Contents
Cal Poly Pomona

Latest Unix and Other Bulletins

Report date: November 17, 2008  Date posted: November 17, 2008

This report combines relevant bulletins from SANS, Secunia and CERT. The wording is original with some "back" links added where needed. The CERT index lists vulnerabilities with and without solutions. Click the link for specific information.

At a very minimum, look at the SANS bulletins as they include the top issues on a weekly basis. Next, review Secunia for a more complete listing with well structured bulletins avaiable as external links. Finally, the CERT section contains very detailed information and many newly discovered vulnerabilities and updates on existing issues.

Tip: highlight any link below to reveal the criticality or priority.

    SANS Bulletin - Vol 7 Num 45

    None relevant

    Secunia Bulletin - 2008-46

    CERT Bulletin - SB08-322

    None relevant

    BULLETIN DETAIL


    Secunia Bulletin

    back  [SA32698] ooVoo URI Handler Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-12

    bruiser has discovered a vulnerability in ooVoo, which potentially can
    be exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32698/


    back  [SA32682] SAP GUI MDrmSap ActiveX Control Code Execution Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-11

    A vulnerability has been reported in SAPgui, which can be exploited by
    malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32682/


    back  [SA32597] hMAilServer PHPWebAdmin File Inclusion Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Exposure of sensitive information, System access
    Released: 2008-11-07

    Nine:Situations:Group::strawdog has discovered some vulnerabilities in
    hMailServer PHPWebAdmin, which can be exploited by malicious people to
    disclose potentially sensitive information and compromise a vulnerable
    system.

    Full Advisory:
    http://secunia.com/advisories/32597/


    back  [SA32675] Dizi Film Portal "film" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-11

    Kaan KAMIS has discovered a vulnerability in Dizi Film Portal, which
    can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32675/


    back  [SA32590] Arab Portal "file" File Disclosure Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Exposure of sensitive information
    Released: 2008-11-10

    IRCRASH has reported a vulnerability in Arab Portal, which can be
    exploited by malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32590/


    back  [SA32633] Microsoft Windows SMB Authentication Credential Replay
    Vulnerability

    Critical:  Moderately critical
    Where: From local network
    Impact: Security Bypass, Spoofing
    Released: 2008-11-11

    A vulnerability has been reported in Microsoft Windows, which can be
    exploited by malicious people to bypass certain security features.

    Full Advisory:
    http://secunia.com/advisories/32633/


    back  [SA32618] Trend Micro ServerProtect Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From local network
    Impact: DoS, System access
    Released: 2008-11-12

    Some vulnerabilities have been reported in Trend Micro ServerProtect,
    which potentially can be exploited by malicious people to compromise a
    vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32618/


    back  [SA32683] IBM Metrica Products Cross-Site Scripting and Script
    Insertion

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-13

    Francesco Bianchino has reported a vulnerability in Metrica products,
    which can be exploited by malicious users to conduct script insertion
    attacks and by malicious people to conduct cross-site scripting
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32683/


    back  [SA32592] Orb Networks Orb Directory Traversal Vulnerability

    Critical:  Less critical
    Where: From local network
    Impact: Exposure of system information, Exposure of sensitive
    information
    Released: 2008-11-10

    A vulnerability has been reported in Orb, which can be exploited by
    malicious people to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32592/


    back  [SA32669] Anti-Trojan Elite Atepmon.sys IOCTL Handling Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation, DoS
    Released: 2008-11-10

    alex has discovered a vulnerability in Anti-Trojan Elite, which can be
    exploited by malicious, local users to cause a DoS (Denial of Service)
    or potentially gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32669/


    back  [SA32634] Anti-Keylogger Elite "AKEProtect.sys" IOCTL Handling
    Vulnerabilities

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation, DoS
    Released: 2008-11-10

    alex has discovered some vulnerabilities in Anti-Keylogger Elite, which
    can be exploited by malicious, local users to cause a DoS (Denial of
    Service) or to potentially gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32634/


    back  [SA32714] Mozilla SeaMonkey Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, System access
    Released: 2008-11-13

    Some vulnerabilities have been reported in Mozilla SeaMonkey, which can
    be exploited by malicious people to disclose sensitive information,
    bypass certain security restrictions, or compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32714/


    back  [SA32713] Mozilla Firefox 3 Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, System access
    Released: 2008-11-13

    Some vulnerabilities have been reported in Mozilla Firefox, which can
    be exploited by malicious people to disclose sensitive information,
    bypass certain security restrictions, or compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32713/


    back  [SA32708] Fedora update for optipng

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-13

    Fedora has issued an update for optipng. This fixes a vulnerability,
    which can be exploited by malicious people to compromise a user's
    system.

    Full Advisory:
    http://secunia.com/advisories/32708/


    back  [SA32700] Red Hat update for acroread

    Critical:  Highly critical
    Where: From remote
    Impact: Privilege escalation, System access
    Released: 2008-11-13

    Red Hat has issued an update for acroread. This fixes some
    vulnerabilities, which can be exploited by malicious, local users to
    gain escalated privileges or by malicious people to compromise a user's
    system.

    Full Advisory:
    http://secunia.com/advisories/32700/


    back  [SA32695] Red Hat update for firefox

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, System access
    Released: 2008-11-13

    Red Hat has issued an update for firefox. This fixes some
    vulnerabilities, which can be exploited by malicious people to disclose
    sensitive information, bypass certain security restrictions, or
    compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32695/


    back  [SA32694] Red Hat update for seamonkey

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, System access
    Released: 2008-11-13

    Red Hat has issued an update for seamonkey. This fixes some
    vulnerabilities, which can be exploited by malicious people to disclose
    sensitive information, bypass certain security restrictions, or
    compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32694/


    back  [SA32688] Apple iLife / Aperture Image Processing Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-12

    Apple has acknowledged some vulnerabilities in Apple iLife and
    Aperture, which can potentially be exploited by malicious people to
    compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32688/


    back  [SA32629] SUSE update for yelp

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-07

    SUSE has issued an update for yelp. This fixes a vulnerability, which
    potentially can be exploited by malicious people to compromise a user's
    system.

    Full Advisory:
    http://secunia.com/advisories/32629/


    back  [SA32702] Red Hat update for flash-plugin

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting, Manipulation of
    data, Exposure of sensitive information
    Released: 2008-11-13

    Red Hat has issued an update for flash-plugin. This fixes some
    vulnerabilities, which can be exploited by malicious people to bypass
    certain security restrictions, manipulate certain data, conduct
    cross-site scripting attacks, or disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32702/


    back  [SA32687] Red Hat update for gnutls

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Spoofing
    Released: 2008-11-12

    Red Hat has issued an update for gnutls. This fixes a vulnerability,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32687/


    back  [SA32681] Fedora update for gnutls

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Spoofing
    Released: 2008-11-12

    Fedora has issued an update for gnutls. This fixes a vulnerability,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32681/


    back  [SA32678] Debian update for libcdaudio

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-13

    Debian has issued an update for libcdaudio. This fixes a vulnerability,
    which can be exploited by malicious people to compromise an application
    using the library.

    Full Advisory:
    http://secunia.com/advisories/32678/


    back  [SA32677] Ubuntu update for dovecot

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-11-10

    Ubuntu has issued an update for dovecot. This fixes a vulnerability,
    which can be exploited by malicious people to cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32677/


    back  [SA32661] Gentoo update for faad2

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-10

    Gentoo has issued an update for faad2. This fixes a vulnerability,
    which potentially can be exploited by malicious people to compromise a
    user's system.

    Full Advisory:
    http://secunia.com/advisories/32661/


    back  [SA32656] Gentoo update for graphviz

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2008-11-10

    Gentoo has issued an update for graphviz. This fixes a vulnerability,
    which can be exploited by malicious people to compromise a user's
    system.

    Full Advisory:
    http://secunia.com/advisories/32656/


    back  [SA32625] Sun Solaris IP Filter DNS Cache Poisoning

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing
    Released: 2008-11-12

    A vulnerability has been reported in Sun Solaris, which can be
    exploited by malicious people to poison the DNS cache.

    Full Advisory:
    http://secunia.com/advisories/32625/


    back  [SA32619] GnuTLS X.509 Certificate Chain Validation Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Spoofing
    Released: 2008-11-10

    A vulnerability has been reported in GnuTLS, which can be exploited by
    malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/32619/


    back  [SA32614] Fedora update for ipsec-tools

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS
    Released: 2008-11-07

    Fedora has issued an update for ipsec-tools. This fixes some
    vulnerabilities, which can be exploited by malicious people to cause a
    DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32614/


    back  [SA32608] Ubuntu update for tk

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-07

    Ubuntu has issued an update for tk. This fixes a vulnerability, which
    can be exploited by malicious people to compromise an application using
    the library.

    Full Advisory:
    http://secunia.com/advisories/32608/


    back  [SA32607] Ubuntu update for netpbm

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-07

    Ubuntu has issued an update for netpbm. This fixes a vulnerability,
    which can be exploited by malicious people to potentially compromise a
    vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32607/


    back  [SA32606] Sun Java System Identity Manager Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Cross Site Scripting
    Released: 2008-11-12

    Some vulnerabilities have been reported in Sun Java System Identity
    Manager, which can be exploited by malicious people to conduct
    cross-site scripting attacks and to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32606/


    back  [SA32668] Sun Solaris DHCP Request Handling Vulnerabilities

    Critical:  Moderately critical
    Where: From local network
    Impact: DoS, System access
    Released: 2008-11-10

    Some vulnerabilities have been reported in Sun Solaris, which can be
    exploited by malicious people to cause a DoS (Denial of Service) or
    potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32668/


    back  [SA32685] Red Hat update for httpd

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting, DoS
    Released: 2008-11-12

    Red Hat has issued an update for httpd. This fixes some
    vulnerabilities, which can be exploited by malicious people to conduct
    cross-site scripting attacks or potentially cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32685/


    back  [SA32662] Gentoo update for gallery

    Critical:  Less critical
    Where: From remote
    Impact: Exposure of system information, Exposure of sensitive
    information, Cross Site Scripting
    Released: 2008-11-10

    Gentoo has issued an update for gallery. This fixes some
    vulnerabilities, which can be exploited by malicious users to conduct
    script insertion attacks and disclose potentially sensitive
    information.

    Full Advisory:
    http://secunia.com/advisories/32662/


    back  [SA32630] op5 Monitor Cross-Site Request Forgery

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-11

    A vulnerability has been reported in op5 Monitor, which can be
    exploited by malicious people to conduct cross-site request forgery
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32630/


    back  [SA32620] Fedora update for php-Smarty

    Critical:  Less critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-07

    Fedora has issued an update for php-Smarty. This fixes a vulnerability,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32620/


    back  [SA32615] Fedora update for drupal-cck

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-07

    Fedora has issued an update for drupal-cck. This fixes some
    vulnerabilities, which can be exploited by malicious users to conduct
    script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/32615/


    back  [SA32610] Nagios "cmd.cgi" Cross-Site Request Forgery

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-07

    Andreas Ericsson has discovered a vulnerability in Nagios, which can be
    exploited by malicious people to conduct cross-site request forgery
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32610/


    back  [SA32599] TestLink Multiple Script Insertion Vulnerabilities

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-07

    Some vulnerabilities have been reported in TestLink, which can be
    exploited by malicious users to conduct script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/32599/


    back  [SA32711] rPath update for net-snmp

    Critical:  Less critical
    Where: From local network
    Impact: DoS
    Released: 2008-11-13

    rPath has issued an update for net-snmp. This fixes a vulnerability,
    which can be exploited by malicious people to cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32711/


    back  [SA32664] Debian update for net-snmp

    Critical:  Less critical
    Where: From local network
    Impact: Spoofing, DoS, System access
    Released: 2008-11-10

    Debian has issued an update for net-snmp. This fixes some
    vulnerabilities, which can be exploited by malicious people to spoof
    authenticated SNMPv3 packets, cause a DoS (Denial of Service), and
    compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32664/


    back  [SA32709] rPath update for kernel

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-13

    rPath has issued an update for the kernel. This fixes a vulnerability,
    which can be exploited by malicious, local users to gain escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32709/


    back  [SA32701] Fedora update for blender

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-12

    Fedora has issued an update for blender. This fixes a vulnerability,
    which can be exploited by malicious, local users to gain escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32701/


    back  [SA32679] smcFanControl "main()" Privilege Escalation Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-12

    KaiJern Lau has reported a vulnerability in smcFanControl, which can be
    exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32679/


    back  [SA32674] Sun Logical Domains Authentication Bypass Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-13

    A vulnerability has been reported in Sun Logical Domains (LDoms), which
    can be exploited by malicious, local users to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32674/


    back  [SA32627] CDRW-Taper "amlabel-cdrw" Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    A security issue has been reported in CDRW-Taper, which can be
    exploited by malicious, local users to perform certain actions with
    escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32627/


    back  [SA32621] HP Tru64 UNIX AdvFS "showfile" Privilege Escalation
    Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    A vulnerability has been reported in HP Tru64 UNIX, which can be
    exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32621/


    back  [SA32616] Fedora update for cman, gfs2-utils, and rgmanager

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    Fedora has issued an update for cman, gfs2-utils, and rgmanager. This
    fixes some security issues, which can be exploited by malicious, local
    users to perform certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32616/


    back  [SA32605] Apertium Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-11

    Some security issues have been reported in Apertium, which can be
    exploited by malicious, local users to perform certain actions with
    escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32605/


    back  [SA32602] Cluster Project Unspecified Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    Some security issues have been reported in Cluster Project, which can
    be exploited by malicious, local users to perform certain actions with
    escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32602/


    back  [SA32598] Scilab Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-10

    Some security issues have been reported in Scilab, which can be
    exploited by malicious, local users to perform certain actions with
    escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32598/


    back  [SA32589] DigitalDJ fest.pl Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    A security issue has been reported in DigitalDJ, which can be exploited
    by malicious, local users to perform certain actions with escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32589/


    back  [SA32588] Rancid "getipacctg" Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    A security issue has been reported in Rancid, which can be exploited by
    malicious, local users to perform certain actions with escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32588/


    back  [SA32587] lmbench Insecure Temporary Files

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    Some security issue have been reported in lmbench, which can be
    exploited by malicious, local users to perform certain actions with
    escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32587/


    back  [SA32707] Fedora update for libpng10

    Critical:  Not critical
    Where: From remote
    Impact: DoS
    Released: 2008-11-13

    Fedora has issued an update for libpng10. This fixes a vulnerability,
    which can be exploited by malicious people to cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32707/


    back  [SA32710] rPath update for initscripts

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-13

    rPath has issued an update for initscripts. This fixes a security
    issue, which can be exploited by malicious, local users to perform
    certain actions with escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32710/


    back  [SA32691] Ubuntu update for gnome-screensaver

    Critical:  Not critical
    Where: Local system
    Impact: Security Bypass, Exposure of sensitive information
    Released: 2008-11-12

    Ubuntu has issued an update for gnome-screensaver. This fixes a
    weakness and a security issue, which can be exploited by malicious
    people with physical access to disclose potentially sensitive
    information or bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/32691/


    back  [SA32671] WIMS "account.sh" Insecure Temporary Files

    Critical:  Not critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-11

    A security issue has been reported in WIMS, which can be exploited by
    malicious, local users to perform certain actions with escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32671/


    back  [SA32667] Sun Solstice X.25 Local Denial of Service

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2008-11-10

    A vulnerability has been reported in Solstice X.25, which can be
    exploited by malicious, local users to cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32667/


    back  [SA32655] Linux Kernel Denial of Service Vulnerabilities

    Critical:  Not critical
    Where: Local system
    Impact: DoS
    Released: 2008-11-11

    Some vulnerabilities have been reported in the Linux Kernel, which can
    be exploited by malicious, local users to cause a DoS (Denial of
    Service).

    Full Advisory:
    http://secunia.com/advisories/32655/


    back  [SA32631] 2Wire Routers Denial of Service Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: DoS
    Released: 2008-11-12

    hkm has reported a vulnerability in various 2Wire Routers, which can be
    exploited by malicious people to cause a DoS (Denial of Service).

    Full Advisory:
    http://secunia.com/advisories/32631/


    back  [SA32635] Siemens SpeedStream 5200 "Host" Header Authentication Bypass

    Critical:  Less critical
    Where: From local network
    Impact: Security Bypass
    Released: 2008-11-12

    hkm has reported a vulnerability in Siemens SpeedStream 5200, which can
    be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32635/


    back  [SA32623] Sweex RO002 Router Undocumented Account Security Issue

    Critical:  Less critical
    Where: From local network
    Impact: Security Bypass
    Released: 2008-11-11

    Rob Stout has reported a security issue in the Sweex RO002 Router,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32623/


    back  [SA32715] Mozilla Thunderbird Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: System access, Exposure of sensitive information, Exposure
    of system information, Security Bypass
    Released: 2008-11-13

    Some vulnerabilities have been reported in Mozilla Thunderbird, which
    can be exploited by malicious people to disclose sensitive information,
    bypass certain security restrictions, or compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32715/


    back  [SA32693] Mozilla Firefox 2 Multiple Vulnerabilities

    Critical:  Highly critical
    Where: From remote
    Impact: Security Bypass, Exposure of system information, Exposure
    of sensitive information, System access
    Released: 2008-11-13

    Some vulnerabilities have been reported in Mozilla Firefox, which can
    be exploited by malicious people to disclose sensitive information,
    bypass certain security restrictions, or compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32693/


    back  [SA32666] AlstraSoft SendIt Pro File Upload Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-13

    ZoRLu has reported a vulnerability in AlstraSoft SendIt Pro, which can
    be exploited by malicious people to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32666/


    back  [SA32651] OptiPNG BMP Reader Buffer Overflow Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-11

    A vulnerability has been reported in OptiPNG, which potentially can be
    exploited by malicious people to compromise a user's system.

    Full Advisory:
    http://secunia.com/advisories/32651/


    back  [SA32643] Sanusart Simple PHP Guestbook Script PHP Code Execution

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-11

    GoLd_M has reported a vulnerability in Sanusart Simple PHP Guestbook
    Script, which can be exploited by malicious people to compromise a
    vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32643/


    back  [SA32628] Enthusiast "path" File Inclusion Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-10

    AmnPardaz Security Research Team has discovered a vulnerability in
    Enthusiast, which can be exploited by malicious people to compromise a
    vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32628/


    back  [SA32626] PHPStore Multiple Products File Upload Vulnerability

    Critical:  Highly critical
    Where: From remote
    Impact: System access
    Released: 2008-11-12

    ZoRLu has reported a vulnerability in multiple PHPStore products, which
    can be exploited by malicious users to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32626/


    back  [SA32712] HP Service Manager Unspecified Security Bypass Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-13

    A vulnerability has been reported in HP Service Manager, which can be
    exploited by malicious users to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/32712/


    back  [SA32703] ActiveCampaign TrioLive "department_id" SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Manipulation of data
    Released: 2008-11-12

    Russ McRee has reported a vulnerability in ActiveCampaign TrioLive,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32703/


    back  [SA32673] MyioSoft Products "rsargs" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-10

    ZoRLu has discovered a vulnerability in multiple MyioSoft products,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32673/


    back  [SA32665] AlstraSoft Article Manager Pro "username" SQL Injection
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data
    Released: 2008-11-13

    ZoRLu has reported a vulnerability in AlstraSoft Article Manager Pro,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32665/


    back  [SA32663] ClamAV "get_unicode_name()" Off-By-One Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: DoS, System access
    Released: 2008-11-10

    Moritz Jodeit has reported a vulnerability in ClamAV, which can be
    exploited by malicious people to cause a DoS (Denial of Service) or
    potentially compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32663/


    back  [SA32660] AlstraSoft Web Host Directory "pwd" SQL Injection
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-13

    ZoRLu has reported a vulnerability in AlstraSoft Web Host Directory,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32660/


    back  [SA32653] WOW Raid Manager "auth_phpbb3.php" Authentication Bypass

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-11

    A vulnerability has been reported in WOW Raid Manager, which can be
    exploited by malicious people to bypass certain security restrictions.

    Full Advisory:
    http://secunia.com/advisories/32653/


    back  [SA32652] Trac Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Spoofing, DoS
    Released: 2008-11-10

    Some vulnerabilities have been reported in Trac, which can be exploited
    by malicious people to cause a DoS (Denial of Service) or to conduct
    phishing attacks.

    Full Advisory:
    http://secunia.com/advisories/32652/


    back  [SA32647] PozScripts Business Directory Script "cid" SQL Injection
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-11-12

    Hussin X has reported a vulnerability in PozScripts Business Directory
    Script, which can be exploited by malicious people to conduct SQL
    injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32647/


    back  [SA32646] Mole Group Rental Script "username" SQL Injection
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-11-10

    Cyber-Zone has reported a vulnerability in Mole Group Rental Script,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32646/


    back  [SA32645] OTManager CMS "Tipo" File Inclusion Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: System access
    Released: 2008-11-13

    colt7r has discovered a vulnerability in OTManager CMS, which can be
    exploited by malicious users to compromise a vulnerable system.

    Full Advisory:
    http://secunia.com/advisories/32645/


    back  [SA32644] TurnkeyForms Web Hosting Directory Multiple Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Exposure of sensitive information
    Released: 2008-11-13

    G4N0K has reported some vulnerabilities in TurnkeyForms Web Hosting
    Directory, which can be exploited by malicious people to bypass certain
    security restrictions and disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32644/


    back  [SA32641] E-topbiz Online Store 1 "user" and "cat_id" SQL Injection
    Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-10

    Some vulnerabilities have been reported in E-topbiz Online Store 1,
    which can be exploited by malicious people to conduct SQL injection
    attacks.

    Full Advisory:
    http://secunia.com/advisories/32641/


    back  [SA32640] Mini Web Calendar Cross-Site Scripting and Local File
    Disclosure

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Exposure of system information,
    Exposure of sensitive information
    Released: 2008-11-10

    ahmadbady has discovered two vulnerabilities in Mini Web Calendar,
    which can be exploited by malicious people to conduct cross-site
    scripting attacks or to disclose sensitive information.

    Full Advisory:
    http://secunia.com/advisories/32640/


    back  [SA32639] E-topbiz Number Links 1 "id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-10

    Hussin X has reported a vulnerability in E-topbiz Number Links 1, which
    can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32639/


    back  [SA32638] TYPO3 eluna_pagecomments Extension Cross-Site Scripting and
    SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting, Manipulation of data
    Released: 2008-11-10

    Some vulnerabilities have been reported in the eluna_pagecomments
    extension for TYPO3, which can be exploited by malicious people to
    conduct cross-site scripting and SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32638/


    back  [SA32637] Domain Seller Pro "id" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-11-10

    TR-ShaRk has reported a vulnerability in Domain Seller Pro, which can
    be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32637/


    back  [SA32636] MyioSoft EasyBookMarker "Parent" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-10

    G4N0K has discovered a vulnerability in MyioSoft EasyBookMarker, which
    can be exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32636/


    back  [SA32632] MemHT Portal "title" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-12

    Ams has discovered a vulnerability in MemHT Portal, which can be
    exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32632/


    back  [SA32622] Joomla! Script Insertion Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-11

    Some vulnerabilities have been reported in Joomla!, which can be
    exploited by malicious users and potentially malicious people to
    conduct script insertion attacks.

    Full Advisory:
    http://secunia.com/advisories/32622/


    back  [SA32617] Zeeways Shaadi Clone Authentication Bypass Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-11

    G4N0K has reported a vulnerability in Zeeways Shaadi Clone, which can
    be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32617/


    back  [SA32613] Mole Group Pizza Online Ordering Script "manufacturers_id"
    SQL Injection

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-11-07

    Cyb3r-1sT has reported a vulnerability in Mole Group Pizza Online
    Ordering Script, which can be exploited by malicious people to conduct
    SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32613/


    back  [SA32603] V3 Chat Products "admin" Cookie Security Bypass
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-10

    Cyber-Zone has reported a vulnerability in multiple V3 Chat products,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32603/


    back  [SA32601] Zeeways PhotoVideoTube Authentication Bypass Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data
    Released: 2008-11-11

    Mountassif Moad has reported a vulnerability in Zeeways PhotoVideoTube,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32601/


    back  [SA32600] AJSquare Free Polling Script Authentication Bypass
    Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass
    Released: 2008-11-12

    G4N0K has discovered a vulnerability in AJ Square Free Polling Script,
    which can be exploited by malicious people to bypass certain security
    restrictions.

    Full Advisory:
    http://secunia.com/advisories/32600/


    back  [SA32596] DevelopItEasy Events Calendar Multiple SQL Injection
    Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-07

    Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Events
    Calendar, which can be exploited by malicious people to conduct SQL
    injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32596/


    back  [SA32595] DevelopItEasy News And Article System Multiple SQL Injection
    Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-07

    Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy News And
    Article System, which can be exploited by malicious people to conduct
    SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32595/


    back  [SA32594] DevelopItEasy Membership System Multiple SQL Injection
    Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-07

    Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Membership
    System, which can be exploited by malicious people to conduct SQL
    injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32594/


    back  [SA32593] DevelopItEasy Photo Gallery Multiple SQL Injection
    Vulnerabilities

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-07

    Cyb3r-1sT has reported some vulnerabilities in DevelopItEasy Photo
    Gallery, which can be exploited by malicious people to conduct SQL
    injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32593/


    back  [SA32591] TurnkeyForms Local Classifieds SQL Injection and Security
    Bypass

    Critical:  Moderately critical
    Where: From remote
    Impact: Security Bypass, Manipulation of data, Exposure of
    sensitive information
    Released: 2008-11-07

    A vulnerability and a security issue have been reported in TurnkeyForms
    Local Classifieds, which can be exploited by malicious people to conduct
    SQL injection attacks and bypass certain security restrictions

    Full Advisory:
    http://secunia.com/advisories/32591/


    back  [SA32586] PHP Classifieds "admin_username" SQL Injection Vulnerability

    Critical:  Moderately critical
    Where: From remote
    Impact: Manipulation of data, Exposure of sensitive information
    Released: 2008-11-07

    ZoRLu has reported a vulnerability in PHP Classifieds, which can be
    exploited by malicious people to conduct SQL injection attacks.

    Full Advisory:
    http://secunia.com/advisories/32586/


    back  [SA32689] TYPO3 "file" Backend Module Cross-Site Scripting
    Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-13

    A vulnerability has been reported in TYPO3, which can be exploited by
    malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32689/


    back  [SA32670] Sun Java System Messaging Server Cross-Site Scripting
    Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-13

    A vulnerability has been reported in Sun Java System Messaging Server,
    which can be exploited by malicious people to conduct cross-site
    scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32670/


    back  [SA32657] buymyscripts.net Lyrics Script "k" Cross-Site Scripting
    Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-12

    A vulnerability has been reported in buymyscripts.net Lyrics Script,
    which can be exploited by malicious people to conduct cross-site
    scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32657/


    back  [SA32654] TYPO3 phpMyAdmin Extension "db" Cross-Site Scripting
    Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-10

    A vulnerability has been reported in the phpMyAdmin extension for
    TYPO3, which can be exploited by malicious people to conduct cross-site
    scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32654/


    back  [SA32650] buymyscripts.net Clickbank Portal "keyword" Cross-Site
    Scripting Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-12

    A vulnerability has been reported in buymyscripts.net Clickbank Portal,
    which can be exploited by malicious people to conduct cross-site
    scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32650/


    back  [SA32649] buymyscripts.net Recipe Website Script "keyword" Cross-Site
    Scripting

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-12

    A vulnerability has been reported in buymyscripts.net Recipe Website
    Script, which can be exploited by malicious people to conduct
    cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32649/


    back  [SA32642] Fresh Email Script "Email" Cross-Site Scripting
    Vulnerability

    Critical:  Less critical
    Where: From remote
    Impact: Cross Site Scripting
    Released: 2008-11-13

    Don has reported a vulnerability in Fresh Email Script, which can be
    exploited by malicious people to conduct cross-site scripting attacks.

    Full Advisory:
    http://secunia.com/advisories/32642/


    back  [SA32680] Blender Insecure Python Module Search Path Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-12

    A vulnerability has been reported in Blender, which can be exploited by
    malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32680/


    back  [SA32624] VMware ESX / ESXi Privilege Escalation and Directory
    Traversal Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    Some vulnerabilities have been reported in VMware ESX and ESXi, which
    can be exploited by malicious, local users to gain escalated
    privileges.

    Full Advisory:
    http://secunia.com/advisories/32624/


    back  [SA32612] VMware Products Privilege Escalation Vulnerability

    Critical:  Less critical
    Where: Local system
    Impact: Privilege escalation
    Released: 2008-11-07

    A vulnerability has been reported in various VMware products, which can
    be exploited by malicious, local users to gain escalated privileges.

    Full Advisory:
    http://secunia.com/advisories/32612/


    back  [SA32686] MoinMoin Full Path Disclosure Weakness

    Critical:  Not critical
    Where: From remote
    Impact: Exposure of system information
    Released: 2008-11-10

    Xia Shing Zee has discovered a weakness in MoinMoin, which can be
    exploited by malicious people to disclose system information.

    Full Advisory:
    http://secunia.com/advisories/32686/



CERT Bulletin


back Relevant Products

  • DNS
  • Ethereal
  • PCRE
  • Sun
  • activesync
  • aol
  • apache
  • bea
  • blackboard
  • cisco
  • citrix
  • comodo
  • epolicy
  • fedora
  • gentoo
  • gnu
  • gzip
  • jakarta
  • linux
  • metaframe
  • mysql
  • nagios
  • novell
  • openoffice
  • openoffice.org
  • openoffice.org/staroffice
  • openssh
  • openssl
  • oracle
  • palm
  • palmos
  • peoplesoft
  • perl
  • php
  • postfix
  • red hat
  • samba
  • solaris
  • sql
  • ssh
  • tomcat
  • vim
  • vmware
  • webct
  • windows ce
  • windowsce