dovecot -- Specific LDAP + auth cache configuration may mix up user logins dovecot 1.0.10

Dovecot reports:

If two users with the same password and same pass_filter variables log in within auth_cache_ttl seconds (1h by default), the second user may get logged in with the first user's cached pass_attrs. For example if pass_attrs contained the user's home/mail directory, this would mean that the second user will be accessing the first user's mails.

http://www.dovecot.org/list/dovecot-news/2007-December/000057.html 2007-12-21 2007-12-29
gallery2 -- multiple vulnerabilities gallery2 2.2.4

The Gallery team reports:

Gallery 2.2.4 addresses the following security vulnerabilities:

  • Publish XP module - Fixed unauthorized album creation and file uploads.
  • URL rewrite module - Fixed local file inclusion vulnerability in unsecured admin controller and information disclosure in hotlink protection.
  • Core / add-item modules - Fixed Cross Site Scripting (XSS) vulnerabilities through malicious file names.
  • Installation (Gallery application) - Update web-accessibility protection of the storage folder for Apache 2.2.
  • Core (Gallery application) / MIME module - Fixed vulnerability in checks for disallowed file extensions in file uploads.
  • Gallery Remote module - Added missing permissions checks for some GR commands.
  • WebDAV module - Fixed Cross Site Scripting (XSS) vulnerability through HTTP PROPPATCH.
  • WebDAV module - Fixed information (item data) disclosure in a WebDAV view.
  • Comment module - Fixed information (item data) disclosure in comment views.
  • Core module (Gallery application) - Improved resilience against item information disclosure attacks.
  • Slideshow module - Fixed information (item data) disclosure in the slideshow.
  • Print modules - Fixed information (item data) disclosure in several print modules.
  • Core / print modules - Fixed arbitrary URL redirection (phishing attacks) in the core module and several print modules.
  • WebCam module - Fixed proxied request weakness.
CVE-2007-6685 CVE-2007-6686 CVE-2007-6687 CVE-2007-6689 CVE-2007-6690 CVE-2007-6692 http://gallery.menalto.com/gallery_2.2.4_released 2007-12-24 2007-12-25 2010-05-12
e2fsprogs -- heap buffer overflow e2fsprogs 1.40.3

Theodore Y. Ts'o reports:

Fix a potential security vulnerability where an untrusted filesystem can be corrupted in such a way that a program using libext2fs will allocate a buffer which is far too small. This can lead to either a crash or potentially a heap-based buffer overflow crash. No known exploits exist, but main concern is where an untrusted user who possesses privileged access in a guest Xen environment could corrupt a filesystem which is then accessed by thus allowing the untrusted user to gain privileged access in the host OS. Thanks to the McAfee AVERT Research group for reporting this issue.

26772 CVE-2007-5497 http://secunia.com/advisories/27889/ http://sourceforge.net/project/shownotes.php?group_id=2406&release_id=560230 2007-12-07 2007-12-20
wireshark -- multiple vulnerabilities wireshark wireshark-lite ethereal ethereal-lite tethereal tethereal-lite 0.8.160.99.7

The Wireshark team reports of multiple vulnerabilities:

  • Wireshark could crash when reading an MP3 file.
  • Beyond Security discovered that Wireshark could loop excessively while reading a malformed DNP packet.
  • Stefan Esser discovered a buffer overflow in the SSL dissector.
  • The ANSI MAP dissector could be susceptible to a buffer overflow on some platforms.
  • The Firebird/Interbase dissector could go into an infinite loop or crash.
  • The NCP dissector could cause a crash.
  • The HTTP dissector could crash on some systems while decoding chunked messages.
  • The MEGACO dissector could enter a large loop and consume system resources.
  • The DCP ETSI dissector could enter a large loop and consume system resources.
  • Fabiodds discovered a buffer overflow in the iSeries (OS/400) Communication trace file parser.
  • The PPP dissector could overflow a buffer.
  • The Bluetooth SDP dissector could go into an infinite loop.
  • A malformed RPC Portmap packet could cause a crash.
  • The IPv6 dissector could loop excessively.
  • The USB dissector could loop excessively or crash.
  • The SMB dissector could crash.
  • The RPL dissector could go into an infinite loop.
  • The WiMAX dissector could crash due to unaligned access on some platforms.
  • The CIP dissector could attempt to allocate a huge amount of memory and crash.

Impact

It may be possible to make Wireshark or Ethereal crash or use up available memory by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

CVE-2007-6112 CVE-2007-6113 CVE-2007-6114 CVE-2007-6115 CVE-2007-6117 CVE-2007-6118 CVE-2007-6120 CVE-2007-6121 CVE-2007-6438 CVE-2007-6439 CVE-2007-6441 CVE-2007-6450 CVE-2007-6451 http://www.wireshark.org/security/wnpa-sec-2007-03.html 2007-12-19 2007-12-19 2007-12-22
opera -- multiple vulnerabilities opera opera-devel linux-opera 9.25

Opera Software ASA reports about multiple security fixes:

  • Fixed an issue where plug-ins could be used to allow cross domain scripting, as reported by David Bloom. Details will be disclosed at a later date.
  • Fixed an issue with TLS certificates that could be used to execute arbitrary code, as reported by Alexander Klink (Cynops GmbH). Details will be disclosed at a later date.
  • Rich text editing can no longer be used to allow cross domain scripting, as reported by David Bloom. See our advisory.
  • Prevented bitmaps from revealing random data from memory, as reported by Gynvael Coldwind. Details will be disclosed at a later date.
CVE-2007-6520 CVE-2007-6521 CVE-2007-6522 CVE-2007-6524 http://www.opera.com/docs/changelogs/freebsd/925/ http://www.opera.com/support/search/view/875/ 2007-12-19 2007-12-19 2007-12-29
peercast -- buffer overflow vulnerability peercast 0.1218

Luigi Auriemma reports that peercast is vulnerable to a buffer overflow which could lead to a DoS or potentially remote code execution:

The handshakeHTTP function which handles all the requests received by the other clients is vulnerable to a heap overflow which allows an attacker to fill the loginPassword and loginMount buffers located in the Servent class with how much data he wants.

CVE-2007-6454 http://aluigi.altervista.org/adv/peercasthof-adv.txt http://secunia.com/advisories/28120/ 2007-12-17 2007-12-19 2010-05-12
ganglia-webfrontend -- XSS vulnerabilities ganglia-webfrontend 3.0.6

The Ganglia project reports:

The Ganglia development team is pleased to release Ganglia 3.0.6 (Foss) which is available[...]. This release includes a security fix for web frontend cross-scripting vulnerability.

http://sourceforge.net/mailarchive/message.php?msg_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com http://sourceforge.net/mailarchive/forum.php?thread_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com&forum_name=ganglia-developers 2007-12-10 2007-12-17 2007-12-18
qemu -- Translation Block Local Denial of Service Vulnerability qemu qemu-devel 0.9.0_4 0.9.0s.20070101*0.9.0s.20070802_1

SecurityFocus reports:

QEMU is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks when handling user-supplied input.

Attackers can exploit this issue to cause denial-of-service conditions. Given the nature of the issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.

26666 CVE-2007-6227 http://www.securityfocus.com/archive/1/484429 2007-11-30 2007-12-12 2007-12-14
drupal -- SQL injection vulnerability drupal5 5.4 drupal4 4.7.9

The Drupal Project reports:

The function taxonomy_select_nodes() directly injects variables into SQL queries instead of using placeholders. While taxonomy module itself validates the input passed to taxonomy_select_nodes(), this is a weakness in Drupal core. Several contributed modules, such as taxonomy_menu, ajaxLoader, and ubrowser, directly pass user input to taxonomy_select_nodes(), enabling SQL injection attacks by anonymous users.

CVE-2007-6299 http://drupal.org/node/198162 http://secunia.com/advisories/27932/ 2007-12-05 2007-12-12
samba -- buffer overflow vulnerability samba samba3 ja-samba 3.0.28 *,13.0.28,1

Secuna Research reports:

Secunia Research has discovered a vulnerability in Samba, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error within the "send_mailslot()" function. This can be exploited to cause a stack-based buffer overflow with zero bytes via a specially crafted "SAMLOGON" domain logon packet containing a username string placed at an odd offset followed by an overly long GETDC string. Successful exploitation allows execution of arbitrary code, but requires that the "domain logons" option is enabled.

CVE-2007-6015 http://secunia.com/advisories/27760/ 2007-12-10 2007-12-12 2008-09-26
smbftpd -- format string vulnerability smbftpd 0.96

Secunia reports:

Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary code via format string specifiers in a directory name.

CVE-2007-5184 http://secunia.com/advisories/27014/ http://sourceforge.net/project/shownotes.php?release_id=543077 2007-10-01 2007-12-12
jetty -- multiple vulnerabilities jetty 6.1.6

Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.

Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

237888 212984 438616 CVE-2007-5613 CVE-2007-5614 CVE-2007-5615 http://svn.codehaus.org/jetty/jetty/trunk/VERSION.txt 2007-12-05 2007-12-10
liveMedia -- DoS vulnerability liveMedia 2007.11.18,1

The live555 development team reports:

Fixed a bounds-checking error in "parseRTSPRequestString()" caused by an int vs. unsigned problem.

The function which handles the incoming queries from the clients is affected by a vulnerability which allows an attacker to crash the server remotely using the smallest RTSP query possible to use.

CVE-2007-6036 http://aluigi.altervista.org/adv/live555x-adv.txt http://www.live555.com/liveMedia/public/changelog.txt 2007-11-20 2007-12-08 2007-12-09
GNU finger vulnerability gnu-finger 1.37_1

GNU security announcement:

GNU Finger unfortunately has not been updated in many years, and has known security vulnerabilities. Please do not use it in production environments.

CVE-1999-1165 http://www.gnu.org/software/finger/ 1999-07-21 2007-12-05
Squid -- Denial of Service Vulnerability squid 2.02.6.16_1 3.*3.0.r1.20071001_1

Squid secuirty advisory reports:

Due to incorrect bounds checking Squid is vulnerable to a denial of service check during some cache update reply processing.

This problem allows any client trusted to use the service to perform a denial of service attack on the Squid service.

26687 CVE-2007-6239 2007-11-28 2007-12-04 2007-12-07
rubygem-rails -- session-fixation vulnerability rubygem-rails 1.2.6

Rails core team reports:

The rails core team has released ruby on rails 1.2.6 to address a bug in the fix for session fixation attacks (CVE-2007-5380). The CVE Identifier for this new issue is CVE-2007-6077.

CVE-2007-6077 2007-11-24 2007-11-27
rubygem-rails -- JSON XSS vulnerability rubygem-rails 1.2.5 rubygem-activesupport 1.4.4

Rails core team reports:

All users of Rails 1.2.4 or earlier are advised to upgrade to 1.2.5, though it isn't strictly necessary if you aren't working with JSON. For more information the JSON vulnerability, see CVE-2007-3227.

CVE-2007-3227 2007-10-12 2007-11-28 2007-12-01
ikiwiki -- improper symlink verification vulnerability ikiwiki 2.14

The ikiwiki development team reports:

Ikiwiki did not check if path to the srcdir to contained a symlink. If an attacker had commit access to the directories in the path, they could change it to a symlink, causing ikiwiki to read and publish files that were not intended to be published. (But not write to them due to other checks.)

http://ikiwiki.info/security/#index29h2 2007-11-26 2007-11-27
firefox -- multiple remote unspecified memory corruption vulnerabilities firefox 2.0.0.10,1 linux-firefox 2.0.0.10 seamonkey linux-seamonkey 1.1.7 flock linux-flock 1.0.2 linux-firefox-devel 3.0.a2007.12.12 linux-seamonkey-devel 2.0.a2007.12.12

Mozilla Foundation reports:

The Firefox 2.0.0.10 update contains fixes for three bugs that improve the stability of the product. These crashes showed some evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

26593 CVE-2007-5959 2007-11-26 2007-11-27 2007-12-14
phpmyadmin -- Cross Site Scripting phpmyadmin 2.11.2.2

phpMyAdmin security announcement:

The login page auth_type cookie was vulnerable to XSS via the convcharset parameter. An attacker could use this to execute malicious code on the visitors computer

CVE-2007-6100 http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8 http://www.nth-dimension.org.uk/downloads.php?id=38 2007-11-20 2007-11-21 2010-05-12
samba -- multiple vulnerabilities samba samba3 ja-samba 3.0.26a *,13.0.26a_2,1

The Samba Team reports:

Secunia Research reported a vulnerability that allows for the execution of arbitrary code in nmbd. This defect may only be exploited when the "wins support" parameter has been enabled in smb.conf.

Samba developers have discovered what is believed to be a non-exploitable buffer over in nmbd during the processing of GETDC logon server requests. This code is only used when the Samba server is configured as a Primary or Backup Domain Controller.

26454 CVE-2007-4572 CVE-2007-5398 http://secunia.com/advisories/27450/ http://us1.samba.org/samba/security/CVE-2007-4572.html http://us1.samba.org/samba/security/CVE-2007-5398.html 2007-11-15 2007-11-21 2008-09-26
php -- multiple security vulnerabilities php5 5.2.5

PHP project reports:

Security Enhancements and Fixes in PHP 5.2.5:

  • Fixed dl() to only accept filenames. Reported by Laurent Gaffie.
  • Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). Reported by Laurent Gaffie.
  • Fixed htmlentities/htmlspecialchars not to accept partial multibyte sequences. Reported by Rasmus Lerdorf
  • Fixed possible triggering of buffer overflows inside glibc implementations of the fnmatch(), setlocale() and glob() functions. Reported by Laurent Gaffie.
  • Fixed "mail.force_extra_parameters" php.ini directive not to be modifiable in .htaccess due to the security implications. Reported by SecurityReason.
  • Fixed bug #42869 (automatic session id insertion adds sessions id to non-local forms).
  • Fixed bug #41561 (Values set with php_admin_* in httpd.conf can be overwritten with ini_set()).
26403 CVE-2007-4887 2007-11-08 2007-11-16
mt-daapd -- denial of service vulnerability mt-daapd 0.2.4.1

US-CERT reports:

webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function.

CVE-2007-5824 2007-11-05 2007-11-12
net-snmp -- denial of service via GETBULK request net-snmp 5.3.1_7

CVE reports:

The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.

CVE-2007-5846 2007-11-06 2007-11-13 2007-11-14
flac -- media file processing integer overflow vulnerabilities flac 1.1.2_2

iDefense Laps reports:

Remote exploitation of multiple integer overflow vulnerabilities in libFLAC, as included with various vendor's software distributions, allows attackers to execute arbitrary code in the context of the currently logged in user.

These vulnerabilities specifically exist in the handling of malformed FLAC media files. In each case, an integer overflow can occur while calculating the amount of memory to allocate. As such, insufficient memory is allocated for the data that is subsequently read in from the file, and a heap based buffer overflow occurs.

CVE-2007-4619 http://secunia.com/advisories/27210/ http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608 2007-10-11 2007-11-13
xpdf -- multiple remote Stream.CC vulnerabilities cups-base 1.3.3_2 gpdf 0 kdegraphics 3.5.8_1 koffice 1.6.3_3,2 poppler 0.6 xpdf 3.02_5

Secunia Research reports:

Secunia Research has discovered some vulnerabilities in Xpdf, which can be exploited by malicious people to compromise a user's system.

  • An array indexing error within the "DCTStream::readProgressiveDataUnit()" method in xpdf/Stream.cc can be exploited to corrupt memory via a specially crafted PDF file.
  • An integer overflow error within the "DCTStream::reset()" method in xpdf/Stream.cc can be exploited to cause a heap-based buffer overflow via a specially crafted PDF file.
  • A boundary error within the "CCITTFaxStream::lookChar()" method in xpdf/Stream.cc can be exploited to cause a heap-based buffer overflow by tricking a user into opening a PDF file containing a specially crafted "CCITTFaxDecode" filter.

Successful exploitation may allow execution of arbitrary code.

26367 CVE-2007-4352 CVE-2007-5392 CVE-2007-5393 2007-11-07 2007-11-12 2007-11-14
plone -- unsafe data interpreted as pickles plone 2.52.5.5 3.03.0.3

Plone projectreports:

This hotfix corrects a vulnerability in the statusmessages and linkintegrity modules, where unsafe network data was interpreted as python pickles. This allows an attacker to run arbitrary python code within the Zope/Plone process.

26354 CVE-2007-5741 2007-11-06 2007-11-12
phpmyadmin -- cross-site scripting vulnerability phpMyAdmin 2.11.2.1

The DigiTrust Group reports:

When creating a new database, a malicious user can use a client-side Web proxy to place malicious code in the db parameter of the POST request. Since db_create.php does not properly sanitize user-supplied input, an administrator could face a persistent XSS attack when the database names are displayed.

CVE-2007-5976 CVE-2007-5977 http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-7 2007-11-11 2007-11-11 2010-05-12
gallery2 -- multiple vulnerabilities gallery2 2.2.3

Gallery project reports:

Gallery 2.2.3 addresses the following security vulnerabilities:

  • Unauthorized renaming of items possible with WebDAV (reported by Merrick Manalastas)
  • Unauthorized modification and retrieval of item properties possible with WebDAV
  • Unauthorized locking and replacing of items possible with WebDAV
  • Unauthorized editing of data file possible via linked items with Reupload and WebDAV (reported by Nicklous Roberts)
CVE-2007-4650 25580 2007-08-29 2007-11-09
tikiwiki -- multiple vulnerabilities tikiwik 1.9.8.2

Secunia reports:

Some vulnerabilities have been reported in TikiWiki, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks and disclose potentially sensitive information.

Input passed to the username parameter in tiki-remind_password.php (when remind is set to send me my password) is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code (for example with meta refreshes to a javascript: URL) in a user's browser session in context of an affected site.

Input passed to the local_php and error_handler parameters in tiki-index.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources.

Input passed to the imp_language parameter in tiki-imexport_languages.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources.

Certain img src elements are not properly santised before being used. This can be exploited to insert arbitrary HTML and script code, which is executed in a user's browser session in context of an affected site when the malicious data is viewed.

CVE-2007-4554 CVE-2007-5683 CVE-2007-5684 http://secunia.com/advisories/26618/ http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/changelog.txt?view=markup&pathrev=REL-1-9-8-2 2007-08-27 2007-11-09 2008-10-03
cups -- off-by-one buffer overflow cups-base 1.3.3_1

Secunia reports:

Secunia Research has discovered a vulnerability in CUPS, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the "ippReadIO()" function in cups/ipp.c when processing IPP (Internet Printing Protocol) tags. This can be exploited to overwrite one byte on the stack with a zero by sending an IPP request containing specially crafted "textWithLanguage" or "nameWithLanguage" tags.

Successful exploitation allows execution of arbitrary code.

CVE-2007-4351 http://secunia.com/secunia_research/2007-76/ 2007-11-06 2007-11-09 2007-11-12
perl -- regular expressions unicode data buffer overflow perl perl-threaded 5.8.*5.8.8_1

Red Hat reports:

A flaw was found in Perl's regular expression engine. Specially crafted input to a regular expression can cause Perl to improperly allocate memory, possibly resulting in arbitrary code running with the permissions of the user running Perl.

CVE-2007-5116 http://secunia.com/advisories/27546/ 2007-11-05 2007-11-06 2007-11-07
pcre -- arbitrary code execution pcre pcre-utf8 7.3

Debian project reports:

Tavis Ormandy of the Google Security Team has discovered several security issues in PCRE, the Perl-Compatible Regular Expression library, which potentially allow attackers to execute arbitrary code by compiling specially crafted regular expressions.

CVE-2007-1659 CVE-2007-1660 CVE-2007-1661 CVE-2007-1662 CVE-2007-4766 CVE-2007-4767 CVE-2007-4768 http://www.pcre.org/changelog.txt 2007-11-05 2007-11-06
perdition -- str_vwrite format string vulnerability perdition 1.17.1

SEC-Consult reports:

Perdition IMAP is affected by a format string bug in one of its IMAP output-string formatting functions. The bug allows the execution of arbitrary code on the affected server. A successful exploit does not require prior authentication.

26270 CVE-2007-5740 http://www.sec-consult.com/300.html http://secunia.com/advisories/27458 2007-10-31 2007-11-05
gftp -- multiple vulnerabilities gftp 2.0.18_6

Gentoo reports:

Kalle Olavi Niemitalo discovered two boundary errors in fsplib code included in gFTP when processing overly long directory or file names.

A remote attacker could trigger these vulnerabilities by enticing a user to download a file with a specially crafted directory or file name, possibly resulting in the execution of arbitrary code or a Denial of Service.

CVE-2007-3961 CVE-2007-3962 http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml 2007-11-01 2007-11-05 2007-11-11
dircproxy -- remote denial of service dircproxy 1.0.5_1 dircproxy-devel 1.2.0.b2_1

Securiweb reports:

dircproxy allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer dereference, as demonstrated using a blank /me message from irssi.

CVE-2007-5226 http://dircproxy.securiweb.net/ticket/89 https://bugzilla.redhat.com/show_bug.cgi?id=319301 2006-09-06 2007-11-04 2008-01-31
wordpress -- cross-site scripting wordpress de-wordpress 2.3.1 zh-wordpress 0

A Secunia Advisory report:

Input passed to the "posts_columns" parameter in wp-admin/edit-post-rows.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

CVE-2007-5710 http://secunia.com/advisories/27407 http://wordpress.org/development/2007/10/wordpress-231/ 2007-10-29 2007-11-01
openldap -- multiple remote denial of service vulnerabilities openldap-server 2.3.39 2.4.02.4.6

BugTraq reports:

OpenLDAP is prone to multiple remote denial-of-service vulnerabilities because of an incorrect NULL-termination issue and a double-free issue.

26245 CVE-2007-5707 CVE-2007-5708 2007-10-29 2007-10-30 2007-10-31
py-django -- denial of service vulnerability py23-django py24-django py25-django 0.96.1 py23-django-devel py24-django-devel py25-django-devel 20071026

Django project reports:

A per-process cache used by Django's internationalization ("i18n") system to store the results of translation lookups for particular values of the HTTP Accept-Language header used the full value of that header as a key. An attacker could take advantage of this by sending repeated requests with extremely large strings in the Accept-Language header, potentially causing a denial of service by filling available memory.

Due to limitations imposed by Web server software on the size of HTTP header fields, combined with reasonable limits on the number of requests which may be handled by a single server process over its lifetime, this vulnerability may be difficult to exploit. Additionally, it is only present when the "USE_I18N" setting in Django is "True" and the i18n middleware component is enabled*. Nonetheless, all users of affected versions of Django are encouraged to update.

http://www.djangoproject.com/weblog/2007/oct/26/security-fix/ 2007-10-26 2007-10-27
opera -- multiple vulnerabilities opera opera-devel linux-opera 9.24

An advisory from Opera reports:

If a user has configured Opera to use an external newsgroup client or e-mail application, specially crafted Web pages can cause Opera to run that application incorrectly. In some cases this can lead to execution of arbitrary code.

When accesing frames from different Web sites, specially crafted scripts can bypass the same-origin policy, and overwrite functions from those frames. If scripts on the page then run those functions, this can cause the script of the attacker's choice to run in the context of the target Web site.

CVE-2007-5540 CVE-2007-5541 http://www.opera.com/support/search/view/866/ http://www.opera.com/support/search/view/867/ http://secunia.com/advisories/27277/ 2007-10-17 2007-10-25
drupal --- multiple vulnerabilities drupal4 4.7.8 drupal5 5.3

The Drupal Project reports:

In some circumstances Drupal allows user-supplied data to become part of response headers. As this user-supplied data is not always properly escaped, this can be exploited by malicious users to execute HTTP response splitting attacks which may lead to a variety of issues, among them cache poisoning, cross-user defacement and injection of arbitrary code.

The Drupal installer allows any visitor to provide credentials for a database when the site's own database is not reachable. This allows attackers to run arbitrary code on the site's server. An immediate workaround is the removal of the file install.php in the Drupal root directory.

The allowed extension list of the core Upload module contains the extension HTML by default. Such files can be used to execute arbitrary script code in the context of the affected site when a user views the file. Revoking upload permissions or removing the .html extension from the allowed extension list will stop uploads of malicious files. but will do nothing to protect your site againstfiles that are already present. Carefully inspect the file system path for any HTML files. We recommend you remove any HTML file you did not update yourself. You should look for , CSS includes, Javascript includes, and onerror="" attributes if you need to review files individually.

The Drupal Forms API protects against cross site request forgeries (CSRF), where a malicious site can cause a user to unintentionally submit a form to a site where he is authenticated. The user deletion form does not follow the standard Forms API submission model and is therefore not protected against this type of attack. A CSRF attack may result in the deletion of users.

The publication status of comments is not passed during the hook_comments API operation, causing various modules that rely on the publication status (such as Organic groups, or Subscriptions) to mail out unpublished comments.

CVE-2007-5597 CVE-2007-5596 CVE-2007-5595 CVE-2007-5594 CVE-2007-5593 http://drupal.org/node/184315 http://drupal.org/node/184316 http://drupal.org/node/184348 http://drupal.org/node/184354 http://drupal.org/node/184320 http://secunia.com/advisories/27292 http://secunia.com/advisories/27292 http://secunia.com/advisories/27292 http://secunia.com/advisories/27290 http://secunia.com/advisories/27290 2007-10-17 2007-10-24
ldapscripts -- Command Line User Credentials Disclosure ldapscripts 1.7.1

Ganael Laplanche reports:

Up to now, each ldap* command was called with the -w parameter, which allows to specify the bind password on the command line. Unfortunately, this could make the password appear to anybody performing a `ps` during the call. This is now avoided by using the -y parameter and a password file.

http://sourceforge.net/project/shownotes.php?group_id=156483&release_id=546600 http://secunia.com/advisories/27111 CVE-2007-5373 2007-10-09 2007-10-23
firefox -- OnUnload Javascript browser entrapment vulnerability firefox 2.0.0.8,1 linux-firefox 2.0.0.8 seamonkey linux-seamonkey 1.1.5

RedHat reports:

Several flaws were found in the way in which Firefox displayed malformed web content. A web page containing specially-crafted content could potentially trick a user into surrendering sensitive information. (CVE-2007-1095, CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)

CVE-2007-1095 2007-10-19 2007-10-22 2007-10-23
phpmyadmin -- cross-site scripting vulnerability phpMyAdmin 2.11.1.2

The DigiTrust Group discovered serious XSS vulnerability in the phpMyAdmin server_status.php script. According to their report

vulnerability can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

CVE-2007-5589 http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-6 2007-10-17 2007-10-17 2010-05-12
phpmyadmin -- cross-site scripting vulnerability phpMyAdmin 2.11.1.1

SecurityFocus reports:

phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal potentially sensitive information and launch other attacks.

CVE-2007-5386 http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-5 http://www.digitrustgroup.com/advisories/TDG-advisory071009a http://secunia.com/advisories/27173 26020 2007-10-12 2007-10-16 2007-10-20
nagios-plugins -- Long Location Header Buffer Overflow Vulnerability nagios-plugins 1.4.10,1

A Secunia Advisory reports:

The vulnerability is caused due to a boundary error within the redir() function in check_http.c when processing HTTP Location: header information. This can be exploited to cause a buffer overflow by returning an overly long string in the "Location:" header to a vulnerable system.

http://sourceforge.net/forum/forum.php?forum_id=740172 http://secunia.com/advisories/27124/ CVE-2007-5198 2007-09-28 2007-10-11
png -- multiple vulnerabilities png 1.2.22

A Secunia Advisory reports:

Some vulnerabilities have been reported in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service).

Certain errors within libpng, including a logical NOT instead of a bitwise NOT in pngtrtran.c, an error in the 16bit cheap transparency extension, and an incorrect use of sizeof() may be exploited to crash an application using the library.

Various out-of-bounds read errors exist within the functions png_handle_pCAL(), png_handle_sCAL(), png_push_read_tEXt(), png_handle_iTXt(), and png_handle_ztXt(), which may be exploited by exploited to crash an application using the library.

The vulnerability is caused due to an off-by-one error within the ICC profile chunk handling, which potentially can be exploited to crash an application using the library.

http://secunia.com/advisories/27093/ http://secunia.com/advisories/27130/ CVE-2007-5267 CVE-2007-5266 CVE-2007-5268 CVE-2007-5269 2007-10-08 2007-10-11
ImageMagick -- multiple vulnerabilities ImageMagick ImageMagick-nox11 6.3.5.9

Multiple vulnerabilities have been discovered in ImageMagick.

ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.

Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.

Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.

Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.

CVE-2007-4985 CVE-2007-4986 CVE-2007-4987 CVE-2007-4988 http://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.html 2007-09-19 2007-10-10
jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented jdk 1.3.01.6.0.3p3 1.5.0,11.5.0.13p7,1 linux-blackdown-jdk 1.3.0 linux-sun-jdk 1.3.01.3.1.20 1.4.01.4.2.16 1.5.0.b1 1.5.0.b1,1 1.5.0,21.5.0.13,2 1.6.01.6.0.03

SUN reports:

A vulnerability in the Java Runtime Environment (JRE) with applet caching may allow an untrusted applet that is downloaded from a malicious website to make network connections to network services on machines other than the one that the applet was downloaded from. This may allow network resources (such as web pages) and vulnerabilities (that exist on these network services) which are not otherwise normally accessible to be accessed or exploited.

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1 CVE-2007-5232 2007-10-03 2007-10-08 2007-11-16
xfs -- multiple vulnerabilities xfs 1.0.5,1

Matthieu Herrb reports:

Problem Description:

Several vulnerabilities have been identified in xfs, the X font server. The QueryXBitmaps and QueryXExtents protocol requests suffer from lack of validation of their 'length' parameters.

Impact:

On most modern systems, the font server is accessible only for local clients and runs with reduced privileges, but on some systems it may still be accessible from remote clients and possibly running with root privileges, creating an opportunity for remote privilege escalation.

CVE-2007-4568 http://lists.freedesktop.org/archives/xorg/2007-October/028899.html 2007-10-02 2007-10-08
tcl/tk -- buffer overflow in ReadImage function tk tk-threads 8.2.*8.2.3_11 8.3.*8.3.5_10 8.4.*,28.4.16,2

A Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl/Tk, allows remote attackers to execute arbitrary code via multi-frame interlaced GIF files in which later frames are smaller than the first.

http://secunia.com/advisories/26942 http://sourceforge.net/project/shownotes.php?release_id=541207 CVE-2007-5137 2007-09-27 2007-10-05 2011-09-04
firebird -- multiple remote buffer overflow vulnerabilities firebird-server 1.*1.5.5 2.0.*2.0.3

RISE Security reports:

There exists multiple vulnerabilities within functions of Firebird Relational Database, which when properly exploited can lead to remote compromise of the vulnerable system.

25925 2007-10-03 2007-10-04
id3lib -- insecure temporary file creation id3lib 3.8.3_4

Debian Bug report log reports:

When tagging file $foo, a temporary copy of the file is created, and for some reason, libid3 doesn't use mkstemp but just creates $foo.XXXXXX literally, without any checking.

This would silently truncate and overwrite an existing $foo.XXXXXX.

25372 CVE-2007-4460 2007-08-20 2007-10-01 2007-10-01
mediawiki -- cross site scripting vulnerability mediawiki 1.10.01.10.2 1.9.01.9.4 1.8.01.8.5

The MediaWiki development team reports:

A possible HTML/XSS injection vector in the API pretty-printing mode has been found and fixed.

The vulnerability may be worked around in an unfixed version by simply disabling the API interface if it is not in use, by adding this to LocalSettings.php:

$wgEnableAPI = false;

(This is the default setting in 1.8.x.)

CVE-2007-4828 http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html 2007-09-10 2007-09-21 2007-10-10
wordpress -- remote sql injection vulnerability wordpress 2.2.3,1 de-wordpress zh-wordpress 2.2.3 wordpress-mu 1.2.4,2

Alexander Concha reports:

While testing WordPress, it has been discovered a SQL Injection vulnerability that allows an attacker to retrieve remotely any user credentials from a vulnerable site, this bug is caused because of early database escaping and the lack of validation in query string like parameters.

CVE-2007-4894 http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html 2007-09-10 2007-09-21
samba -- nss_info plugin privilege escalation vulnerability samba 3.0.26a *,13.0.26a,1

The Samba development team reports:

The idmap_ad.so library provides an nss_info extension to Winbind for retrieving a user's home directory path, login shell and primary group id from an Active Directory domain controller. This functionality is enabled by defining the "winbind nss info" smb.conf option to either "sfu" or "rfc2307".

Both the Windows "Identity Management for Unix" and "Services for Unix" MMC plug-ins allow a user to be assigned a primary group for Unix clients that differs from the user's Windows primary group. When the rfc2307 or sfu nss_info plugin has been enabled, in the absence of either the RFC2307 or SFU primary group attribute, Winbind will assign a primary group ID of 0 to the domain user queried using the getpwnam() C library call.

CVE-2007-4138 http://www.samba.org/samba/security/CVE-2007-4138.html 2007-09-11 2007-09-21 2008-09-26
bugzilla -- multiple vulnerabilities bugzilla ja-bugzilla 2.20.*2.22.3 3.*3.0.1

A Bugzilla Security Advisory reports:

This advisory covers three security issues that have recently been fixed in the Bugzilla code:

  • A possible cross-site scripting (XSS) vulnerability when filing bugs using the guided form.
  • When using email_in.pl, insufficiently escaped data may be passed to sendmail.
  • Users using the WebService interface may access Bugzilla's time-tracking fields even if they normally cannot see them.

We strongly advise that 2.20.x and 2.22.x users should upgrade to 2.20.5 and 2.22.3 respectively. 3.0 users, and users of 2.18.x or below, should upgrade to 3.0.1.

25425 CVE-2007-4538 CVE-2007-4539 CVE-2007-4543 http://www.bugzilla.org/security/2.20.4/ 2007-08-23 2007-09-21
clamav -- multiple remote Denial of Service vulnerabilities clamav 0.91.2

BugTraq reports:

ClamAV is prone to multiple denial-of-service vulnerabilities.

A successful attack may allow an attacker to crash the application and deny service to users.

25398 CVE-2007-4510 2007-08-21 2007-09-21
coppermine -- multiple vulnerabilities coppermine 1.4.13

The coppermine development team reports two vulnerabilities with the coppermine application. These vulnerabilities are caused by improper checking of the log variable in "viewlog.php" and improper checking of the referer variable in "mode.php". This could allow local file inclusion, potentially disclosing valuable information and could lead to an attacker conducting a cross site scripting attack against the targeted site.

CVE-2007-4976 CVE-2007-4977 http://coppermine-gallery.net/forum/index.php?topic=46847.0 2007-09-14 2007-09-20 2010-05-12
openoffice -- arbitrary command execution vulnerability openoffice 0

iDefense reports:

Remote exploitation of multiple integer overflow vulnerabilities within OpenOffice, as included in various vendors' operating system distributions, allows attackers to execute arbitrary code.

These vulnerabilities exist within the TIFF parsing code of the OpenOffice suite. When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow.

CVE-2007-2834 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593 2007-09-19 2007-09-20
bugzilla -- "createmailregexp" security bypass vulnerability bugzilla 3.*3.0.2

The Bugzilla development team reports:

Bugzilla::WebService::User::offer_account_by_email does not check the "createemailregexp" parameter, and thus allows users to create accounts who would normally be denied account creation. The "emailregexp" parameter is still checked. If you do not have the SOAP::Lite Perl module installed on your Bugzilla system, your system is not vulnerable (because the Bugzilla WebService will not be enabled).

CVE-2007-5038 http://www.bugzilla.org/security/3.0.1/ 2007-09-18 2007-09-20 2010-05-12
konquerer -- address bar spoofing kdebase 3.5.7_3 kdelibs 3.5.7_2

The KDE development team reports:

The Konqueror address bar is vulnerable to spoofing attacks that are based on embedding white spaces in the url. In addition the address bar could be tricked to show an URL which it is intending to visit for a short amount of time instead of the current URL.

CVE-2007-3820 CVE-2007-4224 CVE-2007-4225 http://www.kde.org/info/security/advisory-20070914-1.txt 2007-09-14 2007-09-19
kdm -- passwordless login vulnerability kdebase3 3.5.7_3

The KDE development team reports:

KDM can be tricked into performing a password-less login even for accounts with a password set under certain circumstances, namely autologin to be configured and "shutdown with password" enabled.

CVE-2007-4569 http://www.kde.org/info/security/advisory-20070919-1.txt 2007-09-19 2007-09-19
flyspray -- authentication bypass flyspray 0.9.9.2

The Flyspray Project reports:

Flyspray authentication system can be bypassed by sending a carefully crafted post request.

To be vulnerable, PHP configuration directive output_buffering has to be disabled or set to a low value.

CVE-2007-1788 http://www.flyspray.org/fsa:1 2007-03-13 2007-09-19
mozilla -- code execution via Quicktime media-link files firefox 2.0.0.7,1 linux-firefox 2.0.0.7 seamonkey linux-seamonkey 1.1.5 linux-firefox-devel 3.0.a2007.12.12 linux-seamonkey-devel 2.0.a2007.12.12 firefox-ja linux-mozilla-devel linux-mozilla mozilla 0

The Mozilla Foundation reports a vulnerability within the mozilla browser. This vulnerability also affects various other browsers like firefox and seamonkey. The vulnerability is caused by QuickTime Media-Link files that contain a qtnext attribute. This could allow an attacker to start the browser with arbitrary command-line options. This could allow the attacker to install malware, steal local data and possibly execute and/or do other arbitrary things within the users context.

CVE-2006-4965 http://www.mozilla.org/security/announce/2007/mfsa2007-28.html 2007-09-18 2007-09-19 2007-12-14
php -- multiple vulnerabilities php5 5.2.4 php4 4.4.8

The PHP development team reports:

Security Enhancements and Fixes in PHP 5.2.4:

  • Fixed a floating point exception inside wordwrap() (Reported by Mattias Bengtsson)
  • Fixed several integer overflows inside the GD extension (Reported by Mattias Bengtsson)
  • Fixed size calculation in chunk_split() (Reported by Gerhard Wagner)
  • Fixed integer overflow in str[c]spn(). (Reported by Mattias Bengtsson)
  • Fixed money_format() not to accept multiple %i or %n tokens. (Reported by Stanislav Malyshev)
  • Fixed zend_alter_ini_entry() memory_limit interruption vulnerability. (Reported by Stefan Esser)
  • Fixed INFILE LOCAL option handling with MySQL extensions not to be allowed when open_basedir or safe_mode is active. (Reported by Mattias Bengtsson)
  • Fixed session.save_path and error_log values to be checked against open_basedir and safe_mode (CVE-2007-3378) (Reported by Maksymilian Arciemowicz)
  • Fixed a possible invalid read in glob() win32 implementation (CVE-2007-3806) (Reported by shinnai)
  • Fixed a possible buffer overflow in php_openssl_make_REQ (Reported by zatanzlatan at hotbrev dot com)
  • Fixed an open_basedir bypass inside glob() function (Reported by dr at peytz dot dk)
  • Fixed a possible open_basedir bypass inside session extension when the session file is a symlink (Reported by c dot i dot morris at durham dot ac dot uk)
  • Improved fix for MOPB-03-2007.
  • Corrected fix for CVE-2007-2872.
CVE-2007-2872 CVE-2007-3378 CVE-2007-3806 CVE-2007-3996 CVE-2007-3997 CVE-2007-3998 CVE-2007-4652 CVE-2007-4657 CVE-2007-4658 CVE-2007-4659 CVE-2007-4660 CVE-2007-4661 CVE-2007-4662 CVE-2007-4663 CVE-2007-4670 http://www.php.net/releases/4_4_8.php http://www.php.net/releases/5_2_4.php http://secunia.com/advisories/26642 2007-08-30 2007-09-11 2008-01-14
apache -- multiple vulnerabilities apache 2.2.02.2.6 2.0.02.0.61

Apache HTTP server project reports:

The following potential security flaws are addressed:

  • CVE-2007-3847: mod_proxy: Prevent reading past the end of a buffer when parsing date-related headers.
  • CVE-2007-1863: mod_cache: Prevent a segmentation fault if attributes are listed in a Cache-Control header without any value.
  • CVE-2007-3304: prefork, worker, event MPMs: Ensure that the parent process cannot be forced to kill processes outside its process group.
  • CVE-2006-5752: mod_status: Fix a possible XSS attack against a site with a public server-status page and ExtendedStatus enabled, for browsers which perform charset "detection". Reported by Stefan Esser.
  • CVE-2006-1862: mod_mem_cache: Copy headers into longer lived storage; header names and values could previously point to cleaned up storage.
CVE-2007-3847 CVE-2007-1863 CVE-2006-5752 CVE-2007-3304 2007-09-07 2007-09-11
lighttpd -- FastCGI header overrun in mod_fastcgi lighttpd 1.4.18

lighttpd maintainer reports:

Lighttpd is prone to a header overflow when using the mod_fastcgi extension, this can lead to arbitrary code execution in the fastcgi application. For a detailed description of the bug see the external reference.

This bug was found by Mattias Bengtsson and Philip Olausson

http://www.lighttpd.net/assets/2007/9/9/lighttpd_sa_2007_12.txt http://secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/ CVE-2007-4727 2007-09-09 2007-09-10
rkhunter -- insecure temporary file creation rkhunter 1.2.5

Gentoo reports:

Sune Kloppenborg Jeppesen and Tavis Ormandy of the Gentoo Linux Security Team have reported that the check_update.sh script and the main rkhunter script insecurely creates several temporary files with predictable filenames.

A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When rkhunter or the check_update.sh script runs, this would result in the file being overwritten with the rights of the user running the utility, which could be the root user.

13399 CVE-2005-1270 http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml 2005-04-26 2007-09-05
lsh -- multiple vulnerabilities lsh 2.0.1

Secunia reports:

A vulnerability has been reported in LSH, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

CVE-2003-0826 CVE-2005-0814 http://secunia.com/advisories/14609 2005-03-17 2007-09-05 2008-01-07
fetchmail -- denial of service on reject of local warning message fetchmail 4.6.86.3.8_4

Matthias Andree reports:

fetchmail will generate warning messages in certain circumstances (for instance, when leaving oversized messages on the server or login to the upstream fails) and send them to the local postmaster or the user running it.

If this warning message is then refused by the SMTP listener that fetchmail is forwarding the message to, fetchmail crashes and does not collect further messages until it is restarted.

CVE-2007-4565 http://www.fetchmail.info/fetchmail-SA-2007-02.txt 2007-07-29 2007-09-02
gtar -- Directory traversal vulnerability gtar 1.18_1

Red Hat reports:

A path traversal flaw was discovered in the way GNU tar extracted archives. A malicious user could create a tar archive that could write to arbitrary files to which the user running GNU tar had write access.

Red Hat credits Dmitry V. Levin for reporting the issue.

25417 CVE-2007-4131 http://rhn.redhat.com/errata/RHSA-2007-0860.html https://bugzilla.redhat.com/show_bug.cgi?id=251921 2007-08-23 2007-09-01
claws-mail -- POP3 Format String Vulnerability claws-mail sylpheed-claws 2.10.0_3 sylpheed2 2.4.4_1

A Secunia Advisory reports:

A format string error in the "inc_put_error()" function in src/inc.c when displaying a POP3 server's error response can be exploited via specially crafted POP3 server replies containing format specifiers.

Successful exploitation may allow execution of arbitrary code, but requires that the user is tricked into connecting to a malicious POP3 server.

CVE-2007-2958 http://secunia.com/advisories/26550/ http://secunia.com/secunia_research/2007-70/advisory/ 2007-08-24 2007-08-27 2010-05-12
rsync -- off by one stack overflow rsync 2.6.9_1

BugTraq reports:

The rsync utility is prone to an off-by-one buffer-overflow vulnerability. This issue is due to a failure of the application to properly bounds-check user-supplied input.

Successfully exploiting this issue may allow arbitrary code-execution in the context of the affected utility.

25336 CVE-2007-4091 2007-08-15 2007-08-21 2007-08-23
opera -- Vulnerability in javascript handling opera opera-devel linux-opera 9.23.20070809

An advisory from Opera reports:

A specially crafted JavaScript can make Opera execute arbitrary code.

http://www.opera.com/support/search/view/865/ 2007-08-03 2007-08-15 2007-08-25
fsplib -- multiple vulnerabilities fsplib 0.9

A Secunia Advisory reports:

fsplib can be exploited to compromise an application using the library.

A boundary error exists in the processing of file names in fsp_readdir_native, which can be exploited to cause a stack-based buffer overflow if the defined MAXNAMLEN is bigger than 256.

A boundary error exists in the processing of directory entries in fsp_readdir, which can be exploited to cause a stack-based buffer overflow on systems with an insufficient size allocated for the d_name field of directory entries.

CVE-2007-3961 CVE-2007-3962 http://secunia.com/advisories/26184/ 2007-07-24 2007-08-02
joomla -- multiple vulnerabilities joomla 1.0.13

A Secunia Advisory reports:

joomla can be exploited to conduct session fixation attacks, cross-site scripting attacks or HTTP response splitting attacks.

Certain unspecified input passed in com_search, com_content and mod_login is not properly sanitised before being returned to a user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Input passed to the url parameter is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers, which will be included in a response sent to the user, allowing for execution of arbitrary HTML and script code in a user's browser session in context of an affected site.

An error exists in the handling of sessions and can be exploited to hijack another user's session by tricking the user into logging in after following a specially crafted link.

CVE-2007-4188 CVE-2007-4189 CVE-2007-4190 CVE-2007-5577 http://www.joomla.org/content/view/3677/1/ http://secunia.com/advisories/26239/ 2007-07-30 2007-08-02 2010-05-12
FreeBSD -- Buffer overflow in tcpdump(1) tcpdump 3.9.6 FreeBSD 6.26.2_7 6.16.1_19 5.55.5_15

Problem Description:

An un-checked return value in the BGP dissector code can result in an integer overflow. This value is used in subsequent buffer management operations, resulting in a stack based buffer overflow under certain circumstances.

Impact:

By crafting malicious BGP packets, an attacker could exploit this vulnerability to execute code or crash the tcpdump process on the target system. This code would be executed in the context of the user running tcpdump(1). It should be noted that tcpdump(1) requires privileges in order to open live network interfaces.

Workaround:

No workaround is available.

CVE-2007-3798 SA-07:06.tcpdump 2007-08-01 2007-08-02 2016-08-09
FreeBSD -- Predictable query ids in named(8) named 9.49.4.1.1 9.39.3.4.1 FreeBSD 6.26.2_7 6.16.1_19 5.55.5_15

Problem Description:

When named(8) is operating as a recursive DNS server or sending NOTIFY requests to slave DNS servers, named(8) uses a predictable query id.

Impact:

An attacker who can see the query id for some request(s) sent by named(8) is likely to be able to perform DNS cache poisoning by predicting the query id for other request(s).

Workaround:

No workaround is available.

CVE-2007-2926 SA-07:07.bind 2007-07-24 2007-08-02 2016-08-09
xpdf -- stack based buffer overflow xpdf 3.02_2 kdegraphics 3.5.7_1 cups-base 1.2.11_3 gpdf 0 pdftohtml 0.39_3 poppler 0.5.9_4

The KDE Team reports:

kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains a vulnerability that can cause a stack based buffer overflow via a PDF file that exploits an integer overflow in StreamPredictor::StreamPredictor(). Remotely supplied pdf files can be used to disrupt the kpdf viewer on the client machine and possibly execute arbitrary code.

25124 CVE-2007-3387 http://www.kde.org/info/security/advisory-20070730-1.txt 2007-07-30 2007-07-31 2009-04-29
mutt -- buffer overflow vulnerability mutt mutt-lite ja-mutt zh-mutt 1.4.2.3

Securityfocus reports:

Mutt is prone to a local buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before using it in a memory copy operation. An attacker can exploit this issue to execute arbitrary code with the with the privileges of the victim. Failed exploit attempts will result in a denial of service.

24192 CVE-2007-2683 http://www.redhat.com/support/errata/RHSA-2007-0386.html 2007-05-28 2007-07-29
p5-Net-DNS -- multiple Vulnerabilities p5-Net-DNS 0.60

A Secunia Advisory reports:

An error exists in the handling of DNS queries where IDs are incremented with a fixed value and are additionally used for child processes in a forking server. This can be exploited to poison the DNS cache of an application using the module if a valid ID is guessed.

An error in the PP implementation within the "dn_expand()" function can be exploited to cause a stack overflow due to an endless loop via a specially crafted DNS packet.

CVE-2007-3377 CVE-2007-3409 http://secunia.com/advisories/25829/ 2007-06-27 2007-07-28
phpsysinfo -- url Cross-Site Scripting phpSysInfo 2.5.3_1

Doz reports:

A Input passed in the URL to index.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

http://secunia.com/advisories/26248/ 2007-07-27 2007-07-28 2007-08-01
drupal -- Cross site request forgeries drupal5 5.2

The Drupal Project reports:

Several parts in Drupal core are not protected against cross site request forgeries due to inproper use of the Forms API, or by taking action solely on GET requests. Malicious users are able to delete comments and content revisions and disable menu items by enticing a privileged users to visit certain URLs while the victim is logged-in to the targeted site.

http://drupal.org/node/162360 http://secunia.com/advisories/26224/ 2007-07-26 2007-07-28
drupal -- Multiple cross-site scripting vulnerabilities drupal4 4.7.7 drupal5 5.2

The Drupal Project reports:

Some server variables are not escaped consistently. When a malicious user is able to entice a victim to visit a specially crafted link or webpage, arbitrary HTML and script code can be injected and executed in the context of the victim's session on the targeted website.

Custom content type names are not escaped consistently. A malicious user with the 'administer content types' permission would be able to inject and execute arbitrary HTML and script code on the website. Revoking the 'administer content types' permission provides an immediate workaround.

http://drupal.org/node/162361 http://secunia.com/advisories/26224/ 2007-07-26 2007-07-28
vim -- Command Format String Vulnerability vim vim-console vim-lite vim-ruby vim6 vim6-ruby 7.1.39

A Secunia Advisory reports:

A format string error in the "helptags_one()" function in src/ex_cmds.c when running the "helptags" command can be exploited to execute arbitrary code via specially crafted help files.

CVE-2007-2953 http://secunia.com/advisories/25941/ 2007-07-27 2007-07-27
libvorbis -- Multiple memory corruption flaws libvorbis 1.2.0,3

isecpartners reports:

libvorbis contains several vulnerabilities allowing heap overwrite, read violations and a function pointer overwrite. These bugs cause a at least a denial of service, and potentially code execution.

http://www.isecpartners.com/advisories/2007-003-libvorbis.txt CVE-2007-3106 2007-06-05 2007-07-26
tomcat -- XSS vulnerability in sample applications apache-tomcat 6.0.06.0.11 tomcat 5.0.05.5.24 jakarta-tomcat 5.0.05.5.24

The Apache Project reports:

The JSP and Servlet included in the sample application within the Tomcat documentation webapp did not escape user provided data before including it in the output. This enabled a XSS attack. These pages have been simplified not to use any user provided data in the output.

CVE-2007-1355 24058 2007-05-19 2007-07-24
tomcat -- multiple vulnerabilities apache-tomcat 4.1.04.1.36 6.0.06.0.11 tomcat 5.0.05.5.23 jakarta-tomcat 4.0.04.1.0 5.0.05.5.23

Apache Project reports:

The Apache Tomcat team is proud to announce the immediate availability of Tomcat 4.1.36 stable. This build contains numerous library updates, A small number of bug fixes and two important security fixes.

CVE-2005-2090 CVE-2007-0450 CVE-2007-1358 2007-04-27 2007-07-24
dokuwiki -- XSS vulnerability in spellchecker backend dokuwiki 20070626_1 dokuwiki-devel 20070524_1

DokuWiki reports:

The spellchecker tests the UTF-8 capabilities of the used browser by sending an UTF-8 string to the backend, which will send it back unfiltered. By comparing string length the spellchecker can work around broken implementations. An attacker could construct a form to let users send JavaScript to the spellchecker backend, resulting in malicious JavaScript being executed in their browser.

Affected are all versions up to and including 2007-06-26 even when the spell checker is disabled.

http://xforce.iss.net/xforce/xfdb/35501 CVE-2007-3930 2007-06-26 2007-07-24
lighttpd -- multiple vulnerabilities lighttpd 1.4.15_1

Secunia Advisory reports:

Some vulnerabilities have been reported in lighttpd, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service).

CVE-2007-3947 CVE-2007-3948 CVE-2007-3949 CVE-2007-3950 http://trac.lighttpd.net/trac/ticket/1216 http://trac.lighttpd.net/trac/ticket/1232 http://trac.lighttpd.net/trac/ticket/1230 http://trac.lighttpd.net/trac/ticket/1263 2007-07-20 2007-07-21 2010-05-12
opera -- multiple vulnerabilities opera opera-devel linux-opera 9.22

Opera Software ASA reports of multiple security fixes in Opera, including an arbitrary code execute vulnerability:

Opera for Linux, FreeBSD, and Solaris has a flaw in the createPattern function that leaves old data that was in the memory before Opera allocated it in the new pattern. The pattern can be read and analyzed by JavaScript, so an attacker can get random samples of the user's memory, which may contain data.

Removing a specially crafted torrent from the download manager can crash Opera. The crash is caused by an erroneous memory access.

An attacker needs to entice the user to accept the malicious BitTorrent download, and later remove it from Opera's download manager. To inject code, additional means will have to be employed.

Users clicking a BitTorrent link and rejecting the download are not affected.

data: URLs embed data inside them, instead of linking to an external resource. Opera can mistakenly display the end of a data URL instead of the beginning. This allows an attacker to spoof the URL of a trusted site.

Opera's HTTP authentication dialog is displayed when the user enters a Web page that requires a login name and a password. To inform the user which server it was that asked for login credentials, the dialog displays the server name.

The user has to see the entire server name. A truncated name can be misleading. Opera's authentication dialog cuts off the long server names at the right hand side, adding an ellipsis (...) to indicate that it has been cut off.

The dialog has a predictable size, allowing an attacker to create a server name which will look almost like a trusted site, because the real domain name has been cut off. The three dots at the end will not be obvious to all users.

This flaw can be exploited by phishers who can set up custom sub-domains, for example by hosting their own public DNS.

CVE-2007-3929 CVE-2007-4944 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=564 http://www.opera.com/support/search/view/861/ http://www.opera.com/support/search/view/862/ http://www.opera.com/support/search/view/863/ http://www.opera.com/support/search/view/864/ http://www.opera.com/docs/changelogs/freebsd/922/ 2007-07-19 2007-07-19 2010-05-12
mozilla -- multiple vulnerabilities firefox 2.0.0.5,1 3.*,13.0.a2_3,1 linux-firefox linux-thunderbird mozilla-thunderbird thunderbird 2.0.0.5 seamonkey linux-seamonkey 1.1.3 linux-firefox-devel 3.0.a2007.12.12 linux-seamonkey-devel 2.0.a2007.12.12 firefox-ja linux-mozilla-devel linux-mozilla mozilla 0

The Mozilla Foundation reports of multiple security issues in Firefox, Seamonkey, and Thunderbird. Several of these issues can probably be used to run arbitrary code with the privilege of the user running the program.

  • MFSA 2007-25 XPCNativeWrapper pollution
  • MFSA 2007-24 Unauthorized access to wyciwyg:// documents
  • MFSA 2007-21 Privilege escalation using an event handler attached to an element not in the document
  • MFSA 2007-20 Frame spoofing while window is loading
  • MFSA 2007-19 XSS using addEventListener and setTimeout
  • MFSA 2007-18 Crashes with evidence of memory corruption
CVE-2007-3089 CVE-2007-3734 CVE-2007-3735 CVE-2007-3737 CVE-2007-3738 http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.5 http://www.mozilla.org/security/announce/2007/mfsa2007-18.html http://www.mozilla.org/security/announce/2007/mfsa2007-19.html http://www.mozilla.org/security/announce/2007/mfsa2007-20.html http://www.mozilla.org/security/announce/2007/mfsa2007-21.html http://www.mozilla.org/security/announce/2007/mfsa2007-24.html http://www.mozilla.org/security/announce/2007/mfsa2007-25.html TA07-199A 2007-07-17 2007-07-19 2008-06-21
linux-flashplugin -- critical vulnerabilities linux-flashplugin 9.09.0r45 8.08.0r34 7.0r69

Adobe reports:

Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities.

CVE-2007-2022 CVE-2007-3456 CVE-2007-3457 2007-07-10 2007-07-18
wireshark -- Multiple problems wireshark wireshark-lite ethereal ethereal-lite tethereal tethereal-lite 0.8.200.99.6

wireshark Team reports:

It may be possible to make Wireshark or Ethereal crash or use up available memory by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

CVE-2007-3389 CVE-2007-3390 CVE-2007-3391 CVE-2007-3392 CVE-2007-3393 http://secunia.com/advisories/25833/ http://www.wireshark.org/security/wnpa-sec-2007-02.html 2007-06-29 2007-07-06 2010-05-12
typespeed -- arbitrary code execution typespeed 0.4.1

Debian reports:

Ulf Härnhammar from the Debian Security Audit Project discovered a problem in typespeed, a touch-typist trainer disguised as game. This could lead to a local attacker executing arbitrary code.

CVE-2005-0105 http://www.debian.org/security/2005/dsa-684 2005-02-16 2007-07-03 2007-07-09
vlc -- format string vulnerability and integer overflow vlc 0.8.6c

isecpartners reports:

VLC is vulnerable to a format string attack in the parsing of Vorbis comments in Ogg Vorbis and Ogg Theora files, CDDA data or SAP/SDP service discovery messages. Additionally, there are two errors in the handling of wav files, one a denial of service due to an uninitialized variable, and one integer overflow in sampling frequency calculations.

CVE-2007-3316 CVE-2007-3468 CVE-2007-3467 http://www.isecpartners.com/advisories/2007-001-vlc.txt 2007-06-05 2007-06-18 2010-05-12
flac123 -- stack overflow in comment parsing flac123 0.0.10

isecpartners reports:

flac123, also known as flac-tools, is vulnerable to a buffer overflow in vorbis comment parsing. This allows for the execution of arbitrary code.

CVE-2007-3507 http://sourceforge.net/forum/forum.php?forum_id=710314 http://www.isecpartners.com/advisories/2007-002-flactools.txt 2007-06-05 2007-06-28 2007-08-10
gd -- multiple vulnerabilities gd 2.0.35,1

gd had been reported vulnerable to several vulnerabilities:

CVE-2007-3472 CVE-2007-3473 CVE-2007-3474 CVE-2007-3475 CVE-2007-3476 CVE-2007-3477 CVE-2007-3478 http://www.libgd.org/ReleaseNote020035 http://www.frsirt.com/english/advisories/2007/2336 http://bugs.libgd.org/?do=details&task_id=89 http://bugs.libgd.org/?do=details&task_id=94 http://bugs.libgd.org/?do=details&task_id=70 http://bugs.libgd.org/?do=details&task_id=87 http://bugs.libgd.org/?do=details&task_id=92 http://bugs.libgd.org/?do=details&task_id=74 http://bugs.libgd.org/?do=details&task_id=48 http://bugs.php.net/bug.php?id=40578 2007-06-21 2007-06-29
evolution-data-server -- remote execution of arbitrary code vulnerability evolution-data-server 1.10.2_1 1.11.*1.11.4

Debian project reports:

It was discovered that the IMAP code in the Evolution Data Server performs insufficient sanitising of a value later used an array index, which can lead to the execution of arbitrary code.

CVE-2007-3257 http://secunia.com/advisories/25766/ http://bugzilla.gnome.org/show_bug.cgi?id=447414 2007-06-23 2007-06-25 2007-06-28
xpcd -- buffer overflow xpcd 0

Debian Project reports:

Erik Sjolund discovered a buffer overflow in pcdsvgaview, an SVGA PhotoCD viewer. xpcd-svga is part of xpcd and uses svgalib to display graphics on the Linux console for which root permissions are required. A malicious user could overflow a fixed-size buffer and may cause the program to execute arbitrary code with elevated privileges.

12523 CVE-2005-0074 http://www.debian.org/security/2005/dsa-676 2005-02-11 2007-06-21
clamav -- multiple vulnerabilities clamav 0.90.3

Clamav had been found vulnerable to multiple vulnerabilities:

CVE-2007-2650 CVE-2007-3023 CVE-2007-3024 CVE-2007-3122 CVE-2007-3123 http://news.gmane.org/gmane.comp.security.virus.clamav.devel/cutoff=2853 2007-04-18 2007-06-19
p5-Mail-SpamAssassin -- local user symlink-attack DoS vulnerability p5-Mail-SpamAssassin 3.2.1

SpamAssassin website reports:

A local user symlink-attack DoS vulnerability in SpamAssassin has been found, affecting versions 3.1.x, 3.2.0, and SVN trunk.

http://spamassassin.apache.org/advisories/cve-2007-2873.txt CVE-2007-2873 2007-06-11 2007-06-18
cups -- Incomplete SSL Negotiation Denial of Service cups-base 1.2.11

Secunia reports:

CUPS is not using multiple workers to handle connections. This can be exploited to stop CUPS from accepting new connections by starting but never completing an SSL negotiation.

http://secunia.com/advisories/24517/ http://security.gentoo.org/glsa/glsa-200703-28.xml CVE-2007-0720 2007-05-05 2007-06-12
c-ares -- DNS Cache Poisoning Vulnerability c-ares 1.4.0

Secunia reports:

The vulnerability is caused due to predictable DNS "Transaction ID" field in DNS queries and can be exploited to poison the DNS cache of an application using the library if a valid ID is guessed.

CVE-2007-3152 CVE-2007-3153 http://secunia.com/advisories/25579/ http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&content-type=text/vnd.viewcvs-markup 2007-06-08 2007-06-09 2010-05-12
wordpress -- XMLRPC SQL Injection wordpress de-wordpress zh-wordpress 2.2.1

Secunia reports:

Slappter has discovered a vulnerability in WordPress, which can be exploited by malicious users to conduct SQL injection attacks.

Input passed to the "wp.suggestCategories" method in xmlrpc.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Successful exploitation allows e.g. retrieving usernames and password hashes, but requires valid user credentials and knowledge of the database table prefix.

24344 http://secunia.com/advisories/25552/ 2007-06-06 2007-06-09 2007-06-24
wordpress -- unmoderated comments disclosure wordpress de-wordpress zh-wordpress 2.2.2

Blogsecurity reports:

An attacker can read comments on posts that have not been moderated. This can be a real security risk if blog admins are using unmoderated comments (comments that have not been made public) to hide sensitive notes regarding posts, future work, passwords etc. So please be careful if you are one of these blog admins.

http://blogsecurity.net/news/news-310507/ 2007-06-01 2007-06-09 2007-08-16
webmin -- cross site scripting vulnerability webmin 1.350

Secunia reports:

Input passed to unspecified parameters in pam_login.cgi is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

24381 CVE-2007-3156 http://secunia.com/advisories/25580/ http://www.webmin.com/changes-1.350.html 2007-06-01 2007-06-09 2010-05-12
mplayer -- cddb stack overflow mplayer mplayer-esound mplayer-gtk mplayer-gtk2 mplayer-gtk-esound mplayer-gtk2-esound 0.99.10_10

Mplayer Team reports:

A stack overflow was found in the code used to handle cddb queries. When copying the album title and category, no checking was performed on the size of the strings before storing them in a fixed-size array. A malicious entry in the database could trigger a stack overflow in the program, leading to arbitrary code execution with the uid of the user running MPlayer.

24302 CVE-2007-2948 2007-06-06 2007-06-07
mod_jk -- information disclosure mod_jk 1.2.23,1 mod_jk-ap2 1.2.23

Kazu Nambo reports:

URL decoding the the Apache webserver prior to decoding in the Tomcat server could pypass access control rules and give access to pages on a different AJP by sending a crafted URL.

CVE-2007-1860 http://secunia.com/advisories/25383/ http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1 http://tomcat.apache.org/security-jk.html 2007-05-18 2007-06-05 2007-10-31
typo3 -- email header injection typo3 3.04.0.5 4.14.1.1

Olivier Dobberkau, Andreas Otto, and Thorsten Kahler report:

An unspecified error in the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for, e.g. sending spam messages.

CVE-2007-1081 http://secunia.com/advisories/24207/ http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/ 2007-02-21 2007-06-04
phppgadmin -- cross site scripting vulnerability phppgadmin 4.1.1

SecurityFocus reports about phppgadmin:

Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.

24115 CVE-2007-5728 http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html http://secunia.com/advisories/25446/ 2007-05-27 2007-06-04 2010-05-12
findutils -- GNU locate heap buffer overrun findutils 4.2.31

James Youngman reports:

When GNU locate reads filenames from an old-format locate database, they are read into a fixed-length buffer allocated on the heap. Filenames longer than the 1026-byte buffer can cause a buffer overrun. The overrunning data can be chosen by any person able to control the names of filenames created on the local system. This will normally include all local users, but in many cases also remote users (for example in the case of FTP servers allowing uploads).

CVE-2007-2452 http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html 2007-05-30 2007-06-01
FreeType 2 -- Heap overflow vulnerability freetype2 2.2.1_2

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

CVE-2007-2754 http://lists.gnu.org/archive/html/freetype-devel/2007-04/msg00041.html http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2754 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240200 ports/112769 2007-04-27 2007-05-24
FreeBSD -- heap overflow in file(1) file 4.21 FreeBSD 6.26.2_5 6.16.1_17 5.55.5_13

Problem Description:

When writing data into a buffer in the file_printf function, the length of the unused portion of the buffer is not correctly tracked, resulting in a buffer overflow when processing certain files.

Impact:

An attacker who can cause file(1) to be run on a maliciously constructed input can cause file(1) to crash. It may be possible for such an attacker to execute arbitrary code with the privileges of the user running file(1).

The above also applies to any other applications using the libmagic(3) library.

Workaround:

No workaround is available, but systems where file(1) and other libmagic(3)-using applications are never run on untrusted input are not vulnerable.

CVE-2007-1536 SA-07:04.file 2007-05-23 2007-05-23 2016-08-09
squirrelmail -- Cross site scripting in HTML filter squirrelmail 1.4.01.4.9a

The SquirrelMail developers report:

Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.

CVE-2007-1262 http://www.squirrelmail.org/security/issue/2007-05-09 2007-05-09 2007-05-21
png -- DoS crash vulnerability png 1.2.17

A Libpng Security Advisory reports:

A grayscale PNG image with a malformed (bad CRC) tRNS chunk will crash some libpng applications.

This vulnerability could be used to crash a browser when a user tries to view such a malformed PNG file. It is not known whether the vulnerability could be exploited otherwise.

CVE-2007-2445 684664 http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt 2007-05-15 2007-05-16
samba -- multiple vulnerabilities samba ja-samba 3.*3.0.25 3.*,13.0.25,1

The Samba Team reports:

A bug in the local SID/Name translation routines may potentially result in a user being able to issue SMB/CIFS protocol operations as root.

When translating SIDs to/from names using Samba local list of user and group accounts, a logic error in the smbd daemon's internal security stack may result in a transition to the root user id rather than the non-root user. The user is then able to temporarily issue SMB/CIFS protocol operations as the root user. This window of opportunity may allow the attacker to establish additional means of gaining root access to the server.

Various bugs in Samba's NDR parsing can allow a user to send specially crafted MS-RPC requests that will overwrite the heap space with user defined data.

Unescaped user input parameters are passed as arguments to /bin/sh allowing for remote command execution.

This bug was originally reported against the anonymous calls to the SamrChangePassword() MS-RPC function in combination with the "username map script" smb.conf option (which is not enabled by default).

After further investigation by Samba developers, it was determined that the problem was much broader and impacts remote printer and file share management as well. The root cause is passing unfiltered user input provided via MS-RPC calls to /bin/sh when invoking externals scripts defined in smb.conf. However, unlike the "username map script" vulnerability, the remote file and printer management scripts require an authenticated user session.

CVE-2007-2444 CVE-2007-2446 CVE-2007-2447 http://de5.samba.org/samba/security/CVE-2007-2444.html http://de5.samba.org/samba/security/CVE-2007-2446.html http://de5.samba.org/samba/security/CVE-2007-2447.html 2007-05-14 2007-05-16 2008-09-26
php -- multiple vulnerabilities php5-imap php5-odbc php5-session php5-shmop php5-sqlite php5-wddx php5 5.2.2 php4-odbc php4-session php4-shmop php4-wddx php4 4.4.7 mod_php4-twig mod_php4 mod_php5 mod_php php4-cgi php4-cli php4-dtc php4-horde php4-nms php5-cgi php5-cli php5-dtc php5-horde php5-nms 44.4.7 55.2.2

The PHP development team reports:

Security Enhancements and Fixes in PHP 5.2.2 and PHP 4.4.7:

  • Fixed CVE-2007-1001, GD wbmp used with invalid image size
  • Fixed asciiz byte truncation inside mail()
  • Fixed a bug in mb_parse_str() that can be used to activate register_globals
  • Fixed unallocated memory access/double free in in array_user_key_compare()
  • Fixed a double free inside session_regenerate_id()
  • Added missing open_basedir & safe_mode checks to zip:// and bzip:// wrappers.
  • Limit nesting level of input variables with max_input_nesting_level as fix for.
  • Fixed CRLF injection inside ftp_putcmd().
  • Fixed a possible super-global overwrite inside import_request_variables().
  • Fixed a remotely trigger-able buffer overflow inside bundled libxmlrpc library.

Security Enhancements and Fixes in PHP 5.2.2 only:

  • Fixed a header injection via Subject and To parameters to the mail() function
  • Fixed wrong length calculation in unserialize S type.
  • Fixed substr_compare and substr_count information leak.
  • Fixed a remotely trigger-able buffer overflow inside make_http_soap_request().
  • Fixed a buffer overflow inside user_filter_factory_create().

Security Enhancements and Fixes in PHP 4.4.7 only:

  • XSS in phpinfo()
CVE-2007-1001 http://www.php.net/releases/4_4_7.php http://www.php.net/releases/5_2_2.php 2007-05-03 2007-05-07 2014-04-01
qemu -- several vulnerabilities qemu qemu-devel 0.9.0_1 0.9.0s.20070101*0.9.0s.20070405_3

The Debian Security Team reports:

Several vulnerabilities have been discovered in the QEMU processor emulator, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video driver performs insufficient bounds checking, which might allow the execution of arbitrary code through a heap overflow.

CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the socket code perform insufficient input validation, which might allow the execution of arbitrary code through a heap overflow.

CVE-2007-1322
Tavis Ormandy discovered that the "icebp" instruction can be abused to terminate the emulation, resulting in denial of service.

CVE-2007-1323
Tavis Ormandy discovered that the NE2000 network driver and the socket code perform insufficient input validation, which might allow the execution of arbitrary code through a heap overflow.

CVE-2007-1366
Tavis Ormandy discovered that the "aam" instruction can be abused to crash qemu through a division by zero, resulting in denial of service.

CVE-2007-1320 CVE-2007-1321 CVE-2007-1322 CVE-2007-1323 CVE-2007-1366 http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html 2007-05-01 2007-05-01 2007-05-02
p5-Imager -- possibly exploitable buffer overflow p5-Imager 0.57

Imager 0.56 and all earlier versions with BMP support have a security issue when reading compressed 8-bit per pixel BMP files where either a compressed run of data or a literal run of data overflows the scan-line.

Such an overflow causes a buffer overflow in a malloc() allocated memory buffer, possibly corrupting the memory arena headers.

The effect depends on your system memory allocator, with glibc this typically results in an abort, but with other memory allocators it may be possible to cause local code execution.

CVE-2007-1942 CVE-2007-1943 CVE-2007-1946 CVE-2007-1948 https://rt.cpan.org/Public/Bug/Display.html?id=26811 http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html 2007-04-04 2007-04-30 2010-05-12
FreeBSD -- IPv6 Routing Header 0 is dangerous FreeBSD 6.26.2_4 6.16.1_16 5.55.5_12

Problem Description

There is no mechanism for preventing IPv6 routing headers from being used to route packets over the same link(s) many times.

Impact

An attacker can "amplify" a denial of service attack against a link between two vulnerable hosts; that is, by sending a small volume of traffic the attacker can consume a much larger amount of bandwidth between the two vulnerable hosts.

An attacker can use vulnerable hosts to "concentrate" a denial of service attack against a victim host or network; that is, a set of packets sent over a period of 30 seconds or more could be constructed such that they all arrive at the victim within a period of 1 second or less over a period of 30 seconds or more could be constructed such that they all arrive at the victim within a period of 1 second or less.

Other attacks may also be possible.

Workaround

No workaround is available.

CVE-2007-2242 SA-07:03.ipv6 2007-04-26 2007-04-28 2016-08-09
mod_perl -- remote DoS in PATH_INFO parsing mod_perl 1.30 mod_perl2 2.0.3_2,3

Mandriva reports:

PerlRun.pm in Apache mod_perl 1.29 and earlier, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.

CVE-2007-1349 http://www.mandriva.com/security/advisories?name=MDKSA-2007:083 http://secunia.com/advisories/24839 2007-03-29 2007-04-24 2007-06-27
claws-mail -- APOP vulnerability claws-mail 2.9.0

CVE reports:

The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.

CVE-2007-1558 http://www.claws-mail.org/news.php 2007-04-02 2007-04-19
lighttpd -- DOS when access files with mtime 0 lighttpd 1.4.15

Lighttpd SA:

Lighttpd caches the rendered string for mtime. The cache key has as a default value 0. At that point the pointer to the string are still NULL. If a file with an mtime of 0 is requested it tries to access the pointer and crashes.

The bug requires that a malicious user can either upload files or manipulate the mtime of the files.

The bug was reported by cubiq and fixed by Marcus Rueckert.

CVE-2007-1870 http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt 2007-01-14 2007-04-14
lighttpd -- Remote DOS in CRLF parsing lighttpd 1.4.111.4.13_2

Lighttpd SA:

If the connection aborts during parsing "\r\n\r\n" the server might get into a infinite loop and use 100% of the CPU time. lighttpd still responses to other requests. This can be repeated until either the server limit for concurrent connections or file descriptors is reached.

The bug was reported and fixed by Robert Jakabosky.

CVE-2007-1869 http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt 2006-12-15 2007-04-14
freeradius -- EAP-TTLS Tunnel Memory Leak Remote DOS Vulnerability freeradius freeradius-mysql 1.1.5

The freeradius development team reports:

A malicious 802.1x supplicant could send malformed Diameter format attributes inside of an EAP-TTLS tunnel. The server would reject the authentication request, but would leak one VALUE_PAIR data structure, of approximately 300 bytes. If an attacker performed the attack many times (e.g. thousands or more over a period of minutes to hours), the server could leak megabytes of memory, potentially leading to an "out of memory" condition, and early process exit.

23466 CVE-2005-1455 CVE-2005-1454 CVE-2007-2028 CVE-2005-4745 http://www.freeradius.org/security.html 2007-04-10 2007-04-13 2010-05-12
fetchmail -- insecure APOP authentication fetchmail 6.3.8

Matthias Andree reports:

The POP3 standard, currently RFC-1939, has specified an optional, MD5-based authentication scheme called "APOP" which no longer should be considered secure.

Additionally, fetchmail's POP3 client implementation has been validating the APOP challenge too lightly and accepted random garbage as a POP3 server's APOP challenge. This made it easier than necessary for man-in-the-middle attackers to retrieve by several probing and guessing the first three characters of the APOP secret, bringing brute forcing the remaining characters well within reach.

CVE-2007-1558 http://www.fetchmail.info/fetchmail-SA-2007-01.txt 2007-04-06 2007-04-09
mcweject -- exploitable buffer overflow mcweject 0.9

CVE reports:

Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.

CVE-2007-1719 ports/111365 http://www.milw0rm.com/exploits/3578 2007-03-27 2007-04-08
WebCalendar -- "noSet" variable overwrite vulnerability WebCalendar 1.0.5

Secunia reports:

A vulnerability has been discovered in WebCalendar, which can be exploited by malicious people to compromise a vulnerable system.

Input passed to unspecified parameters is not properly verified before being used with the "noSet" parameter set. This can be exploited to overwrite certain variables, and allows e.g. the inclusion of arbitrary PHP files from internal or external resources.

CVE-2007-1343 22834 http://sourceforge.net/project/shownotes.php?release_id=491130 http://xforce.iss.net/xforce/xfdb/32832 2007-03-04 2007-04-08
zope -- cross-site scripting vulnerability zope 2.7.9_2 2.8.02.8.8 2.9.02.9.6 2.10.02.10.2 plone 2.5.3

The Zope Team reports:

A vulnerability has been discovered in Zope, where by certain types of misuse of HTTP GET, an attacker could gain elevated privileges. All Zope versions up to and including 2.10.2 are affected.

23084 CVE-2007-0240 ports/111119 http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view http://plone.org/products/plone/releases/2.5.3 2007-01-16 2007-04-05 2009-03-22
Squid -- TRACE method handling denial of service squid 2.6.*2.6.12

Squid advisory 2007:1 notes:

Due to an internal error Squid-2.6 is vulnerable to a denial of service attack when processing the TRACE request method.

Workarounds:

To work around the problem deny access to using the TRACE method by inserting the following two lines before your first http_access rule.

acl TRACE method TRACE

http_access deny TRACE

CVE-2007-1560 http://www.squid-cache.org/Advisories/SQUID-2007_1.txt 2007-03-20 2007-03-21 2010-05-12
sql-ledger -- security bypass vulnerability sql-ledger 2.6.26

Chris Travers reports:

George Theall of Tenable Security notified the LedgerSMB core team today of an authentication bypass vulnerability allowing full access to the administrator interface of LedgerSMB 1.1 and SQL-Ledger 2.x. The problem is caused by the password checking routine failing to enforce a password check under certain circumstances. The user can then create accounts or effect denial of service attacks.

This is not related to any previous CVE.

We have coordinated with the SQL-Ledger vendor and today both of us released security patches correcting the problem. SQL-Ledger users who can upgrade to 2.6.26 should do so, and LedgerSMB 1.1 or 1.0 users should upgrade to 1.1.9. Users who cannot upgrade should configure their web servers to use http authentication for the admin.pl script in the main root directory.

ports/110350 http://www.securityfocus.com/archive/1/462375 2007-03-09 2007-03-16
samba -- potential Denial of Service bug in smbd samba ja-samba 3.0.6,13.0.24,1

The Samba Team reports:

Internally Samba's file server daemon, smbd, implements support for deferred file open calls in an attempt to serve client requests that would otherwise fail due to a share mode violation. When renaming a file under certain circumstances it is possible that the request is never removed from the deferred open queue. smbd will then become stuck is a loop trying to service the open request.

This bug may allow an authenticated user to exhaust resources such as memory and CPU on the server by opening multiple CIFS sessions, each of which will normally spawn a new smbd process, and sending each connection into an infinite loop.

CVE-2007-0452 http://www.samba.org/samba/security/CVE-2007-0452.html 2007-02-05 2007-03-16
samba -- format string bug in afsacl.so VFS plugin samba ja-samba 3.0.6,13.0.24,1

The Samba Team reports:

NOTE: This security advisory only impacts Samba servers that share AFS file systems to CIFS clients and which have been explicitly instructed in smb.conf to load the afsacl.so VFS module.

The source defect results in the name of a file stored on disk being used as the format string in a call to snprintf(). This bug becomes exploitable only when a user is able to write to a share which utilizes Samba's afsacl.so library for setting Windows NT access control lists on files residing on an AFS file system.

CVE-2007-0454 http://www.samba.org/samba/security/CVE-2007-0454.html 2007-02-05 2007-03-16
ktorrent -- multiple vulnerabilities ktorrent 2.1.2 ktorrent-devel 20070311

Two problems have been found in KTorrent:

CVE-2007-1384 CVE-2007-1385 http://ktorrent.org/forum/viewtopic.php?t=1401 2007-03-09 2007-03-11 2007-03-14
mplayer -- DMO File Parsing Buffer Overflow Vulnerability mplayer mplayer-esound mplayer-gtk mplayer-gtk2 mplayer-gtk-esound mplayer-gtk2-esound 0.99.10_5

"Moritz Jodeit reports:

There's an exploitable buffer overflow in the current version of MPlayer (v1.0rc1) which can be exploited with a maliciously crafted video file. It is hidden in the DMO_VideoDecoder() function of `loader/dmo/DMO_VideoDecoder.c' file.

22771 CVE-2007-1246 2007-02-11 2007-03-09
trac -- cross site scripting vulnerability trac 0.10.3 ja-trac 0.10.3_1

Secunia reports:

The vulnerability is caused due to an error within the "download wiki page as text" function, which can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Successful exploitation may require that the victim uses IE.

http://secunia.com/advisories/24470 http://trac.edgewall.org/wiki/ChangeLog#a0.10.3.1 2007-03-09 2007-03-09
mod_jk -- long URL stack overflow vulnerability mod_jk-ap2 mod_jk 1.2.191.2.21

TippingPoint and The Zero Day Initiative reports:

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apache Tomcat JK Web Server Connector. Authentication is not required to exploit this vulnerability.

The specific flaw exists in the URI handler for the mod_jk.so library, map_uri_to_worker(), defined in native/common/jk_uri_worker_map.c. When parsing a long URL request, the URI worker map routine performs an unsafe memory copy. This results in a stack overflow condition which can be leveraged to execute arbitrary code.

CVE-2007-0774 http://tomcat.apache.org/security-jk.html http://www.zerodayinitiative.com/advisories/ZDI-07-008.html 2007-03-02 2007-03-05 2007-03-06
bind -- Multiple Denial of Service vulnerabilities named 9.3.4 FreeBSD 6.26.2_1 6.16.1_13 5.55.5_11

Problem Description:

A type * (ANY) query response containing multiple RRsets can trigger an assertion failure.

Certain recursive queries can cause the nameserver to crash by using memory which has already been freed.

Impact:

A remote attacker sending a type * (ANY) query to an authoritative DNS server for a DNSSEC signed zone can cause the named(8) daemon to exit, resulting in a Denial of Service.

A remote attacker sending recursive queries can cause the nameserver to crash, resulting in a Denial of Service.

Workaround:

There is no workaround available, but systems which are not authoritative servers for DNSSEC signed zones are not affected by the first issue; and systems which do not permit untrusted users to perform recursive DNS resolution are not affected by the second issue. Note that the default configuration for named(8) in FreeBSD allows local access only (which on many systems is equivalent to refusing access to untrusted users).

CVE-2007-0493 CVE-2007-0494 SA-07:02.bind 2007-02-09 2007-02-27 2016-08-09
FreeBSD -- Jail rc.d script privilege escalation FreeBSD 6.16.1_12 6.06.0_17 5.55.5_15

Problem Description:

In multiple situations the host's jail rc.d(8) script does not check if a path inside the jail file system structure is a symbolic link before using the path. In particular this is the case when writing the output from the jail start-up to /var/log/console.log and when mounting and unmounting file systems inside the jail directory structure.

Impact:

Due to the lack of handling of potential symbolic links the host's jail rc.d(8) script is vulnerable to "symlink attacks". By replacing /var/log/console.log inside the jail with a symbolic link it is possible for the superuser (root) inside the jail to overwrite files on the host system outside the jail with arbitrary content. This in turn can be used to execute arbitrary commands with non-jailed superuser privileges.

Similarly, by changing directory mount points inside the jail file system structure into symbolic links, it may be possible for a jailed attacker to mount file systems which were meant to be mounted inside the jail at arbitrary points in the host file system structure, or to unmount arbitrary file systems on the host system.

NOTE WELL: The above vulnerabilities occur only when a jail is being started or stopped using the host's jail rc.d(8) script; once started (and until stopped), running jails cannot exploit this.

Workaround:

If the sysctl(8) variable security.jail.chflags_allowed is set to 0 (the default), setting the "sunlnk" system flag on /var, /var/log, /var/log/console.log, and all file system mount points and their parent directories inside the jail(s) will ensure that the console log file and mount points are not replaced by symbolic links. If this is done while jails are running, the administrator must check that an attacker has not replaced any directories with symlinks after setting the "sunlnk" flag.

CVE-2007-0166 SA-07:01.jail 2007-01-11 2007-02-27 2016-08-09
gtar -- name mangling symlink vulnerability FreeBSD 5.55.5_9 4.114.11_26

Problem Description:

Symlinks created using the "GNUTYPE_NAMES" tar extension can be absolute due to lack of proper sanity checks.

Impact:

If an attacker can get a user to extract a specially crafted tar archive the attacker can overwrite arbitrary files with the permissions of the user running gtar. If file system permissions allow it, this may allow the attacker to overwrite important system file (if gtar is being run as root), or important user configuration files such as .tcshrc or .bashrc, which would allow the attacker to run arbitrary commands.

Workaround:

Use "bsdtar", which is the default tar implementation in FreeBSD 5.3 and higher. For FreeBSD 4.x, bsdtar is available in the FreeBSD Ports Collection as ports/archivers/libarchive.

CVE-2006-6097 SA-06:26.gtar 2006-12-06 2007-02-27 2016-08-09
FreeBSD -- Kernel memory disclosure in firewire(4) FreeBSD 6.16.1_11 6.06.2_16 5.55.5_9 4.114.11_26

Problem Description:

In the FW_GCROM ioctl, a signed integer comparison is used instead of an unsigned integer comparison when computing the length of a buffer to be copied from the kernel into the calling application.

Impact:

A user in the "operator" group can read the contents of kernel memory. Such memory might contain sensitive information, such as portions of the file cache or terminal buffers. This information might be directly useful, or it might be leveraged to obtain elevated privileges in some way; for example, a terminal buffer might include a user-entered password.

Workaround:

No workaround is available, but systems without IEEE 1394 ("FireWire") interfaces are not vulnerable. (Note that systems with IEEE 1394 interfaces are affected regardless of whether any devices are attached.)

Note also that FreeBSD does not have any non-root users in the "operator" group by default; systems on which no users have been added to this group are therefore also not vulnerable.

CVE-2006-6013 SA-06:25.kmem 2006-12-06 2007-02-27 2016-08-09
libarchive -- Infinite loop in corrupt archives handling in libarchive libarchive 1.3.1

Problem Description:

If the end of an archive is reached while attempting to "skip" past a region of an archive, libarchive will enter an infinite loop wherein it repeatedly attempts (and fails) to read further data.

Impact:

An attacker able to cause a system to extract (via "tar -x" or another application which uses libarchive) or list the contents (via "tar -t" or another libarchive-using application) of an archive provided by the attacker can cause libarchive to enter an infinite loop and use all available CPU time.

Workaround:

No workaround is available.

CVE-2006-5680 SA-06:24.libarchive 2006-11-08 2007-02-26
OpenSSL -- Multiple problems in crypto(3) openssl 0.9.7l_0 0.9.80.9.8d_0 FreeBSD 6.16.1_9 6.06.0_14 5.55.5_7 5.45.4_21 5.35.3_36 4.114.11_24

Problem Description:

Several problems have been found in OpenSSL:

In addition, many applications using OpenSSL do not perform any validation of the lengths of public keys being used.

Impact:

Servers which parse ASN1 data from untrusted sources may be vulnerable to a denial of service attack.

An attacker accessing a server which uses SSL version 2 may be able to execute arbitrary code with the privileges of that server.

A malicious SSL server can cause clients connecting using SSL version 2 to crash.

Applications which perform public key operations using untrusted keys may be vulnerable to a denial of service attack.

Workaround:

No workaround is available, but not all of the vulnerabilities mentioned affect all applications.

CVE-2006-2937 CVE-2006-2938 CVE-2006-2940 CVE-2006-3738 CVE-2006-4343 SA-06:23.openssl 2006-09-28 2007-02-26 2016-08-09
mozilla -- multiple vulnerabilities firefox 1.5.0.10,1 2.*,12.0.0.2,1 linux-firefox 1.5.0.10 lightning 0.3.1 seamonkey linux-seamonkey 1.0.8 1.11.1.1 thunderbird linux-thunderbird mozilla-thunderbird 1.5.0.10 linux-firefox-devel 3.0.a2007.04.18 linux-seamonkey-devel 1.5.a2007.04.18 firefox-ja linux-mozilla-devel linux-mozilla mozilla 0

The Mozilla Foundation reports of multiple security issues in Firefox, Seamonkey, and Thunderbird. Several of these issues can probably be used to run arbitrary code with the privilege of the user running the program.

  • MFSA 2007-08 onUnload + document.write() memory corruption
  • MFSA 2007-07 Embedded nulls in location.hostname confuse same-domain checks
  • MFSA 2007-06 Mozilla Network Security Services (NSS) SSLv2 buffer overflow
  • MFSA 2007-05 XSS and local file access by opening blocked popups
  • MFSA 2007-04 Spoofing using custom cursor and CSS3 hotspot
  • MFSA 2007-03 Information disclosure through cache collisions
  • MFSA 2007-02 Improvements to help protect against Cross-Site Scripting attacks
  • MFSA 2007-01 Crashes with evidence of memory corruption (rv:1.8.0.10/1.8.1.2)
CVE-2006-6077 CVE-2007-0008 CVE-2007-0009 CVE-2007-0775 CVE-2007-0776 CVE-2007-0777 CVE-2007-0778 CVE-2007-0779 CVE-2007-0780 CVE-2007-0800 CVE-2007-0981 CVE-2007-0995 CVE-2007-1092 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483 http://www.mozilla.org/security/announce/2007/mfsa2007-01.html http://www.mozilla.org/security/announce/2007/mfsa2007-02.html http://www.mozilla.org/security/announce/2007/mfsa2007-03.html http://www.mozilla.org/security/announce/2007/mfsa2007-04.html http://www.mozilla.org/security/announce/2007/mfsa2007-05.html http://www.mozilla.org/security/announce/2007/mfsa2007-06.html http://www.mozilla.org/security/announce/2007/mfsa2007-07.html http://www.mozilla.org/security/announce/2007/mfsa2007-08.html 2007-02-23 2007-02-24 2007-04-19
snort -- DCE/RPC preprocessor vulnerability snort 2.6.12.6.1.3

A IBM Internet Security Systems Protection Advisory reports:

Snort is vulnerable to a stack-based buffer overflow as a result of DCE/RPC reassembly. This vulnerability is in a dynamic-preprocessor enabled in the default configuration, and the configuration for this preprocessor allows for auto-recognition of SMB traffic to perform reassembly on. No checks are performed to see if the traffic is part of a valid TCP session, and multiple Write AndX requests can be chained in the same TCP segment. As a result, an attacker can exploit this overflow with a single TCP PDU sent across a network monitored by Snort or Sourcefire.

Snort users who cannot upgrade immediately are advised to disable the DCE/RPC preprocessor by removing the DCE/RPC preprocessor directives from snort.conf and restarting Snort. However, be advised that disabling the DCE/RPC preprocessor reduces detection capabilities for attacks in DCE/RPC traffic. After upgrading, customers should re-enable the DCE/RPC preprocessor.

196240 CVE-2006-5276 http://xforce.iss.net/xforce/xfdb/31275 http://www.snort.org/docs/advisory-2007-02-19.html 2007-02-19 2007-02-21
rar -- password prompt buffer overflow vulnerability rar 3.70.b1,1 unrar zh-unrar 3.70.b1,4

iDefense reports:

Remote exploitation of a stack based buffer overflow vulnerability in RARLabs Unrar may allow an attacker to execute arbitrary code with the privileges of the user opening the archive.

Unrar is prone to a stack based buffer overflow when processing specially crafted password protected archives.

If users are using the vulnerable command line based unrar, they still need to interact with the program in order to trigger the vulnerability. They must respond to the prompt asking for the password, after which the vulnerability will be triggered. They do not need to enter a correct password, but they must at least push the enter key.

22447 CVE-2007-0855 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472 http://www.rarsoft.com/rarnew.htm 2007-02-07 2007-02-17
php -- multiple vulnerabilities php5-imap php5-odbc php5-session php5-shmop php5-sqlite php5-wddx php5 5.2.1_2 php4-odbc php4-session php4-shmop php4-wddx php4 4.4.5 mod_php4-twig mod_php4 mod_php5 mod_php php4-cgi php4-cli php4-dtc php4-horde php4-nms php5-cgi php5-cli php5-dtc php5-horde php5-nms 44.4.5 55.2.1_2

Multiple vulnerabilities have been found in PHP, including: buffer overflows, stack overflows, format string, and information disclosure vulnerabilities.

The session extension contained safe_mode and open_basedir bypasses, but the FreeBSD Security Officer does not consider these real security vulnerabilities, since safe_mode and open_basedir are insecure by design and should not be relied upon.

CVE-2007-0905 CVE-2007-0906 CVE-2007-0907 CVE-2007-0908 CVE-2007-0909 CVE-2007-0910 CVE-2007-0988 http://secunia.com/advisories/24089/ http://www.php.net/releases/4_4_5.php http://www.php.net/releases/5_2_1.php 2007-02-09 2007-02-17 2013-04-01
joomla -- multiple remote vulnerabilities joomla 1.0.12

Secunia reports:

Some vulnerabilities have been reported in Joomla!, where some have unknown impacts and one can be exploited by malicious people to conduct cross-site scripting attacks.

  1. Input passed to an unspecified parameter is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
  2. The vulnerabilities are caused due to unspecified errors in Joomla!. The vendor describes them as "several low level security issues". No further information is currently available.
21810 CVE-2006-6832 CVE-2006-6833 CVE-2006-6834 http://secunia.com/advisories/23563/ 2006-12-29 2007-01-17
sircd -- remote reverse DNS buffer overflow sircd 0.4.0

Secunia reports:

A vulnerability in sircd can be exploited by a malicious person to compromise a vulnerable system. The vulnerability is caused by a boundary error in the code handling reverse DNS lookups, when a user connects to the service. If the FQDN (Fully Qualified Domain Name) returned is excessively long, the allocated buffer is overflowed making it possible to execute arbitrary code on the system with the privileges of the sircd daemon.

6924 http://secunia.com/advisories/8153 2003-02-24 2007-01-15
sircd -- remote operator privilege escalation vulnerability sircd 0

Secunia reports:

A vulnerability has been reported in sircd, which can be exploited by malicious users to gain operator privileges. The problem is that any user reportedly can set their usermode to operator. The vulnerability has been reported in versions 0.5.2 and 0.5.3. Other versions may also be affected.

9097 http://secunia.com/advisories/10274/ 2003-11-20 2007-01-15
cacti -- Multiple vulnerabilities cacti 0.8.6i.4

Secunia reports:

rgod has discovered four vulnerabilities in Cacti, which can be exploited by malicious people to bypass certain security restrictions, manipulate data and compromise vulnerable systems.

http://secunia.com/advisories/23528/ http://forums.cacti.net/about18846-0-asc-0.html 2006-12-28 2007-01-12
mplayer -- buffer overflow in the code for RealMedia RTSP streams. mplayer mplayer-esound mplayer-gtk mplayer-gtk2 mplayer-gtk-esound mplayer-gtk2-esound 0.99.10_1

A potential buffer overflow was found in the code used to handle RealMedia RTSP streams. When checking for matching asm rules, the code stores the results in a fixed-size array, but no boundary checks are performed. This may lead to a buffer overflow if the user is tricked into connecting to a malicious server. Since the attacker cannot write arbitrary data into the buffer, creating an exploit is very hard; but a DoS attack is easily made. A fix for this problem was committed to SVN on Sun Dec 31 13:27:53 2006 UTC as r21799. The fix involves three files: stream/realrtsp/asmrp.c, stream/realrtsp/asmrp.h and stream/realrtsp/real.c.

ports/107217 CVE-2006-6172 http://www.mplayerhq.hu/design7/news.html 2006-12-31 2007-01-08
fetchmail -- crashes when refusing a message bound for an MDA fetchmail 6.3.56.3.6

Matthias Andree reports:

When delivering messages to a message delivery agent by means of the "mda" option, fetchmail can crash (by passing a NULL pointer to ferror() and fflush()) when refusing a message. SMTP and LMTP delivery modes aren't affected.

CVE-2006-5974 http://www.fetchmail.info/fetchmail-SA-2006-03.txt 2007-01-04 2007-01-06
fetchmail -- TLS enforcement problem/MITM attack/password exposure fetchmail 6.3.6

Matthias Andree reports:

Fetchmail has had several longstanding password disclosure vulnerabilities.

  • sslcertck/sslfingerprint options should have implied "sslproto tls1" in order to enforce TLS negotiation, but did not.
  • Even with "sslproto tls1" in the config, fetches would go ahead in plain text if STLS/STARTTLS wasn't available (not advertised, or advertised but rejected).
  • POP3 fetches could completely ignore all TLS options whether available or not because it didn't reliably issue CAPA before checking for STLS support - but CAPA is a requisite for STLS. Whether or not CAPAbilities were probed, depended on the "auth" option. (Fetchmail only tried CAPA if the auth option was not set at all, was set to gssapi, kerberos, kerberos_v4, otp, or cram-md5.)
  • POP3 could fall back to using plain text passwords, even if strong authentication had been configured.
  • POP2 would not complain if strong authentication or TLS had been requested.
CVE-2006-5867 http://www.fetchmail.info/fetchmail-SA-2006-02.txt 2007-01-04 2007-01-06
opera -- multiple vulnerabilities opera opera-devel linux-opera 9.10

iDefense reports:

The vulnerability specifically exists due to Opera improperly processing a JPEG DHT marker. The DHT marker is used to define a Huffman Table which is used for decoding the image data. An invalid number of index bytes in the DHT marker will trigger a heap overflow with partially user controlled data.

Exploitation of this vulnerability would allow an attacker to execute arbitrary code on the affected host. The attacker would first need to construct a website containing the malicious image and trick the vulnerable user into visiting the site. This would trigger the vulnerability and allow the code to execute with the privileges of the local user.

A flaw exists within Opera's Javascript SVG implementation. When processing a createSVGTransformFromMatrix request Opera does not properly validate the type of object passed to the function. Passing an incorrect object to this function can result in it using a pointer that is user controlled when it attempts to make the virtual function call.

Exploitation of this vulnerability would allow an attacker to execute arbitrary code on the affected host. The attacker would first need to construct a website containing the malicious JavaScript and trick the vulnerable user into visiting the site. This would trigger the vulnerability and allow the code to execute with the privileges of the local user.

CVE-2007-0126 CVE-2007-0127 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458 http://www.opera.com/support/search/supsearch.dml?index=851 http://www.opera.com/support/search/supsearch.dml?index=852 2007-01-05 2007-01-05 2010-05-12
drupal -- multiple vulnerabilities drupal 4.74.7.5 4.6.11

The Drupal security team reports:

A few arguments passed via URLs are not properly sanitized before display. When an attacker is able to entice an administrator to follow a specially crafted link, arbitrary HTML and script code can be injected and executed in the victim's session. Such an attack may lead to administrator access if certain conditions are met.

The way page caching was implemented allows a denial of service attack. An attacker has to have the ability to post content on the site. He or she would then be able to poison the page cache, so that it returns cached 404 page not found errors for existing pages.

If the page cache is not enabled, your site is not vulnerable. The vulnerability only affects sites running on top of MySQL.

CVE-2007-0136 http://drupal.org/files/sa-2007-001/advisory.txt http://drupal.org/files/sa-2007-002/advisory.txt 2007-01-05 2007-01-05 2010-05-12
w3m -- format string vulnerability w3m w3m-img w3m-m17n w3m-m17n-img ja-w3m ja-w3m-img 0.5.1_6

An anonymous person reports:

w3m-0.5.1 crashes when using the -dump or -backend options to open a HTTPS URL with a SSL certificate where the CN contains "%n%n%n%n%n%n".

21735 CVE-2006-6772 http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439 http://secunia.com/advisories/23492/ 2006-12-10 2007-01-03