very detailed information and many newly discovered vulnerabilities and updates on existing issues.

Tip: highlight any link below to reveal the criticality or priority.

    SANS Bulletin - Vol 7 Num 53

    None relevant

    Secunia Bulletin - 2008-54

    CERT Bulletin - SB08-378

    None relevant

    BULLETIN DETAIL


    Secunia Bulletin

    back  [SA33496] Triologic Media Player Playlist Processing Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-13

    A vulnerability has been discovered in Triologic Media Player, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33496/


    back  [SA33483] Browse3D ".sfs" Processing Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-12

    Houssamix has discovered a vulnerability in Browse3D, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33483/


    back  [SA33478] Winamp AIFF Processing Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-13

    securfrog has discovered a vulnerability in Winamp, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33478/


    back  [SA33541] Avira Antivir RAR Processing Denial of Service Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2009-01-15

    Thierry Zoller has reported some vulnerabilities in Avira Antivir, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33541/


    back  [SA33489] DMXReady SDK "download_link.asp" Security Bypass Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information
    Released: 2009-01-15

    ajann has reported a vulnerability in DMXReady SDK, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33489/


    back  [SA33487] Members Area Manager "cid" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-14

    ajann has reported a vulnerability in Members Area Manager, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33487/


    back  [SA33482] DMXReady Multiple Products "cid" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-15

    ajann has reported a vulnerability in multiple DMXReady products, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33482/


    back  [SA33537] AAA EasyGrid ActiveX Control "DoSaveFile()" Insecure Method

    Critical:  Less critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-15

    Houssamix has discovered a vulnerability in AAA EasyGrid ActiveX, which can be exploited by malicious people to overwrite arbitrary files.

    Full Advisory:
    http://secunia.com/advisories/33537/


    back  [SA33561] TFTPUtil Directory Traversal Vulnerability

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of system information, Exposure of sensitive
    information
    Released: 2009-01-15

    Rob Kraus has discovered a vulnerability in TFTPUtil, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33561/


    back  [SA33547] Debian update for xulrunner

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting, Exposure of
    sensitive information, System access
    Released: 2009-01-15

    Debian has issued an update for xulrunner. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33547/


    back  [SA33536] Red Hat update for java-1.5.0-ibm

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access, Exposure of sensitive information,
    Exposure of system information, Security Bypass
    Released: 2009-01-14

    Red Hat has issued an update for java-1.5.0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33536/


    back  [SA33528] Red Hat update for java-1.6.0-ibm

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, DoS, System access
    Released: 2009-01-14

    Red Hat has issued an update for java-1.6.0-ibm. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33528/


    back  [SA33505] Amarok Audible Audio Processing Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-12

    Tobias Klein has reported some vulnerabilities in Amarok, which potentially can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33505/


    back  [SA33503] Gentoo update for mplayer

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2009-01-13

    Gentoo has issued an update for mplayer. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33503/


    back  [SA33493] SUSE Update for Mozilla Products

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting, Exposure of
    sensitive information, System access
    Released: 2009-01-14

    SUSE has issued an update for MozillaFirefox, MozillaThunderbird, and mozilla. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33493/


    back  [SA33491] Sun Solaris Adobe Reader Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Privilege escalation, System access
    Released: 2009-01-12

    Sun has acknowledged some vulnerabilities Adobe Reader included in Solaris, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33491/


    back  [SA33473] FTTSS A Free Text-To-Speech System "voz" Command Injection Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-12

    A vulnerability has been discovered in FTTSS A Free Text-To-Speech System, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33473/


    back  [SA33462] SUSE Update for Multiple Packages

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data, Exposure of
    sensitive information, Privilege escalation, DoS, System access
    Released: 2009-01-13

    SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or to gain escalated privileges, by malicious users to bypass certain security restrictions or to cause a DoS (Denial of Service), and by malicious people to disclose sensitive information, bypass certain security restrictions, conduct SQL injection and cross-site scripting attacks, to cause a DoS, or potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33462/


    back  [SA33460] Gentoo update for acroread

    Critical:  Highly critical
    Where: From remote
    Impact: Privilege escalation, System access
    Released: 2009-01-13

    Gentoo has issued an update for acroread. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33460/


    back  [SA33457] SUSE update for Sun Java

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, DoS, System access
    Released: 2009-01-12

    SUSE has issued an update for Sun Java. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, cause a DoS (Denial of service), or compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33457/


    back  [SA33557] Slackware update for openssl

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    Slackware has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33557/


    back  [SA33518] IBM HMC Unspecified Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Unknown
    Released: 2009-01-15

    A vulnerability with an unknown impact has been reported in IBM Hardware Management Console (HMC).

    Full Advisory:
    http://secunia.com/advisories/33518/


    back  [SA33517] Red Hat update for squirrelmail

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2009-01-13

    Red Hat has issued an update for squirrelmail. This fixes a vulnerability, which can be exploited by malicious people to conduct script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/33517/


    back  [SA33515] Debian update for openssl and openssl097

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-13

    Debian has issued an update for openssl and openssl097. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33515/


    back  [SA33513] Gentoo update for pdnsd

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2009-01-12

    Gentoo has issued an update for pdnsd. This fixes some vulnerabilities, which can be exploited by malicious people to poison the DNS cache and cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33513/


    back  [SA33511] Gentoo update for ndiswrapper

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2009-01-12

    Gentoo has issued an update for ndiswrapper. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33511/


    back  [SA33509] Gentoo update for streamripper

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2009-01-12

    Gentoo has issued an update for streamripper. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33509/


    back  [SA33508] Gentoo tremulous Buffer Overflow Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2009-01-12

    Gentoo has acknowledged a vulnerability in tremulous and tremulous-bin, which can be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/33508/


    back  [SA33502] Gentoo update for online-bookmarks

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting, Manipulation of
    data
    Released: 2009-01-13

    Gentoo has issued an update for online-bookmarks. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions and conduct cross-site scripting and SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33502/


    back  [SA33501] Gentoo update for gnutls

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Spoofing
    Released: 2009-01-15

    Gentoo has issued an update for gnutls. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33501/


    back  [SA33497] Debian update for lasso

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-12

    Debian has issued an update for lasso. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33497/


    back  [SA33559] Slackware update for bind

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    Slackware has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33559/


    back  [SA33558] Slackware update for ntp

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    Slackware has issued an update for ntp. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33558/


    back  [SA33556] Red Hat update for kernel

    Critical:  Less critical
    Where: From remote
    Impact: DoS
    Released: 2009-01-15

    Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users and malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33556/


    back  [SA33551] OpenBSD update for named

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    OpenBSD has issued an update for named. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33551/


    back  [SA33546] Fedora update for bind

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    Fedora has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33546/


    back  [SA33543] Fedora update for tqsllib

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    Fedora has issued an update for tqsllib. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33543/


    back  [SA33507] Debian update for ntp

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-13

    Debian has issued an update for ntp. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33507/


    back  [SA33504] Debian update for bind9

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-13

    Debian has issued an update for bind9. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33504/


    back  [SA33499] Debian update for gforge

    Critical:  Less critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-12

    Debian has issued an update for gforge. This fixes a vulnerability, which can be exploited by malicious users to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33499/


    back  [SA33494] FreeBSD update for bind

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-15

    FreeBSD has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33494/


    back  [SA33485] libmikmod Denial of Service Vulnerabilities

    Critical:  Less critical
    Where: From remote
    Impact: DoS
    Released: 2009-01-15

    Some vulnerabilities have been reported in libmikmod, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33485/


    back  [SA33454] Red Hat update for bind

    Critical:  Less critical
    Where: From remote
    Impact: Spoofing
    Released: 2009-01-09

    Red Hat has issued an update for bind. This fixes a vulnerability, which potentially can be exploited by malicious people to conduct spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33454/


    back  [SA33527] rPath update for samba, samba-client, and samba-server

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of sensitive information
    Released: 2009-01-14

    rPath has issued an update for samba, samba-client, and samba-server.
    This fixes a vulnerability, which can potentially be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33527/


    back  [SA33520] Red Hat update for avahi

    Critical:  Less critical
    Where: From local network
    Impact: DoS
    Released: 2009-01-13

    Red Hat has issued an update for avahi. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33520/


    back  [SA33492] rPath update for samba

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of sensitive information
    Released: 2009-01-14

    rPath has issued an update for samba. This fixes a vulnerability, which potentially can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33492/


    back  [SA33475] Gentoo update for avahi

    Critical:  Less critical
    Where: From local network
    Impact: DoS
    Released: 2009-01-15

    Gentoo has issued an update for avahi. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33475/


    back  [SA33545] Fedora update for nfs-utils

    Critical:  Less critical
    Where: Local system
    Impact: Security Bypass
    Released: 2009-01-15

    Fedora has acknowledged a weakness in nfs-utils, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33545/


    back  [SA33540] Red Hat Certificate Server Information Disclosure

    Critical:  Less critical
    Where: Local system
    Impact: Exposure of sensitive information
    Released: 2009-01-15

    Red Hat has acknowledged some security issues in Red Hat Certificate Server, which can be exploited by malicious, local users to disclose potentially sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33540/


    back  [SA33539] Ubuntu hplip Privilege Escalation Security Issue

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2009-01-14

    Ubuntu has acknowledged a security issue in hplip, which can be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33539/


    back  [SA33530] Ubuntu update for cups and cupsys

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2009-01-13

    Ubuntu has issued an update for cups and cupsys. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33530/


    back  [SA33512] Gentoo update for jhead

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2009-01-12

    Gentoo has issued an update for jhead. This fixes some security issues, which can be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33512/


    back  [SA33477] Linux Kernel 64bit ABI System Call Parameter Sign Extension Security Issue

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation, DoS
    Released: 2009-01-14

    A security issue has been reported in the Linux Kernel, which can be exploited by malicious, local users to potentially cause a DoS (Denial of Service) or gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33477/


    back  [SA33455] Red Hat update for kernel

    Critical:  Less critical
    Where: Local system
    Impact: Security Bypass, Exposure of sensitive information,
    Privilege escalation, DoS
    Released: 2009-01-09

    Red Hat has issued an update for the kernel. This fixes some security issues and vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service), disclose potentially sensitive information, bypass certain security restrictions, and gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33455/


    back  [SA33453] Asterisk User Account Enumeration Weakness

    Critical:  Not critical
    Where: From local network
    Impact: Exposure of system information
    Released: 2009-01-09

    A weakness has been reported in Asterisk, which can be exploited by malicious people to identify valid user accounts.

    Full Advisory:
    http://secunia.com/advisories/33453/


    back  [SA33516] Sun Solaris "aio_suspend()" Integer Overflow Vulnerability

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2009-01-12

    Tobias Klein has reported a vulnerability in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33516/


    back  [SA33510] Gentoo update for dbus

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2009-01-12

    Gentoo has issued an update for dbus. This fixes a weakness, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33510/


    back  [SA33498] Debian update for zaptel

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2009-01-12

    Debian has issued an update for zaptel. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33498/


    back  [SA33488] Sun Solaris "lpadmin" and "ppdmgr" Denial of Service Vulnerabilities

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2009-01-15

    Some vulnerabilities have been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33488/


    back  [SA33519] pfSense update for lukemftpd and openssl

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting, Spoofing
    Released: 2009-01-12

    pfSense has acknowledged some vulnerabilities in pfSense, which can be exploited by malicious people to conduct cross-site request forgery or spoofing attacks.

    Full Advisory:
    http://secunia.com/advisories/33519/


    back  [SA33479] Cisco IronPort Products Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Exposure of sensitive information
    Released: 2009-01-15

    Some vulnerabilities have been reported in Cisco IronPort products, which can be exploited by malicious people to disclose sensitive information or conduct cross-site request forgery attacks.

    Full Advisory:
    http://secunia.com/advisories/33479/


    back  [SA33456] WebSphere DataPower XML Security Gateway XS40 Denial of Service

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2009-01-13

    A vulnerability has been reported in IBM DataPower XS40, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33456/


    back  [SA33461] Cisco IOS HTTP Server Two Cross-Site Scripting Vulnerabilities

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2009-01-15

    Two vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/33461/


    back  [SA33464] Cisco ONS Products Denial of Service Vulnerability

    Critical:  Less critical
    Where: From local network
    Impact: DoS
    Released: 2009-01-15

    A vulnerability has been reported in several Cisco ONS products, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33464/


    back  [SA33534] BlackBerry Products PDF Distiller Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2009-01-13

    Some vulnerabilities have been reported in BlackBerry Enterprise Server and BlackBerry Unite!, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33534/


    back  [SA33526] Oracle BEA WebLogic Server Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Exposure of sensitive information, DoS, System access
    Released: 2009-01-14

    Some vulnerabilities have been reported in Oracle BEA WebLogic Server, which can be exploited by malicious people to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33526/


    back  [SA33525] Oracle Products Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Unknown, Cross Site Scripting, Manipulation of data,
    Privilege escalation, DoS, System access
    Released: 2009-01-14

    Some vulnerabilities have been reported in various Oracle products.
    Some have unknown impact while others can be exploited by malicious users to conduct SQL injection attacks or manipulate certain data, and by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), or to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33525/


    back  [SA33465] Realtor 747 "INC_DIR" File Inclusion Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2009-01-14

    ahmadbady has discovered a vulnerability in Realtor 747, which can be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/33465/


    back  [SA33535] Oracle BEA WebLogic Portal Security Bypass Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2009-01-14

    A vulnerability has been reported in Oracle BEA WebLogic Portal, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33535/


    back  [SA33533] phpList "_SERVER[ConfigFile]" Local File Inclusion Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information
    Released: 2009-01-15

    AmnPardaz Security Research Team has discovered a vulnerability in phpList, which can be exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33533/


    back  [SA33490] AN Guestbook "country" Script Insertion Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2009-01-15

    A vulnerability has been discovered in AN Guestbook, which can be exploited by malicious people to conduct script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/33490/


    back  [SA33486] Joomla JA Showcase Component "catid" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-12

    EcHoLL has reported a vulnerability in the JA Showcase component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33486/


    back  [SA33484] Fast Guest Book Two SQL Injection Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-14

    Moudi has discovered two vulnerabilities in Fast Guest Book, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33484/


    back  [SA33480] phpMDJ "id_animateur" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-14

    darkjoker has discovered a vulnerability in phpMDJ, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33480/


    back  [SA33476] Weight Loss Recipe Book Two SQL Injection Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-14

    x0r has discovered two vulnerabilities in Weight Loss Recipe Book, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33476/


    back  [SA33474] SocialEngine "classifiedcat_id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-12

    A vulnerability has been reported in SocialEngine, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33474/


    back  [SA33471] Photobase "language" Local File Inclusion Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information
    Released: 2009-01-12

    A vulnerability has been reported in Photobase, which can be exploited by malicious people to disclose potentially sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33471/


    back  [SA33470] DevIL "iGetHdrHeader()" Buffer Overflow Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2009-01-13

    Secunia Research has discovered two vulnerabilities in DevIL, which can be exploited by malicious people to compromise an application using the library.

    Full Advisory:
    http://secunia.com/advisories/33470/


    back  [SA33459] Joomla Fantasy Tournament Component Multiple SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2009-01-14

    H!tm@N has reported some vulnerabilities in the Fantasy Tournament Component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/33459/


    back  [SA33554] Sun Java System Access Manager Privilege Escalation Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Privilege escalation
    Released: 2009-01-15

    A vulnerability has been reported in Sun Java System Access Manager, which can be exploited by malicious users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33554/


    back  [SA33553] Sun Java System Access Manager Password Disclosure Security Issue

    Critical:  Less critical
    Where: From remote
    Impact: Exposure of sensitive information
    Released: 2009-01-15

    A security issue has been reported in Sun Java System Access Manager, which can be exploited by malicious users to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33553/


    back  [SA33550] Drupal Content Translation Module Security Bypass Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Security Bypass
    Released: 2009-01-15

    A vulnerability has been reported in the Content Translation module for Drupal, which can be exploited by malicious users to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33550/


    back  [SA33549] Drupal Internationalization (i18n) Translation Module Security Bypass

    Critical:  Less critical
    Where: From remote
    Impact: Security Bypass
    Released: 2009-01-15

    A vulnerability has been reported in the Internationalization (i18n) Translation module for Drupal, which can be exploited by malicious users to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33549/


    back  [SA33542] Drupal Notify Module Privilege Escalation Security Issue

    Critical:  Less critical
    Where: From remote
    Impact: Privilege escalation
    Released: 2009-01-15

    A security issue has been reported in the Notify module for Drupal, which can be exploited by malicious users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/33542/


    back  [SA33452] Openfire Multiple Vulnerabilities

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting, Exposure of system information,
    Exposure of sensitive information
    Released: 2009-01-09

    Some vulnerabilities have been discovered in Openfire, which can be exploited by malicious people to conduct cross-site scripting attacks, and by malicious users to conduct script insertion attacks and disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/33452/


    back  [SA33529] IBM DB2 Denial of Service Vulnerabilities

    Critical:  Less critical
    Where: From local network
    Impact: DoS
    Released: 2009-01-14

    Some vulnerabilities have been reported in IBM DB2, which can be exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/33529/


    back  [SA33463] RackTables Authentication Bypass Security Issue

    Critical:  Less critical
    Where: From local network
    Impact: Security Bypass
    Released: 2009-01-13

    A security issue has been reported in RackTables, which can be exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/33463/



CERT Bulletin


back Relevant Products

  • DNS
  • Ethereal
  • PCRE
  • Sun
  • activesync
  • aol
  • apache
  • bea
  • blackboard
  • cisco
  • citrix
  • comodo
  • epolicy
  • fedora
  • gentoo
  • gnu
  • gzip
  • jakarta
  • linux
  • metaframe
  • mysql
  • nagios
  • novell
  • openoffice
  • openoffice.org
  • openoffice.org/staroffice
  • openssh
  • openssl
  • oracle
  • palm
  • palmos
  • peoplesoft
  • perl
  • php
  • postfix
  • red hat
  • samba
  • solaris
  • sql
  • ssh
  • tomcat
  • vim
  • vmware
  • webct
  • windows ce
  • windowsce