1 <vuln vid="cf484358-b5d6-11dc-8de0-001c2514716c"> 2 <topic>dovecot -- Specific LDAP + auth cache configuration may mix up user logins</topic> 3 <affects> 4 <package> 5 <name>dovecot</name> 6 <range><lt>1.0.10</lt></range> 7 </package> 8 </affects> 9 <description> 10 <body xmlns="http://www.w3.org/1999/xhtml"> 11 <p>Dovecot reports:</p> 12 <blockquote cite="http://www.dovecot.org/list/dovecot-news/2007-December/000057.html"> 13 <p>If two users with the same password and same pass_filter 14 variables log in within auth_cache_ttl seconds (1h by default), 15 the second user may get logged in with the first user's cached 16 pass_attrs. For example if pass_attrs contained the user's 17 home/mail directory, this would mean that the second user will 18 be accessing the first user's mails.</p> 19 </blockquote> 20 </body> 21 </description> 22 <references> 23 <url>http://www.dovecot.org/list/dovecot-news/2007-December/000057.html</url> 24 </references> 25 <dates> 26 <discovery>2007-12-21</discovery> 27 <entry>2007-12-29</entry> 28 </dates> 29 </vuln> 30 31 <vuln vid="4aab7bcd-b294-11dc-a6f0-00a0cce0781e"> 32 <topic>gallery2 -- multiple vulnerabilities</topic> 33 <affects> 34 <package> 35 <name>gallery2</name> 36 <range><lt>2.2.4</lt></range> 37 </package> 38 </affects> 39 <description> 40 <body xmlns="http://www.w3.org/1999/xhtml"> 41 <p>The Gallery team reports:</p> 42 <blockquote cite="http://gallery.menalto.com/gallery_2.2.4_released"> 43 <p>Gallery 2.2.4 addresses the following security 44 vulnerabilities:</p> 45 <ul> 46 <li>Publish XP module - Fixed unauthorized album creation 47 and file uploads.</li> 48 <li>URL rewrite module - Fixed local file inclusion 49 vulnerability in unsecured admin controller and 50 information disclosure in hotlink protection.</li> 51 <li>Core / add-item modules - Fixed Cross Site Scripting 52 (XSS) vulnerabilities through malicious file names.</li> 53 <li>Installation (Gallery application) - Update 54 web-accessibility protection of the storage folder for 55 Apache 2.2.</li> 56 <li>Core (Gallery application) / MIME module - Fixed 57 vulnerability in checks for disallowed file extensions 58 in file uploads.</li> 59 <li>Gallery Remote module - Added missing permissions 60 checks for some GR commands.</li> 61 <li>WebDAV module - Fixed Cross Site Scripting (XSS) 62 vulnerability through HTTP PROPPATCH.</li> 63 <li>WebDAV module - Fixed information (item data) 64 disclosure in a WebDAV view.</li> 65 <li>Comment module - Fixed information (item data) 66 disclosure in comment views.</li> 67 <li>Core module (Gallery application) - Improved 68 resilience against item information disclosure 69 attacks.</li> 70 <li>Slideshow module - Fixed information (item data) 71 disclosure in the slideshow.</li> 72 <li>Print modules - Fixed information (item data) 73 disclosure in several print modules.</li> 74 <li>Core / print modules - Fixed arbitrary URL redirection 75 (phishing attacks) in the core module and several print 76 modules.</li> 77 <li>WebCam module - Fixed proxied request weakness.</li> 78 </ul> 79 </blockquote> 80 </body> 81 </description> 82 <references> 83 <cvename>CVE-2007-6685</cvename> 84 <cvename>CVE-2007-6686</cvename> 85 <cvename>CVE-2007-6687</cvename> 86 <cvename>CVE-2007-6689</cvename> 87 <cvename>CVE-2007-6690</cvename> 88 <cvename>CVE-2007-6692</cvename> 89 <url>http://gallery.menalto.com/gallery_2.2.4_released</url> 90 </references> 91 <dates> 92 <discovery>2007-12-24</discovery> 93 <entry>2007-12-25</entry> 94 <modified>2010-05-12</modified> 95 </dates> 96 </vuln> 97 98 <vuln vid="299e3f81-aee7-11dc-b781-0016179b2dd5"> 99 <topic>e2fsprogs -- heap buffer overflow</topic> 100 <affects> 101 <package> 102 <name>e2fsprogs</name> 103 <range><lt>1.40.3</lt></range> 104 </package> 105 </affects> 106 <description> 107 <body xmlns="http://www.w3.org/1999/xhtml"> 108 <p>Theodore Y. Ts'o reports:</p> 109 <blockquote cite="http://sourceforge.net/project/shownotes.php?group_id=2406&release_id=560230"> 110 <p>Fix a potential security vulnerability where an untrusted 111 filesystem can be corrupted in such a way that a program using 112 libext2fs will allocate a buffer which is far too small. This 113 can lead to either a crash or potentially a heap-based buffer 114 overflow crash. No known exploits exist, but main concern is 115 where an untrusted user who possesses privileged access in a 116 guest Xen environment could corrupt a filesystem which is then 117 accessed by thus allowing the untrusted user to gain privileged 118 access in the host OS. Thanks to the McAfee AVERT Research group 119 for reporting this issue.</p> 120 </blockquote> 121 </body> 122 </description> 123 <references> 124 <bid>26772</bid> 125 <cvename>CVE-2007-5497</cvename> 126 <url>http://secunia.com/advisories/27889/</url> 127 <url>http://sourceforge.net/project/shownotes.php?group_id=2406&release_id=560230</url> 128 </references> 129 <dates> 130 <discovery>2007-12-07</discovery> 131 <entry>2007-12-20</entry> 132 </dates> 133 </vuln> 134 135 <vuln vid="8a835235-ae84-11dc-a5f9-001a4d49522b"> 136 <topic>wireshark -- multiple vulnerabilities</topic> 137 <affects> 138 <package> 139 <name>wireshark</name> 140 <name>wireshark-lite</name> 141 <name>ethereal</name> 142 <name>ethereal-lite</name> 143 <name>tethereal</name> 144 <name>tethereal-lite</name> 145 <range><ge>0.8.16</ge><lt>0.99.7</lt></range> 146 </package> 147 </affects> 148 <description> 149 <body xmlns="http://www.w3.org/1999/xhtml"> 150 <p>The Wireshark team reports of multiple vulnerabilities:</p> 151 <blockquote cite="http://www.wireshark.org/security/wnpa-sec-2007-03.html"> 152 <ul> 153 <li>Wireshark could crash when reading an MP3 file.</li> 154 <li>Beyond Security discovered that Wireshark could loop 155 excessively while reading a malformed DNP packet.</li> 156 <li>Stefan Esser discovered a buffer overflow in the SSL 157 dissector.</li> 158 <li>The ANSI MAP dissector could be susceptible to a 159 buffer overflow on some platforms.</li> 160 <li>The Firebird/Interbase dissector could go into an 161 infinite loop or crash.</li> 162 <li>The NCP dissector could cause a crash.</li> 163 <li>The HTTP dissector could crash on some systems while 164 decoding chunked messages.</li> 165 <li>The MEGACO dissector could enter a large loop and 166 consume system resources.</li> 167 <li>The DCP ETSI dissector could enter a large loop and 168 consume system resources.</li> 169 <li>Fabiodds discovered a buffer overflow in the iSeries 170 (OS/400) Communication trace file parser.</li> 171 <li>The PPP dissector could overflow a buffer.</li> 172 <li>The Bluetooth SDP dissector could go into an infinite 173 loop.</li> 174 <li>A malformed RPC Portmap packet could cause a 175 crash.</li> 176 <li>The IPv6 dissector could loop excessively.</li> 177 <li>The USB dissector could loop excessively or crash.</li> 178 <li>The SMB dissector could crash.</li> 179 <li>The RPL dissector could go into an infinite loop.</li> 180 <li>The WiMAX dissector could crash due to unaligned 181 access on some platforms.</li> 182 <li>The CIP dissector could attempt to allocate a huge 183 amount of memory and crash.</li> 184 </ul> 185 186 <h2>Impact</h2> 187 188 <p>It may be possible to make Wireshark or Ethereal crash or 189 use up available memory by injecting a purposefully 190 malformed packet onto the wire or by convincing someone to 191 read a malformed packet trace file.</p> 192 </blockquote> 193 </body> 194 </description> 195 <references> 196 <cvename>CVE-2007-6112</cvename> 197 <cvename>CVE-2007-6113</cvename> 198 <cvename>CVE-2007-6114</cvename> 199 <cvename>CVE-2007-6115</cvename> 200 <cvename>CVE-2007-6117</cvename> 201 <cvename>CVE-2007-6118</cvename> 202 <cvename>CVE-2007-6120</cvename> 203 <cvename>CVE-2007-6121</cvename> 204 <cvename>CVE-2007-6438</cvename> 205 <cvename>CVE-2007-6439</cvename> 206 <cvename>CVE-2007-6441</cvename> 207 <cvename>CVE-2007-6450</cvename> 208 <cvename>CVE-2007-6451</cvename> 209 <url>http://www.wireshark.org/security/wnpa-sec-2007-03.html</url> 210 </references> 211 <dates> 212 <discovery>2007-12-19</discovery> 213 <entry>2007-12-19</entry> 214 <modified>2007-12-22</modified> 215 </dates> 216 </vuln> 217 218 <vuln vid="31b045e7-ae75-11dc-a5f9-001a4d49522b"> 219 <topic>opera -- multiple vulnerabilities</topic> 220 <affects> 221 <package> 222 <name>opera</name> 223 <name>opera-devel</name> 224 <name>linux-opera</name> 225 <range><lt>9.25</lt></range> 226 </package> 227 </affects> 228 <description> 229 <body xmlns="http://www.w3.org/1999/xhtml"> 230 <p>Opera Software ASA reports about multiple security 231 fixes:</p> 232 <blockquote cite="http://www.opera.com/docs/changelogs/freebsd/925/"> 233 <ul> 234 <li>Fixed an issue where plug-ins could be used to allow 235 cross domain scripting, as reported by David 236 Bloom. Details will be disclosed at a later date.</li> 237 <li>Fixed an issue with TLS certificates that could be 238 used to execute arbitrary code, as reported by Alexander 239 Klink (Cynops GmbH). Details will be disclosed at a 240 later date.</li> 241 <li>Rich text editing can no longer be used to allow cross 242 domain scripting, as reported by David Bloom. See our 243 advisory.</li> 244 <li>Prevented bitmaps from revealing random data from 245 memory, as reported by Gynvael Coldwind. Details will be 246 disclosed at a later date.</li> 247 </ul> 248 </blockquote> 249 </body> 250 </description> 251 <references> 252 <cvename>CVE-2007-6520</cvename> 253 <cvename>CVE-2007-6521</cvename> 254 <cvename>CVE-2007-6522</cvename> 255 <cvename>CVE-2007-6524</cvename> 256 <url>http://www.opera.com/docs/changelogs/freebsd/925/</url> 257 <url>http://www.opera.com/support/search/view/875/</url> 258 </references> 259 <dates> 260 <discovery>2007-12-19</discovery> 261 <entry>2007-12-19</entry> 262 <modified>2007-12-29</modified> 263 </dates> 264 </vuln> 265 266 <vuln vid="31435fbc-ae73-11dc-a5f9-001a4d49522b"> 267 <topic>peercast -- buffer overflow vulnerability</topic> 268 <affects> 269 <package> 270 <name>peercast</name> 271 <range><lt>0.1218</lt></range> 272 </package> 273 </affects> 274 <description> 275 <body xmlns="http://www.w3.org/1999/xhtml"> 276 <p>Luigi Auriemma reports that peercast is vulnerable to a 277 buffer overflow which could lead to a DoS or potentially 278 remote code execution:</p> 279 <blockquote cite="http://aluigi.altervista.org/adv/peercasthof-adv.txt"> 280 <p>The handshakeHTTP function which handles all the requests 281 received by the other clients is vulnerable to a heap 282 overflow which allows an attacker to fill the 283 loginPassword and loginMount buffers located in the 284 Servent class with how much data he wants.</p> 285 </blockquote> 286 </body> 287 </description> 288 <references> 289 <cvename>CVE-2007-6454</cvename> 290 <url>http://aluigi.altervista.org/adv/peercasthof-adv.txt</url> 291 <url>http://secunia.com/advisories/28120/</url> 292 </references> 293 <dates> 294 <discovery>2007-12-17</discovery> 295 <entry>2007-12-19</entry> 296 <modified>2010-05-12</modified> 297 </dates> 298 </vuln> 299 300 <vuln vid="fee7e059-acec-11dc-807f-001b246e4fdf"> 301 <topic>ganglia-webfrontend -- XSS vulnerabilities</topic> 302 <affects> 303 <package> 304 <name>ganglia-webfrontend</name> 305 <range><lt>3.0.6</lt></range> 306 </package> 307 </affects> 308 <description> 309 <body xmlns="http://www.w3.org/1999/xhtml"> 310 <p>The Ganglia project reports:</p> 311 <blockquote cite="http://ganglia.info/?p=60"> 312 <p>The Ganglia development team is pleased to release Ganglia 313 3.0.6 (Foss) which is available[...]. This release includes a 314 security fix for web frontend cross-scripting vulnerability.</p> 315 </blockquote> 316 </body> 317 </description> 318 <references> 319 <url>http://sourceforge.net/mailarchive/message.php?msg_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com</url> 320 <url>http://sourceforge.net/mailarchive/forum.php?thread_name=d4c731da0712101044l7245cba9l34974008879f47a3%40mail.gmail.com&forum_name=ganglia-developers</url> 321 </references> 322 <dates> 323 <discovery>2007-12-10</discovery> 324 <entry>2007-12-17</entry> 325 <modified>2007-12-18</modified> 326 </dates> 327 </vuln> 328 329 <vuln vid="30f5ca1d-a90b-11dc-bf13-0211060005df"> 330 <topic>qemu -- Translation Block Local Denial of Service Vulnerability</topic> 331 <affects> 332 <package> 333 <name>qemu</name> 334 <name>qemu-devel</name> 335 <range><lt>0.9.0_4</lt></range> 336 <range><ge>0.9.0s.20070101*</ge><lt>0.9.0s.20070802_1</lt></range> 337 </package> 338 </affects> 339 <description> 340 <body xmlns="http://www.w3.org/1999/xhtml"> 341 <p>SecurityFocus reports:</p> 342 <blockquote cite="http://www.securityfocus.com/bid/26666/discuss"> 343 <p>QEMU is prone to a local denial-of-service vulnerability 344 because it fails to perform adequate boundary checks when 345 handling user-supplied input.</p> 346 <p>Attackers can exploit this issue to cause denial-of-service 347 conditions. Given the nature of the issue, attackers may also be 348 able to execute arbitrary code, but this has not been confirmed.</p> 349 </blockquote> 350 </body> 351 </description> 352 <references> 353 <bid>26666</bid> 354 <cvename>CVE-2007-6227</cvename> 355 <url>http://www.securityfocus.com/archive/1/484429</url> 356 </references> 357 <dates> 358 <discovery>2007-11-30</discovery> 359 <entry>2007-12-12</entry> 360 <modified>2007-12-14</modified> 361 </dates> 362 </vuln> 363 364 <vuln vid="fa708908-a8c7-11dc-b41d-000fb5066b20"> 365 <topic>drupal -- SQL injection vulnerability</topic> 366 <affects> 367 <package> 368 <name>drupal5</name> 369 <range><lt>5.4</lt></range> 370 </package> 371 <package> 372 <name>drupal4</name> 373 <range><lt>4.7.9</lt></range> 374 </package> 375 </affects> 376 <description> 377 <body xmlns="http://www.w3.org/1999/xhtml"> 378 <p>The Drupal Project reports:</p> 379 <blockquote cite="http://drupal.org/node/198162"> 380 <p>The function taxonomy_select_nodes() directly injects variables 381 into SQL queries instead of using placeholders. While taxonomy 382 module itself validates the input passed to 383 taxonomy_select_nodes(), this is a weakness in Drupal core. 384 Several contributed modules, such as taxonomy_menu, ajaxLoader, 385 and ubrowser, directly pass user input to taxonomy_select_nodes(), 386 enabling SQL injection attacks by anonymous users.</p> 387 </blockquote> 388 </body> 389 </description> 390 <references> 391 <cvename>CVE-2007-6299</cvename> 392 <url>http://drupal.org/node/198162</url> 393 <url>http://secunia.com/advisories/27932/</url> 394 </references> 395 <dates> 396 <discovery>2007-12-05</discovery> 397 <entry>2007-12-12</entry> 398 </dates> 399 </vuln> 400 401 <vuln vid="ffcbd42d-a8c5-11dc-bec2-02e0185f8d72"> 402 <topic>samba -- buffer overflow vulnerability</topic> 403 <affects> 404 <package> 405 <name>samba</name> 406 <name>samba3</name> 407 <name>ja-samba</name> 408 <range><lt>3.0.28</lt></range> 409 <range><gt>*,1</gt><lt>3.0.28,1</lt></range> 410 </package> 411 </affects> 412 <description> 413 <body xmlns="http://www.w3.org/1999/xhtml"> 414 <p>Secuna Research reports:</p> 415 <blockquote cite="http://secunia.com/advisories/27760/"> 416 <p>Secunia Research has discovered a vulnerability in Samba, which 417 can be exploited by malicious people to compromise a vulnerable 418 system. The vulnerability is caused due to a boundary error within 419 the "send_mailslot()" function. This can be exploited to cause a 420 stack-based buffer overflow with zero bytes via a specially crafted 421 "SAMLOGON" domain logon packet containing a username string placed 422 at an odd offset followed by an overly long GETDC string. 423 Successful exploitation allows execution of arbitrary code, but 424 requires that the "domain logons" option is enabled.</p> 425 </blockquote> 426 </body> 427 </description> 428 <references> 429 <cvename>CVE-2007-6015</cvename> 430 <url>http://secunia.com/advisories/27760/</url> 431 </references> 432 <dates> 433 <discovery>2007-12-10</discovery> 434 <entry>2007-12-12</entry> 435 <modified>2008-09-26</modified> 436 </dates> 437 </vuln> 438 439 <vuln vid="b2571f88-a867-11dc-a6f0-00a0cce0781e"> 440 <topic>smbftpd -- format string vulnerability</topic> 441 <affects> 442 <package> 443 <name>smbftpd</name> 444 <range><lt>0.96</lt></range> 445 </package> 446 </affects> 447 <description> 448 <body xmlns="http://www.w3.org/1999/xhtml"> 449 <p>Secunia reports:</p> 450 <blockquote cite="http://secunia.com/advisories/27014/"> 451 <p>Format string vulnerability in the SMBDirList function in dirlist.c 452 in SmbFTPD 0.96 allows remote attackers to execute arbitrary code 453 via format string specifiers in a directory name.</p> 454 </blockquote> 455 </body> 456 </description> 457 <references> 458 <cvename>CVE-2007-5184</cvename> 459 <url>http://secunia.com/advisories/27014/</url> 460 <url>http://sourceforge.net/project/shownotes.php?release_id=543077</url> 461 </references> 462 <dates> 463 <discovery>2007-10-01</discovery> 464 <entry>2007-12-12</entry> 465 </dates> 466 </vuln> 467 468 <vuln vid="6ae7cef2-a6ae-11dc-95e6-000c29c5647f"> 469 <topic>jetty -- multiple vulnerabilities</topic> 470 <affects> 471 <package> 472 <name>jetty</name> 473 <range><lt>6.1.6</lt></range> 474 </package> 475 </affects> 476 <description> 477 <body xmlns="http://www.w3.org/1999/xhtml"> 478 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5613"> 479 <p>Cross-site scripting (XSS) vulnerability in Dump Servlet in 480 Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject 481 arbitrary web script or HTML via unspecified parameters and 482 cookies.</p> 483 </blockquote> 484 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5614"> 485 <p>Mortbay Jetty before 6.1.6rc1 does not properly handle "certain 486 quote sequences" in HTML cookie parameters, which allows remote 487 attackers to hijack browser sessions via unspecified vectors.</p> 488 </blockquote> 489 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5615"> 490 <p>CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 491 allows remote attackers to inject arbitrary HTTP headers and 492 conduct HTTP response splitting attacks via unspecified vectors. 493 </p> 494 </blockquote> 495 </body> 496 </description> 497 <references> 498 <certvu>237888</certvu> 499 <certvu>212984</certvu> 500 <certvu>438616</certvu> 501 <cvename>CVE-2007-5613</cvename> 502 <cvename>CVE-2007-5614</cvename> 503 <cvename>CVE-2007-5615</cvename> 504 <url>http://svn.codehaus.org/jetty/jetty/trunk/VERSION.txt</url> 505 </references> 506 <dates> 507 <discovery>2007-12-05</discovery> 508 <entry>2007-12-10</entry> 509 </dates> 510 </vuln> 511 512 <vuln vid="821afaa2-9e9a-11dc-a7e3-0016360406fa"> 513 <topic>liveMedia -- DoS vulnerability</topic> 514 <affects> 515 <package> 516 <name>liveMedia</name> 517 <range><lt>2007.11.18,1</lt></range> 518 </package> 519 </affects> 520 <description> 521 <body xmlns="http://www.w3.org/1999/xhtml"> 522 <p>The live555 development team reports:</p> 523 <blockquote cite="http://www.live555.com/liveMedia/public/changelog.txt"> 524 <p>Fixed a bounds-checking error in "parseRTSPRequestString()" 525 caused by an int vs. unsigned problem.</p> 526 </blockquote> 527 <blockquote cite="http://aluigi.altervista.org/adv/live555x-adv.txt"> 528 <p>The function which handles the incoming queries from the 529 clients is affected by a vulnerability which allows an attacker 530 to crash the server remotely using the smallest RTSP query 531 possible to use.</p> 532 </blockquote> 533 </body> 534 </description> 535 <references> 536 <cvename>CVE-2007-6036</cvename> 537 <url>http://aluigi.altervista.org/adv/live555x-adv.txt</url> 538 <url>http://www.live555.com/liveMedia/public/changelog.txt</url> 539 </references> 540 <dates> 541 <discovery>2007-11-20</discovery> 542 <entry>2007-12-08</entry> 543 <modified>2007-12-09</modified> 544 </dates> 545 </vuln> 546 547 <vuln vid="610bc692-a2ad-11dc-900c-000bcdc1757a"> 548 <topic>GNU finger vulnerability</topic> 549 <affects> 550 <package> 551 <name>gnu-finger</name> 552 <range><le>1.37_1</le></range> 553 </package> 554 </affects> 555 <description> 556 <body xmlns="http://www.w3.org/1999/xhtml"> 557 <p>GNU security announcement:</p> 558 <blockquote cite="http://www.gnu.org/software/finger/"> 559 <p>GNU Finger unfortunately has not been updated in 560 many years, and has known security vulnerabilities. 561 Please do not use it in production environments.</p> 562 </blockquote> 563 </body> 564 </description> 565 <references> 566 <cvename>CVE-1999-1165</cvename> 567 <url>http://www.gnu.org/software/finger/</url> 568 </references> 569 <dates> 570 <discovery>1999-07-21</discovery> 571 <entry>2007-12-05</entry> 572 </dates> 573 </vuln> 574 575 <vuln vid="6eb580d7-a29c-11dc-8919-001c2514716c"> 576 <topic>Squid -- Denial of Service Vulnerability</topic> 577 <affects> 578 <package> 579 <name>squid</name> 580 <range><ge>2.0</ge><lt>2.6.16_1</lt></range> 581 <range><ge>3.*</ge><lt>3.0.r1.20071001_1</lt></range> 582 </package> 583 </affects> 584 <description> 585 <body xmlns="http://www.w3.org/1999/xhtml"> 586 <p>Squid secuirty advisory reports:</p> 587 <blockquote cite="http://www.squid-cache.org/Advisories/SQUID-2007_2.txt"> 588 <p>Due to incorrect bounds checking Squid is vulnerable 589 to a denial of service check during some cache update 590 reply processing.</p> 591 <p>This problem allows any client trusted to use the 592 service to perform a denial of service attack on the 593 Squid service.</p> 594 </blockquote> 595 </body> 596 </description> 597 <references> 598 <bid>26687</bid> 599 <cvename>CVE-2007-6239</cvename> 600 </references> 601 <dates> 602 <discovery>2007-11-28</discovery> 603 <entry>2007-12-04</entry> 604 <modified>2007-12-07</modified> 605 </dates> 606 </vuln> 607 608 <vuln vid="30acb8ae-9d46-11dc-9114-001c2514716c"> 609 <topic>rubygem-rails -- session-fixation vulnerability</topic> 610 <affects> 611 <package> 612 <name>rubygem-rails</name> 613 <range><lt>1.2.6</lt></range> 614 </package> 615 </affects> 616 <description> 617 <body xmlns="http://www.w3.org/1999/xhtml"> 618 <p>Rails core team reports:</p> 619 <blockquote cite="http://weblog.rubyonrails.com/2007/11/24/ruby-on-rails-1-2-6-security-and-maintenance-release"> 620 <p>The rails core team has released ruby on rails 1.2.6 to 621 address a bug in the fix for session fixation attacks 622 (CVE-2007-5380). The CVE Identifier for this new issue 623 is CVE-2007-6077.</p> 624 </blockquote> 625 </body> 626 </description> 627 <references> 628 <cvename>CVE-2007-6077</cvename> 629 </references> 630 <dates> 631 <discovery>2007-11-24</discovery> 632 <entry>2007-11-27</entry> 633 </dates> 634 </vuln> 635 636 <vuln vid="44fb0302-9d38-11dc-9114-001c2514716c"> 637 <topic>rubygem-rails -- JSON XSS vulnerability</topic> 638 <affects> 639 <package> 640 <name>rubygem-rails</name> 641 <range><lt>1.2.5</lt></range> 642 </package> 643 <package> 644 <name>rubygem-activesupport</name> 645 <range><lt>1.4.4</lt></range> 646 </package> 647 </affects> 648 <description> 649 <body xmlns="http://www.w3.org/1999/xhtml"> 650 <p>Rails core team reports:</p> 651 <blockquote cite="http://weblog.rubyonrails.org/2007/10/12/rails-1-2-5-maintenance-release"> 652 <p>All users of Rails 1.2.4 or earlier are advised to upgrade 653 to 1.2.5, though it isn't strictly necessary if you 654 aren't working with JSON. For more information the JSON 655 vulnerability, see CVE-2007-3227.</p> 656 </blockquote> 657 </body> 658 </description> 659 <references> 660 <cvename>CVE-2007-3227</cvename> 661 </references> 662 <dates> 663 <discovery>2007-10-12</discovery> 664 <entry>2007-11-28</entry> 665 <modified>2007-12-01</modified> 666 </dates> 667 </vuln> 668 669 <vuln vid="31d9fbb4-9d09-11dc-a29d-0016d325a0ed"> 670 <topic>ikiwiki -- improper symlink verification vulnerability</topic> 671 <affects> 672 <package> 673 <name>ikiwiki</name> 674 <range><lt>2.14</lt></range> 675 </package> 676 </affects> 677 <description> 678 <body xmlns="http://www.w3.org/1999/xhtml"> 679 <p>The ikiwiki development team reports:</p> 680 <blockquote cite="http://ikiwiki.info/security/#index29h2"> 681 <p>Ikiwiki did not check if path to the srcdir to contained a 682 symlink. If an attacker had commit access to the directories in 683 the path, they could change it to a symlink, causing ikiwiki to 684 read and publish files that were not intended to be 685 published. (But not write to them due to other checks.)</p> 686 </blockquote> 687 </body> 688 </description> 689 <references> 690 <url>http://ikiwiki.info/security/#index29h2</url> 691 </references> 692 <dates> 693 <discovery>2007-11-26</discovery> 694 <entry>2007-11-27</entry> 695 </dates> 696 </vuln> 697 698 <vuln vid="f1f6f6da-9d2f-11dc-9114-001c2514716c"> 699 <topic>firefox -- multiple remote unspecified memory corruption vulnerabilities</topic> 700 <affects> 701 <package> 702 <name>firefox</name> 703 <range><lt>2.0.0.10,1</lt></range> 704 </package> 705 <package> 706 <name>linux-firefox</name> 707 <range><lt>2.0.0.10</lt></range> 708 </package> 709 <package> 710 <name>seamonkey</name> 711 <name>linux-seamonkey</name> 712 <range><lt>1.1.7</lt></range> 713 </package> 714 <package> 715 <name>flock</name> 716 <name>linux-flock</name> 717 <range><lt>1.0.2</lt></range> 718 </package> 719 <package> 720 <name>linux-firefox-devel</name> 721 <range><lt>3.0.a2007.12.12</lt></range> 722 </package> 723 <package> 724 <name>linux-seamonkey-devel</name> 725 <range><lt>2.0.a2007.12.12</lt></range> 726 </package> 727 </affects> 728 <description> 729 <body xmlns="http://www.w3.org/1999/xhtml"> 730 <p>Mozilla Foundation reports:</p> 731 <blockquote cite="http://www.mozilla.org/security/announce/2007/mfsa2007-38.html"> 732 <p>The Firefox 2.0.0.10 update contains fixes for three bugs that 733 improve the stability of the product. These crashes showed some 734 evidence of memory corruption under certain circumstances and we 735 presume that with enough effort at least some of these could be 736 exploited to run arbitrary code.</p> 737 </blockquote> 738 </body> 739 </description> 740 <references> 741 <bid>26593</bid> 742 <cvename>CVE-2007-5959</cvename> 743 </references> 744 <dates> 745 <discovery>2007-11-26</discovery> 746 <entry>2007-11-27</entry> 747 <modified>2007-12-14</modified> 748 </dates> 749 </vuln> 750 751 <vuln vid="15485ae8-9848-11dc-9e48-0016179b2dd5"> 752 <topic>phpmyadmin -- Cross Site Scripting</topic> 753 <affects> 754 <package> 755 <name>phpmyadmin</name> 756 <range><lt>2.11.2.2</lt></range> 757 </package> 758 </affects> 759 <description> 760 <body xmlns="http://www.w3.org/1999/xhtml"> 761 <p>phpMyAdmin security announcement:</p> 762 <blockquote cite="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8"> 763 <p>The login page auth_type cookie was vulnerable to XSS via 764 the convcharset parameter. An attacker could use this to 765 execute malicious code on the visitors computer</p> 766 </blockquote> 767 </body> 768 </description> 769 <references> 770 <cvename>CVE-2007-6100</cvename> 771 <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-8</url> 772 <url>http://www.nth-dimension.org.uk/downloads.php?id=38</url> 773 </references> 774 <dates> 775 <discovery>2007-11-20</discovery> 776 <entry>2007-11-21</entry> 777 <modified>2010-05-12</modified> 778 </dates> 779 </vuln> 780 781 <vuln vid="a63b15f9-97ff-11dc-9e48-0016179b2dd5"> 782 <topic>samba -- multiple vulnerabilities</topic> 783 <affects> 784 <package> 785 <name>samba</name> 786 <name>samba3</name> 787 <name>ja-samba</name> 788 <range><lt>3.0.26a</lt></range> 789 <range><gt>*,1</gt><lt>3.0.26a_2,1</lt></range> 790 </package> 791 </affects> 792 <description> 793 <body xmlns="http://www.w3.org/1999/xhtml"> 794 <p>The Samba Team reports:</p> 795 <blockquote cite="http://us1.samba.org/samba/security/CVE-2007-5398.html"> 796 <p>Secunia Research reported a vulnerability that allows for 797 the execution of arbitrary code in nmbd. This defect may 798 only be exploited when the "wins support" parameter has 799 been enabled in smb.conf.</p> 800 </blockquote> 801 <blockquote cite="http://us1.samba.org/samba/security/CVE-2007-4572.html"> 802 <p>Samba developers have discovered what is believed to be 803 a non-exploitable buffer over in nmbd during the processing 804 of GETDC logon server requests. This code is only used 805 when the Samba server is configured as a Primary or Backup 806 Domain Controller.</p> 807 </blockquote> 808 </body> 809 </description> 810 <references> 811 <bid>26454</bid> 812 <cvename>CVE-2007-4572</cvename> 813 <cvename>CVE-2007-5398</cvename> 814 <url>http://secunia.com/advisories/27450/</url> 815 <url>http://us1.samba.org/samba/security/CVE-2007-4572.html</url> 816 <url>http://us1.samba.org/samba/security/CVE-2007-5398.html</url> 817 </references> 818 <dates> 819 <discovery>2007-11-15</discovery> 820 <entry>2007-11-21</entry> 821 <modified>2008-09-26</modified> 822 </dates> 823 </vuln> 824 825 <vuln vid="392b5b1d-9471-11dc-9db7-001c2514716c"> 826 <topic>php -- multiple security vulnerabilities</topic> 827 <affects> 828 <package> 829 <name>php5</name> 830 <range><lt>5.2.5</lt></range> 831 </package> 832 </affects> 833 <description> 834 <body xmlns="http://www.w3.org/1999/xhtml"> 835 <p>PHP project reports:</p> 836 <blockquote cite="http://www.php.net/releases/5_2_5.php"> 837 <p>Security Enhancements and Fixes in PHP 5.2.5:</p> 838 <ul> 839 <li>Fixed dl() to only accept filenames. Reported by Laurent 840 Gaffie.</li> 841 <li>Fixed dl() to limit argument size to MAXPATHLEN (CVE-2007-4887). 842 Reported by Laurent Gaffie.</li> 843 <li>Fixed htmlentities/htmlspecialchars not to accept partial 844 multibyte sequences. Reported by Rasmus Lerdorf</li> 845 <li>Fixed possible triggering of buffer overflows inside glibc 846 implementations of the fnmatch(), setlocale() and glob() 847 functions. Reported by Laurent Gaffie.</li> 848 <li>Fixed "mail.force_extra_parameters" php.ini directive not to be 849 modifiable in .htaccess due to the security implications. Reported 850 by SecurityReason.</li> 851 <li>Fixed bug #42869 (automatic session id insertion adds sessions 852 id to non-local forms).</li> 853 <li>Fixed bug #41561 (Values set with php_admin_* in httpd.conf can 854 be overwritten with ini_set()).</li> 855 </ul> 856 </blockquote> 857 </body> 858 </description> 859 <references> 860 <bid>26403</bid> 861 <cvename>CVE-2007-4887</cvename> 862 </references> 863 <dates> 864 <discovery>2007-11-08</discovery> 865 <entry>2007-11-16</entry> 866 </dates> 867 </vuln> 868 869 <vuln vid="a7080c30-91a2-11dc-b2eb-00b0d07e6c7e"> 870 <topic>mt-daapd -- denial of service vulnerability</topic> 871 <affects> 872 <package> 873 <name>mt-daapd</name> 874 <range><lt>0.2.4.1</lt></range> 875 </package> 876 </affects> 877 <description> 878 <body xmlns="http://www.w3.org/1999/xhtml"> 879 <p>US-CERT reports:</p> 880 <blockquote cite="http://www.us-cert.gov/cas/bulletins/SB07-316.html"> 881 <p>webserver.c in mt-dappd in Firefly Media Server 0.2.4 and 882 earlier allows remote attackers to cause a denial of service 883 (NULL dereference and daemon crash) via a stats method action 884 to /xml-rpc with (1) an empty Authorization header line, which 885 triggers a crash in the ws_decodepassword function; or (2) a 886 header line without a ':' character, which triggers a crash 887 in the ws_getheaders function.</p> 888 </blockquote> 889 </body> 890 </description> 891 <references> 892 <cvename>CVE-2007-5824</cvename> 893 </references> 894 <dates> 895 <discovery>2007-11-05</discovery> 896 <entry>2007-11-12</entry> 897 </dates> 898 </vuln> 899 900 <vuln vid="92f86b93-923f-11dc-a2bf-02e081235dab"> 901 <topic>net-snmp -- denial of service via GETBULK request</topic> 902 <affects> 903 <package> 904 <name>net-snmp</name> 905 <range><lt>5.3.1_7</lt></range> 906 </package> 907 </affects> 908 <description> 909 <body xmlns="http://www.w3.org/1999/xhtml"> 910 <p>CVE reports:</p> 911 <blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5846"> 912 <p>The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 913 allows remote attackers to cause a denial of service (CPU 914 and memory consumption) via a GETBULK request with a large 915 max-repeaters value.</p> 916 </blockquote> 917 </body> 918 </description> 919 <references> 920 <cvename>CVE-2007-5846</cvename> 921 </references> 922 <dates> 923 <discovery>2007-11-06</discovery> 924 <entry>2007-11-13</entry> 925 <modified>2007-11-14</modified> 926 </dates> 927 </vuln> 928 929 <vuln vid="ff65eecb-91e4-11dc-bd6c-0016179b2dd5"> 930 <topic>flac -- media file processing integer overflow vulnerabilities</topic> 931 <affects> 932 <package> 933 <name>flac</name> 934 <range><lt>1.1.2_2</lt></range> 935 </package> 936 </affects> 937 <description> 938 <body xmlns="http://www.w3.org/1999/xhtml"> 939 <p>iDefense Laps reports:</p> 940 <blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608"> 941 <p>Remote exploitation of multiple integer overflow vulnerabilities 942 in libFLAC, as included with various vendor's software 943 distributions, allows attackers to execute arbitrary code 944 in the context of the currently logged in user.</p> 945 <p>These vulnerabilities specifically exist in the handling of 946 malformed FLAC media files. In each case, an integer overflow can 947 occur while calculating the amount of memory to allocate. As such, 948 insufficient memory is allocated for the data that is subsequently 949 read in from the file, and a heap based buffer overflow occurs.</p> 950 </blockquote> 951 </body> 952 </description> 953 <references> 954 <cvename>CVE-2007-4619</cvename> 955 <url>http://secunia.com/advisories/27210/</url> 956 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=608</url> 957 </references> 958 <dates> 959 <discovery>2007-10-11</discovery> 960 <entry>2007-11-13</entry> 961 </dates> 962 </vuln> 963 964 <vuln vid="2747fc39-915b-11dc-9239-001c2514716c"> 965 <topic>xpdf -- multiple remote Stream.CC vulnerabilities</topic> 966 <affects> 967 <package> 968 <name>cups-base</name> 969 <range><lt>1.3.3_2</lt></range> 970 </package> 971 <package> 972 <name>gpdf</name> 973 <range><gt>0</gt></range> 974 </package> 975 <package> 976 <name>kdegraphics</name> 977 <range><lt>3.5.8_1</lt></range> 978 </package> 979 <package> 980 <name>koffice</name> 981 <range><lt>1.6.3_3,2</lt></range> 982 </package> 983 <package> 984 <name>poppler</name> 985 <range><lt>0.6</lt></range> 986 </package> 987 <package> 988 <name>xpdf</name> 989 <range><lt>3.02_5</lt></range> 990 </package> 991 </affects> 992 <description> 993 <body xmlns="http://www.w3.org/1999/xhtml"> 994 <p>Secunia Research reports:</p> 995 <blockquote cite="http://www.securityfocus.com/archive/1/483372"> 996 <p>Secunia Research has discovered some vulnerabilities in Xpdf, 997 which can be exploited by malicious people to compromise a user's 998 system.</p> 999 <ul> 1000 <li>An array indexing error within the 1001 "DCTStream::readProgressiveDataUnit()" method in xpdf/Stream.cc 1002 can be exploited to corrupt memory via a specially crafted PDF 1003 file.</li> 1004 <li>An integer overflow error within the "DCTStream::reset()" 1005 method in xpdf/Stream.cc can be exploited to cause a heap-based 1006 buffer overflow via a specially crafted PDF file.</li> 1007 <li>A boundary error within the "CCITTFaxStream::lookChar()" method 1008 in xpdf/Stream.cc can be exploited to cause a heap-based buffer 1009 overflow by tricking a user into opening a PDF file containing a 1010 specially crafted "CCITTFaxDecode" filter.</li> 1011 </ul> 1012 <p>Successful exploitation may allow execution of arbitrary code.</p> 1013 </blockquote> 1014 </body> 1015 </description> 1016 <references> 1017 <bid>26367</bid> 1018 <cvename>CVE-2007-4352</cvename> 1019 <cvename>CVE-2007-5392</cvename> 1020 <cvename>CVE-2007-5393</cvename> 1021 </references> 1022 <dates> 1023 <discovery>2007-11-07</discovery> 1024 <entry>2007-11-12</entry> 1025 <modified>2007-11-14</modified> 1026 </dates> 1027 </vuln> 1028 1029 <vuln vid="ffba6ab0-90b5-11dc-9835-003048705d5a"> 1030 <topic>plone -- unsafe data interpreted as pickles</topic> 1031 <affects> 1032 <package> 1033 <name>plone</name> 1034 <range><ge>2.5</ge><lt>2.5.5</lt></range> 1035 <range><ge>3.0</ge><lt>3.0.3</lt></range> 1036 </package> 1037 </affects> 1038 <description> 1039 <body xmlns="http://www.w3.org/1999/xhtml"> 1040 <p>Plone projectreports:</p> 1041 <blockquote cite="http://plone.org/about/security/advisories/cve-2007-5741"> 1042 <p>This hotfix corrects a vulnerability in the statusmessages 1043 and linkintegrity modules, where unsafe network data was 1044 interpreted as python pickles. This allows an attacker to 1045 run arbitrary python code within the Zope/Plone process.</p> 1046 </blockquote> 1047 </body> 1048 </description> 1049 <references> 1050 <bid>26354</bid> 1051 <cvename>CVE-2007-5741</cvename> 1052 </references> 1053 <dates> 1054 <discovery>2007-11-06</discovery> 1055 <entry>2007-11-12</entry> 1056 </dates> 1057 </vuln> 1058 1059 <vuln vid="2d2dcbb4-906c-11dc-a951-0016179b2dd5"> 1060 <topic>phpmyadmin -- cross-site scripting vulnerability</topic> 1061 <affects> 1062 <package> 1063 <name>phpMyAdmin</name> 1064 <range><lt>2.11.2.1</lt></range> 1065 </package> 1066 </affects> 1067 <description> 1068 <body xmlns="http://www.w3.org/1999/xhtml"> 1069 <p>The DigiTrust Group reports:</p> 1070 <blockquote cite="http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html"> 1071 <p>When creating a new database, a malicious user can use a 1072 client-side Web proxy to place malicious code in the db parameter of 1073 the POST request. Since db_create.php does not properly sanitize 1074 user-supplied input, an administrator could face a persistent XSS 1075 attack when the database names are displayed.</p> 1076 </blockquote> 1077 </body> 1078 </description> 1079 <references> 1080 <cvename>CVE-2007-5976</cvename> 1081 <cvename>CVE-2007-5977</cvename> 1082 <url>http://www.digitrustgroup.com/advisories/tdg-advisory071108a.html</url> 1083 <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-7</url> 1084 </references> 1085 <dates> 1086 <discovery>2007-11-11</discovery> 1087 <entry>2007-11-11</entry> 1088 <modified>2010-05-12</modified> 1089 </dates> 1090 </vuln> 1091 1092 <vuln vid="9b718b82-8ef5-11dc-8e42-001c2514716c"> 1093 <topic>gallery2 -- multiple vulnerabilities</topic> 1094 <affects> 1095 <package> 1096 <name>gallery2</name> 1097 <range><lt>2.2.3</lt></range> 1098 </package> 1099 </affects> 1100 <description> 1101 <body xmlns="http://www.w3.org/1999/xhtml"> 1102 <p>Gallery project reports:</p> 1103 <blockquote cite="http://gallery.menalto.com/gallery_2.2.3_released"> 1104 <p>Gallery 2.2.3 addresses the following security vulnerabilities:</p> 1105 <ul> 1106 <li>Unauthorized renaming of items possible with WebDAV (reported 1107 by Merrick Manalastas)</li> 1108 <li>Unauthorized modification and retrieval of item properties 1109 possible with WebDAV</li> 1110 <li>Unauthorized locking and replacing of items possible with 1111 WebDAV</li> 1112 <li>Unauthorized editing of data file possible via linked items with 1113 Reupload and WebDAV (reported by Nicklous Roberts)</li> 1114 </ul> 1115 </blockquote> 1116 </body> 1117 </description> 1118 <references> 1119 <cvename>CVE-2007-4650</cvename> 1120 <bid>25580</bid> 1121 </references> 1122 <dates> 1123 <discovery>2007-08-29</discovery> 1124 <entry>2007-11-09</entry> 1125 </dates> 1126 </vuln> 1127 1128 <vuln vid="20a4eb11-8ea3-11dc-a396-0016179b2dd5"> 1129 <topic>tikiwiki -- multiple vulnerabilities</topic> 1130 <affects> 1131 <package> 1132 <name>tikiwik</name> 1133 <range><lt>1.9.8.2</lt></range> 1134 </package> 1135 </affects> 1136 <description> 1137 <body xmlns="http://www.w3.org/1999/xhtml"> 1138 <p>Secunia reports:</p> 1139 <blockquote cite="http://secunia.com/advisories/26618/"> 1140 <p>Some vulnerabilities have been reported in TikiWiki, which 1141 can be exploited by malicious people to conduct cross-site 1142 scripting and script insertion attacks and disclose potentially 1143 sensitive information.</p> 1144 <p>Input passed to the username parameter in tiki-remind_password.php 1145 (when remind is set to send me my password) is not properly 1146 sanitised before being returned to the user. This can be exploited 1147 to execute arbitrary HTML and script code (for example with meta 1148 refreshes to a javascript: URL) in a user's browser session in 1149 context of an affected site.</p> 1150 <p>Input passed to the local_php and error_handler parameters in 1151 tiki-index.php is not properly verified before being used to include 1152 files. This can be exploited to include arbitrary files from local 1153 resources.</p> 1154 <p>Input passed to the imp_language parameter in 1155 tiki-imexport_languages.php is not properly verified before being 1156 used to include files. This can be exploited to include arbitrary 1157 files from local resources.</p> 1158 <p>Certain img src elements are not properly santised before being 1159 used. This can be exploited to insert arbitrary HTML and script 1160 code, which is executed in a user's browser session in context of an 1161 affected site when the malicious data is viewed.</p> 1162 </blockquote> 1163 </body> 1164 </description> 1165 <references> 1166 <cvename>CVE-2007-4554</cvename> 1167 <cvename>CVE-2007-5683</cvename> 1168 <cvename>CVE-2007-5684</cvename> 1169 <url>http://secunia.com/advisories/26618/</url> 1170 <url>http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/changelog.txt?view=markup&pathrev=REL-1-9-8-2</url> 1171 </references> 1172 <dates> 1173 <discovery>2007-08-27</discovery> 1174 <entry>2007-11-09</entry> 1175 <modified>2008-10-03</modified> 1176 </dates> 1177 </vuln> 1178 1179 <vuln vid="8dd9722c-8e97-11dc-b8f6-001c2514716c"> 1180 <topic>cups -- off-by-one buffer overflow</topic> 1181 <affects> 1182 <package> 1183 <name>cups-base</name> 1184 <range><lt>1.3.3_1</lt></range> 1185 </package> 1186 </affects> 1187 <description> 1188 <body xmlns="http://www.w3.org/1999/xhtml"> 1189 <p>Secunia reports:</p> 1190 <blockquote cite="http://secunia.com/advisories/27233"> 1191 <p>Secunia Research has discovered a vulnerability in CUPS, which can 1192 be exploited by malicious people to compromise a vulnerable 1193 system.</p> 1194 <p>The vulnerability is caused due to a boundary error within the 1195 "ippReadIO()" function in cups/ipp.c when processing IPP (Internet 1196 Printing Protocol) tags. This can be exploited to overwrite one 1197 byte on the stack with a zero by sending an IPP request containing 1198 specially crafted "textWithLanguage" or "nameWithLanguage" tags.</p> 1199 <p>Successful exploitation allows execution of arbitrary code.</p> 1200 </blockquote> 1201 </body> 1202 </description> 1203 <references> 1204 <cvename>CVE-2007-4351</cvename> 1205 <url>http://secunia.com/secunia_research/2007-76/</url> 1206 </references> 1207 <dates> 1208 <discovery>2007-11-06</discovery> 1209 <entry>2007-11-09</entry> 1210 <modified>2007-11-12</modified> 1211 </dates> 1212 </vuln> 1213 1214 <vuln vid="5b47c279-8cb5-11dc-8878-0016179b2dd5"> 1215 <topic>perl -- regular expressions unicode data buffer overflow</topic> 1216 <affects> 1217 <package> 1218 <name>perl</name> 1219 <name>perl-threaded</name> 1220 <range><gt>5.8.*</gt><lt>5.8.8_1</lt></range> 1221 </package> 1222 </affects> 1223 <description> 1224 <body xmlns="http://www.w3.org/1999/xhtml"> 1225 <p>Red Hat reports:</p> 1226 <blockquote cite="https://rhn.redhat.com/errata/RHSA-2007-0966.html"> 1227 <p>A flaw was found in Perl's regular expression engine. Specially 1228 crafted input to a regular expression can cause Perl to improperly 1229 allocate memory, possibly resulting in arbitrary code running with 1230 the permissions of the user running Perl.</p> 1231 </blockquote> 1232 </body> 1233 </description> 1234 <references> 1235 <cvename>CVE-2007-5116</cvename> 1236 <url>http://secunia.com/advisories/27546/</url> 1237 </references> 1238 <dates> 1239 <discovery>2007-11-05</discovery> 1240 <entry>2007-11-06</entry> 1241 <modified>2007-11-07</modified> 1242 </dates> 1243 </vuln> 1244 1245 <vuln vid="bfd6eef4-8c94-11dc-8c55-001c2514716c"> 1246 <topic>pcre -- arbitrary code execution</topic> 1247 <affects> 1248 <package> 1249 <name>pcre</name> 1250 <name>pcre-utf8</name> 1251 <range><lt>7.3</lt></range> 1252 </package> 1253 </affects> 1254 <description> 1255 <body xmlns="http://www.w3.org/1999/xhtml"> 1256 <p>Debian project reports:</p> 1257 <blockquote cite="http://www.debian.org/security/2007/dsa-1399"> 1258 <p>Tavis Ormandy of the Google Security Team has discovered 1259 several security issues in PCRE, the Perl-Compatible Regular 1260 Expression library, which potentially allow attackers to 1261 execute arbitrary code by compiling specially crafted regular 1262 expressions.</p> 1263 </blockquote> 1264 </body> 1265 </description> 1266 <references> 1267 <cvename>CVE-2007-1659</cvename> 1268 <cvename>CVE-2007-1660</cvename> 1269 <cvename>CVE-2007-1661</cvename> 1270 <cvename>CVE-2007-1662</cvename> 1271 <cvename>CVE-2007-4766</cvename> 1272 <cvename>CVE-2007-4767</cvename> 1273 <cvename>CVE-2007-4768</cvename> 1274 <url>http://www.pcre.org/changelog.txt</url> 1275 </references> 1276 <dates> 1277 <discovery>2007-11-05</discovery> 1278 <entry>2007-11-06</entry> 1279 </dates> 1280 </vuln> 1281 1282 <vuln vid="617a4021-8bf0-11dc-bffa-0016179b2dd5"> 1283 <topic>perdition -- str_vwrite format string vulnerability</topic> 1284 <affects> 1285 <package> 1286 <name>perdition</name> 1287 <range><lt>1.17.1</lt></range> 1288 </package> 1289 </affects> 1290 <description> 1291 <body xmlns="http://www.w3.org/1999/xhtml"> 1292 <p>SEC-Consult reports:</p> 1293 <blockquote cite="http://www.sec-consult.com/300.html"> 1294 <p>Perdition IMAP is affected by a format string bug in one of its 1295 IMAP output-string formatting functions. The bug allows the 1296 execution of arbitrary code on the affected server. 1297 A successful exploit does not require prior authentication.</p> 1298 </blockquote> 1299 </body> 1300 </description> 1301 <references> 1302 <bid>26270</bid> 1303 <cvename>CVE-2007-5740</cvename> 1304 <url>http://www.sec-consult.com/300.html</url> 1305 <url>http://secunia.com/advisories/27458</url> 1306 </references> 1307 <dates> 1308 <discovery>2007-10-31</discovery> 1309 <entry>2007-11-05</entry> 1310 </dates> 1311 </vuln> 1312 1313 <vuln vid="f8b0f83c-8bb3-11dc-bffa-0016179b2dd5"> 1314 <topic>gftp -- multiple vulnerabilities</topic> 1315 <affects> 1316 <package> 1317 <name>gftp</name> 1318 <range><lt>2.0.18_6</lt></range> 1319 </package> 1320 </affects> 1321 <description> 1322 <body xmlns="http://www.w3.org/1999/xhtml"> 1323 <p>Gentoo reports:</p> 1324 <blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml"> 1325 <p>Kalle Olavi Niemitalo discovered two boundary errors in fsplib code 1326 included in gFTP when processing overly long directory or file 1327 names.</p> 1328 <p>A remote attacker could trigger these vulnerabilities by enticing 1329 a user to download a file with a specially crafted directory or file 1330 name, possibly resulting in the execution of arbitrary code or a 1331 Denial of Service.</p> 1332 </blockquote> 1333 </body> 1334 </description> 1335 <references> 1336 <cvename>CVE-2007-3961</cvename> 1337 <cvename>CVE-2007-3962</cvename> 1338 <url>http://www.gentoo.org/security/en/glsa/glsa-200711-01.xml</url> 1339 </references> 1340 <dates> 1341 <discovery>2007-11-01</discovery> 1342 <entry>2007-11-05</entry> 1343 <modified>2007-11-11</modified> 1344 </dates> 1345 </vuln> 1346 1347 <vuln vid="a1ef3fc0-8ad0-11dc-9490-0016179b2dd5"> 1348 <topic>dircproxy -- remote denial of service</topic> 1349 <affects> 1350 <package> 1351 <name>dircproxy</name> 1352 <range><lt>1.0.5_1</lt></range> 1353 </package> 1354 <package> 1355 <name>dircproxy-devel</name> 1356 <range><lt>1.2.0.b2_1</lt></range> 1357 </package> 1358 </affects> 1359 <description> 1360 <body xmlns="http://www.w3.org/1999/xhtml"> 1361 <p>Securiweb reports:</p> 1362 <blockquote cite="http://dircproxy.securiweb.net/ticket/89"> 1363 <p>dircproxy allows remote attackers to cause a denial of 1364 service (segmentation fault) via an ACTION command without a 1365 parameter, which triggers a NULL pointer dereference, as 1366 demonstrated using a blank /me message from irssi.</p> 1367 </blockquote> 1368 </body> 1369 </description> 1370 <references> 1371 <cvename>CVE-2007-5226</cvename> 1372 <url>http://dircproxy.securiweb.net/ticket/89</url> 1373 <url>https://bugzilla.redhat.com/show_bug.cgi?id=319301</url> 1374 </references> 1375 <dates> 1376 <discovery>2006-09-06</discovery> 1377 <entry>2007-11-04</entry> 1378 <modified>2008-01-31</modified> 1379 </dates> 1380 </vuln> 1381 1382 <vuln vid="a467d0f9-8875-11dc-b3ba-0016179b2dd5"> 1383 <topic>wordpress -- cross-site scripting</topic> 1384 <affects> 1385 <package> 1386 <name>wordpress</name> 1387 <name>de-wordpress</name> 1388 <range><lt>2.3.1</lt></range> 1389 </package> 1390 <package> 1391 <name>zh-wordpress</name> 1392 <range><gt>0</gt></range> 1393 </package> 1394 </affects> 1395 <description> 1396 <body xmlns="http://www.w3.org/1999/xhtml"> 1397 <p>A Secunia Advisory report:</p> 1398 <blockquote cite="http://secunia.com/advisories/27407"> 1399 <p>Input passed to the "posts_columns" parameter in 1400 wp-admin/edit-post-rows.php is not properly sanitised before 1401 being returned to the user. This can be exploited to execute 1402 arbitrary HTML and script code in a user's browser session in 1403 context of an affected site.</p> 1404 </blockquote> 1405 </body> 1406 </description> 1407 <references> 1408 <cvename>CVE-2007-5710</cvename> 1409 <url>http://secunia.com/advisories/27407</url> 1410 <url>http://wordpress.org/development/2007/10/wordpress-231/</url> 1411 </references> 1412 <dates> 1413 <discovery>2007-10-29</discovery> 1414 <entry>2007-11-01</entry> 1415 </dates> 1416 </vuln> 1417 1418 <vuln vid="db449245-870d-11dc-a3ec-001921ab2fa4"> 1419 <topic>openldap -- multiple remote denial of service vulnerabilities</topic> 1420 <affects> 1421 <package> 1422 <name>openldap-server</name> 1423 <range><lt>2.3.39</lt></range> 1424 <range><gt>2.4.0</gt><lt>2.4.6</lt></range> 1425 </package> 1426 </affects> 1427 <description> 1428 <body xmlns="http://www.w3.org/1999/xhtml"> 1429 <p>BugTraq reports:</p> 1430 <blockquote cite="http://www.securityfocus.com/bid/26245/"> 1431 <p>OpenLDAP is prone to multiple remote denial-of-service 1432 vulnerabilities because of an incorrect NULL-termination 1433 issue and a double-free issue.</p> 1434 </blockquote> 1435 </body> 1436 </description> 1437 <references> 1438 <bid>26245</bid> 1439 <cvename>CVE-2007-5707</cvename> 1440 <cvename>CVE-2007-5708</cvename> 1441 </references> 1442 <dates> 1443 <discovery>2007-10-29</discovery> 1444 <entry>2007-10-30</entry> 1445 <modified>2007-10-31</modified> 1446 </dates> 1447 </vuln> 1448 1449 <vuln vid="d2c2952d-85a1-11dc-bfff-003048705d5a"> 1450 <topic>py-django -- denial of service vulnerability</topic> 1451 <affects> 1452 <package> 1453 <name>py23-django</name> 1454 <name>py24-django</name> 1455 <name>py25-django</name> 1456 <range><lt>0.96.1</lt></range> 1457 </package> 1458 <package> 1459 <name>py23-django-devel</name> 1460 <name>py24-django-devel</name> 1461 <name>py25-django-devel</name> 1462 <range><lt>20071026</lt></range> 1463 </package> 1464 </affects> 1465 <description> 1466 <body xmlns="http://www.w3.org/1999/xhtml"> 1467 <p>Django project reports:</p> 1468 <blockquote cite="http://www.djangoproject.com/weblog/2007/oct/26/security-fix/"> 1469 <p>A per-process cache used by Django's internationalization 1470 ("i18n") system to store the results of translation lookups 1471 for particular values of the HTTP Accept-Language header 1472 used the full value of that header as a key. An attacker 1473 could take advantage of this by sending repeated requests 1474 with extremely large strings in the Accept-Language header, 1475 potentially causing a denial of service by filling available 1476 memory.</p> 1477 <p>Due to limitations imposed by Web server software on the 1478 size of HTTP header fields, combined with reasonable limits 1479 on the number of requests which may be handled by a single 1480 server process over its lifetime, this vulnerability may be 1481 difficult to exploit. Additionally, it is only present when 1482 the "USE_I18N" setting in Django is "True" and the i18n 1483 middleware component is enabled*. Nonetheless, all users of 1484 affected versions of Django are encouraged to update.</p> 1485 </blockquote> 1486 </body> 1487 </description> 1488 <references> 1489 <url>http://www.djangoproject.com/weblog/2007/oct/26/security-fix/</url> 1490 </references> 1491 <dates> 1492 <discovery>2007-10-26</discovery> 1493 <entry>2007-10-27</entry> 1494 </dates> 1495 </vuln> 1496 1497 <vuln vid="44224e08-8306-11dc-9283-0016179b2dd5"> 1498 <topic>opera -- multiple vulnerabilities</topic> 1499 <affects> 1500 <package> 1501 <name>opera</name> 1502 <name>opera-devel</name> 1503 <name>linux-opera</name> 1504 <range><lt>9.24</lt></range> 1505 </package> 1506 </affects> 1507 <description> 1508 <body xmlns="http://www.w3.org/1999/xhtml"> 1509 <p>An advisory from Opera reports:</p> 1510 <blockquote cite="http://www.opera.com/support/search/view/866/"> 1511 <p>If a user has configured Opera to use an external newsgroup 1512 client or e-mail application, specially crafted Web pages can 1513 cause Opera to run that application incorrectly. In some cases 1514 this can lead to execution of arbitrary code.</p> 1515 </blockquote> 1516 <blockquote cite="http://www.opera.com/support/search/view/867/"> 1517 <p>When accesing frames from different Web sites, specially crafted 1518 scripts can bypass the same-origin policy, and overwrite functions 1519 from those frames. If scripts on the page then run those functions, 1520 this can cause the script of the attacker's choice to run in the 1521 context of the target Web site.</p> 1522 </blockquote> 1523 </body> 1524 </description> 1525 <references> 1526 <cvename>CVE-2007-5540</cvename> 1527 <cvename>CVE-2007-5541</cvename> 1528 <url>http://www.opera.com/support/search/view/866/</url> 1529 <url>http://www.opera.com/support/search/view/867/</url> 1530 <url>http://secunia.com/advisories/27277/</url> 1531 </references> 1532 <dates> 1533 <discovery>2007-10-17</discovery> 1534 <entry>2007-10-25</entry> 1535 </dates> 1536 </vuln> 1537 1538 <vuln vid="9c00d446-8208-11dc-9283-0016179b2dd5"> 1539 <topic>drupal --- multiple vulnerabilities</topic> 1540 <affects> 1541 <package> 1542 <name>drupal4</name> 1543 <range><lt>4.7.8</lt></range> 1544 </package> 1545 <package> 1546 <name>drupal5</name> 1547 <range><lt>5.3</lt></range> 1548 </package> 1549 </affects> 1550 <description> 1551 <body xmlns="http://www.w3.org/1999/xhtml"> 1552 <p>The Drupal Project reports:</p> 1553 <blockquote cite="http://drupal.org/node/184315"> 1554 <p>In some circumstances Drupal allows user-supplied data to 1555 become part of response headers. As this user-supplied data 1556 is not always properly escaped, this can be exploited by 1557 malicious users to execute HTTP response splitting attacks 1558 which may lead to a variety of issues, among them cache 1559 poisoning, cross-user defacement and injection of arbitrary 1560 code.</p> 1561 </blockquote> 1562 <blockquote cite="http://drupal.org/node/184316"> 1563 <p>The Drupal installer allows any visitor to provide credentials 1564 for a database when the site's own database is not reachable. This 1565 allows attackers to run arbitrary code on the site's server. 1566 An immediate workaround is the removal of the file install.php 1567 in the Drupal root directory.</p> 1568 </blockquote> 1569 <blockquote cite="http://drupal.org/node/184320"> 1570 <p>The allowed extension list of the core Upload module contains 1571 the extension HTML by default. Such files can be used to execute 1572 arbitrary script code in the context of the affected site when a 1573 user views the file. Revoking upload permissions or removing the 1574 .html extension from the allowed extension list will stop uploads 1575 of malicious files. but will do nothing to protect your site 1576 againstfiles that are already present. Carefully inspect the file 1577 system path for any HTML files. We recommend you remove any HTML 1578 file you did not update yourself. You should look for , CSS 1579 includes, Javascript includes, and onerror="" attributes if 1580 you need to review files individually.</p> 1581 </blockquote> 1582 <blockquote cite="http://drupal.org/node/184348"> 1583 <p>The Drupal Forms API protects against cross site request 1584 forgeries (CSRF), where a malicious site can cause a user 1585 to unintentionally submit a form to a site where he is 1586 authenticated. The user deletion form does not follow the 1587 standard Forms API submission model and is therefore not 1588 protected against this type of attack. A CSRF attack may 1589 result in the deletion of users.</p> 1590 </blockquote> 1591 <blockquote cite="http://drupal.org/node/184354"> 1592 <p>The publication status of comments is not passed during the 1593 hook_comments API operation, causing various modules that rely 1594 on the publication status (such as Organic groups, or Subscriptions) 1595 to mail out unpublished comments.</p> 1596 </blockquote> 1597 </body> 1598 </description> 1599 <references> 1600 <cvename>CVE-2007-5597</cvename> 1601 <cvename>CVE-2007-5596</cvename> 1602 <cvename>CVE-2007-5595</cvename> 1603 <cvename>CVE-2007-5594</cvename> 1604 <cvename>CVE-2007-5593</cvename> 1605 <url>http://drupal.org/node/184315</url> 1606 <url>http://drupal.org/node/184316</url> 1607 <url>http://drupal.org/node/184348</url> 1608 <url>http://drupal.org/node/184354</url> 1609 <url>http://drupal.org/node/184320</url> 1610 <url>http://secunia.com/advisories/27292</url> 1611 <url>http://secunia.com/advisories/27292</url> 1612 <url>http://secunia.com/advisories/27292</url> 1613 <url>http://secunia.com/advisories/27290</url> 1614 <url>http://secunia.com/advisories/27290</url> 1615 </references> 1616 <dates> 1617 <discovery>2007-10-17</discovery> 1618 <entry>2007-10-24</entry> 1619 </dates> 1620 </vuln> 1621 1622 <vuln vid="3a81017a-8154-11dc-9283-0016179b2dd5"> 1623 <topic>ldapscripts -- Command Line User Credentials Disclosure</topic> 1624 <affects> 1625 <package> 1626 <name>ldapscripts</name> 1627 <range><lt>1.7.1</lt></range> 1628 </package> 1629 </affects> 1630 <description> 1631 <body xmlns="http://www.w3.org/1999/xhtml"> 1632 <p>Ganael Laplanche reports:</p> 1633 <blockquote cite="http://sourceforge.net/project/shownotes.php?group_id=156483&release_id=546600"> 1634 <p>Up to now, each ldap* command was called with the -w parameter, 1635 which allows to specify the bind password on the command line. 1636 Unfortunately, this could make the password appear to anybody 1637 performing a `ps` during the call. This is now avoided by using 1638 the -y parameter and a password file.</p> 1639 </blockquote> 1640 </body> 1641 </description> 1642 <references> 1643 <url>http://sourceforge.net/project/shownotes.php?group_id=156483&release_id=546600</url> 1644 <url>http://secunia.com/advisories/27111</url> 1645 <cvename>CVE-2007-5373</cvename> 1646 </references> 1647 <dates> 1648 <discovery>2007-10-09</discovery> 1649 <entry>2007-10-23</entry> 1650 </dates> 1651 </vuln> 1652 1653 <vuln vid="e24797af-803d-11dc-b787-003048705d5a"> 1654 <topic>firefox -- OnUnload Javascript browser entrapment vulnerability</topic> 1655 <affects> 1656 <package> 1657 <name>firefox</name> 1658 <range><lt>2.0.0.8,1</lt></range> 1659 </package> 1660 <package> 1661 <name>linux-firefox</name> 1662 <range><lt>2.0.0.8</lt></range> 1663 </package> 1664 <package> 1665 <name>seamonkey</name> 1666 <name>linux-seamonkey</name> 1667 <range><lt>1.1.5</lt></range> 1668 </package> 1669 </affects> 1670 <description> 1671 <body xmlns="http://www.w3.org/1999/xhtml"> 1672 <p>RedHat reports:</p> 1673 <blockquote cite="https://rhn.redhat.com/errata/RHSA-2007-0979.html"> 1674 <p>Several flaws were found in the way in which Firefox 1675 displayed malformed web content. A web page containing 1676 specially-crafted content could potentially trick a user 1677 into surrendering sensitive information. (CVE-2007-1095, 1678 CVE-2007-3844, CVE-2007-3511, CVE-2007-5334)</p> 1679 </blockquote> 1680 </body> 1681 </description> 1682 <references> 1683 <cvename>CVE-2007-1095</cvename> 1684 </references> 1685 <dates> 1686 <discovery>2007-10-19</discovery> 1687 <entry>2007-10-22</entry> 1688 <modified>2007-10-23</modified> 1689 </dates> 1690 </vuln> 1691 1692 <vuln vid="498a8731-7cfc-11dc-96e6-0012f06707f0"> 1693 <topic>phpmyadmin -- cross-site scripting vulnerability</topic> 1694 <affects> 1695 <package> 1696 <name>phpMyAdmin</name> 1697 <range><lt>2.11.1.2</lt></range> 1698 </package> 1699 </affects> 1700 <description> 1701 <body xmlns="http://www.w3.org/1999/xhtml"> 1702 <p>The DigiTrust Group discovered serious XSS vulnerability in 1703 the phpMyAdmin server_status.php script. According to their 1704 report</p> 1705 <blockquote cite="http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html"> 1706 <p>vulnerability can be exploited to execute arbitrary HTML and 1707 script code in a user's browser session in context of an affected 1708 site.</p> 1709 </blockquote> 1710 </body> 1711 </description> 1712 <references> 1713 <cvename>CVE-2007-5589</cvename> 1714 <url>http://www.digitrustgroup.com/advisories/TDG-advisory071015a.html</url> 1715 <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-6</url> 1716 </references> 1717 <dates> 1718 <discovery>2007-10-17</discovery> 1719 <entry>2007-10-17</entry> 1720 <modified>2010-05-12</modified> 1721 </dates> 1722 </vuln> 1723 1724 <vuln vid="51b51d4a-7c0f-11dc-9e47-0011d861d5e2"> 1725 <topic>phpmyadmin -- cross-site scripting vulnerability</topic> 1726 <affects> 1727 <package> 1728 <name>phpMyAdmin</name> 1729 <range><lt>2.11.1.1</lt></range> 1730 </package> 1731 </affects> 1732 <description> 1733 <body xmlns="http://www.w3.org/1999/xhtml"> 1734 <p>SecurityFocus reports:</p> 1735 <blockquote cite="http://www.securityfocus.com/bid/26020/discuss"> 1736 <p>phpMyAdmin is prone to a cross-site scripting vulnerability 1737 because it fails to properly sanitize user-supplied input.</p> 1738 <p>An attacker may leverage this issue to execute arbitrary script 1739 code in the browser of an unsuspecting user in the context of the 1740 affected site. This may help the attacker steal potentially 1741 sensitive information and launch other attacks.</p> 1742 </blockquote> 1743 </body> 1744 </description> 1745 <references> 1746 <cvename>CVE-2007-5386</cvename> 1747 <url>http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-5</url> 1748 <url>http://www.digitrustgroup.com/advisories/TDG-advisory071009a</url> 1749 <url>http://secunia.com/advisories/27173</url> 1750 <bid>26020</bid> 1751 </references> 1752 <dates> 1753 <discovery>2007-10-12</discovery> 1754 <entry>2007-10-16</entry> 1755 <modified>2007-10-20</modified> 1756 </dates> 1757 </vuln> 1758 1759 <vuln vid="7453c85d-7830-11dc-b4c8-0016179b2dd5"> 1760 <topic>nagios-plugins -- Long Location Header Buffer Overflow Vulnerability</topic> 1761 <affects> 1762 <package> 1763 <name>nagios-plugins</name> 1764 <range><lt>1.4.10,1</lt></range> 1765 </package> 1766 </affects> 1767 <description> 1768 <body xmlns="http://www.w3.org/1999/xhtml"> 1769 <p>A Secunia Advisory reports:</p> 1770 <blockquote cite="http://secunia.com/advisories/27124/"> 1771 <p>The vulnerability is caused due to a boundary error within the 1772 redir() function in check_http.c when processing HTTP Location: 1773 header information. This can be exploited to cause a buffer overflow 1774 by returning an overly long string in the "Location:" header to a 1775 vulnerable system.</p> 1776 </blockquote> 1777 </body> 1778 </description> 1779 <references> 1780 <url>http://sourceforge.net/forum/forum.php?forum_id=740172</url> 1781 <url>http://secunia.com/advisories/27124/</url> 1782 <cvename>CVE-2007-5198</cvename> 1783 </references> 1784 <dates> 1785 <discovery>2007-09-28</discovery> 1786 <entry>2007-10-11</entry> 1787 </dates> 1788 </vuln> 1789 1790 <vuln vid="172acf78-780c-11dc-b3f4-0016179b2dd5"> 1791 <topic>png -- multiple vulnerabilities</topic> 1792 <affects> 1793 <package> 1794 <name>png</name> 1795 <range><lt>1.2.22</lt></range> 1796 </package> 1797 </affects> 1798 <description> 1799 <body xmlns="http://www.w3.org/1999/xhtml"> 1800 <p>A Secunia Advisory reports:</p> 1801 <blockquote cite="http://secunia.com/advisories/27093/"> 1802 <p>Some vulnerabilities have been reported in libpng, which can be 1803 exploited by malicious people to cause a DoS (Denial of 1804 Service).</p> 1805 <p>Certain errors within libpng, including a logical NOT instead of a 1806 bitwise NOT in pngtrtran.c, an error in the 16bit cheap transparency 1807 extension, and an incorrect use of sizeof() may be exploited to 1808 crash an application using the library.</p> 1809 <p>Various out-of-bounds read errors exist within the functions 1810 png_handle_pCAL(), png_handle_sCAL(), png_push_read_tEXt(), 1811 png_handle_iTXt(), and png_handle_ztXt(), which may be exploited by 1812 exploited to crash an application using the library.</p> 1813 </blockquote> 1814 <blockquote cite="http://secunia.com/advisories/27130/"> 1815 <p>The vulnerability is caused due to an off-by-one error within 1816 the ICC profile chunk handling, which potentially can be 1817 exploited to crash an application using the library.</p> 1818 </blockquote> 1819 </body> 1820 </description> 1821 <references> 1822 <url>http://secunia.com/advisories/27093/</url> 1823 <url>http://secunia.com/advisories/27130/</url> 1824 <cvename>CVE-2007-5267</cvename> 1825 <cvename>CVE-2007-5266</cvename> 1826 <cvename>CVE-2007-5268</cvename> 1827 <cvename>CVE-2007-5269</cvename> 1828 </references> 1829 <dates> 1830 <discovery>2007-10-08</discovery> 1831 <entry>2007-10-11</entry> 1832 </dates> 1833 </vuln> 1834 1835 <vuln vid="f5b29ec0-71f9-11dc-8c6a-00304881ac9a"> 1836 <topic>ImageMagick -- multiple vulnerabilities</topic> 1837 <affects> 1838 <package> 1839 <name>ImageMagick</name> 1840 <name>ImageMagick-nox11</name> 1841 <range><lt>6.3.5.9</lt></range> 1842 </package> 1843 </affects> 1844 <description> 1845 <body xmlns="http://www.w3.org/1999/xhtml"> 1846 <p>Multiple vulnerabilities have been discovered in ImageMagick.</p> 1847 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4985"> 1848 <p>ImageMagick before 6.3.5-9 allows context-dependent attackers 1849 to cause a denial of service via a crafted image file that 1850 triggers (1) an infinite loop in the ReadDCMImage function, 1851 related to ReadBlobByte function calls; or (2) an infinite 1852 loop in the ReadXCFImage function, related to ReadBlobMSBLong 1853 function calls.</p> 1854 </blockquote> 1855 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4986"> 1856 <p>Multiple integer overflows in ImageMagick before 6.3.5-9 1857 allow context-dependent attackers to execute arbitrary code 1858 via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) 1859 .xwd image file, which triggers a heap-based buffer overflow.</p> 1860 </blockquote> 1861 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4987"> 1862 <p>Off-by-one error in the ReadBlobString function in blob.c in 1863 ImageMagick before 6.3.5-9 allows context-dependent attackers 1864 to execute arbitrary code via a crafted image file, which 1865 triggers the writing of a '\0' character to an out-of-bounds 1866 address.</p> 1867 </blockquote> 1868 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4988"> 1869 <p>Sign extension error in the ReadDIBImage function in 1870 ImageMagick before 6.3.5-9 allows context-dependent attackers 1871 to execute arbitrary code via a crafted width value in an 1872 image file, which triggers an integer overflow and a 1873 heap-based buffer overflow.</p> 1874 </blockquote> 1875 </body> 1876 </description> 1877 <references> 1878 <cvename>CVE-2007-4985</cvename> 1879 <cvename>CVE-2007-4986</cvename> 1880 <cvename>CVE-2007-4987</cvename> 1881 <cvename>CVE-2007-4988</cvename> 1882 <url>http://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.html</url> 1883 </references> 1884 <dates> 1885 <discovery>2007-09-19</discovery> 1886 <entry>2007-10-10</entry> 1887 </dates> 1888 </vuln> 1889 1890 <vuln vid="c93e4d41-75c5-11dc-b903-0016179b2dd5"> 1891 <topic>jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented</topic> 1892 <affects> 1893 <package> 1894 <name>jdk</name> 1895 <range><ge>1.3.0</ge><lt>1.6.0.3p3</lt></range> 1896 <range><ge>1.5.0,1</ge><lt>1.5.0.13p7,1</lt></range> 1897 </package> 1898 <package> 1899 <name>linux-blackdown-jdk</name> 1900 <range><ge>1.3.0</ge></range> 1901 </package> 1902 <package> 1903 <name>linux-sun-jdk</name> 1904 <range><ge>1.3.0</ge><lt>1.3.1.20</lt></range> 1905 <range><ge>1.4.0</ge><lt>1.4.2.16</lt></range> 1906 <range><eq>1.5.0.b1</eq></range> 1907 <range><eq>1.5.0.b1,1</eq></range> 1908 <range><ge>1.5.0,2</ge><lt>1.5.0.13,2</lt></range> 1909 <range><ge>1.6.0</ge><lt>1.6.0.03</lt></range> 1910 </package> 1911 </affects> 1912 <description> 1913 <body xmlns="http://www.w3.org/1999/xhtml"> 1914 <p>SUN reports:</p> 1915 <blockquote cite="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1"> 1916 <p>A vulnerability in the Java Runtime Environment (JRE) with applet 1917 caching may allow an untrusted applet that is downloaded from a 1918 malicious website to make network connections to network services 1919 on machines other than the one that the applet was downloaded from. 1920 This may allow network resources (such as web pages) and 1921 vulnerabilities (that exist on these network services) which are not 1922 otherwise normally accessible to be accessed or exploited.</p> 1923 </blockquote> 1924 </body> 1925 </description> 1926 <references> 1927 <url>http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1</url> 1928 <cvename>CVE-2007-5232</cvename> 1929 </references> 1930 <dates> 1931 <discovery>2007-10-03</discovery> 1932 <entry>2007-10-08</entry> 1933 <modified>2007-11-16</modified> 1934 </dates> 1935 </vuln> 1936 1937 <vuln vid="a5f667db-7596-11dc-8b7a-0019b944b34e"> 1938 <topic>xfs -- multiple vulnerabilities</topic> 1939 <affects> 1940 <package> 1941 <name>xfs</name> 1942 <range><lt>1.0.5,1</lt></range> 1943 </package> 1944 </affects> 1945 <description> 1946 <body xmlns="http://www.w3.org/1999/xhtml"> 1947 <p>Matthieu Herrb reports:</p> 1948 <blockquote cite="http://lists.freedesktop.org/archives/xorg/2007-October/028899.html"> 1949 <h1>Problem Description:</h1> 1950 <p>Several vulnerabilities have been identified in xfs, the X font 1951 server. The QueryXBitmaps and QueryXExtents protocol requests 1952 suffer from lack of validation of their 'length' parameters.</p> 1953 <h1>Impact:</h1> 1954 <p>On most modern systems, the font server is accessible only for 1955 local clients and runs with reduced privileges, but on some 1956 systems it may still be accessible from remote clients and 1957 possibly running with root privileges, creating an opportunity 1958 for remote privilege escalation.</p> 1959 </blockquote> 1960 </body> 1961 </description> 1962 <references> 1963 <cvename>CVE-2007-4568</cvename> 1964 <url>http://lists.freedesktop.org/archives/xorg/2007-October/028899.html</url> 1965 </references> 1966 <dates> 1967 <discovery>2007-10-02</discovery> 1968 <entry>2007-10-08</entry> 1969 </dates> 1970 </vuln> 1971 1972 <vuln vid="a058d6fa-7325-11dc-ae10-0016179b2dd5"> 1973 <topic>tcl/tk -- buffer overflow in ReadImage function</topic> 1974 <affects> 1975 <package> 1976 <name>tk</name> 1977 <name>tk-threads</name> 1978 <range><gt>8.2.*</gt><lt>8.2.3_11</lt></range> 1979 <range><gt>8.3.*</gt><lt>8.3.5_10</lt></range> 1980 <range><gt>8.4.*,2</gt><lt>8.4.16,2</lt></range> 1981 </package> 1982 </affects> 1983 <description> 1984 <body xmlns="http://www.w3.org/1999/xhtml"> 1985 <p>A Buffer overflow in the ReadImage function in generic/tkImgGIF.c 1986 in Tcl/Tk, allows remote attackers to execute arbitrary code via 1987 multi-frame interlaced GIF files in which later frames are smaller 1988 than the first.</p> 1989 </body> 1990 </description> 1991 <references> 1992 <url>http://secunia.com/advisories/26942</url> 1993 <url>http://sourceforge.net/project/shownotes.php?release_id=541207</url> 1994 <cvename>CVE-2007-5137</cvename> 1995 </references> 1996 <dates> 1997 <discovery>2007-09-27</discovery> 1998 <entry>2007-10-05</entry> 1999 <modified>2011-09-04</modified> 2000 </dates> 2001 </vuln> 2002 2003 <vuln vid="91ed69f9-72c7-11dc-981a-001921ab2fa4"> 2004 <topic>firebird -- multiple remote buffer overflow vulnerabilities</topic> 2005 <affects> 2006 <package> 2007 <name>firebird-server</name> 2008 <range><ge>1.*</ge><lt>1.5.5</lt></range> 2009 <range><ge>2.0.*</ge><lt>2.0.3</lt></range> 2010 </package> 2011 </affects> 2012 <description> 2013 <body xmlns="http://www.w3.org/1999/xhtml"> 2014 <p>RISE Security reports:</p> 2015 <blockquote cite="http://risesecurity.org/advisory/RISE-2007003/"> 2016 <p>There exists multiple vulnerabilities within functions 2017 of Firebird Relational Database, which when properly 2018 exploited can lead to remote compromise of the vulnerable 2019 system.</p> 2020 </blockquote> 2021 </body> 2022 </description> 2023 <references> 2024 <bid>25925</bid> 2025 </references> 2026 <dates> 2027 <discovery>2007-10-03</discovery> 2028 <entry>2007-10-04</entry> 2029 </dates> 2030 </vuln> 2031 2032 <vuln vid="15ec9123-7061-11dc-b372-001921ab2fa4"> 2033 <topic>id3lib -- insecure temporary file creation</topic> 2034 <affects> 2035 <package> 2036 <name>id3lib</name> 2037 <range><lt>3.8.3_4</lt></range> 2038 </package> 2039 </affects> 2040 <description> 2041 <body xmlns="http://www.w3.org/1999/xhtml"> 2042 <p>Debian Bug report log reports:</p> 2043 <blockquote cite="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=438540"> 2044 <p>When tagging file $foo, a temporary copy of the file is 2045 created, and for some reason, libid3 doesn't use mkstemp 2046 but just creates $foo.XXXXXX literally, without any checking.</p> 2047 <p>This would silently truncate and overwrite an existing 2048 $foo.XXXXXX.</p> 2049 </blockquote> 2050 </body> 2051 </description> 2052 <references> 2053 <bid>25372</bid> 2054 <cvename>CVE-2007-4460</cvename> 2055 </references> 2056 <dates> 2057 <discovery>2007-08-20</discovery> 2058 <entry>2007-10-01</entry> 2059 <modified>2007-10-01</modified> 2060 </dates> 2061 </vuln> 2062 2063 <vuln vid="c9c14242-6843-11dc-82b6-02e0185f8d72"> 2064 <topic>mediawiki -- cross site scripting vulnerability</topic> 2065 <affects> 2066 <package> 2067 <name>mediawiki</name> 2068 <range><gt>1.10.0</gt><lt>1.10.2</lt></range> 2069 <range><gt>1.9.0</gt><lt>1.9.4</lt></range> 2070 <range><gt>1.8.0</gt><lt>1.8.5</lt></range> 2071 </package> 2072 </affects> 2073 <description> 2074 <body xmlns="http://www.w3.org/1999/xhtml"> 2075 <p>The MediaWiki development team reports:</p> 2076 <blockquote cite="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html"> 2077 <p>A possible HTML/XSS injection vector in the API 2078 pretty-printing mode has been found and fixed.</p> 2079 <p>The vulnerability may be worked around in an unfixed version 2080 by simply disabling the API interface if it is not in use, by 2081 adding this to LocalSettings.php:</p> 2082 <p>$wgEnableAPI = false;</p> 2083 <p>(This is the default setting in 1.8.x.)</p> 2084 </blockquote> 2085 </body> 2086 </description> 2087 <references> 2088 <cvename>CVE-2007-4828</cvename> 2089 <url>http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-September/000067.html</url> 2090 </references> 2091 <dates> 2092 <discovery>2007-09-10</discovery> 2093 <entry>2007-09-21</entry> 2094 <modified>2007-10-10</modified> 2095 </dates> 2096 </vuln> 2097 2098 <vuln vid="63347ee7-6841-11dc-82b6-02e0185f8d72"> 2099 <topic>wordpress -- remote sql injection vulnerability</topic> 2100 <affects> 2101 <package> 2102 <name>wordpress</name> 2103 <range><lt>2.2.3,1</lt></range> 2104 </package> 2105 <package> 2106 <name>de-wordpress</name> 2107 <name>zh-wordpress</name> 2108 <range><lt>2.2.3</lt></range> 2109 </package> 2110 <package> 2111 <name>wordpress-mu</name> 2112 <range><lt>1.2.4,2</lt></range> 2113 </package> 2114 </affects> 2115 <description> 2116 <body xmlns="http://www.w3.org/1999/xhtml"> 2117 <p>Alexander Concha reports:</p> 2118 <blockquote cite="http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html"> 2119 <p>While testing WordPress, it has been discovered a SQL 2120 Injection vulnerability that allows an attacker to retrieve 2121 remotely any user credentials from a vulnerable site, this 2122 bug is caused because of early database escaping and the 2123 lack of validation in query string like parameters.</p> 2124 </blockquote> 2125 </body> 2126 </description> 2127 <references> 2128 <cvename>CVE-2007-4894</cvename> 2129 <url>http://www.buayacorp.com/files/wordpress/wordpress-sql-injection-advisory.html</url> 2130 </references> 2131 <dates> 2132 <discovery>2007-09-10</discovery> 2133 <entry>2007-09-21</entry> 2134 </dates> 2135 </vuln> 2136 2137 <vuln vid="2bc96f18-683f-11dc-82b6-02e0185f8d72"> 2138 <topic>samba -- nss_info plugin privilege escalation vulnerability</topic> 2139 <affects> 2140 <package> 2141 <name>samba</name> 2142 <range><lt>3.0.26a</lt></range> 2143 <range><gt>*,1</gt><lt>3.0.26a,1</lt></range> 2144 </package> 2145 </affects> 2146 <description> 2147 <body xmlns="http://www.w3.org/1999/xhtml"> 2148 <p>The Samba development team reports:</p> 2149 <blockquote cite="http://www.samba.org/samba/security/CVE-2007-4138.html"> 2150 <p>The idmap_ad.so library provides an nss_info extension to 2151 Winbind for retrieving a user's home directory path, login 2152 shell and primary group id from an Active Directory domain 2153 controller. This functionality is enabled by defining the 2154 "winbind nss info" smb.conf option to either "sfu" or 2155 "rfc2307".</p> 2156 <p>Both the Windows "Identity Management for Unix" and 2157 "Services for Unix" MMC plug-ins allow a user to be assigned 2158 a primary group for Unix clients that differs from the user's 2159 Windows primary group. When the rfc2307 or sfu nss_info plugin 2160 has been enabled, in the absence of either the RFC2307 or SFU 2161 primary group attribute, Winbind will assign a primary group ID 2162 of 0 to the domain user queried using the getpwnam() C library 2163 call.</p> 2164 </blockquote> 2165 </body> 2166 </description> 2167 <references> 2168 <cvename>CVE-2007-4138</cvename> 2169 <url>http://www.samba.org/samba/security/CVE-2007-4138.html</url> 2170 </references> 2171 <dates> 2172 <discovery>2007-09-11</discovery> 2173 <entry>2007-09-21</entry> 2174 <modified>2008-09-26</modified> 2175 </dates> 2176 </vuln> 2177 2178 <vuln vid="75231c63-f6a2-499d-8e27-787773bda284"> 2179 <topic>bugzilla -- multiple vulnerabilities</topic> 2180 <affects> 2181 <package> 2182 <name>bugzilla</name> 2183 <name>ja-bugzilla</name> 2184 <range><ge>2.20.*</ge><lt>2.22.3</lt></range> 2185 <range><ge>3.*</ge><lt>3.0.1</lt></range> 2186 </package> 2187 </affects> 2188 <description> 2189 <body xmlns="http://www.w3.org/1999/xhtml"> 2190 <p>A Bugzilla Security Advisory reports:</p> 2191 <blockquote cite="http://www.bugzilla.org/security/2.20.4/"> 2192 <p>This advisory covers three security issues that have recently been 2193 fixed in the Bugzilla code:</p> 2194 <ul> 2195 <li>A possible cross-site scripting (XSS) vulnerability when filing 2196 bugs using the guided form.</li> 2197 <li>When using email_in.pl, insufficiently escaped data may be 2198 passed to sendmail.</li> 2199 <li>Users using the WebService interface may access Bugzilla's 2200 time-tracking fields even if they normally cannot see them.</li> 2201 </ul> 2202 <p>We strongly advise that 2.20.x and 2.22.x users should upgrade to 2203 2.20.5 and 2.22.3 respectively. 3.0 users, and users of 2.18.x or 2204 below, should upgrade to 3.0.1.</p> 2205 </blockquote> 2206 </body> 2207 </description> 2208 <references> 2209 <bid>25425</bid> 2210 <cvename>CVE-2007-4538</cvename> 2211 <cvename>CVE-2007-4539</cvename> 2212 <cvename>CVE-2007-4543</cvename> 2213 <url>http://www.bugzilla.org/security/2.20.4/</url> 2214 </references> 2215 <dates> 2216 <discovery>2007-08-23</discovery> 2217 <entry>2007-09-21</entry> 2218 </dates> 2219 </vuln> 2220 2221 <vuln vid="b6f6da57-680a-11dc-b350-001921ab2fa4"> 2222 <topic>clamav -- multiple remote Denial of Service vulnerabilities</topic> 2223 <affects> 2224 <package> 2225 <name>clamav</name> 2226 <range><lt>0.91.2</lt></range> 2227 </package> 2228 </affects> 2229 <description> 2230 <body xmlns="http://www.w3.org/1999/xhtml"> 2231 <p>BugTraq reports:</p> 2232 <blockquote cite="http://www.securityfocus.com/bid/25398"> 2233 <p>ClamAV is prone to multiple denial-of-service vulnerabilities.</p> 2234 <p>A successful attack may allow an attacker to crash the 2235 application and deny service to users.</p> 2236 </blockquote> 2237 </body> 2238 </description> 2239 <references> 2240 <bid>25398</bid> 2241 <cvename>CVE-2007-4510</cvename> 2242 </references> 2243 <dates> 2244 <discovery>2007-08-21</discovery> 2245 <entry>2007-09-21</entry> 2246 </dates> 2247 </vuln> 2248 2249 <vuln vid="12488805-6773-11dc-8be8-02e0185f8d72"> 2250 <topic>coppermine -- multiple vulnerabilities</topic> 2251 <affects> 2252 <package> 2253 <name>coppermine</name> 2254 <range><lt>1.4.13</lt></range> 2255 </package> 2256 </affects> 2257 <description> 2258 <body xmlns="http://www.w3.org/1999/xhtml"> 2259 <p>The coppermine development team reports two vulnerabilities 2260 with the coppermine application. These vulnerabilities are 2261 caused by improper checking of the log variable in "viewlog.php" 2262 and improper checking of the referer variable in "mode.php". 2263 This could allow local file inclusion, potentially disclosing 2264 valuable information and could lead to an attacker conducting 2265 a cross site scripting attack against the targeted site.</p> 2266 </body> 2267 </description> 2268 <references> 2269 <cvename>CVE-2007-4976</cvename> 2270 <cvename>CVE-2007-4977</cvename> 2271 <url>http://coppermine-gallery.net/forum/index.php?topic=46847.0</url> 2272 </references> 2273 <dates> 2274 <discovery>2007-09-14</discovery> 2275 <entry>2007-09-20</entry> 2276 <modified>2010-05-12</modified> 2277 </dates> 2278 </vuln> 2279 2280 <vuln vid="e595e170-6771-11dc-8be8-02e0185f8d72"> 2281 <topic>openoffice -- arbitrary command execution vulnerability</topic> 2282 <affects> 2283 <package> 2284 <name>openoffice</name> 2285 <range><gt>0</gt></range> 2286 </package> 2287 </affects> 2288 <description> 2289 <body xmlns="http://www.w3.org/1999/xhtml"> 2290 <p>iDefense reports:</p> 2291 <blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593"> 2292 <p>Remote exploitation of multiple integer overflow 2293 vulnerabilities within OpenOffice, as included in various 2294 vendors' operating system distributions, allows attackers to 2295 execute arbitrary code.</p> 2296 <p>These vulnerabilities exist within the TIFF parsing code of 2297 the OpenOffice suite. When parsing the TIFF directory entries 2298 for certain tags, the parser uses untrusted values from the 2299 file to calculate the amount of memory to allocate. By 2300 providing specially crafted values, an integer overflow occurs 2301 in this calculation. This results in the allocation of a 2302 buffer of insufficient size, which in turn leads to a heap 2303 overflow.</p> 2304 </blockquote> 2305 </body> 2306 </description> 2307 <references> 2308 <cvename>CVE-2007-2834</cvename> 2309 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593</url> 2310 </references> 2311 <dates> 2312 <discovery>2007-09-19</discovery> 2313 <entry>2007-09-20</entry> 2314 </dates> 2315 </vuln> 2316 2317 <vuln vid="f8d3689e-6770-11dc-8be8-02e0185f8d72"> 2318 <topic>bugzilla -- "createmailregexp" security bypass vulnerability</topic> 2319 <affects> 2320 <package> 2321 <name>bugzilla</name> 2322 <range><ge>3.*</ge><lt>3.0.2</lt></range> 2323 </package> 2324 </affects> 2325 <description> 2326 <body xmlns="http://www.w3.org/1999/xhtml"> 2327 <p>The Bugzilla development team reports:</p> 2328 <blockquote cite="http://www.bugzilla.org/security/3.0.1/"> 2329 <p>Bugzilla::WebService::User::offer_account_by_email does 2330 not check the "createemailregexp" parameter, and thus 2331 allows users to create accounts who would normally be 2332 denied account creation. The "emailregexp" parameter is 2333 still checked. If you do not have the SOAP::Lite Perl 2334 module installed on your Bugzilla system, your system is 2335 not vulnerable (because the Bugzilla WebService will not 2336 be enabled).</p> 2337 </blockquote> 2338 </body> 2339 </description> 2340 <references> 2341 <cvename>CVE-2007-5038</cvename> 2342 <url>http://www.bugzilla.org/security/3.0.1/</url> 2343 </references> 2344 <dates> 2345 <discovery>2007-09-18</discovery> 2346 <entry>2007-09-20</entry> 2347 <modified>2010-05-12</modified> 2348 </dates> 2349 </vuln> 2350 2351 <vuln vid="14ad2a28-66d2-11dc-b25f-02e0185f8d72"> 2352 <topic>konquerer -- address bar spoofing</topic> 2353 <affects> 2354 <package> 2355 <name>kdebase</name> 2356 <range><lt>3.5.7_3</lt></range> 2357 </package> 2358 <package> 2359 <name>kdelibs</name> 2360 <range><lt>3.5.7_2</lt></range> 2361 </package> 2362 </affects> 2363 <description> 2364 <body xmlns="http://www.w3.org/1999/xhtml"> 2365 <p>The KDE development team reports:</p> 2366 <blockquote cite="http://www.kde.org/info/security/advisory-20070914-1.txt"> 2367 <p>The Konqueror address bar is vulnerable to spoofing attacks 2368 that are based on embedding white spaces in the url. In addition 2369 the address bar could be tricked to show an URL which it is 2370 intending to visit for a short amount of time instead of the 2371 current URL.</p> 2372 </blockquote> 2373 </body> 2374 </description> 2375 <references> 2376 <cvename>CVE-2007-3820</cvename> 2377 <cvename>CVE-2007-4224</cvename> 2378 <cvename>CVE-2007-4225</cvename> 2379 <url>http://www.kde.org/info/security/advisory-20070914-1.txt</url> 2380 </references> 2381 <dates> 2382 <discovery>2007-09-14</discovery> 2383 <entry>2007-09-19</entry> 2384 </dates> 2385 </vuln> 2386 2387 <vuln vid="79b616d0-66d1-11dc-b25f-02e0185f8d72"> 2388 <topic>kdm -- passwordless login vulnerability</topic> 2389 <affects> 2390 <package> 2391 <name>kdebase3</name> 2392 <range><lt>3.5.7_3</lt></range> 2393 </package> 2394 </affects> 2395 <description> 2396 <body xmlns="http://www.w3.org/1999/xhtml"> 2397 <p>The KDE development team reports:</p> 2398 <blockquote cite="http://www.kde.org/info/security/advisory-20070919-1.txt"> 2399 <p>KDM can be tricked into performing a password-less login 2400 even for accounts with a password set under certain 2401 circumstances, namely autologin to be configured and 2402 "shutdown with password" enabled.</p> 2403 </blockquote> 2404 </body> 2405 </description> 2406 <references> 2407 <cvename>CVE-2007-4569</cvename> 2408 <url>http://www.kde.org/info/security/advisory-20070919-1.txt</url> 2409 </references> 2410 <dates> 2411 <discovery>2007-09-19</discovery> 2412 <entry>2007-09-19</entry> 2413 </dates> 2414 </vuln> 2415 2416 <vuln vid="209f0d75-4b5c-11dc-a6cd-000fb5066b20"> 2417 <topic>flyspray -- authentication bypass</topic> 2418 <affects> 2419 <package> 2420 <name>flyspray</name> 2421 <range><lt>0.9.9.2</lt></range> 2422 </package> 2423 </affects> 2424 <description> 2425 <body xmlns="http://www.w3.org/1999/xhtml"> 2426 <p>The Flyspray Project reports:</p> 2427 <blockquote cite="http://www.flyspray.org/fsa:1"> 2428 <p>Flyspray authentication system can be bypassed by sending a 2429 carefully crafted post request.</p> 2430 <p>To be vulnerable, PHP configuration directive output_buffering 2431 has to be disabled or set to a low value.</p> 2432 </blockquote> 2433 </body> 2434 </description> 2435 <references> 2436 <cvename>CVE-2007-1788</cvename> 2437 <url>http://www.flyspray.org/fsa:1</url> 2438 </references> 2439 <dates> 2440 <discovery>2007-03-13</discovery> 2441 <entry>2007-09-19</entry> 2442 </dates> 2443 </vuln> 2444 2445 <vuln vid="3ce8c7e2-66cf-11dc-b25f-02e0185f8d72"> 2446 <topic>mozilla -- code execution via Quicktime media-link files</topic> 2447 <affects> 2448 <package> 2449 <name>firefox</name> 2450 <range><lt>2.0.0.7,1</lt></range> 2451 </package> 2452 <package> 2453 <name>linux-firefox</name> 2454 <range><lt>2.0.0.7</lt></range> 2455 </package> 2456 <!-- Packages which probably will be upgraded --> 2457 <package> 2458 <name>seamonkey</name> 2459 <name>linux-seamonkey</name> 2460 <range><lt>1.1.5</lt></range> 2461 </package> 2462 <package> 2463 <name>linux-firefox-devel</name> 2464 <range><lt>3.0.a2007.12.12</lt></range> 2465 </package> 2466 <package> 2467 <name>linux-seamonkey-devel</name> 2468 <range><lt>2.0.a2007.12.12</lt></range> 2469 </package> 2470 <!-- Deprecated/old names --> 2471 <package> 2472 <name>firefox-ja</name> 2473 <name>linux-mozilla-devel</name> 2474 <name>linux-mozilla</name> 2475 <name>mozilla</name> 2476 <range><gt>0</gt></range> 2477 </package> 2478 </affects> 2479 <description> 2480 <body xmlns="http://www.w3.org/1999/xhtml"> 2481 <p>The Mozilla Foundation reports a vulnerability within the 2482 mozilla browser. This vulnerability also affects various 2483 other browsers like firefox and seamonkey. The vulnerability 2484 is caused by QuickTime Media-Link files that contain a qtnext 2485 attribute. This could allow an attacker to start the browser 2486 with arbitrary command-line options. This could allow the 2487 attacker to install malware, steal local data and possibly 2488 execute and/or do other arbitrary things within the users 2489 context.</p> 2490 </body> 2491 </description> 2492 <references> 2493 <cvename>CVE-2006-4965</cvename> 2494 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-28.html</url> 2495 </references> 2496 <dates> 2497 <discovery>2007-09-18</discovery> 2498 <entry>2007-09-19</entry> 2499 <modified>2007-12-14</modified> 2500 </dates> 2501 </vuln> 2502 2503 <vuln vid="71d903fc-602d-11dc-898c-001921ab2fa4"> 2504 <topic>php -- multiple vulnerabilities</topic> 2505 <affects> 2506 <package> 2507 <name>php5</name> 2508 <range><lt>5.2.4</lt></range> 2509 </package> 2510 <package> 2511 <name>php4</name> 2512 <range><lt>4.4.8</lt></range> 2513 </package> 2514 </affects> 2515 <description> 2516 <body xmlns="http://www.w3.org/1999/xhtml"> 2517 <p>The PHP development team reports:</p> 2518 <blockquote cite="http://www.php.net/releases/5_2_4.php"> 2519 <p>Security Enhancements and Fixes in PHP 5.2.4:</p> 2520 <ul> 2521 <li>Fixed a floating point exception inside wordwrap() (Reported 2522 by Mattias Bengtsson)</li> 2523 <li>Fixed several integer overflows inside the GD extension 2524 (Reported by Mattias Bengtsson)</li> 2525 <li>Fixed size calculation in chunk_split() (Reported by Gerhard 2526 Wagner)</li> 2527 <li>Fixed integer overflow in str[c]spn(). (Reported by Mattias 2528 Bengtsson)</li> 2529 <li>Fixed money_format() not to accept multiple %i or %n tokens. 2530 (Reported by Stanislav Malyshev)</li> 2531 <li>Fixed zend_alter_ini_entry() memory_limit interruption 2532 vulnerability. (Reported by Stefan Esser)</li> 2533 <li>Fixed INFILE LOCAL option handling with MySQL extensions not 2534 to be allowed when open_basedir or safe_mode is active. (Reported 2535 by Mattias Bengtsson)</li> 2536 <li>Fixed session.save_path and error_log values to be checked 2537 against open_basedir and safe_mode (CVE-2007-3378) (Reported by 2538 Maksymilian Arciemowicz)</li> 2539 <li>Fixed a possible invalid read in glob() win32 implementation 2540 (CVE-2007-3806) (Reported by shinnai)</li> 2541 <li>Fixed a possible buffer overflow in php_openssl_make_REQ 2542 (Reported by zatanzlatan at hotbrev dot com)</li> 2543 <li>Fixed an open_basedir bypass inside glob() function (Reported 2544 by dr at peytz dot dk)</li> 2545 <li>Fixed a possible open_basedir bypass inside session extension 2546 when the session file is a symlink (Reported by c dot i dot morris 2547 at durham dot ac dot uk)</li> 2548 <li>Improved fix for MOPB-03-2007.</li> 2549 <li>Corrected fix for CVE-2007-2872.</li> 2550 </ul> 2551 </blockquote> 2552 </body> 2553 </description> 2554 <references> 2555 <cvename>CVE-2007-2872</cvename> 2556 <cvename>CVE-2007-3378</cvename> 2557 <cvename>CVE-2007-3806</cvename> 2558 <cvename>CVE-2007-3996</cvename> 2559 <cvename>CVE-2007-3997</cvename> 2560 <cvename>CVE-2007-3998</cvename> 2561 <cvename>CVE-2007-4652</cvename> 2562 <cvename>CVE-2007-4657</cvename> 2563 <cvename>CVE-2007-4658</cvename> 2564 <cvename>CVE-2007-4659</cvename> 2565 <cvename>CVE-2007-4660</cvename> 2566 <cvename>CVE-2007-4661</cvename> 2567 <cvename>CVE-2007-4662</cvename> 2568 <cvename>CVE-2007-4663</cvename> 2569 <cvename>CVE-2007-4670</cvename> 2570 <url>http://www.php.net/releases/4_4_8.php</url> 2571 <url>http://www.php.net/releases/5_2_4.php</url> 2572 <url>http://secunia.com/advisories/26642</url> 2573 </references> 2574 <dates> 2575 <discovery>2007-08-30</discovery> 2576 <entry>2007-09-11</entry> 2577 <modified>2008-01-14</modified> 2578 </dates> 2579 </vuln> 2580 2581 <vuln vid="c115271d-602b-11dc-898c-001921ab2fa4"> 2582 <topic>apache -- multiple vulnerabilities</topic> 2583 <affects> 2584 <package> 2585 <name>apache</name> 2586 <range><gt>2.2.0</gt><lt>2.2.6</lt></range> 2587 <range><gt>2.0.0</gt><lt>2.0.61</lt></range> 2588 </package> 2589 </affects> 2590 <description> 2591 <body xmlns="http://www.w3.org/1999/xhtml"> 2592 <p>Apache HTTP server project reports:</p> 2593 <blockquote cite="http://www.apache.org/dist/httpd/Announcement2.2.html"> 2594 <p>The following potential security flaws are addressed:</p> 2595 <ul> 2596 <li>CVE-2007-3847: mod_proxy: Prevent reading past the end of a 2597 buffer when parsing date-related headers.</li> 2598 <li>CVE-2007-1863: mod_cache: Prevent a segmentation fault if 2599 attributes are listed in a Cache-Control header without any 2600 value.</li> 2601 <li>CVE-2007-3304: prefork, worker, event MPMs: Ensure that the 2602 parent process cannot be forced to kill processes outside its 2603 process group.</li> 2604 <li>CVE-2006-5752: mod_status: Fix a possible XSS attack against 2605 a site with a public server-status page and ExtendedStatus 2606 enabled, for browsers which perform charset "detection". 2607 Reported by Stefan Esser.</li> 2608 <li>CVE-2006-1862: mod_mem_cache: Copy headers into longer lived 2609 storage; header names and values could previously point to 2610 cleaned up storage.</li> 2611 </ul> 2612 </blockquote> 2613 </body> 2614 </description> 2615 <references> 2616 <cvename>CVE-2007-3847</cvename> 2617 <cvename>CVE-2007-1863</cvename> 2618 <cvename>CVE-2006-5752</cvename> 2619 <cvename>CVE-2007-3304</cvename> 2620 </references> 2621 <dates> 2622 <discovery>2007-09-07</discovery> 2623 <entry>2007-09-11</entry> 2624 </dates> 2625 </vuln> 2626 2627 <vuln vid="4b673ae7-5f9a-11dc-84dd-000102cc8983"> 2628 <topic>lighttpd -- FastCGI header overrun in mod_fastcgi</topic> 2629 <affects> 2630 <package> 2631 <name>lighttpd</name> 2632 <range><lt>1.4.18</lt></range> 2633 </package> 2634 </affects> 2635 <description> 2636 <body xmlns="http://www.w3.org/1999/xhtml"> 2637 <p>lighttpd maintainer reports:</p> 2638 <blockquote cite="http://www.lighttpd.net/assets/2007/9/9/lighttpd_sa_2007_12.txt"> 2639 <p>Lighttpd is prone to a header overflow when using the mod_fastcgi 2640 extension, this can lead to arbitrary code execution in the fastcgi 2641 application. For a detailed description of the bug see the external 2642 reference.</p> 2643 <p>This bug was found by Mattias Bengtsson and Philip Olausson</p> 2644 </blockquote> 2645 </body> 2646 </description> 2647 <references> 2648 <url>http://www.lighttpd.net/assets/2007/9/9/lighttpd_sa_2007_12.txt</url> 2649 <url>http://secweb.se/en/advisories/lighttpd-fastcgi-remote-vulnerability/</url> 2650 <cvename>CVE-2007-4727</cvename> 2651 </references> 2652 <dates> 2653 <discovery>2007-09-09</discovery> 2654 <entry>2007-09-10</entry> 2655 </dates> 2656 </vuln> 2657 2658 <vuln vid="f14ad681-5b88-11dc-812d-0011098b2f36"> 2659 <topic>rkhunter -- insecure temporary file creation</topic> 2660 <affects> 2661 <package> 2662 <name>rkhunter</name> 2663 <range><lt>1.2.5</lt></range> 2664 </package> 2665 </affects> 2666 <description> 2667 <body xmlns="http://www.w3.org/1999/xhtml"> 2668 <p>Gentoo reports:</p> 2669 <blockquote cite="http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml"> 2670 <p>Sune Kloppenborg Jeppesen and Tavis Ormandy of the Gentoo Linux 2671 Security Team have reported that the check_update.sh script and 2672 the main rkhunter script insecurely creates several temporary 2673 files with predictable filenames.</p> 2674 <p>A local attacker could create symbolic links in the temporary 2675 files directory, pointing to a valid file somewhere on the 2676 filesystem. When rkhunter or the check_update.sh script runs, 2677 this would result in the file being overwritten with the rights of 2678 the user running the utility, which could be the root user.</p> 2679 </blockquote> 2680 </body> 2681 </description> 2682 <references> 2683 <bid>13399</bid> 2684 <cvename>CVE-2005-1270</cvename> 2685 <url>http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml</url> 2686 </references> 2687 <dates> 2688 <discovery>2005-04-26</discovery> 2689 <entry>2007-09-05</entry> 2690 </dates> 2691 </vuln> 2692 2693 <vuln vid="72cdf2ab-5b87-11dc-812d-0011098b2f36"> 2694 <topic>lsh -- multiple vulnerabilities</topic> 2695 <affects> 2696 <package> 2697 <name>lsh</name> 2698 <range><lt>2.0.1</lt></range> 2699 </package> 2700 </affects> 2701 <description> 2702 <body xmlns="http://www.w3.org/1999/xhtml"> 2703 <p>Secunia reports:</p> 2704 <blockquote cite="http://secunia.com/advisories/14609"> 2705 <p>A vulnerability has been reported in LSH, which potentially 2706 can be exploited by malicious people to cause a DoS (Denial 2707 of Service).</p> 2708 </blockquote> 2709 </body> 2710 </description> 2711 <references> 2712 <cvename>CVE-2003-0826</cvename> 2713 <cvename>CVE-2005-0814</cvename> 2714 <url>http://secunia.com/advisories/14609</url> 2715 </references> 2716 <dates> 2717 <discovery>2005-03-17</discovery> 2718 <entry>2007-09-05</entry> 2719 <modified>2008-01-07</modified> 2720 </dates> 2721 </vuln> 2722 2723 <vuln vid="45500f74-5947-11dc-87c1-000e2e5785ad"> 2724 <topic>fetchmail -- denial of service on reject of local warning message</topic> 2725 <affects> 2726 <package> 2727 <name>fetchmail</name> 2728 <range><ge>4.6.8</ge><lt>6.3.8_4</lt></range> 2729 </package> 2730 </affects> 2731 <description> 2732 <body xmlns="http://www.w3.org/1999/xhtml"> 2733 <p>Matthias Andree reports:</p> 2734 <blockquote cite="http://www.fetchmail.info/fetchmail-SA-2007-02.txt"> 2735 <p>fetchmail will generate warning messages in certain 2736 circumstances (for instance, when leaving oversized messages 2737 on the server or login to the upstream fails) and send them 2738 to the local postmaster or the user running it.</p> 2739 <p>If this warning message is then refused by the SMTP listener 2740 that fetchmail is forwarding the message to, fetchmail 2741 crashes and does not collect further messages until it is 2742 restarted.</p> 2743 </blockquote> 2744 </body> 2745 </description> 2746 <references> 2747 <cvename>CVE-2007-4565</cvename> 2748 <url>http://www.fetchmail.info/fetchmail-SA-2007-02.txt</url> 2749 </references> 2750 <dates> 2751 <discovery>2007-07-29</discovery> 2752 <entry>2007-09-02</entry> 2753 </dates> 2754 </vuln> 2755 2756 <vuln vid="d944719e-42f4-4864-89ed-f045b541919f"> 2757 <topic>gtar -- Directory traversal vulnerability</topic> 2758 <affects> 2759 <package> 2760 <name>gtar</name> 2761 <range><lt>1.18_1</lt></range> 2762 </package> 2763 </affects> 2764 <description> 2765 <body xmlns="http://www.w3.org/1999/xhtml"> 2766 <p>Red Hat reports:</p> 2767 <blockquote cite="http://rhn.redhat.com/errata/RHSA-2007-0860.html"> 2768 <p>A path traversal flaw was discovered in the way GNU 2769 tar extracted archives. A malicious user could create a 2770 tar archive that could write to arbitrary files to which 2771 the user running GNU tar had write access.</p> 2772 </blockquote> 2773 <p>Red Hat credits Dmitry V. Levin for reporting the issue.</p> 2774 </body> 2775 </description> 2776 <references> 2777 <bid>25417</bid> 2778 <cvename>CVE-2007-4131</cvename> 2779 <url>http://rhn.redhat.com/errata/RHSA-2007-0860.html</url> 2780 <url>https://bugzilla.redhat.com/show_bug.cgi?id=251921</url> 2781 </references> 2782 <dates> 2783 <discovery>2007-08-23</discovery> 2784 <entry>2007-09-01</entry> 2785 </dates> 2786 </vuln> 2787 2788 <vuln vid="d9867f50-54d0-11dc-b80b-0016179b2dd5"> 2789 <topic>claws-mail -- POP3 Format String Vulnerability</topic> 2790 <affects> 2791 <package> 2792 <name>claws-mail</name> 2793 <name>sylpheed-claws</name> 2794 <range><lt>2.10.0_3</lt></range> 2795 </package> 2796 <package> 2797 <name>sylpheed2</name> 2798 <range><lt>2.4.4_1</lt></range> 2799 </package> 2800 </affects> 2801 <description> 2802 <body xmlns="http://www.w3.org/1999/xhtml"> 2803 <p>A Secunia Advisory reports:</p> 2804 <blockquote cite="http://secunia.com/advisories/26550/"> 2805 <p>A format string error in the "inc_put_error()" function in 2806 src/inc.c when displaying a POP3 server's error response can 2807 be exploited via specially crafted POP3 server replies containing 2808 format specifiers.</p> 2809 <p>Successful exploitation may allow execution of arbitrary code, 2810 but requires that the user is tricked into connecting to a malicious 2811 POP3 server.</p> 2812 </blockquote> 2813 </body> 2814 </description> 2815 <references> 2816 <cvename>CVE-2007-2958</cvename> 2817 <url>http://secunia.com/advisories/26550/</url> 2818 <url>http://secunia.com/secunia_research/2007-70/advisory/</url> 2819 </references> 2820 <dates> 2821 <discovery>2007-08-24</discovery> 2822 <entry>2007-08-27</entry> 2823 <modified>2010-05-12</modified> 2824 </dates> 2825 </vuln> 2826 2827 <vuln vid="af8e3a0c-5009-11dc-8a43-003048705d5a"> 2828 <topic>rsync -- off by one stack overflow</topic> 2829 <affects> 2830 <package> 2831 <name>rsync</name> 2832 <range><lt>2.6.9_1</lt></range> 2833 </package> 2834 </affects> 2835 <description> 2836 <body xmlns="http://www.w3.org/1999/xhtml"> 2837 <p>BugTraq reports:</p> 2838 <blockquote cite="http://www.securityfocus.com/bid/25336/discuss"> 2839 <p>The rsync utility is prone to an off-by-one buffer-overflow 2840 vulnerability. This issue is due to a failure of the application 2841 to properly bounds-check user-supplied input.</p> 2842 <p>Successfully exploiting this issue may allow arbitrary 2843 code-execution in the context of the affected utility.</p> 2844 </blockquote> 2845 </body> 2846 </description> 2847 <references> 2848 <bid>25336</bid> 2849 <cvename>CVE-2007-4091</cvename> 2850 </references> 2851 <dates> 2852 <discovery>2007-08-15</discovery> 2853 <entry>2007-08-21</entry> 2854 <modified>2007-08-23</modified> 2855 </dates> 2856 </vuln> 2857 2858 <vuln vid="df4a7d21-4b17-11dc-9fc2-001372ae3ab9"> 2859 <topic>opera -- Vulnerability in javascript handling</topic> 2860 <affects> 2861 <package> 2862 <name>opera</name> 2863 <name>opera-devel</name> 2864 <name>linux-opera</name> 2865 <range><lt>9.23.20070809</lt></range> 2866 </package> 2867 </affects> 2868 <description> 2869 <body xmlns="http://www.w3.org/1999/xhtml"> 2870 <p>An advisory from Opera reports:</p> 2871 <blockquote cite="http://www.opera.com/support/search/view/865/"> 2872 <p>A specially crafted JavaScript can make Opera execute 2873 arbitrary code.</p> 2874 </blockquote> 2875 </body> 2876 </description> 2877 <references> 2878 <url>http://www.opera.com/support/search/view/865/</url> 2879 </references> 2880 <dates> 2881 <discovery>2007-08-03</discovery> 2882 <entry>2007-08-15</entry> 2883 <modified>2007-08-25</modified> 2884 </dates> 2885 </vuln> 2886 2887 <vuln vid="4a338d17-412d-11dc-bdb0-0016179b2dd5"> 2888 <topic>fsplib -- multiple vulnerabilities</topic> 2889 <affects> 2890 <package> 2891 <name>fsplib</name> 2892 <range><lt>0.9</lt></range> 2893 </package> 2894 </affects> 2895 <description> 2896 <body xmlns="http://www.w3.org/1999/xhtml"> 2897 <p>A Secunia Advisory reports:</p> 2898 <blockquote cite="http://secunia.com/advisories/26184/"> 2899 <p>fsplib can be exploited to compromise an application using 2900 the library.</p> 2901 <p>A boundary error exists in the processing of file names in 2902 fsp_readdir_native, which can be exploited to cause a stack-based 2903 buffer overflow if the defined MAXNAMLEN is bigger than 256.</p> 2904 <p>A boundary error exists in the processing of directory entries in 2905 fsp_readdir, which can be exploited to cause a stack-based buffer 2906 overflow on systems with an insufficient size allocated for the 2907 d_name field of directory entries.</p> 2908 </blockquote> 2909 </body> 2910 </description> 2911 <references> 2912 <cvename>CVE-2007-3961</cvename> 2913 <cvename>CVE-2007-3962</cvename> 2914 <url>http://secunia.com/advisories/26184/</url> 2915 </references> 2916 <dates> 2917 <discovery>2007-07-24</discovery> 2918 <entry>2007-08-02</entry> 2919 </dates> 2920 </vuln> 2921 2922 <vuln vid="4872d9a7-4128-11dc-bdb0-0016179b2dd5"> 2923 <topic>joomla -- multiple vulnerabilities</topic> 2924 <affects> 2925 <package> 2926 <name>joomla</name> 2927 <range><lt>1.0.13</lt></range> 2928 </package> 2929 </affects> 2930 <description> 2931 <body xmlns="http://www.w3.org/1999/xhtml"> 2932 <p>A Secunia Advisory reports:</p> 2933 <p>joomla can be exploited to conduct session fixation 2934 attacks, cross-site scripting attacks or HTTP response 2935 splitting attacks.</p> 2936 <p>Certain unspecified input passed in com_search, com_content and 2937 mod_login is not properly sanitised before being returned to a 2938 user. This can be exploited to execute arbitrary HTML and script 2939 code in a user's browser session in context of an affected 2940 site.</p> 2941 <p>Input passed to the url parameter is not properly sanitised 2942 before being returned to the user. This can be exploited to insert 2943 arbitrary HTTP headers, which will be included in a response sent 2944 to the user, allowing for execution of arbitrary HTML and script 2945 code in a user's browser session in context of an affected 2946 site.</p> 2947 <p>An error exists in the handling of sessions and can be exploited 2948 to hijack another user's session by tricking the user into logging 2949 in after following a specially crafted link.</p> 2950 </body> 2951 </description> 2952 <references> 2953 <cvename>CVE-2007-4188</cvename> 2954 <cvename>CVE-2007-4189</cvename> 2955 <cvename>CVE-2007-4190</cvename> 2956 <cvename>CVE-2007-5577</cvename> 2957 <url>http://www.joomla.org/content/view/3677/1/</url> 2958 <url>http://secunia.com/advisories/26239/</url> 2959 </references> 2960 <dates> 2961 <discovery>2007-07-30</discovery> 2962 <entry>2007-08-02</entry> 2963 <modified>2010-05-12</modified> 2964 </dates> 2965 </vuln> 2966 2967 <vuln vid="2dc764fa-40c0-11dc-aeac-02e0185f8d72"> 2968 <topic>FreeBSD -- Buffer overflow in tcpdump(1)</topic> 2969 <affects> 2970 <package> 2971 <name>tcpdump</name> 2972 <range><lt>3.9.6</lt></range> 2973 </package> 2974 <package> 2975 <name>FreeBSD</name> 2976 <range><ge>6.2</ge><lt>6.2_7</lt></range> 2977 <range><ge>6.1</ge><lt>6.1_19</lt></range> 2978 <range><ge>5.5</ge><lt>5.5_15</lt></range> 2979 </package> 2980 </affects> 2981 <description> 2982 <body xmlns="http://www.w3.org/1999/xhtml"> 2983 <h1>Problem Description:</h1> 2984 <p>An un-checked return value in the BGP dissector code can 2985 result in an integer overflow. This value is used in 2986 subsequent buffer management operations, resulting in a stack 2987 based buffer overflow under certain circumstances.</p> 2988 <h1>Impact:</h1> 2989 <p>By crafting malicious BGP packets, an attacker could exploit 2990 this vulnerability to execute code or crash the tcpdump 2991 process on the target system. This code would be executed in 2992 the context of the user running tcpdump(1). It should be 2993 noted that tcpdump(1) requires privileges in order to open live 2994 network interfaces.</p> 2995 <h1>Workaround:</h1> 2996 <p>No workaround is available.</p> 2997 </body> 2998 </description> 2999 <references> 3000 <cvename>CVE-2007-3798</cvename> 3001 <freebsdsa>SA-07:06.tcpdump</freebsdsa> 3002 </references> 3003 <dates> 3004 <discovery>2007-08-01</discovery> 3005 <entry>2007-08-02</entry> 3006 <modified>2016-08-09</modified> 3007 </dates> 3008 </vuln> 3009 3010 <vuln vid="3de342fb-40be-11dc-aeac-02e0185f8d72"> 3011 <topic>FreeBSD -- Predictable query ids in named(8)</topic> 3012 <affects> 3013 <package> 3014 <name>named</name> 3015 <range><ge>9.4</ge><lt>9.4.1.1</lt></range> 3016 <range><ge>9.3</ge><lt>9.3.4.1</lt></range> 3017 </package> 3018 <package> 3019 <name>FreeBSD</name> 3020 <range><ge>6.2</ge><lt>6.2_7</lt></range> 3021 <range><ge>6.1</ge><lt>6.1_19</lt></range> 3022 <range><ge>5.5</ge><lt>5.5_15</lt></range> 3023 </package> 3024 </affects> 3025 <description> 3026 <body xmlns="http://www.w3.org/1999/xhtml"> 3027 <h1>Problem Description:</h1> 3028 <p>When named(8) is operating as a recursive DNS server or 3029 sending NOTIFY requests to slave DNS servers, named(8) 3030 uses a predictable query id.</p> 3031 <h1>Impact:</h1> 3032 <p>An attacker who can see the query id for some request(s) 3033 sent by named(8) is likely to be able to perform DNS cache 3034 poisoning by predicting the query id for other request(s).</p> 3035 <h1>Workaround:</h1> 3036 <p>No workaround is available.</p> 3037 </body> 3038 </description> 3039 <references> 3040 <cvename>CVE-2007-2926</cvename> 3041 <freebsdsa>SA-07:07.bind</freebsdsa> 3042 </references> 3043 <dates> 3044 <discovery>2007-07-24</discovery> 3045 <entry>2007-08-02</entry> 3046 <modified>2016-08-09</modified> 3047 </dates> 3048 </vuln> 3049 3050 <vuln vid="0e43a14d-3f3f-11dc-a79a-0016179b2dd5"> 3051 <topic>xpdf -- stack based buffer overflow</topic> 3052 <affects> 3053 <package> 3054 <name>xpdf</name> 3055 <range><lt>3.02_2</lt></range> 3056 </package> 3057 <package> 3058 <name>kdegraphics</name> 3059 <range><lt>3.5.7_1</lt></range> 3060 </package> 3061 <package> 3062 <name>cups-base</name> 3063 <range><lt>1.2.11_3</lt></range> 3064 </package> 3065 <package> 3066 <name>gpdf</name> 3067 <range><gt>0</gt></range> 3068 </package> 3069 <package> 3070 <name>pdftohtml</name> 3071 <range><lt>0.39_3</lt></range> 3072 </package> 3073 <package> 3074 <name>poppler</name> 3075 <range><lt>0.5.9_4</lt></range> 3076 </package> 3077 </affects> 3078 <description> 3079 <body xmlns="http://www.w3.org/1999/xhtml"> 3080 <p>The KDE Team reports:</p> 3081 <blockquote cite="http://www.kde.org/info/security/advisory-20070730-1.txt"> 3082 <p>kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains 3083 a vulnerability that can cause a stack based buffer overflow 3084 via a PDF file that exploits an integer overflow in 3085 StreamPredictor::StreamPredictor(). Remotely supplied 3086 pdf files can be used to disrupt the kpdf viewer on 3087 the client machine and possibly execute arbitrary code.</p> 3088 </blockquote> 3089 </body> 3090 </description> 3091 <references> 3092 <bid>25124</bid> 3093 <cvename>CVE-2007-3387</cvename> 3094 <url>http://www.kde.org/info/security/advisory-20070730-1.txt</url> 3095 </references> 3096 <dates> 3097 <discovery>2007-07-30</discovery> 3098 <entry>2007-07-31</entry> 3099 <modified>2009-04-29</modified> 3100 </dates> 3101 </vuln> 3102 3103 <vuln vid="ff284bf0-3f32-11dc-a79a-0016179b2dd5"> 3104 <cancelled superseded="2dc764fa-40c0-11dc-aeac-02e0185f8d72"/> 3105 </vuln> 3106 3107 <vuln vid="863f95d3-3df1-11dc-b3d3-0016179b2dd5"> 3108 <topic>mutt -- buffer overflow vulnerability</topic> 3109 <affects> 3110 <package> 3111 <name>mutt</name> 3112 <name>mutt-lite</name> 3113 <name>ja-mutt</name> 3114 <name>zh-mutt</name> 3115 <range><lt>1.4.2.3</lt></range> 3116 </package> 3117 </affects> 3118 <description> 3119 <body xmlns="http://www.w3.org/1999/xhtml"> 3120 <p>Securityfocus reports:</p> 3121 <blockquote cite="http://www.securityfocus.com/bid/24192/"> 3122 <p>Mutt is prone to a local buffer-overflow vulnerability 3123 because it fails to properly bounds-check user-supplied 3124 input before using it in a memory copy operation. 3125 An attacker can exploit this issue to execute arbitrary 3126 code with the with the privileges of the victim. Failed 3127 exploit attempts will result in a denial of service.</p> 3128 </blockquote> 3129 </body> 3130 </description> 3131 <references> 3132 <bid>24192</bid> 3133 <cvename>CVE-2007-2683</cvename> 3134 <url>http://www.redhat.com/support/errata/RHSA-2007-0386.html</url> 3135 </references> 3136 <dates> 3137 <discovery>2007-05-28</discovery> 3138 <entry>2007-07-29</entry> 3139 </dates> 3140 </vuln> 3141 3142 <vuln vid="d2b8a963-3d59-11dc-b3d3-0016179b2dd5"> 3143 <topic>p5-Net-DNS -- multiple Vulnerabilities</topic> 3144 <affects> 3145 <package> 3146 <name>p5-Net-DNS</name> 3147 <range><lt>0.60</lt></range> 3148 </package> 3149 </affects> 3150 <description> 3151 <body xmlns="http://www.w3.org/1999/xhtml"> 3152 <p>A Secunia Advisory reports:</p> 3153 <blockquote cite="http://secunia.com/advisories/25829/"> 3154 <p>An error exists in the handling of DNS queries where IDs are 3155 incremented with a fixed value and are additionally used for 3156 child processes in a forking server. This can be exploited to 3157 poison the DNS cache of an application using the module if a 3158 valid ID is guessed.</p> 3159 <p>An error in the PP implementation within the "dn_expand()" 3160 function can be exploited to cause a stack overflow due to an 3161 endless loop via a specially crafted DNS packet.</p> 3162 </blockquote> 3163 </body> 3164 </description> 3165 <references> 3166 <cvename>CVE-2007-3377</cvename> 3167 <cvename>CVE-2007-3409</cvename> 3168 <url>http://secunia.com/advisories/25829/</url> 3169 </references> 3170 <dates> 3171 <discovery>2007-06-27</discovery> 3172 <entry>2007-07-28</entry> 3173 </dates> 3174 </vuln> 3175 3176 <vuln vid="88260dfe-3d21-11dc-b3d3-0016179b2dd5"> 3177 <topic>phpsysinfo -- url Cross-Site Scripting</topic> 3178 <affects> 3179 <package> 3180 <name>phpSysInfo</name> 3181 <range><lt>2.5.3_1</lt></range> 3182 </package> 3183 </affects> 3184 <description> 3185 <body xmlns="http://www.w3.org/1999/xhtml"> 3186 <p>Doz reports:</p> 3187 <blockquote cite="http://secunia.com/advisories/26248/"> 3188 <p>A Input passed in the URL to index.php is not properly 3189 sanitised before being returned to the user. This can be 3190 exploited to execute arbitrary HTML and script code in a 3191 user's browser session in context of an affected site.</p> 3192 </blockquote> 3193 </body> 3194 </description> 3195 <references> 3196 <url>http://secunia.com/advisories/26248/</url> 3197 </references> 3198 <dates> 3199 <discovery>2007-07-27</discovery> 3200 <entry>2007-07-28</entry> 3201 <modified>2007-08-01</modified> 3202 </dates> 3203 </vuln> 3204 3205 <vuln vid="98dd7788-3d13-11dc-b3d3-0016179b2dd5"> 3206 <topic>drupal -- Cross site request forgeries</topic> 3207 <affects> 3208 <package> 3209 <name>drupal5</name> 3210 <range><lt>5.2</lt></range> 3211 </package> 3212 </affects> 3213 <description> 3214 <body xmlns="http://www.w3.org/1999/xhtml"> 3215 <p>The Drupal Project reports:</p> 3216 <blockquote cite="http://drupal.org/node/162360"> 3217 <p>Several parts in Drupal core are not protected against cross 3218 site request forgeries due to inproper use of the Forms API, 3219 or by taking action solely on GET requests. Malicious users are 3220 able to delete comments and content revisions and disable menu 3221 items by enticing a privileged users to visit certain URLs while 3222 the victim is logged-in to the targeted site.</p> 3223 </blockquote> 3224 </body> 3225 </description> 3226 <references> 3227 <url>http://drupal.org/node/162360</url> 3228 <url>http://secunia.com/advisories/26224/</url> 3229 </references> 3230 <dates> 3231 <discovery>2007-07-26</discovery> 3232 <entry>2007-07-28</entry> 3233 </dates> 3234 </vuln> 3235 3236 <vuln vid="1f5b711b-3d0e-11dc-b3d3-0016179b2dd5"> 3237 <topic>drupal -- Multiple cross-site scripting vulnerabilities</topic> 3238 <affects> 3239 <package> 3240 <name>drupal4</name> 3241 <range><lt>4.7.7</lt></range> 3242 </package> 3243 <package> 3244 <name>drupal5</name> 3245 <range><lt>5.2</lt></range> 3246 </package> 3247 </affects> 3248 <description> 3249 <body xmlns="http://www.w3.org/1999/xhtml"> 3250 <p>The Drupal Project reports:</p> 3251 <blockquote cite="http://drupal.org/node/162361"> 3252 <p>Some server variables are not escaped consistently. When 3253 a malicious user is able to entice a victim to visit a specially 3254 crafted link or webpage, arbitrary HTML and script code can be 3255 injected and executed in the context of the victim's session on 3256 the targeted website.</p> 3257 <p>Custom content type names are not escaped consistently. A 3258 malicious user with the 'administer content types' permission 3259 would be able to inject and execute arbitrary HTML and script 3260 code on the website. Revoking the 'administer content types' 3261 permission provides an immediate workaround.</p> 3262 </blockquote> 3263 </body> 3264 </description> 3265 <references> 3266 <url>http://drupal.org/node/162361</url> 3267 <url>http://secunia.com/advisories/26224/</url> 3268 </references> 3269 <dates> 3270 <discovery>2007-07-26</discovery> 3271 <entry>2007-07-28</entry> 3272 </dates> 3273 </vuln> 3274 3275 <vuln vid="1ed03222-3c65-11dc-b3d3-0016179b2dd5"> 3276 <topic>vim -- Command Format String Vulnerability</topic> 3277 <affects> 3278 <package> 3279 <name>vim</name> 3280 <name>vim-console</name> 3281 <name>vim-lite</name> 3282 <name>vim-ruby</name> 3283 <name>vim6</name> 3284 <name>vim6-ruby</name> 3285 <range><lt>7.1.39</lt></range> 3286 </package> 3287 </affects> 3288 <description> 3289 <body xmlns="http://www.w3.org/1999/xhtml"> 3290 <p>A Secunia Advisory reports:</p> 3291 <blockquote cite="http://secunia.com/advisories/25941/"> 3292 <p>A format string error in the "helptags_one()" function in 3293 src/ex_cmds.c when running the "helptags" command can be exploited 3294 to execute arbitrary code via specially crafted help files.</p> 3295 </blockquote> 3296 </body> 3297 </description> 3298 <references> 3299 <cvename>CVE-2007-2953</cvename> 3300 <url>http://secunia.com/advisories/25941/</url> 3301 </references> 3302 <dates> 3303 <discovery>2007-07-27</discovery> 3304 <entry>2007-07-27</entry> 3305 </dates> 3306 </vuln> 3307 3308 <vuln vid="b73335a5-3bbe-11dc-8e83-0016179b2dd5"> 3309 <topic>libvorbis -- Multiple memory corruption flaws</topic> 3310 <affects> 3311 <package> 3312 <name>libvorbis</name> 3313 <range><lt>1.2.0,3</lt></range> 3314 </package> 3315 </affects> 3316 <description> 3317 <body xmlns="http://www.w3.org/1999/xhtml"> 3318 <p>isecpartners reports:</p> 3319 <blockquote cite="http://www.isecpartners.com/advisories/2007-003-libvorbis.txt"> 3320 <p>libvorbis contains several vulnerabilities 3321 allowing heap overwrite, read violations and a function 3322 pointer overwrite. These bugs cause a at least a denial 3323 of service, and potentially code execution.</p> 3324 </blockquote> 3325 </body> 3326 </description> 3327 <references> 3328 <url>http://www.isecpartners.com/advisories/2007-003-libvorbis.txt</url> 3329 <cvename>CVE-2007-3106</cvename> 3330 </references> 3331 <dates> 3332 <discovery>2007-06-05</discovery> 3333 <entry>2007-07-26</entry> 3334 </dates> 3335 </vuln> 3336 3337 <vuln vid="ab2575d6-39f0-11dc-b8cc-000fea449b8a"> 3338 <topic>tomcat -- XSS vulnerability in sample applications</topic> 3339 <affects> 3340 <package> 3341 <name>apache-tomcat</name> 3342 <range><gt>6.0.0</gt><lt>6.0.11</lt></range> 3343 </package> 3344 <package> 3345 <name>tomcat</name> 3346 <range><gt>5.0.0</gt><lt>5.5.24</lt></range> 3347 </package> 3348 <package> 3349 <name>jakarta-tomcat</name> 3350 <range><gt>5.0.0</gt><lt>5.5.24</lt></range> 3351 </package> 3352 </affects> 3353 <description> 3354 <body xmlns="http://www.w3.org/1999/xhtml"> 3355 <p>The Apache Project reports:</p> 3356 <blockquote cite="http://tomcat.apache.org/security-5.html"> 3357 <p>The JSP and Servlet included in the sample application within 3358 the Tomcat documentation webapp did not escape user provided 3359 data before including it in the output. This enabled a XSS 3360 attack. These pages have been simplified not to use any user 3361 provided data in the output.</p> 3362 </blockquote> 3363 </body> 3364 </description> 3365 <references> 3366 <cvename>CVE-2007-1355</cvename> 3367 <bid>24058</bid> 3368 </references> 3369 <dates> 3370 <discovery>2007-05-19</discovery> 3371 <entry>2007-07-24</entry> 3372 </dates> 3373 </vuln> 3374 3375 <vuln vid="872623af-39ec-11dc-b8cc-000fea449b8a"> 3376 <topic>tomcat -- multiple vulnerabilities</topic> 3377 <affects> 3378 <package> 3379 <name>apache-tomcat</name> 3380 <range><ge>4.1.0</ge><lt>4.1.36</lt></range> 3381 <range><gt>6.0.0</gt><lt>6.0.11</lt></range> 3382 </package> 3383 <package> 3384 <name>tomcat</name> 3385 <range><gt>5.0.0</gt><lt>5.5.23</lt></range> 3386 </package> 3387 <package> 3388 <name>jakarta-tomcat</name> 3389 <range><ge>4.0.0</ge><lt>4.1.0</lt></range> 3390 <range><gt>5.0.0</gt><lt>5.5.23</lt></range> 3391 </package> 3392 </affects> 3393 <description> 3394 <body xmlns="http://www.w3.org/1999/xhtml"> 3395 <p>Apache Project reports:</p> 3396 <blockquote cite="http://www.mail-archive.com/dev@tomcat.apache.org/msg16385.html"> 3397 <p>The Apache Tomcat team is proud to announce the immediate 3398 availability of Tomcat 4.1.36 stable. This build contains 3399 numerous library updates, A small number of bug fixes and 3400 two important security fixes.</p> 3401 </blockquote> 3402 </body> 3403 </description> 3404 <references> 3405 <cvename>CVE-2005-2090</cvename> 3406 <cvename>CVE-2007-0450</cvename> 3407 <cvename>CVE-2007-1358</cvename> 3408 </references> 3409 <dates> 3410 <discovery>2007-04-27</discovery> 3411 <entry>2007-07-24</entry> 3412 </dates> 3413 </vuln> 3414 3415 <vuln vid="cddde37a-39b5-11dc-b3da-001921ab2fa4"> 3416 <topic>dokuwiki -- XSS vulnerability in spellchecker backend</topic> 3417 <affects> 3418 <package> 3419 <name>dokuwiki</name> 3420 <range><lt>20070626_1</lt></range> 3421 </package> 3422 <package> 3423 <name>dokuwiki-devel</name> 3424 <range><lt>20070524_1</lt></range> 3425 </package> 3426 </affects> 3427 <description> 3428 <body xmlns="http://www.w3.org/1999/xhtml"> 3429 <p>DokuWiki reports:</p> 3430 <blockquote cite="http://bugs.splitbrain.org/index.php?do=details&task_id=1195"> 3431 <p>The spellchecker tests the UTF-8 capabilities of the used browser 3432 by sending an UTF-8 string to the backend, which will send it back 3433 unfiltered. By comparing string length the spellchecker can work 3434 around broken implementations. An attacker could construct a form to 3435 let users send JavaScript to the spellchecker backend, resulting in 3436 malicious JavaScript being executed in their browser.</p> 3437 <p>Affected are all versions up to and including 2007-06-26 even when 3438 the spell checker is disabled.</p> 3439 </blockquote> 3440 </body> 3441 </description> 3442 <references> 3443 <url>http://xforce.iss.net/xforce/xfdb/35501</url> 3444 <cvename>CVE-2007-3930</cvename> 3445 </references> 3446 <dates> 3447 <discovery>2007-06-26</discovery> 3448 <entry>2007-07-24</entry> 3449 </dates> 3450 </vuln> 3451 3452 <vuln vid="fc9c217e-3791-11dc-bb1a-000fea449b8a"> 3453 <topic>lighttpd -- multiple vulnerabilities</topic> 3454 <affects> 3455 <package> 3456 <name>lighttpd</name> 3457 <range><lt>1.4.15_1</lt></range> 3458 </package> 3459 </affects> 3460 <description> 3461 <body xmlns="http://www.w3.org/1999/xhtml"> 3462 <p>Secunia Advisory reports:</p> 3463 <blockquote cite="http://secunia.com/advisories/26130/"> 3464 <p>Some vulnerabilities have been reported in lighttpd, 3465 which can be exploited by malicious people to bypass 3466 certain security restrictions or cause a DoS (Denial 3467 of Service).</p> 3468 </blockquote> 3469 </body> 3470 </description> 3471 <references> 3472 <cvename>CVE-2007-3947</cvename> 3473 <cvename>CVE-2007-3948</cvename> 3474 <cvename>CVE-2007-3949</cvename> 3475 <cvename>CVE-2007-3950</cvename> 3476 <url>http://trac.lighttpd.net/trac/ticket/1216</url> 3477 <url>http://trac.lighttpd.net/trac/ticket/1232</url> 3478 <url>http://trac.lighttpd.net/trac/ticket/1230</url> 3479 <url>http://trac.lighttpd.net/trac/ticket/1263</url> 3480 </references> 3481 <dates> 3482 <discovery>2007-07-20</discovery> 3483 <entry>2007-07-21</entry> 3484 <modified>2010-05-12</modified> 3485 </dates> 3486 </vuln> 3487 3488 <vuln vid="12d266b6-363f-11dc-b6c9-000c6ec775d9"> 3489 <topic>opera -- multiple vulnerabilities</topic> 3490 <affects> 3491 <package> 3492 <name>opera</name> 3493 <name>opera-devel</name> 3494 <name>linux-opera</name> 3495 <range><lt>9.22</lt></range> 3496 </package> 3497 </affects> 3498 <description> 3499 <body xmlns="http://www.w3.org/1999/xhtml"> 3500 <p>Opera Software ASA reports of multiple security fixes in 3501 Opera, including an arbitrary code execute 3502 vulnerability:</p> 3503 <blockquote cite="http://www.opera.com/support/search/view/861/"> 3504 <p>Opera for Linux, FreeBSD, and Solaris has a flaw in the 3505 createPattern function that leaves old data that was in 3506 the memory before Opera allocated it in the new 3507 pattern. The pattern can be read and analyzed by 3508 JavaScript, so an attacker can get random samples of the 3509 user's memory, which may contain data.</p> 3510 </blockquote> 3511 <blockquote cite="http://www.opera.com/support/search/view/862/"> 3512 <p>Removing a specially crafted torrent from the download 3513 manager can crash Opera. The crash is caused by an 3514 erroneous memory access.</p> 3515 <p>An attacker needs to entice the user to accept the 3516 malicious BitTorrent download, and later remove it from 3517 Opera's download manager. To inject code, additional means 3518 will have to be employed.</p> 3519 <p>Users clicking a BitTorrent link and rejecting the 3520 download are not affected.</p> 3521 </blockquote> 3522 <blockquote cite="http://www.opera.com/support/search/view/863/"> 3523 <p>data: URLs embed data inside them, instead of linking to 3524 an external resource. Opera can mistakenly display the end 3525 of a data URL instead of the beginning. This allows an 3526 attacker to spoof the URL of a trusted site.</p> 3527 </blockquote> 3528 <blockquote cite="http://www.opera.com/support/search/view/864/"> 3529 <p>Opera's HTTP authentication dialog is displayed when the 3530 user enters a Web page that requires a login name and a 3531 password. To inform the user which server it was that 3532 asked for login credentials, the dialog displays the 3533 server name.</p> 3534 <p>The user has to see the entire server name. A truncated 3535 name can be misleading. Opera's authentication dialog cuts 3536 off the long server names at the right hand side, adding 3537 an ellipsis (...) to indicate that it has been cut off.</p> 3538 <p>The dialog has a predictable size, allowing an attacker 3539 to create a server name which will look almost like a 3540 trusted site, because the real domain name has been cut 3541 off. The three dots at the end will not be obvious to all 3542 users.</p> 3543 <p>This flaw can be exploited by phishers who can set up 3544 custom sub-domains, for example by hosting their own 3545 public DNS.</p> 3546 </blockquote> 3547 </body> 3548 </description> 3549 <references> 3550 <cvename>CVE-2007-3929</cvename> 3551 <cvename>CVE-2007-4944</cvename> 3552 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=564</url> 3553 <url>http://www.opera.com/support/search/view/861/</url> 3554 <url>http://www.opera.com/support/search/view/862/</url> 3555 <url>http://www.opera.com/support/search/view/863/</url> 3556 <url>http://www.opera.com/support/search/view/864/</url> 3557 <url>http://www.opera.com/docs/changelogs/freebsd/922/</url> 3558 </references> 3559 <dates> 3560 <discovery>2007-07-19</discovery> 3561 <entry>2007-07-19</entry> 3562 <modified>2010-05-12</modified> 3563 </dates> 3564 </vuln> 3565 3566 <vuln vid="e190ca65-3636-11dc-a697-000c6ec775d9"> 3567 <topic>mozilla -- multiple vulnerabilities</topic> 3568 <affects> 3569 <package> 3570 <name>firefox</name> 3571 <range><lt>2.0.0.5,1</lt></range> 3572 <range><gt>3.*,1</gt><lt>3.0.a2_3,1</lt></range> 3573 </package> 3574 <package> 3575 <name>linux-firefox</name> 3576 <name>linux-thunderbird</name> 3577 <name>mozilla-thunderbird</name> 3578 <name>thunderbird</name> 3579 <range><lt>2.0.0.5</lt></range> 3580 </package> 3581 <!-- Packages which probably will be upgraded --> 3582 <package> 3583 <name>seamonkey</name> 3584 <name>linux-seamonkey</name> 3585 <range><lt>1.1.3</lt></range> 3586 </package> 3587 <package> 3588 <name>linux-firefox-devel</name> 3589 <range><lt>3.0.a2007.12.12</lt></range> 3590 </package> 3591 <package> 3592 <name>linux-seamonkey-devel</name> 3593 <range><lt>2.0.a2007.12.12</lt></range> 3594 </package> 3595 <!-- Deprecated/old names --> 3596 <package> 3597 <name>firefox-ja</name> 3598 <name>linux-mozilla-devel</name> 3599 <name>linux-mozilla</name> 3600 <name>mozilla</name> 3601 <range><gt>0</gt></range> 3602 </package> 3603 </affects> 3604 <description> 3605 <body xmlns="http://www.w3.org/1999/xhtml"> 3606 <p>The Mozilla Foundation reports of multiple security issues 3607 in Firefox, Seamonkey, and Thunderbird. Several of these 3608 issues can probably be used to run arbitrary code with the 3609 privilege of the user running the program.</p> 3610 <blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.5"> 3611 <ul> 3612 <li>MFSA 2007-25 XPCNativeWrapper pollution</li> 3613 <li>MFSA 2007-24 Unauthorized access to wyciwyg:// documents</li> 3614 <li>MFSA 2007-21 Privilege escalation using an event 3615 handler attached to an element not in the document</li> 3616 <li>MFSA 2007-20 Frame spoofing while window is loading</li> 3617 <li>MFSA 2007-19 XSS using addEventListener and setTimeout</li> 3618 <li>MFSA 2007-18 Crashes with evidence of memory corruption</li> 3619 </ul> 3620 </blockquote> 3621 </body> 3622 </description> 3623 <references> 3624 <cvename>CVE-2007-3089</cvename> 3625 <cvename>CVE-2007-3734</cvename> 3626 <cvename>CVE-2007-3735</cvename> 3627 <cvename>CVE-2007-3737</cvename> 3628 <cvename>CVE-2007-3738</cvename> 3629 <url>http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.5</url> 3630 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-18.html</url> 3631 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-19.html</url> 3632 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-20.html</url> 3633 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-21.html</url> 3634 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-24.html</url> 3635 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-25.html</url> 3636 <uscertta>TA07-199A</uscertta> 3637 </references> 3638 <dates> 3639 <discovery>2007-07-17</discovery> 3640 <entry>2007-07-19</entry> 3641 <modified>2008-06-21</modified> 3642 </dates> 3643 </vuln> 3644 3645 <vuln vid="b42e8c32-34f6-11dc-9bc9-001921ab2fa4"> 3646 <topic>linux-flashplugin -- critical vulnerabilities</topic> 3647 <affects> 3648 <package> 3649 <name>linux-flashplugin</name> 3650 <range><gt>9.0</gt><le>9.0r45</le></range> 3651 <range><gt>8.0</gt><le>8.0r34</le></range> 3652 <range><le>7.0r69</le></range> 3653 </package> 3654 </affects> 3655 <description> 3656 <body xmlns="http://www.w3.org/1999/xhtml"> 3657 <p>Adobe reports:</p> 3658 <blockquote cite="http://www.adobe.com/support/security/bulletins/apsb07-12.html"> 3659 <p>Critical vulnerabilities have been identified in 3660 Adobe Flash Player that could allow an attacker who 3661 successfully exploits these potential vulnerabilities 3662 to take control of the affected system. A malicious 3663 SWF must be loaded in Flash Player by the user for 3664 an attacker to exploit these potential vulnerabilities.</p> 3665 </blockquote> 3666 </body> 3667 </description> 3668 <references> 3669 <cvename>CVE-2007-2022</cvename> 3670 <cvename>CVE-2007-3456</cvename> 3671 <cvename>CVE-2007-3457</cvename> 3672 </references> 3673 <dates> 3674 <discovery>2007-07-10</discovery> 3675 <entry>2007-07-18</entry> 3676 </dates> 3677 </vuln> 3678 3679 <vuln vid="7fadc049-2ba0-11dc-9377-0016179b2dd5"> 3680 <topic>wireshark -- Multiple problems</topic> 3681 <affects> 3682 <package> 3683 <name>wireshark</name> 3684 <name>wireshark-lite</name> 3685 <name>ethereal</name> 3686 <name>ethereal-lite</name> 3687 <name>tethereal</name> 3688 <name>tethereal-lite</name> 3689 <range><ge>0.8.20</ge><lt>0.99.6</lt></range> 3690 </package> 3691 </affects> 3692 <description> 3693 <body xmlns="http://www.w3.org/1999/xhtml"> 3694 <p>wireshark Team reports:</p> 3695 <blockquote cite="http://www.wireshark.org/security/wnpa-sec-2007-02.html"> 3696 <p>It may be possible to make Wireshark or Ethereal crash or use up 3697 available memory by injecting a purposefully malformed packet onto 3698 the wire or by convincing someone to read a malformed packet trace 3699 file.</p> 3700 </blockquote> 3701 </body> 3702 </description> 3703 <references> 3704 <cvename>CVE-2007-3389</cvename> 3705 <cvename>CVE-2007-3390</cvename> 3706 <cvename>CVE-2007-3391</cvename> 3707 <cvename>CVE-2007-3392</cvename> 3708 <cvename>CVE-2007-3393</cvename> 3709 <url>http://secunia.com/advisories/25833/</url> 3710 <url>http://www.wireshark.org/security/wnpa-sec-2007-02.html</url> 3711 </references> 3712 <dates> 3713 <discovery>2007-06-29</discovery> 3714 <entry>2007-07-06</entry> 3715 <modified>2010-05-12</modified> 3716 </dates> 3717 </vuln> 3718 3719 <vuln vid="2c4f4688-298b-11dc-a197-0011098b2f36"> 3720 <topic>typespeed -- arbitrary code execution</topic> 3721 <affects> 3722 <package> 3723 <name>typespeed</name> 3724 <range><le>0.4.1</le></range> 3725 </package> 3726 </affects> 3727 <description> 3728 <body xmlns="http://www.w3.org/1999/xhtml"> 3729 <p>Debian reports:</p> 3730 <blockquote cite="http://www.debian.org/security/2005/dsa-684"> 3731 <p>Ulf Härnhammar from the Debian Security Audit Project 3732 discovered a problem in typespeed, a touch-typist trainer 3733 disguised as game. This could lead to a local attacker 3734 executing arbitrary code.</p> 3735 </blockquote> 3736 </body> 3737 </description> 3738 <references> 3739 <cvename>CVE-2005-0105</cvename> 3740 <url>http://www.debian.org/security/2005/dsa-684</url> 3741 </references> 3742 <dates> 3743 <discovery>2005-02-16</discovery> 3744 <entry>2007-07-03</entry> 3745 <modified>2007-07-09</modified> 3746 </dates> 3747 </vuln> 3748 3749 <vuln vid="7128fb45-2633-11dc-94da-0016179b2dd5"> 3750 <topic>vlc -- format string vulnerability and integer overflow</topic> 3751 <affects> 3752 <package> 3753 <name>vlc</name> 3754 <range><lt>0.8.6c</lt></range> 3755 </package> 3756 </affects> 3757 <description> 3758 <body xmlns="http://www.w3.org/1999/xhtml"> 3759 <p>isecpartners reports:</p> 3760 <blockquote cite="http://www.isecpartners.com/advisories/2007-001-vlc.txt"> 3761 <p>VLC is vulnerable to a format string attack in the parsing 3762 of Vorbis comments in Ogg Vorbis and Ogg Theora files, CDDA 3763 data or SAP/SDP service discovery messages. Additionally, 3764 there are two errors in the handling of wav files, one a 3765 denial of service due to an uninitialized variable, and one 3766 integer overflow in sampling frequency calculations.</p> 3767 </blockquote> 3768 </body> 3769 </description> 3770 <references> 3771 <cvename>CVE-2007-3316</cvename> 3772 <cvename>CVE-2007-3468</cvename> 3773 <cvename>CVE-2007-3467</cvename> 3774 <url>http://www.isecpartners.com/advisories/2007-001-vlc.txt</url> 3775 </references> 3776 <dates> 3777 <discovery>2007-06-05</discovery> 3778 <entry>2007-06-18</entry> 3779 <modified>2010-05-12</modified> 3780 </dates> 3781 </vuln> 3782 3783 <vuln vid="32d38cbb-2632-11dc-94da-0016179b2dd5"> 3784 <topic>flac123 -- stack overflow in comment parsing</topic> 3785 <affects> 3786 <package> 3787 <name>flac123</name> 3788 <range><lt>0.0.10</lt></range> 3789 </package> 3790 </affects> 3791 <description> 3792 <body xmlns="http://www.w3.org/1999/xhtml"> 3793 <p>isecpartners reports:</p> 3794 <blockquote cite="http://www.isecpartners.com/advisories/2007-002-flactools.txt"> 3795 <p>flac123, also known as flac-tools, is vulnerable 3796 to a buffer overflow in vorbis comment parsing. 3797 This allows for the execution of arbitrary code.</p> 3798 </blockquote> 3799 </body> 3800 </description> 3801 <references> 3802 <cvename>CVE-2007-3507</cvename> 3803 <url>http://sourceforge.net/forum/forum.php?forum_id=710314</url> 3804 <url>http://www.isecpartners.com/advisories/2007-002-flactools.txt</url> 3805 </references> 3806 <dates> 3807 <discovery>2007-06-05</discovery> 3808 <entry>2007-06-28</entry> 3809 <modified>2007-08-10</modified> 3810 </dates> 3811 </vuln> 3812 3813 <vuln vid="6e099997-25d8-11dc-878b-000c29c5647f"> 3814 <topic>gd -- multiple vulnerabilities</topic> 3815 <affects> 3816 <package> 3817 <name>gd</name> 3818 <range><lt>2.0.35,1</lt></range> 3819 </package> 3820 </affects> 3821 <description> 3822 <body xmlns="http://www.w3.org/1999/xhtml"> 3823 <p>gd had been reported vulnerable to several 3824 vulnerabilities:</p> 3825 <ul> 3826 <li>CVE-2007-3472: Integer overflow in gdImageCreateTrueColor 3827 function in the GD Graphics Library (libgd) before 2.0.35 3828 allows user-assisted remote attackers has unspecified attack 3829 vectors and impact.</li> 3830 <li>CVE-2007-3473: The gdImageCreateXbm function in the GD 3831 Graphics Library (libgd) before 2.0.35 allows user-assisted 3832 remote attackers to cause a denial of service (crash) via 3833 unspecified vectors involving a gdImageCreate failure.</li> 3834 <li>CVE-2007-3474: Multiple unspecified vulnerabilities in the GIF 3835 reader in the GD Graphics Library (libgd) before 2.0.35 allow 3836 user-assisted remote attackers to have unspecified attack vectors 3837 and impact.</li> 3838 <li>CVE-2007-3475: The GD Graphics Library (libgd) before 2.0.35 3839 allows user-assisted remote attackers to cause a denial of service 3840 (crash) via a GIF image that has no global color map.</li> 3841 <li>CVE-2007-3476: Array index error in gd_gif_in.c in the GD Graphics 3842 Library (libgd) before 2.0.35 allows user-assisted remote attackers 3843 to cause a denial of service (crash and heap corruption) via large 3844 color index values in crafted image data, which results in a 3845 segmentation fault.</li> 3846 <li>CVE-2007-3477: The (a) imagearc and (b) imagefilledarc functions 3847 in GD Graphics Library (libgd) before 2.0.35 allows attackers to 3848 cause a denial of service (CPU consumption) via a large (1) start or 3849 (2) end angle degree value.</li> 3850 <li>CVE-2007-3478: Race condition in gdImageStringFTEx 3851 (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd) 3852 before 2.0.35 allows user-assisted remote attackers to cause a 3853 denial of service (crash) via unspecified vectors, possibly 3854 involving truetype font (TTF) support.</li> 3855 </ul> 3856 </body> 3857 </description> 3858 <references> 3859 <cvename>CVE-2007-3472</cvename> 3860 <cvename>CVE-2007-3473</cvename> 3861 <cvename>CVE-2007-3474</cvename> 3862 <cvename>CVE-2007-3475</cvename> 3863 <cvename>CVE-2007-3476</cvename> 3864 <cvename>CVE-2007-3477</cvename> 3865 <cvename>CVE-2007-3478</cvename> 3866 <url>http://www.libgd.org/ReleaseNote020035</url> 3867 <url>http://www.frsirt.com/english/advisories/2007/2336</url> 3868 <url>http://bugs.libgd.org/?do=details&task_id=89</url> 3869 <url>http://bugs.libgd.org/?do=details&task_id=94</url> 3870 <url>http://bugs.libgd.org/?do=details&task_id=70</url> 3871 <url>http://bugs.libgd.org/?do=details&task_id=87</url> 3872 <url>http://bugs.libgd.org/?do=details&task_id=92</url> 3873 <url>http://bugs.libgd.org/?do=details&task_id=74</url> 3874 <url>http://bugs.libgd.org/?do=details&task_id=48</url> 3875 <url>http://bugs.php.net/bug.php?id=40578</url> 3876 </references> 3877 <dates> 3878 <discovery>2007-06-21</discovery> 3879 <entry>2007-06-29</entry> 3880 </dates> 3881 </vuln> 3882 3883 <vuln vid="b1b5c125-2308-11dc-b91a-001921ab2fa4"> 3884 <topic>evolution-data-server -- remote execution of arbitrary code vulnerability</topic> 3885 <affects> 3886 <package> 3887 <name>evolution-data-server</name> 3888 <range><lt>1.10.2_1</lt></range> 3889 <range><gt>1.11.*</gt><lt>1.11.4</lt></range> 3890 </package> 3891 </affects> 3892 <description> 3893 <body xmlns="http://www.w3.org/1999/xhtml"> 3894 <p>Debian project reports:</p> 3895 <blockquote cite="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00082.html"> 3896 <p>It was discovered that the IMAP code in the Evolution 3897 Data Server performs insufficient sanitising of a value 3898 later used an array index, which can lead to the execution 3899 of arbitrary code.</p> 3900 </blockquote> 3901 </body> 3902 </description> 3903 <references> 3904 <cvename>CVE-2007-3257</cvename> 3905 <url>http://secunia.com/advisories/25766/</url> 3906 <url>http://bugzilla.gnome.org/show_bug.cgi?id=447414</url> 3907 </references> 3908 <dates> 3909 <discovery>2007-06-23</discovery> 3910 <entry>2007-06-25</entry> 3911 <modified>2007-06-28</modified> 3912 </dates> 3913 </vuln> 3914 3915 <vuln vid="d337b206-200f-11dc-a197-0011098b2f36"> 3916 <topic>xpcd -- buffer overflow</topic> 3917 <affects> 3918 <package> 3919 <name>xpcd</name> 3920 <range><gt>0</gt></range> 3921 </package> 3922 </affects> 3923 <description> 3924 <body xmlns="http://www.w3.org/1999/xhtml"> 3925 <p>Debian Project reports:</p> 3926 <blockquote cite="http://www.debian.org/security/2005/dsa-676"> 3927 <p>Erik Sjolund discovered a buffer overflow in pcdsvgaview, 3928 an SVGA PhotoCD viewer. xpcd-svga is part of xpcd and uses 3929 svgalib to display graphics on the Linux console for which 3930 root permissions are required. A malicious user could 3931 overflow a fixed-size buffer and may cause the program to 3932 execute arbitrary code with elevated privileges.</p> 3933 </blockquote> 3934 </body> 3935 </description> 3936 <references> 3937 <bid>12523</bid> 3938 <cvename>CVE-2005-0074</cvename> 3939 <url>http://www.debian.org/security/2005/dsa-676</url> 3940 </references> 3941 <dates> 3942 <discovery>2005-02-11</discovery> 3943 <entry>2007-06-21</entry> 3944 </dates> 3945 </vuln> 3946 3947 <vuln vid="903654bd-1927-11dc-b8a0-02e0185f8d72"> 3948 <topic>clamav -- multiple vulnerabilities</topic> 3949 <affects> 3950 <package> 3951 <name>clamav</name> 3952 <range><lt>0.90.3</lt></range> 3953 </package> 3954 </affects> 3955 <description> 3956 <body xmlns="http://www.w3.org/1999/xhtml"> 3957 <p>Clamav had been found vulnerable to multiple vulnerabilities:</p> 3958 <ul> 3959 <li>Improper checking for the end of an buffer causing an 3960 unspecified attack vector.</li> 3961 <li>Insecure temporary file handling, which could be exploited 3962 to read sensitive information.</li> 3963 <li>A flaw in the parser engine which could allow a remote 3964 attacker to bypass the scanning of RAR files.</li> 3965 <li>A flaw in libclamav/unrar.c which could cause a remote 3966 Denial of Service (DoS) by sending a specially crafted 3967 RAR file with a modified vm_codesize.</li> 3968 <li>A flaw in the OLE2 parser which could cause a remote 3969 Denial of Service (DoS).</li> 3970 </ul> 3971 </body> 3972 </description> 3973 <references> 3974 <cvename>CVE-2007-2650</cvename> 3975 <cvename>CVE-2007-3023</cvename> 3976 <cvename>CVE-2007-3024</cvename> 3977 <cvename>CVE-2007-3122</cvename> 3978 <cvename>CVE-2007-3123</cvename> 3979 <url>http://news.gmane.org/gmane.comp.security.virus.clamav.devel/cutoff=2853</url> 3980 </references> 3981 <dates> 3982 <discovery>2007-04-18</discovery> 3983 <entry>2007-06-19</entry> 3984 </dates> 3985 </vuln> 3986 3987 <vuln vid="8092b820-1d6f-11dc-a0b2-001921ab2fa4"> 3988 <topic>p5-Mail-SpamAssassin -- local user symlink-attack DoS vulnerability</topic> 3989 <affects> 3990 <package> 3991 <name>p5-Mail-SpamAssassin</name> 3992 <range><lt>3.2.1</lt></range> 3993 </package> 3994 </affects> 3995 <description> 3996 <body xmlns="http://www.w3.org/1999/xhtml"> 3997 <p>SpamAssassin website reports:</p> 3998 <blockquote cite="http://spamassassin.apache.org/advisories/cve-2007-2873.txt"> 3999 <p>A local user symlink-attack DoS vulnerability in 4000 SpamAssassin has been found, affecting versions 3.1.x, 4001 3.2.0, and SVN trunk.</p> 4002 </blockquote> 4003 </body> 4004 </description> 4005 <references> 4006 <url>http://spamassassin.apache.org/advisories/cve-2007-2873.txt</url> 4007 <cvename>CVE-2007-2873</cvename> 4008 </references> 4009 <dates> 4010 <discovery>2007-06-11</discovery> 4011 <entry>2007-06-18</entry> 4012 </dates> 4013 </vuln> 4014 4015 <vuln vid="39988ee8-1918-11dc-b6bd-0016179b2dd5"> 4016 <topic>cups -- Incomplete SSL Negotiation Denial of Service</topic> 4017 <affects> 4018 <package> 4019 <name>cups-base</name> 4020 <range><lt>1.2.11</lt></range> 4021 </package> 4022 </affects> 4023 <description> 4024 <body xmlns="http://www.w3.org/1999/xhtml"> 4025 <p>Secunia reports:</p> 4026 <blockquote cite="http://secunia.com/advisories/24517/"> 4027 <p>CUPS is not using multiple workers to handle connections. 4028 This can be exploited to stop CUPS from accepting new connections 4029 by starting but never completing an SSL negotiation.</p> 4030 </blockquote> 4031 </body> 4032 </description> 4033 <references> 4034 <url>http://secunia.com/advisories/24517/</url> 4035 <url>http://security.gentoo.org/glsa/glsa-200703-28.xml</url> 4036 <cvename>CVE-2007-0720</cvename> 4037 </references> 4038 <dates> 4039 <discovery>2007-05-05</discovery> 4040 <entry>2007-06-12</entry> 4041 </dates> 4042 </vuln> 4043 4044 <vuln vid="70ae62b0-16b0-11dc-b803-0016179b2dd5"> 4045 <topic>c-ares -- DNS Cache Poisoning Vulnerability</topic> 4046 <affects> 4047 <package> 4048 <name>c-ares</name> 4049 <range><lt>1.4.0</lt></range> 4050 </package> 4051 </affects> 4052 <description> 4053 <body xmlns="http://www.w3.org/1999/xhtml"> 4054 <p>Secunia reports:</p> 4055 <blockquote cite="http://secunia.com/advisories/25579/"> 4056 <p>The vulnerability is caused due to predictable 4057 DNS "Transaction ID" field in DNS queries and can 4058 be exploited to poison the DNS cache of an application 4059 using the library if a valid ID is guessed.</p> 4060 </blockquote> 4061 </body> 4062 </description> 4063 <references> 4064 <cvename>CVE-2007-3152</cvename> 4065 <cvename>CVE-2007-3153</cvename> 4066 <url>http://secunia.com/advisories/25579/</url> 4067 <url>http://cool.haxx.se/cvs.cgi/curl/ares/CHANGES?rev=HEAD&content-type=text/vnd.viewcvs-markup</url> 4068 </references> 4069 <dates> 4070 <discovery>2007-06-08</discovery> 4071 <entry>2007-06-09</entry> 4072 <modified>2010-05-12</modified> 4073 </dates> 4074 </vuln> 4075 4076 <vuln vid="0838733d-1698-11dc-a197-0011098b2f36"> 4077 <topic>wordpress -- XMLRPC SQL Injection</topic> 4078 <affects> 4079 <package> 4080 <name>wordpress</name> 4081 <name>de-wordpress</name> 4082 <name>zh-wordpress</name> 4083 <range><lt>2.2.1</lt></range> 4084 </package> 4085 </affects> 4086 <description> 4087 <body xmlns="http://www.w3.org/1999/xhtml"> 4088 <p>Secunia reports:</p> 4089 <blockquote cite="http://secunia.com/advisories/25552/"> 4090 <p>Slappter has discovered a vulnerability in WordPress, which can 4091 be exploited by malicious users to conduct SQL injection 4092 attacks.</p> 4093 <p>Input passed to the "wp.suggestCategories" method in xmlrpc.php 4094 is not properly sanitised before being used in SQL queries. This 4095 can be exploited to manipulate SQL queries by injecting arbitrary 4096 SQL code.</p> 4097 <p>Successful exploitation allows e.g. retrieving usernames and 4098 password hashes, but requires valid user credentials and knowledge 4099 of the database table prefix.</p> 4100 </blockquote> 4101 </body> 4102 </description> 4103 <references> 4104 <bid>24344</bid> 4105 <url>http://secunia.com/advisories/25552/</url> 4106 </references> 4107 <dates> 4108 <discovery>2007-06-06</discovery> 4109 <entry>2007-06-09</entry> 4110 <modified>2007-06-24</modified> 4111 </dates> 4112 </vuln> 4113 4114 <vuln vid="6a31cbe3-1695-11dc-a197-0011098b2f36"> 4115 <topic>wordpress -- unmoderated comments disclosure</topic> 4116 <affects> 4117 <package> 4118 <name>wordpress</name> 4119 <name>de-wordpress</name> 4120 <name>zh-wordpress</name> 4121 <range><lt>2.2.2</lt></range> 4122 </package> 4123 </affects> 4124 <description> 4125 <body xmlns="http://www.w3.org/1999/xhtml"> 4126 <p>Blogsecurity reports:</p> 4127 <blockquote cite="http://blogsecurity.net/news/news-310507/"> 4128 <p>An attacker can read comments on posts that have not been 4129 moderated. This can be a real security risk if blog admins 4130 are using unmoderated comments (comments that have not been 4131 made public) to hide sensitive notes regarding posts, future 4132 work, passwords etc. So please be careful if you are one of 4133 these blog admins.</p> 4134 </blockquote> 4135 </body> 4136 </description> 4137 <references> 4138 <url>http://blogsecurity.net/news/news-310507/</url> 4139 </references> 4140 <dates> 4141 <discovery>2007-06-01</discovery> 4142 <entry>2007-06-09</entry> 4143 <modified>2007-08-16</modified> 4144 </dates> 4145 </vuln> 4146 4147 <vuln vid="12b7286f-16a2-11dc-b803-0016179b2dd5"> 4148 <topic>webmin -- cross site scripting vulnerability</topic> 4149 <affects> 4150 <package> 4151 <name>webmin</name> 4152 <range><lt>1.350</lt></range> 4153 </package> 4154 </affects> 4155 <description> 4156 <body xmlns="http://www.w3.org/1999/xhtml"> 4157 <p>Secunia reports:</p> 4158 <blockquote cite="http://secunia.com/advisories/25580/"> 4159 <p>Input passed to unspecified parameters in pam_login.cgi 4160 is not properly sanitised before being returned to the 4161 user. This can be exploited to execute arbitrary HTML and 4162 script code in a user's browser session in context of an 4163 affected site.</p> 4164 </blockquote> 4165 </body> 4166 </description> 4167 <references> 4168 <bid>24381</bid> 4169 <cvename>CVE-2007-3156</cvename> 4170 <url>http://secunia.com/advisories/25580/</url> 4171 <url>http://www.webmin.com/changes-1.350.html</url> 4172 </references> 4173 <dates> 4174 <discovery>2007-06-01</discovery> 4175 <entry>2007-06-09</entry> 4176 <modified>2010-05-12</modified> 4177 </dates> 4178 </vuln> 4179 4180 <vuln vid="3ac80dd2-14df-11dc-bcfc-0016179b2dd5"> 4181 <topic>mplayer -- cddb stack overflow</topic> 4182 <affects> 4183 <package> 4184 <name>mplayer</name> 4185 <name>mplayer-esound</name> 4186 <name>mplayer-gtk</name> 4187 <name>mplayer-gtk2</name> 4188 <name>mplayer-gtk-esound</name> 4189 <name>mplayer-gtk2-esound</name> 4190 <range><lt>0.99.10_10</lt></range> 4191 </package> 4192 </affects> 4193 <description> 4194 <body xmlns="http://www.w3.org/1999/xhtml"> 4195 <p>Mplayer Team reports:</p> 4196 <blockquote cite="http://www.mplayerhq.hu/design7/news.html"> 4197 <p>A stack overflow was found in the code used to handle 4198 cddb queries. When copying the album title and category, 4199 no checking was performed on the size of the strings 4200 before storing them in a fixed-size array. A malicious 4201 entry in the database could trigger a stack overflow in 4202 the program, leading to arbitrary code execution with the 4203 uid of the user running MPlayer.</p> 4204 </blockquote> 4205 </body> 4206 </description> 4207 <references> 4208 <bid>24302</bid> 4209 <cvename>CVE-2007-2948</cvename> 4210 </references> 4211 <dates> 4212 <discovery>2007-06-06</discovery> 4213 <entry>2007-06-07</entry> 4214 </dates> 4215 </vuln> 4216 4217 <vuln vid="d9405748-1342-11dc-a35c-001485ab073e"> 4218 <topic>mod_jk -- information disclosure</topic> 4219 <affects> 4220 <package> 4221 <name>mod_jk</name> 4222 <range><lt>1.2.23,1</lt></range> 4223 </package> 4224 <package> 4225 <name>mod_jk-ap2</name> 4226 <range><lt>1.2.23</lt></range> 4227 </package> 4228 </affects> 4229 <description> 4230 <body xmlns="http://www.w3.org/1999/xhtml"> 4231 <p>Kazu Nambo reports:</p> 4232 <blockquote cite="http://tomcat.apache.org/security-jk.html"> 4233 <p>URL decoding the the Apache webserver prior to 4234 decoding in the Tomcat server could pypass access 4235 control rules and give access to pages on a different 4236 AJP by sending a crafted URL.</p> 4237 </blockquote> 4238 </body> 4239 </description> 4240 <references> 4241 <cvename>CVE-2007-1860</cvename> 4242 <url>http://secunia.com/advisories/25383/</url> 4243 <url>http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1</url> 4244 <url>http://tomcat.apache.org/security-jk.html</url> 4245 </references> 4246 <dates> 4247 <discovery>2007-05-18</discovery> 4248 <entry>2007-06-05</entry> 4249 <modified>2007-10-31</modified> 4250 </dates> 4251 </vuln> 4252 4253 <vuln vid="62b8f253-12d9-11dc-a35c-001485ab073e"> 4254 <topic>typo3 -- email header injection</topic> 4255 <affects> 4256 <package> 4257 <name>typo3</name> 4258 <range><gt>3.0</gt><lt>4.0.5</lt></range> 4259 <range><gt>4.1</gt><lt>4.1.1</lt></range> 4260 </package> 4261 </affects> 4262 <description> 4263 <body xmlns="http://www.w3.org/1999/xhtml"> 4264 <p>Olivier Dobberkau, Andreas Otto, and Thorsten Kahler report:</p> 4265 <blockquote cite="http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/"> 4266 <p>An unspecified error in the internal form engine can be used for 4267 sending arbitrary mail headers, using it for purposes which it 4268 is not meant for, e.g. sending spam messages.</p> 4269 </blockquote> 4270 </body> 4271 </description> 4272 <references> 4273 <cvename>CVE-2007-1081</cvename> 4274 <url>http://secunia.com/advisories/24207/</url> 4275 <url>http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/</url> 4276 </references> 4277 <dates> 4278 <discovery>2007-02-21</discovery> 4279 <entry>2007-06-04</entry> 4280 </dates> 4281 </vuln> 4282 4283 <vuln vid="3d0e724e-129b-11dc-9f79-0016179b2dd5"> 4284 <topic>phppgadmin -- cross site scripting vulnerability</topic> 4285 <affects> 4286 <package> 4287 <name>phppgadmin</name> 4288 <range><lt>4.1.1</lt></range> 4289 </package> 4290 </affects> 4291 <description> 4292 <body xmlns="http://www.w3.org/1999/xhtml"> 4293 <p>SecurityFocus reports about phppgadmin:</p> 4294 <blockquote cite="http://www.securityfocus.com/bid/24115/info"> 4295 <p>Exploiting this vulnerability may allow an attacker to perform 4296 cross-site scripting attacks on unsuspecting users in the context 4297 of the affected website. As a result, the attacker may be able to 4298 steal cookie-based authentication credentials and to launch other 4299 attacks.</p> 4300 </blockquote> 4301 </body> 4302 </description> 4303 <references> 4304 <bid>24115</bid> 4305 <cvename>CVE-2007-5728</cvename> 4306 <url>http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063617.html</url> 4307 <url>http://secunia.com/advisories/25446/</url> 4308 </references> 4309 <dates> 4310 <discovery>2007-05-27</discovery> 4311 <entry>2007-06-04</entry> 4312 <modified>2010-05-12</modified> 4313 </dates> 4314 </vuln> 4315 4316 <vuln vid="7ca2a709-103b-11dc-8e82-00001cd613f9"> 4317 <topic>findutils -- GNU locate heap buffer overrun</topic> 4318 <affects> 4319 <package> 4320 <name>findutils</name> 4321 <range><lt>4.2.31</lt></range> 4322 </package> 4323 </affects> 4324 <description> 4325 <body xmlns="http://www.w3.org/1999/xhtml"> 4326 <p>James Youngman reports:</p> 4327 <blockquote cite="http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html"> 4328 <p>When GNU locate reads filenames from an old-format locate database, 4329 they are read into a fixed-length buffer allocated on the heap. 4330 Filenames longer than the 1026-byte buffer can cause a buffer 4331 overrun. The overrunning data can be chosen by any person able to 4332 control the names of filenames created on the local system. This 4333 will normally include all local users, but in many cases also remote 4334 users (for example in the case of FTP servers allowing uploads).</p> 4335 </blockquote> 4336 </body> 4337 </description> 4338 <references> 4339 <cvename>CVE-2007-2452</cvename> 4340 <mlist>http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html</mlist> 4341 </references> 4342 <dates> 4343 <discovery>2007-05-30</discovery> 4344 <entry>2007-06-01</entry> 4345 </dates> 4346 </vuln> 4347 4348 <vuln vid="de2fab2d-0a37-11dc-aae2-00304881ac9a"> 4349 <topic>FreeType 2 -- Heap overflow vulnerability</topic> 4350 <affects> 4351 <package> 4352 <name>freetype2</name> 4353 <range><lt>2.2.1_2</lt></range> 4354 </package> 4355 </affects> 4356 <description> 4357 <body xmlns="http://www.w3.org/1999/xhtml"> 4358 <blockquote cite="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2754"> 4359 <p>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and 4360 earlier might allow remote attackers to execute arbitrary code via a 4361 crafted TTF image with a negative n_points value, which leads to an 4362 integer overflow and heap-based buffer overflow.</p> 4363 </blockquote> 4364 </body> 4365 </description> 4366 <references> 4367 <cvename>CVE-2007-2754</cvename> 4368 <mlist>http://lists.gnu.org/archive/html/freetype-devel/2007-04/msg00041.html</mlist> 4369 <url>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2754</url> 4370 <url>https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240200</url> 4371 <freebsdpr>ports/112769</freebsdpr> 4372 </references> 4373 <dates> 4374 <discovery>2007-04-27</discovery> 4375 <entry>2007-05-24</entry> 4376 </dates> 4377 </vuln> 4378 4379 <vuln vid="8e01ab5b-0949-11dc-8163-000e0c2e438a"> 4380 <topic>FreeBSD -- heap overflow in file(1)</topic> 4381 <affects> 4382 <package> 4383 <name>file</name> 4384 <range><lt>4.21</lt></range> 4385 </package> 4386 <package> 4387 <name>FreeBSD</name> 4388 <range><ge>6.2</ge><lt>6.2_5</lt></range> 4389 <range><ge>6.1</ge><lt>6.1_17</lt></range> 4390 <range><ge>5.5</ge><lt>5.5_13</lt></range> 4391 </package> 4392 </affects> 4393 <description> 4394 <body xmlns="http://www.w3.org/1999/xhtml"> 4395 <h1>Problem Description:</h1> 4396 <p>When writing data into a buffer in the file_printf function, 4397 the length of the unused portion of the buffer is not 4398 correctly tracked, resulting in a buffer overflow when 4399 processing certain files.</p> 4400 <h1>Impact:</h1> 4401 <p>An attacker who can cause file(1) to be run on a maliciously 4402 constructed input can cause file(1) to crash. It may be 4403 possible for such an attacker to execute arbitrary code with 4404 the privileges of the user running file(1).</p> 4405 <p>The above also applies to any other applications using the 4406 libmagic(3) library.</p> 4407 <h1>Workaround:</h1> 4408 <p>No workaround is available, but systems where file(1) and 4409 other libmagic(3)-using applications are never run on 4410 untrusted input are not vulnerable.</p> 4411 </body> 4412 </description> 4413 <references> 4414 <cvename>CVE-2007-1536</cvename> 4415 <freebsdsa>SA-07:04.file</freebsdsa> 4416 </references> 4417 <dates> 4418 <discovery>2007-05-23</discovery> 4419 <entry>2007-05-23</entry> 4420 <modified>2016-08-09</modified> 4421 </dates> 4422 </vuln> 4423 4424 <vuln vid="0e575ed3-0764-11dc-a80b-0016179b2dd5"> 4425 <topic>squirrelmail -- Cross site scripting in HTML filter</topic> 4426 <affects> 4427 <package> 4428 <name>squirrelmail</name> 4429 <range><ge>1.4.0</ge><lt>1.4.9a</lt></range> 4430 </package> 4431 </affects> 4432 <description> 4433 <body xmlns="http://www.w3.org/1999/xhtml"> 4434 <p>The SquirrelMail developers report:</p> 4435 <blockquote cite="http://www.squirrelmail.org/security/issue/2007-05-09"> 4436 <p>Multiple cross-site scripting (XSS) vulnerabilities in the HTML 4437 filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers 4438 to inject arbitrary web script or HTML via the (1) data: URI in an 4439 HTML e-mail attachment or (2) various non-ASCII character sets that 4440 are not properly filtered when viewed with Microsoft Internet 4441 Explorer.</p> 4442 </blockquote> 4443 </body> 4444 </description> 4445 <references> 4446 <cvename>CVE-2007-1262</cvename> 4447 <url>http://www.squirrelmail.org/security/issue/2007-05-09</url> 4448 </references> 4449 <dates> 4450 <discovery>2007-05-09</discovery> 4451 <entry>2007-05-21</entry> 4452 </dates> 4453 </vuln> 4454 4455 <vuln vid="4cb9c513-03ef-11dc-a51d-0019b95d4f14"> 4456 <topic>png -- DoS crash vulnerability</topic> 4457 <affects> 4458 <package> 4459 <name>png</name> 4460 <range><lt>1.2.17</lt></range> 4461 </package> 4462 </affects> 4463 <description> 4464 <body xmlns="http://www.w3.org/1999/xhtml"> 4465 <p>A Libpng Security Advisory reports:</p> 4466 <blockquote cite="http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt"> 4467 <p>A grayscale PNG image with a malformed (bad CRC) tRNS 4468 chunk will crash some libpng applications.</p> 4469 <p>This vulnerability could be used to crash a browser when 4470 a user tries to view such a malformed PNG file. It is not 4471 known whether the vulnerability could be exploited 4472 otherwise.</p> 4473 </blockquote> 4474 </body> 4475 </description> 4476 <references> 4477 <cvename>CVE-2007-2445</cvename> 4478 <certvu>684664</certvu> 4479 <url>http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt</url> 4480 </references> 4481 <dates> 4482 <discovery>2007-05-15</discovery> 4483 <entry>2007-05-16</entry> 4484 </dates> 4485 </vuln> 4486 4487 <vuln vid="3546a833-03ea-11dc-a51d-0019b95d4f14"> 4488 <topic>samba -- multiple vulnerabilities</topic> 4489 <affects> 4490 <package> 4491 <name>samba</name> 4492 <name>ja-samba</name> 4493 <range><gt>3.*</gt><lt>3.0.25</lt></range> 4494 <range><gt>3.*,1</gt><lt>3.0.25,1</lt></range> 4495 </package> 4496 </affects> 4497 <description> 4498 <body xmlns="http://www.w3.org/1999/xhtml"> 4499 <p>The Samba Team reports:</p> 4500 <blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2444.html"> 4501 <p>A bug in the local SID/Name translation routines may 4502 potentially result in a user being able to issue SMB/CIFS 4503 protocol operations as root.</p> 4504 <p>When translating SIDs to/from names using Samba local 4505 list of user and group accounts, a logic error in the smbd 4506 daemon's internal security stack may result in a 4507 transition to the root user id rather than the non-root 4508 user. The user is then able to temporarily issue SMB/CIFS 4509 protocol operations as the root user. This window of 4510 opportunity may allow the attacker to establish additional 4511 means of gaining root access to the server.</p> 4512 </blockquote> 4513 <blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2446.html"> 4514 <p>Various bugs in Samba's NDR parsing can allow a user to 4515 send specially crafted MS-RPC requests that will overwrite 4516 the heap space with user defined data.</p> 4517 </blockquote> 4518 <blockquote cite="http://de5.samba.org/samba/security/CVE-2007-2447.html"> 4519 <p>Unescaped user input parameters are passed as arguments 4520 to /bin/sh allowing for remote command execution.</p> 4521 <p>This bug was originally reported against the anonymous 4522 calls to the SamrChangePassword() MS-RPC function in 4523 combination with the "username map script" smb.conf option 4524 (which is not enabled by default).</p> 4525 <p>After further investigation by Samba developers, it was 4526 determined that the problem was much broader and impacts 4527 remote printer and file share management as well. The 4528 root cause is passing unfiltered user input provided via 4529 MS-RPC calls to /bin/sh when invoking externals scripts 4530 defined in smb.conf. However, unlike the "username map 4531 script" vulnerability, the remote file and printer 4532 management scripts require an authenticated user 4533 session.</p> 4534 </blockquote> 4535 </body> 4536 </description> 4537 <references> 4538 <cvename>CVE-2007-2444</cvename> 4539 <cvename>CVE-2007-2446</cvename> 4540 <cvename>CVE-2007-2447</cvename> 4541 <url>http://de5.samba.org/samba/security/CVE-2007-2444.html</url> 4542 <url>http://de5.samba.org/samba/security/CVE-2007-2446.html</url> 4543 <url>http://de5.samba.org/samba/security/CVE-2007-2447.html</url> 4544 </references> 4545 <dates> 4546 <discovery>2007-05-14</discovery> 4547 <entry>2007-05-16</entry> 4548 <modified>2008-09-26</modified> 4549 </dates> 4550 </vuln> 4551 4552 <vuln vid="f5e52bf5-fc77-11db-8163-000e0c2e438a"> 4553 <topic>php -- multiple vulnerabilities</topic> 4554 <affects> 4555 <package> 4556 <name>php5-imap</name> 4557 <name>php5-odbc</name> 4558 <name>php5-session</name> 4559 <name>php5-shmop</name> 4560 <name>php5-sqlite</name> 4561 <name>php5-wddx</name> 4562 <name>php5</name> 4563 <range><lt>5.2.2</lt></range> 4564 </package> 4565 <package> 4566 <name>php4-odbc</name> 4567 <name>php4-session</name> 4568 <name>php4-shmop</name> 4569 <name>php4-wddx</name> 4570 <name>php4</name> 4571 <range><lt>4.4.7</lt></range> 4572 </package> 4573 <package> 4574 <name>mod_php4-twig</name> 4575 <name>mod_php4</name> 4576 <name>mod_php5</name> 4577 <name>mod_php</name> 4578 <name>php4-cgi</name> 4579 <name>php4-cli</name> 4580 <name>php4-dtc</name> 4581 <name>php4-horde</name> 4582 <name>php4-nms</name> 4583 <name>php5-cgi</name> 4584 <name>php5-cli</name> 4585 <name>php5-dtc</name> 4586 <name>php5-horde</name> 4587 <name>php5-nms</name> 4588 <range><ge>4</ge><lt>4.4.7</lt></range> 4589 <range><ge>5</ge><lt>5.2.2</lt></range> 4590 </package> 4591 </affects> 4592 <description> 4593 <body xmlns="http://www.w3.org/1999/xhtml"> 4594 <p>The PHP development team reports:</p> 4595 <blockquote cite="http://www.php.net/releases/5_2_2.php"> 4596 <p>Security Enhancements and Fixes in PHP 5.2.2 and PHP 4597 4.4.7:</p> 4598 <ul> 4599 <li>Fixed CVE-2007-1001, GD wbmp used with invalid image 4600 size</li> 4601 <li>Fixed asciiz byte truncation inside mail()</li> 4602 <li>Fixed a bug in mb_parse_str() that can be used to 4603 activate register_globals</li> 4604 <li>Fixed unallocated memory access/double free in in 4605 array_user_key_compare()</li> 4606 <li>Fixed a double free inside session_regenerate_id()</li> 4607 <li>Added missing open_basedir & safe_mode checks to zip:// 4608 and bzip:// wrappers.</li> 4609 <li>Limit nesting level of input variables with 4610 max_input_nesting_level as fix for.</li> 4611 <li>Fixed CRLF injection inside ftp_putcmd().</li> 4612 <li>Fixed a possible super-global overwrite inside 4613 import_request_variables().</li> 4614 <li>Fixed a remotely trigger-able buffer overflow inside 4615 bundled libxmlrpc library.</li> 4616 </ul> 4617 <p>Security Enhancements and Fixes in PHP 5.2.2 only:</p> 4618 <ul> 4619 <li>Fixed a header injection via Subject and To parameters 4620 to the mail() function</li> 4621 <li>Fixed wrong length calculation in unserialize S 4622 type.</li> 4623 <li>Fixed substr_compare and substr_count information 4624 leak.</li> 4625 <li>Fixed a remotely trigger-able buffer overflow inside 4626 make_http_soap_request().</li> 4627 <li>Fixed a buffer overflow inside 4628 user_filter_factory_create().</li> 4629 </ul> 4630 <p>Security Enhancements and Fixes in PHP 4.4.7 only:</p> 4631 <ul> 4632 <li>XSS in phpinfo()</li> 4633 </ul> 4634 </blockquote> 4635 </body> 4636 </description> 4637 <references> 4638 <cvename>CVE-2007-1001</cvename> 4639 <url>http://www.php.net/releases/4_4_7.php</url> 4640 <url>http://www.php.net/releases/5_2_2.php</url> 4641 </references> 4642 <dates> 4643 <discovery>2007-05-03</discovery> 4644 <entry>2007-05-07</entry> 4645 <modified>2014-04-01</modified> 4646 </dates> 4647 </vuln> 4648 4649 <vuln vid="0ac89b39-f829-11db-b55c-000e0c6d38a9"> 4650 <topic>qemu -- several vulnerabilities</topic> 4651 <affects> 4652 <package> 4653 <name>qemu</name> 4654 <name>qemu-devel</name> 4655 <range><lt>0.9.0_1</lt></range> 4656 <range><ge>0.9.0s.20070101*</ge><lt>0.9.0s.20070405_3</lt></range> 4657 </package> 4658 </affects> 4659 <description> 4660 <body xmlns="http://www.w3.org/1999/xhtml"> 4661 <p>The Debian Security Team reports:</p> 4662 <blockquote cite="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html"> 4663 <p>Several vulnerabilities have been discovered in the QEMU processor 4664 emulator, which may lead to the execution of arbitrary code or 4665 denial of service. The Common Vulnerabilities and Exposures project 4666 identifies the following problems:</p> 4667 <p>CVE-2007-1320<br/>Tavis Ormandy discovered that a memory management 4668 routine of the Cirrus video driver performs insufficient bounds 4669 checking, which might allow the execution of arbitrary code through 4670 a heap overflow.</p> 4671 <p>CVE-2007-1321<br/>Tavis Ormandy discovered that the NE2000 network 4672 driver and the socket code perform insufficient input validation, 4673 which might allow the execution of arbitrary code through a heap 4674 overflow.</p> 4675 <p>CVE-2007-1322<br/>Tavis Ormandy discovered that the "icebp" 4676 instruction can be abused to terminate the emulation, resulting in 4677 denial of service.</p> 4678 <p>CVE-2007-1323<br/>Tavis Ormandy discovered that the NE2000 network 4679 driver and the socket code perform insufficient input validation, 4680 which might allow the execution of arbitrary code through a heap 4681 overflow.</p> 4682 <p>CVE-2007-1366<br/>Tavis Ormandy discovered that the "aam" 4683 instruction can be abused to crash qemu through a division by zero, 4684 resulting in denial of service.</p> 4685 </blockquote> 4686 </body> 4687 </description> 4688 <references> 4689 <cvename>CVE-2007-1320</cvename> 4690 <cvename>CVE-2007-1321</cvename> 4691 <cvename>CVE-2007-1322</cvename> 4692 <cvename>CVE-2007-1323</cvename> 4693 <cvename>CVE-2007-1366</cvename> 4694 <mlist msgid="20070501100313.GA4074@galadriel.inutil.org">http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html</mlist> 4695 </references> 4696 <dates> 4697 <discovery>2007-05-01</discovery> 4698 <entry>2007-05-01</entry> 4699 <modified>2007-05-02</modified> 4700 </dates> 4701 </vuln> 4702 4703 <vuln vid="632c98be-aad2-4af2-849f-41a6862afd6a"> 4704 <topic>p5-Imager -- possibly exploitable buffer overflow</topic> 4705 <affects> 4706 <package> 4707 <name>p5-Imager</name> 4708 <range><lt>0.57</lt></range> 4709 </package> 4710 </affects> 4711 <description> 4712 <body xmlns="http://www.w3.org/1999/xhtml"> 4713 <p>Imager 0.56 and all earlier versions with BMP support have 4714 a security issue when reading compressed 8-bit per pixel BMP 4715 files where either a compressed run of data or a literal run 4716 of data overflows the scan-line.</p> 4717 <p>Such an overflow causes a buffer overflow in a malloc() 4718 allocated memory buffer, possibly corrupting the memory arena 4719 headers.</p> 4720 <p>The effect depends on your system memory allocator, with glibc 4721 this typically results in an abort, but with other memory 4722 allocators it may be possible to cause local code execution.</p> 4723 </body> 4724 </description> 4725 <references> 4726 <cvename>CVE-2007-1942</cvename> 4727 <cvename>CVE-2007-1943</cvename> 4728 <cvename>CVE-2007-1946</cvename> 4729 <cvename>CVE-2007-1948</cvename> 4730 <url>https://rt.cpan.org/Public/Bug/Display.html?id=26811</url> 4731 <url>http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</url> 4732 </references> 4733 <dates> 4734 <discovery>2007-04-04</discovery> 4735 <entry>2007-04-30</entry> 4736 <modified>2010-05-12</modified> 4737 </dates> 4738 </vuln> 4739 4740 <vuln vid="275b845e-f56c-11db-8163-000e0c2e438a"> 4741 <topic>FreeBSD -- IPv6 Routing Header 0 is dangerous</topic> 4742 <affects> 4743 <package> 4744 <name>FreeBSD</name> 4745 <range><ge>6.2</ge><lt>6.2_4</lt></range> 4746 <range><ge>6.1</ge><lt>6.1_16</lt></range> 4747 <range><ge>5.5</ge><lt>5.5_12</lt></range> 4748 </package> 4749 </affects> 4750 <description> 4751 <body xmlns="http://www.w3.org/1999/xhtml"> 4752 <h1>Problem Description</h1> 4753 <p>There is no mechanism for preventing IPv6 routing headers 4754 from being used to route packets over the same link(s) many 4755 times.</p> 4756 <h1>Impact</h1> 4757 <p>An attacker can "amplify" a denial of service attack against 4758 a link between two vulnerable hosts; that is, by sending a 4759 small volume of traffic the attacker can consume a much larger 4760 amount of bandwidth between the two vulnerable hosts.</p> 4761 <p>An attacker can use vulnerable hosts to "concentrate" a 4762 denial of service attack against a victim host or network; 4763 that is, a set of packets sent over a period of 30 seconds 4764 or more could be constructed such that they all arrive at 4765 the victim within a period of 1 second or less over a 4766 period of 30 seconds or more could be constructed such that 4767 they all arrive at the victim within a period of 1 second or 4768 less.</p> 4769 <p>Other attacks may also be possible.</p> 4770 <h1>Workaround</h1> 4771 <p>No workaround is available.</p> 4772 </body> 4773 </description> 4774 <references> 4775 <cvename>CVE-2007-2242</cvename> 4776 <freebsdsa>SA-07:03.ipv6</freebsdsa> 4777 </references> 4778 <dates> 4779 <discovery>2007-04-26</discovery> 4780 <entry>2007-04-28</entry> 4781 <modified>2016-08-09</modified> 4782 </dates> 4783 </vuln> 4784 4785 <vuln vid="ef2ffb03-f2b0-11db-ad25-0010b5a0a860"> 4786 <topic>mod_perl -- remote DoS in PATH_INFO parsing</topic> 4787 <affects> 4788 <package> 4789 <name>mod_perl</name> 4790 <range><lt>1.30</lt></range> 4791 </package> 4792 <package> 4793 <name>mod_perl2</name> 4794 <range><lt>2.0.3_2,3</lt></range> 4795 </package> 4796 </affects> 4797 <description> 4798 <body xmlns="http://www.w3.org/1999/xhtml"> 4799 <p>Mandriva reports:</p> 4800 <blockquote cite="http://www.mandriva.com/security/advisories?name=MDKSA-2007:083"> 4801 <p>PerlRun.pm in Apache mod_perl 1.29 and earlier, and 4802 RegistryCooker.pm in mod_perl 2.x, does not properly escape 4803 PATH_INFO before use in a regular expression, which allows remote 4804 attackers to cause a denial of service (resource consumption) via a 4805 crafted URI.</p> 4806 </blockquote> 4807 </body> 4808 </description> 4809 <references> 4810 <cvename>CVE-2007-1349</cvename> 4811 <url>http://www.mandriva.com/security/advisories?name=MDKSA-2007:083</url> 4812 <url>http://secunia.com/advisories/24839</url> 4813 </references> 4814 <dates> 4815 <discovery>2007-03-29</discovery> 4816 <entry>2007-04-24</entry> 4817 <modified>2007-06-27</modified> 4818 </dates> 4819 </vuln> 4820 4821 <vuln vid="c389d06d-ee57-11db-bd51-0016179b2dd5"> 4822 <topic>claws-mail -- APOP vulnerability</topic> 4823 <affects> 4824 <package> 4825 <name>claws-mail</name> 4826 <range><lt>2.9.0</lt></range> 4827 </package> 4828 </affects> 4829 <description> 4830 <body xmlns="http://www.w3.org/1999/xhtml"> 4831 <p>CVE reports:</p> 4832 <blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1558"> 4833 <p>The APOP protocol allows remote attackers to guess the first 3 4834 characters of a password via man-in-the-middle (MITM) attacks 4835 that use crafted message IDs and MD5 collisions.</p> 4836 </blockquote> 4837 </body> 4838 </description> 4839 <references> 4840 <cvename>CVE-2007-1558</cvename> 4841 <url>http://www.claws-mail.org/news.php</url> 4842 </references> 4843 <dates> 4844 <discovery>2007-04-02</discovery> 4845 <entry>2007-04-19</entry> 4846 </dates> 4847 </vuln> 4848 4849 <vuln vid="5678da43-ea99-11db-a802-000fea2763ce"> 4850 <topic>lighttpd -- DOS when access files with mtime 0</topic> 4851 <affects> 4852 <package> 4853 <name>lighttpd</name> 4854 <range><lt>1.4.15</lt></range> 4855 </package> 4856 </affects> 4857 <description> 4858 <body xmlns="http://www.w3.org/1999/xhtml"> 4859 <p>Lighttpd SA:</p> 4860 <blockquote cite="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt"> 4861 <p>Lighttpd caches the rendered string for mtime. The cache key has 4862 as a default value 0. At that point the pointer to the string are 4863 still NULL. If a file with an mtime of 0 is requested it tries to 4864 access the pointer and crashes.</p> 4865 <p>The bug requires that a malicious user can either upload files or 4866 manipulate the mtime of the files.</p> 4867 <p>The bug was reported by cubiq and fixed by Marcus Rueckert.</p> 4868 </blockquote> 4869 </body> 4870 </description> 4871 <references> 4872 <cvename>CVE-2007-1870</cvename> 4873 <url>http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt</url> 4874 </references> 4875 <dates> 4876 <discovery>2007-01-14</discovery> 4877 <entry>2007-04-14</entry> 4878 </dates> 4879 </vuln> 4880 4881 <vuln vid="d2b48d30-ea97-11db-a802-000fea2763ce"> 4882 <topic>lighttpd -- Remote DOS in CRLF parsing</topic> 4883 <affects> 4884 <package> 4885 <name>lighttpd</name> 4886 <range><gt>1.4.11</gt><lt>1.4.13_2</lt></range> 4887 </package> 4888 </affects> 4889 <description> 4890 <body xmlns="http://www.w3.org/1999/xhtml"> 4891 <p>Lighttpd SA:</p> 4892 <blockquote cite="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt"> 4893 <p>If the connection aborts during parsing "\r\n\r\n" the server 4894 might get into a infinite loop and use 100% of the CPU time. 4895 lighttpd still responses to other requests. This can be repeated 4896 until either the server limit for concurrent connections or file 4897 descriptors is reached.</p> 4898 <p>The bug was reported and fixed by Robert Jakabosky.</p> 4899 </blockquote> 4900 </body> 4901 </description> 4902 <references> 4903 <cvename>CVE-2007-1869</cvename> 4904 <url>http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt</url> 4905 </references> 4906 <dates> 4907 <discovery>2006-12-15</discovery> 4908 <entry>2007-04-14</entry> 4909 </dates> 4910 </vuln> 4911 4912 <vuln vid="c110eda2-e995-11db-a944-0012f06707f0"> 4913 <topic>freeradius -- EAP-TTLS Tunnel Memory Leak Remote DOS Vulnerability</topic> 4914 <affects> 4915 <package> 4916 <name>freeradius</name> 4917 <name>freeradius-mysql</name> 4918 <range><le>1.1.5</le></range> 4919 </package> 4920 </affects> 4921 <description> 4922 <body xmlns="http://www.w3.org/1999/xhtml"> 4923 <p>The freeradius development team reports:</p> 4924 <blockquote cite="http://www.freeradius.org/security.html"> 4925 <p>A malicious 802.1x supplicant could send malformed Diameter format 4926 attributes inside of an EAP-TTLS tunnel. The server would reject 4927 the authentication request, but would leak one VALUE_PAIR data 4928 structure, of approximately 300 bytes. If an attacker performed 4929 the attack many times (e.g. thousands or more over a period of 4930 minutes to hours), the server could leak megabytes of memory, 4931 potentially leading to an "out of memory" condition, and early 4932 process exit.</p> 4933 </blockquote> 4934 </body> 4935 </description> 4936 <references> 4937 <bid>23466</bid> 4938 <cvename>CVE-2005-1455</cvename> 4939 <cvename>CVE-2005-1454</cvename> 4940 <cvename>CVE-2007-2028</cvename> 4941 <cvename>CVE-2005-4745</cvename> 4942 <url>http://www.freeradius.org/security.html</url> 4943 </references> 4944 <dates> 4945 <discovery>2007-04-10</discovery> 4946 <entry>2007-04-13</entry> 4947 <modified>2010-05-12</modified> 4948 </dates> 4949 </vuln> 4950 4951 <vuln vid="f1c4d133-e6d3-11db-99ea-0060084a00e5"> 4952 <topic>fetchmail -- insecure APOP authentication</topic> 4953 <affects> 4954 <package> 4955 <name>fetchmail</name> 4956 <range><lt>6.3.8</lt></range> 4957 </package> 4958 </affects> 4959 <description> 4960 <body xmlns="http://www.w3.org/1999/xhtml"> 4961 <p>Matthias Andree reports:</p> 4962 <blockquote cite="http://www.fetchmail.info/fetchmail-SA-2007-01.txt"> 4963 <p>The POP3 standard, currently RFC-1939, has specified an optional, 4964 MD5-based authentication scheme called "APOP" which no longer 4965 should be considered secure.</p> 4966 <p>Additionally, fetchmail's POP3 client implementation has been 4967 validating the APOP challenge too lightly and accepted random 4968 garbage as a POP3 server's APOP challenge. This made it easier 4969 than necessary for man-in-the-middle attackers to retrieve by 4970 several probing and guessing the first three characters of the 4971 APOP secret, bringing brute forcing the remaining characters well 4972 within reach.</p> 4973 </blockquote> 4974 </body> 4975 </description> 4976 <references> 4977 <cvename>CVE-2007-1558</cvename> 4978 <url>http://www.fetchmail.info/fetchmail-SA-2007-01.txt</url> 4979 </references> 4980 <dates> 4981 <discovery>2007-04-06</discovery> 4982 <entry>2007-04-09</entry> 4983 </dates> 4984 </vuln> 4985 4986 <vuln vid="84d3fbb2-e607-11db-8a32-000c76189c4c"> 4987 <topic>mcweject -- exploitable buffer overflow</topic> 4988 <affects> 4989 <package> 4990 <name>mcweject</name> 4991 <range><le>0.9</le></range> 4992 </package> 4993 </affects> 4994 <description> 4995 <body xmlns="http://www.w3.org/1999/xhtml"> 4996 <p>CVE reports:</p> 4997 <blockquote cite="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1719"> 4998 <p>Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on 4999 FreeBSD, and possibly other versions, allows local users to execute 5000 arbitrary code via a long command line argument, possibly involving 5001 the device name.</p> 5002 </blockquote> 5003 </body> 5004 </description> 5005 <references> 5006 <cvename>CVE-2007-1719</cvename> 5007 <freebsdpr>ports/111365</freebsdpr> 5008 <url>http://www.milw0rm.com/exploits/3578</url> 5009 </references> 5010 <dates> 5011 <discovery>2007-03-27</discovery> 5012 <entry>2007-04-08</entry> 5013 </dates> 5014 </vuln> 5015 5016 <vuln vid="72999d57-d6f6-11db-961b-005056847b26"> 5017 <topic>WebCalendar -- "noSet" variable overwrite vulnerability</topic> 5018 <affects> 5019 <package> 5020 <name>WebCalendar</name> 5021 <range><lt>1.0.5</lt></range> 5022 </package> 5023 </affects> 5024 <description> 5025 <body xmlns="http://www.w3.org/1999/xhtml"> 5026 <p>Secunia reports:</p> 5027 <blockquote cite="http://secunia.com/advisories/24403/"> 5028 <p>A vulnerability has been discovered in WebCalendar, 5029 which can be exploited by malicious people to compromise 5030 a vulnerable system.</p> 5031 <p>Input passed to unspecified parameters is not properly 5032 verified before being used with the "noSet" parameter set. 5033 This can be exploited to overwrite certain variables, and 5034 allows e.g. the inclusion of arbitrary PHP files from internal 5035 or external resources.</p> 5036 </blockquote> 5037 </body> 5038 </description> 5039 <references> 5040 <cvename>CVE-2007-1343</cvename> 5041 <bid>22834</bid> 5042 <url>http://sourceforge.net/project/shownotes.php?release_id=491130</url> 5043 <url>http://xforce.iss.net/xforce/xfdb/32832</url> 5044 </references> 5045 <dates> 5046 <discovery>2007-03-04</discovery> 5047 <entry>2007-04-08</entry> 5048 </dates> 5049 </vuln> 5050 5051 <vuln vid="34414a1e-e377-11db-b8ab-000c76189c4c"> 5052 <topic>zope -- cross-site scripting vulnerability</topic> 5053 <affects> 5054 <package> 5055 <name>zope</name> 5056 <range><lt>2.7.9_2</lt></range> 5057 <range><ge>2.8.0</ge><le>2.8.8</le></range> 5058 <range><ge>2.9.0</ge><le>2.9.6</le></range> 5059 <range><ge>2.10.0</ge><le>2.10.2</le></range> 5060 </package> 5061 <package> 5062 <name>plone</name> 5063 <range><lt>2.5.3</lt></range> 5064 </package> 5065 </affects> 5066 <description> 5067 <body xmlns="http://www.w3.org/1999/xhtml"> 5068 <p>The Zope Team reports:</p> 5069 <blockquote cite="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view"> 5070 <p>A vulnerability has been discovered in Zope, where by certain types 5071 of misuse of HTTP GET, an attacker could gain elevated privileges. 5072 All Zope versions up to and including 2.10.2 are affected.</p> 5073 </blockquote> 5074 </body> 5075 </description> 5076 <references> 5077 <bid>23084</bid> 5078 <cvename>CVE-2007-0240</cvename> 5079 <freebsdpr>ports/111119</freebsdpr> 5080 <url>http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view</url> 5081 <url>http://plone.org/products/plone/releases/2.5.3</url> 5082 </references> 5083 <dates> 5084 <discovery>2007-01-16</discovery> 5085 <entry>2007-04-05</entry> 5086 <modified>2009-03-22</modified> 5087 </dates> 5088 </vuln> 5089 5090 <vuln vid="c27bc173-d7aa-11db-b141-0016179b2dd5"> 5091 <topic>Squid -- TRACE method handling denial of service</topic> 5092 <affects> 5093 <package> 5094 <name>squid</name> 5095 <range><ge>2.6.*</ge><lt>2.6.12</lt></range> 5096 </package> 5097 </affects> 5098 <description> 5099 <body xmlns="http://www.w3.org/1999/xhtml"> 5100 <p>Squid advisory 2007:1 notes:</p> 5101 <blockquote cite="http://www.squid-cache.org/Advisories/SQUID-2007_1.txt"> 5102 <p>Due to an internal error Squid-2.6 is vulnerable to a denial of 5103 service attack when processing the TRACE request method.</p> 5104 <p>Workarounds:</p> 5105 <p>To work around the problem deny access to using the TRACE method by 5106 inserting the following two lines before your first http_access 5107 rule.</p> 5108 <p>acl TRACE method TRACE</p> 5109 <p>http_access deny TRACE</p> 5110 </blockquote> 5111 </body> 5112 </description> 5113 <references> 5114 <cvename>CVE-2007-1560</cvename> 5115 <url>http://www.squid-cache.org/Advisories/SQUID-2007_1.txt</url> 5116 </references> 5117 <dates> 5118 <discovery>2007-03-20</discovery> 5119 <entry>2007-03-21</entry> 5120 <modified>2010-05-12</modified> 5121 </dates> 5122 </vuln> 5123 5124 <vuln vid="8e02441d-d39c-11db-a6da-0003476f14d3"> 5125 <topic>sql-ledger -- security bypass vulnerability</topic> 5126 <affects> 5127 <package> 5128 <name>sql-ledger</name> 5129 <range><lt>2.6.26</lt></range> 5130 </package> 5131 </affects> 5132 <description> 5133 <body xmlns="http://www.w3.org/1999/xhtml"> 5134 <p>Chris Travers reports:</p> 5135 <blockquote cite="http://www.securityfocus.com/archive/1/462375"> 5136 <p>George Theall of Tenable Security notified the LedgerSMB 5137 core team today of an authentication bypass vulnerability 5138 allowing full access to the administrator interface of 5139 LedgerSMB 1.1 and SQL-Ledger 2.x. The problem is caused 5140 by the password checking routine failing to enforce a 5141 password check under certain circumstances. The user 5142 can then create accounts or effect denial of service 5143 attacks.</p> 5144 <p>This is not related to any previous CVE.</p> 5145 <p>We have coordinated with the SQL-Ledger vendor and 5146 today both of us released security patches correcting 5147 the problem. SQL-Ledger users who can upgrade to 2.6.26 5148 should do so, and LedgerSMB 1.1 or 1.0 users should 5149 upgrade to 1.1.9. Users who cannot upgrade should 5150 configure their web servers to use http authentication 5151 for the admin.pl script in the main root directory.</p> 5152 </blockquote> 5153 </body> 5154 </description> 5155 <references> 5156 <freebsdpr>ports/110350</freebsdpr> 5157 <url>http://www.securityfocus.com/archive/1/462375</url> 5158 </references> 5159 <dates> 5160 <discovery>2007-03-09</discovery> 5161 <entry>2007-03-16</entry> 5162 </dates> 5163 </vuln> 5164 5165 <vuln vid="f235fe7a-b9ca-11db-bf0f-0013720b182d"> 5166 <topic>samba -- potential Denial of Service bug in smbd</topic> 5167 <affects> 5168 <package> 5169 <name>samba</name> 5170 <name>ja-samba</name> 5171 <range><ge>3.0.6,1</ge><lt>3.0.24,1</lt></range> 5172 </package> 5173 </affects> 5174 <description> 5175 <body xmlns="http://www.w3.org/1999/xhtml"> 5176 <p>The Samba Team reports:</p> 5177 <blockquote cite="http://www.samba.org/samba/security/CVE-2007-0452.html"> 5178 <p>Internally Samba's file server daemon, smbd, implements 5179 support for deferred file open calls in an attempt to serve 5180 client requests that would otherwise fail due to a share mode 5181 violation. When renaming a file under certain circumstances 5182 it is possible that the request is never removed from the deferred 5183 open queue. smbd will then become stuck is a loop trying to 5184 service the open request.</p> 5185 <p>This bug may allow an authenticated user to exhaust resources 5186 such as memory and CPU on the server by opening multiple CIFS 5187 sessions, each of which will normally spawn a new smbd process, 5188 and sending each connection into an infinite loop.</p> 5189 </blockquote> 5190 </body> 5191 </description> 5192 <references> 5193 <cvename>CVE-2007-0452</cvename> 5194 <url>http://www.samba.org/samba/security/CVE-2007-0452.html</url> 5195 </references> 5196 <dates> 5197 <discovery>2007-02-05</discovery> 5198 <entry>2007-03-16</entry> 5199 </dates> 5200 </vuln> 5201 5202 <vuln vid="57ae52f7-b9cc-11db-bf0f-0013720b182d"> 5203 <topic>samba -- format string bug in afsacl.so VFS plugin</topic> 5204 <affects> 5205 <package> 5206 <name>samba</name> 5207 <name>ja-samba</name> 5208 <range><ge>3.0.6,1</ge><lt>3.0.24,1</lt></range> 5209 </package> 5210 </affects> 5211 <description> 5212 <body xmlns="http://www.w3.org/1999/xhtml"> 5213 <p>The Samba Team reports:</p> 5214 <blockquote cite="http://www.samba.org/samba/security/CVE-2007-0454.html"> 5215 <p>NOTE: This security advisory only impacts Samba servers 5216 that share AFS file systems to CIFS clients and which have 5217 been explicitly instructed in smb.conf to load the afsacl.so 5218 VFS module.</p> 5219 <p>The source defect results in the name of a file stored on 5220 disk being used as the format string in a call to snprintf(). 5221 This bug becomes exploitable only when a user is able 5222 to write to a share which utilizes Samba's afsacl.so library 5223 for setting Windows NT access control lists on files residing 5224 on an AFS file system.</p> 5225 </blockquote> 5226 </body> 5227 </description> 5228 <references> 5229 <cvename>CVE-2007-0454</cvename> 5230 <url>http://www.samba.org/samba/security/CVE-2007-0454.html</url> 5231 </references> 5232 <dates> 5233 <discovery>2007-02-05</discovery> 5234 <entry>2007-03-16</entry> 5235 </dates> 5236 </vuln> 5237 5238 <vuln vid="73f53712-d028-11db-8c07-0211d85f11fb"> 5239 <topic>ktorrent -- multiple vulnerabilities</topic> 5240 <affects> 5241 <package> 5242 <name>ktorrent</name> 5243 <range><lt>2.1.2</lt></range> 5244 </package> 5245 <package> 5246 <name>ktorrent-devel</name> 5247 <range><lt>20070311</lt></range> 5248 </package> 5249 </affects> 5250 <description> 5251 <body xmlns="http://www.w3.org/1999/xhtml"> 5252 <p>Two problems have been found in KTorrent:</p> 5253 <ul> 5254 <li>KTorrent does not properly sanitize file names to filter 5255 out ".." components, so it's possible for an attacker to create 5256 a malicious torrent in order to overwrite arbitrary files within 5257 the filesystem.</li> 5258 <li>Messages with invalid chunk indexes aren't rejected.</li> 5259 </ul> 5260 </body> 5261 </description> 5262 <references> 5263 <cvename>CVE-2007-1384</cvename> 5264 <cvename>CVE-2007-1385</cvename> 5265 <url>http://ktorrent.org/forum/viewtopic.php?t=1401</url> 5266 </references> 5267 <dates> 5268 <discovery>2007-03-09</discovery> 5269 <entry>2007-03-11</entry> 5270 <modified>2007-03-14</modified> 5271 </dates> 5272 </vuln> 5273 5274 <vuln vid="abeb9b64-ce50-11db-bc24-0016179b2dd5"> 5275 <topic>mplayer -- DMO File Parsing Buffer Overflow Vulnerability</topic> 5276 <affects> 5277 <package> 5278 <name>mplayer</name> 5279 <name>mplayer-esound</name> 5280 <name>mplayer-gtk</name> 5281 <name>mplayer-gtk2</name> 5282 <name>mplayer-gtk-esound</name> 5283 <name>mplayer-gtk2-esound</name> 5284 <range><lt>0.99.10_5</lt></range> 5285 </package> 5286 </affects> 5287 <description> 5288 <body xmlns="http://www.w3.org/1999/xhtml"> 5289 <p>"Moritz Jodeit reports:</p> 5290 <blockquote cite="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html"> 5291 <p>There's an exploitable buffer overflow in the current version 5292 of MPlayer (v1.0rc1) which can be exploited with a maliciously 5293 crafted video file. It is hidden in the DMO_VideoDecoder() 5294 function of `loader/dmo/DMO_VideoDecoder.c' file.</p> 5295 </blockquote> 5296 </body> 5297 </description> 5298 <references> 5299 <bid>22771</bid> 5300 <cvename>CVE-2007-1246</cvename> 5301 </references> 5302 <dates> 5303 <discovery>2007-02-11</discovery> 5304 <entry>2007-03-09</entry> 5305 </dates> 5306 </vuln> 5307 5308 <vuln vid="e546c7ce-ce46-11db-bc24-0016179b2dd5"> 5309 <topic>trac -- cross site scripting vulnerability</topic> 5310 <affects> 5311 <package> 5312 <name>trac</name> 5313 <range><lt>0.10.3</lt></range> 5314 </package> 5315 <package> 5316 <name>ja-trac</name> 5317 <range><lt>0.10.3_1</lt></range> 5318 </package> 5319 </affects> 5320 <description> 5321 <body xmlns="http://www.w3.org/1999/xhtml"> 5322 <p>Secunia reports:</p> 5323 <blockquote cite="http://secunia.com/advisories/24470/"> 5324 <p>The vulnerability is caused due to an error within the 5325 "download wiki page as text" function, which can be exploited 5326 to execute arbitrary HTML and script code in a user's browser 5327 session in context of an affected site.</p> 5328 <p>Successful exploitation may require that the victim uses IE.</p> 5329 </blockquote> 5330 </body> 5331 </description> 5332 <references> 5333 <url>http://secunia.com/advisories/24470</url> 5334 <url>http://trac.edgewall.org/wiki/ChangeLog#a0.10.3.1</url> 5335 </references> 5336 <dates> 5337 <discovery>2007-03-09</discovery> 5338 <entry>2007-03-09</entry> 5339 </dates> 5340 </vuln> 5341 5342 <vuln vid="cf86c644-cb6c-11db-8e9d-000c6ec775d9"> 5343 <topic>mod_jk -- long URL stack overflow vulnerability</topic> 5344 <affects> 5345 <package> 5346 <name>mod_jk-ap2</name> 5347 <name>mod_jk</name> 5348 <range><ge>1.2.19</ge><lt>1.2.21</lt></range> 5349 </package> 5350 </affects> 5351 <description> 5352 <body xmlns="http://www.w3.org/1999/xhtml"> 5353 <p>TippingPoint and The Zero Day Initiative reports:</p> 5354 <blockquote cite="http://www.zerodayinitiative.com/advisories/ZDI-07-008.html"> 5355 <p>This vulnerability allows remote attackers to execute 5356 arbitrary code on vulnerable installations of Apache 5357 Tomcat JK Web Server Connector. Authentication is not 5358 required to exploit this vulnerability.</p> 5359 <p>The specific flaw exists in the URI handler for the 5360 mod_jk.so library, map_uri_to_worker(), defined in 5361 native/common/jk_uri_worker_map.c. When parsing a long URL 5362 request, the URI worker map routine performs an unsafe 5363 memory copy. This results in a stack overflow condition 5364 which can be leveraged to execute arbitrary code.</p> 5365 </blockquote> 5366 </body> 5367 </description> 5368 <references> 5369 <cvename>CVE-2007-0774</cvename> 5370 <url>http://tomcat.apache.org/security-jk.html</url> 5371 <url>http://www.zerodayinitiative.com/advisories/ZDI-07-008.html</url> 5372 </references> 5373 <dates> 5374 <discovery>2007-03-02</discovery> 5375 <entry>2007-03-05</entry> 5376 <modified>2007-03-06</modified> 5377 </dates> 5378 </vuln> 5379 5380 <vuln vid="3cb6f059-c69d-11db-9f82-000e0c2e438a"> 5381 <topic>bind -- Multiple Denial of Service vulnerabilities</topic> 5382 <affects> 5383 <package> 5384 <name>named</name> 5385 <range><lt>9.3.4</lt></range> 5386 </package> 5387 <package> 5388 <name>FreeBSD</name> 5389 <range><ge>6.2</ge><lt>6.2_1</lt></range> 5390 <range><ge>6.1</ge><lt>6.1_13</lt></range> 5391 <range><ge>5.5</ge><lt>5.5_11</lt></range> 5392 </package> 5393 </affects> 5394 <description> 5395 <body xmlns="http://www.w3.org/1999/xhtml"> 5396 <h1>Problem Description:</h1> 5397 <p>A type * (ANY) query response containing multiple RRsets can 5398 trigger an assertion failure.</p> 5399 <p>Certain recursive queries can cause the nameserver to crash 5400 by using memory which has already been freed.</p> 5401 <h1>Impact:</h1> 5402 <p>A remote attacker sending a type * (ANY) query to an 5403 authoritative DNS server for a DNSSEC signed zone can cause 5404 the named(8) daemon to exit, resulting in a Denial of 5405 Service.</p> 5406 <p>A remote attacker sending recursive queries can cause the 5407 nameserver to crash, resulting in a Denial of Service.</p> 5408 <h1>Workaround:</h1> 5409 <p>There is no workaround available, but systems which are not 5410 authoritative servers for DNSSEC signed zones are not 5411 affected by the first issue; and systems which do not permit 5412 untrusted users to perform recursive DNS resolution are not 5413 affected by the second issue. Note that the default 5414 configuration for named(8) in FreeBSD allows local access 5415 only (which on many systems is equivalent to refusing access 5416 to untrusted users).</p> 5417 </body> 5418 </description> 5419 <references> 5420 <cvename>CVE-2007-0493</cvename> 5421 <cvename>CVE-2007-0494</cvename> 5422 <freebsdsa>SA-07:02.bind</freebsdsa> 5423 </references> 5424 <dates> 5425 <discovery>2007-02-09</discovery> 5426 <entry>2007-02-27</entry> 5427 <modified>2016-08-09</modified> 5428 </dates> 5429 </vuln> 5430 5431 <vuln vid="46b922a8-c69c-11db-9f82-000e0c2e438a"> 5432 <topic>FreeBSD -- Jail rc.d script privilege escalation</topic> 5433 <affects> 5434 <package> 5435 <name>FreeBSD</name> 5436 <range><ge>6.1</ge><lt>6.1_12</lt></range> 5437 <range><ge>6.0</ge><lt>6.0_17</lt></range> 5438 <range><ge>5.5</ge><lt>5.5_15</lt></range> 5439 </package> 5440 </affects> 5441 <description> 5442 <body xmlns="http://www.w3.org/1999/xhtml"> 5443 <h1>Problem Description:</h1> 5444 <p>In multiple situations the host's jail rc.d(8) script does 5445 not check if a path inside the jail file system structure is 5446 a symbolic link before using the path. In particular this is 5447 the case when writing the output from the jail start-up to 5448 /var/log/console.log and when mounting and unmounting file 5449 systems inside the jail directory structure.</p> 5450 <h1>Impact:</h1> 5451 <p>Due to the lack of handling of potential symbolic links the 5452 host's jail rc.d(8) script is vulnerable to "symlink 5453 attacks". By replacing /var/log/console.log inside the jail 5454 with a symbolic link it is possible for the superuser (root) 5455 inside the jail to overwrite files on the host system outside 5456 the jail with arbitrary content. This in turn can be used to 5457 execute arbitrary commands with non-jailed superuser 5458 privileges.</p> 5459 <p>Similarly, by changing directory mount points inside the 5460 jail file system structure into symbolic links, it may be 5461 possible for a jailed attacker to mount file systems which 5462 were meant to be mounted inside the jail at arbitrary points 5463 in the host file system structure, or to unmount arbitrary 5464 file systems on the host system.</p> 5465 <p>NOTE WELL: The above vulnerabilities occur only when a jail 5466 is being started or stopped using the host's jail rc.d(8) 5467 script; once started (and until stopped), running jails 5468 cannot exploit this.</p> 5469 <h1>Workaround:</h1> 5470 <p>If the sysctl(8) variable security.jail.chflags_allowed is 5471 set to 0 (the default), setting the "sunlnk" system flag on 5472 /var, /var/log, /var/log/console.log, and all file system 5473 mount points and their parent directories inside the jail(s) 5474 will ensure that the console log file and mount points are 5475 not replaced by symbolic links. If this is done while jails 5476 are running, the administrator must check that an attacker 5477 has not replaced any directories with symlinks after setting 5478 the "sunlnk" flag.</p> 5479 </body> 5480 </description> 5481 <references> 5482 <cvename>CVE-2007-0166</cvename> 5483 <freebsdsa>SA-07:01.jail</freebsdsa> 5484 </references> 5485 <dates> 5486 <discovery>2007-01-11</discovery> 5487 <entry>2007-02-27</entry> 5488 <modified>2016-08-09</modified> 5489 </dates> 5490 </vuln> 5491 5492 <vuln vid="44449bf7-c69b-11db-9f82-000e0c2e438a"> 5493 <topic>gtar -- name mangling symlink vulnerability</topic> 5494 <affects> 5495 <package> 5496 <name>FreeBSD</name> 5497 <range><ge>5.5</ge><lt>5.5_9</lt></range> 5498 <range><ge>4.11</ge><lt>4.11_26</lt></range> 5499 </package> 5500 </affects> 5501 <description> 5502 <body xmlns="http://www.w3.org/1999/xhtml"> 5503 <h1>Problem Description:</h1> 5504 <p>Symlinks created using the "GNUTYPE_NAMES" tar extension can 5505 be absolute due to lack of proper sanity checks.</p> 5506 <h1>Impact:</h1> 5507 <p>If an attacker can get a user to extract a specially crafted 5508 tar archive the attacker can overwrite arbitrary files with 5509 the permissions of the user running gtar. If file system 5510 permissions allow it, this may allow the attacker to overwrite 5511 important system file (if gtar is being run as root), or 5512 important user configuration files such as .tcshrc or .bashrc, 5513 which would allow the attacker to run arbitrary commands.</p> 5514 <h1>Workaround:</h1> 5515 <p>Use "bsdtar", which is the default tar implementation in 5516 FreeBSD 5.3 and higher. For FreeBSD 4.x, bsdtar is available 5517 in the FreeBSD Ports Collection as 5518 ports/archivers/libarchive.</p> 5519 </body> 5520 </description> 5521 <references> 5522 <cvename>CVE-2006-6097</cvename> 5523 <freebsdsa>SA-06:26.gtar</freebsdsa> 5524 </references> 5525 <dates> 5526 <discovery>2006-12-06</discovery> 5527 <entry>2007-02-27</entry> 5528 <modified>2016-08-09</modified> 5529 </dates> 5530 </vuln> 5531 5532 <vuln vid="5c554c0f-c69a-11db-9f82-000e0c2e438a"> 5533 <topic>FreeBSD -- Kernel memory disclosure in firewire(4)</topic> 5534 <affects> 5535 <package> 5536 <name>FreeBSD</name> 5537 <range><ge>6.1</ge><lt>6.1_11</lt></range> 5538 <range><ge>6.0</ge><lt>6.2_16</lt></range> 5539 <range><ge>5.5</ge><lt>5.5_9</lt></range> 5540 <range><ge>4.11</ge><lt>4.11_26</lt></range> 5541 </package> 5542 </affects> 5543 <description> 5544 <body xmlns="http://www.w3.org/1999/xhtml"> 5545 <h1>Problem Description:</h1> 5546 <p>In the FW_GCROM ioctl, a signed integer comparison is used 5547 instead of an unsigned integer comparison when computing the 5548 length of a buffer to be copied from the kernel into the 5549 calling application.</p> 5550 <h1>Impact:</h1> 5551 <p>A user in the "operator" group can read the contents of 5552 kernel memory. Such memory might contain sensitive 5553 information, such as portions of the file cache or terminal 5554 buffers. This information might be directly useful, or it 5555 might be leveraged to obtain elevated privileges in some way; 5556 for example, a terminal buffer might include a user-entered 5557 password.</p> 5558 <h1>Workaround:</h1> 5559 <p>No workaround is available, but systems without IEEE 1394 5560 ("FireWire") interfaces are not vulnerable. (Note that 5561 systems with IEEE 1394 interfaces are affected regardless of 5562 whether any devices are attached.)</p> 5563 <p>Note also that FreeBSD does not have any non-root users in 5564 the "operator" group by default; systems on which no users 5565 have been added to this group are therefore also not 5566 vulnerable.</p> 5567 </body> 5568 </description> 5569 <references> 5570 <cvename>CVE-2006-6013</cvename> 5571 <freebsdsa>SA-06:25.kmem</freebsdsa> 5572 </references> 5573 <dates> 5574 <discovery>2006-12-06</discovery> 5575 <entry>2007-02-27</entry> 5576 <modified>2016-08-09</modified> 5577 </dates> 5578 </vuln> 5579 5580 <vuln vid="792bc222-c5d7-11db-9f82-000e0c2e438a"> 5581 <topic>libarchive -- Infinite loop in corrupt archives handling in libarchive</topic> 5582 <affects> 5583 <package> 5584 <name>libarchive</name> 5585 <range><lt>1.3.1</lt></range> 5586 </package> 5587 </affects> 5588 <description> 5589 <body xmlns="http://www.w3.org/1999/xhtml"> 5590 <h1>Problem Description:</h1> 5591 <p>If the end of an archive is reached while attempting to 5592 "skip" past a region of an archive, libarchive will enter an 5593 infinite loop wherein it repeatedly attempts (and fails) to 5594 read further data.</p> 5595 <h1>Impact:</h1> 5596 <p>An attacker able to cause a system to extract (via "tar -x" 5597 or another application which uses libarchive) or list the 5598 contents (via "tar -t" or another libarchive-using 5599 application) of an archive provided by the attacker can cause 5600 libarchive to enter an infinite loop and use all available 5601 CPU time.</p> 5602 <h1>Workaround:</h1> 5603 <p>No workaround is available.</p> 5604 </body> 5605 </description> 5606 <references> 5607 <cvename>CVE-2006-5680</cvename> 5608 <freebsdsa>SA-06:24.libarchive</freebsdsa> 5609 </references> 5610 <dates> 5611 <discovery>2006-11-08</discovery> 5612 <entry>2007-02-26</entry> 5613 </dates> 5614 </vuln> 5615 5616 <vuln vid="0f37d765-c5d4-11db-9f82-000e0c2e438a"> 5617 <topic>OpenSSL -- Multiple problems in crypto(3)</topic> 5618 <affects> 5619 <package> 5620 <name>openssl</name> 5621 <range><lt>0.9.7l_0</lt></range> 5622 <range><ge>0.9.8</ge><lt>0.9.8d_0</lt></range> 5623 </package> 5624 <package> 5625 <name>FreeBSD</name> 5626 <range><ge>6.1</ge><lt>6.1_9</lt></range> 5627 <range><ge>6.0</ge><lt>6.0_14</lt></range> 5628 <range><ge>5.5</ge><lt>5.5_7</lt></range> 5629 <range><ge>5.4</ge><lt>5.4_21</lt></range> 5630 <range><ge>5.3</ge><lt>5.3_36</lt></range> 5631 <range><ge>4.11</ge><lt>4.11_24</lt></range> 5632 </package> 5633 </affects> 5634 <description> 5635 <body xmlns="http://www.w3.org/1999/xhtml"> 5636 <h1>Problem Description:</h1> 5637 <p>Several problems have been found in OpenSSL:</p> 5638 <ul> 5639 <li>During the parsing of certain invalid ASN1 structures an 5640 error condition is mishandled, possibly resulting in an 5641 infinite loop.</li> 5642 <li>A buffer overflow exists in the SSL_get_shared_ciphers 5643 function.</li> 5644 <li>A NULL pointer may be dereferenced in the SSL version 2 5645 client code.</li> 5646 </ul> 5647 <p>In addition, many applications using OpenSSL do not perform 5648 any validation of the lengths of public keys being used.</p> 5649 <h1>Impact:</h1> 5650 <p>Servers which parse ASN1 data from untrusted sources may be 5651 vulnerable to a denial of service attack.</p> 5652 <p>An attacker accessing a server which uses SSL version 2 may 5653 be able to execute arbitrary code with the privileges of that 5654 server.</p> 5655 <p>A malicious SSL server can cause clients connecting using 5656 SSL version 2 to crash.</p> 5657 <p>Applications which perform public key operations using 5658 untrusted keys may be vulnerable to a denial of service 5659 attack.</p> 5660 <h1>Workaround:</h1> 5661 <p>No workaround is available, but not all of the 5662 vulnerabilities mentioned affect all applications.</p> 5663 </body> 5664 </description> 5665 <references> 5666 <cvename>CVE-2006-2937</cvename> 5667 <cvename>CVE-2006-2938</cvename> 5668 <cvename>CVE-2006-2940</cvename> 5669 <cvename>CVE-2006-3738</cvename> 5670 <cvename>CVE-2006-4343</cvename> 5671 <freebsdsa>SA-06:23.openssl</freebsdsa> 5672 </references> 5673 <dates> 5674 <discovery>2006-09-28</discovery> 5675 <entry>2007-02-26</entry> 5676 <modified>2016-08-09</modified> 5677 </dates> 5678 </vuln> 5679 5680 <vuln vid="12bd6ecf-c430-11db-95c5-000c6ec775d9"> 5681 <topic>mozilla -- multiple vulnerabilities</topic> 5682 <affects> 5683 <package> 5684 <name>firefox</name> 5685 <range><lt>1.5.0.10,1</lt></range> 5686 <range><gt>2.*,1</gt><lt>2.0.0.2,1</lt></range> 5687 </package> 5688 <package> 5689 <name>linux-firefox</name> 5690 <range><lt>1.5.0.10</lt></range> 5691 </package> 5692 <package> 5693 <name>lightning</name> 5694 <range><lt>0.3.1</lt></range> 5695 </package> 5696 <package> 5697 <name>seamonkey</name> 5698 <name>linux-seamonkey</name> 5699 <range><lt>1.0.8</lt></range> 5700 <range><ge>1.1</ge><lt>1.1.1</lt></range> 5701 </package> 5702 <package> 5703 <name>thunderbird</name> 5704 <name>linux-thunderbird</name> 5705 <name>mozilla-thunderbird</name> 5706 <range><lt>1.5.0.10</lt></range> 5707 </package> 5708 <package> 5709 <name>linux-firefox-devel</name> 5710 <range><lt>3.0.a2007.04.18</lt></range> 5711 </package> 5712 <package> 5713 <name>linux-seamonkey-devel</name> 5714 <range><lt>1.5.a2007.04.18</lt></range> 5715 </package> 5716 <package> 5717 <name>firefox-ja</name> 5718 <name>linux-mozilla-devel</name> 5719 <name>linux-mozilla</name> 5720 <name>mozilla</name> 5721 <range><gt>0</gt></range> 5722 </package> 5723 </affects> 5724 <description> 5725 <body xmlns="http://www.w3.org/1999/xhtml"> 5726 <p>The Mozilla Foundation reports of multiple security issues 5727 in Firefox, Seamonkey, and Thunderbird. Several of these 5728 issues can probably be used to run arbitrary code with the 5729 privilege of the user running the program.</p> 5730 <blockquote cite="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.2"> 5731 <ul> 5732 <li>MFSA 2007-08 onUnload + document.write() memory corruption</li> 5733 <li>MFSA 2007-07 Embedded nulls in location.hostname confuse same-domain checks</li> 5734 <li>MFSA 2007-06 Mozilla Network Security Services (NSS) SSLv2 buffer overflow</li> 5735 <li>MFSA 2007-05 XSS and local file access by opening blocked popups</li> 5736 <li>MFSA 2007-04 Spoofing using custom cursor and CSS3 hotspot</li> 5737 <li>MFSA 2007-03 Information disclosure through cache collisions</li> 5738 <li>MFSA 2007-02 Improvements to help protect against Cross-Site Scripting attacks</li> 5739 <li>MFSA 2007-01 Crashes with evidence of memory corruption (rv:1.8.0.10/1.8.1.2)</li> 5740 </ul> 5741 </blockquote> 5742 </body> 5743 </description> 5744 <references> 5745 <cvename>CVE-2006-6077</cvename> 5746 <cvename>CVE-2007-0008</cvename> 5747 <cvename>CVE-2007-0009</cvename> 5748 <cvename>CVE-2007-0775</cvename> 5749 <cvename>CVE-2007-0776</cvename> 5750 <cvename>CVE-2007-0777</cvename> 5751 <cvename>CVE-2007-0778</cvename> 5752 <cvename>CVE-2007-0779</cvename> 5753 <cvename>CVE-2007-0780</cvename> 5754 <cvename>CVE-2007-0800</cvename> 5755 <cvename>CVE-2007-0981</cvename> 5756 <cvename>CVE-2007-0995</cvename> 5757 <cvename>CVE-2007-1092</cvename> 5758 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482</url> 5759 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483</url> 5760 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</url> 5761 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</url> 5762 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-03.html</url> 5763 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-04.html</url> 5764 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</url> 5765 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</url> 5766 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-07.html</url> 5767 <url>http://www.mozilla.org/security/announce/2007/mfsa2007-08.html</url> 5768 </references> 5769 <dates> 5770 <discovery>2007-02-23</discovery> 5771 <entry>2007-02-24</entry> 5772 <modified>2007-04-19</modified> 5773 </dates> 5774 </vuln> 5775 5776 <vuln vid="afdf500f-c1f6-11db-95c5-000c6ec775d9"> 5777 <topic>snort -- DCE/RPC preprocessor vulnerability</topic> 5778 <affects> 5779 <package> 5780 <name>snort</name> 5781 <range><ge>2.6.1</ge><lt>2.6.1.3</lt></range> 5782 </package> 5783 </affects> 5784 <description> 5785 <body xmlns="http://www.w3.org/1999/xhtml"> 5786 <p>A IBM Internet Security Systems Protection Advisory 5787 reports:</p> 5788 <blockquote cite="http://iss.net/threats/257.html"> 5789 <p>Snort is vulnerable to a stack-based buffer overflow as a 5790 result of DCE/RPC reassembly. This vulnerability is in a 5791 dynamic-preprocessor enabled in the default configuration, 5792 and the configuration for this preprocessor allows for 5793 auto-recognition of SMB traffic to perform reassembly 5794 on. No checks are performed to see if the traffic is part 5795 of a valid TCP session, and multiple Write AndX requests 5796 can be chained in the same TCP segment. As a result, an 5797 attacker can exploit this overflow with a single TCP PDU 5798 sent across a network monitored by Snort or Sourcefire.</p> 5799 <p>Snort users who cannot upgrade immediately are advised to 5800 disable the DCE/RPC preprocessor by removing the DCE/RPC 5801 preprocessor directives from snort.conf and restarting 5802 Snort. However, be advised that disabling the DCE/RPC 5803 preprocessor reduces detection capabilities for attacks in 5804 DCE/RPC traffic. After upgrading, customers should 5805 re-enable the DCE/RPC preprocessor.</p> 5806 </blockquote> 5807 </body> 5808 </description> 5809 <references> 5810 <certvu>196240</certvu> 5811 <cvename>CVE-2006-5276</cvename> 5812 <url>http://xforce.iss.net/xforce/xfdb/31275</url> 5813 <url>http://www.snort.org/docs/advisory-2007-02-19.html</url> 5814 </references> 5815 <dates> 5816 <discovery>2007-02-19</discovery> 5817 <entry>2007-02-21</entry> 5818 </dates> 5819 </vuln> 5820 5821 <vuln vid="94234e00-be8a-11db-b2ec-000c6ec775d9"> 5822 <topic>rar -- password prompt buffer overflow vulnerability</topic> 5823 <affects> 5824 <package> 5825 <name>rar</name> 5826 <range><lt>3.70.b1,1</lt></range> 5827 </package> 5828 <package> 5829 <name>unrar</name> 5830 <name>zh-unrar</name> 5831 <range><lt>3.70.b1,4</lt></range> 5832 </package> 5833 </affects> 5834 <description> 5835 <body xmlns="http://www.w3.org/1999/xhtml"> 5836 <p>iDefense reports:</p> 5837 <blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472"> 5838 <p>Remote exploitation of a stack based buffer overflow 5839 vulnerability in RARLabs Unrar may allow an attacker to 5840 execute arbitrary code with the privileges of the user 5841 opening the archive.</p> 5842 <p>Unrar is prone to a stack based buffer overflow when 5843 processing specially crafted password protected 5844 archives.</p> 5845 <p>If users are using the vulnerable command line based 5846 unrar, they still need to interact with the program in 5847 order to trigger the vulnerability. They must respond to 5848 the prompt asking for the password, after which the 5849 vulnerability will be triggered. They do not need to enter 5850 a correct password, but they must at least push the enter 5851 key.</p> 5852 </blockquote> 5853 </body> 5854 </description> 5855 <references> 5856 <bid>22447</bid> 5857 <cvename>CVE-2007-0855</cvename> 5858 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472</url> 5859 <url>http://www.rarsoft.com/rarnew.htm</url> 5860 </references> 5861 <dates> 5862 <discovery>2007-02-07</discovery> 5863 <entry>2007-02-17</entry> 5864 </dates> 5865 </vuln> 5866 5867 <vuln vid="7fcf1727-be71-11db-b2ec-000c6ec775d9"> 5868 <topic>php -- multiple vulnerabilities</topic> 5869 <affects> 5870 <package> 5871 <name>php5-imap</name> 5872 <name>php5-odbc</name> 5873 <name>php5-session</name> 5874 <name>php5-shmop</name> 5875 <name>php5-sqlite</name> 5876 <name>php5-wddx</name> 5877 <name>php5</name> 5878 <range><lt>5.2.1_2</lt></range> 5879 </package> 5880 <package> 5881 <name>php4-odbc</name> 5882 <name>php4-session</name> 5883 <name>php4-shmop</name> 5884 <name>php4-wddx</name> 5885 <name>php4</name> 5886 <range><lt>4.4.5</lt></range> 5887 </package> 5888 <package> 5889 <name>mod_php4-twig</name> 5890 <name>mod_php4</name> 5891 <name>mod_php5</name> 5892 <name>mod_php</name> 5893 <name>php4-cgi</name> 5894 <name>php4-cli</name> 5895 <name>php4-dtc</name> 5896 <name>php4-horde</name> 5897 <name>php4-nms</name> 5898 <name>php5-cgi</name> 5899 <name>php5-cli</name> 5900 <name>php5-dtc</name> 5901 <name>php5-horde</name> 5902 <name>php5-nms</name> 5903 <range><ge>4</ge><lt>4.4.5</lt></range> 5904 <range><ge>5</ge><lt>5.2.1_2</lt></range> 5905 </package> 5906 </affects> 5907 <description> 5908 <body xmlns="http://www.w3.org/1999/xhtml"> 5909 <p>Multiple vulnerabilities have been found in PHP, including: 5910 buffer overflows, stack overflows, format string, and 5911 information disclosure vulnerabilities.</p> 5912 <p>The session extension contained <code>safe_mode</code> and 5913 <code>open_basedir</code> bypasses, but the FreeBSD Security 5914 Officer does not consider these real security 5915 vulnerabilities, since <code>safe_mode</code> and 5916 <code>open_basedir</code> are insecure by design and should 5917 not be relied upon.</p> 5918 </body> 5919 </description> 5920 <references> 5921 <cvename>CVE-2007-0905</cvename> 5922 <cvename>CVE-2007-0906</cvename> 5923 <cvename>CVE-2007-0907</cvename> 5924 <cvename>CVE-2007-0908</cvename> 5925 <cvename>CVE-2007-0909</cvename> 5926 <cvename>CVE-2007-0910</cvename> 5927 <cvename>CVE-2007-0988</cvename> 5928 <url>http://secunia.com/advisories/24089/</url> 5929 <url>http://www.php.net/releases/4_4_5.php</url> 5930 <url>http://www.php.net/releases/5_2_1.php</url> 5931 </references> 5932 <dates> 5933 <discovery>2007-02-09</discovery> 5934 <entry>2007-02-17</entry> 5935 <modified>2013-04-01</modified> 5936 </dates> 5937 </vuln> 5938 5939 <vuln vid="7bb127c1-a5aa-11db-9ddc-0011098b2f36"> 5940 <topic>joomla -- multiple remote vulnerabilities</topic> 5941 <affects> 5942 <package> 5943 <name>joomla</name> 5944 <range><lt>1.0.12</lt></range> 5945 </package> 5946 </affects> 5947 <description> 5948 <body xmlns="http://www.w3.org/1999/xhtml"> 5949 <p>Secunia reports:</p> 5950 <blockquote cite="http://secunia.com/advisories/23563/"> 5951 <p>Some vulnerabilities have been reported in Joomla!, where some 5952 have unknown impacts and one can be exploited by malicious people 5953 to conduct cross-site scripting attacks.</p> 5954 <ol> 5955 <li>Input passed to an unspecified parameter is not properly 5956 sanitised before being returned to the user. This can be 5957 exploited to execute arbitrary HTML and script code in a 5958 user's browser session in context of an affected site.</li> 5959 <li>The vulnerabilities are caused due to unspecified errors 5960 in Joomla!. The vendor describes them as "several low level 5961 security issues". No further information is currently 5962 available.</li> 5963 </ol> 5964 </blockquote> 5965 </body> 5966 </description> 5967 <references> 5968 <bid>21810</bid> 5969 <cvename>CVE-2006-6832</cvename> 5970 <cvename>CVE-2006-6833</cvename> 5971 <cvename>CVE-2006-6834</cvename> 5972 <url>http://secunia.com/advisories/23563/</url> 5973 </references> 5974 <dates> 5975 <discovery>2006-12-29</discovery> 5976 <entry>2007-01-17</entry> 5977 </dates> 5978 </vuln> 5979 5980 <vuln vid="1374b96c-a1c2-11db-9ddc-0011098b2f36"> 5981 <topic>sircd -- remote reverse DNS buffer overflow</topic> 5982 <affects> 5983 <package> 5984 <name>sircd</name> 5985 <range><le>0.4.0</le></range> 5986 </package> 5987 </affects> 5988 <description> 5989 <body xmlns="http://www.w3.org/1999/xhtml"> 5990 <p>Secunia reports:</p> 5991 <blockquote cite="http://secunia.com/advisories/8153/"> 5992 <p>A vulnerability in sircd can be exploited by a malicious person 5993 to compromise a vulnerable system. The vulnerability is caused 5994 by a boundary error in the code handling reverse DNS lookups, 5995 when a user connects to the service. If the FQDN (Fully Qualified 5996 Domain Name) returned is excessively long, the allocated buffer 5997 is overflowed making it possible to execute arbitrary code on the 5998 system with the privileges of the sircd daemon.</p> 5999 </blockquote> 6000 </body> 6001 </description> 6002 <references> 6003 <bid>6924</bid> 6004 <url>http://secunia.com/advisories/8153</url> 6005 </references> 6006 <dates> 6007 <discovery>2003-02-24</discovery> 6008 <entry>2007-01-15</entry> 6009 </dates> 6010 </vuln> 6011 6012 <vuln vid="e92d8f6b-a1c0-11db-9ddc-0011098b2f36"> 6013 <topic>sircd -- remote operator privilege escalation vulnerability</topic> 6014 <affects> 6015 <package> 6016 <name>sircd</name> 6017 <range><ge>0</ge></range> 6018 </package> 6019 </affects> 6020 <description> 6021 <body xmlns="http://www.w3.org/1999/xhtml"> 6022 <p>Secunia reports:</p> 6023 <blockquote cite="http://secunia.com/advisories/10274/"> 6024 <p>A vulnerability has been reported in sircd, which can be 6025 exploited by malicious users to gain operator privileges. 6026 The problem is that any user reportedly can set their usermode 6027 to operator. The vulnerability has been reported in 6028 versions 0.5.2 and 0.5.3. Other versions may also be affected.</p> 6029 </blockquote> 6030 </body> 6031 </description> 6032 <references> 6033 <bid>9097</bid> 6034 <url>http://secunia.com/advisories/10274/</url> 6035 </references> 6036 <dates> 6037 <discovery>2003-11-20</discovery> 6038 <entry>2007-01-15</entry> 6039 </dates> 6040 </vuln> 6041 6042 <vuln vid="41da2ba4-a24e-11db-bd24-000f3dcc6a5d"> 6043 <topic>cacti -- Multiple vulnerabilities</topic> 6044 <affects> 6045 <package> 6046 <name>cacti</name> 6047 <range><lt>0.8.6i.4</lt></range> 6048 </package> 6049 </affects> 6050 <description> 6051 <body xmlns="http://www.w3.org/1999/xhtml"> 6052 <p>Secunia reports:</p> 6053 <blockquote cite="http://secunia.com/advisories/23528/"> 6054 <p>rgod has discovered four vulnerabilities in Cacti, 6055 which can be exploited by malicious people to bypass 6056 certain security restrictions, manipulate data 6057 and compromise vulnerable systems.</p> 6058 </blockquote> 6059 </body> 6060 </description> 6061 <references> 6062 <url>http://secunia.com/advisories/23528/</url> 6063 <url>http://forums.cacti.net/about18846-0-asc-0.html</url> 6064 </references> 6065 <dates> 6066 <discovery>2006-12-28</discovery> 6067 <entry>2007-01-12</entry> 6068 </dates> 6069 </vuln> 6070 6071 <vuln vid="b2ff68b2-9f29-11db-a4e4-0211d87675b7"> 6072 <topic>mplayer -- buffer overflow in the code for RealMedia RTSP streams.</topic> 6073 <affects> 6074 <package> 6075 <name>mplayer</name> 6076 <name>mplayer-esound</name> 6077 <name>mplayer-gtk</name> 6078 <name>mplayer-gtk2</name> 6079 <name>mplayer-gtk-esound</name> 6080 <name>mplayer-gtk2-esound</name> 6081 <range><lt>0.99.10_1</lt></range> 6082 </package> 6083 </affects> 6084 <description> 6085 <body xmlns="http://www.w3.org/1999/xhtml"> 6086 <blockquote cite="http://www.mplayerhq.hu/design7/news.html"> 6087 <p>A potential buffer overflow was found in the code used to handle 6088 RealMedia RTSP streams. When checking for matching asm rules, the code 6089 stores the results in a fixed-size array, but no boundary checks are 6090 performed. This may lead to a buffer overflow if the user is tricked 6091 into connecting to a malicious server. Since the attacker cannot write 6092 arbitrary data into the buffer, creating an exploit is very hard; but a 6093 DoS attack is easily made. 6094 A fix for this problem was committed to SVN on Sun Dec 31 13:27:53 2006 6095 UTC as r21799. The fix involves three files: stream/realrtsp/asmrp.c, 6096 stream/realrtsp/asmrp.h and stream/realrtsp/real.c.</p> 6097 </blockquote> 6098 </body> 6099 </description> 6100 <references> 6101 <freebsdpr>ports/107217</freebsdpr> 6102 <cvename>CVE-2006-6172</cvename> 6103 <url>http://www.mplayerhq.hu/design7/news.html</url> 6104 </references> 6105 <dates> 6106 <discovery>2006-12-31</discovery> 6107 <entry>2007-01-08</entry> 6108 </dates> 6109 </vuln> 6110 6111 <vuln vid="37e30313-9d8c-11db-858b-0060084a00e5"> 6112 <topic>fetchmail -- crashes when refusing a message bound for an MDA</topic> 6113 <affects> 6114 <package> 6115 <name>fetchmail</name> 6116 <range><ge>6.3.5</ge><lt>6.3.6</lt></range> 6117 </package> 6118 </affects> 6119 <description> 6120 <body xmlns="http://www.w3.org/1999/xhtml"> 6121 <p>Matthias Andree reports:</p> 6122 <blockquote cite="http://www.fetchmail.info/fetchmail-SA-2006-03.txt"> 6123 <p>When delivering messages to a message delivery agent by means 6124 of the "mda" option, fetchmail can crash (by passing 6125 a NULL pointer to ferror() and fflush()) when refusing a message. 6126 SMTP and LMTP delivery modes aren't affected.</p> 6127 </blockquote> 6128 </body> 6129 </description> 6130 <references> 6131 <cvename>CVE-2006-5974</cvename> 6132 <url>http://www.fetchmail.info/fetchmail-SA-2006-03.txt</url> 6133 </references> 6134 <dates> 6135 <discovery>2007-01-04</discovery> 6136 <entry>2007-01-06</entry> 6137 </dates> 6138 </vuln> 6139 6140 <vuln vid="5238ac45-9d8c-11db-858b-0060084a00e5"> 6141 <topic>fetchmail -- TLS enforcement problem/MITM attack/password exposure</topic> 6142 <affects> 6143 <package> 6144 <name>fetchmail</name> 6145 <range><lt>6.3.6</lt></range> 6146 </package> 6147 </affects> 6148 <description> 6149 <body xmlns="http://www.w3.org/1999/xhtml"> 6150 <p>Matthias Andree reports:</p> 6151 <blockquote cite="http://www.fetchmail.info/fetchmail-SA-2006-02.txt"> 6152 <p>Fetchmail has had several longstanding password disclosure 6153 vulnerabilities.</p> 6154 <ul> 6155 <li>sslcertck/sslfingerprint options should have implied 6156 "sslproto tls1" in order to enforce TLS negotiation, 6157 but did not.</li> 6158 <li>Even with "sslproto tls1" in the config, fetches 6159 would go ahead in plain text if STLS/STARTTLS wasn't available 6160 (not advertised, or advertised but rejected).</li> 6161 <li>POP3 fetches could completely ignore all TLS options 6162 whether available or not because it didn't reliably issue 6163 CAPA before checking for STLS support - but CAPA is a 6164 requisite for STLS. Whether or not CAPAbilities were probed, 6165 depended on the "auth" option. (Fetchmail only 6166 tried CAPA if the auth option was not set at all, was set 6167 to gssapi, kerberos, kerberos_v4, otp, or cram-md5.)</li> 6168 <li>POP3 could fall back to using plain text passwords, even 6169 if strong authentication had been configured.</li> 6170 <li>POP2 would not complain if strong authentication or TLS 6171 had been requested.</li> 6172 </ul> 6173 </blockquote> 6174 </body> 6175 </description> 6176 <references> 6177 <cvename>CVE-2006-5867</cvename> 6178 <url>http://www.fetchmail.info/fetchmail-SA-2006-02.txt</url> 6179 </references> 6180 <dates> 6181 <discovery>2007-01-04</discovery> 6182 <entry>2007-01-06</entry> 6183 </dates> 6184 </vuln> 6185 6186 <vuln vid="78ad2525-9d0c-11db-a5f6-000c6ec775d9"> 6187 <topic>opera -- multiple vulnerabilities</topic> 6188 <affects> 6189 <package> 6190 <name>opera</name> 6191 <name>opera-devel</name> 6192 <name>linux-opera</name> 6193 <range><lt>9.10</lt></range> 6194 </package> 6195 </affects> 6196 <description> 6197 <body xmlns="http://www.w3.org/1999/xhtml"> 6198 <p>iDefense reports:</p> 6199 <blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457"> 6200 <p>The vulnerability specifically exists due to Opera 6201 improperly processing a JPEG DHT marker. The DHT marker is 6202 used to define a Huffman Table which is used for decoding 6203 the image data. An invalid number of index bytes in the 6204 DHT marker will trigger a heap overflow with partially 6205 user controlled data.</p> 6206 <p>Exploitation of this vulnerability would allow an 6207 attacker to execute arbitrary code on the affected 6208 host. The attacker would first need to construct a website 6209 containing the malicious image and trick the vulnerable 6210 user into visiting the site. This would trigger the 6211 vulnerability and allow the code to execute with the 6212 privileges of the local user.</p> 6213 </blockquote> 6214 <blockquote cite="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458"> 6215 <p>A flaw exists within Opera's Javascript SVG 6216 implementation. When processing a 6217 createSVGTransformFromMatrix request Opera does not 6218 properly validate the type of object passed to the 6219 function. Passing an incorrect object to this function can 6220 result in it using a pointer that is user controlled when 6221 it attempts to make the virtual function call.</p> 6222 <p>Exploitation of this vulnerability would allow an 6223 attacker to execute arbitrary code on the affected 6224 host. The attacker would first need to construct a website 6225 containing the malicious JavaScript and trick the 6226 vulnerable user into visiting the site. This would trigger 6227 the vulnerability and allow the code to execute with the 6228 privileges of the local user.</p> 6229 </blockquote> 6230 </body> 6231 </description> 6232 <references> 6233 <cvename>CVE-2007-0126</cvename> 6234 <cvename>CVE-2007-0127</cvename> 6235 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457</url> 6236 <url>http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458</url> 6237 <url>http://www.opera.com/support/search/supsearch.dml?index=851</url> 6238 <url>http://www.opera.com/support/search/supsearch.dml?index=852</url> 6239 </references> 6240 <dates> 6241 <discovery>2007-01-05</discovery> 6242 <entry>2007-01-05</entry> 6243 <modified>2010-05-12</modified> 6244 </dates> 6245 </vuln> 6246 6247 <vuln vid="3d8d3548-9d02-11db-a541-000ae42e9b93"> 6248 <topic>drupal -- multiple vulnerabilities</topic> 6249 <affects> 6250 <package> 6251 <name>drupal</name> 6252 <range><gt>4.7</gt><lt>4.7.5</lt></range> 6253 <range><lt>4.6.11</lt></range> 6254 </package> 6255 </affects> 6256 <description> 6257 <body xmlns="http://www.w3.org/1999/xhtml"> 6258 <p>The Drupal security team reports:</p> 6259 <blockquote cite="http://drupal.org/files/sa-2007-001/advisory.txt"> 6260 <p>A few arguments passed via URLs are not properly sanitized 6261 before display. When an attacker is able to entice an 6262 administrator to follow a specially crafted link, arbitrary 6263 HTML and script code can be injected and executed in the 6264 victim's session. Such an attack may lead to administrator 6265 access if certain conditions are met.</p> 6266 </blockquote> 6267 <blockquote cite="http://drupal.org/files/sa-2007-002/advisory.txt"> 6268 <p>The way page caching was implemented allows a denial of 6269 service attack. An attacker has to have the ability to post 6270 content on the site. He or she would then be able to poison 6271 the page cache, so that it returns cached 404 page not found 6272 errors for existing pages.</p> 6273 <p>If the page cache is not enabled, your site is not vulnerable. 6274 The vulnerability only affects sites running on top of MySQL.</p> 6275 </blockquote> 6276 </body> 6277 </description> 6278 <references> 6279 <cvename>CVE-2007-0136</cvename> 6280 <url>http://drupal.org/files/sa-2007-001/advisory.txt</url> 6281 <url>http://drupal.org/files/sa-2007-002/advisory.txt</url> 6282 </references> 6283 <dates> 6284 <discovery>2007-01-05</discovery> 6285 <entry>2007-01-05</entry> 6286 <modified>2010-05-12</modified> 6287 </dates> 6288 </vuln> 6289 6290 <vuln vid="9347d82d-9a66-11db-b271-000e35248ad7"> 6291 <topic>w3m -- format string vulnerability</topic> 6292 <affects> 6293 <package> 6294 <name>w3m</name> 6295 <name>w3m-img</name> 6296 <name>w3m-m17n</name> 6297 <name>w3m-m17n-img</name> 6298 <name>ja-w3m</name> 6299 <name>ja-w3m-img</name> 6300 <range><lt>0.5.1_6</lt></range> 6301 </package> 6302 </affects> 6303 <description> 6304 <body xmlns="http://www.w3.org/1999/xhtml"> 6305 <p>An anonymous person reports:</p> 6306 <blockquote cite="http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439"> 6307 <p>w3m-0.5.1 crashes when using the -dump or -backend options to 6308 open a HTTPS URL with a SSL certificate where the CN contains 6309 "%n%n%n%n%n%n".</p> 6310 </blockquote> 6311 </body> 6312 </description> 6313 <references> 6314 <bid>21735</bid> 6315 <cvename>CVE-2006-6772</cvename> 6316 <url>http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439</url> 6317 <url>http://secunia.com/advisories/23492/</url> 6318 </references> 6319 <dates> 6320 <discovery>2006-12-10</discovery> 6321 <entry>2007-01-03</entry> 6322 </dates> 6323 </vuln> 6324