Skip to content

customize
National Cyber Alert System
Cyber Security Bulletin SB06-117archive

Summary of Security Items from April 20 through April 26, 2006

The US-CERT Cyber Security Bulletin provides a summary of new and updated vulnerabilities, exploits, trends, and malicious code that have recently been openly reported. Information in the Cyber Security Bulletin is a compilation of open source and US-CERT vulnerability information. As such, the Cyber Security Bulletin includes information published by sources outside of US-CERT and should not be considered the result of US-CERT analysis or as an official report of US-CERT. Although this information does reflect open source reports, it is not an official description and should be used for informational purposes only. The intention of the Cyber Security Bulletin is to serve as a comprehensive directory of pertinent vulnerability reports, providing brief summaries and additional sources for further investigation.

Vulnerabilities
Wireless Trends & Vulnerabilities
General Trends
Viruses/Trojans


Vulnerabilities

The tables below summarize vulnerabilities that have been reported by various open source organizations or presented in newsgroups and on web sites. Items in bold designate updates that have been made to past entries. Entries are grouped by the operating system on which the reported software operates, and vulnerabilities which affect both Windows and Unix/ Linux Operating Systems are included in the Multiple Operating Systems table. Note, entries in each table are not necessarily vulnerabilities in that operating system, but vulnerabilities in software which operate on some version of that operating system.

Entries may contain additional US-CERT sponsored information, including Common Vulnerabilities and Exposures (CVE) numbers, National Vulnerability Database (NVD) links, Common Vulnerability Scoring System (CVSS) values, Open Vulnerability and Assessment Language (OVAL) definitions, or links to US-CERT Vulnerability Notes. Metrics, values, and information included in the Cyber Security Bulletin which has been provided by other US-CERT sponsored programs, is prepared, managed, and contributed by those respective programs. CVSS values are managed and provided by the US-CERT/ NIST National Vulnerability Database. Links are also provided to patches and workarounds that have been provided by the product’s vendor.

The Risk levels are defined below:

High - Vulnerabilities will be labeled “High” severity if they have a CVSS base score of 7.0-10.0.

Medium - Vulnerabilities will be labeled “Medium” severity if they have a base CVSS score of 4.0-6.9.

Low - Vulnerabilities will be labeled “Low” severity if they have a CVSS base score of 0.0-3.9.

Note that scores provided prior to 11/9/2005 are approximated from only partially available CVSS metric data. Such scores are marked as "Approximated" within NVD. In particular, the following CVSS metrics are only partially available for these vulnerabilities and NVD assumes certain values based on an approximation algorithm: AccessComplexity, Authentication, ConfImpact of 'partial', IntegImpact of 'partial', AvailImpact of 'partial', and the impact biases.

Windows Operating Systems Only
Vendor & Software Name
Description

Common Name

CVSS
Resources
ampleShop 2.1

Multiple vulnerabilities have been reported in ampleShop that could let remote malicious users perform SQL injection.

No workaround or patch available at time of publishing.

There is no exploit code required.

ampleShop SQL Injection

CVE-2006-2038

Not Available Secunia, Advisory: SA19806, April 25, 2006
Bloggage

Multiple vulnerabilities have been reported in Bloggage, 'check_login.asp', that could let remote malicious users perform SQL injection.

No workaround or patch available at time of publishing.

There is no exploit code required.

Bloggage SQL Injection

CVE-2006-2010

7.0 Secunia, Advisory: SA19751, April 21, 2006

HP

StorageWorks Secure Path for Windows 4.0C-SP2

A vulnerability has been reported in StorageWorks Secure Path for Windows that could let remote malicious users cause a Denial of Service.

HP

Currently we are not aware of any exploits for this vulnerability.

HP StorageWorks Secure Path for Windows Denial Of Service
Not Available Security Tracker, Alert ID: 1015969, April 20, 2006
iOpus Secure Email Attachments

A vulnerability has been reported in iOpus Secure Email Attachments, insecure encryption, that could let remote malicious users disclose encrypted information.

No workaround or patch available at time of publishing.

There is no exploit code required.

iOpus Secure Email Attachments Information Disclosure

CVE-2006-2036

Not Available Security Tracker, Alert ID: 1015980, April 24, 2006

Ivan Zahariev

IZArc 3.5 beta 3

Multiple input validation vulnerabilities have been reported in IZArc that could let remote malicious users traverse directories.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

IZArc Directory Traversal

CVE-2006-2006

2.3 Secunia, Advisory: SA19791, April 24, 2006

Microsoft

Internet Explorer 6.0 SP2

A vulnerability has been reported in Internet Explorer, 'object' tag memory corruption, that could let remote malicious users execute arbitrary code.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Microsoft Internet Explorer Arbitrary Code Execution

CVE-2006-1992

8.0 Secunia, Advisory: SA19762, April 22, 2006

Microsoft

Outlook Express

A vulnerability has been reported in Outlook Express that could let remote malicious users execute arbitrary code.

Microsoft
V1.2: Revised due to issues discovered with the security update.

Currently we are not aware of any exploits for this vulnerability.

Microsoft Outlook Express Arbitrary Code Execution

CVE-2006-0014

5.6

Microsoft, Security Bulletin MS06-016, April 11, 2006

US-CERT VU#234812

Microsoft, Security Bulletin MS06-016 V1.2, April 26, 2006

Microsoft

Windows Explorer

A vulnerability has been reported in Windows Explorer, COM Object handling, that could let remote malicious users execute arbitrary code.

Microsoft
V2.0: Revised to inform customers that revised versions of the security update are available.

Currently we are not aware of any exploits for this vulnerability.

Microsoft Windows Explorer Arbitrary Code Execution

CVE-2006-0012

5.6

Microsoft, Security Bulletin MS06-015, April 11, 2006

US-CERT VU#641460

Microsoft, Security Bulletin MS06-015 V2.0, April 25, 2006

Pablo Software Solutions

Quick 'n Easy FTP Server 1.60 through 1.71, 3.0

A buffer overflow vulnerability has been reported in Quick 'n Easy FTP Server that could let remote malicious users execute arbitrary code.

No workaround or patch available at time of publishing.

A Proof of Concept exploit has been published.

Quick 'n Easy FTP Server Arbitrary Code Execution

CVE-2006-2027

Not Available Security Focus, ID: 17681, April 24, 2006
Skulltag 0.96f

A vulnerability has been reported in Skulltag that could let remote malicious users cause a Denial of Service or execute arbitrary code.

No workaround or patch available at time of publishing.

A Proof of Concept exploit, skulltagfs.zip, has been published.

Skulltag Denial of Service or Arbitrary Code Execution

CVE-2006-2012

2.3 Secunia, Advisory: SA19767, April 24, 2006

SolarWinds

TFTP Server 5.0.55, 5.0.60, 8.1

An input validation vulnerability has been reported in TFTP Server that could let remote malicious users traverse directories.

SolarWinds TFTP Server 8.2

There is no exploit code required.

SolarWinds TFTP Server Directory Traversal Vulnerability

CVE-2006-1951

2.3 Security Focus, ID: 17648, April 21, 2006

SpeedProject

Squeez 5.10 Build 4460, SpeedCommander 10.52 build 4450, SpeedCommander 11.01 build 4450

A buffer overflow vulnerability has been reported in SpeedProject products, ACE archive handling, that could let remote malicious users execute arbitrary code execution.

SpeedProject

There is no exploit code required.

SpeedProject Multiple Arbitrary Code Execution Not Available Secunia, Advisory: SA19473, April 26, 2006

Sybase

Pylon Anywhere 5.5.4, 6.2.1, 6.3.2, 6.4.2, 6.4.9

A vulnerability has been reported in Pylon Anywhere that could let remote malicious uses disclose information.

Sybase

Currently we are not aware of any exploits for this vulnerability.

Sybase Pylon Anywhere Information Disclosure

CVE-2006-1997

1.6 Security Focus, ID: 17677, April 24, 2006
Winny 2.0 b5.7, 2.0 b7.1

A heap overflow vulnerability has been reported in Winny that could let remote malicious users to execute arbitrary code.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

Winny Arbitrary Code Execution

CVE-2006-2007

7.0 Security Focus, ID: 17666, April 24, 2006
UNIX / Linux Operating Systems Only
Vendor & Software Name
Description

Common Name

CVSS
Resources

(LS)3

Fenice 1.10

Several vulnerabilities have been reported: a buffer overflow vulnerability was reported when parsing an RTSP URL received from a client due to a boundary error, which could let a remote malicious user execute arbitrary code; and a remote Denial of Service vulnerability was reported due to an input validation error when handling the Content-Length HTTP header received from a client.

No workaround or patch available at time of publishing.

Proof of Concept exploits and an exploit script, fenice.c, have been published.

Fenice Remote Buffer Overflow & Denial of Service

CVE-2006-2022
CVE-2006-2023

7.0
(CVE-2006-2022)

2.3
(CVE-2006-2023)

Security Focus, Bugtraq ID: 17678, April 24, 2006

4homepages

4images 1.7

A Cross-Site Scripting vulnerability has been reported in 'register.php' ' due to insufficient sanitization of the 'user_name' parameter before using, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

4homepages 4images Cross-Site Scripting

CVE-2006-2011

Secunia Advisory: SA19745, April 21, 2006

Apple

Safari 2.0-2.0.3, Mac OS X Server 10.4-10.4.6, 10.3-10.3.9, OS X 10.4-10.4.6, 10.3-10.3.9


Multiple vulnerabilities have been reported which could let a remote malicious user cause a Denial of Service or execute arbitrary code: a vulnerability was reported in the 'BOMStackPop()' function in the 'BOMArchiveHelper' when decompressing malformed ZIP archives, a vulnerability was reported in the 'KWQListlteratorImpl(),' 'drawText(),' and 'objc_msgSend_rtp()' functions in Safari when processing malformed HTML tags; a vulnerability was reported in the 'ReadBM()' function when processing malformed BMP images; a vulnerability was reported in the 'CFAllocatorAllocate()' function when processing malformed GIF images; and a vulnerability was reported in the '_cg_TIFFSetField()' and 'PredictorVSetField()' functions when processing malformed TIFF images.

No workaround or patch available at time of publishing.

Proof of Concept exploits have been reported.

7.0
(CVE-2006-1982)

4.7
(CVE-2006-1983)

2.3
(CVE-2006-1984)

1.6
(CVE-2006-1985)

7.0
(CVE-2006-1986)

7.0
(CVE-2006-1987)

2.3
(CVE-2006-1988)

 

Secunia Advisory: SA19686, April 21, 2006

Apple

Safari 2.0.3, 1.3.1

A remote Denial of Service vulnerability has been reported in the 'rowspan' attribute when processing 'td' HTML tags that contain overly large values.

No workaround or patch available at time of publishing.

An exploit script, safari-dos.txt, has been published.

Apple Safari Web Browser Rowspan Denial of Service

CVE-2006-2019

Security Tracker Alert ID: 1015982, April 24, 2006

CrossFire

CrossFire 1.8.0 & prior

A remote Denial of Service vulnerability has been reported in the 'oldsocketmode' option due to an error.

Updates available

Gentoo

There is no exploit code required.

CrossFire Remote Denial of Service

CVE-2006-1010

Secunia Advisory: SA19044, February 28, 2006

Gentoo Linux Security Advisory, GLSA 200604-11, April 22, 2006

Cyrus SASL

Cyrus SASL Library 2.x

A remote Denial of Service vulnerability has been reported due to an unspecified error during DIGEST-MD5 negotiation.

Update to version 2.1.21.

Gentoo

Ubuntu

Debian

Currently we are not aware of any exploits for this vulnerability.

Cyrus SASL Remote Digest-MD5 Denial of Service

CVE-2006-1721

Secunia Advisory: SA19618, April 11, 2006

Gentoo Linux Security Advisory, GLSA 200604-09, April 21, 2006

Ubuntu Security Notice, USN-272-1, April 24, 2006

Debian Security Advisory,
DSA-1042-1, April 25, 2006

Dan Littlejohn

Asterisk Recording Interface 0.7.15

A buffer overflow vulnerability has been reported in 'audio.php' due to a signedness error in 'format_jpeg.c' when processing an overly large JPEG image, which could let a remote malicious user execute arbitrary code.

Update available

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

Asterisk JPEG Image Handling Buffer Overflow

CVE-2006-1827

Secunia Advisory: SA19800, April 24, 2006

Dnsmasq

Dnsmasq 2.29

A remote Denial of Service vulnerability has been reported when a 'broadcast reply' request is submitted to the server.

Update available

There is no exploit code required.

DNSmasq Broadcast Reply Denial of Service

CVE-2006-2017

Security Focus, Bugtraq ID: 17662, April 24, 2006

fbida

fbida 2.03, 2.01

A vulnerability has been reported in the 'fbgs' script because temporary files are created insecurely when the 'TMPDIR' environment variable isn't defined, which could let a remote malicious user create/overwrite arbitrary files.

Gentoo

There is no exploit code required.

Fbida FBGS Insecure Temporary File Creation

CVE-2006-1695

Secunia Advisory: SA19559, April 10, 2006

Gentoo Linux Security Advisory, GLSA 200604-13, April 23, 2006

Free
RADIUS

FreeRADIUS 1.0-1.0.5

A vulnerability has been reported in the EAP-MSCHAPv2 state machine due to an error, which could let a malicious user bypass authentication and cause a Denial of Service.

Updates available

SuSE

RedHat

Gentoo

SGI

Currently we are not aware of any exploits for this vulnerability.

FreeRADIUS EAP-MSCHAPv2 Authentication Bypass

CVE-2006-1354

8.0

Security Focus, Bugtraq ID: 17171, March 21, 2006

SUSE Security Announcement, SUSE-SA:2006:019, March 28, 2006

RedHat Security Advisory, RHSA-2006:0271-11, April 4, 2006

Gentoo Linux Security Advisory, GLSA 200604-03, April 4, 2006

SGI Security Advisory, 20060404-01-U, April 24, 2006

IPsec-Tools

IPsec-Tools0.6-0.6.2, 0.5-0.5.2

A remote Denial of Service vulnerability has been reported due to a failure to handle exceptional conditions when in 'AGGRESSIVE' mode.

IpsecTools

Ubuntu

Gentoo

SUSE

Conectiva

Mandriva

Debian

RHSA-2006-0267

Vulnerability can be reproduced with the PROTOS IPSec Test Suite.

IPsec-Tools ISAKMP IKE Remote Denial of Service

CVE-2005-3732

Security Focus, Bugtraq ID: 15523, November 22, 2005

Ubuntu Security Notice, USN-221-1, December 01, 2005

Gentoo Linux Security Advisory, GLSA 200512-04, December 12, 2005

SUSE Security Announcement, SUSE-SA:2005:070, December 20, 2005

Conectiva Linux Announcement, CLSA-2006:1058, January 2, 2006

Mandriva Security Advisory, MDKSA-2006:020, January 25, 2006

Debian Security Advisory,
DSA-965-1, February 6, 2006

RedHat Security Advisory, RHSA-2006:0267-11, April 25, 2006

ISC

BIND 4.x.x, 8.x.x, 9.2.x, 9.3.x

A remote Denial of Service vulnerability has been reported due to a failure to properly handle malformed TSIG (Secret Key Transaction Authentication for DNS) replies.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for this vulnerability.

ISC BIND TSIG Zone Transfer Remote Denial of Service
Not Available Security Focus, Bugtraq ID: 17692, April 25, 2006

KRANKIKOM GmbH

ContentBoxX 0

A Cross-Site Scripting vulnerability has been reported in 'login.php' due to insufficient sanitization of the 'action' parameter, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

ContentBoxx Cross-Site Scripting

CVE-2006-1971

Secunia Advisory: SA19733, April 20, 2006

Multiple Vendors

Xpdf 3.0 pl2 & pl3, 3.0 1, 3.00, 2.0-2.03, 1.0 0, 1.0 0a, 0.90-0.93; RedHat Fedora Core4, Core3, Enterprise Linux WS 4, WS 3, WS 2.1 IA64, WS 2.1, ES 4, ES 3, ES 2.1 IA64, 2.1, Enterprise Linux AS 4, AS 3, 2.1 IA64, 2.1, Desktop 4.0, 3.0, Advanced Workstation for the Itanium Processor 2.1 IA64, 2.1; teTeX 2.0.1, 2.0; Poppler poppler 0.4.2;
KDE kpdf 0.5, KOffice 1.4.2 ; PDFTOHTML DFTOHTML 0.36


Multiple vulnerabilities have been reported: a heap-based buffer overflow vulnerability was reported in the 'DCTStream::read
BaselineSOF()' function in 'xpdf/Stream.cc' when copying data from a PDF file, which could let a remote malicious user potentially execute arbitrary code; a buffer overflow vulnerability was reported in the 'DCTStream::read
ProgressiveSOF()' function in 'xpdf/Stream.cc' when copying data from a PDF file, which could let a remote malicious user potentially execute arbitrary code; a buffer overflow vulnerability was reported in the 'StreamPredictor::
StreamPredictor()' function in 'xpdf/Stream.cc' when using the 'numComps' value to calculate the memory size, which could let a remote malicious user potentially execute arbitrary code; and a vulnerability was reported in the 'JPXStream:
:readCodestream()' function in 'xpdf/JPXStream.cc' when using the 'nXTiles' and 'nYTiles' values from a PDF file to copy data from the file into allocated memory, which could let a remote malicious user potentially execute arbitrary code.

Patches available

Fedora

RedHat

KDE

SUSE

Ubuntu

Gentoo

RedHat

RedHat

RedHat

Mandriva

Debian

Debian

Debian

Fedora

SuSE

RedHat

SGI

Debian

TurboLinux

Debian

Debian

Slackware

Slackware

Gentoo

SGI

SCO

SCOSA-2006.20

SCOSA-2006.21

Currently we are not aware of any exploits for these vulnerabilities.

3.9
(CVE-2005-3191)

7.0
(CVE-2005-3192)

3.9
(CVE-2005-3193)

iDefense Security Advisory, December 5, 2005

Fedora Update Notifications,
FEDORA-2005-1121 & 1122, December 6, 2005

RedHat Security Advisory, RHSA-2005:840-5, December 6, 2005

KDE Security Advisory, advisory-20051207-1, December 7, 2005

SUSE Security Summary Report, SUSE-SR:2005:029, December 9, 2005

Ubuntu Security Notice, USN-227-1, December 12, 2005

Gentoo Linux Security Advisory, GLSA 200512-08, December 16, 2005

RedHat Security Advisories, RHSA-2005:868-4, RHSA-2005:867-5 & RHSA-2005:878-4, December 20, 2005

Mandriva Linux Security Advisories MDKSA-2006:003-003-006, January 6, 2006

Debian Security Advisory,
DSA-936-1, January 11, 2006

Debian Security Advisory, DSA-937-1, January 12, 2006

Debian Security Advisory, DSA 938-1, January 12, 2006

Fedora Update Notifications,
FEDORA-2005-028 & 029, January 12, 2006

SUSE Security Summary Report, SUSE-SR:2006:001, January 13, 2006

RedHat Security Advisory, RHSA-2006:0160-14, January 19, 2006

SUSE Security Summary Report, SUSE-SR:2006:002, January 20, 2006

SGI Security Advisory, 20051201-01-U, January 20, 2006

Debian Security Advisory, DSA-950-1, January 23, 2006

Turbolinux Security Advisory, TLSA-2006-2, January 25, 2006

Debian Security Advisories,
DSA-961-1 & 962-1, February 1, 2006

Slackware Security Advisories, SSA:2006-045-04 & SSA:2006-045-09, February 14, 2006

Gentoo Linux Security Advisory, GLSA 200603-02, March 4, 2006

SGI Security Advisory, 20060201-01-U, March 14, 2006

SCO Security Advisory, SCOSA-2006.15, March 22, 2006

SCO Security Advisories, SCOSA-2006.20 & SCOSA-2006.21, April 18, 2006

Multiple Vendors

Debian Linux 3.1, sparc, s/390, ppc, mipsel, mips, m68k, ia-64, ia-32, hppa, arm, amd64, alpha; 3.0, sparc, s/390, ppc, mipsel, mips, m68k, ia-64, ia-32, hppa, arm, alpha; abc2ps 1.3.3

Multiple buffer overflow vulnerabilities have been reported when processing ABC music files due to various boundary errors, which could let a remote malicious user execute arbitrary code.

Debian

Currently we are not aware of any exploits for these vulnerabilities.

abc2ps ABC Music File Buffer Overflows

CVE-2006-1513

Security Focus, Bugtraq ID: 17689, April 25, 2006

Debian Security Advisory,
DSA-1041-1, April 25, 2006

Multiple Vendors

Debian Linux 3.1, sparc, s/390, ppc, mipsel, mips, m68k, ia-64, ia-32, hppa, arm, amd64, alpha; Blender 2.36

A vulnerability has been reported due to a failure to sanitize user-supplied input before using in a Python 'eval' statement, which could let a remote malicious user execute arbitrary python code.

Blender

Debian

Proof of Concept exploits have been published.

Blender BVF File Import Python Code Execution

CVE-2005-3302

Debian Security Advisory,
DSA-1039-1, April 24, 2006

Multiple Vendors

Linux Kernel 2.6.x

A Denial of Service vulnerability has been reported in the '_keyring_search_
one()' function when a key is added to a non-keyring key.

Update to version 2.6.16.3 or later.

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel
'__keyring_
search_one' Denial of Service

CVE-2006-1522

Secunia Advisory: SA19573, April 11, 2006

Fedora Update Notifications, FEDORA-2006-421,
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

Linux Kernel 2.6.x

A vulnerability has been reported because AMD K7/K8 CPUs only save/restore certain x87 registers in FXSAVE instructions when an exception is pending, which could let a remote malicious user obtain sensitive information.

Updates available

FreeBSD

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel x87 Register Information Leak

CVE-2006-1056

1.6

Secunia Advisory: SA19724, April 19, 2006

FreeBSD Security Advisory, FreeBSD-SA-06:14, April 19, 2006

Fedora Update Notifications, FEDORA-2006-421,
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

Linux kernel 2.6-2.6.16

A Denial of Service vulnerability has been reported when program control is returned using SYSRET on Intel EM64T CPUs.

Updates available

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel Intel EM64T SYSRET Denial of Service

CVE-2006-0744

Secunia Advisory: SA19639, April 17, 2006

Fedora Update Notifications, FEDORA-2006-421,
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

Linux kernel 2.6-2.6.16, 2.5-2.5.69, 2.4-2.4.33

A vulnerability has been reported regarding shared memory access, which could let a malicious user bypass security restrictions.

Patches available

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel Shared Memory Security Restriction Bypass

CVE-2006-1524

3.3

Security Focus, Bugtraq ID: 17587, April 18, 2006

Fedora Update Notifications, FEDORA-2006-421, &
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

Linux Kernel prior to 2.6.16.8

A Denial of Service vulnerability has been reported in the 'ip_route_input()' function when requesting a multi-cast IP address.

Updates available

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel IP_ROUTE_INPUT Denial of Service

CVE-2006-1525

2.3

Secunia Advisory: SA19709, April 19, 2006

Fedora Update Notifications, FEDORA-2006-421, &
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

RedHat Fedora Core5, Core4;
GNOME GDM 2.14.1;
Debian Linux 3.1, sparc, s/390, ppc, mipsel, mips, m68k, ia-64, ia-32, hppa, arm, amd64, alpha

A vulnerability has been reported in GDM gdm due to the way permissions on the '.ICEauthority' file are modified, which could let a remote malicious user obtain sensitive information.

This issue has been addressed in the latest CVS repository.

Vulnerability may be exploited with standard utilities and applications.

GNOME Foundation GDM .ICEauthority Improper File Permissions

CVE-2006-1057

Security Focus, Bugtraq ID: 17635, April 20, 2006

Multiple Vendors

RedHat Fedora Core5; Beagle prior to 0.2.5

A vulnerability has been reported due to the insecure construction of command line arguments that are passed to external helper applications, which could let a remote malicious user execute arbitrary code.

Updates available

Fedora

There is no exploit code required.

Beagle Helper Applications Arbitrary Code Execution

CVE-2006-1865

7.0 Secunia Advisory: SA19778, April 25, 2006

Multiple Vendors

Trustix Secure Linux 3.0, 2.2;
Linux kernel 2.6.12 up to versions before 2.6.17-rc1

A Denial of Service vulnerability has been reported in the 'fill_write_buffer()' function due to an out-of-bounds memory error.

Update to version 2.6.16.2.

Fedora

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel SYSFS Denial of Service

CVE-2006-1055

Secunia Advisory: SA19495, April 10, 2006

Fedora Update Notifications, FEDORA-2006-421,
FEDORA-2006-423, April 19 & 20, 2006

Multiple Vendors

Trustix Secure Linux 3.0;
Linux kernel 2.6-2.6.16

A vulnerability has been reported in the '__group_
complete_signal' function of the RCU signal-handling facility. The impact was not specified.

A patch is available from the vendor.

Currently we are not aware of any exploits for this vulnerability.

Linux Kernel RCU signal 'handling __group_
complete_signal' Function

CVE-2006-1523

Security Focus, Bugtraq ID: 17640, April 21, 2006

Multiple Vendors

XFree86 X11R6 4.3 .0,
4.1 .0; X.org X11R6 6.8.2;
RedHat Enterprise Linux WS 2.1, IA64, ES 2.1, IA64, AS 2.1, IA64, Advanced Workstation for the Itanium Processor 2.1, IA64; Gentoo Linux

A buffer overflow vulnerability has been reported in the pixmap processing code, which could let a malicious user execute arbitrary code and possibly obtain superuser privileges.

Gentoo

RHSA-2005-329.html

RHSA-2005-396.htm

Ubuntu

Mandriva

Fedora

Trustix

Debian

Sun

SUSE

Slackware

Sun

SUSE

Avaya

Sun 101926: Updated Contributing Factors, Relief/Workaround, and Resolution sections.

NetBSD

SGI

SCOSA-2006.22

Currently we are not aware of any exploits for this vulnerability.

XFree86 Pixmap Allocation Buffer Overflow

CVE-2005-2495

Gentoo Linux Security Advisory, GLSA 200509-07, September 12, 2005

RedHat Security Advisory, RHSA-2005:329-12 & RHSA-2005:396-9, September 12 & 13, 2005

Ubuntu Security Notice, USN-182-1, September 12, 2005

Mandriva Security Advisory, MDKSA-2005:164, September 13, 2005

US-CERT VU#102441

Fedora Update Notifications,
FEDORA-2005-893 & 894, September 16, 2005

Trustix Secure Linux Security Advisory, TSLSA-2005-0049, September 16, 2005

Debian Security Advisory DSA 816-1, September 19, 2005

Sun(sm) Alert Notification
Sun Alert ID: 101926, September 19, 2005

SUSE Security Announcement, SUSE-SA:2005:056, September 26, 2005

Slackware Security Advisory, SSA:2005-269-02, September 26, 2005

Sun(sm) Alert Notification
Sun Alert ID: 101953, October 3, 2005

SUSE Security Summary Report, SUSE-SR:2005:023, October 14, 2005

Avaya Security Advisory, ASA-2005-218, October 19, 2005

Sun(sm) Alert Notification
Sun Alert ID: 101926, Updated October 24, 2005

NetBSD Security Update, October 31, 2005

SGI Security Advisory, 20060403-01-U, April 11, 2006

SCO Security Advisory, SCOSA-2006.22, April 21, 2006

Multiple Vendors

xzgv Image Viewer 0.8 0.7, 0.6;
SuSE Linux Professional 10.0 OSS, 9.3 x86_64, 9.3, 9.2 x86_64, 9.2, 9.1 x86_64, 9.1, Linux Personal 10.0 OSS, 9.3 x86_64, 9.3, 9.2 x86_64, 9.2, 9.1 x86_64, 9.1

A buffer overflow vulnerability has been reported when processing JPEG files due to a boundary error, which could let a remote malicious user execute arbitrary code.

SuSE

Gentoo

dsa-1037

dsa-1038

Currently we are not aware of any exploits for this vulnerability.

XZGV Image Viewer Remote Buffer Overflow

CVE-2006-1060

SUSE Security Summary Report Announcement, SUSE-SR:2006:008, April 7, 2006

Gentoo Linux Security Advisory, GLSA 200604-10, April 21, 2006

Debian Securities, Advisory,DSA-1037-1,
DSA-1038-1, April 21 & 22, 2006

Multiple Vendors

Yukihiro Matsumoto Ruby 1.8-1.8.2, 1.6 - 1.6.8; Ubuntu Linux 5.10 powerpc, i386, amd64, 5.0.4 powerpc, i386, amd64, 4.1 ppc, ia64, ia32;
RedHat Fedora Core1-Core4,
Enterprise Linux WS 4, ES 4, Enterprise Linux Desktop version 4, Enterprise Linux AS 4

A remote Denial of Service vulnerability has been reported in the WEBrick HTTP server due to the use of blocking network operations.

Ruby

Ubuntu

Mandriva

Vulnerability may be with standard network utilities; however, a Proof of Concept exploit has been published.

Yukihiro Matsumoto Ruby XMLRPC Server Remote Denial of Service

CVE-2006-1931

Security Focus, Bugtraq ID: 17645, April 21, 2006

Ubuntu Security Notice, USN-273-1, April 24, 2006

Mandriva Security Advisory, MDKSA-2006:079, April 25, 2006

Net Clubs Pro

Net Clubs Pro 4.0

Cross-Site Scripting vulnerabilities have been reported in '/vchat/scripts/
sendim.cgi' due to insufficient sanitization of the 'onuser,' 'pass,' 'chatsys,' 'room,' 'username,' and 'to' parameters, in 'vchat/scripts/imessge.cgi' due to insufficient sanitization of the 'username' parameter, and in 'login.cgi' due to insufficient sanitization of the 'password' parameter, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit has been published.

Net Clubs Pro Multiple Cross-Site Scripting

CVE-2006-1965

Secunia Advisory: SA19651, April 20, 2006

pdnsd

pdnsd prior to 1.2.4

A remote Denial of Service vulnerability has been reported due to a failure to properly handle DNS queries.

Updates available

Currently we are not aware of any exploits for this vulnerability.

PDNSD DNS Query Remote Denial of Service
Not Available Secunia Advisory: SA19835, April 26, 2006

Sendmail Consortium

Sendmail prior to 8.13.6: Sun Cobalt RaQ 4, RaQ 550, RaQ XTR

A vulnerability has been reported due to a race condition caused by the improper handling of asynchronous signals, which could let a remote malicious user execute arbitrary code.

Updates available

RHSA-2006:0264-8

RHSA-2006:0265-9

Fedora

Gentoo

AIX

Sun

SuSE

FreeBSD

Slackware

OpenBSD

Avaya

Debian

HP

NetBSD

SGI

F-Secure

SGI

Sun

A Proof of Concept exploit script, sendtest.c, has been published.

Sendmail Asynchronous Signal Handling Remote Code Execution

CVE-2006-0058

8.0

Internet Security Systems Protection Advisory, March 22, 2006

Technical Cyber Security Alert TA06-081A

US-CERT VU#834865

RedHat Security Advisories, RHSA-2006:0264-8 & RHSA-2006:0265-9, March 22, 2006

Sun(sm) Alert Notification
Sun Alert ID: 102262, March 24, 2006

Gentoo Linux Security Advisory, GLSA 200603-21, March 22, 2006

SUSE Security Announcement, SUSE-SA:2006:017, March 22, 2006

FreeBSD Security Advisory, FreeBSD-SA-06:13, March 22, 2006

Slackware Security Advisory, SSA:2006-081-01, March 22, 2006

Avaya Security Advisory, ASA-2006-074, March 24, 2006

Debian Security Advisory,
DSA-1015-1, March 24, 2006

HP Security Bulletin,
HPSBUX02108, March 27, 2006

NetBSD Security Advisory, /NetBSD-SA2006-010, March 28, 2006

SGI Security Advisory, 20060302-01-P, March 22, 2006

F-Secure Security Bulletin, FSC-2006-2, March 28, 2006

SGI Security Advisory, 20060401-01-U, April 4, 2006

Sun(sm) Alert Notification
Sun Alert ID: 102324, April 25, 2006

Sun Microsystems Inc.

Solaris 10_x86, 10

A vulnerability has been reported in the 'getpwnam()' family of non-reentrant functions due to a failure of the PKCS#11 library to properly utilize non-reentrant functions, which could let a malicious user obtain elevated privileges.

Patches available

Currently we are not aware of any exploits for this vulnerability.

Sun Solaris PKCS#11 Library Elevated Privileges

CVE-2006-2064

Not Available Sun Alert ID: 102316, April 24, 2006

Tcpick

Tcpick 0.2.1

A remote Denial of Service vulnerability has been reported in 'write.c' due to a failure to handle malformed input.

No workaround or patch available at time of publishing.

Vulnerability may be exploited with readily available network utilities.

Tcpick Remote Denial of Service

CVE-2006-0048

Not Available Security Focus, Bugtraq ID: 17665, April 24, 2006

University of Washington

UW-imapd imap-2004c1

A buffer overflow has been reported in UW-imapd that could let remote malicious users cause a Denial of Service or execute arbitrary code.

Upgrade to version imap-2004g

Trustix

Debian

Gentoo

SUSE

Mandriva

Slackware

Conectiva

RedHat

RedHat

Fedora

Trustix

SGI

RHSA-2006-0267

Currently we are not aware of any exploits for this vulnerability.

UW-imapd Denial of Service and Arbitrary Code Execution

CVE-2005-2933

7.0

Secunia, Advisory: SA17062, October 5, 2005

Trustix Secure Linux Security Advisory, TSLSA-2005-0055, October 7, 2005

Debian Security Advisory, DSA 861-1, October 11, 2005

Gentoo Linux Security Advisory, GLSA 200510-10, October 11, 2005

US-CERT VU#933601

SUSE Security Summary Report, SUSE-SR:2005:023, October 14, 2005

Mandriva Linux Security Update Advisory, MDKSA-2005:189 & 194, October 21 & 26, 2005

Slackware Security Advisory, SSA:2005-310-06, November 7, 2005

Conectiva Linux Announcement, CLSA-2005:1046, November 21, 2005

RedHat Security Advisory, RHSA-2005:848-6 & 850-5, December 6, 2005

Fedora Update Notifications,
FEDORA-2005-1112 & 1115, December 8, 2005

Trustix Secure Linux Security Advisory, TSLSA-2005-0074, December 23, 2005

SGI Security Advisory, 20051201-01-U, January 20, 2006

RedHat Security Advisory, RHSA-2006:0267-11, April 25, 2006

UPDI Network Enterprise

@1 Event Publisher

Several vulnerabilities have been reported: an HTML injection vulnerability was reported in 'event-publisher_
admin.htm' and 'eventpublisher_
usersubmit.htm' due to insufficient sanitization of the 'Event,' 'Description,' 'Time,' 'Website,' and 'Public Remarks' fields before using, which could let a remote malicious user execute arbitrary HTML and script code; and a vulnerability was reported due to insufficient restriction of 'eventpublisher.txt' which could lead to the disclosure of sensitive information.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client.

@1 Event Publisher HTML Injection & Information Disclosure

CVE-2006-1436
CVE-2006-1437

2.3
(CVE-2006-1436)

2.3
(CVE-2006-1437)

Secunia Advisory: SA19727, April 21, 2006

UPDI Network Enterprise

@1 Table Publisher 2006.3.23

An HTML injection vulnerability has been reported due to insufficient sanitization of the 'Title of table' field when adding a new table, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client.

@1 Table Publisher HTML Injection

CVE-2006-1795

Secunia Advisory: SA19723, April 21, 2006
Multiple Operating Systems - Windows/UNIX/Linux/Other
Vendor & Software Name
Description

Common Name

CVSS
Resources

3Com

Baseline Switch 2848-SFP Plus 1.0.2

A remote Denial of Service vulnerability has been reported due to an error when handling DHCP packets.

Update available

There is no exploit code required.

3Com Baseline Switch 2848-SFP Plus Remote Denial of Service

CVE-2006-2054

Not Available Secunia Advisory: SA19756, April 25, 2006

AspSitem

AspSitem 1.83 & prior

An SQL injection vulnerability has been reported in 'haberler.asp' due to insufficient sanitization of the 'id' parameter before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code.

Update available

Vulnerability can be exploited through a web client; however, an exploit script, aspsitem.pl, has been published.

AspSitem SQL Injection

CVE-2006-1964

Secunia Advisory: SA19693, April 20, 2006

built2go

built2go Movie Review 2B & prior

A file include vulnerability has been reported in 'Movie_CLS.PHP3' due to insufficient sanitization of the 'full_path' parameter, which could let a remote malicious user execute arbitrary PHP code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit script, built2go.rfi.txt, has been published.

Built2go Movie Review Remote File Include

CVE-2006-2008

Secunia Advisory: SA19749, April 24, 2006

Cartweaver

Cartweaver 2.16.11

Several vulnerabilities have been reported: SQL injection vulnerabilities were reported in 'Results.cfm' due to insufficient sanitization of the 'category' parameter and in 'Details.cfm' due to insufficient sanitization of the 'ProdID' parameter, which could let a remote malicious user execute arbitrary SQL code; and it is also possible to reveal installation path by passing invalid parameter values to 'Results.cfm,' 'Details.cfm,' and 'Results.cfm.'

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for these vulnerabilities.

Cartweaver SQL Injection & Path Disclosure

CVE-2006-2046
CVE-2006-2047

Not Available Secunia Advisory: SA19812, April 26, 2006

Cisco

Linksys RT31P2 VoIP Router 0

Remote Denials of Service vulnerabilities have been reported when processing malformed SIP (Session Initiation Protocol) messages due to various errors.

No workaround or patch available at time of publishing.

Currently we are not aware of any exploits for these vulnerabilities.

Linksys RT31P2 Remote Denials of Service

CVE-2006-1973

US-CERT VU#621566

CoreNews

CoreNews 2.0.1

Multiple input validation vulnerabilities have been reported including a remote file include vulnerability and an SQL injection vulnerability due to insufficient sanitization of user-supplied input, which could lead to the execution of arbitrary SQL and PHP code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, Proof of Concept exploit scripts, 17655-exploit.pl and 17655.html, have been published.

CoreNews Multiple Input Validation

CVE-2006-2032
CVE-2006-2033

Not Available Security Focus, Bugtraq ID: 17655, April 22, 2006

David Zhong

logMethods 0.9

A Cross-Site Scripting vulnerability has been reported in 'A2Z.JSP' due to insufficient sanitization of the 'kwd' parameter before returning to the user, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client.

LogMethods Cross-Site Scripting

CVE-2006-2000

Security Focus, Bugtraq ID: 17675, April 24, 2006

DC Scripts

DCForum 3.0

Multiple input validation vulnerabilities have been reported in 'DCBoard.cgi' include Cross-Site Scripting and SQL injection due to insufficient sanitization of user-supplied input, which could let a remote malicious user execute arbitrary HTML, script code, and SQL code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit script, dcforumlite-3.0-sql-xss.txt, has been published.

DCForum Multiple Input Validation

CVE-2006-2049
CVE-2006-2050

Not Available Security Focus, Bugtraq ID: 17697, April 25, 2006

DeleGate

DeleGate 8.11.5 & prior (stable), 9.0.5 & prior (development)

A remote Denial of Service vulnerability has been reported due to a failure to properly handle malformed DNS query packets.

Updates available

Currently we are not aware of any exploits for this vulnerability.

DeleGate DNS Query Handling Remote Denial of Service
Not Available Secunia Advisory: SA19750, April 26, 2006

dForum

dForum 1.5 & prior

File include vulnerabilities have been reported due to insufficient verification of the 'DFORUM_PATH' parameter in various scripts, which could let a remote malicious user execute arbitrary PHP files.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit has been published.

dForum Multiple Remote File Include

CVE-2006-1994

Security Focus, Bugtraq ID: 17650, April 22, 2006
DIA

DIA 0.87-0.94

Multiple remote buffer overflow vulnerabilities have been reported due to a failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers, which could let a remote malicious user execute arbitrary code.

The vendor has released version 0.95-pre6, along with a patch for 0.94 to address these issues.

Mandriva

Ubuntu

Fedora

Debian

Gentoo

Currently we are not aware of any exploits for these vulnerabilities.

DIA XFIG File Import Multiple Remote Buffer Overflows

CVE-2006-1550

5.6

Security Focus, Bugtraq ID: 17310, March 29, 2006

Mandriva Security Advisory, MDKSA-2006:062, April 3, 2006

Debian Security Advisory,
DSA-1025-1, April 6, 2006

Gentoo Linux Security Advisory, GLSA 200604-14, April 23, 2006

DUware

DUportal Pro 3.4

An SQL injection vulnerability has been reported in 'cat.asp' due to insufficient sanitization of user-supplied input before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit script, DUportalPro-cat.asp-sql.txt, has been published.

DUWare DUPortal Pro SQL Injection
Not Available Security Focus, Bugtraq ID: 17702, April 26, 2006

Help Center Live

Help Center Live 2.0, 1.2- 1.2.8, 1.0

Multiple SQL injection vulnerabilities have been reported in the 'osTicket' module due to insufficient sanitization of unspecified parameters before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code.

Updates available

Vulnerabilities can be exploited through a web client.

Help Center Live OSTicket Module Multiple SQL Injection

CVE-2006-2039

Not Available Secunia Advisory: SA19776, April 24, 2006

Instant Photo Gallery

Instant Photo Gallery 1.0

A Cross-Site Scripting and SQL injection vulnerability has been reported in 'portfolio_photo_
popup.php' due to insufficient sanitization of the 'id' parameter, which could let a remote malicious user execute arbitrary HTML, script code, and SQL code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit script, instantphotogallery-xss.txt, has been published.

Instant Photo Gallery Cross-Site Scripting & SQL Injection

CVE-2006-2052

Not Available Secunia Advisory: SA19813, April 26, 2006

Invision Power Services

Invision Board 2.0-2.1.5

Multiple vulnerabilities have been reported: a vulnerability was reported in the 'search.php' due to insufficient sanitization of the 'lastdate' parameter before using in a 'preg_replace()' call, which could let a remote malicious user execute arbitrary PHP code; an SQL injection vulnerability was reported in 'index.php' due to insufficient sanitization of the 'ck' parameter before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code; a vulnerability was reported in 'admin.php' because it is possible for administrators to include arbitrary PHP scripts via the 'name' parameter, which could lead to the execution of arbitrary PHP code; and a vulnerability was reported because it is possible to upload a malicious JPEG image with a GIF header, which could let a remote malicious user execute arbitrary HTML and script code.

Patches available

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit script, invisionpowerboard-
2.1.5-sql-inj.txt, has been published.

Invision Power Board Multiple Vulnerabilities

CVE-2006-2059
CVE-2006-2060
CVE-2006-2061

Not Available Secunia Advisory: SA19830, April 26, 2006

IP3 Networks

NA75 4.0.34 firmware

Multiple vulnerabilities have been reported: an SQL injection vulnerability was reported due to insufficient sanitization of unspecified input passed to the web interface before using in an SQL query, which could let a remote malicious user execute arbitrary SQL code; a vulnerability was reported due to input validation errors in the command line interface, which could let a remote malicious user inject arbitrary shell commands; a vulnerability was reported because the shadow password file has world-readable permissions, which could let a remote malicious user obtain sensitive information; and a vulnerability was reported because the database file is stored with world-readable and world-writable permissions.

Patch available

Currently we are not aware of any exploits for these vulnerabilities.

IP3 Networks NA75 Multiple Vulnerabilities

CVE-2006-2043
CVE-2006-2044
CVE-2006-2045

Not Available Secunia Advisory: SA19818. April 26, 2006

I-RATER

I-RATER Platinum 0

A file include vulnerability has been reported in 'common.php' due to insufficient verification of the 'include_path' parameter, which could let a remote malicious user execute arbitrary PHP code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

I-RATER Platinum Remote File Include

CVE-2006-1929

Security Focus, Bugtraq ID: 17623, April 20, 2006

Juniper Networks

JUNOSe 5.x, 6.x, 7.x

A remote Denial of Service vulnerability has been reported due to a failure to properly handle DNS datagrams.

The vendor has released updated versions of the affected software to address this issue.

Currently we are not aware of any exploits for this vulnerability.

Juniper JUNOSe DNS Client Remote Denial of Service
Not Available Security Focus, Bugtraq ID: 17693, April 25, 2006

kcscripts.com

Portal Pack 6.0

Cross-Site Scripting vulnerabilities have been reported in 'calendar/Visitor.cgi' and 'news/NsVisitor.cgi' due to insufficient sanitization of the 'sort_order' parameter, in 'search/search.cgi' due to insufficient sanitization of the 'q' parameter, and in 'classifieds/viewcat.cgi' due to insufficient sanitization of the 'cat_id' parameter, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, Proof of Concept exploit scripts have been published.

Portal Pack Multiple Cross-Site Scripting

CVE-2006-1967 CVE-2006-1968 CVE-2006-1969
CVE-2006-1970

1.9
(CVE-2006-1967)

4.7
(CVE-2006-1968)

1.9
(CVE-2006-1969)

2.3
(CVE-2006-1970)

Secunia Advisory: SA19695, April 20, 2006

Manic Web

MWGuest 2.1

An HTML injection vulnerability has been reported in 'MWguest.PHP' due to insufficient sanitization of user-supplied input, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

Manic Web MWGuest HTML Injection

CVE-2006-1979

Security Focus, Bugtraq ID: 17630, April 20, 2006

Michael Romedahl

RI Blog 1.1

SQL injection vulnerabilities have been reported due to insufficient sanitization of the 'Username' and 'Password' fields during login, which could let a remote malicious user execute arbitrary SQL code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client.

RI Blog Multiple SQL Injection

CVE-2006-2004

Security Focus, Bugtraq ID: 17654, April 22, 2006

MiniNuke

MiniNuke CMS 1.8.2 & prior

An SQL injection vulnerability has been reported in 'pages.asp' due to insufficient sanitization of user-supplied input, which could let a remote malicious user execute arbitrary SQL code.

No workaround or patch available at time of publishing.

Vulnerability can be exploited through a web client; however, a Proof of Concept exploit has been published.

Mini-NUKE SQL Injection

CVE-2006-0870

Security Focus, Bugtraq ID: 17636, April 20, 2006

MKPortal

MKPortal 1.1 RC1

Several vulnerabilities have been reported: an SQL injection vulnerability was reported in the 'include/VB/vb_board_
functions.php' script due to insufficient validation of several parameters, which could let a remote malicious user execute arbitrary SQL code; and a Cross-Site Scripting vulnerability was reported in the 'includes/pm_popup.php' script due to insufficient filtering of HTML code from user-supplied input before displaying, which could let a remote malicious user execute arbitrary HTML and script code.

No workaround or patch available at time of publishing.

Vulnerabilities can be exploited through a web client; however, a Proof of Concept exploit has been published.

MKPortal Cross-Site Scripting & SQL Injection

CVE-2006-2066
CVE-2006-2067

Not Available Security Tracker Alert ID: 1015977, April 22, 2006

Mozilla. org

Mozilla Browser prior to 1.7.13, Seamonkey prior to 1.0.1, Thunderbird prior to 1.0.8, 1.5 - 1.5.0.1, Firefox, 1.5 - 1.5.0.1

A vulnerability has been reported in the 'crypto.generate
CRMFRequest' method, which could let a remote malicious user execute arbitrary code.

Updates available

Fedora

RHSA-2006-0328.html

RHSA-2006-0329.html

Ubuntu

SuSE

Gentoo

MDKSA-2006:075

Slackware

SGI

RHSA-2006-0330

MDKSA-2006:078

SUSE-SA:2006:022

Currently we are not aware of any exploits for this vulnerability.

Mozilla Browser Suite 'crypto.generate CRMFRequest' Arbitrary Code Execution

CVE-2006-1728

Security Tracker Alert IDs: 1015922, 1015923, 1015924, 015925, April 14, 2006

RedHat Security Advisories, RHSA-2006-0328 & 0329, April 14 & 18, 2006

Technical Cyber Security Alert TA06-107A

US-CERT VU#932734

Ubuntu Security Notice, USN-271-1 April 19, 2006

SuSE Security Announcement, SUSE-SA:2006:021, April 20, 2006

Gentoo Linux Security Advisory, GLSA 200604-12, April 23, 2006

Mandriva Security Advisory, MDKSA-2006:075, April 24, 2006

Slackware Security Advisory, SSA:2006-114-01, April 24, 2006

SGI Security Advisory, 20060404-01-U, April 24, 2006

RedHat Security Advisory, RHSA-2006:0330-15, April 25, 2006

Mandriva Security Advisory, MDKSA-2006:078, April 25, 2006

SuSE Security Announcement, SUSE-SA:2006:022, April 25, 2006

Mozilla.oeg

Thunderbird prior to 1.0.8, 1.5 - 1.5.0.1; Seamonkey prior to 1.0.1; Mozilla browser prior to 1.7.13; Firefox prior to 1.0.8, 1.5 - 1.5.0.1

A integer overflow vulnerability has been reported because a remote malicious user can create an HTML based email that contains a specially crafted CSS letter-spacing property value, which could lead to the execution of arbitrary code.

Updates available

RHSA-2006-0328.html

RHSA-2006-0329.html

Ubuntu

SuSE

Gentoo

MDKSA-2006:075

Slackware

SGI

RHSA-2006-0330

MDKSA-2006:078

SUSE-SA:2006:022

Currently we are not aware of any exploits for this vulnerability.

Mozilla Integer Overflow

CVE-2006-1730

Security Tracker Alert IDs: 1015915, 1015916, 1015917, 1015918, April 14, 2005

RedHat Security Advisories, RHSA-2006-0328 & 0329, April 14 & 18, 2006

Technical Cyber Security Alert TA06-107A

US-CERT VU#179014

Ubuntu Security Notice, USN-271-1 April 19, 2006

SuSE Security Announcement, SUSE-SA:2006:021, April 20, 2006

Gentoo Linux Security Advisory, GLSA 200604-12, April 23, 2006

Mandriva Security Advisory, MDKSA-2006:075, April 24, 2006

Slackware Security Advisory, SSA:2006-114-01, April 24, 2006

SGI Security Advisory, 20060404-01-U, April 24, 2006

RedHat Security Advisory, RHSA-2006:0330-15, April 25, 2006

Mandriva Security Advisory, MDKSA-2006:078, April 25, 2006

SuSE Security Announcement, SUSE-SA:2006:022, April 25, 2006

Mozilla.org

Firefox 0.x, 1.x

Multiple vulnerabilities have been reported: a vulnerability was reported due to an error because untrusted events generated by web content are delivered to the browser user interface; a vulnerability was reported because scripts in XBL controls can be executed even when JavaScript has been disabled; a vulnerability was reported because remote malicious users can execute arbitrary code by tricking the user into using the 'Set As Wallpaper' context menu on an image URL that is really a javascript; a vulnerability was reported in the 'Install
Trigger.install()' function due to an error in the callback function, which could let a remote malicious user execute arbitrary code; a vulnerability was reported due to an error when handling 'data:' URL that originates from the sidebar, which could let a remote malicious user execute arbitrary code; an input validation vulnerability was reported in the 'InstallVersion.compareTo()' function when handling unexpected JavaScript objects, which could let a remote malicious user execute arbitrary code; a vulnerability was reported because it is possible for a remote malicious user to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL; a vulnerability was reported due to an error when handling DOM node names with different namespaces, which could let a remote malicious user execute arbitrary code; and a vulnerability was reported due to insecure cloning of base objects, which could let a remote malicious user execute arbitrary code.

Updates available

Gentoo

Mandriva

Fedora

RedHat

Slackware

Ubuntu

Ubuntu

Ubuntu

SUSE

Debian

Debian

SGI

Gentoo

Slackware

Debian

Debian

Fedora

HP

HP

Ubuntu

Sun

SUSE

Mandriva

SUSE-SA:2006:022

Exploits have been published.

Firefox Multiple Vulnerabilities

CVE-2005-2260
CVE-2005-2261
CVE-2005-2262
CVE-2005-2263
CVE-2005-2264
CVE-2005-2265
CVE-2005-2267
CVE-2005-2269
CVE-2005-2270

8.0
(CVE-2005-2260)